#!/usr/bin/env python3
"""One-mass-pair non-planar hexa-box (two-loop, five-point, p1^2 = p3^2 = m^2; p2^2 = p4^2 = p5^2 = 0) --
final-form evaluator: every number checked below is COMPUTED IN THIS RUN by
block-analytic variation-of-parameters (VoP) layer recursions over closed-form
kernels, then compared live against independent AMFlow oracles.

FUNCTION CLASS (the final form). All results are layered iterated integrals
along the kinematic path t in [0,1], (s45,s15,m^2)(t) linear from the fit point
(-3,-5,-7,-2,-11;1) to the verification point (-3,-5,-7,-11,-17;2):

    n[i,k](t) = sum_terms  C * sqrt(rad(t)) * R(t) * G_word(t),

with exact fmpq rational kernels R, dlog / rational-remainder / algebraic
kernels in the words G, radical letters sqrt(l(t)/l(0)), and named boundary
constants C seeded at the fit point.  Evaluation to arbitrary precision =
raise the Chebyshev spectral order NC (--nc / --vop-nc, or env HEXABOX_NC /
HEXABOX_VOP_NC) and the working precision (--dps) -- the integrands are
analytic, nothing bottoms out in stored floats, and every kernel of the
recursion is an exact fmpq rational, EXCEPT the stored boundary-seed strings
(sec219 rows 1-13 = 50 digits, sec255 seeds = 70 digits), which cap value
precision of every coefficient above eps^-4.  --boundary-regenerate (2026-09-09; BOUNDARY
REGENERATE below) runs the sec255 recursion with
the 447 covered sec255 seeds from definition (certificate >= 78 d, the
printed length) and prints the TRUE input cap of that run: 34 significant
components on 24 kept cells at eps^-4 / eps^-2 still carry the
served 70-digit strings (closed-form constants not yet entered exactly), so
the cap is the served floor 69.32 d, not 78 d; the sec219 caps stand.

WHAT RUNS LIVE HERE (vs. what is archived input):

  Check 1 -- sec219 orbit: the certified eps-form path connection (rational
      entries, DE-derived) is integrated at runtime by the eps-layer VoP
      recursion (1x1 blocks: homogeneous dlog factors + layered quadrature)
      along the complex detour around the t=2/5 path pole; the seven sunrise
      subsector sources are evaluated from their analytic closed form
      c(eps)*(-p^2(t)-i0)^(1-2eps) at every node. Row-0 eps-form identity
      re-proven symbolically; eps^-3 vanishing identities checked live.

  Check 2 -- sec255 TOP SECTOR, fully live: the layer-recursion engine
      (hexabox_vop.py + hexabox_vop_lib.py) re-derives the closure of the
      graded 98-row exact rational path DE at runtime: every block's
      homogeneous fundamental is solved and certified EXACTLY over fmpq,
      Tier-1 layers are rebuilt as fully-expanded symbolic closed forms with
      zero-remainder exact-DE certificates (83 terms/row at eps^-4, 5576 at
      eps^-3), and the layered VoP recursion is evaluated spectrally to eps^0.
      All 15 top-sector Laurent coefficients are checked live against the
      independent deep-60 AMFlow oracle. Interior-path values are printed to
      show these are FUNCTIONS of the kinematics, not point lookups.

  Check 3a -- exact Laurent coefficients as FUNCTIONS of the path kinematics:
      the Tier-1 eps^-4 containers are audited live to contain ONLY exact
      rational constants (the sunrise residue c(0) = 1/4 -- so the eps^-4
      coefficient of every top master is an 83-term exact iterated-integral
      closed form with ZERO numeric seeds; on the path these three coefficients
      equal the rational functions m_i[eps^-4](t) of hexabox-expression.md
      Section 2a (denominator (t+1)(6t+11)(9t+2)^2(10t+7)(16t+9) times 105 /
      420 / 420); Check 3b's exact-function comparison can read them directly),
      then evaluated per-word directly
      at the verification endpoint (vs the independent oracle + the named
      Section-2a rationals) and at an interior kinematic point, cross-checked
      against the independent Tier-2 spectral route. The eps^-3 containers are
      censused: closed-form constants (rationals, log-primes, i*pi, sunrise
      Gamma-Taylor x log-rational -- all computed live) plus named fit-point
      boundary literals (transport seeds; counted and disclosed).

  Check 3b -- named boundary constants: the exact eps^-4 rationals, endpoint-rotation
      eps^-4 rationals and eps^-3 pi-rational imaginary parts are computed
      from rational arithmetic + pi at runtime and verified BOTH against the
      live recursion output of Check 2 and against the independent oracle.

  Check 4 -- sec223 orbit: KNOWN GAP -- NOT final form. The 18 'this work'
      values are archived outputs of the multi-layer Taylor transport of this
      work (exact rational layer reconstruction; archived artifact). The
      transport is not re-run here, so these are labeled archived; only the
      agreement digits vs the independent oracle are recomputed live.
      Recasting sec223 as a shipped live recursion remains open (its
      connection admits no eps-linear rescale; see hexabox-expression.md
      Section 3).

THE THREE KERNELS (97,0,m), m = 2, 3, 4 (the KNOWN GAP of earlier releases, retired):
the bundle carries them EXACT in exactA -- fmpq rationals reconstructed by CRT +
rational reconstruction on 101 path nodes, 8 withheld nodes reproduced; degrees
(120,122), (149,151), (178,180) -- byte-equal to layers 2, 3, 4 of
vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_0_*.json and of the candidate file
vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_97_0_*.json (the same object that supplies
the (97,0) layers m = 5..9); hybrid_kernels is empty and no tier runs a numeric kernel
(asserted).  The numeric fits of the earlier bundles (leave-one-out saturated at 187
nodes, degrees 93/93) agree with the exact layers to >= 68 digits along the path and
are kept under superseded_04bfd5f45c625ae8/ for the record; --boundary-regenerate now differs
from the default tier only in the 447 regenerated seeds.  eps^-4 and eps^-3 were exact
in every tier before this change as well.

Sub-orbits sec231/215/222 are NOT evaluated by this script; their verification
records live in hexabox-expression.md Section 2 (archived records).

EVALUATION INTERFACE (CLI; default run = the full check demo below, unchanged):

    python3 hexabox-evaluate.py                        # full check demo (checks 1-4, about seven minutes)
    python3 hexabox-evaluate.py --point 0.7            # sec219 row-0 at path point t=0.7 (tens of seconds)
    python3 hexabox-evaluate.py --point s45=-8.3,s15=-15.2,mm=1.7   # same point, kinematic form
    python3 hexabox-evaluate.py --point 0.62 --sec 255 # + sec255 top sector (re-derives the
                                                       #   live closure first, about eight minutes)
    python3 hexabox-evaluate.py --point 0.62 --sec 255 --dps 30     # sec255 30d FAST MODE
    python3 hexabox-evaluate.py --dps 120 --nc 120 --point 0.7      # precision knobs
    python3 hexabox-evaluate.py --dps-double           # rerun the sec219 verification point at 2x dps
                                                       #   (about a minute for both passes)
    python3 hexabox-evaluate.py --record-point P2      # RECORD PAIR at the second point (strings only; seconds)
    python3 hexabox-evaluate.py --record-point P2 --mutate-record   # control: one digit planted in memory -> FAIL, exit 1
    python3 hexabox-evaluate.py --kmax 5               # sec255 recursion to layer 5 = eps^1, eps^2 of the top sector,
                                                       #   GATED against the served 60-digit strings and the two vendored
                                                       #   oracle records (about ten minutes; EPS^1, EPS^2 SUCCESSION)
    python3 hexabox-evaluate.py --kmax 5 --dps-double  # + the two-precision pair of that gate (Check 2 twice: the deeper
                                                       #   pass first; about half an hour)
    python3 hexabox-evaluate.py --kmax 5 --mutate-eps12   # control: one digit of the served eps^1 string planted in
                                                       #   memory -> the string comparator FAILS by name, exit 1
    python3 hexabox-evaluate.py --boundary-regenerate  # the default check demo with the sec255 recursion on the 447
                                                       #   from-definition seeds, the (97,0,2..4) layers of the bundle
                                                       #   asserted equal to the vendored exact object (BOUNDARY
                                                       #   REGENERATE below; the served default's wall class)
    python3 hexabox-evaluate.py --boundary-regenerate --kmax 5   # + the eps^1, eps^2 gate on the regenerated inputs
    python3 hexabox-evaluate.py --boundary-regenerate --regen-dir DIR   # the regenerated bundle written under DIR
                                                       #   (default ./hexabox_regen_<stamp>/ in the working directory;
                                                       #   never removed by this tool)
    python3 hexabox-evaluate.py --gatepoint            # GATE POINT: the two-precision floors of all 98 masters at the
                                                       #   verification point, recomputed from the vendored pair strings
                                                       #   and read against the PAIR v2 keys (strings only; seconds)
    python3 hexabox-evaluate.py --gatepoint --mutate-gatepoint   # control: one digit of a goal-60 string planted in
                                                       #   memory -> the floor FAILS by name, exit 1

sec255 FAST MODE. For --point --sec 255 the pass bar of the independent
comparison scales with the requested target: bar = min(45, --dps),
strict-greater + directed-rounding slack (at-bar => FAIL, raising); the deep
bar (45 d) is unchanged for the default run. With --dps < 45 and no explicit
--vop-nc, the spectral order auto-drops to the MEASURED per-target floor
(VOP_NC_FAST_FLOOR; 30d target -> NC=180). The floor is CERTIFICATION-limited,
not bar-limited: the trailing-window tail bound must clear
10^-(min(dps,36)+10) without escalation (at dps 30: NC=160 bound 2.49e-38 >=
tol 1e-40 -> escalates; NC=180 bound 2.21e-43 certifies; the independent
comparison then measures 46.3 d >> the 30 d bar). Runtimes are approximate:
about six minutes at 30 digits (the Tier-1 closure is re-derived per call,
plus the Tier-2 recursion at NC=180) vs about seven at the deep NC=220, on a
2026 workstation -- the full live closure re-runs per call by design (nothing
archived), so the fast mode cannot reach a ~2 min wall; the sec219 --point
route (tens of seconds) is the fast single-point option. Values: fast-vs-deep
agreement measured at the full 24 printed digits (worst tag >= 60 d parse
floor, eps^-4 ~79 d).

DOMAIN (documented limits). The shipped final form lives on the one-parameter
Euclidean path (s45,s15,mm)(t) = (-2,-11,1) + t*(-9,-6,1) with (s12,s23,s34)
fixed at (-3,-5,-7), t in [0,1] (all invariants negative, mm>0: Euclidean).
sec219: real t in [0,0.35] U [0.45,1] -- the open window (0.35,0.45) is
bypassed by the complex detour around the path pole t=2/5. sec255: real t
outside the detour windows around the bundle's real path poles (printed at
runtime; approx (0.09,0.17) U (0.31,0.44) U (0.46,0.54)). Off-path kinematics
require deriving a new path DE (not shipped here).

PRECISION MODEL / STORED-STRING CAPS. --dps and --nc/--vop-nc are free knobs:
the integrands are analytic, so quadrature error falls spectrally in NC and
arithmetic error in dps (nothing in the sec219 machinery bottoms out in stored
floats -- --dps-double demonstrates this live on the structural-zero
identities). Agreement against STORED artifacts is capped by their string
lengths: sec219 fit-point boundary seeds rows 1-13 = 50 digits (caps the
transported eps^-1..eps^+2 endpoint agreement at ~40-50 d; measured NC- and
dps-stable), row-0 seed and independent oracle = 65 digits (eps^-2 sits at
this cap); sec255 seeds = 70 digits in the served default and --point tiers
(every kernel exact, THE THREE KERNELS above; --boundary-regenerate replaces
the 447 covered seeds, its own cap stated under BOUNDARY REGENERATE).
--dps-double prints these caps explicitly.

Inputs: hexabox-data.json (sec219 eps-form + boundary seeds + independent
oracles, each block states its origin in "_src"), hexabox-vop-data.json.gz
(exact rational graded path DE: the full 8151 exact entries + the 28 gated
candidate kernels + the three (97,0,2..4) layers exact (8182 exact entries and
no numeric kernel, run by every tier; --boundary-regenerate asserts the three
equal the vendored object of vendor_row24_kernels/) + the
fit-point boundary seeds to eps^4; its _provenance.item56_succession and _succession_2 blocks
state the successions -- the served bundle before 2026-09-07 carried the 5018 entries
reachable at layers <= 3 and the seeds to eps^2; the bundle before 2026-09-11
carried the three layers as numeric fits). Deps (pip):
mpmath, sympy, python-flint. Runtime at defaults: about seven minutes on a
2026 workstation (incl. the exact-function Check 3a; dominated by Check 2's
live spectral recursion; --vop-nc trades digits for time, ~0.26 digits of
endpoint agreement per unit NC).
Date packaged: 2026-07-03 (supersedes the 2026-07-01 and 2026-07-03-am
versions; the archived-endpoint replay of the top sector is REPLACED by the
live recursion). Evaluation interface (--point/--dps/--dps-double) and the
exact eps^-4-function check (3a) added 2026-07-03-pm.

RECORD PAIR AT THE SECOND POINT P2 (--record-point P2; strings only, seconds).
The six-scale function is NOT established (the final forms above live on the
one-parameter path), so nothing in this script can compute the masters at a
second point.  What exists at P2 = (s12,s23,s34,s45,s15,mm) =
(-5,-7,-11,-13,-19,3) is a RECORD PAIR: the three top-sector masters of hexaboxP3P4
through eps^0 evaluated twice by AMFlow, at goal 40 and at goal 50, shipped as
record_P2/out_goal40.json and record_P2/out_goal50.json (the record bytes,
sha256-pinned here with the comparison module hexabox_record_pair.py).  The tier
re-runs the record's comparison on the pinned bytes: per re/im component the
relative matched digits (the reproducing command's rule, vendored function for
function), structural zeros |value| <= 1e-40 on either side named and not
counted (30 components, 27 significant), the per-order complex-relative
minima (93.62 / 84.38 / 75.37 / 66.45 / 57.14 at eps^-4..eps^0) and the
component-wise minimum (56.65 at master 1, eps^0, im) against the bar 56 =
the floor of that minimum: PASS/FAIL by name.  Labels printed on every run: two
AMFlow precisions agreeing is what the digits mean; no independent record exists
at P2; eps^1, eps^2 were not run; the six-scale function is open; the reduction
ran at N = 33 prime fields vs 31 at the first point; the runs' own Arb radii
(~110 digits) are NOT a certification.  --mutate-record plants one digit in a
vendored output IN MEMORY (the files untouched) and the gate must FAIL by name.
Exit codes of this tier: 0 the gate passes and the recomputed figures equal the
record's (two decimals); 1 a gate FAILS by name; 2 the option refused (a value
other than P2, or combined with --point / --dps-double); 3 a pinned file's sha256
mismatches; 4 a pinned file is missing.  The tier is dispatched before any
final-form machinery is built and exits; every other tier is unchanged.

REACH CHECK (--kmax K, default 3 = the served recursion; 2026-09-07).  The sec255
recursion V_i^(k) = sum_j sum_{m in SUPP(i,j)} A_ij^(m) V_j^(k-m) reads only the layers m
the bundle carries; a layer absent from SUPP(i,j) within the reach of the requested
layer (k - k_min(j) >= m, k_min(j) the lowest live layer of the source row: its first
nonzero fit-point seed order plus L_j, -1 for a sunrise row) used to be dropped silently.
The engine (hexabox_vop.Vop255.reach_check) now refuses by name before the sum: for
every coupling above the record layer 3, for the top-sector couplings at every layer,
and for a row computed above layer 3 without a fit-point seed there (the seeds stop at
eps^2).  Check 2 prints the reach report right after the loader -- one '[vop/reach]'
line per row (k_min, the seeded layers, the couplings consuming it, the max m needed at
K) and the summary 'reach complete for KMAX K: yes/no' -- and on a short coupling prints
'REFUSED by name -- VoP reach: ...' and exits 1 before any layer is computed.  The record
layer of a bundle (the engine's KMAX_RECORD: the layer through which its supports and
seeds were computed and checked against the independent oracles) is 3 by the engine's
class default -- the served bundle before 2026-09-07, on which --kmax 5 refused at layer 4
(every top-sector coupling's support ended exactly at the layer-3 reach) -- and 5 for the
SUCCEEDED bundle shipped here, declared on the engine by this script when the loaded
bundle's sha256 is the succession's (EPS^1, EPS^2 SUCCESSION below): the gate of record
checked that bundle's layers through 5 against both oracle records, so above layer 3 its
non-top couplings whose supports end below the reach (386 at K = 5, the (61,61) class:
max m present 1..4 against a record ceiling of 7) are complete expansions of the exact
reconstruction, not drops, by the same reading the served default gives the 350 below
layer 3 -- the bundle carries no per-entry expansion order, so that reading is the
oracle's, not the bytes'.  On the succeeded bundle --kmax 5 passes the check (0 short
couplings, 0 rows without a seed) and --kmax 6 refuses at layer 6 by name (the
top-sector supports end at the exact reconstruction's ceiling m = 7; the seeds stop at
eps^4).  Not a short coupling: an absent m below a coupling's max m present (on the
succeeded bundle of 2026-09-11 the (97,0,2..4) layers sit in exactA in every tier, so that
count prints 0 in the default, --point and --boundary-regenerate tiers alike; the bundle
before it kept them in hybrid_kernels as numeric fits and printed 3 such gaps).  Exit codes: 1 REFUSED by name (a short coupling or seed); 2
--kmax below 3 (the served digits need the layers through 3), or --kmax other than 3
with a tier that runs no sec255 recursion (--record-point, --point --sec 219).  The
default run and every other tier print exactly the served output plus the '[vop/reach]'
lines (the loader line and the reach table count this bundle's 8182 entries).

EPS^1, EPS^2 SUCCESSION (--kmax 4 / 5; 2026-09-07).  The served hexabox-vop-data.json.gz
(35c91bc11f762196...) is succeeded by the gated candidate bundle of the eps^1, eps^2 gate
of record (c4d86690801bcef6..., re-cut only in provenance strings to 04bfd5f45c625ae8...,
itself succeeded 2026-09-11 by the shipped f9e64518cb2e9ef3..., which differs from it only in
the three (97,0,2..4) layers entered exact, hybrid_kernels emptied and the provenance strings
saying so: 8182 exact entries, THE THREE KERNELS above; superseded_04bfd5f45c625ae8/ keeps the
earlier bytes): the FULL exact A (8151 entries; the served 5018 byte-equal), the 28
CANDIDATE KERNELS entered from eleven exact candidate files -- (86..91,70) and
(95..97,70) at m = 8, 9, (97,0) and (97,2) at m = 5..9; exact rationals reconstructed on
101 path nodes by CRT + rational reconstruction, every record layer reproduced exactly,
8 withheld nodes reproduced -- and the 196 fit-point seed cells at orders 3 and 4 for all
98 rows (the 506 served cells kept byte for byte).  Those files and the gate's objects
are vendored under vendor_row24_eps12/ (the eleven KERNELS_CANDIDATE_v2_*.json, GATE_EPS12.json,
SUPPORT_AUDIT.json, BUILD_RECEIPT.json, ORACLE_goal30.json / ORACLE_goal60.json = the
two AMFlow evaluations of record at the verification point, precision goals 30 and 60,
whose eps^-4..eps^0 are the served deep-60 strings' source), sha256-pinned in SUCCESSION
below and checked BEFORE any check runs (missing -> exit 4, mismatch -> exit 3).  With
--kmax 4 / 5 Check 2 runs the recursion to layer 4 / 5, prints the served eps^-4..eps^0
comparison unchanged, then the eps^1 (and eps^2) endpoint of every master against (i)
the served 60-digit strings of hexabox-data.json sec255 (orders 1, 2; they are the goal-60
record's own values, so (i) is the served-string tamper check), (ii) the vendored goal-60
record and (iii) the vendored goal-30 record (the two independent records), digits in the
gate's convention
(complex-relative, -log10(|a-b| / max(|a|,|b|)); the real-part reading printed beside),
and with --dps-double (iv) the two-precision pair (Check 2 twice, the deeper pass first:
the engine library's constant registry is per process and tolerates only a coarser
re-registration).  THE RULE (the gate of record's): the eps^1, eps^2 layers are
ESTABLISHED iff the minimum over the three masters and over the references present is
>= 30 d at every order computed; below the bar the tier FAILS by name, exit 1.  The
gate of record read eps^1 40.21 d, eps^2 35.29 d (the goal-30 record is the
floor: the goal-60 record and the served strings sit at ~57 d, the pair at ~71-74 d) with
the eps^-4..eps^0 control at 44.59 d, at eng dps 85 / 115, NC 220; this script
prints those figures beside its live ones (the served defaults reproduce the dps-115
pass).  --mutate-eps12 plants one digit of the served eps^1 string of master 0 IN
MEMORY: the string comparator FAILS by name while both oracle comparators pass.  Exit
codes of the tier: 0 ESTABLISHED; 1 FAIL by name (a reference below the bar) or a
reach refusal; 2 --mutate-eps12 without --kmax >= 4, the declared oracle point (the script
literal SUCCESSION['oracle_point'] = the gate of record's point; the vendored records carry
no kinematic key, so this is a literal-vs-literal check) not the served verification point;
3 a pinned file's sha256 mismatches; 4 a pinned file is missing.
NOT ESTABLISHED by this script: the four m >= 5 top-row kernels' analytic status beyond
the gate (exact candidates reproducing both oracles, no proof); the 146 non-top couplings
of the record whose supports stop at m <= 4 (complete by the oracle reading only); a
second kinematic point at eps^1, eps^2 (the record pair at P2 stops at eps^0); the 187
path samples of record (deleted; D_spec reconstructed).

BOUNDARY REGENERATE (--boundary-regenerate; 2026-09-09).  The sec255 recursion of Check 2 (and of the eps^1, eps^2 gate
with --kmax 4 / 5) re-run on REGENERATED INPUTS, everything else as served: (i) the three kernels (97,0,m), m = 2, 3, 4:
since the 2026-09-11 succession the bundle itself carries them EXACT in exactA, so this tier no longer swaps them in; it
asserts that hybrid_kernels is empty and that the bundle's three layers equal layers 2, 3, 4 of
vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_0_*.json (the exact object of the eps^1, eps^2 succession's factored
read, layers 2..7; the file's layers 2, 3, 4 are asserted byte-equal to the served candidate file
vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_97_0_*.json before the run) -- the loader reads 8182 exact entries + 0
certified-numeric here as in every tier, and no numeric kernel enters the recursion (asserted in every tier); the
fit-vs-exact probe reading of the earlier releases is retired with the fits (their agreement with the exact layers,
>= 68 digits along the path, is recorded in the bundle's _succession_2 block and in superseded_04bfd5f45c625ae8/README.md);
(ii) the fit-point seeds
of the 447 covered (row, eps-order) cells replaced by the FROM-DEFINITION strings of vendor_row24_seeds/
fresh_strings_447_fromdef_*.json (the eta-chain generator re-run from definition at working precisions 90 and 120,
four checkpointed legs; the tag 'row,j' is positional with eps order = the tag's eps_order field, the bundle's own key
convention), the other 255 cells (the 24 eps^-4 and 35 eps^-2 / eps^-1 cells outside the chain's coverage and the 196
eps^3, eps^4 cells of the succession) kept as the bundle's.  THE KEPT CELLS AND THE TRUE INPUT CAP (2026-09-09,
cure 1; counted from the objects at every run and printed): of the 59 kept cells at eps^-4..eps^-1 -- in the value
path of every regenerate run, the recursion to eps^0 -- 49 components are structural zeros (|x| <= 1e-40),
35 are short terminating decimals (exact rationals as printed: 1/2, 7/4, 1/40, ...; the served printing rule pads
them to 70 digits) and 34 SIGNIFICANT components on 24 cells carry the served 70-digit strings of closed-form
constants NOT yet entered exactly -- rows 39..41, 58..60, 79..82 at eps^-2 (re and im: pi/6-, pi/4-class
constants) and rows 71..72, 86..97 at eps^-4 (re: rationals such as 1/24, -1/12) -- and those strings stay in
the recursion's input.  The true input cap of the regenerate recursion is therefore min(the seed certificate >= 78 d
on the 447 replaced cells, the served floor 69.32 d bounding those 34 components) = 69.32 d, NOT 78 d, until those
components are entered exactly at the working precision (an open point for a later succession -- they are closed-form
constants -- not built here).  The served floor 69.32 d is the measured agreement of the served 70-digit strings with
the from-definition strings over the 855 covered significant components (63,3:re:eps0 the worst; one printing rule
for every served cell, the kept strings printed at 70 digits), read at every run.  With --kmax 4 / 5 the 196 kept
eps^3, eps^4 cells (374 significant components, the succession's served 70-digit strings; 18 structural zeros)
enter the eps^1, eps^2 layers under the same floor.  Printed before the recursion, from the objects: the seed
certificate -- the number of tags whose dps-90 and dps-120 strings are identical and the significant digits of the
shortest such string (two runs agreeing on every printed digit certify a string to its printed length; the strings
are printed at 80 digits, mp.nstr(x, 80) under working precision 140 in the generator, so the certificate
is the printed length, 78 at the shortest), the served 70-digit seeds read against the dps-120 strings (min over the
855 significant components; the 39 structural zeros named by count), the kept-cell census above -- and the kernel
identity above.  The recursion, the exact-DE certificates, the [BOUND] lines and the independent-oracle comparison
then print in the served form; the oracle comparison stays capped by the oracle's own 60 digits: the tier
lifts the seed cap on the 447 replaced cells to the printed length of the
from-definition strings, while the 34 kept components, bounded by the served floor, hold the input cap there; it does not raise
the printed oracle agreement.  The engine's own loader line ('boundary seeds: 447 derived values cross-checked on
load against the retired interim strings, worst agreement N digits (threshold 60)') reads 69.35 d under this
tier where the served default reads 85.8 d: the 80-digit replaced strings are read against the retired 70-digit
interim cache the bundle carries as a load-time cross-check (the threshold 60 d holds; the cache is not an input of
the recursion) -- informational.  The regenerated bundle is written for the engine's loader to --regen-dir DIR
(default ./hexabox_regen_<stamp>/ under the working directory; the path is printed on the NOTE line); this tool
removes nothing -- the caller owns the directory.  Refused (exit 2) with --record-point, --point, --dps-double or
--gatepoint (--regen-dir without --boundary-regenerate likewise); every vendored file of vendor_row24_kernels/ and
vendor_row24_seeds/ is sha256-pinned in REGEN below (missing -> exit 4, mismatch -> exit 3, before any check runs);
the ten vendored objects of the two groups are re-cut by field (cure 3): a narrative string value -> "withheld", a
path value -> its basename with the sha256 of the file it named, every numeric leaf and every key name as emitted (the
four LEG_LANDING_* receipts' host strings "withheld" since cure 1); the objects as emitted are named by sha256 in
REGEN['vendored_from'] and in the two READMEs.  Not established here:
the exact kernels beyond the 101-node reconstruction (candidates reproducing both oracle records, no proof); the
34 kept components beyond the served strings.

GATE POINT (--gatepoint; 2026-09-09; strings only, seconds).  The two-precision floor of ALL 98 masters at the
verification point: vendor_row24_gatepoint/DATA_C24g60_pair_strings_*.json carries every master's goal-30 and goal-60
Arb-ball strings at every order eps^-4..eps^4 (the two evaluations of record) with the matched digits per component.
The tier pins the file, recomputes the matched digits of every component from the two strings with the record pair's
own function (hexabox_record_pair.matched_digits, pinned), skips the components the record marks null (numerical
zeros by the tool's rule), and prints the floors from its own table: all masters through eps^0, through eps^2, all
orders, per order, and the top sector; each is read against the stored digits (identical to two decimals, asserted)
and against the PAIR v2 keys of record (GATEPOINT['pair_v2'], script-emitted from the object bb0b69e312ea86f6...:
integer floors 48 / 42 / 32 and the per-order floors) -- PASS iff the recomputed floors equal those keys, FAIL by
name otherwise (exit 1).  --mutate-gatepoint plants one digit of a goal-60 string in memory (the file untouched): the
floor drops and the tier FAILS by name.  The digits are a two-precision agreement of one program (bounded by the
goal-30 member); no independent record exists at these orders for the 95 non-top masters.

Release note 2026-07-05 (precision tracking + certified bounds):
  * BUG FIX: the sec255 routes (Check 2, Check 3a, --point --sec 255) ran at a
    HARDCODED mp.mp.dps = 80, silently overriding --dps.  They now run at
    ENG_DPS = max(--dps + ENG_GUARD, 80): the ambient dps tracks the caller's
    --dps with a working pad; the floor 80 (the precision at which the
    boundary seeds were named) only ever ADDS precision and keeps the
    seed-string classification tolerances valid.  Boundary-seed PSLQ *naming*
    stays pinned at 80 dps (hexabox_vop.NAMING_DPS, mp.workdps): naming is
    bounded by the 65-70 digit seed strings and is re-certified downstream by
    the zero-remainder exact-DE certificates and the independent endpoint
    checks.
  * Certified truncation bounds: --nc and --vop-nc are now STARTING guesses
    of refine-until-bound loops.  sec219: every Clenshaw-Curtis integration
    carries a trailing-window (TAIL_WINDOW=8) Chebyshev tail bound measured
    in a certification pass at dps+CERT_PAD (same NC, same recursion; the pad
    pushes the coefficient noise floor below the true tail); the
    per-integration bounds are propagated through the layer recursion by the
    L1 path norms of the exact kernels and printed as value-level "[BOUND]"
    lines.  sec255: a posteriori trailing-window tail bounds on the Tier-2
    top-sector solution tables.  Both loops: if the bound misses
    10^-(min(dps, SEED_CAP_219 / CERT_CAP_255)+TAIL_GUARD) the SAME recursion
    is re-run at ceil(1.5*NC), up to NC_CAP_MULT*N0, then RuntimeError
    (fail-closed; no value is printed that its loop did not certify).
    Default runs are calibrated to never escalate.
  The stored boundary-seed strings still cap ENDPOINT agreement as disclosed
  above, and CERT_CAP_255 is additionally pinned by the measured spectral
  resolution of the shipped --vop-nc=220 contour (see its comment) -- the
  caps bound only the certification TARGET.  Output format and all
  pre-existing printed values at default settings are unchanged; the new
  lines are prefixed "[BOUND]".
"""
import argparse, json, os, sys, time
import mpmath as mp
import sympy as sp

_ap = argparse.ArgumentParser(description="hexabox final-form evaluator; see module docstring "
                                          "for the interface, domain and stored-string caps")
_ap.add_argument('--dps', type=int, default=90, help="working precision, decimal digits (default 90)")
_ap.add_argument('--nc', type=int, default=int(os.environ.get("HEXABOX_NC", "80")),
                 help="sec219 spectral order per contour segment (default 80)")
_ap.add_argument('--vop-nc', type=int, default=None,
                 help="sec255 spectral order per contour segment (default 220; "
                      "env HEXABOX_VOP_NC; --point --sec 255 at --dps < 45 "
                      "auto-selects the measured per-target fast floor, see "
                      "FAST MODE in the docstring)")
_ap.add_argument('--point', type=str, default=None,
                 help="evaluate at a path point: t (e.g. 0.7) or s45=..,s15=..,mm=.. on the path")
_ap.add_argument('--sec', choices=['219', '255', 'both'], default='219',
                 help="which final-form family --point evaluates (default 219)")
_ap.add_argument('--dps-double', action='store_true',
                 help="rerun the sec219 verification point at 2x dps: identity digits grow live; "
                      "oracle agreement hits the stored-string caps (printed)")
_ap.add_argument('--record-point', type=str, default=None, metavar='P2',
                 help="RECORD-PAIR tier: re-compare the two vendored AMFlow outputs of record at the second "
                      "point P2 (strings only, seconds; see RECORD PAIR in the docstring); any other value "
                      "is refused (exit 2)")
_ap.add_argument('--mutate-record', action='store_true',
                 help="control for --record-point: one digit of a vendored output is changed IN MEMORY, "
                      "the component-wise gate must FAIL by name (exit 1)")
_ap.add_argument('--kmax', type=int, default=3, metavar='K',
                 help="last layer of the sec255 recursion (default 3 = eps^0 of the top sector, the served "
                      "run); K < 3 refused (exit 2); K = 4 / 5 runs the recursion to eps^1 / eps^2 of the top "
                      "sector and GATES those orders against the served 60-digit strings and the two vendored "
                      "oracle records, bar 30 d (see EPS^1, EPS^2 SUCCESSION in the docstring); a bundle whose "
                      "layers or seeds are short of the reach is REFUSED by name (exit 1) -- see REACH CHECK")
_ap.add_argument('--mutate-eps12', action='store_true',
                 help="control for --kmax 4 / 5: one digit of the served eps^1 string of master 0 is changed IN "
                      "MEMORY, the served-string comparator must FAIL by name (exit 1) while the oracle comparators pass")
_ap.add_argument('--boundary-regenerate', action='store_true',
                 help="sec255 recursion on REGENERATED inputs: the 447 from-definition fit-point seeds of "
                      "vendor_row24_seeds/ in place of the 70-digit strings, the bundle's exact (97,0,2..4) layers asserted "
                      "equal to the object of vendor_row24_kernels/ (see BOUNDARY REGENERATE in the docstring; "
                      "the true input cap of the run is printed there); "
                      "combines with --kmax 4 / 5; refused (exit 2) with --record-point / --point / --dps-double / --gatepoint")
_ap.add_argument('--regen-dir', default=None, metavar='DIR',
                 help="with --boundary-regenerate: the directory the regenerated bundle is written to for the engine's "
                      "loader (default ./hexabox_regen_<stamp>/ under the working directory); this tool removes nothing, "
                      "the caller owns the directory; refused (exit 2) without --boundary-regenerate")
_ap.add_argument('--gatepoint', action='store_true',
                 help="GATE-POINT tier: the two-precision floors of all 98 masters at the verification point, recomputed "
                      "from the vendored pair strings (vendor_row24_gatepoint/) and read against the PAIR v2 keys "
                      "(strings only, seconds; see GATE POINT in the docstring); refused (exit 2) with any other tier")
_ap.add_argument('--mutate-gatepoint', action='store_true',
                 help="control for --gatepoint: one digit of a goal-60 string is changed IN MEMORY, the floor must FAIL by name (exit 1)")
ARGS, _unk = _ap.parse_known_args()
if ARGS.gatepoint and (ARGS.boundary_regenerate or ARGS.record_point is not None or ARGS.point is not None
                       or ARGS.dps_double or ARGS.kmax != 3 or ARGS.mutate_eps12 or ARGS.mutate_record):
    print("--gatepoint: REFUSED -- it is a strings-only tier of its own and does not combine with --boundary-regenerate, "
          "--record-point, --point, --dps-double, --kmax, --mutate-eps12 or --mutate-record")
    sys.exit(2)
if ARGS.mutate_gatepoint and not ARGS.gatepoint:
    print("--mutate-gatepoint: REFUSED -- it is the control of the gate-point tier and needs --gatepoint")
    sys.exit(2)
if ARGS.boundary_regenerate and (ARGS.record_point is not None or ARGS.point is not None or ARGS.dps_double):
    print("--boundary-regenerate: REFUSED -- it regenerates the inputs of the sec255 recursion of the default check demo "
          "(with --kmax 4 / 5 the eps^1, eps^2 gate); it does not combine with --record-point, --point or --dps-double")
    sys.exit(2)
if ARGS.regen_dir is not None and not ARGS.boundary_regenerate:
    print("--regen-dir: REFUSED -- it names the directory of the regenerated bundle and needs --boundary-regenerate")
    sys.exit(2)
if ARGS.kmax < 3:
    print(f"--kmax {ARGS.kmax}: REFUSED -- the served digits need the sec255 layers through 3 (eps^0 of the "
          f"top sector); pass --kmax 3 (the default) or higher")
    sys.exit(2)
if ARGS.kmax != 3 and (ARGS.record_point is not None
                       or (ARGS.point is not None and ARGS.sec == '219')):
    print(f"--kmax {ARGS.kmax}: REFUSED -- no sec255 layer recursion runs in this tier (--record-point, "
          f"--point --sec 219); the knob applies to the default check demo, to --point --sec 255 / both and, "
          f"for K > 3, to --dps-double (the two-precision pair of the eps^1, eps^2 gate)")
    sys.exit(2)
if ARGS.mutate_eps12 and ARGS.kmax < 4:
    print("--mutate-eps12: REFUSED -- it is the control of the eps^1, eps^2 gate and needs --kmax 4 or 5")
    sys.exit(2)

# ============================================================================
# RECORD PAIR at the second point P2 (--record-point P2): dispatched HERE, before any
# final-form machinery is built, and exits.  Strings only: the two vendored AMFlow
# outputs of record are re-compared; nothing is computed from the final forms (the
# six-scale function is open, so the served forms cannot reach P2).
# ============================================================================
RECORD_P2 = {  # script-emitted from the receipt of record and the vendored bytes (build_script.py); nothing typed
    'point': {'s12': '-5', 's23': '-7', 's34': '-11', 's45': '-13', 's15': '-19', 'mm': '3'},
    'family': 'hexaboxP3P4',
    'first_point': '(-3,-5,-7,-11,-17,2)',
    'fixtures': {
        'record_P2/out_goal40.json': 'f292d9193dcb94105be12ea4408880d2331c8bda770a92bd8232dc91f24c68af',
        'record_P2/out_goal50.json': '28ad93f9a914f3600fa7116d5f1708c33811ce69767b8652b711d6279b0f0020',
    },
    'module': {'hexabox_record_pair.py': 'b0d5747b30543d5e483e06b0c406808437c315e76d1cc954b1fafb8f9560709d'},
    'bar': 56,                     # = floor of the record's component-wise minimum 56.65
    'zero_floor': '1e-40',        # structural zero: |value| <= this on either side, named and not counted
    'tool_min_digits': 30.0,       # the reproducing command's --min-digits
    'record': {                    # the record's figures, printed beside the recomputed ones and asserted equal (two decimals)
        'per_order_complex_relative_min': {'-4': 93.62, '-3': 84.38, '-2': 75.37, '-1': 66.45, '0': 57.14},
        'component_min': {'master': 1, 'order': 0, 'part': 'im', 'rel_digits': 56.65},
        'n_components': 30, 'n_significant': 27,
    },
    'labels': [
        'the three top-sector masters of hexaboxP3P4 at P2 through eps^0: two AMFlow precisions (goal 40, goal 50) agreeing -- digits = the two-precision agreement',
        'no independent record at P2 (none exists; the second arm never reached the DE)',
        'eps^1, eps^2 at P2 not run',
        'the six-scale function is open: a second point is the gate the program asked for, not the function; the served final forms live on the one-parameter path and cannot compute P2',
        'the reduction ran at N = 33 prime fields at P2 vs 31 at the first point (taller coefficients)',
        'the runs\' own Arb radii read ~110 digits and are NOT a certification; digits = the two-precision agreement',
    ],
}

def run_record_point(tag):
    import hashlib
    here = os.path.dirname(os.path.abspath(__file__))
    if tag != 'P2':
        print(f"--record-point {tag!r}: REFUSED -- the only record pair shipped is P2 "
              f"(pass --record-point P2); no other point carries a vendored pair")
        sys.exit(2)
    if ARGS.point is not None or ARGS.dps_double:
        print("--record-point P2: REFUSED -- it does not combine with --point / --dps-double "
              "(the record pair is strings only; run the tiers separately)")
        sys.exit(2)
    R = RECORD_P2
    pt = R['point']
    print(f"== RECORD PAIR at the second point P2 = (s12,s23,s34,s45,s15,mm) = "
          f"({pt['s12']},{pt['s23']},{pt['s34']},{pt['s45']},{pt['s15']},{pt['mm']}): "
          f"the three top-sector masters of {R['family']} through eps^0, AMFlow goal 40 vs goal 50 ==")
    print("   nothing is computed from the final forms here: the six-scale function is open; the two")
    print("   vendored outputs are the record objects and this tier re-runs the record's comparison on them")
    # pins first: a missing file -> exit 4, a mismatch -> exit 3, before anything is read as data
    for rel, want in list(R['fixtures'].items()) + list(R['module'].items()):
        path = os.path.join(here, rel)
        if not os.path.exists(path):
            print(f"   PIN MISSING: {rel} is not beside this script -> exit 4")
            sys.exit(4)
        got = hashlib.sha256(open(path, 'rb').read()).hexdigest()
        if got != want:
            print(f"   PIN MISMATCH: {rel} sha256 {got[:16]}... != pinned {want[:16]}... -> exit 3")
            sys.exit(3)
        print(f"   pin OK: {rel} sha256 {want[:16]}...")
    sys.path.insert(0, here)
    import hexabox_record_pair as RP
    doc40 = json.load(open(os.path.join(here, 'record_P2/out_goal40.json')))
    doc50 = json.load(open(os.path.join(here, 'record_P2/out_goal50.json')))
    for d in (doc40, doc50):
        assert d['mode'] == 'solve_integrals' and len(d['result']) == 3, "unexpected record form"
        assert all(e['integral']['family'] == R['family'] for e in d['result'])
    if ARGS.mutate_record:
        cm = R['record']['component_min']
        old, new, pos = RP.plant_digit(doc50, cm['master'], cm['order'], cm['part'], 20)
        print(f"   MUTATION (--mutate-record): goal-50 master {cm['master']} eps^{cm['order']:+d} {cm['part']}, "
              f"decimal digit 20 (string position {pos}) changed {old!r} -> {new!r} IN MEMORY; the files are untouched")
    T = RP.pair_table(doc40, doc50, zero_floor=R['zero_floor'], min_digits=R['tool_min_digits'])
    print(f"   component-wise table (relative matched digits per re/im component; the reproducing command's rule; "
          f"working precision {RP.RECORD_DPS} digits):")
    for r in T['rows']:
        lab = f"m{r['master']}_eps{r['order']:+d} {r['part']:<2s}"
        s40 = (r['ref_str'][:27] + '..') if len(r['ref_str']) > 29 else r['ref_str']
        s50 = (r['test_str'][:27] + '..') if len(r['test_str']) > 29 else r['test_str']
        if r['significant']:
            print(f"   {lab}: goal-40 {s40:<30s} goal-50 {s50:<30s} agree {r['rel_digits']:6.2f} d")
        else:
            print(f"   {lab}: goal-40 {s40:<30s} goal-50 {s50:<30s} structural zero "
                  f"(|value| <= {R['zero_floor']} on either side; named, not counted)")
    zs = ", ".join(f"m{i}_eps{o:+d} {p}" for i, o, p in T['structural_zeros'])
    print(f"   components {T['n_components']}, significant {T['n_significant']}, structural zeros "
          f"{len(T['structural_zeros'])} ({zs})")
    print(f"   the reproducing command at --min-digits {R['tool_min_digits']:g} over all {T['n_components']} components: "
          f"{T['tool']['pass']} PASS / {T['tool']['fail']} FAIL, OVERALL {T['tool']['overall']} "
          f"(its FAILs are the structural zeros, 0.0 d by its zero-vs-nonzero rule; the basis of record is the "
          f"component-wise table over the {T['n_significant']} significant components)")
    print("   per-order minima, complex-relative (min over the three masters of log10(max|a|,|b| / |a-b|)):")
    rec_po = R['record']['per_order_complex_relative_min']
    ok_rec = True
    for o in sorted(T['per_order']):
        got = round(T['per_order'][o], 2)
        want = rec_po[str(o)]
        same = (got == want)
        ok_rec = ok_rec and same
        print(f"      eps^{o:+d}: {got:6.2f} d   record {want:6.2f} d   {'==' if same else 'DIFFERS'}")
    mn = T['min']
    cm = R['record']['component_min']
    got_min = round(mn['rel_digits'], 2)
    same_min = (got_min == cm['rel_digits'] and mn['master'] == cm['master'] and mn['order'] == cm['order']
                and mn['part'] == cm['part'])
    ok_rec = ok_rec and same_min and T['n_components'] == R['record']['n_components'] \
             and T['n_significant'] == R['record']['n_significant']
    print(f"   component-wise minimum: {got_min:.2f} d at master {mn['master']}, eps^{mn['order']:+d}, {mn['part']} "
          f"(record {cm['rel_digits']} at master {cm['master']}, eps^{cm['order']:+d}, {cm['part']}: "
          f"{'==' if same_min else 'DIFFERS'})")
    gate = got_min >= R['bar']
    print(f"   RECORD-PAIR GATE: component-wise minimum {got_min:.2f} d vs bar {R['bar']} d (the floor of the "
          f"record's {cm['rel_digits']}): {'PASS' if gate else 'FAIL'}")
    print(f"   RECORD MATCH (recomputed figures == the record's to two decimals, counts included): "
          f"{'PASS' if ok_rec else 'FAIL'}")
    print("   labels:")
    for l in R['labels']:
        print(f"      - {l}")
    if not gate:
        print(f"RECORD-PAIR FAIL by name: the component-wise minimum {got_min:.2f} d is below the bar {R['bar']} d"
              + (" (the planted digit of --mutate-record)" if ARGS.mutate_record else ""))
        sys.exit(1)
    if not ok_rec:
        print("RECORD-PAIR FAIL by name: a recomputed figure differs from the record's")
        sys.exit(1)
    print(f"Record pair at P2: PASS (the {T['n_significant']} significant components agree to >= {got_min:.2f} d; "
          f"two precisions of one program, not an independent record).")
    sys.exit(0)

if ARGS.mutate_record and ARGS.record_point is None:
    print("--mutate-record: REFUSED -- it is the control of --record-point P2 and needs it")
    sys.exit(2)
if ARGS.record_point is not None:
    run_record_point(ARGS.record_point)

# --vop-nc resolution (FAST MODE): explicit flag >
# env HEXABOX_VOP_NC > per-target floor. The deep default stays 220. For the
# --point --sec 255 route with a requested target --dps < 45 the floor is the
# MEASURED minimum NC that (i) certifies the trailing-window tail bound at
# tol 10^-(min(dps,36)+10) without escalation and (ii) clears the scaled pass
# bar min(45, dps) with the strict-greater slack — calibrated 2026-07-07 (see
# sec255 FAST MODE in the docstring).
VOP_NC_FAST_FLOOR = {30: 180}  # target dps -> measured NC floor (2026-07-07:
#   NC=160 tail bound 2.49e-38 >= tol 1e-40 at dps 30 -> escalates; NC=180
#   certifies without escalation. The floor is CERTIFICATION-limited (the
#   scaled pass bar clears with wide margin at the floor).
if ARGS.vop_nc is None:
    _env = os.environ.get("HEXABOX_VOP_NC")
    if _env is not None:
        ARGS.vop_nc = int(_env)
    elif (ARGS.point is not None and ARGS.sec in ('255', 'both')
          and ARGS.dps < 45):
        _cal = sorted(k for k in VOP_NC_FAST_FLOOR if k >= ARGS.dps)
        ARGS.vop_nc = VOP_NC_FAST_FLOOR[_cal[0]] if _cal else 220
        print(f"[fast-mode] --point --sec 255 at --dps {ARGS.dps} < 45: "
              f"--vop-nc auto-set to the measured floor {ARGS.vop_nc} "
              f"(calibrated at target {_cal[0] if _cal else 'deep'}; the pass bar "
              f"scales to min(45, dps) = {min(45, ARGS.dps)} d; pass "
              f"--vop-nc explicitly to override)")
    else:
        ARGS.vop_nc = 220

mp.mp.dps = ARGS.dps  # set BEFORE any mpf (import-dps footgun); default 90 = the default check demo
T_START = time.time()

# ── 2026-07-05: precision-tracking + certified-bound constants ──
# BUG FIX: the sec255 routes (Check 2 / Check 3a / --point --sec 255) previously ran at a
# HARDCODED mp.mp.dps = 80, silently overriding --dps.  They now run at ENG_DPS, which
# tracks the caller's --dps with a working-precision pad; the floor 80 (the seed-naming
# precision) only ever ADDS precision and keeps the fixed seed-string classification
# tolerances (1e-52..1e-72, matched to the 65-70 digit seed strings) valid at low --dps.
TAIL_WINDOW = 8    # trailing-window width of the certified spectral tail bounds
TAIL_GUARD  = 10   # guard digits on the truncation tolerance (range 8-12)
CERT_PAD    = 25   # sec219 certification pass runs at dps+CERT_PAD: pushes the Chebyshev-
                   # coefficient arithmetic noise floor ~10^CERT_PAD below the value pass,
                   # so the measured trailing tail is the TRUE truncation tail
ENG_GUARD   = 25   # sec255 engine working-precision pad over --dps (same role as CERT_PAD)
ENG_DPS     = max(ARGS.dps + ENG_GUARD, 80)
NC_CAP_MULT = 8    # refine-until-bound escalation cap: NC may grow to NC_CAP_MULT * N0
# INTERIM certification-target caps (they cap only the CERTIFICATION TARGET, never the
# computation):
SEED_CAP_219 = 50  # sec219 fit-point boundary seeds rows 1-13 = 50-digit strings
CERT_CAP_255 = 36  # sec255 target cap = MEASURED spectral resolution of the shipped
                   # --vop-nc=220 contour: worst top-sector table tail bound 1.75e-53
                   # (row 97 = the hybrid-kernel row, eps^0 layer, detour segment;
                   # measured 2026-07-05 at ENG_DPS=115).  Target sits 10^6 above the
                   # measurement so default runs NEVER escalate;
                   # the independent comparison RAISES at >=45 d (measures ~56.5 d
                   # at NC=220 — endpoint error is ~3 digits better than the per-segment
                   # table bound).  Measured refinement rate ~0.16 d/NC near NC~300
                   # (NC=330 gives worst bound 6.4e-71, ~67-69 d): to go deeper,
                   # lift this cap and recalibrate the default --vop-nc accordingly.

def _ttol(cap, dps_req):
    """truncation tolerance 10^-(min(dps,cap)+guard): tracks --dps up to the disclosed
    INTERIM seed-string cap (beyond it the stored strings, not the truncation, limit)."""
    return mp.mpf(10)**(-(min(dps_req, cap) + TAIL_GUARD))

def _tail_geom(tail, prev):
    """Trailing-window geometric tail bound: tail * r/(1-r), with the per-coefficient
    ratio r measured from the last two TAIL_WINDOW-blocks of the Chebyshev spectrum and
    clipped to [1/4, 3/4] (r>=3/4, i.e. poor decay, gives the conservative factor 3 and
    fails the tolerance test => the refine loop escalates NC)."""
    if tail == 0:
        return mp.mpf(0)
    if prev > 0 and tail < prev:
        r = (tail/prev)**(mp.mpf(1)/TAIL_WINDOW)
    else:
        r = mp.mpf(1)
    r = min(max(r, mp.mpf(1)/4), mp.mpf(3)/4)
    return tail*r/(1-r)

STAGE_DIR = os.path.dirname(os.path.abspath(__file__))  # flipped: live blog dir
HERE = os.path.dirname(os.path.abspath(__file__))  # flipped: own dir
sys.path.insert(0, STAGE_DIR)
sys.path.insert(0, HERE)
DATA = json.load(open(os.path.join(HERE, "hexabox-data.json")))

def digits(p, r):
    """(absolute, relative) matched digits between complex pred and oracle."""
    if p == r:
        return float(mp.mp.dps), float(mp.mp.dps)
    delta = abs(p - r)
    return float(-mp.log10(delta + mp.mpf('1e-300'))), \
           float(-mp.log10(delta / abs(r) + mp.mpf('1e-300')))

def mpc_of(pair):
    return mp.mpc(mp.mpf(pair[0]), mp.mpf(pair[1]))

def pmc(s):
    """parse '(a + bj)' / '(a - bj)' strings."""
    s = s.strip().strip('()')
    for cut in range(1, len(s)):
        if s[cut] in '+-' and s[cut-1] in ' e0123456789.' and s[cut-1] != 'e':
            if s[cut-1] == ' ':
                a, b = s[:cut].strip(), s[cut:].replace(' ', '').rstrip('j')
                return mp.mpc(mp.mpf(a), mp.mpf(b))
    return mp.mpc(mp.mpf(s.rstrip('j')), 0)

# ============================================================================
# Check 1 -- sec219: live eps-form VoP transport, fit point -> verification point.
# The eps-form transport of this work; data =
# DE-derived rational eps-form (hexabox-data.json sec219 block).
# ============================================================================
FAM   = DATA["family"]
VARS  = FAM["VARS"]
SY    = {v: sp.Symbol(v) for v in VARS}
tt, eps = sp.Symbol('x'), sp.Symbol('eps')
PFIT, GATE = FAM["Pfit"], FAM["gate"]
SUN, P5, N219 = list(range(1, 8)), list(range(8, 14)), 14

# path: straight segment, fit point -> verification point, in the 6 kinematic invariants
path_sub = {SY[v]: sp.Rational(PFIT[v]) + tt*(GATE[v] - PFIT[v]) for v in VARS}
G5_expr  = sp.sympify(FAM["G5"], locals=SY)          # Gram5 (alphabet radical)
G5p      = sp.expand(G5_expr.subs(path_sub))
P2Je     = {j: sp.sympify(FAM["P2J"][str(j)], locals=SY) for j in SUN}
p2p      = {j: sp.expand(P2Je[j].subs(path_sub)) for j in SUN}

S219 = DATA["sec219"]
loc  = {'x': tt, 'eps': eps}
def _sy(s):                         # the data strings use '//' for division
    return sp.sympify(s.replace('//', '/').replace('^', '**'), locals=loc)
gfun, hfun = {}, {}
for j in SUN:                       # T_13[SUN_j] = 1/(eps*g_j(x))
    gfun[j] = sp.cancel(1/sp.cancel(_sy(S219["T13_diag"][j-1])*eps))
for k in P5:                        # T_13[5p_k] = h_k(x)
    hfun[k] = _sy(S219["T13_diag"][k-1])
Atil = {}
for key, s in S219["Atilde"].items():
    i, j = (int(u) for u in key.split(','))
    Atil[(i, j)] = _sy(s)
A0 = {l: _sy(S219["A0"][str(l)]) for l in range(N219)}

A00_e0 = sp.cancel(A0[0].subs(eps, 0))
A00_e1 = sp.cancel((A0[0] - A00_e0)/eps)
B0_rat = {0: A00_e1}
for j in SUN: B0_rat[j] = sp.cancel(A0[j].subs(eps, 0)*gfun[j])
for k in P5:  B0_rat[k] = sp.cancel(sp.cancel(sp.together(A0[k])/eps)/hfun[k])

LAM = {
    'G5': sp.lambdify(tt, G5p, 'mpmath'),
    'g':  {j: sp.lambdify(tt, gfun[j], 'mpmath') for j in SUN},
    'h':  {k: sp.lambdify(tt, hfun[k], 'mpmath') for k in P5},
    'p2': {j: sp.lambdify(tt, p2p[j], 'mpmath') for j in SUN},
    'At': {ij: sp.lambdify(tt, e, 'mpmath') for ij, e in Atil.items()},
    'B0': {l: sp.lambdify(tt, e, 'mpmath') for l, e in B0_rat.items()},
}
# f(eps) = (d-3)(3d-10)(3d-8)/(d-4)^2 at d=4-2eps, exact Laurent coefficients
ds = sp.Symbol('d')
fL = sp.series(sp.cancel(((ds-3)*(3*ds-10)*(3*ds-8)/(ds-4)**2).subs(ds, 4-2*eps)),
               eps, 0, 14).removeO()
# analytic 2L sunrise normalization: eps*c(eps), regular at 0 (Taylor at runtime)
def _epsC(e):
    return -mp.gamma(1-e)**3 * mp.gamma(1+2*e) / (2*(2*e-1)*mp.gamma(3-3*e))

def _build_eps_consts():
    """(Re)build every dps-dependent numeric constant at the CURRENT mp.mp.dps.
    Called once at import and again by --dps-double after doubling dps: all of
    these are exact rationals / Gamma-Taylor coefficients, nothing bottoms out
    in stored floats (the lambdified path functions evaluate their exact
    rationals at call-time dps as well)."""
    global G5_0, G5_1, fcoef, ccoef, KCOEF
    G5_0 = mp.mpf(int(G5p.subs(tt, 0)))
    G5_1 = mp.mpf(int(G5p.subs(tt, 1)))
    fcoef = {p: mp.mpf(sp.Rational(fL.coeff(eps, p)).p)/mp.mpf(sp.Rational(fL.coeff(eps, p)).q)
             for p in range(-2, 12)}
    _cT = mp.taylor(_epsC, 0, 16)
    ccoef = {k: _cT[k+1] for k in range(-1, 16)}
    KCOEF = {}                      # K(eps) = (1/eps) f(eps) c(eps), orders -4..8
    for n in range(-4, 9):
        KCOEF[n] = sum(fcoef[p]*ccoef[n+1-p] for p in fcoef if (n+1-p) in ccoef)
_build_eps_consts()

def mcan_SUN(j, tval, n_range):
    """m_can[SUN_j][eps^n](t): analytic closed form, ANY complex t."""
    p2 = mp.mpc(LAM['p2'][j](tval))
    gj = mp.mpc(LAM['g'][j](tval))
    L  = mp.log(-p2) if (p2.imag != 0 or p2.real < 0) else (mp.log(p2) - mp.mpc(0, 1)*mp.pi)
    pre = (-p2)/gj
    return {n: pre*sum(KCOEF[m]*(-2*L)**(n-m)/mp.factorial(n-m) for m in range(-4, n+1))
            for n in n_range}

def cheb_segment(a, b, NC):
    """Chebyshev-Lobatto nodes + Clenshaw-Curtis cumulative integration on [a,b].
    2026-07-05: cumint additionally returns the certified trailing-window
    tail bound of the integrand's Chebyshev spectrum on this segment,
    |half| * max(|c_j|, last TAIL_WINDOW) * r/(1-r); ctail exposes the same trailing-
    window measurement for solution node tables."""
    half, mid = (b-a)/2, (a+b)/2
    th    = [mp.pi*k/NC for k in range(NC+1)]
    nodes = [mid - half*mp.cos(t) for t in th]
    cosk  = [[((-1)**j)*mp.cos(j*t) for j in range(NC+1)] for t in th]
    def coeffs(f):
        c = []
        for j in range(NC+1):
            s = sum((mp.mpf(1) if 0 < k < NC else mp.mpf('0.5'))*f[k]*cosk[k][j]
                    for k in range(NC+1))
            cj = 2*s/NC
            if j == 0 or j == NC: cj /= 2
            c.append(cj)
        return c
    def _tails(c):
        m = [abs(x) for x in c[max(0, NC+1-2*TAIL_WINDOW):]]
        if len(m) <= TAIL_WINDOW:
            return max(m), max(m)
        return max(m[-TAIL_WINDOW:]), max(m[:-TAIL_WINDOW])
    def ctail(f):
        tail, prev = _tails(coeffs(f))
        return _tail_geom(tail, prev)
    def cumint(f):
        c = coeffs(f)
        tail, prev = _tails(c)
        qb = abs(half)*_tail_geom(tail, prev)
        C = [mp.mpc(0)]*(NC+2)
        C[1] = c[0] - (c[2] if NC >= 2 else mp.mpc(0))/2
        for j in range(2, NC+2):
            cm = c[j-1] if j-1 <= NC else mp.mpc(0)
            cp = c[j+1] if j+1 <= NC else mp.mpc(0)
            C[j] = (cm - cp)/(2*j)
        C[0] = -sum(C[j]*((-1)**j) for j in range(1, NC+2))
        Fu = [sum(C[j]*cosk[k][j] for j in range(NC+1)) for k in range(NC+1)]
        Ft = [half*v for v in Fu]
        Ft[-1] += half*C[NC+1]
        return Ft, half*sum(C[j] for j in range(NC+2)), qb
    return nodes, cumint, ctail

def _transport_219_run(NC, ledger=False):
    """One pass of the eps-form transport, t=0 (fit point) -> t=1 (verification point), at
    spectral order NC and the CURRENT mp.mp.dps.  ledger=True additionally accumulates
    the certified per-integration trailing-window tail bounds through the layer
    recursion, propagated by the L1 path norms of the exact kernels:
    E5[k][n], E0[n] are ABSOLUTE bounds on the truncation error of mc5/mc0."""
    # complex rectangle around the single real path pole t=2/5 (the contour used throughout)
    ct = [(mp.mpf(0),      mp.mpf('0.15')),
          (mp.mpf('0.15'), mp.mpf('0.35')),
          (mp.mpf('0.35'), mp.mpc('0.35', '0.1')),
          (mp.mpc('0.35', '0.1'), mp.mpc('0.45', '0.1')),
          (mp.mpc('0.45', '0.1'), mp.mpf('0.45')),
          (mp.mpf('0.45'), mp.mpf('0.7')),
          (mp.mpf('0.7'),  mp.mpf(1))]
    segs = [cheb_segment(mp.mpc(a), mp.mpc(b), NC) for a, b in ct]
    all_nodes = [t for nodes, _, _ in segs for t in nodes]
    NT = len(all_nodes)

    sqG5 = [mp.sqrt(LAM['G5'](t)/G5_0) for t in all_nodes]
    B0v  = {l: [LAM['B0'][l](t) for t in all_nodes] for l in range(N219)}
    Atv  = {ij: [LAM['At'][ij](t) for t in all_nodes] for ij in Atil}

    nSUN = list(range(-4, 2))
    mcS = {j: {n: [None]*NT for n in nSUN} for j in SUN}
    for it, t in enumerate(all_nodes):
        for j in SUN:
            v = mcan_SUN(j, t, nSUN)
            for n in nSUN: mcS[j][n][it] = v[n]

    def cumint_path(integrand):
        F = [mp.mpc(0)]*NT; off = mp.mpc(0); idx = 0; qb = mp.mpf(0)
        for nodes, cum, _ in segs:
            np_ = len(nodes)
            Fseg, Fb, qseg = cum(integrand[idx:idx+np_])
            for kk in range(np_): F[idx+kk] = off + Fseg[kk]
            off += Fb; idx += np_; qb += qseg
        return F, off, qb

    BND = S219["boundary_Pfit"]     # FIT-INPUT seed (fit-point AMFlow values)
    row0_b = {int(k): mpc_of(v) for k, v in BND["row0"].items() if not k.startswith('_')}
    rows_b = {k: {int(o): mpc_of(v) for o, v in BND[f"row{k}"].items()} for k in range(8, 14)}
    h0 = {k: mp.mpc(LAM['h'][k](mp.mpf(0))) for k in P5}

    # eps^-3 vanishing identities (structural certificate of the eps-form)
    van = []
    for r in [0] + P5:
        integ = [mp.mpc(0)]*NT
        for j in SUN:
            if r == 0:
                for it in range(NT): integ[it] += sqG5[it]*B0v[j][it]*mcS[j][-4][it]
            elif (r, j) in Atv:
                for it in range(NT): integ[it] += Atv[(r, j)][it]*mcS[j][-4][it]
        van.append(float(-mp.log10(max(abs(x) for x in integ) + mp.mpf(10)**(-mp.mp.dps))))

    # certified-bound ledger: L1 path norms of the exact kernels propagate the
    # per-integration trailing-window tail bounds through the layers.  SUN sources are
    # analytic closed forms (no truncation); boundary seeds are data, not truncation.
    E5 = {k: {-3: mp.mpf(0)} for k in P5}
    E0 = {-3: mp.mpf(0)}
    if ledger:
        def _l1(vals):
            tot = mp.mpf(0); idx = 0
            for nodes, cum, _ in segs:
                np_ = len(nodes)
                _, s_tot, _ = cum([mp.mpc(abs(v)) for v in vals[idx:idx+np_]])
                tot += abs(s_tot); idx += np_
            return tot
        L1_55 = {k: (_l1(Atv[(k, k)]) if (k, k) in Atv else mp.mpf(0)) for k in P5}
        L1_00 = _l1(B0v[0])
        L1_0k = {k: _l1([sqG5[it]*B0v[k][it] for it in range(NT)]) for k in P5}

    # 5p rows, VoP layer recursion n = -2..1
    mc5 = {k: {-3: [mp.mpc(0)]*NT} for k in P5}
    for n in range(-2, 2):
        for k in P5:
            integ = [mp.mpc(0)]*NT
            if (k, k) in Atv:
                prev = mc5[k].get(n-1, [mp.mpc(0)]*NT)
                for it in range(NT): integ[it] += Atv[(k, k)][it]*prev[it]
            for j in SUN:
                if (k, j) in Atv:
                    for it in range(NT): integ[it] += Atv[(k, j)][it]*mcS[j][n-1][it]
            F, _, qb = cumint_path(integ)
            bnd = h0[k]*rows_b[k].get(n, mp.mpc(0))
            mc5[k][n] = [bnd + F[it] for it in range(NT)]
            if ledger:
                E5[k][n] = qb + L1_55[k]*E5[k].get(n-1, mp.mpf(0))

    # row 0, VoP layer recursion n = -2..2  (m_can[0] = sqrt(G5/G5_0)*m_raw[0])
    mc0 = {-3: [mp.mpc(0)]*NT}
    for n in range(-2, 3):
        integ = [mp.mpc(0)]*NT
        prev0 = mc0.get(n-1, [mp.mpc(0)]*NT)
        for it in range(NT):
            s = B0v[0][it]*prev0[it]
            for j in SUN: s += sqG5[it]*B0v[j][it]*mcS[j][n-1][it]
            for k in P5:  s += sqG5[it]*B0v[k][it]*mc5[k].get(n-1, [mp.mpc(0)]*NT)[it]
            integ[it] = s
        F, _, qb = cumint_path(integ)
        mc0[n] = [row0_b.get(n, mp.mpc(0)) + F[it] for it in range(NT)]
        if ledger:
            E0[n] = qb + L1_00*E0.get(n-1, mp.mpf(0)) \
                    + sum(L1_0k[k]*E5[k].get(n-1, mp.mpf(0)) for k in P5)

    T00_1 = mp.sqrt(G5_1/G5_0)
    pred  = {n: mc0[n][-1]/T00_1 for n in range(-2, 3)}
    # interior kinematic point: last node of segment 2 is t=0.35 (real axis)
    it_int = 2*(NC+1) - 1
    t_int  = all_nodes[it_int]
    T00_i  = mp.sqrt(mp.mpc(LAM['G5'](t_int))/G5_0)
    interior = (t_int, {n: mc0[n][it_int]/T00_i for n in range(-2, 3)})

    # arbitrary-point evaluator: spectral barycentric interpolation of the
    # transported node tables on the segment containing t (analytic integrand
    # => spectrally accurate; precision grows with NC and dps).
    uch = [(1 - mp.cos(mp.pi*k/NC))/2 for k in range(NC+1)]
    def evalrow0(tq):
        """Row-0 raw-master Laurent coefficients {n: m219_row0[eps^n](tq)} at
        any real path point tq in [0,0.35] U [0.45,1] (docstring DOMAIN)."""
        tq = mp.mpf(tq)
        si = None
        for s2, (a, b) in enumerate(ct):
            if mp.im(mp.mpc(a)) == 0 and mp.im(mp.mpc(b)) == 0 and \
               mp.re(mp.mpc(a)) - mp.mpf('1e-12') <= tq <= mp.re(mp.mpc(b)) + mp.mpf('1e-12'):
                si, a0, b0 = s2, mp.re(mp.mpc(a)), mp.re(mp.mpc(b))
                break
        if si is None:
            raise ValueError(
                f"t={mp.nstr(tq, 12)} is off the real contour: sec219 domain is "
                "[0,0.35] U [0.45,1] (the open window (0.35,0.45) is bypassed by "
                "the complex detour around the path pole t=2/5)")
        u = (tq - a0)/(b0 - a0)
        def bary(vals):
            num = mp.mpc(0); den = mp.mpc(0)
            for k in range(NC+1):
                d = u - uch[k]
                if abs(d) < mp.mpf(10)**(-mp.mp.dps): return vals[k]
                w = (-1)**k*(mp.mpf(1)/2 if k in (0, NC) else mp.mpf(1))/d
                num += w*vals[k]; den += w
            return num/den
        base = si*(NC+1)
        T00 = mp.sqrt(mp.mpc(LAM['G5'](tq))/G5_0)
        vals = {n: bary(mc0[n][base:base+NC+1])/T00 for n in range(-2, 3)}
        # per-order representation tail of the transported table on this segment
        # (trailing-window bound of the SOLUTION spectrum; interpolation is spectral)
        repb = {n: segs[si][2](mc0[n][base:base+NC+1])/abs(T00) for n in range(-2, 3)}
        return vals, repb
    cb = {n: E0[n]/abs(T00_1) for n in range(-2, 3)} if ledger else None
    return pred, van, interior, evalrow0, cb, E0

def transport_219(NC, dps_req=None):
    """Refine-until-bound wrapper (2026-07-05, certified-bound treatment): --nc is a STARTING guess
    only.  Values are computed at the CURRENT mp.mp.dps (unchanged code path); a
    certification pass at dps+CERT_PAD — same NC, same recursion, only the arithmetic
    noise floor pushed ~10^CERT_PAD below the truncation tail — measures the certified
    per-order value-level transport truncation bounds.  If any bound misses
    10^-(min(dps,SEED_CAP_219)+TAIL_GUARD), NC grows x1.5 (the SAME spectral recursion
    refined — never a different algorithm) up to NC_CAP_MULT*NC0, then RuntimeError.
    Returns (pred, van, interior, evalrow0, cert)."""
    dps_req = dps_req if dps_req is not None else mp.mp.dps
    tol = _ttol(SEED_CAP_219, dps_req)
    NC0, NCc = NC, NC
    while True:
        pred, van, interior, evalrow0, _, _ = _transport_219_run(NCc, ledger=False)
        with mp.workdps(mp.mp.dps + CERT_PAD):
            _, _, _, _, cb, E0 = _transport_219_run(NCc, ledger=True)
        worst = max(cb.values())
        if worst < tol:
            return pred, van, interior, evalrow0, \
                {'bounds': cb, 'E0': E0, 'tol': tol, 'NC': NCc, 'dps_req': dps_req}
        NCn = int(mp.ceil(mp.mpf(3)*NCc/2))
        if NCn > NC_CAP_MULT*NC0:
            raise RuntimeError(
                f"sec219 transport NOT certified: value-level truncation bound "
                f"{mp.nstr(worst, 3)} >= tol {mp.nstr(tol, 3)} "
                f"(=10^-(min(dps,{SEED_CAP_219})+{TAIL_GUARD})) at NC={NCc}, dps_req="
                f"{dps_req}; refusing NC={NCn} > cap {NC_CAP_MULT}*{NC0}={NC_CAP_MULT*NC0}")
        print(f"   [BOUND] sec219 refine: bound {mp.nstr(worst, 3)} >= tol "
              f"{mp.nstr(tol, 3)} at NC={NCc} -> escalating to NC={NCn} (cap {NC_CAP_MULT*NC0})")
        NCc = NCn

def run_sec219(bar=30.0):
    print("== Check 1: sec219 orbit -- LIVE eps-form VoP transport, fit point -> verification point ==")
    # (1) symbolic eps-form certificate, proven at runtime
    resid = sp.simplify(A00_e0 + sp.Rational(1, 2)*sp.diff(G5p, tt)/G5p)
    print(f"   row-0 eps-form certificate  A[0,0]|eps^0 + (1/2) dlog Gram5 == 0 (sympy): {resid == 0}")
    assert resid == 0
    # (2) analytic sunrise closed form vs fit-point AMFlow boundary (consistency)
    dd = 200.0
    for j in SUN:
        p2 = int(P2Je[j].subs({SY[v]: PFIT[v] for v in VARS}))
        L  = mp.log(-p2) if p2 < 0 else (mp.log(p2) - mp.mpc(0, 1)*mp.pi)
        bnd = {int(o): mpc_of(v) for o, v in DATA["sec219"]["boundary_Pfit"][f"row{j}"].items()}
        for kk in [-1, 0, 1, 2]:
            prd = sum(ccoef[m]*(-p2)*(-2*L)**(kk-m)/mp.factorial(kk-m) for m in range(-1, kk+1))
            dd = min(dd, digits(prd, bnd[kk])[1])
    print(f"   analytic sunrise c(eps)*(-p^2)^(1-2eps) vs fit-point AMFlow: {dd:.1f} d (boundary-precision capped)")
    assert dd >= 30.0
    # (3) the transport itself
    NC = ARGS.nc
    t0 = time.time()
    pred, van, (t_int, m_int), evalfn, cert = transport_219(NC)
    print(f"   transported 14-master eps-form (7-segment contour around t=2/5, NC={NC}) in {time.time()-t0:.1f} s")
    print(f"   [BOUND] certified transport truncation bounds (trailing-{TAIL_WINDOW} spectral tail, "
          f"L1-propagated; cert pass at dps+{CERT_PAD}, NC={cert['NC']}): " +
          ", ".join(f"eps^{n:+d} {mp.nstr(cert['bounds'][n], 3)}" for n in range(-2, 3)))
    print(f"   [BOUND] all < tol {mp.nstr(cert['tol'], 3)} = 10^-(min(dps,{SEED_CAP_219})+{TAIL_GUARD}) "
          f"-> values certified (seed strings, not truncation, cap the agreement below)")
    print(f"   eps^-3 vanishing identities (row0 + six 5p rows): min {min(van):.1f} d (~dps => structural zero)")
    kin_int = {v: float(PFIT[v] + mp.re(t_int)*(GATE[v]-PFIT[v])) for v in VARS}
    print(f"   interior kinematic point t={mp.nstr(mp.re(t_int),3)}: "
          f"(s45,s15,m^2)=({kin_int['s45']:.2f},{kin_int['s15']:.2f},{kin_int['mm']:.2f})  "
          f"m219[eps^0] = {mp.nstr(m_int[0], 20)}   (function value; no oracle exists there)")
    # (4) independent comparison, digits recomputed live
    HO = {int(k): mpc_of(v) for k, v in S219["heldout_oracle_row0"].items() if not k.startswith('_')}
    worst = float("inf"); dd_ord = {}
    for n in range(-2, 3):
        dabs, drel = digits(pred[n], HO[n])
        worst = min(worst, drel); dd_ord[n] = drel
        print(f"   eps^{n:+d}: this work (transported HERE) = {mp.nstr(pred[n], 30)}")
        print(f"           independent AMFlow oracle    = {mp.nstr(HO[n], 30)}   agree {drel:6.2f} d (live)")
        assert drel >= bar, f"sec219 check FAILED at eps^{n}: {drel:.2f} d < {bar} d"
    print(f"   -> min over 5 orders: {worst:.2f} d (all >= {bar} d, measured in this run)\n")
    return worst, dd_ord, min(van), evalfn

# ============================================================================
# EPS^1, EPS^2 SUCCESSION (--kmax 4 / 5; 2026-09-07): the served bundle succeeded by the gated
# candidate bundle; the gate's objects vendored under vendor_row24_eps12/ and pinned here; the gate's
# rule re-run live on the recursion's eps^1, eps^2 endpoints (see the docstring).
# ============================================================================
SUCCESSION = {  # script-emitted from the gate of record and the shipped bytes (build_script.py); nothing typed
    'bundle': {'hexabox-vop-data.json.gz': 'f9e64518cb2e9ef35dfb827c37de8ddf463025c428102487a6c71a6f8f7321ea',
               'gated_bytes': 'c4d86690801bcef693b2106b612e10cbf5e861a70dc17d6abe15c9f9a2c282a6',
               'served_before': '35c91bc11f76219606fc977e0d2581dca620769fc3dadb3992a8ce3057a6262a',
               'served_before_2': '04bfd5f45c625ae8a2c4a05b054ab37e7c5fbc7c50f0fa3bbbf6d65cdf2fbbe9'},   # the 2026-09-07 bundle, succeeded 2026-09-11: the (97,0,2..4) layers entered exact (superseded_04bfd5f45c625ae8/)
    'record_layer': 5,             # the layer through which the succeeded bundle was checked against the oracles (the gate of record)
    'gate': 'vendor_row24_eps12/GATE_EPS12.json',
    'oracles': {'goal30': 'vendor_row24_eps12/ORACLE_goal30.json', 'goal60': 'vendor_row24_eps12/ORACLE_goal60.json'},
    'oracle_point': {"s12": "-3", "s23": "-5", "s34": "-7", "s45": "-11", "s15": "-17", "mm": "2"},   # the gate of record's point as a script literal (the vendored records carry no kinematic key), checked against the served one
    'fixtures': {
        'vendor_row24_eps12/BUILD_RECEIPT.json': 'd68d6e14d0c8094c6a56f8969cae7ebcc87b235929cbf53f4a60ff9f3a59b60e',
        'vendor_row24_eps12/GATE_EPS12.json': '607db54afff0e76ad027c00795406eba80f527dbf30af690032d7b08cabaf0bb',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_86_70_20260907T050708Z.json': '8557dca8be0d111fc4a76d73f3491c7413e6f94613593b52359dc94db66510c9',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_87_70_20260907T050708Z.json': 'ab598f5548aeec027b42cf434bdf22c63803abe05748e3b1ad3b4867bc65673e',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_88_70_20260907T050708Z.json': '8334f28d2a322aa6186fab9d8f659168ae7b8f3b6b7f8dd21dffeb7ee0db5ea1',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_89_70_20260907T050709Z.json': '574b83c2b5bd3da285829540ec0faf5867c1a77e74b82d07426bb5b5ecd4e290',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_90_70_20260907T050709Z.json': 'da419b51885bb069263322afd0e55e2ddcf72ebe101e9c8d3f2b3ecce7445970',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_91_70_20260907T050709Z.json': '4e1ac068ebd3c43a35ac92fadf9552250ffb4ae87b8cede7bc257c880f0f6e49',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_95_70_20260907T044009Z.json': 'bbb18253ce1df8479bac96536338cbbdb06a4a096a4832f52d1622baea78fa70',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_96_70_20260907T044009Z.json': '675a49ffd2885b2b60f0c7fea7a9e4cfc9e9d69caf7ad04facda6f54366eccaf',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_97_0_20260907T043901Z.json': '13f543565bf26ce475060bb6c40553273d49e30e59c5c2a7ef31999d933ba521',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_97_2_20260907T043900Z.json': '0544894bfdc1de7e2fdb8f6c33bef1865aec5b20bce90306a76f340db3b2dc95',
        'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_97_70_20260907T044008Z.json': 'b1fa1929c6a382b513a2e811906f370bdccaa1f5e1b1e49f4222ad5e941264f7',
        'vendor_row24_eps12/ORACLE_goal30.json': '92b3be0b6044a8e92d717eb9e0c3d7ff35c31e28dfc8408b39446e12d59dc360',
        'vendor_row24_eps12/ORACLE_goal60.json': 'c980694afed367868ea5561818c0508adc1514d90e692c60f3932746fa9298c1',
        'vendor_row24_eps12/SUPPORT_AUDIT.json': '256ea5ba8bc4e5c4d364761e3c974c7b538881fcf51b73aedc5f06a6e70efb51',
    },
    'module': {'hexabox_record_pair.py': 'b0d5747b30543d5e483e06b0c406808437c315e76d1cc954b1fafb8f9560709d'},   # parse_arb / coeffs_of: the record pair's parser, reused for the two oracle records
    'kernels': {   # the 28 entered keys per vendored candidate file (the gate's bundle_provenance.entered)
        'KERNELS_CANDIDATE_v2_item56_86_70_20260907T050708Z.json': ["86,70,8", "86,70,9"],
        'KERNELS_CANDIDATE_v2_item56_87_70_20260907T050708Z.json': ["87,70,8", "87,70,9"],
        'KERNELS_CANDIDATE_v2_item56_88_70_20260907T050708Z.json': ["88,70,8", "88,70,9"],
        'KERNELS_CANDIDATE_v2_item56_89_70_20260907T050709Z.json': ["89,70,8", "89,70,9"],
        'KERNELS_CANDIDATE_v2_item56_90_70_20260907T050709Z.json': ["90,70,8", "90,70,9"],
        'KERNELS_CANDIDATE_v2_item56_91_70_20260907T050709Z.json': ["91,70,8", "91,70,9"],
        'KERNELS_CANDIDATE_v2_item56_95_70_20260907T044009Z.json': ["95,70,8", "95,70,9"],
        'KERNELS_CANDIDATE_v2_item56_96_70_20260907T044009Z.json': ["96,70,8", "96,70,9"],
        'KERNELS_CANDIDATE_v2_item56_97_0_20260907T043901Z.json': ["97,0,5", "97,0,6", "97,0,7", "97,0,8", "97,0,9"],
        'KERNELS_CANDIDATE_v2_item56_97_2_20260907T043900Z.json': ["97,2,5", "97,2,6", "97,2,7", "97,2,8", "97,2,9"],
        'KERNELS_CANDIDATE_v2_item56_97_70_20260907T044008Z.json': ["97,70,8", "97,70,9"],
    },
    'bar': 30,                     # the gate's rule: >= 30 d at every order computed
    'labels': [
        'the eps^1, eps^2 layers of the three top-sector masters at the verification point: the live layer recursion on the succeeded bundle against the served 60-digit strings, the goal-60 record and the goal-30 record (and, with --dps-double, its own two-precision pair)',
        'the goal-30 record is the floor of the minimum (~40 / ~35 d): its own precision at eps^1, eps^2; the goal-60 record and the served strings agree to ~57 d, the pair to ~71-74 d',
        'the 28 candidate kernels are exact rationals reproducing both oracles through eps^2: candidates, not proofs; the 146 non-top couplings whose supports stop at m <= 4 are complete by the oracle reading only',
        'one kinematic point: the record pair at P2 stops at eps^0; the six-scale function is open',
    ],
}
EPS12_STATE = {}     # filled by run_eps12_gate: values, floors, verdict (read by the summary lines and the pair)
EPS12_PAIR_REF = None  # the deeper pass of --kmax K --dps-double: its eps^1, eps^2 endpoints for the pair
EPS12_FIX = None       # the vendored objects, loaded after the pins


def succession_pins():
    """The served PINS form: a missing vendored file -> exit 4, a mismatch -> exit 3, before anything is read as data;
    then the vendored objects are loaded and their forms asserted (the two oracle records at the served verification point:
    the gate's own point check, refused by name otherwise, exit 2)."""
    import hashlib
    here = os.path.dirname(os.path.abspath(__file__))
    R = SUCCESSION
    print(f"== eps^1, eps^2 succession (--kmax {ARGS.kmax}): the vendored objects of the gate of record, pinned ==")
    for rel, want in list(R['fixtures'].items()) + list(R['module'].items()):
        path = os.path.join(here, rel)
        if not os.path.exists(path):
            print(f"   PIN MISSING: {rel} is not beside this script -> exit 4")
            sys.exit(4)
        got = hashlib.sha256(open(path, 'rb').read()).hexdigest()
        if got != want:
            print(f"   PIN MISMATCH: {rel} sha256 {got[:16]}... != pinned {want[:16]}... -> exit 3")
            sys.exit(3)
        print(f"   pin OK: {rel} sha256 {want[:16]}...")
    sys.path.insert(0, here)
    import hexabox_record_pair as RP
    fx = {'gate': json.load(open(os.path.join(here, R['gate'])))}
    for tag, rel in R['oracles'].items():
        d = json.load(open(os.path.join(here, rel)))
        assert d['mode'] == 'solve_integrals' and len(d['result']) == 3, "unexpected record form"
        assert all(e['integral']['family'] == 'hexabox' for e in d['result'])
        fx[tag] = {(mi, n): mp.mpc(v[0], v[1]) for mi, e in enumerate(d['result']) for n, v in RP.coeffs_of(e).items()}
    gate_pt = R['oracle_point']; served_pt = {k: str(GATE[k]) for k in VARS}
    if gate_pt != served_pt:
        print(f"   REFUSED -- the vendored records' point {gate_pt} is not the served verification point {served_pt} -> exit 2")
        sys.exit(2)
    print(f"   oracle point {gate_pt} == the served verification point: PASS")
    fx['kernels'] = {}
    for rel, keys in R['kernels'].items():
        K = json.load(open(os.path.join(here, VD_DIR, rel)))
        for key in keys:
            m = key.split(',')[2]
            fx['kernels'][key] = [K['layers'][m]['P'], K['layers'][m]['Q']]
    print(f"   vendored: {len(R['fixtures'])} files pinned; the gate of record {os.path.basename(R['gate'])} "
          f"(stamp {fx['gate']['stamp_utc']}, bundle {fx['gate']['inputs_sha256']['bundle'][:16]}...); "
          f"{len(fx['kernels'])} entered kernel layers read from {len(R['kernels'])} candidate files")
    return fx


VD_DIR = 'vendor_row24_eps12'
# ============================================================================
# BOUNDARY REGENERATE (--boundary-regenerate; 2026-09-09): the exact (97,0,2..4) kernels and the from-definition seeds
# vendored under vendor_row24_kernels/ and vendor_row24_seeds/, pinned here; the sec255 recursion re-run on them (the
# docstring section BOUNDARY REGENERATE).
# ============================================================================
REGEN = {  # script-emitted from the vendored bytes and the objects of record (build_script_r5.py); nothing typed
    'kernel_file': 'vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_0_20260907T041028Z.json',
    'kernel_file_97_2': 'vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_2_20260907T040525Z.json',
    'gate_v4': 'vendor_row24_kernels/GATE_ITEM56_EPS12_20260907T052752Z.json',
    'seeds_file': 'vendor_row24_seeds/fresh_strings_447_fromdef_20260908T053054Z.json',
    'kernels': ['97,0,2', '97,0,3', '97,0,4'],   # the three (97,0,m) layers the bundle carries exact since 2026-09-11, asserted equal to the vendored object's layers 2, 3, 4
    'served_candidate_file': 'vendor_row24_eps12/KERNELS_CANDIDATE_v2_item56_97_0_20260907T043901Z.json',   # its layers 2, 3, 4 = the exact ones
    'fixtures': {
        "vendor_row24_kernels/GATE_ITEM56_EPS12_20260907T052752Z.json": "1ef0b8a96ddebacbada56b4f1801cbf7e3b4dc99fa3f1d2758d5939869d5d804",
        "vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_0_20260907T041028Z.json": "adbae0c89d3db90024dde6740e5d99d18b9dbea93e9d5fdf8f084fab91e8ea4d",
        "vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_2_20260907T040525Z.json": "752b050c0877963eb6aa8be081933a1de39a01e4b9a4840e7af03d7e1f6bf980",
        "vendor_row24_seeds/BOUNDARY_REGENERATE_447_fromdef_20260908T053054Z.json": "48294da70bfa1c2b350deec2c944af776250483be23cc8b9aed3e87ed7145592",
        "vendor_row24_seeds/FROMDEF_COMPARE_447_20260908T053054Z.json": "cedafa9e212ee1b54121d132f4f6a7be85589281d1fd23da96c711a07054e573",
        "vendor_row24_seeds/LEG_LANDING_wave12_dps120_20260907T235745Z.json": "dd72beb3aa11bf5e5f2f4f1f696036ec5ba8dc34ddf4f5facefcd6991d6a74fe",
        "vendor_row24_seeds/LEG_LANDING_wave12_dps90_20260907T201119Z.json": "58457f3a7bff654303e072fc3e312a7b46de62f10b2affd9926e46efc580fed0",
        "vendor_row24_seeds/LEG_LANDING_wave3_dps120_20260908T053011Z.json": "82108e0e4630bcb0fac88dad16cc8e324c14a9ea0fad8c4f53566102dbe6dec3",
        "vendor_row24_seeds/LEG_LANDING_wave3_dps90_20260908T024214Z.json": "16fb65e69f8886684fcadd472458c835a343c940c09f65470134fae77cec2855",
        "vendor_row24_seeds/fresh_strings_447_fromdef_20260908T053054Z.json": "c353b8d589f7025666979a209c1f7cdca68561ce2818e00e94b87073da62c1a0"
    },
    'vendored_from': {   # the ten objects as emitted, by sha256 (script-emitted from the re-cut reports; nothing typed): their string VALUES re-cut by field -- cure 1: the four leg receipts' host strings (run_diag_nodes.host under the halves and the extra leaves) -> "withheld"; cure 3: a narrative value -> "withheld" (fields_withheld), a path value -> its basename + the sha256 of the file it named or "(directory)" (paths_recut), a numerical-term sentence kept as written (numerical_term_fields_kept); no numeric leaf, no machine label and no key name moved
        "vendor_row24_kernels/GATE_ITEM56_EPS12_20260907T052752Z.json": {'original_sha256': "65d5566cb74da059cf152a7eff372f0bdddb1b51ceed7d5cb32eef708185797a", 'fields_withheld': 1, 'paths_recut': 3, 'numerical_term_fields_kept': 0},
        "vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_0_20260907T041028Z.json": {'original_sha256': "d223992d5ee27c0270d8ba7ac9c3bc690aa4e702223ff5ad478af56db562d2c4", 'fields_withheld': 1, 'paths_recut': 2, 'numerical_term_fields_kept': 1},
        "vendor_row24_kernels/KERNELS_CANDIDATE_item56_97_2_20260907T040525Z.json": {'original_sha256': "5679228f877351295f11bc217046528a46fa9fce54239278585842fb3e6e03cd", 'fields_withheld': 1, 'paths_recut': 2, 'numerical_term_fields_kept': 1},
        "vendor_row24_seeds/BOUNDARY_REGENERATE_447_fromdef_20260908T053054Z.json": {'original_sha256': "2785b15146f704693996ced6fa665e9edff4b9ef9e1715d13a4dd50fb0c9d08b", 'fields_withheld': 0, 'paths_recut': 4, 'numerical_term_fields_kept': 0},
        "vendor_row24_seeds/FROMDEF_COMPARE_447_20260908T053054Z.json": {'original_sha256': "27b5d0e6234816e265eb5263c79be4dd52b2e77e03ab6fc39b2fd6508d10439d", 'fields_withheld': 0, 'paths_recut': 4, 'numerical_term_fields_kept': 0},
        "vendor_row24_seeds/LEG_LANDING_wave12_dps120_20260907T235745Z.json": {'original_sha256': "459e247e3a7407507151ad2505af55aacccc95eb4e20de5e29f31e923cac9dea", 'host_fields_withheld': 2, 'cure1_sha256': "d0a68c4dc5c27e910542e7931dbd9903a9240a4e61f83d25ece430ba6629904d", 'fields_withheld': 1, 'paths_recut': 10, 'numerical_term_fields_kept': 0},
        "vendor_row24_seeds/LEG_LANDING_wave12_dps90_20260907T201119Z.json": {'original_sha256': "753c4cccc0e358a4a997ef79a7fa57162ed959a0bc0bee9bd2a07905832c6491", 'host_fields_withheld': 2, 'cure1_sha256': "88652ed59cdfb62e7a46615c0f70550014951cb1bcf9bee332630bc98178f273", 'fields_withheld': 0, 'paths_recut': 10, 'numerical_term_fields_kept': 0},
        "vendor_row24_seeds/LEG_LANDING_wave3_dps120_20260908T053011Z.json": {'original_sha256': "3a11a43bc2df47c9d179788acf62a4bdeadf578529607c68ef48222a226e7053", 'host_fields_withheld': 4, 'cure1_sha256': "10546a8b240bd5971b851bd7e2e40bf897be97d6cbb86ef3ae2e350df905b26f", 'fields_withheld': 1, 'paths_recut': 16, 'numerical_term_fields_kept': 0},
        "vendor_row24_seeds/LEG_LANDING_wave3_dps90_20260908T024214Z.json": {'original_sha256': "7739ffdaca73d3d002b0849fdfe4cd6976fc17ad81ddc2592e2d6b2f7131d447", 'host_fields_withheld': 3, 'cure1_sha256': "e501bcdb522092606304c674e3a3c70db031f2b55ffbace77a588588d61f4967", 'fields_withheld': 1, 'paths_recut': 13, 'numerical_term_fields_kept': 0},
        "vendor_row24_seeds/fresh_strings_447_fromdef_20260908T053054Z.json": {'original_sha256': "7961fd60d749804a29bfa7da0a9538750c9986bc6e33a367e4cafa28dfdbe8db", 'fields_withheld': 0, 'paths_recut': 2, 'numerical_term_fields_kept': 0},
    },
    'zero_floor': '1e-40',
    'short_decimal_max_digits': 6,   # a kept significant string whose trailing-zero-stripped print has <= 6 digits is a terminating decimal (exact as printed)
    'probe_t': ['1/7', '2/9', '3/8', '5/11', '7/10'],   # the probe points of the retired fit-vs-exact reading (the fits left the bundle 2026-09-11; kept as emitted, unread)
    'labels': [
        'the three (97,0,m) kernels, m = 2, 3, 4: exact fmpq rationals of the succession\'s factored read (CRT + rational reconstruction on 101 path nodes, 8 withheld nodes reproduced), carried exact by the bundle itself since 2026-09-11 and asserted equal to the vendored object here; candidates reproducing both oracle records, not proofs',
        'the 447 covered fit-point seed cells: the from-definition strings of the eta-chain generator at working precisions 90 and 120 (four checkpointed legs), identical to the served bank at every printed digit; the other 255 cells keep the bundle\'s values, 34 significant components on 24 of them (eps^-4 / eps^-2) the served 70-digit strings of closed-form constants not yet entered exactly',
        'the oracle comparison stays capped by the oracle\'s 60 digits: this tier lifts the seed cap on the 447 replaced cells to the printed length (>= 78 d); the input cap of the recursion is the served floor 69.32 d (measured over the covered components, bounding the 34 kept components), not 78 d; the printed oracle agreement does not move',
    ],
}
REGEN_STATE = {}   # filled by regen_pins / regen_bundle_path: the certificate figures (read by the summary line)


def regen_pins():
    """The served PINS form for the regenerate objects: a missing vendored file -> exit 4, a mismatch -> exit 3, before
    anything is read as data; then the exact kernel layers are read and asserted byte-equal to the served candidate file."""
    import hashlib
    here = os.path.dirname(os.path.abspath(__file__))
    R = REGEN
    print("== boundary regenerate (--boundary-regenerate): the vendored exact kernels and from-definition seeds, pinned ==")
    for rel, want in R['fixtures'].items():
        path = os.path.join(here, rel)
        if not os.path.exists(path):
            print(f"   PIN MISSING: {rel} is not beside this script -> exit 4")
            sys.exit(4)
        got = hashlib.sha256(open(path, 'rb').read()).hexdigest()
        if got != want:
            print(f"   PIN MISMATCH: {rel} sha256 {got[:16]}... != pinned {want[:16]}... -> exit 3")
            sys.exit(3)
        print(f"   pin OK: {rel} sha256 {want[:16]}...")
    K = json.load(open(os.path.join(here, R['kernel_file'])))
    assert K['entry'] == [97, 0] and K['form'].startswith('layer m of'), "unexpected kernel object form"
    served_cand = os.path.join(here, R['served_candidate_file'])
    C = json.load(open(served_cand))
    same = 0
    for key in R['kernels']:
        m = key.split(',')[2]
        same += int(K['layers'][m]['P'] == C['layers'][m]['P'] and K['layers'][m]['Q'] == C['layers'][m]['Q'])
        assert K['layers'][m]['Q'][-1] == '1', "Q not monic"
    print(f"   exact kernel layers {', '.join(R['kernels'])} of {os.path.basename(R['kernel_file'])}: byte-equal to layers 2, 3, 4 "
          f"of the served candidate file {os.path.basename(R['served_candidate_file'])}: {same}/{len(R['kernels'])}"
          + ("" if same == len(R['kernels']) else " -> REFUSED"))
    assert same == len(R['kernels']), "an exact kernel layer differs from the served candidate file"
    cert = K['certification']
    print(f"   the exact object's certification: n_primes {cert['n_primes']}, crt_bits {cert['crt_bits']}, full identity on "
          f"{cert['full_identity_all_nodes']} of {cert['n_nodes']} nodes, withheld nodes reproduced {len(cert['heldout_nodes_in_full_identity'])}; "
          f"layer degrees (P,Q) " + ", ".join(f"m {m}: {tuple(K['layers'][m]['degrees(P,Q)'])}" for m in ('2', '3', '4')))
    G4 = json.load(open(os.path.join(here, R['gate_v4'])))
    print(f"   the gate of record's v4 object {os.path.basename(R['gate_v4'])} (stamp {G4['stamp_utc']}): {G4['VERDICT']['eps12_layers']}, "
          f"eps^1 {G4['VERDICT']['eps1_min_d']} d, eps^2 {G4['VERDICT']['eps2_min_d']} d, control {G4['VERDICT']['eps_-4..0_control_min_d']} d "
          f"(the served vendor_row24_eps12/GATE_EPS12.json is the same object re-cut in its path strings)")
    return K


def regen_bundle_path():
    """The served bundle with the 447 covered fit-point seeds replaced by the from-definition dps-120 strings, written under
    --regen-dir (default ./hexabox_regen_<stamp>/ in the working directory; never removed by this tool) for the engine's
    loader (the served bundle bytes are never touched); the seed certificate, the kept-cell census and the TRUE input cap
    printed from the objects (cure 1, 2026-09-09).  Since the 2026-09-11 succession the bundle carries the three (97,0,m)
    kernels, m = 2, 3, 4, exact in exactA and no numeric kernel: part (i) asserts that identity against the vendored exact
    object instead of swapping the layers in, and the fit-vs-exact probe reading is retired with the fits (their bundle is
    kept under superseded_04bfd5f45c625ae8/, unread here)."""
    import datetime
    import gzip
    here = os.path.dirname(os.path.abspath(__file__))
    R = REGEN
    K = regen_pins()
    B = json.loads(gzip.open(os.path.join(STAGE_DIR, "hexabox-vop-data.json.gz"), 'rb').read())
    assert B['hybrid_kernels'] == {}, sorted(B['hybrid_kernels'])   # the succeeded bundle carries no numeric kernel
    # (i) the kernels: the bundle's exact layers == the vendored object's layers 2, 3, 4 (the identity every tier relies on)
    same = 0
    for key in R['kernels']:
        m = key.split(',')[2]
        assert B['exactA'].get(key) == [K['layers'][m]['P'], K['layers'][m]['Q']], key
        same += 1
    print(f"   kernels ({', '.join(R['kernels'])}): the bundle's exactA layers equal layers 2, 3, 4 of {os.path.basename(R['kernel_file'])}: "
          f"{same}/{len(R['kernels'])}; hybrid_kernels empty -- no numeric kernel in the bundle, nothing swapped in "
          f"(the numeric fits of the earlier releases are kept under superseded_04bfd5f45c625ae8/, unread by this tool)")
    # (ii) the seeds
    F = json.load(open(os.path.join(here, R['seeds_file'])))
    zero = mp.mpf(R['zero_floor'])
    n_tags = 0; n_id = 0; n_sig = 0; n_zero = 0; min_sig = None; min_arg = None; worst = None; warg = None; replaced = 0
    with mp.workdps(250):
        for tag, f in sorted(F['tags'].items()):
            n_tags += 1
            r = tag.split(',')[0]; o = str(f['eps_order'])
            assert r in B['boundary_Pfit'] and o in B['boundary_Pfit'][r], (tag, o)
            if f['re'] == f['re_hi']:
                n_id += 1
                sd = len(f['re_hi'].split('e')[0].replace('-', '').replace('+', '').replace('.', '').lstrip('0'))
                if min_sig is None or sd < min_sig:
                    min_sig, min_arg = sd, tag
            sre, sim = B['boundary_Pfit'][r][o]
            for part, s_served, s_fresh in (('re', sre, f['re_hi']), ('im', sim, f['im_hi'])):
                a, b = mp.mpf(s_served), mp.mpf(s_fresh)
                if abs(a) <= zero or abs(b) <= zero:
                    n_zero += 1
                    continue
                n_sig += 1
                d = float(-mp.log10(abs(a - b) / max(abs(a), abs(b)))) if a != b else 250.0
                if worst is None or d < worst:
                    worst, warg = d, f"{tag}:{part} (eps^{o})"
            B['boundary_Pfit'][r][o] = [f['re_hi'], f['im_hi']]
            replaced += 1
    total = sum(len(v) for v in B['boundary_Pfit'].values())
    # the kept cells, censused from the objects at every run (cure 1): structural zeros, short terminating decimals
    # (exact rationals as printed) and the significant served 70-digit strings that stay in the recursion's input
    replaced_cells = {(t.split(',')[0], str(f['eps_order'])) for t, f in F['tags'].items()}
    kept = {'low': {'cells': 0, 'zero': 0, 'short': 0, 'long': 0, 'long_cells': 0, 'rows': {}, 'orders': []},
            'high': {'cells': 0, 'zero': 0, 'short': 0, 'long': 0, 'long_cells': 0, 'rows': {}, 'orders': []}}

    def _sig(s, strip=False):
        m = s.split('e')[0].split('E')[0].replace('-', '').replace('+', '').replace('.', '').lstrip('0')
        return len(m.rstrip('0') if strip else m)
    with mp.workdps(250):
        for r in sorted(B['boundary_Pfit'], key=int):
            for o in sorted(B['boundary_Pfit'][r], key=int):
                if (r, o) in replaced_cells:
                    continue
                g = kept['low'] if int(o) <= 0 else kept['high']
                g['cells'] += 1
                if int(o) not in g['orders']:
                    g['orders'].append(int(o))
                nlong = 0
                for s in B['boundary_Pfit'][r][o]:
                    if abs(mp.mpf(s)) <= zero:
                        g['zero'] += 1
                    elif _sig(s, True) <= R['short_decimal_max_digits']:
                        g['short'] += 1
                    else:
                        g['long'] += 1; nlong += 1
                if nlong:
                    g['long_cells'] += 1
                    g['rows'].setdefault(o, []).append(int(r))
    assert kept['low']['cells'] + kept['high']['cells'] == total - replaced
    cap = min(float(min_sig), worst)
    REGEN_STATE.update({'n_tags': n_tags, 'n_identical': n_id, 'min_sigdigits': min_sig, 'min_sig_tag': min_arg,
                        'served_vs_fromdef_min': worst, 'served_vs_fromdef_arg': warg, 'n_significant': n_sig, 'n_zero': n_zero,
                        'replaced': replaced, 'kept': total - replaced, 'kept_low': kept['low'], 'kept_high': kept['high'],
                        'input_cap': cap})
    print(f"   from-definition seeds ({os.path.basename(R['seeds_file'])}; working precisions {F['_meta']['pair']}): {n_tags} tags; "
          f"the dps-90 and dps-120 strings identical on {n_id}/{n_tags} tags (re), the shortest such string {min_sig} significant "
          f"digits (tag {min_arg}) -> SEED CERTIFICATE >= {min_sig} d on every covered cell")
    print(f"   the served 70-digit seeds read against the dps-120 strings: min {worst:.2f} d at {warg} over {n_sig} significant "
          f"components ({n_zero} structural zeros |x| <= {R['zero_floor']} named by count, not counted)")
    print(f"   seeds replaced: {replaced} of the bundle's {total} cells; {total - replaced} kept (the cells outside the chain's coverage "
          f"and the eps^3, eps^4 cells of the succession)")
    kl, kh = kept['low'], kept['high']
    lo_lbl = "/".join(f"eps^{o}" for o in sorted(kl['orders']))
    hi_lbl = "/".join(f"eps^{o}" for o in sorted(kh['orders']))
    print(f"   kept cells at {lo_lbl} (the orders <= 0, in the value path of this recursion): {kl['cells']} cells = {kl['zero']} structural-zero "
          f"components + {kl['short']} short terminating decimals (exact rationals as printed) + {kl['long']} SIGNIFICANT served 70-digit "
          f"strings on {kl['long_cells']} cells (closed-form constants not yet entered exactly): "
          + "; ".join(f"eps^{o}: rows {', '.join(str(x) for x in rows)}" for o, rows in sorted(kl['rows'].items(), key=lambda kv: int(kv[0]))))
    print(f"   kept cells at {hi_lbl} (the orders > 0, in the value path with --kmax 4 / 5 only): {kh['cells']} cells = {kh['zero']} structural zeros "
          f"+ {kh['short']} short + {kh['long']} served 70-digit strings on {kh['long_cells']} cells")
    print(f"   TRUE INPUT CAP of this recursion: min(the seed certificate >= {min_sig} d on the {replaced} replaced cells, the served floor "
          f"{worst:.2f} d measured over the {n_sig} covered significant components and bounding the {kl['long']} kept significant components, "
          f"which have no from-definition twin) = {cap:.2f} d until those components are entered exactly")
    stamp = datetime.datetime.now(datetime.timezone.utc).strftime('%Y%m%dT%H%M%SZ')
    regdir = ARGS.regen_dir if ARGS.regen_dir else os.path.join(os.getcwd(), f'hexabox_regen_{stamp}')
    os.makedirs(regdir, exist_ok=True)
    path = os.path.join(regdir, f'hexabox-vop-data.regenerated_{stamp}.json.gz')
    assert not os.path.exists(path), f"refusing to overwrite {path}"
    with gzip.open(path, 'wb') as fh:
        fh.write(json.dumps(B).encode())
    REGEN_STATE['regen_path'] = path
    print(f"   regenerated bundle written for the loader at {path} (this tool removes nothing: the caller owns the directory; "
          f"the served bundle untouched): {len(B['exactA'])} exact entries + {len(B['hybrid_kernels'])} certified-numeric")
    return path


# ============================================================================
# GATE POINT (--gatepoint; 2026-09-09): the two-precision floors of all 98 masters at the verification point from the
# vendored pair strings, read against the PAIR v2 keys of record (the docstring section GATE POINT).
# ============================================================================
GATEPOINT = {  # script-emitted from the vendored bytes and the PAIR v2 / settled-receipt v2 objects (build_script_r5.py); nothing typed
    'data_file': 'vendor_row24_gatepoint/DATA_C24g60_pair_strings_20260909T075018Z.json',
    'fixtures': {
        "vendor_row24_gatepoint/DATA_C24g60_pair_strings_20260909T075018Z.json": "2045567bf9c52d396e2722145d92456501d9473b588fde29affe2511e1c44d34"
    },
    'module': {'hexabox_record_pair.py': 'b0d5747b30543d5e483e06b0c406808437c315e76d1cc954b1fafb8f9560709d'},   # matched_digits / parse_arb: the record pair's functions, reused
    'pair_v2': {
        "object": "bb0b69e312ea86f6ece0e9ceea2573171e27edac825a816d4c3a51a1aaad9a2f",
        "settled_receipt": "8a3c9183d633a4175768bc1bb9671f47c9a9e9596865395eb953a095f6836847",
        "stamp_utc": "2026-09-09T07:47:36Z",
        "all_98_all_orders": {
            "min": 32.8,
            "floor_int": 32
        },
        "all_98_through_eps0": {
            "min": 48.4,
            "floor_int": 48
        },
        "all_98_through_eps2": {
            "min": 42.2,
            "floor_int": 42
        },
        "by_order_floor_int": {
            "-4": 49,
            "-3": 49,
            "-2": 49,
            "-1": 49,
            "0": 48,
            "1": 45,
            "2": 42,
            "3": 38,
            "4": 32
        },
        "by_order_min": {
            "-4": 49.5,
            "-3": 49.3,
            "-2": 49.3,
            "-1": 49.3,
            "0": 48.4,
            "1": 45.3,
            "2": 42.2,
            "3": 38.2,
            "4": 32.8
        },
        "top_sector_all_orders": {
            "min": 34.4,
            "floor_int": 34,
            "masters": [
                95,
                96,
                97
            ]
        },
        "counts": {
            "digit_cells": 1298,
            "numerical_zero_cells_excluded": 46,
            "both_exactly_zero_cells": 60,
            "cells_FAIL": 0
        }
    },
}


def run_gatepoint():
    import hashlib
    here = os.path.dirname(os.path.abspath(__file__))
    R = GATEPOINT
    print("== GATE POINT: the two-precision floor of all 98 masters at the verification point, goal 30 vs goal 60 ==")
    print("   strings only: the two evaluations of record are re-read component by component; nothing is computed from the final forms")
    for rel, want in list(R['fixtures'].items()) + list(R['module'].items()):
        path = os.path.join(here, rel)
        if not os.path.exists(path):
            print(f"   PIN MISSING: {rel} is not beside this script -> exit 4")
            sys.exit(4)
        got = hashlib.sha256(open(path, 'rb').read()).hexdigest()
        if got != want:
            print(f"   PIN MISMATCH: {rel} sha256 {got[:16]}... != pinned {want[:16]}... -> exit 3")
            sys.exit(3)
        print(f"   pin OK: {rel} sha256 {want[:16]}...")
    sys.path.insert(0, here)
    import hexabox_record_pair as RP
    Dd = json.load(open(os.path.join(here, R['data_file'])))
    assert len(Dd['rows']) == 98 and Dd['ref']['goal'] == 30 and Dd['test']['goal'] == 60, "unexpected data form"
    pt = {k: str(v) for k, v in Dd['point'].items()}; served_pt = {k: str(GATE[k]) for k in VARS}
    if pt != served_pt:
        print(f"   REFUSED -- the data file's point {pt} is not the served verification point {served_pt} -> exit 2")
        sys.exit(2)
    print(f"   point {pt} == the served verification point: PASS")
    mut = None
    if ARGS.mutate_gatepoint:
        row = Dd['rows'][0]; cell = row['orders']['0']
        s = cell['goal60']['re']; digs = [i for i, ch in enumerate(s) if ch.isdigit()]
        pos = digs[20]; old = s[pos]; new = str((int(old) + 1) % 10)
        cell['goal60']['re'] = s[:pos] + new + s[pos + 1:]
        mut = (row['i'], '0', 're')
        print(f"   MUTATION (--mutate-gatepoint): master {row['i']} eps^+0 re, goal-60 string decimal digit 20 (string position {pos}) "
              f"changed {old!r} -> {new!r} IN MEMORY; the file is untouched")
    cells = []; n_null = 0; n_mismatch = 0
    with mp.workdps(RP.RECORD_DPS):
        for row in Dd['rows']:
            for o, c in row['orders'].items():
                for part in ('re', 'im'):
                    stored = c['digits_' + part]
                    if stored is None:
                        n_null += 1
                        continue
                    d = RP.matched_digits(RP.parse_arb(c['goal30'][part]), RP.parse_arb(c['goal60'][part]))
                    d = 250.0 if d is None else d
                    if abs(d - stored) > 0.05 and (row['i'], o, part) != mut:
                        n_mismatch += 1
                    cells.append((row['i'], int(o), part, d, stored))
    K = R['pair_v2']
    print(f"   {len(cells)} digit cells recomputed (record {K['counts']['digit_cells']}), {n_null} components null in the record "
          f"(numerical zeros by the tool's rule, not counted; record {K['counts']['numerical_zero_cells_excluded']} excluded + "
          f"{K['counts']['both_exactly_zero_cells']} both-zero): recomputed vs stored digits differing by > 0.05: {n_mismatch}")
    assert len(cells) == K['counts']['digit_cells'], "the digit-cell count differs from the record's"
    assert n_mismatch == 0, "a recomputed digit count differs from the stored one"
    def floor_over(pred, label):
        m = min((d for (i, o, p, d, s) in cells if pred(i, o)), default=None)
        am = min(((d, f"master {i} eps^{o:+d} {p}") for (i, o, p, d, s) in cells if pred(i, o)), default=None)
        return m, am[1]
    got = {}
    got['all_98_through_eps0'] = floor_over(lambda i, o: o <= 0, 'through eps^0')
    got['all_98_through_eps2'] = floor_over(lambda i, o: o <= 2, 'through eps^2')
    got['all_98_all_orders'] = floor_over(lambda i, o: True, 'all orders')
    top = set(K['top_sector_all_orders']['masters'])
    got['top_sector_all_orders'] = floor_over(lambda i, o: i in top, 'top sector')
    got_by_order = {str(o): floor_over(lambda i, oo, o=o: oo == o, f'eps^{o}') for o in range(-4, 5)}
    ok = True; lines = []
    for key in ('all_98_through_eps0', 'all_98_through_eps2', 'all_98_all_orders', 'top_sector_all_orders'):
        m, arg = got[key]; want = K[key]
        same = (int(mp.floor(m)) == want['floor_int']) and abs(round(m, 1) - want['min']) <= 0.051
        ok &= same
        lines.append(f"   {key:<24s}: recomputed min {m:6.2f} d (floor {int(mp.floor(m))}; at {arg}) vs the PAIR v2 key min {want['min']} floor {want['floor_int']}: {'PASS' if same else 'FAIL'}")
    for o in sorted(got_by_order, key=int):
        m, arg = got_by_order[o]; wi = K['by_order_floor_int'][o]; wm = K['by_order_min'][o]
        same = (int(mp.floor(m)) == wi) and abs(round(m, 1) - wm) <= 0.051
        ok &= same
        lines.append(f"   eps^{int(o):+d}{'':<19s}: recomputed min {m:6.2f} d (floor {int(mp.floor(m))}; at {arg}) vs the PAIR v2 key min {wm} floor {wi}: {'PASS' if same else 'FAIL'}")
    print("   floors from this run's table (matched digits per component, the record pair's rule; min over the cells named):")
    for l in lines:
        print(l)
    print(f"   the PAIR v2 keys of record: object {K['object'][:16]}... (stamp {K['stamp_utc']}), the settled receipt {K['settled_receipt'][:16]}...; "
          f"the Table-2 cell of the row carries the integer floors {K['all_98_through_eps0']['floor_int']} / "
          f"{K['all_98_through_eps2']['floor_int']} / {K['all_98_all_orders']['floor_int']} (through eps^0 / through eps^2 / all orders)")
    print("   labels:")
    print("      - the digits are a two-precision agreement of one program (AMFlow goal 30 vs goal 60): the lower member bounds them")
    print("      - the three top-sector masters have independent records at eps^-4..eps^2 (the --kmax 5 tier); the 95 others have none at these orders")
    print("      - one kinematic point: the served verification point; nothing here reads the final forms")
    if not ok:
        bad = [l.strip() for l in lines if l.endswith('FAIL')]
        print(f"GATE POINT FAIL by name: {len(bad)} floor(s) differ from the PAIR v2 keys: {bad[0]}"
              + (" (the planted digit of --mutate-gatepoint)" if ARGS.mutate_gatepoint else ""))
        sys.exit(1)
    print(f"Gate point: PASS (the recomputed floors equal the PAIR v2 keys: {K['all_98_through_eps0']['floor_int']} / "
          f"{K['all_98_through_eps2']['floor_int']} / {K['all_98_all_orders']['floor_int']}; two precisions of one program, not an independent record).")
    sys.exit(0)



def declare_record_layer(V):
    """The succeeded bundle's record layer, declared on the engine by sha (the reach check's KMAX_RECORD): 5 for the
    bundle the gate of record checked through layer 5; any other bundle keeps the engine's class default (3)."""
    import hashlib
    got = hashlib.sha256(open(os.path.join(STAGE_DIR, "hexabox-vop-data.json.gz"), 'rb').read()).hexdigest()
    if got == SUCCESSION['bundle']['hexabox-vop-data.json.gz']:
        V.KMAX_RECORD = SUCCESSION['record_layer']
        print(f"   [succession] bundle {got[:16]}... is the succeeded bundle: record layer {V.KMAX_RECORD} declared "
              f"(the gate of record checked its layers through {V.KMAX_RECORD}; the engine's class default is {type(V).KMAX_RECORD})")
        if EPS12_FIX is not None:
            same = sum(1 for key, pq in EPS12_FIX['kernels'].items() if V.B['exactA'].get(key) == pq)
            print(f"   [succession] entered kernels byte-equal to the vendored candidate files: {same}/{len(EPS12_FIX['kernels'])}")
            assert same == len(EPS12_FIX['kernels']), "an entered kernel differs from its vendored candidate file"
    else:
        print(f"   [succession] bundle {got[:16]}... is not the succeeded bundle ({SUCCESSION['bundle']['hexabox-vop-data.json.gz'][:16]}...): "
              f"the engine's record layer {V.KMAX_RECORD} stands")


def digits_cr(a, b):
    """the gate's verdict convention: complex-relative -log10(|a-b| / max(|a|,|b|))."""
    den = max(abs(a), abs(b))
    if den == 0: return 999.0
    num = abs(a - b)
    return 999.0 if num == 0 else float(-mp.log10(num / den))


def digits_re(a, b):
    """the real-part reading, printed beside: -log10(|Re a - Re b| / max(|Re a|,|Re b|))."""
    den = max(abs(mp.re(a)), abs(mp.re(b)))
    if den == 0: return 999.0
    num = abs(mp.re(a) - mp.re(b))
    return 999.0 if num == 0 else float(-mp.log10(num / den))


def run_eps12_gate(V, bar=None):
    """The eps^1 (and eps^2) endpoints of the top-sector recursion (layers 4, 5 = eps order + L_i) against the served
    60-digit strings, the vendored goal-60 and goal-30 records and, on the second pass of --dps-double, the deeper pass
    (the two-precision pair); the gate of record's rule; FAIL by name, exit 1."""
    R = SUCCESSION; bar = R['bar'] if bar is None else bar
    fx = EPS12_FIX; G = fx['gate']
    orders = [n for n in (1, 2) if 3 + n <= ARGS.kmax]
    print(f"   -- eps^1, eps^2 gate (--kmax {ARGS.kmax}; orders {orders}; the gate of record's rule, bar {bar} d; "
          f"digits complex-relative, the real-part reading in brackets) --")
    served = {mi: orc_series(mi) for mi in range(3)}
    if ARGS.mutate_eps12:
        s = DATA["sec255"]["oracle_deep60"]["m0"]["1"][0]
        digs = [i for i, ch in enumerate(s) if ch.isdigit()]
        pos = digs[20]
        old = s[pos]; new = str((int(old) + 1) % 10)
        s2 = s[:pos] + new + s[pos + 1:]
        served[0][1] = mp.mpc(mp.mpf(s2), mp.mpf(DATA["sec255"]["oracle_deep60"]["m0"]["1"][1]))
        print(f"   MUTATION (--mutate-eps12): served string m0 eps^+1 re, decimal digit 20 (string position {pos}) changed "
              f"{old!r} -> {new!r} IN MEMORY; the files are untouched")
    vals = {}; floors = {}; members = {}
    for n in orders:
        rows = []
        for mi, i in enumerate(V.TOP):
            pr = V.endpoint(i, n + V.L[i])
            vals[(mi, n)] = pr
            refs = [("served string", served[mi][n]), ("goal-60 record", fx['goal60'][(mi, n)]), ("goal-30 record", fx['goal30'][(mi, n)])]
            if EPS12_PAIR_REF is not None:
                refs.append((f"pair (dps {EPS12_PAIR_REF['dps']})", EPS12_PAIR_REF['values'][(mi, n)]))
            ds = [(lab, digits_cr(pr, v), digits_re(pr, v)) for lab, v in refs]
            print(f"   m{mi}_eps{n:+d}: this work (recursed HERE) {mp.nstr(pr, 24):<34s} goal-60 record {mp.nstr(fx['goal60'][(mi, n)], 24):<34s}")
            print("             agree " + "; ".join(f"{lab} {d:6.2f} d [re {dr:6.2f}]" for lab, d, dr in ds) + " (live)")
            for lab, d, dr in ds:
                rows.append((d, f"m{mi}_eps{n} vs {lab}"))
        m = min(rows)
        floors[n] = m; members[n] = rows
        rec = G['floors'][str(n)]
        rec_ok = abs(m[0] - rec['min']) <= 0.05
        print(f"   eps^{n:+d}: min over masters and references {m[0]:.2f} d at {m[1]} vs bar {bar} d: {'PASS' if m[0] >= bar else 'FAIL'}"
              f"   (record {rec['min']} d at {rec['argmin']}: {'==' if rec_ok else 'DIFFERS -- information; the bar is the gate'})")
    ctrl = min(digits_cr(V.endpoint(i, V.L[i]), fx['goal30'][(mi, 0)]) for mi, i in enumerate(V.TOP))
    print(f"   eps^+0 control vs the goal-30 record: {ctrl:.2f} d (record {G['floors']['0']['min']} d)")
    ok = all(floors[n][0] >= bar for n in orders)
    EPS12_STATE.update({'values': vals, 'floors': {n: floors[n][0] for n in orders}, 'members': members, 'ok': ok, 'orders': orders,
                        'pair': EPS12_PAIR_REF is not None, 'control': ctrl})
    word = 'ESTABLISHED' if ok else 'NOT ESTABLISHED'
    print(f"   EPS^1,2 GATE (--kmax {ARGS.kmax}): " + ", ".join(f"eps^{n:+d} {floors[n][0]:.2f} d" for n in orders)
          + f" vs bar {bar} d over {'four' if EPS12_PAIR_REF is not None else 'three'} references x 3 masters -> {word}"
          + ("" if 2 in orders else " (eps^+2 needs --kmax 5)")
          + ("" if EPS12_PAIR_REF is not None else "; the two-precision pair by --dps-double"))
    print(f"   record: eps^+1 {G['VERDICT']['eps1_min_d']} d, eps^+2 {G['VERDICT']['eps2_min_d']} d, control {G['VERDICT']['eps_-4..0_control_min_d']} d "
          f"({G['VERDICT']['eps12_layers']}; eng dps {'/'.join(str(k) for k in G['walls_s'])}, NC 220; walls {G['walls_s']})")
    print("   labels:")
    for l in R['labels']:
        print(f"      - {l}")
    if not ok:
        bad = "; ".join(f"{m[1]} {m[0]:.2f} d" for n in orders for m in members[n] if m[0] < bar)
        print(f"EPS^1,2 FAIL by name: below the bar {bar} d: {bad}"
              + (" (the planted digit of --mutate-eps12)" if ARGS.mutate_eps12 else ""))
        sys.exit(1)


def run_dps_double_255():
    """--kmax K --dps-double (K >= 4): the two-precision pair of the eps^1, eps^2 gate -- Check 2 twice, the DEEPER pass
    first (2x dps), then the requested dps whose gate reads the deeper pass as its fourth reference (the engine library's
    constant registry is per process: a coarser re-registration is tolerated, a finer one is refused)."""
    global ENG_DPS, EPS12_PAIR_REF
    d0 = ARGS.dps; d1 = 2 * d0
    print(f"== two-precision pair of the eps^1, eps^2 gate (--kmax {ARGS.kmax} --dps-double): Check 2 at dps={d1} "
          f"(engine {max(d1 + ENG_GUARD, 80)}) first, then at dps={d0} (engine {max(d0 + ENG_GUARD, 80)}), same NC={ARGS.vop_nc} ==\n")
    mp.mp.dps = d1; ENG_DPS = max(d1 + ENG_GUARD, 80)
    t0 = time.time(); g1, live1, V1 = run_sec255_live(); tp1 = time.time() - t0
    EPS12_PAIR_REF = {'values': dict(EPS12_STATE['values']), 'live': live1, 'dps': d1, 'eng': ENG_DPS}
    del V1
    mp.mp.dps = d0; ENG_DPS = max(d0 + ENG_GUARD, 80)
    t0 = time.time(); g2, live2, V2 = run_sec255_live(); tp2 = time.time() - t0
    print("== two-precision summary ==")
    print(f"   working precision {d1} -> {d0} dps (engine {EPS12_PAIR_REF['eng']} -> {ENG_DPS}; wall {tp1:.1f} s -> {tp2:.1f} s)")
    wp = min(digits_cr(live1[k], live2[k]) for k in live2)
    print(f"   eps^-4..eps^0 pair, min over the 15 coefficients: {wp:.2f} d (independent-oracle agreement {g1:.2f} / {g2:.2f} d: the served strings cap it)")
    for n in EPS12_STATE['orders']:
        pm = [m for m in EPS12_STATE['members'][n] if 'pair' in m[1]]
        print(f"   eps^{n:+d} pair, min over the 3 masters: {min(pm)[0]:.2f} d; the gate's floor over four references {EPS12_STATE['floors'][n]:.2f} d")
    print(f"   verdict: {'ESTABLISHED' if EPS12_STATE['ok'] else 'NOT ESTABLISHED'} (the gate line above; the record's pair floors "
          f"{ {n: EPS12_FIX['gate']['floors'][str(n)]['members'] for n in EPS12_STATE['orders']} } are the per-master minima over all four references)")
    return g1, g2


# ============================================================================
# Check 2 -- sec255 top sector: LIVE block-analytic VoP layer recursion on the
# exact rational graded path DE (the layer-recursion engine, hexabox_vop.py).
# ============================================================================
def orc_series(mi):
    return {int(k): mpc_of(v) for k, v in DATA["sec255"]["oracle_deep60"][f"m{mi}"].items()
            if not k.startswith('_')}

def run_sec255_live(bar=45.0):
    # bar semantics: the DEEP bar 45.0 is unchanged
    # for the default check demo. The --point --sec 255 route passes
    # bar = min(45, --dps) (FAST MODE): the independent comparison then RAISES with the
    # strict-greater slack pattern (worst > bar strictly AND worst relative
    # deviation < 10^-bar/2, directed-rounding slack; at-bar => FAIL) — same
    # refusal semantics, scaled to the requested target.
    print("== Check 2: sec255 TOP SECTOR -- LIVE VoP layer recursion on the exact rational path DE ==")
    from hexabox_vop import Vop255
    t0 = time.time()
    dps_outer = mp.mp.dps
    mp.mp.dps = ENG_DPS  # BUG FIX 2026-07-05: was HARDCODED 80, silently
    #                      overriding --dps.  ENG_DPS = max(--dps+ENG_GUARD, 80) tracks the
    #                      caller's precision; the boundary-seed PSLQ *naming* stays pinned
    #                      at 80 dps inside the engine (NAMING_DPS: string-
    #                      length-bound, re-certified downstream by the zero-remainder
    #                      exact-DE certificates + the independent checks below)
    V = Vop255(regen_bundle_path() if ARGS.boundary_regenerate else os.path.join(STAGE_DIR, "hexabox-vop-data.json.gz"),
               log=lambda m: print("   " + m))
    print(f"   sunrise closed containers vs fit-point seed: max err {mp.nstr(V.sunrise_t0_err, 3)} (analytic sources OK)")
    # EPS^1, EPS^2 SUCCESSION (2026-09-07): the succeeded bundle's record layer, declared on the engine by sha
    declare_record_layer(V)
    # REACH CHECK (2026-09-07): the per-row k_min table + the reach summary, once, right after the loader;
    # a coupling's layer absent within the reach of --kmax refuses by name here, before any layer is computed
    try:
        V.reach_check(ARGS.kmax, report=True)
    except RuntimeError as e:
        if not str(e).startswith("VoP reach:"):
            raise
        print(f"   REFUSED by name -- {e}")
        sys.exit(1)
    # Tier 1: fully-expanded exact symbolic closed forms, layers -4..0
    V.close_symbolic(0)
    cert = V.de_certificate(V.TOP, 0)
    for (i, k) in sorted(cert):
        nt, ok = cert[(i, k)]
        lab = {-1: 'eps^-4', 0: 'eps^-3'}[k]
        print(f"   Tier-1 exact form n[{i},{k}] ({lab}): {nt} terms, "
              f"zero-remainder exact-DE certificate: {'PASS' if ok else 'FAIL'}")
        assert ok, f"exact-DE certificate FAILED for n[{i},{k}]"
    # Tier 2: layered spectral evaluation to eps^0 (layers -4..3).
    # Refine-until-bound (2026-07-05): --vop-nc is a STARTING guess; the top-sector
    # solution tables must pass the trailing-window spectral tail bound at
    # 10^-(min(dps,CERT_CAP_255)+TAIL_GUARD) or NC grows x1.5 (same recursion, refined)
    # up to NC_CAP_MULT*NC0, then RuntimeError.
    NC0 = ARGS.vop_nc
    tol255 = _ttol(CERT_CAP_255, dps_outer)
    NC = NC0
    while True:
        V.setup_engine(NC)
        print(f"   spectral contour: {V.NSEG} segments (detours at path poles + "
              f"VoP basis-crossing zeros {V.det_roots}), NC={NC}")
        V.run_numeric(ARGS.kmax)
        assert V.hybrid_used == [] and len(V.HYBRID) == 0, V.hybrid_used   # every tier: no numeric kernel in the bundle
        worstb, wkey = V.top_table_bound(TAIL_WINDOW)
        if worstb < tol255:
            break
        NCn = int(mp.ceil(mp.mpf(3)*NC/2))
        if NCn > NC_CAP_MULT*NC0:
            raise RuntimeError(
                f"sec255 recursion NOT certified: solution-table tail bound "
                f"{mp.nstr(worstb, 3)} >= tol {mp.nstr(tol255, 3)} "
                f"(=10^-(min(dps,{CERT_CAP_255})+{TAIL_GUARD})) at table {wkey}, NC={NC}; "
                f"refusing NC={NCn} > cap {NC_CAP_MULT}*{NC0}={NC_CAP_MULT*NC0}")
        print(f"   [BOUND] sec255 refine: table {wkey} bound {mp.nstr(worstb, 3)} >= tol "
              f"{mp.nstr(tol255, 3)} at NC={NC} -> escalating to NC={NCn} (cap {NC_CAP_MULT*NC0})")
        NC = NCn
    V.cert_worst, V.cert_tol, V.cert_key = worstb, tol255, wkey
    if ARGS.boundary_regenerate:
        kl = REGEN_STATE['kept_low']
        print("   NOTE: every kernel of this recursion is an exact rational (the bundle's exactA; the three (97,0,m) layers equal the")
        print(f"   vendored object of vendor_row24_kernels/, asserted) and the {REGEN_STATE['replaced']} covered seeds are the from-definition strings (vendor_row24_seeds/);")
        print(f"   the input cap of this recursion is min(the seed certificate >= {REGEN_STATE['min_sigdigits']} d on the "
              f"{REGEN_STATE['replaced']} replaced cells, the served floor {REGEN_STATE['served_vs_fromdef_min']:.2f} d measured over the "
              f"{REGEN_STATE['n_significant']} covered components and bounding the {kl['long']} significant components of {kl['long_cells']} kept cells at " + " / ".join(f"eps^{o}" for o in sorted(kl['rows'], key=int))
              + f" that still carry the served 70-digit strings) = {REGEN_STATE['input_cap']:.2f} d until those components are entered "
              f"exactly; the oracle comparison below stays capped by the oracle's 60 digits.")
        print(f"   regenerated bundle of this run: {REGEN_STATE['regen_path']} (not removed by this tool)")
    else:
        print("   NOTE: every kernel of this recursion is an exact rational; the stored boundary-seed strings")
        print("   (50 / 70 digits) cap endpoint agreement above eps^-4 (--boundary-regenerate replaces the 447 covered seeds).")
    print(f"   recursion wall time: {time.time()-t0:.1f} s")
    print(f"   [BOUND] sec255 top-sector solution tables certified: worst trailing-{TAIL_WINDOW} "
          f"spectral tail bound {mp.nstr(worstb, 3)} (table {wkey}) < tol {mp.nstr(tol255, 3)} "
          f"= 10^-(min(dps,{CERT_CAP_255})+{TAIL_GUARD})   [ENG_DPS={ENG_DPS} tracks --dps={dps_outer}]")
    # independent comparison: all 15 Laurent coefficients, digits computed live
    worst = float("inf"); live = {}
    for mi, i in enumerate(V.TOP):
        orc = orc_series(mi)
        for n in range(-4, 1):
            pr = V.endpoint(i, n + V.L[i])       # layer k = eps order + L_i
            live[(mi, n)] = pr
            _, drel = digits(pr, orc[n])
            worst = min(worst, drel)
            print(f"   m{mi}_eps{n:+d}: this work (recursed HERE) {mp.nstr(pr, 24):<34s} "
                  f"independent deep-60 oracle {mp.nstr(orc[n], 24):<34s} agree {drel:6.2f} d (live)")
            # strict-greater + directed-rounding slack (at-bar => FAIL, raises)
            _rel = abs(pr - orc[n]) / abs(orc[n])
            assert drel > bar and _rel < mp.mpf(10)**(-bar)/2, \
                (f"sec255 check FAILED at m{mi}_eps{n}: {drel:.2f} d <= bar "
                 f"{bar} d (strict; rel {mp.nstr(_rel, 3)} vs 10^-bar/2 "
                 f"{mp.nstr(mp.mpf(10)**(-bar)/2, 3)})")
    # interior kinematic point: these are functions of t, not endpoint lookups
    s_int, k_int = 1, V.NC//2
    z_int, _ = V.node_value(V.TOP[0], -1, s_int, k_int)
    kin = {v: float(PFIT[v] + mp.re(z_int)*(GATE[v]-PFIT[v])) for v in VARS}
    print(f"   interior path point t={mp.nstr(mp.re(z_int),4)} "
          f"(s45,s15,m^2)=({kin['s45']:.3f},{kin['s15']:.3f},{kin['mm']:.3f}):")
    for mi, i in enumerate(V.TOP):
        _, v4 = V.node_value(i, -1, s_int, k_int)
        _, v0 = V.node_value(i, 3, s_int, k_int)
        print(f"     m{mi}[eps^-4](t) = {mp.nstr(v4, 18)}   m{mi}[eps^0](t) = {mp.nstr(v0, 18)}"
              f"   (function values; no oracle exists there)")
    print(f"   -> min over 15 coefficients: {worst:.2f} d, ALL COMPUTED IN THIS RUN\n")
    # EPS^1, EPS^2 SUCCESSION (2026-09-07): with --kmax 4 / 5 the recursion reached eps^1 / eps^2 of the top sector --
    # gated here against the served strings and the vendored records (the gate of record's rule)
    if ARGS.kmax >= 4:
        run_eps12_gate(V)
        print()
    mp.mp.dps = dps_outer
    return worst, live, V

# ============================================================================
# Check 3a -- exact eps^-4 / eps^-3 Laurent coefficients as FUNCTIONS of the
# path kinematics (Section 2a of hexabox-expression.md, derived live).
# ============================================================================
def run_exact_functions(live, V, bar_orc=30.0, bar_x=30.0):
    print("== Check 3a: exact eps^-4/eps^-3 coefficients as FUNCTIONS of (s45,s15,m^2) on the path ==")
    from hexabox_vop_lib import CONSTS
    dps_outer = mp.mp.dps
    mp.mp.dps = ENG_DPS                  # engine precision (matches Check 2)
    #                                      BUG FIX 2026-07-05: was hardcoded 80
    # live re-derivation of the sunrise residue: eps*c(eps)|_{eps=0} = 1/4
    q14 = mp.taylor(lambda e: -mp.gamma(1-e)**3*mp.gamma(1+2*e)
                    / (2*(2*e-1)*mp.gamma(3-3*e)), 0, 2)[0]
    assert abs(q14 - mp.mpf(1)/4) < mp.mpf(10)**-70   # = -1/(2*(-1)*Gamma(3)) = 1/4 exactly
    worst = float("inf"); worst_x = float("inf")
    for mi, i in enumerate(V.TOP):
        # (a) audit: eps^-4 container constants are ALL exact rationals
        C = V.NCF[(i, -1)]
        for (tag, rad, word), r in C.items():
            if tag == '1':
                continue                 # coefficient is an exact fmpq Rat
            assert tag.startswith('SUN') and tag.endswith('k-1q0'), \
                f"non-rational constant {tag} in eps^-4 container"
            assert abs(CONSTS[tag] - q14) < mp.mpf(10)**-70
        dw = sorted({w for (_, _, w) in C}, key=len)
        nrad = len({rd for (_, rd, _) in C if rd})
        print(f"   m{mi}[eps^-4](t): {len(C)}-term exact iterated integral, "
              f"{len(dw)} distinct words (max depth {len(dw[-1])}), {nrad} radical(s); "
              f"constants ALL exact rationals (sunrise residue 1/4) -- ZERO numeric seeds")
        # (b) evaluate the FUNCTION per-word at the verification endpoint t=1 (live)
        v1 = V.eng.eval_cf_end(C)
        orc = orc_series(mi)[-4]
        _, d_orc = digits(v1, orc)
        num, den = (int(u) for u in DATA["sec255"]["eps4_rationals"][f"m{mi}"].split('/'))
        d_rat = digits(v1, mp.mpc(mp.mpf(num)/mp.mpf(den), 0))[1]
        worst = min(worst, d_orc)
        print(f"      function(t=1) = {mp.nstr(v1, 24)}: vs independent oracle {d_orc:.1f} d | "
              f"vs named {num}/{den} {d_rat:.1f} d  (per-word eval, NC-limited)")
        assert d_orc >= bar_orc and d_rat >= bar_orc
    # (c) interior kinematic point: the same exact function, two INDEPENDENT
    #     evaluation routes (per-word quadrature vs Tier-2 layered tables)
    tq = mp.mpf(3)/4
    kin = {v: float(PFIT[v] + tq*(GATE[v]-PFIT[v])) for v in VARS}
    print(f"   interior point t=3/4, (s45,s15,m^2)=({kin['s45']:.3f},{kin['s15']:.3f},{kin['mm']:.3f}):")
    for mi, i in enumerate(V.TOP):
        va = V.eng.eval_cf(V.NCF[(i, -1)], mp.mpc(tq))    # per-word route
        vb = V.value_at(i, -1, mp.mpc(tq))                # Tier-2 spectral route
        _, dx = digits(va, vb)
        worst_x = min(worst_x, dx)
        print(f"      m{mi}[eps^-4](3/4) = {mp.nstr(va, 24)}   two routes agree {dx:.1f} d (live)")
        assert dx >= bar_x
    # (d) eps^-3: same exact construction; census its constant content honestly
    C3 = V.NCF[(V.TOP[0], 0)]
    tags = {t for (t, _, _) in C3}
    nB = len([t for t in tags if t.startswith('B') and not t.startswith('SUN')])
    nS = len([t for t in tags if t.startswith('SUN')])
    nL = len([t for t in tags if t.startswith('log') or t == 'ipi'])
    dw3 = max(len(w) for (_, _, w) in C3)
    print(f"   m_i[eps^-3](t): {len(C3)}-term exact container (word depth <= {dw3}), zero-remainder")
    print(f"      DE-certified in Check 2; constants: rationals + {nL} log/i*pi + {nS} sunrise")
    print(f"      Gamma-Taylor values (all closed-form, computed live) + {nB} NAMED fit-point")
    print(f"      boundary literals -- transport seeds (~65-70 d strings), NOT closed forms;")
    print(f"      they cap eps^-3-and-above endpoint agreement (disclosed, Section 2a/6).")
    print(f"   -> eps^-4 exact-function check: min {worst:.1f} d vs independent oracle;")
    print(f"      route cross-check at t=3/4: min {worst_x:.1f} d (both live)\n")
    mp.mp.dps = dps_outer
    return worst, worst_x

# ============================================================================
# Check 3b -- named boundary constants (exact rationals / pi-rationals),
# verified live against BOTH the live recursion and the independent oracle.
# ============================================================================
def run_closed_forms(live, bar_live=40.0, bar_orc=45.0):
    print("== Check 3b: named top-sector constants -- exact rationals + pi-rationals, evaluated live ==")
    S = DATA["sec255"]
    worst = float("inf")
    for mi in range(3):
        num, den = (int(u) for u in S["eps4_rationals"][f"m{mi}"].split('/'))
        cf = mp.mpf(num)/mp.mpf(den)
        d_orc  = digits(mp.mpc(cf, 0), orc_series(mi)[-4])[1]
        d_live = digits(mp.mpc(cf, 0), live[(mi, -4)])[1]
        worst = min(worst, d_orc)
        print(f"   m{mi}[eps^-4] = {num}/{den}: vs independent oracle {d_orc:.1f} d | "
              f"vs live recursion {d_live:.1f} d (NC-limited)")
        assert d_orc >= bar_orc and d_live >= bar_live
    # UT basis: ghat = diag(sqrt45709, sqrt45709, 1) . T(eps) . (m0,m1,m2)
    UT = S["ut"]
    T0 = [[mpc_of(UT["T0"][i][j]) for j in range(3)] for i in range(3)]
    T1 = [[mpc_of(UT["T1"][i][j]) for j in range(3)] for i in range(3)]
    SQ = mp.sqrt(mp.mpf(UT["sqrt_of"]))
    HATS = [SQ, SQ, mp.mpf(1)]
    for src_name, series, bar in (("independent oracle", [orc_series(mi) for mi in range(3)], bar_orc),
                                  ("live recursion", [{n: live[(mi, n)] for n in range(-4, 1)}
                                                      for mi in range(3)], bar_live)):
        wsrc = float("inf")
        for i in range(3):
            g4 = HATS[i]*sum(T0[i][j]*series[j][-4] for j in range(3))
            g3 = HATS[i]*sum(T0[i][j]*series[j][-3] + T1[i][j]*series[j][-4] for j in range(3))
            num, den = (int(u) for u in UT["eps4_rationals"][i].split('/'))
            d4 = digits(g4, mp.mpc(mp.mpf(num)/mp.mpf(den), 0))[1]
            numi, deni = (int(u) for u in UT["eps3_im_over_pi"][i].split('/'))
            v3 = mp.pi*mp.mpf(numi)/mp.mpf(deni)          # pi-rational, computed live
            d3 = float(-mp.log10(abs(mp.im(g3) - v3)/abs(v3)))
            wsrc = min(wsrc, d4, d3)
            if src_name == "independent oracle": worst = min(worst, d4, d3)
            print(f"   ghat{i}[eps^-4] = {num}/{den}: {d4:.1f} d | "
                  f"Im(ghat{i}[eps^-3])/pi = {numi}/{deni}: {d3:.1f} d   (vs {src_name})")
            assert d4 >= bar and d3 >= bar
    print(f"   -> six named boundary constants, min {worst:.1f} d vs independent oracle (live);")
    print("      these are the t=1 endpoint values of the Tier-1 exact functions of Check 2.\n")
    return worst

# ============================================================================
# Check 4 -- sec223 orbit: ARCHIVED transport outputs (Known gap: not final
# form; not re-run here), live relative digits vs the independent oracle.
# ============================================================================
def run_sec223(bar=30.0):
    print("== Check 4: sec223 orbit, 3 masters x eps^-3..eps^2 -- ARCHIVED transport vs independent oracle ==")
    print("   Second-point check (2026-07-04, archived): at t=7/9 all 18 coefficients")
    print("   agreed with a fresh independent evaluation to 33.06-34.93 digits, the")
    print("   prediction recorded BEFORE the reference was read.")
    print("   Known gap: 'this work' = archived output of the multi-layer Taylor")
    print("   transport of this work (archived artifact). The transport is NOT re-run in")
    print("   this script (no eps-linear rescale exists for this orbit; the live recast is")
    print("   open). Only the agreement digits below are computed live.")
    worst = float("inf")
    for lab, row in DATA["sec223"].items():
        if lab.startswith('_'): continue
        pr, orc = pmc(row["pred"]), pmc(row["oracle"])
        _, drel = digits(pr, orc)
        worst = min(worst, drel)
        print(f"   {lab:>9s}: agree {drel:6.2f} d (live)")
        assert drel >= bar, f"sec223 check FAILED at {lab}: {drel:.2f} d < {bar} d"
    print(f"   -> min over 18 coefficients: {worst:.2f} d (all >= {bar} d)\n")
    return worst

# ============================================================================
# Evaluation interface: --point / --dps / --dps-double (see module docstring).
# ============================================================================
def parse_point(spec):
    """--point argument -> path parameter t. Accepts a bare t or the kinematic
    form s45=..,s15=..,mm=.. which must lie ON the shipped path (domain limit:
    the final form is a function on the one-parameter path, not of 6 free
    invariants; off-path points are rejected with the constraint printed)."""
    if '=' in spec:
        try:
            kv = dict(p.split('=') for p in spec.split(','))
        except ValueError:
            sys.exit("--point kinematic form: s45=..,s15=..,mm=..")
        if set(kv) != {'s45', 's15', 'mm'}:
            sys.exit("--point kinematic form needs exactly s45=..,s15=..,mm=.. "
                     "(s12,s23,s34 are fixed at -3,-5,-7 on the shipped path)")
        t = (mp.mpf(kv['s45']) - PFIT['s45'])/(GATE['s45'] - PFIT['s45'])
        for v in ('s15', 'mm'):
            expect = PFIT[v] + t*(GATE[v] - PFIT[v])
            if abs(mp.mpf(kv[v]) - expect) > mp.mpf('1e-9')*(1 + abs(expect)):
                sys.exit(f"point is OFF the shipped path: {v}={kv[v]} but the path gives "
                         f"{v}={mp.nstr(expect, 12)} at t={mp.nstr(t, 12)}. Domain = the line "
                         "(s45,s15,mm) = (-2,-11,1) + t*(-9,-6,1), t in [0,1].")
        return t
    return mp.mpf(spec)

def run_point_219(tq):
    print(f"== --point: sec219 row-0 final form at path point t = {mp.nstr(tq, 12)} "
          f"(dps={mp.mp.dps}, NC={ARGS.nc}) ==")
    kin = {v: PFIT[v] + tq*(GATE[v]-PFIT[v]) for v in VARS}
    print("   kinematics: " + ", ".join(f"{v}={mp.nstr(mp.mpf(kin[v]), 12)}" for v in VARS))
    t0 = time.time()
    _, van, _, evalfn, cert = transport_219(ARGS.nc)
    try:
        vals, repb = evalfn(tq)
    except ValueError as e:
        sys.exit("   DOMAIN: " + str(e))
    print(f"   transported eps-form + spectral interpolation in {time.time()-t0:.1f} s "
          f"(eps^-3 identity floor {min(van):.1f} d, live)")
    for n in range(-2, 3):
        print(f"   m219_row0[eps^{n:+d}](t) = {mp.nstr(vals[n], 30)}")
    T00q = mp.sqrt(mp.mpc(LAM['G5'](tq))/G5_0)
    print(f"   [BOUND] certified truncation bounds at t (transport, L1-propagated, cert pass "
          f"at dps+{CERT_PAD}; + representation tail of the interpolated table): " +
          ", ".join(f"eps^{n:+d} {mp.nstr(cert['E0'][n]/abs(T00q) + repb[n], 3)}"
                    for n in range(-2, 3)))
    print(f"   [BOUND] transport component < tol {mp.nstr(cert['tol'], 3)} "
          f"= 10^-(min(dps,{SEED_CAP_219})+{TAIL_GUARD}) (certified in the refine loop, NC={cert['NC']})")
    if abs(tq - 1) < mp.mpf('1e-12'):
        HO = {int(k): mpc_of(v) for k, v in DATA["sec219"]["heldout_oracle_row0"].items()
              if not k.startswith('_')}
        for n in range(-2, 3):
            print(f"      t=1 is the verification point: eps^{n:+d} agrees with the independent oracle "
                  f"to {digits(vals[n], HO[n])[1]:.2f} d (live)")
    elif abs(tq) < mp.mpf('1e-12'):
        print("   (t=0 is the fit point: these reproduce the INPUT boundary seed, not a check)")
    else:
        print("   (function values -- no stored oracle exists at interior points; the")
        print("    comparison at t=1 is what the default run checks)")

def run_point_255(tq):
    # cheap domain pre-check (bundle path poles +- the contour pad) BEFORE the
    # ~6-minute live closure; the exact contour check happens again below.
    import gzip
    _rp = json.loads(gzip.open(os.path.join(STAGE_DIR, "hexabox-vop-data.json.gz"), 'rb')
                     .read())["real_poles"]
    if not (0 <= float(tq) <= 1) or any(abs(float(tq) - p) < 0.0401 for p in _rp):
        sys.exit(f"   DOMAIN: t={mp.nstr(tq, 12)} is outside [0,1] or inside a detour window "
                 f"around a real path pole {sorted(_rp)} (+-0.04); see docstring DOMAIN")
    # the sec255 final form is re-derived live (certificates + independent check),
    # then interpolated at tq on the same spectral contour. FAST MODE
    # (2026-07-07): the pass bar scales to the requested target,
    # bar = min(45, --dps), strict-greater slack; the deep default-demo bar
    # (45 d) is unchanged. At --dps 30 with the auto vop-nc floor this is the
    # documented 30d fast mode (see docstring).
    _, _, V = run_sec255_live(bar=min(45.0, float(ARGS.dps)))
    print(f"== --point: sec255 top-sector final form at path point t = {mp.nstr(tq, 12)} ==")
    dom = V.real_domain()
    print("   real-t domain of the shipped contour: " +
          " U ".join(f"[{a:.3f},{b:.3f}]" for a, b in dom))
    if not any(a - 1e-12 <= float(tq) <= b + 1e-12 for a, b in dom):
        sys.exit("   DOMAIN: t=%s is inside a detour window (VoP basis-crossing zeros widen "
                 "the pole windows); allowed real t printed above" % mp.nstr(tq, 12))
    kin = {v: PFIT[v] + tq*(GATE[v]-PFIT[v]) for v in VARS}
    print("   kinematics: " + ", ".join(f"{v}={mp.nstr(mp.mpf(kin[v]), 12)}" for v in VARS))
    dps_outer = mp.mp.dps
    mp.mp.dps = ENG_DPS  # node tables were built at this precision in Check 2
    #                      (BUG FIX 2026-07-05: was hardcoded 80, overriding --dps)
    for mi, i in enumerate(V.TOP):
        for n in range(-4, 1):
            val = V.value_at(i, n + V.L[i], mp.mpc(tq))
            print(f"   m{mi}[eps^{n:+d}](t) = {mp.nstr(val, 24)}")
    mp.mp.dps = dps_outer
    print(f"   [BOUND] solution tables certified in the live closure above: worst trailing-"
          f"{TAIL_WINDOW} spectral tail bound {mp.nstr(V.cert_worst, 3)} < tol "
          f"{mp.nstr(V.cert_tol, 3)} (spectral interpolation at the same order)")
    print("   (function values; precision grows with --vop-nc up to the 70-digit fit-point")
    print("    seed strings; every kernel of this tier is an exact rational, the (97,0,2..4)")
    print("    layers included -- --point is refused with --boundary-regenerate)")

def run_dps_double():
    d0 = ARGS.dps
    print(f"== dps-doubling demo: sec219 verification point at dps={d0}, then dps={2*d0} "
          f"(same NC={ARGS.nc}) ==\n")
    t0 = time.time(); w1, dd1, van1, _ = run_sec219(); tp1 = time.time() - t0
    mp.mp.dps = 2*d0
    _build_eps_consts()      # rebuild the dps-dependent constants at 2x dps
    t0 = time.time(); w2, dd2, van2, _ = run_sec219(); tp2 = time.time() - t0
    print("== dps-doubling summary ==")
    print(f"   working precision {d0} -> {2*d0} dps    (wall {tp1:.1f} s -> {tp2:.1f} s)")
    print(f"   live structural-zero identity floor: {van1:.1f} d -> {van2:.1f} d")
    print("     -> GROWS with dps: the machinery is analytic end-to-end, nothing in it")
    print("        bottoms out in stored floats.")
    print("   independent-oracle agreement per order (STORED-STRING CAPS, printed explicitly):")
    print(f"     eps^-2: {dd1[-2]:6.2f} -> {dd2[-2]:6.2f} d   CAP: the 65-digit independent oracle")
    print("             and row-0 seed strings in hexabox-data.json -- already saturated.")
    for n in range(-1, 3):
        print(f"     eps^{n:+d}: {dd1[n]:6.2f} -> {dd2[n]:6.2f} d", end="")
        print("   CAP: 50-digit stored fit-point seed strings (rows 1-13)," if n == -1 else "")
    print("             propagated through the layered recursion (measured NC- and dps-stable:")
    print("             identical at NC=160, so quadrature and arithmetic are NOT the limit).")
    print("   To grow the endpoint agreement past these caps, re-derive the seeds/oracle at higher")
    print("   precision (AMFlow at the fit point) -- the transport itself does not cap.")
    return w1, w2

if __name__ == "__main__":
    if ARGS.gatepoint:
        run_gatepoint()                 # strings only; exits
    if ARGS.kmax >= 4:
        EPS12_FIX = succession_pins()   # the pins before any check runs (missing -> exit 4, mismatch -> exit 3)
    if ARGS.point is not None:
        tq = parse_point(ARGS.point)
        if ARGS.sec in ('219', 'both'):
            run_point_219(tq)
        if ARGS.sec in ('255', 'both'):
            run_point_255(tq)
        print(f"Total wall time: {time.time()-T_START:.1f} s")
    elif ARGS.dps_double:
        if ARGS.kmax >= 4:
            run_dps_double_255()
        else:
            run_dps_double()
        print(f"Total wall time: {time.time()-T_START:.1f} s")
    else:
        g219, _, _, _ = run_sec219()
        g255, live, _V = run_sec255_live()
        gfun, gxr = run_exact_functions(live, _V)
        gcf  = run_closed_forms(live)
        g223 = run_sec223()
        print("All checks passed. Every digit count above was measured in this run.")
        print(f"sec219 min independent check, transported live:          {g219:.2f} d")
        print(f"sec255 top-sector 15-coefficient check, recursed live:   {g255:.2f} d")
        print(f"eps^-4 exact functions (zero seeds) vs independent oracle: {gfun:.1f} d")
        print(f"Named boundary constants vs independent oracle, live:    {gcf:.1f} d")
        print(f"sec223 18-coefficient check (archived transport values): {g223:.2f} d")
        if ARGS.kmax >= 4:
            print("sec255 eps^1, eps^2 gate on the succeeded bundle, recursed live: "
                  + ", ".join(f"eps^{n:+d} {EPS12_STATE['floors'][n]:.2f} d" for n in EPS12_STATE['orders'])
                  + f" ({'ESTABLISHED' if EPS12_STATE['ok'] else 'NOT ESTABLISHED'}; bar {SUCCESSION['bar']} d)")
        if ARGS.boundary_regenerate:
            print(f"sec255 recursion on regenerated inputs (--boundary-regenerate): the (97,0,2..4) kernels exact, "
                  f"{REGEN_STATE['replaced']} seeds from definition; seed certificate >= {REGEN_STATE['min_sigdigits']} d "
                  f"({REGEN_STATE['n_identical']}/{REGEN_STATE['n_tags']} tags identical at the two working precisions); "
                  f"served 70-digit seeds vs from-definition min {REGEN_STATE['served_vs_fromdef_min']:.2f} d; "
                  f"{REGEN_STATE['kept_low']['long']} kept significant components on {REGEN_STATE['kept_low']['long_cells']} cells keep the "
                  f"served 70-digit strings -> input cap {REGEN_STATE['input_cap']:.2f} d; "
                  f"the bundle's ({', '.join(REGEN['kernels'])}) layers equal the vendored exact object (asserted; no numeric kernel)")
        print("Not evaluated here: sec231/215/222 (the records in hexabox-expression.md")
        print("Section 2 only) and the sec223 transport itself (archived).")
        print(f"Total wall time: {time.time()-T_START:.1f} s")
