# SG-9 — Proton Safety (GUT Gate 10): Per-Gate Closure-Attack Dossier

> **What this is.** The closure-attack packet for **SG-9 (Proton safety / the $\mathcal{E}_{\rm proton}$ no-mediator
> layer)** on the **frozen 13D K₆ branch ONLY**. It recaps how our geometry sidesteps the proton-decay wall
> (concise; the full derivation lives on the published site), verifies where the status actually stands, names
> every open residual, and lays out the attack plan to push the gate further. It is **not** a rival comparison
> (that is `BATTLE_GATES/`), **not** the one-line status ledger, **not** a reprint of the manuscript.
>
> **Binding discipline (carry verbatim).** No status was ever upgraded. Frozen branch `dcc66f1b2685` / `a5b1e6f9d951`
> READ-ONLY. Honest throughout: the operator-level pass ($\Pi_q M \Pi_\ell = 0$) is **CANDIDATE-grade safety
> against the *declared* operator class, not a delivered absolute lifetime bound and not a theorem of all
> baryon physics**; the result is an operator-level **selection-rule pass evaluated GIVEN the selected product
> geometry + frozen labeling**, NOT a cross-geometry determination; dim-6 $B/L$-violating proton decay is a
> pressure **SHARED by all GUT-class geometries** (Battle-of-the-Geometries verdict: **SHARED-OPEN** — no
> Fable win, rivals neither cleared nor killed); in the SM, proton longevity is **partly an accidental
> symmetry**; the seesaw Majorana scale **$M_R$ is UNKNOWN/open** (the Weinberg/dim-5 leg has no frozen
> $\Lambda$); the numerical lifetime is **Diagnostic only** and excluded from the closure claim. Closure paths
> must be **non-target-loaded** (the κ³/π kill-test: a proposed axiom counts only if it would be written
> WITHOUT knowing the target). **given-E ≠ derivation of E.** AXIOM-CLOSED ≠ proven; selection ≠ derivation;
> dissolved ≠ solved; a *selection-rule pass on the declared class* ≠ a *proof of absolute proton safety*.

---

## 0. Header & Verdict

| Field | Value |
|---|---|
| **Gate id** | SG-9 — Proton safety (the $\mathcal{E}_{\rm proton}$ no-mediator layer) |
| **GUT manuscript gate** | Gate 10 (§6.10; narrative §5.9; certificate `certificates/G10_proton_safety/`) |
| **Status label (binding)** | **PARTIAL** |
| **Manuscript card status** | *Claimed certificate pass* (operator level, 10a) / *Diagnostic only* (lifetime, 10b) — the manuscript's own two-label split; PARTIAL is the honest scoped-GUT roll-up of it |
| **Frozen hashes it rides** | Branch `dcc66f1b2685` / manifest meta `a5b1e6f9d951`. Sector projectors $\Pi_u,\Pi_d,\Pi_e,\Pi_\nu$ `3b8d68559f5e` (R1.4); FCNC / mediator no-go theorem (full) `fff4b433b7b3` (R1.6); operator-class declaration hash `551488d06011` (R1.6); Cartan-torus modulus $\tau=\omega$ `03b30a9c931a` (chamber substrate for the sector split); global $\mathbb{Z}_6$ centre identification `a68ee92a75be` (drives macro-orthogonality via the gauge-rep factor); $\mathbb{Z}_2$ orbifold on $S^1_Y$ `ac4d2df3e708` (chirality / hypercharge routing in $\Pi_q,\Pi_\ell$); hypercharge bundle (no coloured-Higgs partner) `44516f6400ae`; proton-operator ledger CSV `bc1e4e84840a`. **Macro-projectors $\Pi_q,\Pi_\ell$, $Q_{\rm BRST}$, the no-mediator identity, empty-cohomology statement: derived / standard — no separate R1 hash.** **$M_R$ (seesaw Majorana scale): no hash — UNKNOWN/open** (`BG10-FROZEN-MR` in the axiom ledger). |
| **Target anchor(s)** | The **observed spectrum E** (the product backbone $K_{\rm gauge}=K_6\times S^2\times S^1_Y/\mathbb{Z}_2$ — **no GUT mediator** — plus the $\mathcal{E}_{\rm proton}$ projector; **DERIVED-GIVEN-E**) **+** the **measured Super-K proton-lifetime bound** ($\tau_p\gtrsim10^{34}$ yr, the observable the dim-6 suppression must clear). **Candidate-grade — no lifetime predicted.** Status: **OPEN** (declared-class completeness has no measured-invariant witness; the dim-6/7 census is the hardening move). See §A "🎯 Target anchor(s) for this gate." |

### 0.1 Abstract — established / open / what would close it

**Established (given-E, given the selected product geometry, given the frozen labeling).** The Standard-Model-routing
backbone is a **product** of compact factors, $K_{\rm gauge}=K_6\times S^2\times S^1_Y/\mathbb{Z}_2$ — **not** an
embedding into a single simple GUT group. Therefore there is **no off-diagonal $X/Y$ heavy gauge boson** connecting
quarks to leptons through one multiplet and **no coloured-Higgs triplet** (the Higgs is a Wilson-line $SU(2)_L$
doublet on $K_{\rm gauge}$, hypercharge bundle `44516f6400ae` carries no coloured partner). This is the structural
move that dissolves the failure mode that *executed* minimal $SU(5)$ ($\tau_p\sim10^{30}$ yr vs Super-K's $\sim10^{34}$ yr).
On top of the absence-of-mediator fact, the tenth load-bearing term $\mathcal{E}_{\rm proton}$ — frozen sector
projectors with macro-orthogonality $\Pi_q\Pi_\ell=0$ — delivers the **exact algebraic identity**
$\Pi_q M \Pi_\ell = 0$ for every sector-respecting $M$, so every Wilson coefficient in the **declared** dangerous
class ($QQQL$, $u^c u^c d^c e^c$, $QLu^c d^c$, $QQu^c e^c$, the dim-7 relatives, the $\bar d^c\bar d^c\bar u^c$
$n$-side channel) **vanishes identically** — a zero, not a tuned-small number. The spectator side doors are closed by
a two-channel decoupling: gauge-redundant KK components are BRST-exact (Channel A); physical transverse KK modes are
killed by KK-number conservation at tree level and by projector orthogonality at loop level (Channel B). The
machine certificate `G10_proton_safety/` checks $\Pi_q M \Pi_\ell = 0$ exactly on **25 randomized class members** and
confirms the falsifier fires (an $X$-like off-block entry → nonzero → FAIL).

**Open (the honest deductions).** (1) The pass is **operator-level only**, against a **declared** class
$\mathcal{O}_{\rm danger}^{\rm declared}$ — the certificate's own named falsifier is whether the projector identity
kills the **physically relevant** operator class or **only the declared one** (the "narrowed subclass" attack;
L.2a/L.2b). (2) It is a **selection-rule pass evaluated GIVEN the selected product geometry**, not a cross-geometry
determination: dim-6 $B/L$-violation is a pressure **SHARED** by every GUT-class geometry (Battle verdict
**SHARED-OPEN**; no Fable win). (3) The numerical lifetime is **Diagnostic only** (L.4) — it depends on hadronic
matrix elements, residual Wilson coefficients, and RG running that are **not frozen** to certificate standard; the
closure claim does **not** rest on it, and a reviewer who promotes it commits a status violation. (4) The dim-5
**Weinberg operator $(LH)(LH)/\Lambda$** is *Bounded*, but its scale $\Lambda$ is "the chamber's declared Majorana
scale" — and that scale is **$M_R$, which is UNKNOWN/open** (no value, no formula, no hash; it is the same floating
object that blocks SG-8's absolute neutrino scale). (5) The no-mediator identity is a **theorem** *given* the
projectors' orthogonality, but the orthogonality of $\Pi_q,\Pi_\ell$ on the actual active-branch matter bundle is
*asserted* at A2.6/A2.8 — its reproduction sits in the same AUDIT class as other certificate harnesses (the
`G10_proton_safety/` folder checks the identity on the frozen labeling but `reproduce_all.py` regeneration of the
full pipeline is province-of-the-bundle, not re-run here). (6) The Cartan-torus modulus $\tau=\omega$ that the sector
split rides is inherited from SG-6, where it is **read from a stabilization minimum** (the same soft spot SG-8
inherits).

**What would close it (the ladder).** DERIVED-CLOSED would require either (a) a **coverage theorem** proving the
declared class $\mathcal{O}_{\rm danger}^{\rm declared}$ is *physically complete* — i.e. every operator the Super-K
bound constrains is captured — turning the L.2b coverage table from an audited assertion into a closed statement; or
(b) a **computed $M_R$** from chamber data (discharging the dim-5 $\Lambda$ and the seesaw scale) so the Weinberg
leg becomes a prediction. The realistic ceiling per residual is **AXIOM-CLOSED**: name one explicit, target-blind
posit (e.g. "the dangerous class is exactly the sector-crossing four-fermion operators, and product-geometry
admissibility forbids all others"; or "the Majorana scale is the SG-7 unification scale $M_U$") that pays the debt
in plain sight. The most likely honest outcome on the central residual (declared-vs-physical class) is
**sharper-OPEN**, with the Battle verdict held at **SHARED-OPEN**.

### 0.2 Website source-of-truth (link, don't duplicate)

The full construction, the operator ledger, the three-ingredient no-go proof, the explicit BRST/KK algebra, and the
freeze records are the **published manuscript**, Paper I:

- **GUT.html §6.10** (Gate-10 card, binding status) — <https://physics.magflowmeters.com/articles/GUT.html>
- **§5.9** narrative module; **§6.12** falsification map (Gate 10 row); **§6.13** certificate-status summary;
  **Appendix CR, module CR10** ("Proton Safety as a Worked Constraint", CR10.1–CR10.14) — reader companion.
- **Appendix L** (Proton Safety certificate): L.0 authority + status/falsifier table; L.1 operator basis; L.2
  full operator ledger; **L.2a** declaration-before-elimination; **L.2b** coverage table; **L.3** FCNC / mediator
  no-go theorem (L.3.1 three-ingredient proof; L.3.2 explicit BRST/projector/Wilson algebra); L.4 lifetime
  diagnostic; L.5 safety-vs-prediction; L.6 experimental comparison; L.7 certificate JSON; L.9/L.9a failure
  conditions + migration.
- **Appendix C10** ($\mathcal{E}_{\rm proton}$ term authority card) — formal object, layer assignment, failure-if-removed,
  freeze-authority path, claim boundary.
- **Appendix A2** §A2.6 / §A2.8 / §A2.9 (sector projectors, macro-projectors $\Pi_q,\Pi_\ell$, $Q_{\rm BRST}$).
- **Appendix R0 / R1** freeze records + frozen parameter manifest (all hashes in §0 above).
- Downstream neutrino cross-reference: **Appendix K** (the Weinberg/Majorana-scale leg, $M_R$ UNKNOWN box);
  Paper IV, TOE.html — <https://physics.magflowmeters.com/articles/TOE.html> (boundary cross-ref only).

This dossier recaps only what is needed to attack; the site controls all common material.

---

## 1. How OUR geometry closes proton safety — the closure claim (concise)

> Full derivation: **GUT.html §6.10 + §5.9 + Appendix L + Appendix C10 + CR10**. This section is the attack-grade
> recap, not the derivation.

### 1.1 The mechanism end-to-end

Proton safety on the active branch is **not** secured by making a mediator heavy, and **not** by a global $U(1)_B$
symmetry. It is secured at two levels, one structural (the absence of a mediator) and one algebraic (an exact
selection rule). The implication chain (CR10.2 spine):

```
 product geometry  K_gauge = K_6 × S² × S¹_Y/Z₂   (NOT a simple-group embedding)
        ↓   no off-diagonal X/Y generator; no coloured-Higgs triplet
 sector projectors  Π_q , Π_ℓ   on  E_matter
        ↓   sector orthogonality of the chamber decomposition
 Π_q Π_ℓ = 0
        ↓   lift to the matter bundle; act with any sector-respecting mediator M
 Π_q M Π_ℓ = 0          (no-mediator identity — a THEOREM given orthogonality)
        ↓
 C_dangerous = 0   identically,  for every operator in the DECLARED class
        ↓
 operator-level proton safety   (Claimed certificate pass, 10a)
```

The load-bearing factors, named so a reader can attack each:

1. **Product-factor structure of $K_{\rm gauge}$ ($\times$-layer; C2/C3/C4; A1.4–A1.6).** The SM gauge algebra is the
   surviving **direct-sum** isometry $\mathfrak{su}(3)\oplus\mathfrak{su}(2)\oplus\mathfrak{u}(1)$ of a *product* of
   compact factors, not the residual of breaking a larger simple group. **Ingredient 1 of the no-go theorem is a
   $\times$-layer fact**: there is no off-diagonal generator connecting quarks to leptons through a single multiplet,
   and no $\mathbf{5}_H$-style coloured-Higgs triplet. (Attack handle: this is **why** there is no $X/Y$ — but
   "product not simple" is a *property of the selected geometry*, not a proof that a product geometry is *forced*;
   SG-1/SG-2 conditionality is inherited.)
2. **Sector projectors $\Pi_u,\Pi_d,\Pi_e,\Pi_\nu$ (`3b8d68559f5e`, R1.4).** Four rank-3 self-adjoint orthogonal
   idempotents on the generation module $\mathcal{G}_{\rm gen}=\mathrm{span}\{g_1,g_2,g_3\}$: $\Pi_i^\dagger=\Pi_i$,
   $\Pi_i^2=\Pi_i$, $\Pi_i\Pi_j=\delta_{ij}\Pi_i$, $\sum_i\Pi_i=\mathbb 1$. These are the **same** projectors that
   give SG-8's chamber operators their domain — proton safety and flavor share the sector decomposition. (Attack
   handle: orthogonality is *asserted* on the active-branch matter bundle at A2.6/A2.8 — see R5/R7 below.)
3. **Macro-projectors $\Pi_q=\Pi_u+\Pi_d+\Pi_{Q_L}$, $\Pi_\ell=\Pi_e+\Pi_\nu+\Pi_{L_L}$ on $\mathcal{E}_{\rm matter}$.**
   Derived (no separate hash); the doublet-component projectors $\Pi_{Q_L},\Pi_{L_L}$ come from the A2.3
   matter-bundle factorisation (orthogonal via gauge-bundle orthogonality $V_{\mathbf 3}\otimes V_{\mathbf 1}=0$).
   Macro-orthogonality $\Pi_q\Pi_\ell=0$ follows because the index sets $\{u,d,Q_L\}$ and $\{e,\nu,L_L\}$ are
   disjoint.
4. **The no-mediator identity $\Pi_q M \Pi_\ell = 0$ (theorem; R1.6 operator-class `551488d06011`).** One-line proof
   for any sector-respecting $M=\sum_i\Pi_i M_i\Pi_i$:
   $$\Pi_q M \Pi_\ell=\sum_i(\Pi_q\Pi_i)M_i(\Pi_i\Pi_\ell)=\sum_i\delta_{qi}\delta_{i\ell}\,\Pi_i M_i\Pi_i=0\quad(q\neq\ell).$$
   This is a **theorem given the projectors**, not an axiom — the manuscript is emphatic that asserting it without
   proof would collapse the certificate to a postulate (C10 §5; L.3.2 failure condition).
5. **The FCNC / mediator no-go theorem (full hash `fff4b433b7b3`, R1.6), closing the side doors.** Three ingredients:
   (1) mediator inventory — every candidate ($X/Y$, coloured Higgs, scalar leptoquark, spurious KK mediator,
   chamber-induced cross-sector mode) is absent or handled; (2) **Channel A** — gauge-redundant spectator components
   (longitudinal $A_\mu$, scalar $A_5$) are BRST-exact, decouple by Slavnov–Taylor; (3) **Channel B** — physical
   transverse KK modes (which are **not** BRST-exact — the manuscript explicitly refuses the blanket claim) are
   killed by KK-number conservation $\sum n_{\rm ext}=0$ at tree level and by projector orthogonality at loop level.
   Empty cross-sector cohomology $\Pi_i\mathcal{G}_{\rm gen}\cap\Pi_j\mathcal{G}_{\rm gen}=\{0\}$ for $i\neq j$.
6. **Declaration-before-elimination (L.2a) + coverage table (L.2b).** The certificate **declares**
   $\mathcal{O}_{\rm danger}^{\rm declared}$ = sector-respecting Wilson operators with one quark-sector leg and one
   lepton-sector leg, **before** the identity acts. L.2b then walks each familiar dangerous type and confirms it is
   "Covered," honestly marking sphalerons/Planck operators as **outside** the operator-class framework. (Attack
   handle: this two-part structure is the whole defence against the "you only killed a narrowed subclass" attack —
   and it is also exactly where the residual lives.)

### 1.2 What "closed" means here, and its conditionality

"Closed" for SG-9 is an **operator-level selection-rule pass on a declared dangerous class, given the selected
product geometry + frozen labeling** — strictly **not** a delivered absolute proton-lifetime bound, **not** a proof
that all conceivable baryon physics is safe, **not** a cross-geometry determination that *only* this branch is safe.
It is conditional on:

- **given-E** — the SM chiral content (and the family index $-3$) supplied from SG-2/SG-3; SG-9 acts on that
  content, it does not derive it.
- **given-the-selected-geometry** — the frozen 13D K₆ branch and, decisively, the **product** structure of
  $K_{\rm gauge}$ (Ingredient 1). The safety is a consequence of the product structure being *selected*, not of it
  being *forced over a simple-group rival* (the gauge-group outcome is itself a rival TIE per the SHAPE audit).
- **given-the-frozen-labeling** — the sector projectors' orthogonality on the matter bundle, asserted at A2.6/A2.8;
  the `G10_proton_safety/` certificate checks the identity *on that labeling*.
- **given-the-declared-class** — the pass is for $\mathcal{O}_{\rm danger}^{\rm declared}$; physical completeness of
  that class is an **audited claim** (L.2b), not a theorem.

**The genuine, defensible content** (the part that survives the honest accounting):

| Genuine output (frozen-structure / frozen-identity result) | Mechanism |
|---|---|
| **No simple-group $X/Y$ mediator; no coloured-Higgs triplet** on the active branch | product-factor $K_{\rm gauge}$ + Wilson-line doublet Higgs (Ingredient 1) |
| **Exact zero** Wilson coefficient for every declared dim-6 proton-decay operator | $\Pi_q M \Pi_\ell = 0$ (theorem given orthogonality) |
| **Side doors closed**: gauge-redundant KK BRST-exact; physical KK killed by KK-number + orthogonality | two-channel decoupling (L.3.2 Identity 1) |
| **Sphaleron-compatibility** (no global $U(1)_B$ invoked) | safety is operator-algebra, not symmetry |
| Machine check: identity exact on **25 randomized class members**; falsifier fires on $X$-like off-block entry | `certificates/G10_proton_safety/` |

**The conditional / non-genuine content** (CANDIDATE-grade or Diagnostic, per the ledger):

| Quantity | Honest reality |
|---|---|
| "the **physically relevant** dangerous class is eliminated" | **CANDIDATE-grade** — only the *declared* class is proven killed; physical completeness is an audited assertion (L.2b), the certificate's own named falsifier |
| absolute **proton lifetime** | **Diagnostic only** (L.4) — not frozen to certificate standard; excluded from the closure claim |
| dim-5 **Weinberg $\Lambda$** scale (and the seesaw scale) | **UNKNOWN/open** — $\Lambda = M_R$ has no value/formula/hash (`BG10-FROZEN-MR`) |
| "**this branch is uniquely safe**" | **not claimed** — dim-6 $B/L$-violation is SHARED-OPEN across all GUT-class geometries; this is a *filter*, not a *determiner* |

So the precise statement of closure: **the product geometry removes the $X/Y$ failure mode and the projector
identity makes the declared dangerous coefficients exactly zero — a genuine, non-trivial selection-rule pass — but
this is CANDIDATE-grade safety against a declared class, evaluated given the selected geometry, with the numerical
lifetime Diagnostic, the dim-5 Majorana scale unknown, and no claim that the safety is unique to this branch.**

---

## 2. Verify the status — is PARTIAL real?

This is the verification a skeptic would run. Each witness gets a grade — **hand-checkable** / **symbolic** /
**machine-lane** — and an honest **reproduces?** flag.

### 2.1 The witness ledger

| # | Witness | What it asserts | Grade | Reproduces? |
|---|---|---|---|---|
| W1 | **Product-factor $K_{\rm gauge}=K_6\times S^2\times S^1_Y/\mathbb{Z}_2$ → no $X/Y$, no coloured Higgs** | Ingredient 1: the simple-group mediators that killed $SU(5)$ are structurally **absent** | hand-checkable | **Yes** — a product of compact factors has direct-sum isometry; no off-diagonal generator exists by inspection (given the geometry is the selected product) |
| W2 | **No-mediator identity $\Pi_q M \Pi_\ell = 0$** | every sector-respecting cross-block Wilson coefficient is **identically zero** | hand-checkable (one-line proof) | **Yes given orthogonality** — the proof recomputes by hand: $\sum_i\delta_{qi}\delta_{i\ell}\Pi_iM_i\Pi_i=0$ |
| W3 | **Projector orthogonality $\Pi_i\Pi_j=\delta_{ij}\Pi_i$ on the matter bundle** (A2.6/A2.8, `3b8d68559f5e`) | the macro-orthogonality $\Pi_q\Pi_\ell=0$ that the identity needs holds on the *active-branch* bundle | symbolic / audit | **AUDIT** — asserted at A2.6/A2.8; a reviewer must reproduce the matter bundle and find zero overlap. The `G10` folder checks the identity on the **frozen labeling**, not a from-scratch bundle reconstruction |
| W4 | **Machine certificate `G10_proton_safety/`** | $\Pi_q M \Pi_\ell = 0$ exact on **25 randomized class members**; $X$-like off-block → nonzero → FAIL confirmed | machine-lane | **PASS (on the frozen labeling)** — the folder verifies the frozen claim in exact arithmetic and the falsifier fires; full-pipeline `reproduce_all.py` not re-run here |
| W5 | **Two-channel decoupling** (L.3.2 Identity 1) | Channel A gauge-redundant = BRST-exact; Channel B physical KK = KK-number + projector-killed | symbolic | **Yes (structurally)** — Channel A is the standard Slavnov–Taylor result; Channel B's KK-number selection ($\sum n_{\rm ext}=0$, $n_{\rm mediator}\geq1$) is hand-checkable; the manuscript correctly refuses "all KK are BRST-exact" |
| W6 | **L.2b coverage table** | the declared class covers the standard physically dangerous types ($QQQL$, RH channel, mixed, coloured-Higgs, leptoquark, dim-7) | symbolic / audit | **AUDIT (conditional)** — each row is a *claim* the table asserts "Covered"; physical completeness is the named falsifier, not a theorem |
| W7 | **Operator ledger `appendix_K_proton_operator_ledger.csv`** (`bc1e4e84840a`) | 11-row per-operator ledger up to dim 7 with $(\Delta B,\Delta L)$, status, rule, falsifier | machine-lane | **AUDIT** — CSV referenced + L.2-byte-equal claim; not independently re-run here |
| W8 | **Sphaleron-compatibility** (no global $U(1)_B$) | safety is operator-algebra; SM electroweak sphalerons ($\Delta B=\Delta L=\pm3$) remain allowed | hand-checkable | **Yes** — sphalerons act intra-sector ($Q_L\leftrightarrow L_L$ inside the same algebra), not as a cross-sector $\Pi_q M\Pi_\ell$ amplitude |
| W9 | **Lifetime diagnostic** (L.4) | a numerical $\tau_p$ above Super-K bounds, reported for context only | machine-lane | **Diagnostic only** — explicitly *not frozen* to certificate standard (depends on hadronic ME + residual $C_i$ + RG); cannot be reproduced as a hard claim *by design* |
| W10 | **Freeze hashes** + meta `a5b1e6f9d951` | every load-bearing object content-addressed before comparison | machine-lane | **Yes in principle** (re-hash R1.4/R1.6 rows + recompute meta); not re-run here |

### 2.2 What reproduces, plainly

- **The structural absence of $X/Y$ reproduces by inspection.** A product of compact factors has a direct-sum
  isometry algebra; there is no off-diagonal generator. This is the single strongest, most defensible leg — and it
  is exactly the move that the proton-decay precedent ($SU(5)$) makes load-bearing.
- **The identity reproduces by hand.** Given orthogonal sector projectors, $\Pi_q M \Pi_\ell = 0$ is a one-line
  algebraic fact; nothing is tuned. The dangerous coefficients are **exact zeros**, not suppressed numbers.
- **The machine check passes on the frozen labeling.** `G10_proton_safety/` runs the identity on 25 randomized class
  members and confirms the falsifier ($X$-like off-block → nonzero). This is a genuine, non-vacuous executable check
  — *conditioned on the frozen labeling being the right bundle* (W3).
- **The sphaleron-compatibility leg reproduces.** The manuscript does the harder, more honest thing: it *refuses* a
  global $U(1)_B$ (which would forbid observed SM physics) and secures safety by operator algebra instead.

### 2.3 What does NOT yet reproduce (honest gaps in the status)

- **W3 projector orthogonality is AUDIT on the active-branch bundle.** The identity is a theorem *given*
  orthogonality, but orthogonality is *asserted* at A2.6/A2.8 and only checked on the frozen labeling by the `G10`
  folder. A from-scratch matter-bundle reconstruction confirming zero overlap is the same "absent reproduction
  harness" class flagged for SG-7's δ-triple and SG-8's J.6/K.5 tables.
- **W6 physical completeness of the declared class does NOT reproduce — it is a claim, not a theorem.** The L.2b
  coverage table *asserts* every familiar type is covered; the certificate's own named falsifier (L.2a.4/L.2b.3) is
  precisely an admissible, physically relevant, Super-K-constrained operator **outside** the declared class. Until a
  coverage theorem exists, "the physically dangerous class is eliminated" is **CANDIDATE-grade**, not certified.
- **The dim-5 Weinberg scale does not reproduce — $\Lambda=M_R$ does not exist.** L.1/L.2 set the Weinberg
  coefficient by "the chamber's declared Majorana scale," but that scale is **uncomputed** (no value, no formula, no
  hash; `BG10-FROZEN-MR`). The "Bounded" status of the dim-5 leg therefore rests on an unspecified scale.
- **The lifetime does not reproduce as a hard claim — by design.** L.4/L.5 declare it *Diagnostic only*; promoting
  it to closure is a status violation (the forbidden CR10-C inference). This is correct discipline, but it means the
  most intuitive experimental quantity (the proton lifetime) is **not** a frozen output of the gate.
- **No cross-geometry determination reproduces.** The pass is evaluated *given the selected product geometry*. dim-6
  $B/L$-violation is a pressure SHARED by all GUT-class geometries; the Battle verdict is **SHARED-OPEN** — the
  rivals are neither cleared nor killed, and there is no Fable win.

### 2.4 Why PARTIAL (not higher, not lower)

- **Not DERIVED-GIVEN-E** (the SG-2/SG-3 tier): SG-9 is not a rigid integer/representation recovery. It is an
  operator-level selection-rule pass against a *declared* class, with a CANDIDATE-grade physical-completeness
  residual, an UNKNOWN dim-5 scale, an AUDIT bundle-orthogonality leg, and a Diagnostic-only lifetime — too many
  open residuals for the DERIVED tier.
- **Not OPEN/DECLARED-FROZEN:** the genuine content is real and strong — the product-geometry removal of $X/Y$ is
  the exact thing that killed $SU(5)$, the identity gives **exact zeros** (not tuned-small), the side doors are
  honestly closed with a two-channel argument, and the certificate passes on 25 randomized members with a live
  falsifier. This is well clear of "no theory" or "asserted without witness."
- **PARTIAL is exactly right:** a genuine operator-level selection-rule pass given the selected geometry, with named
  CANDIDATE-grade and Diagnostic-only qualifiers and an unknown dim-5 scale, plus a binding downgrade rule with
  teeth. This matches the SCOPED_GUT ledger SG-9 line verbatim (operator-level pass; CANDIDATE-grade safety against
  the declared class; SHARED-OPEN; lifetime Diagnostic).

---

## 3. The attack surface — what to attack (ranked by leverage)

Every open residual as a named object with its precise obstruction. **Leverage** = how much closing it moves the
gate (and how much it converts CANDIDATE/AUDIT/Diagnostic into certified).

### 3.1 The residual register

| ID | Residual (named object) | Precise obstruction | Status | Leverage |
|---|---|---|---|---|
| **R1** | **Declared-vs-physical operator class (the "narrowed subclass" attack)** | The gate's own named falsifier (L.2a.4 / L.2b.3 / §6.12 Gate-10 row). The pass kills $\mathcal{O}_{\rm danger}^{\rm declared}$ exactly, but physical completeness — every Super-K-constrained operator is captured — is an **audited assertion**, not a theorem. If a physically relevant BV operator lives *outside* the declared class, Gate 10 → *Open*. | OPEN (the meta-residual; CANDIDATE-grade) | **HIGHEST** — it conditions whether the operator-level pass means "proton-safe" |
| **R2** | **SHARED-OPEN: dim-6 BV is not a Fable win** | dim-6 $B/L$-violation is a pressure shared by all GUT-class geometries; the pass is a *selection-rule filter given the selected geometry*, not a cross-geometry determination. Battle verdict: SHARED-OPEN — rivals neither cleared nor killed. | DISCLOSED (Battle verdict) | **HIGH (claim-boundary)** — keeps "we passed proton safety" from inflating into "we uniquely solved it" |
| **R3** | **$M_R$ / dim-5 Weinberg scale UNKNOWN** | The dim-5 Weinberg $(LH)(LH)/\Lambda$ is *Bounded* with $\Lambda$ = "chamber's declared Majorana scale," but $M_R$ is **never computed** (no value, formula, or hash; `BG10-FROZEN-MR`). Shared with SG-8's absolute-ν-scale residual. | OPEN | **HIGH** — closes the dim-5 leg + removes a hidden scale shared with SG-8 |
| **R4** | **Projector orthogonality AUDIT on the active-branch matter bundle** | $\Pi_q M\Pi_\ell=0$ is a theorem *given* $\Pi_q\Pi_\ell=0$; the orthogonality is asserted at A2.6/A2.8 and checked only on the **frozen labeling** by `G10`. A from-scratch bundle reconstruction confirming zero overlap is not re-run. | AUDIT | **MEDIUM** — required for the identity's premise to be machine-real, not assumed |
| **R5** | **Operator ledger / coverage harness AUDIT** | `appendix_K_proton_operator_ledger.csv` (`bc1e4e84840a`) + the L.2b coverage rows referenced but not independently re-run; same class as SG-7/SG-8 absent-harness flags. | AUDIT | **MEDIUM** — converts "ledger byte-equal" + "coverage Covered" into machine-checked |
| **R6** | **Lifetime is Diagnostic only (not a frozen output)** | The numerical $\tau_p$ depends on hadronic ME + residual $C_i$ + RG, none frozen to certificate standard (L.4/L.5). The most intuitive experimental quantity is not a gate output; promoting it is a status violation. | DISCLOSED (Diagnostic only) | **LOW-MEDIUM** — a genuine prediction would *add* content, but is heavy and outside the operator-level closure |
| **R7** | **Product-geometry is selected, not forced** | Ingredient 1 ("no $X/Y$") follows from $K_{\rm gauge}$ being a *product*; but product-vs-simple-group is a *selected* geometry feature (gauge-group outcome is a rival TIE per the SHAPE audit), inherited from SG-1/SG-2. | OPEN (inherited) | **LOW-MEDIUM** — shared with SG-1/SG-2; selection ≠ forcing |
| **R8** | **$\tau=\omega$ Cartan substrate read from a minimum** | The sector split rides the Cartan-torus modulus $\tau=\omega$ (`03b30a9c931a`), inherited from SG-6 where it is read from a one-loop $V$-minimum, not independently derived. | OPEN (inherited from SG-6) | **LOW** — shared with SG-6/SG-8; not unique to proton safety |
| **R9** | **Non-perturbative / Planck channels outside the framework** | Sphalerons/instantons (non-perturbative $B+L$) and Planck-suppressed gravitational BV are *outside the operator-class framework* (L.2b) — honestly named and scoped, but not addressed. | DISCLOSED (Outside scope) | **LOW** — experiment/scope-gated; sphaleron low-$T$ rates exponentially suppressed |

### 3.2 Leverage ranking (attack order)

1. **R1** (declared-vs-physical class) — conditions whether the operator pass *means* proton-safe; the single
   highest-value target and the gate's own named falsifier.
2. **R3** ($M_R$ / dim-5 scale) — removes a hidden scale, closes the dim-5 leg, shared with SG-8 (double value).
3. **R4** (bundle-orthogonality AUDIT) — makes the identity's *premise* machine-real, not assumed.
4. **R5** (ledger/coverage harness) — cheapest to close (owner artifact); makes "Covered" + "byte-equal"
   machine-checked.
5. **R2 / R7** (SHARED-OPEN + selected-not-forced) — claim-boundary honesty; already substantially disclosed.
6. **R6 / R8 / R9** — Diagnostic-only / inherited / outside-scope.

> **The cardinal honest point.** R1 is where the whole gate lives. The operator-level pass is *real and exact* —
> but it is a pass on a **declared** class. If a closure path *enlarges the declared class to match physical
> completeness by hand-fitting* it to whatever vanishes, it has **relocated** the residual (the L.2a
> "declare-then-prove-on-whatever-vanishes" failure mode), not closed it — the κ³/π kill-test applies in full
> force. R3 ($M_R$) is the one genuine *missing number*. R2/R6/R7/R8/R9 are claim-boundary / inherited / scope
> residuals; closing them improves honesty and machine-reality but does not, on its own, upgrade the gate past
> PARTIAL.

---

## 4. THE ATTACK PLAN — closure paths (the core)

For each residual: the **technique** (closure playbook T1 axiom-floor / T4 no-go / T5 firewall / T6
all-operator-conditional / T7 eliminative / T10 selector), the **named axiom it could reduce to** (stated so it
would be written WITHOUT the target value — the κ³/π kill-test), the **specialist target** (theorem to hand off) or
the **owner artifact** (CSV/ruling/computation) needed, the **math to attempt**, and the **success ladder**
(DERIVED-CLOSED rare → AXIOM-CLOSED likely → sharper-OPEN → REFUTED).

---

### 4.1 R1 — Declared-vs-physical operator class (the gate's own falsifier)

**Why first.** The operator-level pass is exact, but it is a pass on $\mathcal{O}_{\rm danger}^{\rm declared}$. The
entire force of "Gate 10 = proton-safe" rests on the **declared class being physically complete** — i.e. that every
operator the Super-K bound constrains has the one-quark-leg + one-lepton-leg structure that $\Pi_q,\Pi_\ell$ catch.
If a physically relevant operator lives outside the declared class, the gate goes to *Open*, not merely *Diagnostic*.

**Technique: T6 (all-operator-conditional) + T4 (no-go on the escapees).** R1 is exactly the question L.2a/L.2b are
built to answer, but L.2b is an *auditable assertion* (a row-by-row "Covered"), not a coverage theorem. The honest
attack is to *try to escape the declared class* and prove the escape impossible.

**The escape-hunt, structured (this is the falsifier, run as an attack):**

| Candidate escapee | Structure | Caught by $\Pi_q M \Pi_\ell=0$? | Verdict |
|---|---|---|---|
| dim-6 $QQQL$, $u^c u^c d^c e^c$, $QLu^c d^c$, $QQu^c e^c$ | one quark leg + one lepton leg | **Yes** — declared class | covered |
| coloured-Higgs-like $\bar Q L H_c$ | needs coloured scalar mediator | **Yes (vacuous)** — $H_c$ absent on the active branch (bundle `44516f6400ae`) | covered (by Ingredient 1, not the identity) |
| leptoquark-like $\bar q M_{\rm LQ}\ell$ | colour + isospin + lepton number on one mode | **Yes** — KK tower of $\mathcal{E}_{\rm gauge}$ produces no such joint-quantum-number mode | covered (claim; needs KK-tower theorem) |
| $\bar d^c\bar d^c\bar u^c$ ($n$–$\bar n$, no lepton) | quark-only $\Delta B=1$ | **No** (no lepton leg) — killed by **Ingredient 1** (coloured-triplet absent), not by the identity | covered by a *different* mechanism |
| **quark-only or lepton-only BV outside the one-leg-each structure** | $\Delta B\neq1$ or no sector-crossing | **NOT by the identity** | **the escape route — must be ruled out** |
| non-perturbative (sphaleron/instanton) | $B+L$, gauge-config | outside framework | scoped out (R9) |

**Named axiom it could reduce to (κ³/π-clean).** The honest reduction is a *target-blind* statement of what the
declared class must be:

> **AXIOM-DANGEROUS-CLASS-COMPLETENESS** (target-blind form): *"On a product-factor compactification with the SM
> chiral content and no simple-group embedding, every gauge-invariant, admissible (per the C6 / B1 rulebook)
> baryon-or-lepton-number-violating operator that can drive nucleon decay is sector-crossing — i.e. carries one
> fermion leg in the quark sector and one in the lepton sector — and is therefore in
> $\mathcal{O}_{\rm danger}^{\rm declared}$; the residual quark-only $\Delta B$ operators require a coloured-triplet
> mediator absent on the product geometry."*

This is writable with **no proton-lifetime number in sight** — it is a statement about *operator structure under
admissibility*, not about a rate. It PASSES the κ³/π kill-test. **But it is not yet proven** — the quark-only /
lepton-only escape route and the leptoquark-KK-tower row are *claims*, not theorems.

**Specialist target (to hand off).** A **coverage theorem**: "Under the active-branch admissibility rulebook (C6 /
B1) and the product-factor gauge structure, the set of admissible nucleon-destabilizing operators up to the relevant
dimension is exactly $\mathcal{O}_{\rm danger}^{\rm declared}\cup\{$coloured-triplet-mediated quark-only channels,
absent by Ingredient 1$\}$." If proven, L.2b upgrades from an audited table to a closed statement and R1 closes.

**Math to attempt.** (1) Enumerate, target-blind, the admissible gauge-invariant $\Delta B\neq0$ and $\Delta L\neq0$
operators up to dim 7 on the active-branch field content (this is a finite, bounded representation-theory exercise).
(2) For each, classify: sector-crossing (caught by identity) / coloured-triplet-mediated quark-only (caught by
Ingredient 1) / **other**. (3) Prove the "other" bin is empty, OR exhibit a member of it (a falsifier). (4) Separately,
prove the leptoquark-KK-tower claim: that no level of the $\mathcal{E}_{\rm gauge}$ KK tower carries simultaneous
colour-$\mathbf3$, nonzero $T_3$, and nonzero $Y_\ell$.

**Success ladder.**
- DERIVED-CLOSED: coverage theorem proven → declared class is physically complete → operator-level pass *means*
  proton-safe (given geometry). **Possible but real work** (a bounded enumeration + two no-go lemmas).
- **AXIOM-CLOSED (likely):** AXIOM-DANGEROUS-CLASS-COMPLETENESS named; the enumeration confirms the standard types
  but the universal "no other admissible escapee" is left as a target-blind posit. Honest ceiling and roughly where
  the corrected manuscript stands (L.2b as audited assertion).
- sharper-OPEN: the leptoquark-KK-tower or quark-only no-go cannot be discharged → the CANDIDATE-grade label stands,
  explicitly.
- REFUTED: an admissible, physically relevant, Super-K-constrained operator is exhibited outside the declared class →
  Gate 10 → *Open / not claimed* (operator leg). **This is the good kind of negative — a structure-first falsifier.**

**Honest disposition: CANDIDATE-grade, reducible to AXIOM-DANGEROUS-CLASS-COMPLETENESS; physical completeness as a
theorem stays OPEN.** The gate is a derivation **of the declared-class zeros** and a CANDIDATE claim **of physical
completeness** — and saying so precisely is the closure, not a higher claim.

---

### 4.2 R2 — SHARED-OPEN: dim-6 BV is not a Fable win

**This is a claim-boundary residual, not physics.** No closure path "solves" it; the task is to **state the correct
scope** and bind it.

**Technique: T2-guarded restatement (no relocation), with a rival imported only inside the closure path.** dim-6
$B/L$-violation is a pressure on *every* GUT-class geometry. Conventional simple-group GUTs suppress it with a heavy
$M_{X/Y}$ (a tuned-small coefficient); the Fable product geometry makes it an **exact zero**. The *mechanism* differs
and is genuinely stronger (zero, not tuned-small), but the *outcome* — "the proton has not decayed" — is achieved by
all viable geometries; none is cleared or killed *by this gate*. The Battle-of-the-Geometries verdict is therefore
**SHARED-OPEN**.

**The honest framing to bind (countersign-gated; nothing applied here, No status was ever upgraded):**

> Gate 10 is a **filter** that prunes mediator-bearing variants, **not a determiner** that proves longevity unique
> to this branch. The Fable distinction is *mechanism* (exact-zero by projector identity vs tuned-small by heavy
> mediator), not *outcome*. "We passed proton safety" must never be read as "we uniquely solved proton stability."

**κ³/π kill-test.** N/A (no axiom, no target value). The danger here is *overclaim*, not tuning to the known answer: the
specific failure is letting the genuine exact-zero mechanism inflate into a uniqueness claim.

**Success ladder.** AXIOM-CLOSED not applicable. The endpoint is **DISCLOSED-CORRECTED**: the SHARED-OPEN verdict
and the filter-not-determiner framing stated wherever the proton-safety pass is summarized. **This is the cleanest,
lowest-risk honesty win in the gate** and requires only an owner countersign.

---

### 4.3 R3 — $M_R$ / dim-5 Weinberg scale UNKNOWN

**The obstruction.** The dim-5 Weinberg operator $(LH)(LH)/\Lambda$ is *Bounded* with $\Lambda$ = "the chamber's
declared Majorana scale." That scale is $M_R$, which is **asserted-derived but never computed** — no value, no
closed form, no hash (`BG10-FROZEN-MR`; the identical object that blocks SG-8's absolute neutrino scale). The dim-5
leg of the proton-safety ledger therefore rests on an unspecified number.

**Technique: T1 (axiom-floor) — name the scale; or T7 (eliminative) — rule out the candidates.** This is the **same
$M_R$** as SG-8 §4.3; the proton-safety dossier inherits that attack and adds nothing new — closing it once closes
both gates' dim-5/seesaw legs.

**Candidate identifications (each writable target-blind):**

| Candidate axiom | Statement (κ³/π-clean) | Test it must pass without a new knob |
|---|---|---|
| **AXIOM-MR-IS-MU** | $M_R = M_U \approx 10^{16}$ GeV (the SG-7 threshold-unification scale) | yield the measured $\Delta m^2$ via $N_\nu^2/M_R$ with $N_\nu$ fixed by the ratio; keep the Weinberg coefficient consistent with $m_\nu\sim0.05$ eV |
| **AXIOM-MR-IS-R0INV** | $M_R = R_0^{-1}$ (compactification scale, $R_0=1.592\times10^{-17}\,\mathrm{GeV}^{-1}$) | same |
| **AXIOM-MR-FLUX** | $M_R = M_U\cdot f(N{=}1,\tau{=}\omega)$ (chamber flux + modulus) | same, with $f$ computed not fit |

**The decisive check (do this first; shared with SG-8 R3).** Invert for the *required* $M_R^{\rm req}=N_\nu^2/(\text{abs }\Delta m^2)$
using $N_\nu$ from the frozen ratio + the measured splitting, then ask whether $M_R^{\rm req}$ coincides (within an
order of magnitude) with $M_U$, $R_0^{-1}$, or a clean chamber-flux scale. **κ³/π pivot:** if $M_R^{\rm req}$ lands
on a frozen scale the geometry *already* committed (e.g. $M_U$ from SG-7), AXIOM-MR-IS-MU is a genuine target-blind
closure; if it lands nowhere clean, every candidate RELOCATES a new tuned scale.

> **Caution from the corpus.** MEMORY records a parallel candidate $M_R=\kappa M_U$ that is **~231× off the corpus
> κ⁰** — flagged candidate-in-tension. The inversion must run **before** adopting any $M_R$ identity, precisely to
> avoid banking a tuned κ-power.

**Specialist target.** Hand the neutrino specialist: "Compute $M_R$ from the chamber Cartan-torus modulus + $N=1$
flux as asserted in K.4, target-blind, and report whether it matches $M_R^{\rm req}$." Either it discharges the
assertion (DERIVED) or it shows the assertion is empty (confirming R3 OPEN). The proton-safety relevance: a computed
$M_R$ pins the dim-5 Weinberg $\Lambda$, upgrading the dim-5 row from "Bounded by an unspecified scale" to a frozen
bound.

**Success ladder.**
- DERIVED-CLOSED: chamber computation yields $M_R$ parameter-free → dim-5 $\Lambda$ pinned; absolute-ν leg becomes a
  prediction (closes SG-8 R3 too).
- AXIOM-CLOSED: $M_R^{\rm req}$ lands on $M_U$ (or $R_0^{-1}$) cleanly → AXIOM-MR-IS-MU named. **Promising and cheap.**
- sharper-OPEN: $M_R^{\rm req}$ lands nowhere clean → R3 stays UNKNOWN; dim-5 row stays unspecified-scale.
- REFUTED: chamber computation gives a definite $M_R$ that *misses* $M_R^{\rm req}$ → the K.4 assertion is false.

**Honest disposition: OPEN, most tractable of the genuine-physics residuals** — the inversion is a half-day
computation and could reach AXIOM-CLOSED. **Run the inversion before adopting any identity.** (Note: $M_R$ is the
shared SG-8/SG-9 hidden scale; resolving it pays two debts.)

---

### 4.4 R4 — Projector orthogonality AUDIT on the active-branch matter bundle

**The obstruction.** $\Pi_q M \Pi_\ell = 0$ is a **theorem given** $\Pi_q\Pi_\ell=0$; the macro-orthogonality in turn
needs the sector projectors orthogonal on the *active-branch matter bundle* $\mathcal{E}_{\rm matter}$. That
orthogonality is **asserted** at A2.6/A2.8 and verified by `G10_proton_safety/` **on the frozen labeling** — not by a
from-scratch reconstruction of the matter bundle that independently confirms zero overlap. A reviewer who reproduces
the matter bundle and finds a non-zero overlap $\langle\Pi_q\cdot\Pi_\ell\rangle$ falsifies the identity (L.2a.4(2)).

**Technique: owner artifact (machine-lane) + T1 reduction of the premise.** Two parts:

1. **Owner artifact (reproduction).** Reconstruct $\mathcal{E}_{\rm matter}$ from the A2.3 matter-bundle
   factorisation + the R1.4 sector projectors + the $\mathbb{Z}_6$ centre (`a68ee92a75be`) + $\mathbb{Z}_2$ orbifold
   (`ac4d2df3e708`), **target-blind**, and confirm $\Pi_i\Pi_j=\delta_{ij}\Pi_i$ and $\Pi_q\Pi_\ell=0$ to machine
   precision — independently of the frozen labeling. Re-hash and confirm `3b8d68559f5e` regenerates from the
   canonical description.
2. **Named axiom for the premise (κ³/π-clean), if the reconstruction is deferred:**

> **AXIOM-SECTOR-ORTHOGONALITY** (target-blind form): *"The sector projectors of the $F^+$ chamber are mutually
> orthogonal idempotents on the matter bundle, with the quark index set $\{u,d,Q_L\}$ disjoint from the lepton index
> set $\{e,\nu,L_L\}$ under the $\mathbb{Z}_6$ centre + $\mathbb{Z}_2$ orbifold assignment."*

This carries no proton number; it is a statement about the bundle decomposition. It PASSES the kill-test. But it is
*better* discharged by reconstruction than axiomatized — orthogonality of group-theoretically defined projectors is a
*computation*, not a brute fact.

**Specialist target.** Hand the geometry/bundle specialist: "Reconstruct $\mathcal{E}_{\rm matter}$ and prove
$\Pi_q\Pi_\ell=0$ from the $\mathbb{Z}_6$/$\mathbb{Z}_2$ assignments alone, target-blind." A clean, bounded
linear-algebra-over-representations task.

**Success ladder.** **BLOCKED_INPUTS until the bundle is reconstructed** → then **VERIFIED** (orthogonality
confirmed from scratch → the identity's premise is machine-real, R4 closes) or **REFUTED** (a non-zero overlap →
Gate 10 downgrades). **AXIOM-CLOSED** (AXIOM-SECTOR-ORTHOGONALITY named) is the fallback if reconstruction is
deferred. **Honest disposition: AUDIT → VERIFIED is the target; the orthogonality is almost certainly true (it is
group theory) but is currently asserted, not independently reconstructed.**

---

### 4.5 R5 — Operator ledger / coverage harness AUDIT

**The obstruction.** "The 11-row operator ledger is byte-equal to `appendix_K_proton_operator_ledger.csv`
(`bc1e4e84840a`)" and "every L.2b row is Covered" are load-bearing reproducibility/coverage claims, but the CSV is
*referenced*, not independently re-run here — the same class as SG-7's absent δ-harness and SG-8's J.6/K.5 tables.

**Technique: owner artifact (machine-lane), not an axiom.** A **fail-closed reproducibility task**, not a physics
closure.

**Owner artifact needed.** (1) Mount the CSV. (2) Regenerate the L.2 ledger from the frozen objects, target-blind,
and confirm byte-equality (hash `bc1e4e84840a`). (3) For each L.2b coverage row, attach the explicit mechanism
witness (sector-crossing → identity; coloured-triplet → Ingredient 1; KK tower → no-joint-quantum-number lemma) and
confirm none is left "expected" or "should be safe." (4) Re-hash the R1.4/R1.6 rows and confirm the meta-hash
recomputes to `a5b1e6f9d951`.

**Math to attempt.** None new — execution + verification. Fail-closed: if any ledger row cannot be regenerated, or
any L.2b mechanism cannot be witnessed, Gate 10 downgrades (L.9 / front-matter Downgrade Rules).

**Success ladder.** **BLOCKED_INPUTS until the CSV/script are mounted** → then **VERIFIED** (ledger reproduces +
coverage witnessed; "Claimed certificate pass" becomes machine-real) or **REFUTED** (a row fails → downgrade).
**Highest value-per-effort closeable item** because it converts an asserted status into machine-checked with no new
physics.

---

### 4.6 R6 — The lifetime is Diagnostic only (not a frozen output)

**The obstruction.** The numerical proton lifetime — the most intuitive experimental quantity — is **not** a gate
output. L.4/L.5 declare it *Diagnostic only* because it depends on hadronic matrix elements, residual higher-dim
Wilson coefficients, and RG running that are **not frozen** to certificate standard. Promoting it to closure is the
forbidden CR10-C inference (a status violation).

**Technique: T7 (eliminative) — is the Diagnostic-only label necessary, or can a *bound* be frozen?** The honest
question is not "predict $\tau_p$" (heavy, and not the closure) but "can a target-blind **lower bound** on $\tau_p$
be frozen from the structure alone?"

- **What is genuinely available without new freezing:** since the *dominant* declared-class coefficients are **exact
  zeros**, $\tau_p$ is set by the *suppressed* residual operators — dim-7 ($(v/M_U)^2\sim10^{-28}$ suppression) and
  higher. A *structural lower bound* $\tau_p\gtrsim$ (suppression) $\times$ (dimensional estimate) could be stated
  target-blind, as a **floor**, distinct from a prediction.
- **Named principle (κ³/π-clean):** **AXIOM-LIFETIME-FLOOR-FROM-SUPPRESSION** — *"with all dim-6 declared
  coefficients exactly zero, the proton lifetime is bounded below by the dim-7-and-higher suppression scale; the
  bound carries no fitted coefficient."* Writable with no measured $\tau_p$. PASSES the kill-test. But it requires
  freezing the hadronic ME convention and the residual-coefficient bound — which the manuscript declines to do, on
  purpose.

**Specialist target.** Hand the lattice/hadronic specialist: "Given the dim-6 exact zeros, compute a *floor* on
$\tau_p$ from the dim-7 suppression + standard hadronic ME, and report whether it is robustly above Super-K — as a
**bound**, not a prediction." If robust, the lifetime leg could be upgraded from *Diagnostic only* to a *frozen
lower bound* — strictly weaker than a prediction but stronger than "consistent with bounds."

**Success ladder.** sharper-OPEN (the floor requires freezing conventions the manuscript declines → stays
Diagnostic, correctly) is most likely; **VERIFIED-FLOOR** (a robust target-blind lower bound is frozen) would *add*
content without overclaiming. There is no operator-level closure here — R6 is downstream of the operator pass.
**Honest disposition: keep Diagnostic only; the operator pass is the closure. A target-blind *floor* is the only
upgrade that does not violate the discipline, and it is optional.**

---

### 4.7 R7 — Product-geometry is selected, not forced

**The obstruction.** Ingredient 1 ("no $X/Y$ mediator") is a *consequence* of $K_{\rm gauge}$ being a **product**.
But product-vs-simple-group is a **selected** feature of the geometry — the SHAPE audit records the gauge-group
outcome as a **rival TIE**, and SG-1/SG-2 do not *force* the product structure over a simple-group competitor. So
"there is no $X/Y$" is true *given the selected geometry*, not forced.

**Technique: T1 (axiom-floor), shared with SG-1/SG-2.** Name the inheritance:

> **AXIOM-PRODUCT-BACKBONE** (κ³/π-clean): *"the SM-routing backbone is the product compactification
> $K_6\times S^2\times S^1_Y/\mathbb{Z}_2$ (no simple-group embedding); the proton-safety Ingredient 1 is the
> $\times$-layer consequence of this selected structure."*

Writable with no proton number. It PASSES the kill-test. The attack: this is *exactly* the SG-1 geometry-selection
residual seen from the proton-safety side — it does not get closed *here*; it is *inherited*. The honest move is to
name the dependency (a $\times$-layer freeze hash, not a silent inheritance — the C10 anti-smuggling table already
does this).

**Specialist target.** None new — this folds into the SG-1/SG-2 "is the product backbone forced?" question. The
proton-safety-specific note: *even if* a simple-group rival were admitted, Gate 10 would *fail on its mediator-inventory
leg* ($X/Y$ present → $C_{QQQL}\sim1/M_{X/Y}^2\neq0$); so the product structure is *necessary for* the operator-level
pass, which means the pass is **conditional on** the selected geometry — exactly the honest framing.

**Success ladder.** AXIOM-CLOSED (AXIOM-PRODUCT-BACKBONE named, inherited) is the realistic endpoint; DERIVED-CLOSED
requires SG-1/SG-2 to *force* the product backbone (not done; rival TIE). sharper-OPEN otherwise. **Honest
disposition: AXIOM-CLOSED at the inherited axiom; the product structure is selected-not-forced, and the proton-safety
pass is conditional on it.**

---

### 4.8 R8 — $\tau=\omega$ Cartan substrate read from a minimum

**The obstruction.** The sector split that defines $\Pi_u,\Pi_d,\Pi_e,\Pi_\nu$ rides the Cartan-torus modulus
$\tau=\omega$ (`03b30a9c931a`), inherited from SG-6, where it is the chamber-center witness **read from a one-loop
$V$-minimum**, not independently derived. SG-6's soft spot propagates here (and into SG-8).

**Technique: T1 (axiom-floor), shared with SG-6/SG-8.** Name the inheritance:

> **AXIOM-MODULAR-FIXED-POINT** (κ³/π-clean): *"the chamber modulus sits at the order-three modular fixed point
> $\tau=\omega$, the unique Weyl-rigid / modular-symmetric point of the $F^+$ Cartan torus."*

This is writable with no proton number — a symmetry statement. It is **stronger than "read from a minimum"** because
an order-three modular fixed point is *symmetry-protected*, not tuned. The attack: prove $\tau=\omega$ is the
*unique* modular-symmetric point (so it is forced by symmetry, not selected by a minimum). If proven, R8 strengthens
from "read from a minimum" to "symmetry-fixed" for *both* the flavor and proton sector decompositions.

**Specialist target.** Identical to SG-8 R8: hand the moduli/SG-6 specialist "show $\tau=\omega$ is the unique fixed
point of the $F^+$ Cartan-torus modular group, independent of the one-loop potential." Clean group theory.

**Success ladder.** AXIOM-CLOSED (named; symmetry-protected) realistic; DERIVED-CLOSED (uniqueness proven) closes
R8; sharper-OPEN if non-unique. **Honest disposition: AXIOM-CLOSED likely; shared with SG-6/SG-8 — not unique to
proton safety, and a genuine improvement over the SG-6 read-from-minimum framing.**

---

### 4.9 R9 — Non-perturbative / Planck channels outside the framework

**The obstruction.** Sphalerons/instantons (non-perturbative $B+L$ violation, $B-L$ conserved) and
Planck-suppressed gravitational BV ($\frac{1}{M_{\rm Pl}^2}\mathcal{O}_{QQQL}$) are **outside the operator-class
framework** (L.2b). They are *named and scoped*, not addressed — sphalerons because they are gauge-field
configurations not perturbative Wilson coefficients (low-$T$ rates exponentially suppressed, well below proton
sensitivity), Planck operators because they are Gate-11 excluded.

**Technique: none internal for the gate — scope + experiment.** The sphaleron leg is *positively* good news: the
manuscript's refusal of a global $U(1)_B$ is *because* sphalerons must remain allowed (a global $U(1)_B$ would forbid
observed SM physics). The honest action is to **keep them scoped-out**, with the sphaleron low-$T$ suppression as the
diagnostic statement, and let the Planck leg sit under Gate-11 exclusion.

**Named axiom?** None for the gate. The only relevant posit is the **claim-boundary** one (Gate 11): Planck-scale BV
is *Outside scoped-GUT claim*.

**Success ladder.** Not applicable (scope/experiment-gated). **Honest disposition: DISCLOSED; the gate's behavior is
correct — non-perturbative and Planck channels named and scoped out, sphaleron-compatibility secured by operator
algebra rather than a symmetry that would break the SM.**

---

### 4.10 Attack-plan roll-up

| Residual | Technique | Named axiom (κ³/π-clean) | Specialist target / owner artifact | Realistic endpoint |
|---|---|---|---|---|
| R1 declared-vs-physical class | T6 + T4 | AXIOM-DANGEROUS-CLASS-COMPLETENESS | coverage theorem (admissible-operator enumeration + 2 no-go lemmas) | CANDIDATE → AXIOM-CLOSED; physical completeness OPEN |
| R2 SHARED-OPEN | T2 restatement | (none) | owner countersign (filter-not-determiner framing) | DISCLOSED-CORRECTED (cleanest win) |
| R3 $M_R$ / dim-5 scale | T1 / T7 | AXIOM-MR-IS-MU | invert for $M_R^{\rm req}$; compute $M_R$ from chamber (shared w/ SG-8) | OPEN → AXIOM-CLOSED if scales coincide (most tractable physics) |
| R4 bundle orthogonality | owner artifact + T1 | AXIOM-SECTOR-ORTHOGONALITY | reconstruct $\mathcal{E}_{\rm matter}$, prove $\Pi_q\Pi_\ell=0$ from scratch | AUDIT → VERIFIED (premise machine-real) |
| R5 ledger/coverage harness | machine-lane | (none) | mount CSV + regenerate L.2/L.2b target-blind | BLOCKED_INPUTS → VERIFIED (best value/effort) |
| R6 lifetime Diagnostic | T7 | AXIOM-LIFETIME-FLOOR-FROM-SUPPRESSION | floor on $\tau_p$ from dim-7 suppression (optional) | sharper-OPEN (or VERIFIED-FLOOR; stays Diagnostic) |
| R7 product selected-not-forced | T1 | AXIOM-PRODUCT-BACKBONE | folds into SG-1/SG-2 forcing question | AXIOM-CLOSED (inherited) |
| R8 $\tau=\omega$ substrate | T1 | AXIOM-MODULAR-FIXED-POINT | modular-fixed-point uniqueness (shared w/ SG-6/SG-8) | AXIOM-CLOSED (improves SG-6 framing) |
| R9 non-perturbative / Planck | scope | (Gate-11 exclusion) | DUNE/Hyper-K (sphaleron scoped) | DISCLOSED (scope-gated) |

**REDUCE-vs-RELOCATE verdict on the plan.** The plan does **not** turn one hard problem into three harder ones. Each
path either (a) names a single target-blind axiom that pays a debt in plain sight (R1-completeness as the bounded
ceiling, R4-orthogonality, R7, R8), (b) attempts a bounded, falsifiable computation that *could* convert
CANDIDATE/AUDIT into certified (R1 coverage enumeration; R3 $M_R$ inversion; R4 bundle reconstruction; R5 ledger
regen), or (c) is a mechanical owner/scope task (R2, R6-floor, R9). The harder-subproblem check: R1's coverage
theorem is a *bounded* enumeration of admissible operators up to dim 7 (finite), not an open-ended search; R3 is one
scalar's provenance (shared with SG-8, so it is *not* a new problem); R4 is linear-algebra-over-representations. None
is harder than the original gate, and the two that touch numbers (R1 enumeration, R3 $M_R$) carry explicit κ³/π
kill-tests so a hand-fit class-enlargement or a tuned $M_R$ cannot be banked. The honest expected outcome of a full
campaign: **~3 AXIOM-CLOSED (R7, R8, R1-completeness-as-posit), 1 likely AXIOM-CLOSED (R3 if scales coincide), 1
DISCLOSED-CORRECTED (R2), 2 VERIFIED (R4, R5), 1 sharper-OPEN (R6), 1 DISCLOSED (R9).** No DERIVED-CLOSED is
promised; the gate would move from PARTIAL-with-CANDIDATE-grade-asserted-status to **PARTIAL-with-machine-verified-premises
+ a named axiom floor + an honest SHARED-OPEN scope** — a real honesty/reproducibility gain, **not** a promotion.

---

## A. Anchoring & Hardening Map

This is SG-9 run through **our internal honesty methodology**: classify each residual as a **gap** (the route is known; what is
missing is a finished computation/certificate/measured input) or a **wall** (the route itself is the problem); hunt
the implicit assumption it smuggles; then ask the decisive question — **what measured invariant must this residual
ultimately terminate on?** — and assign the most conservative honest disposition. The disposition vocabulary is the
same one defined inline in the live **Gaps & Walls Register** (`/articles/GAPS_AND_WALLS_REGISTER.html`): **DERIVED**
(reduces to an already-measured fact, floor doesn't grow) · **DERIVED-GIVEN-E** (rigid once the observed spectrum E
is supplied) · **AXIOM-CLOSED** (reduced to exactly one named, value-free posit; gap stays open) · **DISSOLVED**
(rested on a false/unmeasured premise) · **SCHEME-ANCHORED** (a number reachable only after one named convention
choice) · **OPEN** (genuinely unsolved, or the only escape assumes the answer) · **BLOCKED** (a route exists but a
required file/input is missing — refuse to fabricate) · **measured-but-irreducible** (known from experiment, no
derivation anywhere). The frozen anchor set the framework actually terminates on is **{ℏ, M_Pl, spectrum-E, α_i(M_Z),
y_t, |V_us|}**. The key discipline (carried from the Register): *no theorem breaks a wall*, and a residual that has
**no clean measured invariant to terminate on — or whose only anchor would be the answer itself — is OPEN, not
closed.** This map is consistent with the live SG-9 Register line (PARTIAL → conservatively OPEN; candidate-grade
safety against a *declared* class) and with the SG-7 finding (Diagnostic-only; threshold rows fitted-not-derived;
magnitude SCHEME-ANCHORED), which SG-9 inherits only through the shared $M_R$ / $\tau=\omega$ scales.

### A.1 Per-residual anchoring & hardening table

| Residual | GAP or WALL (+kind) | Measured invariant it must terminate on | Honest disposition | What would HARDEN it (concrete next step) |
|---|---|---|---|---|
| **R1** declared-vs-physical operator class | **WALL** (the route is the problem: physical *completeness* of the declared class is a universal-negative — "no admissible escapee exists") | **spectrum-E + the Super-K bound** ($\tau_p\gtrsim10^{34}$ yr is the measured fact the declared class must provably capture); it does **not** reduce to a single frozen anchor — it needs a **NEW named invariant** (AXIOM-DANGEROUS-CLASS-COMPLETENESS), a structure statement, not a number | **OPEN** (operator-level pass on the declared class is exact and real; physical completeness is candidate-grade, un-proven) — ceiling **AXIOM-CLOSED** at the completeness posit | Bounded target-blind enumeration of admissible $\Delta B,\Delta L\neq0$ operators to dim 7 on the active-branch content, classify each (sector-crossing / coloured-triplet-mediated / **other**), then prove the "other" bin empty or exhibit a falsifier — and prove the leptoquark-KK-tower no-go. κ³/π kill-test binds: enlarging the class to fit whatever vanishes is a *relocation*, not a close |
| **R2** SHARED-OPEN: dim-6 BV is not a Fable win | **GAP** (claim-boundary / disclosure, not physics) | none — there is **no witness** that would make this branch *uniquely* safe; dim-6 BV is a pressure on **every** GUT-class geometry (cross-geometry determination has no measured anchor) | **OPEN** (correctly DISCLOSED as SHARED-OPEN; honestly *not* a Fable win) | Owner countersign of the **filter-not-determiner** framing wherever the pass is summarized: "exact-zero by projector identity" is a stronger *mechanism* than "tuned-small by heavy mediator", but the *outcome* (proton longevity) is shared. Lowest-risk honesty win in the gate |
| **R3** $M_R$ / dim-5 Weinberg scale UNKNOWN | **WALL** (the only apparent anchor — the seesaw scale — is itself unmeasured; the candidate $M_R=\kappa M_U$ is the κ³/π trap, ~231× off corpus κ⁰) | the **measured neutrino splitting $\Delta m^2$ via $N_\nu^2/M_R$**, with $N_\nu$ from the frozen ratio — i.e. it must terminate on **spectrum-E** through the inversion, OR on the **existing $M_U$ anchor** if $M_R^{\rm req}$ lands there | **OPEN** (no value, formula, or hash; `BG10-FROZEN-MR`) — most tractable of the genuine-physics residuals; ceiling **AXIOM-CLOSED** (AXIOM-MR-IS-MU) if scales coincide | **Run the inversion FIRST:** $M_R^{\rm req}=N_\nu^2/(\text{abs }\Delta m^2)$; check whether it lands (within ~1 order) on $M_U$ or $R_0^{-1}$ *before* adopting any identity. A clean coincidence → AXIOM-CLOSED; no clean landing → every candidate RELOCATES a tuned scale. Shared with SG-8 — closing it once pays both debts |
| **R4** projector orthogonality AUDIT on the active-branch matter bundle | **GAP** (the route is fully known — it is linear-algebra-over-representations; only the from-scratch reconstruction is unfinished) | **none new** — terminates on the frozen geometry's own group theory (the $\mathbb{Z}_6$ centre + $\mathbb{Z}_2$ orbifold assignment), which is anchored at **M_Pl-scale UV data** already in the manifest, not on a measured number; orthogonality is a *computation*, not a brute fact | **BLOCKED** (route exists; the from-scratch $\mathcal{E}_{\rm matter}$ reconstruction is not re-run) → **VERIFIED** is the target; **AXIOM-CLOSED** (AXIOM-SECTOR-ORTHOGONALITY) is the fallback if deferred | Reconstruct $\mathcal{E}_{\rm matter}$ target-blind from the A2.3 factorisation + R1.4 projectors + $\mathbb{Z}_6$/$\mathbb{Z}_2$ assignments; confirm $\Pi_i\Pi_j=\delta_{ij}\Pi_i$ and $\Pi_q\Pi_\ell=0$ to machine precision, and that hash `3b8d68559f5e` regenerates. Makes the identity's *premise* machine-real, not assumed |
| **R5** operator ledger / coverage harness AUDIT | **GAP** (reproducibility debt; no new physics — execution + verification only) | **none** — a content-addressed reproducibility fact (byte-equality to hash `bc1e4e84840a` + per-row mechanism witnesses), not a physical invariant | **BLOCKED** (CSV/script referenced, not mounted + re-run here) → **VERIFIED** | Mount the CSV; regenerate the L.2 ledger target-blind and confirm byte-equality; attach an explicit mechanism witness to every L.2b "Covered" row (sector-crossing→identity / coloured-triplet→Ingredient 1 / KK→no-joint-quantum-number lemma); re-hash to `a5b1e6f9d951`. **Highest value-per-effort** closeable item; fail-closed |
| **R6** lifetime is Diagnostic only | **GAP** (downstream of the operator pass; deliberately not frozen) | the **measured Super-K lifetime bound** — but the predicted $\tau_p$ depends on un-frozen hadronic ME + residual $C_i$ + RG, so it is **COMPUTATION-DEBT against spectrum-E**, not a frozen output | **measured-but-irreducible** on the experiment side / Diagnostic-only on the theory side (correct discipline; promoting it is a status violation) | Keep Diagnostic. The *only* non-violating upgrade is a target-blind **lower bound**: with all dim-6 declared coefficients exact-zero, floor $\tau_p$ from the dim-7 suppression ($\sim(v/M_U)^2$) + standard hadronic ME, reported as a **floor**, not a prediction (AXIOM-LIFETIME-FLOOR-FROM-SUPPRESSION). Optional |
| **R7** product-geometry is selected, not forced | **WALL** (inherited from SG-1/SG-2; the minimality-of-shape question rests on an undischarged universal-negative — "no simpler admissible competitor") | **none** — the product-vs-simple-group choice is a **SHAPE-root** question with no measured anchor (the gauge-group outcome is a rival TIE; cross-category minimality is uncomputable) | **OPEN** (inherited) — ceiling **AXIOM-CLOSED** (AXIOM-PRODUCT-BACKBONE, named as a $\times$-layer dependency, not silently smuggled) | Fold into the SG-1/SG-2 "is the product backbone forced?" question; nothing closes *here*. Proton-safety-specific honest note: Ingredient 1 is *necessary for* the operator-level pass, so the pass is explicitly **conditional on** the selected geometry — name the dependency with a $\times$-layer freeze hash |
| **R8** $\tau=\omega$ Cartan substrate read from a minimum | **WALL** (inherited from SG-6; "read from a one-loop $V$-minimum" is the same soft spot SG-7's Diagnostic-only finding flags — a magnitude/object read, not derived) | **none new** — terminates on a **symmetry fact** (order-three modular fixed point of the $F^+$ Cartan torus), not a measured number; if proven unique it is symmetry-protected, not tuned | **OPEN** (inherited from SG-6) — ceiling **AXIOM-CLOSED** (AXIOM-MODULAR-FIXED-POINT), a genuine improvement over "read from a minimum" | Prove $\tau=\omega$ is the *unique* modular-symmetric point of the $F^+$ Cartan-torus modular group, independent of the one-loop potential (clean group theory; shared with SG-6/SG-8). Upgrades both the flavor and proton sector decompositions from "read" to "symmetry-fixed" |
| **R9** non-perturbative / Planck channels outside the framework | **WALL** (no in-framework route: sphalerons/instantons are gauge-field configurations, not Wilson coefficients; Planck BV is Gate-11 excluded) | the **measured proton-decay null result** (sphaleron low-$T$ rates are exponentially suppressed, well below sensitivity); Planck leg has **no witness** at scoped-GUT level | **OPEN** / DISCLOSED (correctly scoped out; behaviour is *good* — the refusal of a global $U(1)_B$ is *because* sphalerons must stay allowed, or observed SM physics breaks) | None internal — scope + experiment (DUNE / Hyper-K ~2035). Keep the sphaleron low-$T$ suppression as the diagnostic statement; let the Planck leg sit under the Gate-11 exclusion lint |

### A.2 Gate-level rollup

**Overall disposition: PARTIAL → conservatively OPEN** (matching the live Register SG-9 line). SG-9 carries **one genuine,
defensible, frozen-structure output** — the product-factor $K_{\rm gauge}$ removes the simple-group $X/Y$ mediator and
the coloured-Higgs triplet (the exact failure mode that executed minimal $SU(5)$), and the sector-projector identity
$\Pi_q M\Pi_\ell=0$ makes every Wilson coefficient in the **declared** dangerous class an **exact zero** (not
tuned-small). But run through the hardening method, the gate has **no residual that terminates DERIVED on a single
measured anchor**: its central object (R1) is a **WALL** whose only honest anchor is a *new structure axiom*
(physical-completeness), and its one genuine missing number (R3, $M_R$) is a **WALL** with no measured anchor unless
the inversion lands $M_R^{\rm req}$ on an *existing* scale. The two cheap wins (R4, R5) are **BLOCKED→VERIFIED**
reproducibility gaps, not promotions.

**Anchors this gate depends on.** Indirectly and *given-E*: **spectrum-E** (the SM chiral content from SG-2/SG-3, on
which the projectors act; the Super-K lifetime bound R1/R6 must capture; the $\Delta m^2$ that R3's inversion uses) and
**M_Pl-scale UV data** (the $\mathbb{Z}_6$/$\mathbb{Z}_2$ assignments and $M_U$ that R3/R4/R7 terminate on). The gate
produces **no new from-nothing anchor**; it derives the declared-class zeros *given* the frozen labeling. It does
**not** depend on α_i, y_t, or |V_us| directly. It inherits the $\tau=\omega$ substrate (R8) and $M_R$ scale (R3) that
SG-6/SG-7/SG-8 also ride — the same un-derived-magnitude soft spot the SG-7 SCHEME-ANCHORED finding names.

**Single highest-leverage hardening move.** **R1's coverage theorem** — the bounded, target-blind enumeration of
admissible BV operators to dim 7, classifying each and proving the "other" bin empty (or exhibiting a falsifier). It
is the gate's own named falsifier and conditions whether the *exact operator-level pass* actually *means* proton-safe.
DERIVED-CLOSED on R1 would upgrade L.2b from an audited table to a closed statement; the realistic ceiling is
**AXIOM-CLOSED** at AXIOM-DANGEROUS-CLASS-COMPLETENESS — and saying so precisely *is* the closure, not a higher claim.
(The cheapest *separate* win is R5, a pure reproducibility mount; the most tractable *physics* win is the R3 $M_R$
inversion, shared with SG-8. None promotes the gate past PARTIAL.) **Ceiling: serious candidate, NOT validated.**

### 🎯 Target anchor(s) for this gate

In the terminate-on (anchoring) sense, SG-9 terminates on **two measured objects, and it is candidate-grade — no
proton lifetime is predicted.** (1) The **observed spectrum E** — the product backbone $K_{\rm gauge}=K_6\times S^2\times
S^1_Y/\mathbb{Z}_2$ with **no GUT mediator** ($X/Y$ generator absent, no coloured-Higgs triplet) and the
$\mathcal{E}_{\rm proton}$ sector projectors — supplied as input (**DERIVED-GIVEN-E**, never producing E). (2) The
**measured Super-K proton-lifetime bound** ($\tau_p\gtrsim10^{34}$ yr) — the observable the dim-6 suppression must
clear, and the fact the *declared* dangerous class must provably capture. **Status: OPEN.** The operator-level pass
$\Pi_q M\Pi_\ell=0$ on the *declared* class is exact and real, but it has **no measured-invariant witness** that the
declared class is physically complete (R1 is a WALL needing a NEW structure posit, AXIOM-DANGEROUS-CLASS-COMPLETENESS),
and the dim-5 Weinberg leg's scale $M_R$ is **UNKNOWN/open** with no measured anchor unless its inversion lands on an
existing scale (R3). The hardening move is a **bounded, target-blind dim-6/dim-7 BV-operator census** on the
active-branch content (the R1 coverage theorem) reported as a **floor**, not a lifetime — enlarging the class to fit
whatever vanishes is a relocation, not a close (κ³/π kill-test). NOT a measured-invariant termination today; NOT promoted.

---

## 5. References & source map

### 5.1 Website source-of-truth (common material — link, don't duplicate)

- **Paper I, GUT.html** — <https://physics.magflowmeters.com/articles/GUT.html>
  - **§6.10** Gate-10 card (binding status: 10a *Claimed certificate pass* operator / 10b *Diagnostic only*
    lifetime); **§6.12** falsification map (Gate-10 row); **§6.13** certificate-status summary.
  - **§5.9** narrative module; **Appendix CR, module CR10** ("Proton Safety as a Worked Constraint",
    CR10.1–CR10.14: the operator-vs-lifetime split, the implication-chain spine, the selector-elimination table, the
    remove-one-term tests, the freeze table, the shows/does-not-show ledger, the audit questions).
  - **Appendix L** (Gate-10 certificate): L.0 authority + status/falsifier table; L.1 operator basis; L.2 11-row
    operator ledger; **L.2a** declaration-before-elimination (the $\mathcal{O}_{\rm danger}^{\rm declared}$ box +
    "what this does NOT claim" + falsification paths + the binding operator-vs-lifetime sentence); **L.2b** coverage
    table + binding scope statement + reviewer falsification path; **L.3** FCNC / mediator no-go theorem (L.3.1
    three-ingredient proof: mediator inventory + two-channel decoupling + projector orthogonality; L.3.2 explicit
    BRST commutator, projector identities, Wilson-coefficient zeros, failure condition); L.4 lifetime diagnostic;
    L.5 safety-vs-prediction; L.6 experimental comparison; L.7 certificate JSON; L.8 outputs; L.9 / L.9a failure
    conditions + migration note (BRST clarity statement).
  - **Appendix C10** ($\mathcal{E}_{\rm proton}$ term authority card): formal object box; layer assignment +
    anti-smuggling table; first gate required; gates served + operator-vs-lifetime split; failure-if-removed table;
    freeze/certificate authority path; claim boundary; minimality.
  - **Appendix A2** §A2.6 (sector projectors), **§A2.8** (macro-projectors $\Pi_q,\Pi_\ell$ + the proton-safety
    identity $\Pi_q M \Pi_\ell = 0$), §A2.9 (BRST/KK support); **A1.13a** (operator-class hash); **A1.14**
    (projector domain-codomain table).
  - **Appendix R0 / R1** freeze records + frozen parameter manifest (all hashes in §0 above); R1.4 (sector
    projectors), R1.6 (FCNC no-go + operator-class), R1.3 ($\mathbb{Z}_6$ / $\mathbb{Z}_2$), R1.11 (meta-hash);
    `certificates/G10_proton_safety/` (25 randomized class members; $X$-like off-block FAIL); `appendix_K_proton_operator_ledger.csv`.
  - **Appendix K** (neutrino certificate) — the dim-5 Weinberg / Majorana-scale leg; **K.4** $M_R$ UNKNOWN box.
- **Paper IV, TOE.html** — <https://physics.magflowmeters.com/articles/TOE.html> (claim-boundary / excluded-sector
  cross-reference only; does not touch the operator-level closure).

### 5.2 Corpus locations (authoritative inputs to this dossier)

| Source | Path | Role |
|---|---|---|
| Per-gate dossier spec | `…/rendered/TOE/PER_GATE_DOSSIER_SPEC.md` | structure (sections 0–5) |
| SG-9 status line | `…/rendered/TOE/SCOPED_GUT_PER_GATE_STATUS_LEDGER.md` | the **PARTIAL** label + the CANDIDATE-grade / SHARED-OPEN / filter-not-determiner caveats (carried verbatim) |
| SG-8 exemplar (shape/depth match) | `…/rendered/TOE/PER_GATE_DOSSIERS/DOSSIER_SG8_FLAVOR_CLOSURE_ATTACK.md` | format reference; shared $M_R$ / $\tau=\omega$ residuals |
| Gate-9 input-ledger finding (shared $M_R$) | `…/rendered/TOE/GATE9_FLAVOR_INPUT_LEDGER_FINDING_2026-06-24.md` | $M_R$ UNKNOWN (the dim-5/seesaw scale this gate inherits) |
| Closure campaign result + round 2 | `…/rendered/TOE/CLOSURE_CAMPAIGN_RESULT_2026-06-24.md` (+ `…_ROUND2_…`) | κ³/π kill-test discipline; AXIOM-CLOSED ≠ proven; demotion-on-verify norm; `BG10-FROZEN-MR` is recipe-absent |
| Axiom ledger | `…/rendered/TOE/AXIOM_LEDGER.md` | `BG10-FROZEN-MR` = DECLARED-OPEN brute fact (the unknown Majorana scale) |
| GUT manuscript | `…/rendered/GUT/GUT.md` | §6.10 (Gate-10 card); §5.9 (narrative); App L (proton-safety certificate); App C10 (E_proton dossier); CR10 (worked module); A2.6/A2.8/A2.9 (projectors/BRST) |
| Exact-geometry anchor | `…/rendered/TOE/00_EXACT_GEOMETRY_ANCHOR.md` + `…/FROZEN_13D_BOUNDARY_DATA_PACKAGE.md` | frozen 13D K₆ branch (anti-drift) |

### 5.3 Frozen-object hash index (load-bearing; READ-ONLY)

Branch `dcc66f1b2685` · manifest meta `a5b1e6f9d951` · sector projectors $\Pi_u,\Pi_d,\Pi_e,\Pi_\nu$
`3b8d68559f5e` (R1.4) · FCNC / mediator no-go theorem (full) `fff4b433b7b3` (R1.6) · operator-class declaration
`551488d06011` (R1.6) · Cartan-torus modulus $\tau=\omega$ `03b30a9c931a` · global $\mathbb{Z}_6$ centre
`a68ee92a75be` · $\mathbb{Z}_2$ orbifold on $S^1_Y$ `ac4d2df3e708` · hypercharge bundle (no coloured-Higgs partner)
`44516f6400ae` · proton-operator ledger CSV `bc1e4e84840a`. **Macro-projectors $\Pi_q,\Pi_\ell$, $Q_{\rm BRST}$, the
no-mediator identity $\Pi_q M \Pi_\ell=0$, empty-cohomology statement: derived / standard — no separate R1 hash.**
**$M_R$ (dim-5 Weinberg / seesaw Majorana scale): no hash — UNKNOWN/open (`BG10-FROZEN-MR`).** Machine certificate:
`certificates/G10_proton_safety/` (25 randomized class members; $X$-like off-block → FAIL confirmed).

---

### Closing honest statement

SG-9 is **PARTIAL**. Its genuine, defensible content is real and strong: the **product-factor** structure of
$K_{\rm gauge}$ removes the simple-group $X/Y$ mediator and the coloured-Higgs triplet — the exact failure mode that
executed minimal $SU(5)$ — and the sector-projector identity $\Pi_q M \Pi_\ell = 0$ makes every Wilson coefficient
in the **declared** dangerous class an **exact zero** (not a tuned-small number), with the spectator side doors
honestly closed by a two-channel BRST/KK-number argument that *refuses* the false "all KK modes are BRST-exact"
claim, and with sphaleron-compatibility secured by operator algebra rather than a global $U(1)_B$ that would break
the SM; the machine certificate passes on 25 randomized class members with a live falsifier. Its honest open surface
is equally clear: the pass is **CANDIDATE-grade safety against the *declared* operator class** — the gate's own named
falsifier is whether the identity kills the *physically relevant* class or only the declared one; dim-6 BV is
**SHARED-OPEN** across all GUT-class geometries (no Fable win; a *filter*, not a *determiner*); the dim-5 Weinberg /
seesaw scale **$M_R$ is UNKNOWN/open** (shared with SG-8); the projector-orthogonality premise and the operator
ledger are **AUDIT**; the numerical lifetime is **Diagnostic only**; and the product geometry it rests on is
**selected, not forced**. The attack plan reduces these to named, target-blind axioms and bounded, falsifiable
computations — with the κ³/π kill-test guarding R1 (so a hand-fit class-enlargement cannot be banked) and R3 (so a
tuned $M_R$ cannot be dressed as a derivation). The realistic ceiling is machine-verified premises over a named
axiom floor, with an honest SHARED-OPEN scope — **not** a promotion. **No status was ever upgraded; frozen branch `dcc66f1b2685` /
`a5b1e6f9d951` READ-ONLY; given-E ≠ derivation of E; a selection-rule pass on a declared class ≠ a proof of absolute
proton safety; nothing applied, nothing deployed.**

*Dossier built 2026-06-24. Our geometry (13D K₆ branch) only. Common material referenced to the published website
source-of-truth, not duplicated.*
