Authority: Explanatory implementation profile · Status: Validated engineering release candidate; public evidence, large runtime not deployed · Applies to: E4.5 Opportunity admission · Verified against: release manifestsha256:cbaaa1cd2b41f698f7b423a516727f5a7907bba56ac6c17136528f40f45d7690· Source:reports/e4-5-opportunity-admission.md
What was admitted
The Genesis steward approved one exact policy proposal at2026-08-12T04:33:44Z. That approval authorized one manual retrieval of one
named Grants.gov bulk extract, its exact range, byte, timeout, field and
retention limits, and nothing broader.
The acquisition:
- made 75 sequential bounded range requests;
- transferred 77,910,428 bytes;
- stored each range as evidence before archive reconstruction;
- completed with the scheduler disabled;
- retained the raw archive as private evidence;
- cannot be repeated because the persisted one-shot claim is consumed.
What the compiler produced
Mappings remain
candidate; frames remain in the
provisional_semantic trust lane. Packet and frame counts establish source
depth, not broad multi-source coverage or canonical semantic review.
The release is completed by release-manifest.json. Its detached SHA-256 is
the trusted input to the read-only runtime. The runtime rejects a different
manifest, missing privacy report, symlinked segment, changed segment size,
changed digest, invalid frame or count mismatch.
Public engineering evidence is versioned at
v0.4.5-rc.1.
The release publishes the exact manifest and its detached SHA-256 while keeping
the 1.73 GB runtime segments and private acquisition projection off the shared
public host.
Privacy treatment
The private projection excluded 247,382 contact fields and 83,130 descriptions. The approved eligibility field still contained contact-like text. Publishing it would have violated the public-surface privacy standard even though the source field itself was in scope. TWIRX therefore compiles each non-empty eligibility field as:not_provided. Frames link the corresponding
packet and preserve that state. The release publishes zero eligibility lexical
values and makes no applicant-eligibility conclusion.
This product uses the Grants.gov public data source but is not endorsed or
certified by the U.S. Department of Health and Human Services.
Agent query
The first admitted scenario is a bounded exact query for records whose source-stated agency code isNSF:
tw:opportunity and tw:world-state. Both paths had
zero origin calls, browser executions, live-source calls and model authority.
The cross-universe investigation coordinates two typed queries; it does not
invent a semantic join between grants and development observations.
Verification and measured scope
The complete Go release verifier rehashes and parses every packet, mapping, frame and segment, verifies every privacy invariant and reconciles all frame-to-packet references. Its recorded full-release run completed in 26.405 seconds on the evidence host. The independent restricted-C verifier checked 132 deterministic canonical artifacts: 63 packets, 63 mapping claims and six frames. The selection takes the first, middle and last entry from every packet and mapping segment and three frames from each universe. This is sample evidence; TWIRX does not claim that C verified the complete million-packet corpus. After one runtime admission, 1,000 local NSF scenario executions had a median of 2.411 ms and p95 of 3.107 ms for exact query, trace and decode of 20 frames. The 4.825-second admission measurement includes whole-file identity and index reconciliation for the 273,165,514-byte combined segment. These are one-host local measurements, not public-network or production capacity claims.Deployment state
The protected FUTO baseline remains live atlab.twirx.org. This larger
Opportunity release is not deployed. Its isolated encrypted off-host archive
passed full data checking, a byte-identical restore, complete release
verification, restricted-C sample verification and the two-universe agent
investigation. The code, report and manifest are admitted as public engineering
evidence. A separate target-host resource and deployment decision remains
required. A second versioned Object Storage replica remains desirable but the
unrelated existing Meridian bucket stays outside scope.