# EM-0042 — Close the second cold-start selection and clock gaps

- Object ID: `em:documentation:sha256:bcd93ae4538622c19a47b59d4d71cc8817058a78592fae7b005c08e66c8f607d`
- Kind: `documentation`
- Repository path: [`docs/execution-plans/EM-0042.md`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/docs/execution-plans/EM-0042.md)
- Content digest: `eedcfa0f6e5ad0f0fb4b69f4d18a50cd164fdc56988091961a9fe056d707d028`

**Also filed under:** [Disclosure and Public Projection](https://epistemedia.org/topics/disclosure/), [Epistemedia](https://epistemedia.org/topics/epistemedia/), [Epistemic Mesh Protocol](https://epistemedia.org/topics/epistemic-mesh/), [Sovereign Realm Federation](https://epistemedia.org/topics/federation/), [Autonomous Governance](https://epistemedia.org/topics/governance/), [Knowledge Objects](https://epistemedia.org/topics/knowledge-objects/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/), [Research Program](https://epistemedia.org/topics/research-program/), [Security and Adversarial Robustness](https://epistemedia.org/topics/security/)

## Source content

# EM-0042 — Close the second cold-start selection and clock gaps

## Objective

Preserve autonomous submission PR #72 as the immutable second cold-start receipt, fix the exact-head
CI binding it exposed, prevent agents from selecting accepted or closely restated work, and replace
contributor-invented runtime timestamps with executable-captured start and completion times before a
third cold start.

## Accepted evidence and boundaries

- Contract-accepted base: `a11c24edafa30e375bc099b7cfe3260bde7f0555`.
- Frozen queue receipt: PR #72 at head `3f965831031b88f4efff954550ecb383fec0e5a8`, tree
  `c67de1a45bd9d97aac6cd39c0f63aa73a30b3a2d`.
- The packet remains an untrusted, blocking, open draft and is never repaired or merged.
- Cases 001–004, PR #69, accepted open dockets, and existing public meanings remain unchanged.
- No admission, promotion, numbered case, deployment, or further provider run occurs until the
  implementation passes exact-head independent review, protected integration, resulting-main
  validation, and an authorized release-identity read-back.

## Implementation

1. Check out the immutable pull-request source head in CI rather than GitHub's synthetic merge ref.
2. Require the accepted base commit time to precede the executable-captured runtime chronology.
3. Have `research prepare` record `runtime.started_at`, `research complete` record
   `runtime.completed_at` before fail-closed validation, and `research submit` re-seal completion
   immediately before canonicalizing queue bytes.
4. Compare against every accepted dossier and reviewed open docket with subject-aware anchors;
   malformed or incomplete comparison records fail closed, while generic shared vocabulary alone
   does not trigger a collision. Instruct agents to inspect open queue PRs and record that comparison.
5. Add focused regressions, run the full deterministic repository check, append an immutable run
   receipt, and obtain a fresh non-author exact-head review before protected merge.

## Status

- 2026-08-30: PR #74 registered the immutable EM-0042 contract, passed independent exact-head review
  and protected checks, merged as `a11c24edafa30e375bc099b7cfe3260bde7f0555`, and passed
  resulting-main validation run `33295729283` / job `99214940856`.
- 2026-08-30: the first pre-registration implementation PR #73 remains open and draft after its
  independent reviewer identified the missing contract/receipt, generic lexical-collision behavior,
  silently skipped malformed prior art, and a non-isolated chronology test. It is preserved as a
  negative review artifact and is not reused as the implementation base.
- 2026-08-30: v2 implementation began from the accepted contract commit on
  `codex/em-0042-implementation-v2`. PR #72, Cases 001–004, and accepted epistemic records remain
  untouched.
- 2026-08-30: the v2 focused open-docket, research-kit, and workflow-security suite passed, including
  exact close-paraphrase, acronym/number-word, unrelated-vocabulary, missing dossier, malformed
  manifest, malformed reviewed-docket, late-base, missing-base-time, and invalid-base-time
  adversaries. Defect-focused Ruff, workflow YAML parsing, `git diff --check`, and full `make check`
  passed. The candidate projection contains 220 repository objects across 11 topics; disclosure
  audit, deterministic rebuild, and source-state checks were clean. The clean-worktree
  bootstrap remains dependent on the documented `PYTHONPATH=src` verified-environment workaround.
- 2026-08-30: independent review of PR #75 at `d25bbd93eb677d98d85c199c641de3fd9ab26991`
  returned CHANGES REQUIRED: broken or symlinked reviewed-docket paths were skipped, and the first
  detailed run receipt bound a pre-commit catalog identity and contained one non-executable display
  form for the YAML command. The original receipt is preserved; this branch adds the two path
  adversaries and an append-only superseding receipt generated from a committed content head.
