# Cost-model loop closed: found, fixed, verified — 2026-09-28

## Result and scope

Company-authored physical-board engineering evidence, completing in public the
loop the cost-rail record opened: the admission table's capability entries —
flagged in its own prose as stub-measured — were measured on the deployed
board, the table was fixed, and the fix was verified on the metal.

**Found** (2026-09-27): a propose through the real monitor costs 13,621
cycles against its 464-credit stub charge (14.8×); the seal, measured for
this close-out, costs **12,262,800 cycles per Ed25519 sign against its
480-credit stub charge — 57.9×**. Ordinary instruction classes held
throughout (71.5–79.4% utilization, the board within 0.2–3.6% of its RTL
model).

**Fixed**: the admission table's call entries are replaced with
deployed-callee bounds — sense 1,280, propose 17,040, seal 15,328,512
cycles — derived by the table's own convention (observed maximum × 1.25,
rounded up to 16). The superseded stub-call table is retained in the source
under its own name so the finding remains reproducible against the table that
exhibited it; the pinning test is updated.

**Verified** (on the board): with the corrected table, every class now runs
within its charged credits — the deployed propose at 667‰, the deployed
seal at 50‰, ordinary classes at 703–794‰ (against 14,848‰ and 57,880‰
before the fix). The firmware now derives its table banner from the compiled
model rather than a string constant, which is itself how the first
verification attempt was caught running a stale table.

## What this establishes — and does not

It establishes the admission model end-to-end on the deployed board: every
instruction class, including the measured capability callees, is charged at
or above its observed cost with margin. It does not establish WCET; the
seal entry bounds one sign of a 32-byte message in the default-features
crate configuration; a different configuration needs its own measurement.

## Reproducibility

The completed internal record is
`evidence/runs/2026-09-27-ecp5-j4-002/manifest.json` (verification run,
fixed table, before/after ratios), building on the finding record
`evidence/runs/2026-09-27-ecp5-j4-001/`. Arm-free; volatile SRAM only; no
actuator, product I/O or configuration flash. Same operator, no independent
review — engineering evidence, not a certification.
