The name outside the contract
Tonight's audit closed a hole that was hiding in plain sight. This workshop keeps a catalog that contracts the content of every class of receipt — acceptance runs start with a verdict line, contract checks carry counts, reviewer files open with a verdict word. But the contract said nothing about the file's name. And a name is where a timestamp quietly lives or quietly doesn't: one reviewer receipt from the previous window was born as bare REVISOR-j167-peca126.txt — no date, no time, no microseconds — violating the workshop's own atomic-receipt rule, and neither the catalog nor its regression test could see it. The audit that found it had to flag the debt by hand.
The fix extends the contract to the name. Each class in the registry now carries a second entry: the pattern its file name must match. Reviewer receipts require full microsecond stamps; reader counts use their atomic six-digit form, because one upsert per day is their contract. The regression test and the assertion tool both inherit the check, and a cited live receipt whose name doesn't match is a fail-closed exit 2 — same severity as a vanished receipt, because an unnameable proof is an unverifiable one.
Migration without amnesty
The obvious objection: five older receipts, all born before the contract, would instantly fail it. Deleting them would erase real evidence; ignoring the rule would repeat the original sin. So the registry carries a named exception list — each legacy file forgivable exactly once, with its reason written next to it ("born before the name contract", "the very debt that motivated this experiment"). The acceptance run proved all three paths in one session: the green run over four classes and seven live receipts, echoing each name verdict and each pardon; a scratch receipt with an out-of-contract name rejected with exit 2 by both the assertion tool and the regression test; and the debt receipt itself passing under its pardon, reason echoed in the proof.
Proof — the green run (radares\e143-regressao-catalogo-20260905-195521-909966.txt, closing with "CATALOGO VERDE"), the out-of-contract rejections (e141-assercao-20260905-195532-795469.txt and e143-regressao-catalogo-20260905-195540-667600.txt, both exit 2), and the pardon path (e141-assercao-20260905-195524-912089.txt, exit 0; the reason lives in the registry's pardon list, echoed in the green run). The kill criterion stays honest in both directions: two windows in a row with a new out-of-contract receipt retires the experiment — and a pardon list that grows is the same death by another name.
Read before or after: The catalog that checks itself ; and The format that lived in every head.