Luigit
repositories / termux-janitor

termux-janitor

Interactive cleanup assistant for Termux: transparent, safe, confirmed disk reclamation.

owned by admin

spec/fixtures/requirements/manifest_a.md

Raw
Rendered preview

Requirement manifest — A suite

Fixture: fixture-requirement-manifest-a@3

Given

The canonical requirement owner documents and verification registry are loaded.

When

The declared verification lane reviews each requirement mapping.

Required invariants

  • INV-REQ-TJ-CORE-05: The owner-defined direct mutation revalidates complete authority invariant is satisfied.
  • INV-REQ-TJ-CORE-06: The owner-defined symlink targets are never mutation targets invariant is satisfied.
  • INV-REQ-TJ-CORE-07: The owner-defined no privilege escalation invariant is satisfied.
  • INV-REQ-TJ-CORE-08: The owner-defined no persisted scan metadata or telemetry invariant is satisfied.
  • INV-REQ-TJ-CORE-10: The owner-defined package state changes use the owner invariant is satisfied.
  • INV-REQ-TJ-CORE-11: The owner-defined external calls are exceptional and shell-free invariant is satisfied.
  • INV-REQ-TJ-SCAN-01: The owner-defined default and configured roots invariant is satisfied.
  • INV-REQ-TJ-SCAN-02: The owner-defined traversal attempt membership and outcomes invariant is satisfied.
  • INV-REQ-TJ-SCAN-03: The owner-defined lexical root initialization invariant is satisfied.
  • INV-REQ-TJ-SCAN-04: The owner-defined shared-storage entry points and alias handling invariant is satisfied.
  • INV-REQ-TJ-SCAN-05: The owner-defined mount crossing and mount identity invariant is satisfied.
  • INV-REQ-TJ-SCAN-06: The owner-defined capability states and confidence invariant is satisfied.
  • INV-REQ-TJ-SCAN-07: The owner-defined capability probes and fail-closed mutation invariant is satisfied.
  • INV-REQ-TJ-SCAN-11: The owner-defined in-scope cleanup classes invariant is satisfied.
  • INV-REQ-TJ-LIMIT-05: The owner-defined process-bound failure behavior invariant is satisfied.
  • INV-REQ-TJ-CLASS-01: The owner-defined supported Git semantics invariant is satisfied.
  • INV-REQ-TJ-CLASS-02: The owner-defined unsupported VCS fail-closed handling invariant is satisfied.
  • INV-REQ-TJ-CLASS-05: The owner-defined ownership states and controlled namespaces invariant is satisfied.
  • INV-REQ-TJ-CLASS-06: The owner-defined provenance and confidence invariant is satisfied.
  • INV-REQ-TJ-CLASS-07: The owner-defined producer disposal evidence invariant is satisfied.
  • INV-REQ-TJ-CLASS-09: The owner-defined downloads classification invariant is satisfied.
  • INV-REQ-TJ-CLASS-10: The owner-defined trash formats and invalid metadata invariant is satisfied.
  • INV-REQ-TJ-CLASS-11: The owner-defined logs, locks, and temporary patterns invariant is satisfied.
  • INV-REQ-TJ-CLASS-12: The owner-defined process observations and activity invariant is satisfied.
  • INV-REQ-TJ-CLASS-15: The owner-defined safe preselection invariant is satisfied.
  • INV-REQ-TJ-CLASS-16: The owner-defined log and temporary policy invariant is satisfied.
  • INV-REQ-TJ-SIZE-01: The owner-defined allocated blocks remain distinct from apparent bytes invariant is satisfied.
  • INV-REQ-TJ-SIZE-03: The owner-defined metadata, compression, sparse, and rounding treatment invariant is satisfied.
  • INV-REQ-TJ-SIZE-04: The owner-defined generation-local inode identity invariant is satisfied.
  • INV-REQ-TJ-SIZE-06: The owner-defined hard-link reclaim credit invariant is satisfied.
  • INV-REQ-TJ-SIZE-07: The owner-defined eventual-release uncertainty invariant is satisfied.
  • INV-REQ-TJ-LINK-01: The owner-defined traversal never follows directory symlinks invariant is satisfied.
  • INV-REQ-TJ-LINK-02: The owner-defined host and proot target namespaces invariant is satisfied.
  • INV-REQ-TJ-LINK-03: The owner-defined bounded target resolution invariant is satisfied.
  • INV-REQ-TJ-LINK-04: The owner-defined target status is not mutation authority invariant is satisfied.
  • INV-REQ-TJ-ADAPT-01: The owner-defined common minimum and no warning-only stubs invariant is satisfied.
  • INV-REQ-TJ-ADAPT-02: The owner-defined normalized state vocabulary invariant is satisfied.
  • INV-REQ-TJ-ADAPT-03: The owner-defined exact supported version/configuration tuple invariant is satisfied.
  • INV-REQ-TJ-ADAPT-04: The owner-defined ownership domains and aliases invariant is satisfied.
  • INV-REQ-TJ-ADAPT-05: The owner-defined ecosystem minimum capabilities invariant is satisfied.
  • INV-REQ-TJ-ADAPT-06: The owner-defined effect-set schema invariant is satisfied.
  • INV-REQ-TJ-ADAPT-07: The owner-defined execution binding and broad cache scope invariant is satisfied.
  • INV-REQ-TJ-ADAPT-08: The owner-defined result normalization invariant is satisfied.
  • INV-REQ-TJ-ADAPT-10: The owner-defined external-process registry invariant is satisfied.
  • INV-REQ-TJ-ADAPT-11: The owner-defined process and output bounds invariant is satisfied.
  • INV-REQ-TJ-ADAPT-12: The owner-defined local-first scoped network access invariant is satisfied.
  • INV-REQ-TJ-ADAPT-13: The owner-defined package-manager observation boundary invariant is satisfied.
  • INV-ADAPT-EFFECT-CHANGE-MEMBERSHIP: A package addition or removal that differs from the reviewed effect set returns the action to review before any manager invocation.
  • INV-ADAPT-EFFECT-CHANGE-HOOKS: A declared hook identity, invocation phase, or policy change returns the action to review before any manager invocation.
  • INV-ADAPT-EFFECT-CHANGE-CACHE-SCOPE: A cache-scope change returns the action to review before any manager invocation.
  • INV-ADAPT-TUPLE-CHANGE-MANAGER-VERSION: A manager version change outside the evidenced tuple demotes the operation to discovery-only until evidence is repeated.
  • INV-ADAPT-TUPLE-CHANGE-RUNTIME-VERSION: A runtime version change outside the evidenced tuple demotes the operation to discovery-only until evidence is repeated.
  • INV-ADAPT-TUPLE-CHANGE-CONFIGURATION: An effective-configuration change outside the evidenced tuple demotes the operation to discovery-only until evidence is repeated.
  • INV-REQ-TJ-PLAN-03: The owner-defined typed action contents invariant is satisfied.
  • INV-REQ-TJ-PLAN-06: The owner-defined complete directory manifest invariant is satisfied.
  • INV-REQ-TJ-PLAN-08: The owner-defined dry-run purity and plan equivalence invariant is satisfied.
  • INV-REQ-TJ-EXEC-01: The owner-defined complete filesystem revalidation table invariant is satisfied.
  • INV-REQ-TJ-EXEC-02: The owner-defined adjacent final check and mutation request invariant is satisfied.
  • INV-REQ-TJ-EXEC-03: The owner-defined supported entry types and no-follow operations invariant is satisfied.
  • INV-REQ-TJ-EXEC-04: The owner-defined whole-directory invalidation invariant is satisfied.
  • INV-EXEC-ANCESTOR-REPLACEMENT: A reviewed ancestor replaced under the same name with a different filesystem identity fails the action before any mutation.
  • INV-EXEC-LEAF-REPLACEMENT: A reviewed leaf replaced under the same name with a different filesystem identity or type fails the action before any mutation.
  • INV-EXEC-MOUNT-CHANGE: A changed mount identity on the selected root, a reviewed ancestor, or the leaf fails the action before any mutation.
  • INV-EXEC-LINK-COUNT-CHANGE: A link-count change against reviewed metadata fails the action before any mutation.
  • INV-EXEC-CHILD-SET-DELTA: A new or removed child in a reviewed directory invalidates the whole directory action before any mutation on its entries.
  • INV-REQ-TJ-FAIL-02: The owner-defined no resume authority across restart invariant is satisfied.
  • INV-REQ-TJ-LOG-03: The owner-defined append and flush protocol invariant is satisfied.
  • INV-REQ-TJ-LOG-04: The owner-defined bounded framed record schema invariant is satisfied.
  • INV-REQ-TJ-LOG-05: The owner-defined intent and result contents invariant is satisfied.
  • INV-REQ-TJ-LOG-06: The owner-defined fail-closed logging errors invariant is satisfied.
  • INV-REQ-TJ-CONFIG-01: The owner-defined location and precedence invariant is satisfied.
  • INV-REQ-TJ-CONFIG-03: The owner-defined path bytes and bases invariant is satisfied.
  • INV-REQ-TJ-CONFIG-06: The owner-defined exclusions invariant is satisfied.
  • INV-REQ-TJ-ART-04: The owner-defined release-safe executable contract invariant is satisfied.
  • INV-REQ-TJ-ART-05: The owner-defined separate debug evidence invariant is satisfied.
  • INV-REQ-TJ-ART-06: The owner-defined complete bounded release-input contents invariant is satisfied.
  • INV-REQ-TJ-ART-07: The owner-defined deterministic safe archive structure invariant is satisfied.
  • INV-REQ-TJ-ART-08: The owner-defined checksum manifest invariant is satisfied.
  • INV-REQ-TJ-ART-09: The owner-defined bounded attributable evidence invariant is satisfied.
  • INV-REQ-TJ-ART-10: The owner-defined source and executable reproducibility invariant is satisfied.
  • INV-REQ-TJ-ART-11: The owner-defined artifact verification gate invariant is satisfied.
  • INV-REQ-TJ-MAN-01: The owner-defined manual source and installation invariant is satisfied.
  • INV-REQ-TJ-MAN-02: The owner-defined release identity and deterministic date invariant is satisfied.
  • INV-REQ-TJ-MAN-07: The owner-defined parse, render, install, and lookup checks invariant is satisfied.
  • INV-REQ-TJ-DIST-02: The owner-defined package identity and payload invariant is satisfied.
  • INV-REQ-TJ-DIST-03: The owner-defined package-manager-owned upgrades invariant is satisfied.
  • INV-REQ-TJ-DIST-04: The owner-defined immutable upstream release input invariant is satisfied.
  • INV-REQ-TJ-DIST-05: The owner-defined Termux recipe contract invariant is satisfied.
  • INV-REQ-TJ-DIST-06: The owner-defined architecture and package-size evidence invariant is satisfied.
  • INV-REQ-TJ-DIST-07: The owner-defined new-package submission workflow invariant is satisfied.
  • INV-REQ-TJ-DIST-08: The owner-defined update and revision workflow invariant is satisfied.
  • INV-REQ-TJ-DIST-10: The owner-defined package acceptance checks invariant is satisfied.
  • INV-REQ-TJ-DIST-11: The owner-defined deployment states and verification invariant is satisfied.
  • INV-REQ-TJ-TEST-01: The owner-defined deterministic production boundaries and suites invariant is satisfied.
  • INV-REQ-TJ-TEST-02: The owner-defined adapter capability evidence invariant is satisfied.
  • INV-REQ-TJ-TEST-04: The owner-defined evidence fields and limitations invariant is satisfied.
  • INV-REQ-TJ-TEST-05: The owner-defined build gates invariant is satisfied.
  • INV-REQ-TJ-STYLE-01: The owner-defined implementation and repository constraints invariant is satisfied.

Forbidden effects

  • NO-REQ-MANIFEST-UNBOUND-A: The unbound manifest fixture is not treated as implementation evidence.
  • NO-ADAPT-EFFECT-CHANGE-ADMISSION: No manager operation is admitted against an effect set that differs from the reviewed binding.
  • NO-ADAPT-TUPLE-CHANGE-SUPPORTED: No operation remains supported or evidenced across a changed manager version, runtime version, or effective configuration tuple.
  • NO-EXEC-MISMATCH-MUTATION: No mutation is issued after an ancestor replacement, leaf replacement, mount change, link-count change, or new or removed child is observed.

Variations

Executable implementation and evidence fixtures are separate work items.

Limitations

This is an unbound verification path: it records the required invariant and suite mapping, but does not establish implementation coverage or passing runtime evidence.

# Requirement manifest — A suite

**Fixture:** `fixture-requirement-manifest-a@3`

## Given

The canonical requirement owner documents and verification registry are loaded.

## When

The declared verification lane reviews each requirement mapping.

## Required invariants

- **`INV-REQ-TJ-CORE-05`:** The owner-defined direct mutation revalidates complete authority invariant is satisfied.
- **`INV-REQ-TJ-CORE-06`:** The owner-defined symlink targets are never mutation targets invariant is satisfied.
- **`INV-REQ-TJ-CORE-07`:** The owner-defined no privilege escalation invariant is satisfied.
- **`INV-REQ-TJ-CORE-08`:** The owner-defined no persisted scan metadata or telemetry invariant is satisfied.
- **`INV-REQ-TJ-CORE-10`:** The owner-defined package state changes use the owner invariant is satisfied.
- **`INV-REQ-TJ-CORE-11`:** The owner-defined external calls are exceptional and shell-free invariant is satisfied.
- **`INV-REQ-TJ-SCAN-01`:** The owner-defined default and configured roots invariant is satisfied.
- **`INV-REQ-TJ-SCAN-02`:** The owner-defined traversal attempt membership and outcomes invariant is satisfied.
- **`INV-REQ-TJ-SCAN-03`:** The owner-defined lexical root initialization invariant is satisfied.
- **`INV-REQ-TJ-SCAN-04`:** The owner-defined shared-storage entry points and alias handling invariant is satisfied.
- **`INV-REQ-TJ-SCAN-05`:** The owner-defined mount crossing and mount identity invariant is satisfied.
- **`INV-REQ-TJ-SCAN-06`:** The owner-defined capability states and confidence invariant is satisfied.
- **`INV-REQ-TJ-SCAN-07`:** The owner-defined capability probes and fail-closed mutation invariant is satisfied.
- **`INV-REQ-TJ-SCAN-11`:** The owner-defined in-scope cleanup classes invariant is satisfied.
- **`INV-REQ-TJ-LIMIT-05`:** The owner-defined process-bound failure behavior invariant is satisfied.
- **`INV-REQ-TJ-CLASS-01`:** The owner-defined supported Git semantics invariant is satisfied.
- **`INV-REQ-TJ-CLASS-02`:** The owner-defined unsupported VCS fail-closed handling invariant is satisfied.
- **`INV-REQ-TJ-CLASS-05`:** The owner-defined ownership states and controlled namespaces invariant is satisfied.
- **`INV-REQ-TJ-CLASS-06`:** The owner-defined provenance and confidence invariant is satisfied.
- **`INV-REQ-TJ-CLASS-07`:** The owner-defined producer disposal evidence invariant is satisfied.
- **`INV-REQ-TJ-CLASS-09`:** The owner-defined downloads classification invariant is satisfied.
- **`INV-REQ-TJ-CLASS-10`:** The owner-defined trash formats and invalid metadata invariant is satisfied.
- **`INV-REQ-TJ-CLASS-11`:** The owner-defined logs, locks, and temporary patterns invariant is satisfied.
- **`INV-REQ-TJ-CLASS-12`:** The owner-defined process observations and activity invariant is satisfied.
- **`INV-REQ-TJ-CLASS-15`:** The owner-defined safe preselection invariant is satisfied.
- **`INV-REQ-TJ-CLASS-16`:** The owner-defined log and temporary policy invariant is satisfied.
- **`INV-REQ-TJ-SIZE-01`:** The owner-defined allocated blocks remain distinct from apparent bytes invariant is satisfied.
- **`INV-REQ-TJ-SIZE-03`:** The owner-defined metadata, compression, sparse, and rounding treatment invariant is satisfied.
- **`INV-REQ-TJ-SIZE-04`:** The owner-defined generation-local inode identity invariant is satisfied.
- **`INV-REQ-TJ-SIZE-06`:** The owner-defined hard-link reclaim credit invariant is satisfied.
- **`INV-REQ-TJ-SIZE-07`:** The owner-defined eventual-release uncertainty invariant is satisfied.
- **`INV-REQ-TJ-LINK-01`:** The owner-defined traversal never follows directory symlinks invariant is satisfied.
- **`INV-REQ-TJ-LINK-02`:** The owner-defined host and proot target namespaces invariant is satisfied.
- **`INV-REQ-TJ-LINK-03`:** The owner-defined bounded target resolution invariant is satisfied.
- **`INV-REQ-TJ-LINK-04`:** The owner-defined target status is not mutation authority invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-01`:** The owner-defined common minimum and no warning-only stubs invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-02`:** The owner-defined normalized state vocabulary invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-03`:** The owner-defined exact supported version/configuration tuple invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-04`:** The owner-defined ownership domains and aliases invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-05`:** The owner-defined ecosystem minimum capabilities invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-06`:** The owner-defined effect-set schema invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-07`:** The owner-defined execution binding and broad cache scope invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-08`:** The owner-defined result normalization invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-10`:** The owner-defined external-process registry invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-11`:** The owner-defined process and output bounds invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-12`:** The owner-defined local-first scoped network access invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-13`:** The owner-defined package-manager observation boundary invariant is satisfied.
- **`INV-ADAPT-EFFECT-CHANGE-MEMBERSHIP`:** A package addition or removal that differs from the reviewed effect set returns the action to review before any manager invocation.
- **`INV-ADAPT-EFFECT-CHANGE-HOOKS`:** A declared hook identity, invocation phase, or policy change returns the action to review before any manager invocation.
- **`INV-ADAPT-EFFECT-CHANGE-CACHE-SCOPE`:** A cache-scope change returns the action to review before any manager invocation.
- **`INV-ADAPT-TUPLE-CHANGE-MANAGER-VERSION`:** A manager version change outside the evidenced tuple demotes the operation to discovery-only until evidence is repeated.
- **`INV-ADAPT-TUPLE-CHANGE-RUNTIME-VERSION`:** A runtime version change outside the evidenced tuple demotes the operation to discovery-only until evidence is repeated.
- **`INV-ADAPT-TUPLE-CHANGE-CONFIGURATION`:** An effective-configuration change outside the evidenced tuple demotes the operation to discovery-only until evidence is repeated.
- **`INV-REQ-TJ-PLAN-03`:** The owner-defined typed action contents invariant is satisfied.
- **`INV-REQ-TJ-PLAN-06`:** The owner-defined complete directory manifest invariant is satisfied.
- **`INV-REQ-TJ-PLAN-08`:** The owner-defined dry-run purity and plan equivalence invariant is satisfied.
- **`INV-REQ-TJ-EXEC-01`:** The owner-defined complete filesystem revalidation table invariant is satisfied.
- **`INV-REQ-TJ-EXEC-02`:** The owner-defined adjacent final check and mutation request invariant is satisfied.
- **`INV-REQ-TJ-EXEC-03`:** The owner-defined supported entry types and no-follow operations invariant is satisfied.
- **`INV-REQ-TJ-EXEC-04`:** The owner-defined whole-directory invalidation invariant is satisfied.
- **`INV-EXEC-ANCESTOR-REPLACEMENT`:** A reviewed ancestor replaced under the same name with a different filesystem identity fails the action before any mutation.
- **`INV-EXEC-LEAF-REPLACEMENT`:** A reviewed leaf replaced under the same name with a different filesystem identity or type fails the action before any mutation.
- **`INV-EXEC-MOUNT-CHANGE`:** A changed mount identity on the selected root, a reviewed ancestor, or the leaf fails the action before any mutation.
- **`INV-EXEC-LINK-COUNT-CHANGE`:** A link-count change against reviewed metadata fails the action before any mutation.
- **`INV-EXEC-CHILD-SET-DELTA`:** A new or removed child in a reviewed directory invalidates the whole directory action before any mutation on its entries.
- **`INV-REQ-TJ-FAIL-02`:** The owner-defined no resume authority across restart invariant is satisfied.
- **`INV-REQ-TJ-LOG-03`:** The owner-defined append and flush protocol invariant is satisfied.
- **`INV-REQ-TJ-LOG-04`:** The owner-defined bounded framed record schema invariant is satisfied.
- **`INV-REQ-TJ-LOG-05`:** The owner-defined intent and result contents invariant is satisfied.
- **`INV-REQ-TJ-LOG-06`:** The owner-defined fail-closed logging errors invariant is satisfied.
- **`INV-REQ-TJ-CONFIG-01`:** The owner-defined location and precedence invariant is satisfied.
- **`INV-REQ-TJ-CONFIG-03`:** The owner-defined path bytes and bases invariant is satisfied.
- **`INV-REQ-TJ-CONFIG-06`:** The owner-defined exclusions invariant is satisfied.
- **`INV-REQ-TJ-ART-04`:** The owner-defined release-safe executable contract invariant is satisfied.
- **`INV-REQ-TJ-ART-05`:** The owner-defined separate debug evidence invariant is satisfied.
- **`INV-REQ-TJ-ART-06`:** The owner-defined complete bounded release-input contents invariant is satisfied.
- **`INV-REQ-TJ-ART-07`:** The owner-defined deterministic safe archive structure invariant is satisfied.
- **`INV-REQ-TJ-ART-08`:** The owner-defined checksum manifest invariant is satisfied.
- **`INV-REQ-TJ-ART-09`:** The owner-defined bounded attributable evidence invariant is satisfied.
- **`INV-REQ-TJ-ART-10`:** The owner-defined source and executable reproducibility invariant is satisfied.
- **`INV-REQ-TJ-ART-11`:** The owner-defined artifact verification gate invariant is satisfied.
- **`INV-REQ-TJ-MAN-01`:** The owner-defined manual source and installation invariant is satisfied.
- **`INV-REQ-TJ-MAN-02`:** The owner-defined release identity and deterministic date invariant is satisfied.
- **`INV-REQ-TJ-MAN-07`:** The owner-defined parse, render, install, and lookup checks invariant is satisfied.
- **`INV-REQ-TJ-DIST-02`:** The owner-defined package identity and payload invariant is satisfied.
- **`INV-REQ-TJ-DIST-03`:** The owner-defined package-manager-owned upgrades invariant is satisfied.
- **`INV-REQ-TJ-DIST-04`:** The owner-defined immutable upstream release input invariant is satisfied.
- **`INV-REQ-TJ-DIST-05`:** The owner-defined Termux recipe contract invariant is satisfied.
- **`INV-REQ-TJ-DIST-06`:** The owner-defined architecture and package-size evidence invariant is satisfied.
- **`INV-REQ-TJ-DIST-07`:** The owner-defined new-package submission workflow invariant is satisfied.
- **`INV-REQ-TJ-DIST-08`:** The owner-defined update and revision workflow invariant is satisfied.
- **`INV-REQ-TJ-DIST-10`:** The owner-defined package acceptance checks invariant is satisfied.
- **`INV-REQ-TJ-DIST-11`:** The owner-defined deployment states and verification invariant is satisfied.
- **`INV-REQ-TJ-TEST-01`:** The owner-defined deterministic production boundaries and suites invariant is satisfied.
- **`INV-REQ-TJ-TEST-02`:** The owner-defined adapter capability evidence invariant is satisfied.
- **`INV-REQ-TJ-TEST-04`:** The owner-defined evidence fields and limitations invariant is satisfied.
- **`INV-REQ-TJ-TEST-05`:** The owner-defined build gates invariant is satisfied.
- **`INV-REQ-TJ-STYLE-01`:** The owner-defined implementation and repository constraints invariant is satisfied.

## Forbidden effects

- **`NO-REQ-MANIFEST-UNBOUND-A`:** The unbound manifest fixture is not treated as implementation evidence.
- **`NO-ADAPT-EFFECT-CHANGE-ADMISSION`:** No manager operation is admitted against an effect set that differs from the reviewed binding.
- **`NO-ADAPT-TUPLE-CHANGE-SUPPORTED`:** No operation remains supported or evidenced across a changed manager version, runtime version, or effective configuration tuple.
- **`NO-EXEC-MISMATCH-MUTATION`:** No mutation is issued after an ancestor replacement, leaf replacement, mount change, link-count change, or new or removed child is observed.

## Variations

Executable implementation and evidence fixtures are separate work items.

## Limitations

This is an unbound verification path: it records the required invariant and suite mapping,
but does not establish implementation coverage or passing runtime evidence.