The canonical requirement owner documents and verification registry are loaded.
When
The declared verification lane reviews each requirement mapping.
Required invariants
INV-REQ-TJ-CORE-05: The owner-defined direct mutation revalidates complete authority invariant is satisfied.
INV-REQ-TJ-CORE-06: The owner-defined symlink targets are never mutation targets invariant is satisfied.
INV-REQ-TJ-CORE-09: The owner-defined incompleteness is always visible invariant is satisfied.
INV-REQ-TJ-SCAN-02: The owner-defined traversal attempt membership and outcomes invariant is satisfied.
INV-REQ-TJ-SCAN-08: The owner-defined fixed storage and exhaustion invariant is satisfied.
INV-REQ-TJ-LIMIT-02: The owner-defined initial allocation and fail-closed exhaustion invariant is satisfied.
INV-REQ-TJ-LIMIT-03: The owner-defined oversized authority and depth handling invariant is satisfied.
INV-REQ-TJ-LIMIT-05: The owner-defined process-bound failure behavior invariant is satisfied.
INV-REQ-TJ-LIMIT-06: The owner-defined queue reservations and latency invariant is satisfied.
INV-REQ-TJ-CLASS-12: The owner-defined process observations and activity invariant is satisfied.
INV-REQ-TJ-SIZE-02: The owner-defined checked arithmetic and overflow propagation invariant is satisfied.
INV-REQ-TJ-SIZE-06: The owner-defined hard-link reclaim credit invariant is satisfied.
INV-REQ-TJ-LINK-01: The owner-defined traversal never follows directory symlinks invariant is satisfied.
INV-REQ-TJ-LINK-04: The owner-defined target status is not mutation authority invariant is satisfied.
INV-REQ-TJ-ADAPT-07: The owner-defined execution binding and broad cache scope invariant is satisfied.
INV-REQ-TJ-ADAPT-11: The owner-defined process and output bounds invariant is satisfied.
INV-ADAPT-EFFECT-CHANGE-MEMBERSHIP: A package addition or removal that differs from the reviewed effect set returns the action to review before any manager invocation.
INV-ADAPT-EFFECT-CHANGE-HOOKS: A declared hook identity, invocation phase, or policy change returns the action to review before any manager invocation.
INV-ADAPT-EFFECT-CHANGE-CACHE-SCOPE: A cache-scope change returns the action to review before any manager invocation.
INV-REQ-TJ-PLAN-02: The owner-defined deterministic topological action order invariant is satisfied.
INV-REQ-TJ-PLAN-04: The owner-defined dependencies and expected effects invariant is satisfied.
INV-REQ-TJ-PLAN-06: The owner-defined complete directory manifest invariant is satisfied.
INV-REQ-TJ-EXEC-01: The owner-defined complete filesystem revalidation table invariant is satisfied.
INV-REQ-TJ-EXEC-02: The owner-defined adjacent final check and mutation request invariant is satisfied.
INV-REQ-TJ-EXEC-04: The owner-defined whole-directory invalidation invariant is satisfied.
INV-EXEC-ANCESTOR-REPLACEMENT: A reviewed ancestor replaced under the same name with a different filesystem identity fails the action before any mutation.
INV-EXEC-LEAF-REPLACEMENT: A reviewed leaf replaced under the same name with a different filesystem identity or type fails the action before any mutation.
INV-EXEC-MOUNT-CHANGE: A changed mount identity on the selected root, a reviewed ancestor, or the leaf fails the action before any mutation.
INV-EXEC-LINK-COUNT-CHANGE: A link-count change against reviewed metadata fails the action before any mutation.
INV-EXEC-CHILD-SET-DELTA: A new or removed child in a reviewed directory invalidates the whole directory action before any mutation on its entries.
INV-REQ-TJ-FAIL-01: The owner-defined action failure pause and dependency blocking invariant is satisfied.
INV-REQ-TJ-FAIL-03: The owner-defined cancellation reconciliation invariant is satisfied.
INV-REQ-TJ-LOG-06: The owner-defined fail-closed logging errors invariant is satisfied.
INV-REQ-TJ-UI-05: The owner-defined refresh teardown invariant is satisfied.
INV-REQ-TJ-UI-06: The owner-defined unified cancellation invariant is satisfied.
INV-REQ-TJ-TEST-01: The owner-defined deterministic production boundaries and suites invariant is satisfied.
INV-REQ-TJ-TEST-03: The owner-defined fixed allocator and capacity boundaries invariant is satisfied.
INV-REQ-TJ-TEST-04: The owner-defined evidence fields and limitations invariant is satisfied.
INV-REQ-TJ-TEST-05: The owner-defined build gates invariant is satisfied.
INV-REQ-TJ-PERF-02: The owner-defined explicit performance budgets invariant is satisfied.
INV-REQ-TJ-PERF-04: The owner-defined measurement methods invariant is satisfied.
Forbidden effects
NO-REQ-MANIFEST-UNBOUND-SIM: The unbound manifest fixture is not treated as implementation evidence.
NO-ADAPT-EFFECT-CHANGE-ADMISSION: No manager operation is admitted against an effect set that differs from the reviewed binding.
NO-EXEC-MISMATCH-MUTATION: No mutation is issued after an ancestor replacement, leaf replacement, mount change, link-count change, or new or removed child is observed.
Variations
Executable implementation and evidence fixtures are separate work items.
Limitations
This is an unbound verification path: it records the required invariant and suite mapping,
but does not establish implementation coverage or passing runtime evidence.
# Requirement manifest — SIM suite
**Fixture:** `fixture-requirement-manifest-sim@4`
## Given
The canonical requirement owner documents and verification registry are loaded.
## When
The declared verification lane reviews each requirement mapping.
## Required invariants
- **`INV-REQ-TJ-CORE-05`:** The owner-defined direct mutation revalidates complete authority invariant is satisfied.
- **`INV-REQ-TJ-CORE-06`:** The owner-defined symlink targets are never mutation targets invariant is satisfied.
- **`INV-REQ-TJ-CORE-09`:** The owner-defined incompleteness is always visible invariant is satisfied.
- **`INV-REQ-TJ-SCAN-02`:** The owner-defined traversal attempt membership and outcomes invariant is satisfied.
- **`INV-REQ-TJ-SCAN-08`:** The owner-defined fixed storage and exhaustion invariant is satisfied.
- **`INV-REQ-TJ-LIMIT-02`:** The owner-defined initial allocation and fail-closed exhaustion invariant is satisfied.
- **`INV-REQ-TJ-LIMIT-03`:** The owner-defined oversized authority and depth handling invariant is satisfied.
- **`INV-REQ-TJ-LIMIT-05`:** The owner-defined process-bound failure behavior invariant is satisfied.
- **`INV-REQ-TJ-LIMIT-06`:** The owner-defined queue reservations and latency invariant is satisfied.
- **`INV-REQ-TJ-CLASS-12`:** The owner-defined process observations and activity invariant is satisfied.
- **`INV-REQ-TJ-SIZE-02`:** The owner-defined checked arithmetic and overflow propagation invariant is satisfied.
- **`INV-REQ-TJ-SIZE-06`:** The owner-defined hard-link reclaim credit invariant is satisfied.
- **`INV-REQ-TJ-LINK-01`:** The owner-defined traversal never follows directory symlinks invariant is satisfied.
- **`INV-REQ-TJ-LINK-04`:** The owner-defined target status is not mutation authority invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-07`:** The owner-defined execution binding and broad cache scope invariant is satisfied.
- **`INV-REQ-TJ-ADAPT-11`:** The owner-defined process and output bounds invariant is satisfied.
- **`INV-ADAPT-EFFECT-CHANGE-MEMBERSHIP`:** A package addition or removal that differs from the reviewed effect set returns the action to review before any manager invocation.
- **`INV-ADAPT-EFFECT-CHANGE-HOOKS`:** A declared hook identity, invocation phase, or policy change returns the action to review before any manager invocation.
- **`INV-ADAPT-EFFECT-CHANGE-CACHE-SCOPE`:** A cache-scope change returns the action to review before any manager invocation.
- **`INV-REQ-TJ-PLAN-02`:** The owner-defined deterministic topological action order invariant is satisfied.
- **`INV-REQ-TJ-PLAN-04`:** The owner-defined dependencies and expected effects invariant is satisfied.
- **`INV-REQ-TJ-PLAN-06`:** The owner-defined complete directory manifest invariant is satisfied.
- **`INV-REQ-TJ-EXEC-01`:** The owner-defined complete filesystem revalidation table invariant is satisfied.
- **`INV-REQ-TJ-EXEC-02`:** The owner-defined adjacent final check and mutation request invariant is satisfied.
- **`INV-REQ-TJ-EXEC-04`:** The owner-defined whole-directory invalidation invariant is satisfied.
- **`INV-EXEC-ANCESTOR-REPLACEMENT`:** A reviewed ancestor replaced under the same name with a different filesystem identity fails the action before any mutation.
- **`INV-EXEC-LEAF-REPLACEMENT`:** A reviewed leaf replaced under the same name with a different filesystem identity or type fails the action before any mutation.
- **`INV-EXEC-MOUNT-CHANGE`:** A changed mount identity on the selected root, a reviewed ancestor, or the leaf fails the action before any mutation.
- **`INV-EXEC-LINK-COUNT-CHANGE`:** A link-count change against reviewed metadata fails the action before any mutation.
- **`INV-EXEC-CHILD-SET-DELTA`:** A new or removed child in a reviewed directory invalidates the whole directory action before any mutation on its entries.
- **`INV-REQ-TJ-FAIL-01`:** The owner-defined action failure pause and dependency blocking invariant is satisfied.
- **`INV-REQ-TJ-FAIL-03`:** The owner-defined cancellation reconciliation invariant is satisfied.
- **`INV-REQ-TJ-LOG-06`:** The owner-defined fail-closed logging errors invariant is satisfied.
- **`INV-REQ-TJ-UI-05`:** The owner-defined refresh teardown invariant is satisfied.
- **`INV-REQ-TJ-UI-06`:** The owner-defined unified cancellation invariant is satisfied.
- **`INV-REQ-TJ-TEST-01`:** The owner-defined deterministic production boundaries and suites invariant is satisfied.
- **`INV-REQ-TJ-TEST-03`:** The owner-defined fixed allocator and capacity boundaries invariant is satisfied.
- **`INV-REQ-TJ-TEST-04`:** The owner-defined evidence fields and limitations invariant is satisfied.
- **`INV-REQ-TJ-TEST-05`:** The owner-defined build gates invariant is satisfied.
- **`INV-REQ-TJ-PERF-02`:** The owner-defined explicit performance budgets invariant is satisfied.
- **`INV-REQ-TJ-PERF-04`:** The owner-defined measurement methods invariant is satisfied.
## Forbidden effects
- **`NO-REQ-MANIFEST-UNBOUND-SIM`:** The unbound manifest fixture is not treated as implementation evidence.
- **`NO-ADAPT-EFFECT-CHANGE-ADMISSION`:** No manager operation is admitted against an effect set that differs from the reviewed binding.
- **`NO-EXEC-MISMATCH-MUTATION`:** No mutation is issued after an ancestor replacement, leaf replacement, mount change, link-count change, or new or removed child is observed.
## Variations
Executable implementation and evidence fixtures are separate work items.
## Limitations
This is an unbound verification path: it records the required invariant and suite mapping,
but does not establish implementation coverage or passing runtime evidence.