Finding ·
The suite catches two of its own no-op edits (control C3)
The inspeximus maintainer found that on the inspeximus and Mem0 rows the T6 cross-context replay was a no-op: the victim pool was read from both contexts, so the donor was copied onto itself and the cell scored as accepted on an edit that never happened. The earlier finding that a receipt does not bind the owning user rested on that no-op and is withdrawn; with the pool scoped to the first context, both receipt rows report T6. A third control now runs before every verdict: each attack proves its edit landed as intended, and a cell whose edit did not land reads error. That control also found the Mem0 T4 reorder was a no-op (the adapter wrote each point back under its own id); fixed, and Mem0 still accepts it on a real swap. Those cells read error until the scoped victim pool lands.