{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__film_media_production","trajectory_id":"R","attempt_index":0,"archetype_slug":"computability_boundary_mapping","domain_slug":"film_media_production","decision":"CANDIDATE","problem_id":"universal_extensible_render_completion_preflight","causal_lever_id":"guarantee_scoped_render_completion_routing","proposal":{"problem":"A film-production pipeline may promise a terminating, correct preflight verdict on whether every arbitrary render or compositing project—including user-authored scripts, plug-ins, and recursive dependencies—will finish successfully. Timeouts and successful sample renders can then be misreported as definitive failure or universal safety, causing false clearances, wasted render capacity, and missed delivery commitments.","actors_substrate":["VFX and post-production engineers","render-farm operators","editors and compositors","production managers","artists submitting projects","arbitrary project graphs, scripts, plug-ins, assets, and render workers"],"observable_state":"The preflight interface returns only pass/fail for unrestricted projects; timed-out analysis is treated as failure, sampled success as a completion guarantee, and the supported project class and computation model are undocumented.","consequence":"Projects may be falsely cleared, falsely rejected, or allowed to consume unbounded render resources while stakeholders cannot distinguish non-completion, timeout, unsupported input, and analyzer uncertainty.","affected_objective":"Reliable delivery scheduling and safe allocation of post-production compute without overstating what completion analysis can guarantee.","structural_mapping":[{"archetype_element":"Unrestricted class-wide exact terminating decision requirement","domain_realization":"A preflight service is asked to decide completion for every project expressible with arbitrary executable plug-ins or scripts.","claim_kind":"HYPOTHESIS"},{"archetype_element":"Explicit input and computation model","domain_realization":"Project manifests, dependency graphs, frame ranges, plug-in binaries, external services, and worker semantics form the declared input/model contract.","claim_kind":"INFERENCE"},{"archetype_element":"Constructive and impossibility evidence in parallel","domain_realization":"Develop a total checker for a restricted render language while testing whether unrestricted completion admits a valid halting-problem reduction.","claim_kind":"HYPOTHESIS"},{"archetype_element":"Decidable restricted region","domain_realization":"A finite acyclic graph of contract-checked total operators, bounded frame ranges, and finite assets is an enforceable candidate fragment.","claim_kind":"HYPOTHESIS"},{"archetype_element":"Explicit weaker fallback","domain_realization":"Out-of-fragment projects receive bounded analysis, witness-backed findings, or UNKNOWN and escalation rather than a Boolean completion promise.","claim_kind":"HYPOTHESIS"},{"archetype_element":"Version-linked boundary and reclassification","domain_realization":"Changes to the graph language, plug-in permissions, worker model, or external dependencies trigger renewed classification.","claim_kind":"INFERENCE"}],"component_map":[{"component":"Problem-Class Specification","status":"adapted","domain_realization":"All valid project manifests under the stated pipeline language."},{"component":"Instance Representation Contract","status":"adapted","domain_realization":"Canonical manifest encoding for graphs, assets, frames, plug-ins, and dependencies."},{"component":"Computation Model Contract","status":"adapted","domain_realization":"Worker, sandbox, storage, network, plug-in, and external-service capabilities."},{"component":"Solvability Guarantee Profile","status":"adapted","domain_realization":"Exact/terminating, sound-incomplete, bounded, or unknown per class."},{"component":"Quantifier and Scope Map","status":"adapted","domain_realization":"Separate every-project claims from one-project and bounded-fragment claims."},{"component":"Computability Status Lattice","status":"direct","domain_realization":"Classify render-completion questions as decidable, recognizable, relative, undecidable, or unresolved."},{"component":"Constructive Procedure Witness","status":"adapted","domain_realization":"Restricted-manifest checker plus termination and correctness argument."},{"component":"Reduction Preservation Contract","status":"adapted","domain_realization":"Specify a computable script-to-project embedding preserving termination."},{"component":"Computability Impossibility Certificate","status":"adapted","domain_realization":"Checked reduction certificate if unrestricted plug-ins can encode arbitrary computation."},{"component":"Assumption Register","status":"direct","domain_realization":"Record language, operator-totality, resource, service, and sandbox assumptions."},{"component":"Decidable Subclass Map","status":"adapted","domain_realization":"Map enforceable bounded, acyclic, total-operator project fragments."},{"component":"One-Sided Recognition Contract","status":"adapted","domain_realization":"Confirmed completion requires a checkable bounded execution or structural witness."},{"component":"Unknown and Nontermination Policy","status":"direct","domain_realization":"Keep UNKNOWN, timeout, out-of-scope, render failure, and predicted non-completion distinct."},{"component":"Fallback Solution Contract","status":"adapted","domain_realization":"Route to exact fragment checking, bounded exploration, preview render, or human review."},{"component":"Computability Guarantee Record","status":"adapted","domain_realization":"Versioned statement of each shipped verdict's actual guarantee."},{"component":"Recheck Trigger","status":"adapted","domain_realization":"New scripting power, plug-in API, external dependency, or worker semantics."},{"component":"Termination Condition","status":"direct","domain_realization":"Declared analysis time, state, depth, and frame bounds."},{"component":"Scope Boundary","status":"direct","domain_realization":"Mechanically enforced admitted fragment and explicit unrestricted region."},{"component":"Decision Record","status":"direct","domain_realization":"Approved boundary, evidence, shipped modes, owners, and expiry conditions."},{"component":"Uncertainty Residue","status":"direct","domain_realization":"Open proof obligations, model mismatch, and unclassified plug-in behavior."},{"component":"Independent Proof Review","status":"adapted","domain_realization":"Independent review of the restricted checker and any reduction."},{"component":"Complexity Follow-On Gate","status":"adapted","domain_realization":"Feasibility analysis begins only after in-principle decidability is established."}],"mechanism_dispositions":[{"slug":"abstract_interpretation_or_model_checking","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Over-approximate finite project-state models; safe verdicts retain one-sided meaning.","counterfactual_removal":"Fallback loses a sound static-analysis mode but boundary classification remains."},{"slug":"bounded_domain_exhaustive_search","disposition":"selected_supporting","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Exhaust finite toy manifests and trace depths in the pilot.","counterfactual_removal":"Pilot loses complete bounded checks."},{"slug":"computability_boundary_decision_record","disposition":"selected_load_bearing","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Version the boundary, guarantees, assumptions, and triggers.","counterfactual_removal":"Guarantee drift becomes unauditable."},{"slug":"computational_complexity_analysis","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Assess cost only for classified decidable fragments.","counterfactual_removal":"Decidable but unusable modes may advance."},{"slug":"constructive_algorithm_and_correctness_proof","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Prove the restricted checker total and correct.","counterfactual_removal":"The positive decidability claim lacks a witness."},{"slug":"diagonalization_impossibility_proof","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"A reduction is more natural than direct self-reference here.","counterfactual_removal":"No material change."},{"slug":"enumeration_and_dovetailing","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Operational bounded execution already supplies safer finite evidence.","counterfactual_removal":"No material change."},{"slug":"fallback_mode_router","disposition":"selected_load_bearing","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Route by fragment membership and label exact, bounded, or UNKNOWN.","counterfactual_removal":"Weaker results can be mistaken for guarantees."},{"slug":"halting_problem_reduction","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Attempt a property-preserving embedding into unrestricted plug-in projects.","counterfactual_removal":"The proposed impossibility boundary rests only on analogy."},{"slug":"language_fragment_restriction","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Enforce an acyclic finite manifest language with total operators.","counterfactual_removal":"There is no mechanically policed exact-answer region."},{"slug":"many_one_reduction_proof","disposition":"selected_supporting","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Formalize totality and answer preservation of the halting embedding.","counterfactual_removal":"Reduction obligations become less explicit."},{"slug":"promise_problem_restriction","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Unenforced promises are weaker than syntactic admission control.","counterfactual_removal":"No material change."},{"slug":"proof_by_counterexample","disposition":"selected_supporting","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Use one in-scope looping project to refute an overbroad existing checker claim.","counterfactual_removal":"Universal overclaims are slower to challenge."},{"slug":"proof_checking","disposition":"selected_load_bearing","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Independently check the positive proof and reduction certificate.","counterfactual_removal":"Boundary claims depend on author authority."},{"slug":"reduction_direction_checklist","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Gate source-to-target direction and assumptions.","counterfactual_removal":"A reversed reduction may be accepted."},{"slug":"semi_decision_with_explicit_unknown","disposition":"selected_load_bearing","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Bound analysis and return UNKNOWN, never fabricated non-completion.","counterfactual_removal":"Timeouts are likely to become false negatives."},{"slug":"theorem_prover_guided_search","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Not required for the bounded first test; manual checkable certificates suffice.","counterfactual_removal":"No material change."},{"slug":"turing_reduction_analysis","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Relative degrees add no necessary operational distinction here.","counterfactual_removal":"No material change."}],"causal_chain":["Declare the project language, representation, computation model, and universal guarantee.","Test unrestricted completion with a checked source-to-target halting reduction while constructing a total restricted checker.","Mechanically admit only projects satisfying the proven fragment contract.","Route admitted projects to exact checking and others to bounded or sound-incomplete modes.","Preserve UNKNOWN, timeout, out-of-scope, and failure as separate outputs.","Record guarantees and recheck when expressiveness or execution assumptions change.","Reduce false clearance and false rejection while preventing unbounded claims from controlling delivery commitments."],"baseline":"Ordinary preflight uses sample renders, heuristic linting, operator experience, and timeouts, then emits or is interpreted as a binary go/no-go decision.","nearest_rival":"A learned duration predictor or static linter that scores completion risk for arbitrary projects but supplies no class-wide termination or correctness guarantee.","authority_safety":{"affected_parties":["artists and editors","VFX vendors","render operators","production managers","clients awaiting delivery"],"decision_authority":"The post-production engineering owner may approve an offline pilot; changing production admission or delivery policy requires the production executive and pipeline reliability owner.","authorized_first_step":"On a synthetic, non-production corpus, define one restricted manifest grammar; prove/check its termination argument; construct looping and terminating plug-in cases; compare tri-state routing with the current preflight under fixed compute limits.","excluded_actions":["Do not cancel or approve live deliveries from pilot verdicts.","Do not execute untrusted plug-ins outside a sandbox.","Do not label timeout or UNKNOWN as non-completion.","Do not publish undecidability until the reduction and model match pass independent review."],"halt_rollback":"Stop if sandbox containment fails, the restricted grammar cannot be mechanically enforced, or any exact verdict is wrong on the bounded oracle set; disable the experimental router and retain the existing advisory workflow."}},"negative_tests":{"strongest_counterevidence":"The actual production language may already be finite, non-recursive, and composed solely of certified total operators; then completion is decidable in principle and the main problem is complexity or reliability rather than computability.","analogy_break":"A render process is not automatically equivalent to an arbitrary program. The reduction fails if plug-ins cannot encode unbounded computation, external state changes the modeled property, or 'finish successfully' lacks a stable formal semantics.","failure_condition":"The candidate fails if no recognizable class-wide completion claim exists, fragment membership cannot be enforced, or domain semantics cannot be represented without changing the operational question.","problem_falsifier":"Audit shows every admitted project has a fixed finite state space and a known total completion procedure, with timeouts used only as capacity controls and never as truth-valued verdicts.","intervention_falsifier":"In the bounded pilot, tri-state boundary routing produces no reduction in false clearances, false rejections, or uncontrolled compute relative to baseline, or its exact-fragment checker yields any incorrect verdict.","risks":["A restrictive fragment may exclude common creative workflows.","UNKNOWN may be operationally coerced into NO despite interface labels.","An unsound operator-totality contract may create false confidence.","Formal completion may omit crashes, corrupt assets, nondeterministic services, or unacceptable output quality.","Boundary work may delay practical reliability fixes for decidable failures."]},"null_rationale":null,"classification":{"candidate_kind":"MECHANISM_COMPOSITION","prior_art_status":"UNSEARCHED","evidence_maturity":"HYPOTHESIS"},"revision_change_log":{"revision_kind":"ORIGINAL","prior_problem_id":null,"prior_causal_lever_id":null,"problem_changed":false,"causal_lever_changed":false,"conceptual_changes":[],"operational_changes":[],"repairs_addressed":[]},"confidence":0.86,"generator_notes":"Closed-book structural transfer. Domain-specific pipeline facts and expected effects are hypotheses or inferences, not established empirical findings."}