# The Narrow Door — preregistration

Written **2026-09-24, before `experiment.js` had been run once.** Committed in this state so
that what follows can be wrong in public. The results page reports each line as HELD or
BROKEN against the measured intervals, including the ones I got wrong.

Design, seeds, metrics, and windows are inherited unchanged from
[`echo/PROTOCOL.md`](../echo/PROTOCOL.md). The only new mechanism is the door.

## What the door is

Movement one let the two source-keeping policies exchange their entire origin sets — an
unbounded message — while the echoing policy sent one number. Its protocol says so
plainly and declines to claim resource-optimality. Movement two caps the channel: an
exchange may carry at most **`door`** origin IDs, so a sender must now *choose*.

Four selection rules, each a defensible instinct:

- **newest** — pass the youngest origins you hold.
- **oldest** — pass the earliest. The archivist.
- **random** — pass a uniform sample. No opinion.
- **firsthand** — pass what you saw yourself, youngest first, then fill.

Two exchange modes:

- **blind** — the sender does not know what the receiver already has, so a narrow door
  spends most of its capacity on redundancy. This is what a channel without negotiation costs.
- **handshake** — the sender chooses from the difference, and the receiver first has to
  say what it holds. That announcement is priced at its naive size. A Bloom filter I did
  not implement is not a saving I get to claim.

The echoing policy is untouched by the door at every setting. Its message was always one
scalar. That is the entire point of the comparison, and `verify.js` check C asserts it.

## Predictions

**P1 — the objection, answered or not.** At `door = 1`, in the turning world, time-aware
provenance still beats the echoing policy on post-change Brier loss (paired difference
negative, 95% interval excluding zero). Under this setting the source-keepers send one
integer per exchange against the echoers' one scalar — comparable payload at last. *If
this breaks, movement one's headline advantage was partly bought with bandwidth, and the
finding needs the qualifier it currently lacks.*

**P2 — the archivist's mistake.** In the turning world, `oldest` is worse than `newest`
for time-aware provenance at every finite door. Forwarding the earliest origins first
means the news arrives last, and the age discount was already discarding what `oldest`
spends the channel on.

**P3 — recency is not free.** In the difficult-stable world (no flip, weak signal, heavy
shared sourcing, half-life 4), a narrow `newest` door damages **timeless** provenance more
than time-aware provenance, measured as the Brier increase from `door = ∞` to `door = 1`.
A policy that counts all history equally needs the history a recency door throws away.

**P4 — negotiation is not cheap.** Handshake beats blind on Brier at every finite door,
and its total payload per message exceeds its own door by more than an order of magnitude
at `door = 1`. You can buy the accuracy back; you cannot buy it back inside the cap.

**P5 — where the ordering breaks.** There exists a finite door and rule at which the
movement-one ordering (temporal better than timeless better than echo) does **not** hold
in the turning world. Movement one's ordering is a claim about memory policies under an
unbounded channel; narrow the channel and the ranking is not guaranteed to survive.

## What would make this worthless

- `verify.js` check A failing: if `door = Infinity` does not reproduce The Echo Garden
  frame-for-frame, any door effect below may be a new bug of mine rather than the channel.
- Choosing doors or rules after seeing results. The grid below is fixed here:
  doors `1, 2, 4, 8, 16, 64, ∞`; rules `newest, oldest, random, firsthand`; modes
  `blind, handshake`; conditions `turning, stable` from movement one; seeds `1–128`
  sequential, no seed search.
- Reporting a rule's advantage without its payload. Every accuracy claim on the page
  carries the measured entries-per-message that bought it.

## What this still cannot say

The door counts **entries**, not bytes. An origin ID is modelled as one unit and a belief
scalar as one unit; in a real system they are not the same size, and a float is not an
integer. The handshake is priced naively because I did not implement a digest. Nothing
here establishes an optimal policy, only how the movement-one ordering behaves when the
channel stops being free.

Leave room for what changes this.
