The four-copy problem

Four copies, none of them publishable

Three distinct versions of the integration specification exist across the corpus. None declares itself the successor to any other. One is half-corrected, one over-corrects into a violation, and the difference between them is five passages.

Footage © Stefan via Pexels · 192 frames · 8s · seam 1.75 / travel 14

Three copies, no succession statement

copybyteswherestate
A9,405election-integrity/site/downloads + safe-elections-isolation/kit/docsByte-identical pair. Singular "StrongRoom". Uses "anchored" and "Anchoring:" throughout.
B9,447strongroom-elections/site/downloads + dist/downloadsByte-identical pair, and the copy currently SERVED. Pluralised, but the correction is HALF-APPLIED.
C9,631safe-elections/site/downloadsUnique. The complete correction: "witness-published" throughout, plus a two-line definition of "anchored to".

Not one of them contains a date, a version number, or a sentence claiming to supersede another. The only way to order them is to read all three and reason about the direction of each edit — and the direction is not consistent.

Live defect — The served copy (B) is half-corrected, and the defect is in production now.

Measured 2026-09-10, on kristenslab/strongroom-elections@HEAD site/downloads/Election-Integrity-on-StrongRoom-SPEC.md

whatvaluereading
anchored2withdrawn vocabulary, still in the tally-artifacts line
Anchor the tally1build step 5 never converted
Witness publishing1only the data-seam heading was converted
Anchored to0the two-line semantic clarification is absent
StrongRooms's1possessive typo, shipping

Copy D — the merge

Takes from C: C's 13 corrected lines — witness-published tally artifacts, the "Anchored to" definition, "Witness-publish the tally log" as build step 5, and the possessive fix.

Keeps from B: B's line 149, "Tamper-evident, with a full report".

0 occurrences of "tamper-proof"; 5 of "tamper-evident".

Action: Build the MERGED copy D over B in strongroom-elections — not C. Then one copy, one location, and every other repository references it rather than carrying its own.

The audit's own SHA-256 for copy C — 72bd79f048d1…c250e — was re-verified byte-for-byte on 2026-09-10 and matches, so the evidence behind this finding is independently checkable.

How this page works

A 54-second spoken walk-through of what is on this page and why it matters.