# Query geometry: direct error, nuisance closure, and finite knowledge

September 10, 2026. Analytic framework for the five concepts proposed in
`research/concepts_2026_09_10/CONCEPTS.md`. These are elementary consequences
of explicit models, not claims of historical priority. Complex observation
spaces are treated as real Hilbert spaces when the requested answer is real.
All norms, source classes, and allowed joint parameter sets are part of an
experiment; none is supplied by the terminology below.

## 1. Direct-query transfer theorem

Let W be positive definite, X an exact finite augmented observation matrix,
G=X*WX >= f I > 0, and Q a real-linear map from coefficient space into the
requested real answer space. Q may discard nuisance coordinates and take
the real parts of arithmetic coefficients. Write T=G^-1 X*W, L=QT. Suppose
every actual explanation satisfies

    y = X theta + h(theta,z) + e,       q(theta)=Q theta,
    (theta,z) in A,                    ||e||_W <= eta(theta),

after exact known centering. A includes the joint incidence of source,
timing, drift, and model uncertainty. Unrestricted nuisance must be exactly
represented in X and annihilated by Q, or removed by a valid preceding map.
The vector h includes the complete infinite tail where appropriate.

For a proposed coefficient vector theta_tilde with verified normal residual

    r = G theta_tilde - X*W y,          ||r||_2 <= rho,

the decoded error satisfies the exact identity

    Q theta_tilde - q(theta) = L h(theta,z) + L e + Q G^-1 r.       (1)

Consequently, for any unit real answer direction v, an upper bound on its
signed error is

    sup_(theta,z in A) <v,L h(theta,z)>
       + sup_theta eta(theta) ||L* v||_(W^-1)
       + rho ||(Q G^-1)* v||_2.                                  (2)

The analogous expression with -v is the lower bound. The adjoints here are
real Hilbert adjoints. One may instead keep theta-dependent bounds until
forming the final outer answer set, which can be sharper. The family of
all these half-spaces encloses every decoded answer error. Replacing a
joint image by a Minkowski sum of separately bounded images is safe but
can lose correlations. It requires no probabilistic independence.

**Proof.** Substitute the model in the residual identity and multiply by
Q G^-1. Taking a real inner product gives (2) by the definition of a
support function and the two dual-norm inequalities. No full-state error
bound is required before evaluating the requested query. QED.

If Q returns n^2 times the real part of arithmetic coordinate n, then
||L|| <= n^2/sqrt(f) and ||Q G^-1|| <= n^2/f. If the complete decoded
tail is bounded by A_n and structured disturbances have direct query
bounds K_n, the usual sufficient integer gate becomes

    A_n + K_n + n^2 [eta/sqrt(f) + rho/f] < 1/2.                  (3)

K_n replaces the corresponding reading-norm disturbance allowance; it is
not added a second time. A failed sufficient gate is not an ambiguity
witness. Every new data vector still requires its own verified residual.

For a general nonlinear pipeline P and any sound outer model C(theta)
containing P(y) for each explanation of y, the exact answer set satisfies

    {q(theta): theta explains y}
      subset {q(theta): P(y) in C(theta)}.                       (4)

This follows by substitution and composes by transitivity. A singleton
outer set determines a discrete query. For continuous answers, the radius
of a supplied enclosure controls an estimator's error; half the diameter
alone is not automatically an enclosing radius for vector answers.

### Restrictions and relative errors

For a restriction R, the original weighted error ball has image R E.
The least original squared cost of r in range(R) is

    min_(Re=r) ||e||_W^2 = r* (R W^-1 R*)^dagger r.              (5)

Whitening and the minimum-norm solution of a linear system prove (5).
It is invalid to silently assign an unrelated spherical noise model to
retained coordinates. If the original radius is eta ||u||, all direct
query bounds above remain relative to ||u|| unless an absolute source
amplitude bound is supplied. Competing explanations have separate source
norms and may choose different permitted clock/model parameters.

## 2. Response spectra and contact order

For an arbitrary complex scalar decoder L_c, let a=L_c sin(omega x) and
b=L_c cos(omega x). The exact arbitrary-phase response obeys

    sup_phi |a cos(phi)+b sin(phi)|^2
      = lambda_max [[|a|^2, Re(a conjugate(b))],
                    [Re(a conjugate(b)), |b|^2]].               (6)

Expansion and the Rayleigh principle prove this identity. For the real
query ell=Re L_c, the exact answer is instead

    sup_phi |ell sin(omega x) cos(phi)
                 + ell cos(omega x) sin(phi)|
      = sqrt((ell sin(omega x))^2+(ell cos(omega x))^2).          (7)

The complex bound remains safe for the real query, but can be conservative.
Frequency maximization is a separate continuum problem: a finite frequency
grid alone does not establish its supremum. Complete Taylor remainders or
interval subdivisions with certified between-sample bounds do.

**Definition (error contact order).** For a calibrated family with actual
answer q(z), a fixed reported estimate map P, base z0, and direction v,
put E(h)=P(y(z0+h v))-q(z0+h v). The contact order is the first positive
integer k with E^(k)(0) nonzero, componentwise for a vector answer. If the
true source/query is fixed during calibration, q is constant and this
reduces to the decoded-response definition in the concept note. Ignoring
the varying true query can otherwise give a spurious contact order.

If E^(j)(0)=0 for 1<=j<k and ||E^(k)(h)||<=M_k on the whole segment from
0 to h, repeated integration of the fundamental theorem of calculus gives

    ||E(h)-E(0)|| <= M_k |h|^k/k!.                              (8)

All derivatives vanishing need not imply constancy for a merely smooth
family: exp(-1/h^2), extended by zero at h=0, is the standard counterexample.
Analyticity does imply local constancy in that case.

For a joint parameter set Z and error Jacobian J_q, the first-order image
is J_q Z. When Z={Sigma^(1/2) v: ||v||<=1}, its worst Euclidean effect is
exactly ||J_q Sigma^(1/2)||_op, and its directional support is
sqrt(v* J_q Sigma J_q* v). A complete second derivative bound charges the
remainder. Directions in ker(J_q) have at least quadratic error growth if
such a bound holds. A source-uniform statement must take the supremum over
every admitted source, time, target, and base parameter: the kernel at a
single example need not be a common harmless direction. Reparameterizing
calibration transforms both J_q and Z; an area comparison is meaningful
only in the fixed units declared for the experiment.

### Independent audit of shared-offset symmetry

Use the actual symmetric arithmetic grid t_(M-1-j)=-t_j and even real W.
Let (J y)_j=conjugate(y_(M-1-j)). Then J is an antilinear W-isometry.
Every arithmetic column Phi_n=exp(-i t log n) is fixed by J; each real
degree-k orthogonal polynomial has parity (-1)^k. Therefore

    J(X theta) = X S conjugate(theta),

where S is diagonal, one on arithmetic columns and (-1)^k on polynomial
columns. Uniqueness of weighted least squares implies
T(Jy)=S conjugate(Ty). In particular L_n(Jy)=conjugate(L_n y) on every
arithmetic coordinate. This remains true with complex polynomial nuisance
coefficients; they transform by S and conjugation in the fit.

For every real slope a, exp(-i a t log m) is J-fixed, so its L_n response
is real. Real source coefficients and absolute convergence then give

    Re L_n F(a t+b)
       = sum_m a(m)/m^2 cos(b log m) L_n exp(-i a t log m).       (9)

Thus the real decoded source is even in b, uniformly at fixed a. The
complex decoded source can change at first order in its imaginary part.
Using |1-cos v|<=v^2/2 and ||L_n||<=n^2/sqrt(f),

    |Re L_n [F(a t+b)-F(a t)]|
      <= n^2 D2 b^2/(2 sqrt(f)),
    D2 >= sum_m d_14(m) (log m)^2/m^2.                          (10)

Termwise arguments are justified by the complete convergent D2 series.
There is no uncharged slope-offset mixed term: (10) is uniform in a and
the source difference is split exactly at F(a t). Affine composition
preserves degree-11 nuisance and shifts the arbitrary sinusoidal phase.
The effective sinusoidal frequency depends on slope, not offset.

I independently rechecked the rational consequences for both saved 320-
and 384-bit reconstructions, without rewriting either predecessor. With
the unchanged slope radius 1e-14 and offset radius 3e-5, the complete
errors are below 0.444378507 (multi) and 0.493361414 (outer). The inherited
old joint clock allowance is valid for slope alone because zero offset is
in its allowed box. Adding (10) is therefore conservative, not a dropped
clock component. These are conditional mathematical guarantees under the
declared source, drift, noise, mismatch and per-data residual premises.
This audit validates their deduction; the actual-matrix reconstruction
remains a separate numerical premise with its existing replay route.

**A bounded symmetry defect.** For a real query ell, suppose the same
involution J obeys ||ell J-ell||_(W->R)<=epsilon_J. The first offset
derivative v=F'(a t) is J-odd, so
2 ell(v)=-(ell J-ell)(v). Since ||v||_W<=D1, where
D1=sum_m d_14(m)log(m)/m^2, Taylor's theorem gives

    |ell[F(a t+b)-F(a t)]|
       <= epsilon_J D1 |b|/2 + ||ell|| D2 b^2/2.               (10a)

More generally a declared derivative-symmetry defect ||Jv+v||_W<=sigma_1
adds ||ell|| sigma_1 |b|/2. These are uniform statements only if their
premises hold for every admitted slope and source. If ell_exact J=ell_exact
and ||ell-ell_exact||<=epsilon_L, J-isometry gives epsilon_J<=2 epsilon_L.
The lemma concerns the source response. It does not cure nonzero leakage
of an unbounded nuisance through an approximate decoder: exact nuisance
removal or a per-data residual remains necessary. A solver's small residual
also does not establish a physical clock or symmetry model. This gives a
continuous error budget between exact symmetry and a declared asymmetry.

### Independent audit of the new complete slope proof

The separate [clock development](../arithmetic/PROOFS.md) uses direct real
query channels through m=100, a zero-extended second-difference bound for
101<=m<=10^12, and a complete zeta-derivative tail for all m>10^12. I checked
the mathematical argument and producer `clock_response.py` independently:
the 0.2 time increment gives |1-z|=2|sin(log(m/i)/10)|; the stated concave
sine interval covers all arithmetic and polynomial normal channels; both
zero-extension boundary terms are included; and the remote derivative
mass covers every later alias. Its complete positive envelope permits
independent actual source coefficients. The inverse transfer and the
stronger comparison C<tau/10 (f<=1) have the correct directions. No
mathematical flaw was found. `check_examples.py` independently checks the
finite second-difference identity at exact unit-circle points. Fresh Arb
transcendental, inverse, and tail enclosures remain that component's
separately reproducible numerical premises.

## 3. Acquisition-stable nuisance: exact closure or bounded leakage

For a linear nuisance space V and acquisition maps G, define

    V_G = span{v composed with g: v in V, g in G}.               (11)

A fixed linear decoder removes every transformed nuisance if and only if
it annihilates V_G. If amplitudes in V are unrestricted and any transformed
direction has nonzero image, scaling that direction proves that no finite
uniform leakage bound exists. This is an obstruction to that linear
removal, not by itself an impossibility theorem for all nonlinear decoders.

**Polynomial-clock classification.** Let P_p contain polynomials of degree
at most p, d>=2, and allow g_e(x)=x+e x^d for e in any nonempty open interval.
Then

    (P_p)_G = span{x^s: s in S_(p,d)},
    S_(p,d)={k+(d-1)r: 0<=r<=k<=p}.                            (12)

**Proof.** Expanding (x+e x^d)^k gives binomial(k,r)e^r x^(k+(d-1)r).
For each k, evaluating at k+1 distinct admitted e values and inverting the
Vandermonde matrix isolates all k+1 monomials. The same expansion supplies
the reverse inclusion. QED.

For d=2 these exponents are all 0,...,2p. For d=3,p=1 they are {0,1,3},
so P_(dp) would be an incorrect generalization. On sampled points, the
dimension is the rank of this sparse monomial evaluation matrix. It is
not always min(m,|S|): at {-1,0,1}, x and x^3 coincide. On m distinct
strictly positive points it is min(m,|S|). To see this, a nonzero sum of s
distinct nonnegative monomials has at most s-1 distinct positive zeros:
divide by the smallest power, differentiate, and use Rolle's theorem
inductively. Every square minor with sorted positive points is therefore
nonsingular. Ordinary P_(2p) has the usual min(m,2p+1) rank on any distinct
real sample points.

If instead all coefficients of a degree-d clock
g_a(x)=a_0+a_1 x+...+a_d x^d vary jointly over an open subset of R^(d+1),
then (P_p)_G=P_(dp). Indeed the coefficient of each parameter monomial
in g_a(x)^p is a nonzero multiple of x^s for some 0<=s<=dp, and every such
s can be written as a sum of p integers in {0,...,d}. The span of values
of a vector-valued polynomial on an open set contains each coefficient:
a linear functional annihilating all values gives a scalar polynomial
zero on an open set, whose every coefficient is zero. Finite-dimensional
duality proves the assertion. This full family is different from (12).

**Bounded-leakage alternative.** Suppose L annihilates P_p, x is the
declared sample vector, |e|<=h, v(x)=sum_(k=0)^p c_k x^k, and
sum_k |c_k|<=B. Then

    |L[v(x+e x^d)]|
      <= B max_(k<=p)
           sum_(r: 0<=r<=k, k+(d-1)r>p)
            binomial(k,r) h^r |L x^(k+(d-1)r)|.                (13)

Expansion, exact annihilation, the triangle inequality, and l1/linfinity
duality prove (13). For a fixed e the exact worst l1 coefficient effect
is B max_k |L[(x+e x^d)^k]|. Replacing its signed polynomial response by
the termwise sum in (13) is conservative. Other coefficient norms use
their own dual support function. A fixed h and finite B give a finite
budget even when exact nuisance closure would consume useful source
directions. The first surviving exponent in e also gives a nuisance
contact order. An amplitude norm must be declared in a specified basis;
it is not invariant under arbitrary polynomial reparameterization.

### An exact three-reading experiment: closed certification gap

This independently checkable example turns the closure/leakage choice
into a complete result. At x=(-1,0,1), observe

    y_j=q x_j^2 + c (x_j+e x_j^2) + b + noise_j,
    q in {0,1}, |c|<=B, |e|<=h, b arbitrary real,
    ||noise||_2<=eta.                                         (14)

Each explanation has its own (c,e,b). Let ell=(1/2,-1,1/2); then
ell(1)=ell(x)=0, ell(x^2)=1, and ||ell||_2=sqrt(3/2). Thus

    |ell(y)-q| <= Bh+eta sqrt(3/2).                            (15)

The exact distance between the two response sets is

    delta=max(0,1-2Bh) sqrt(2/3).                             (16)

**Proof of the lower bound.** Apply ell to any unequal-label center
difference: its magnitude is at least max(0,1-2Bh). Cauchy--Schwarz and
||ell||=sqrt(3/2) give (16). For Bh<1/2, take c=B in both explanations,
e=h for q=0 and e=-h for q=1, and b=-(2/3)(q+c e). Their difference is
(1-2Bh)(x^2-2/3), whose norm is (1-2Bh)sqrt(2/3). For Bh>=1/2 take
c=B and e=+/-1/(2B), with equal b, producing identical centers. The
degenerate B=0 case belongs to the first construction. QED.

Therefore recovery is possible exactly when eta<delta/2 if delta>0,
and it fails at equality because the closest pair is attained. If delta=0
it fails even at zero noise. The sufficient decoder (15) meets the exact
threshold. At B=2,h=1/10 this gives radius squared 3/50, and the checker
constructs the exact rational common midpoint and its two error vectors.
At unrestricted c and any h>0, the same construction gives a noiseless
actual ambiguity. Here a general linear-removal warning has been upgraded
to a true model-specific impossibility witness.

## 4. Observational completion and a terminating strict-gap procedure

The actual quadratic source is a real quadratic field, without a bound
on its discriminant. Give every prime an arbitrary symbol chi(p) in
{-1,0,1}, extend completely multiplicatively, and set

    a_chi(n)=sum_(d divides n) chi(d).

These formal coefficients satisfy 0<=a_chi(n)<=d_2(n). The existing
[finite-prefix theorem](../../five_paths_2026_09/path4_realizability/PROOF.md)
proves that every finite prime-symbol assignment is realized by infinitely
many actual real quadratic fields. Its arithmetic ingredients are the
quadratic splitting laws, CRT, and Dirichlet's theorem for a residue
coprime to its modulus. We do not reinterpret arbitrary d_14 envelopes
as number fields.

Let F be any fixed finite collection of readings at Re(s)=2, in a positive
mass-one weighted norm. Two series with matching coefficients through N
differ in this norm by at most

    T_N=sum_(n>N) d_2(n)/n^2 <= 2(log N+2)/N.                  (17)

The coefficient difference is at most d_2(n), not twice this number,
because both coefficients lie in [0,d_2(n)]. For a full response compared
with its own truncation the same bound holds. To prove the last inequality,
A(x)=sum_(n<=x)d_2(n)<=x(1+log x), since
A(x)=sum_(a<=x)floor(x/a). Partial summation gives
-A(N)/N^2+2 integral_N^infinity A(t)/t^3 dt; drop its nonpositive term.

For each query determined by finitely many prime symbols, the formal
response image in that query class equals the closure of the actual-field
response image in that class. One inclusion follows by realizing ever
longer prefixes and using (17). For the converse, take a diagonal
subsequence of prime assignments. Every fixed prefix stabilizes, and the
uniform tail bound gives convergence to the resulting formal response.
The image is compact and closed. This proof applies separately to each
finite-symbol class, so it does not require the query to be recoverable
from observations in advance. A query without a continuous finite-symbol
extension, such as an arbitrary property of unbounded discriminants, is
not covered by this conclusion.

### Finite strict-gap promise procedure

For the algorithmic conclusion, supply a finite query-label rule on the
prescribed prime symbols and computable specifications of the finitely many
sensor times, positive mass-one weights, and nonnegative noise radius eta.
Here computable means that certified rational intervals of any requested
accuracy can be produced. These premises hold for the project's rational
time grid, computable weights and rational noise contracts. The preceding
analytic completion statement does not itself assert an algorithm for
arbitrary noncomputable real experimental inputs.

Fix N large enough to determine the supplied query label. There
are K_N=3^pi(N) possible prefixes, all realized by actual fields. Enclose
every truncated response and every unequal-label pair distance by verified
intervals [l_ab,u_ab]. Put l_N=min l_ab and u_N=min u_ab; interval arithmetic
must cover all eligible pairs, rather than only a floating-point favorite.
Then the actual-field separation infimum delta obeys

    max(0,l_N-2T_N) <= delta <= u_N+2T_N.                      (18)

The lower bound applies to every actual field pair after truncation. For
the upper bound, realize each prefix of a minimizing upper pair and use
two complete tails. Thus the reported interval is justified by actual
objects, even though a limiting optimizer itself need not be a field.

Choose interval precision so u_N-l_N tends to zero, refine the certified
noise-radius interval as well, and increase N. The computable-input
premises allow these refinements. Assume the strict-gap promise 2 eta!=delta.
If 2 eta<delta, eventually l_N-2T_N>2 eta, proving recovery. If 2 eta>delta,
eventually u_N+2T_N<2 eta. The finite-prefix construction then supplies an
actual unequal-label pair whose midpoint noise is strictly below eta.
These strict comparisons can eventually be verified against the appropriate
noise-radius interval endpoints. This proves termination on every input
meeting the strict-gap promise. It deliberately gives no guaranteed
termination at equality; it is not an unrestricted decision procedure for
all noise thresholds.

The arithmetic witnesses can be made explicit: build the CRT progression
in the cited finite-prefix proof, enumerate its positive candidates,
certify primality (trial division is sufficient for termination), and form
the positive fundamental discriminant. Dirichlet ensures this search
terminates. Complete tails certify the resulting series, and a strict
remaining margin permits a rational approximation to the common midpoint
if a finite output vector is desired. The theorem supplies no practical
uniform bound on how many progression candidates are needed.

The computational cost is explicit in the finite search size: storing
prefixes takes O(N K_N) scalar coefficients; direct response evaluation
takes O(m N K_N), and exhaustive pair comparison O(m K_N^2), with arithmetic
bit cost and certified transcendental precision additional. At N=5 there
are 27 prefixes and at most 729 ordered pairs; at N=50 there are 14,348,907
prefixes and over 2e14 ordered pairs. Branch-and-bound may reduce work but
must preserve valid lower bounds and full coverage. This is a convergent
finite decision route, not a claim that naive enumeration is an efficient
replacement for the existing directional tail certificates.

`check_examples.py` independently constructs all 27 assignments at primes
2,3,5 using exact CRT and trial-division primality, verifies the positive
fundamental discriminants and their five-term coefficient prefixes, and
finds maximum discriminant 28,920. These small witnesses exercise the
constructive route; their finite enumeration does not prove the infinitude
input, which remains Dirichlet's theorem.

## 5. Intrinsic ambiguity, certification gap, and computational priorities

For explanations theta,theta' let f,f' be their noiseless responses and
let their allowed errors be scaled norm balls of radii epsilon r(theta)
and epsilon r(theta'). For r+r'>0 the least scale at which the two balls
meet is

    c(theta,theta')=||f-f'||/[r(theta)+r(theta')].               (19)

If r(theta)+r(theta')=0 (both radii are nonnegative), both error sets are
singletons at every finite scale. Define c=0 when f=f', and c=+infinity
otherwise. This includes noiseless rival explanations in the infimum and
avoids dividing by zero. Such coincident unequal-query centers are already
ambiguous at zero noise; distinct zero-radius centers never meet at any
finite noise scale.

The triangle inequality proves necessity. Sufficiency follows by choosing
the point dividing the segment between centers in the proportions of the
two radii. Equal unit radii give the absolute margin half-distance;
source-relative noise gives r=||u|| and r'=||u'||. General shaped or
correlated error sets require their actual intersection cost instead.
Profiling unrestricted nuisance means including its value in each complete
explanation before taking the infimum. Formula (19) need not define a
metric between query classes: set distances can fail the triangle law.

Let r_q be the infimum of (19) over unequal query answers. Below r_q,
unequal-answer neighborhoods are disjoint. Above r_q an actual pair gives
an ambiguity. At r_q the endpoint depends on attainment and the actual
error sets. For continuous answers, one can instead compare pairs whose
query distance exceeds a declared tolerance; this is an ambiguity modulus,
not an automatic vector estimator-radius formula.

A proof supplies r_low<=r_q. A verified actual pair supplies r_q<=r_high.
Their difference is the certification gap, provided source class, query,
units, uncertainty incidence, noise scaling and endpoint convention agree.
A relaxed point that cannot be realized is only an upper bound for the
relaxed model. An improved lower certificate with unchanged observations
changes knowledge about the experiment, not its intrinsic information.

**Exact endpoint and finite convergence example.** Let formal observations
be y=sum_(k>=1)b_k/4^k, b_k in {0,1}, query b_1. Let actual objects be the
eventually-zero sequences. They are dense in each formal query class. The
formal class-0 maximum is 1/12 and the class-1 minimum is 1/4, so their
distance is 1/6. No actual class-0 sequence reaches 1/12. Thus all unequal
actual pairs have distance strictly greater than 1/6, but actual finite
prefixes approach it. Actual closed noise balls remain disjoint at radius
1/12, whereas completed classes have a common midpoint at that radius.
For N-bit truncations the exact separation is

    delta_N=1/6+1/(3*4^N),       T_N=1/(3*4^N).                 (20)

The generic interval [delta_N-2T_N,delta_N+2T_N] converges with width 4T_N.
The checker enumerates all prefixes through N=8 and reconstructs exact
minimizers and tail sums. The analytic geometric-series proof covers all
N and the nonattained endpoint; enumeration alone would not.

**Decision guidance with mathematical content.** Given a required noise
scale eta, if eta<r_low the current proof already resolves the query. If
eta>r_high, extra proof precision cannot rescue that experiment and model;
one must alter acquisition, the question, or justified uncertainty. If eta
lies between them, either a stronger lower certificate or a better actual
witness can settle the issue. For the completion hierarchy (18), refining
all interval evaluations far below T_N cannot materially shrink the gap
until N or the complete tail bound improves. Conversely increasing N is
unhelpful while matrix/interval error dominates. In the exact example (20),
the cost and tail are explicit: quadrupling prefix count by increasing
N by two reduces T_N by sixteen. The three-reading experiment (14)-(16)
has zero certification gap because decoder and actual collision meet.

These results give the transfer line a concrete purpose: preserve the
geometry of answer-changing perturbations through exact nuisance removal,
restrictions, approximations and finite computation, while tracking which
remaining uncertainty is experimental and which is only in its proof.
