Policy::choose takes the whole GroundState -- every face-down Problem's
suit and value, every seat's hand -- which is exactly what project()
exists to withhold. No shipped policy reads it, but the first thing a
competitive policy must do is VALUE a Problem, and value is the hidden
field. The trap goes live on the first line of the F27 work.
Established behaviourally rather than by narrowing the trait: vary only
what the seat cannot see, and the choice must not move. That binds every
policy including ones written later and outside this crate, without
their cooperation. The mirror of ADR-0013 D1 -- same kernel, two
searches, opposite permissions, discriminated by WHEN the question is
asked; a policy plays from inside an information set, so retrospective
permission would be strategy fusion.
Running the control found two defects IN THE CONTROL:
1. The rearrangements rotated hidden values 2<->3 together, leaving max
invariant -- so the deliberate peeker, which ranks by the largest
hidden value, was not caught. A control whose variation is invariant
under the statistic a violator reads is not a control.
2. It accused `random` of peeking, because it reused one policy instance
and compared a first call against a fourth. It takes a constructor
now, so every variant is judged from identical policy state.
Both are a difference in output read as evidence about hidden state --
the wrong-subject family, found twice inside a control written to detect
wrong subjects.
Three mutations, three red. The control is proven against a deliberate
violator before being trusted about compliant policies.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>