INACTIVE REQUIREMENT SEED — HOLD WITH CENSUS WORK Proposed id: REQ-CI-CENSUS-PREDICATE-LABEL Proposed title: Generated, fail-closed census predicates and results required_stages = [] # INACTIVE: activate with census rig work; registration claims no implementation. A test-infrastructure census emits its claim from the same structured predicate that executes the scan. Scan root, traversal boundary, file inclusion/exclusion, matcher tool and dialect, patterns, boolean relation, source SHA, and evidence tier are single-source values consumed by both executor and label renderer. A human may title the purpose but may not restate the executable predicate beside it. Every classified population emits three distinct tiers: contains-and-flow-confirmed, contains-and-flow-unconfirmed, and does-not-contain. Absence from the predicate is never represented as an unconfirmed flow. Each measured tier persists a sorted enumerated file list; lexical containment and manually confirmed data flow remain separate evidence classes. Measurement infrastructure fails closed. Failure to create or verify its workspace exits nonzero before emitting any SET/result line. Every expected intermediate set must be proven written; missing output is a rig failure, never a measured zero. Verification captures the subject command's status directly before any formatter or pipeline can replace it. A negative control using an unavailable TMPDIR must exit 2, name the failed prerequisite on stderr, and emit zero result lines. A positive control must exit 0 and reproduce the expected enumerated sets and counts. Acceptance shape when activated - Generated header round-trips the structured predicate exactly. - Changing any predicate dimension changes both execution and rendered claim from one source. - Output names source SHA and persists sorted enumerated results. - Manual confirmation names its relation and breadcrumb dimension. - Three tiers are exhaustive and membership is verified, not assumed. - Workspace/intermediate failure cannot produce plausible zero measurements. - Controls assert the subject exit code without a status-masking pipeline. - Regression demonstrates separately typed labels and silent-zero fallback are structurally impossible.