# Publication addendum — explicit R4 adoption holds This is post-audit Codex publication disclosure, not part of the 35-file R4 frozen candidate and not represented as provider-reviewed. All 35 audited files remain byte-identical. Both R4 provider verdicts are ACCEPT WITH LIMITS. Claude permits its two medium documentation findings to be fixed or explicitly carried; this release carries them. No runtime, schema, example or test result is changed by this note. ## M1: incomplete reading list The audited AGENTS.md / agent-guide.md reading list alone is insufficient. Before using the five installed operational assets, read the complete pinned ZIP, specifically final-review-limits.md and this publication-addendum.md. Source/control/bidi display hygiene, source/master consistency and current inspection admission are host duties. validate_native.allowed_issuers is current inspection authorization for the retained issuer, not a credential or incoming-write set. Future valuationAt is accepted for either purpose; the estimate sentence is not an enforced restriction. These limitations remain open for integration into a future single authoritative contract. ## M2: verifier-specific byte encoding monetary.py 0.1.0 on the tested Python 3.12.14 / jsonschema 4.26.0 environment is the only defined executable verifier in this reference release. Cross-language verification, Unicode-equivalent normalization and RFC 8785/JCS compatibility are unsupported. Preserve the exact original package and record bytes. An independent implementation needs a separately reviewed byte-encoding contract and cross-language vectors; do not infer that language-native JSON serialization generates compatible digests. ## Further binding and evidence limits The native object and fact recordedAt values must be identical; fact authority must equal source=the admitted writer and rank=0, with no extra authority keys. The companion validates genesis records only and does not establish current head, access, provenance-source consistency or authentic storage. Its resource limits apply narrowly, not as a general V3 compatibility claim. load rejects explicit nonfinite literals and duplicate keys, but overflow exponent tokens can parse into a float and are refused by the mandatory subsequent validation. Always run load followed by validate, then complete-register import before storage. Source-slot uniqueness is by ID, not digest or semantic equivalence. Corrections may change currency/context/purpose or leave arithmetic identical; the host decides their business legitimacy. The reference requires complete history and has a 256-ID lifetime cap per Dimension. Revoking a historical issuer from the existing-admission set or erasing a required predecessor makes that register unimportable. No quarantine, tombstone or production retention path ships. Native positive acceptance reads stored objects and facts. Most native negatives mutate constructed envelopes; the arithmetic-tamper case is written into the stored fact to demonstrate outer-versus-nested behavior. The schema-tamper test uses a separate temporary sibling copy, not a mutated installed Dimension. Tool source files have pins, but this is not a hermetic transitive-dependency or bytecode supply-chain verification. The whole-object/mastership rows include shared template wording for embedded snapshots; they do not authorize the host to write an external steward's catalogue. MC-Q13 needs host storage and complete-register context despite its local-guidance label. Input numeric limit means 36 total digits, of which at most 18 are fractional. Invariant 11 applies at complete-register import, not at standalone issue. Structural schema alone cannot verify a rounded result; mandatory arithmetic replay does. These are adoption holds for a bounded reviewable draft, not claims of production readiness, standard conformance or completion of EM-XCT-06.