Expected facts are assertions only; compiler output is the source of truth.
highlighted = computed this step
Honest by construction
The book compiles raw schedules, turns recomputed facts into expected assertions, then compiles again before rendering.
expected is assertion only
Show the guarded example
The guarded schedule has 1 reads-from fact and 2 classification violations.
reads-from=1
Safe commit and rollback schedules are tiny finite histories; logging, undo, ARIES, timing, isolation-level, product, and performance claims are out of scope.
Try to tamper
Wrong expected facts, derived sidecars, and reads with no modeled source fail closed before any lesson artifact can be trusted.
fail closed before render
Summary
The book stays inside exact schedule classification; recovery mechanisms and database products are out of scope.