Skip to content

Research: Contract E RC3 target-reference cardinality successor - #82

Draft
camerontjs-dot wants to merge 13 commits into
research/contract-e-v1-rc3-exact-currentness-jcs-20260902from
research/contract-e-v1-rc3-target-reference-cardinality-successor-20260903
Draft

Research: Contract E RC3 target-reference cardinality successor#82
camerontjs-dot wants to merge 13 commits into
research/contract-e-v1-rc3-exact-currentness-jcs-20260902from
research/contract-e-v1-rc3-target-reference-cardinality-successor-20260903

Conversation

@camerontjs-dot

@camerontjs-dot camerontjs-dot commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Research successor only

This Draft PR is a separately named descendant of the frozen RC3 evaluator seal. It does not rewrite predecessor evidence and does not authorize production promotion, merge, tag, release, execution, or verification.

Defect resolved

The frozen RC3 SPEC requires jurisdiction.target_ref to resolve to exactly one validated request reference. The frozen predecessor reference instead checked identity membership / at-least-one resolution.

Preregistration: 6d33124a90b29668cc534765859a3cdd75e46ea6

Successor candidate freeze head: 30dd929b310727737488192af1579729b2d4dd3e

Candidate freeze receipt: e4b47d4b73998c30a09722e9e1ee93d8f00b66a9

Predecessor evaluator seal: 3943dd9e5e0711c894356fd4dfef25fd45507d91

Final successor evidence seal: a678c73a661853a3a704666fc6bbf29fa378948f

Scientific qualification

Accepted current-head confirmation:

  • run 33834840544
  • qualification job 100905157421
  • artifact 9922927161
  • digest sha256:fbe86bde6fbc56297389bc175aaeb78ecfda71fa4bb0bb4f80629cf4d9def400
  • hidden corpus 62
  • successor reference normative exact 62/62
  • predecessor reference regression 59/59, zero mismatches
  • predecessor weak controls 14/14 caught
  • new target-cardinality weak control 1/1 caught
  • total weak controls 15/15 caught
  • diagnostic-only variant SUPPORTED
  • qualification failures: none

The membership/cardinality-blind control is falsified with false permits on NEG-TARGET-DUPLICATE-VALID-IDENTITY and NEG-TARGET-MULTIPLE-MATCHES. The one-valid-plus-one-invalid duplicate-looking case fails structurally before cardinality and remains an explicit denial case.

Preserved apparatus deviation

First hosted successor qualification run 33834615021, job 100904491435, failed before scientific comparison because the successor evaluator did not register the frozen predecessor sibling module under the historical import name expected by hidden_cases_reference_identity_extension.py.

  • all candidate jobs had already passed 65/65 asserted controls;
  • candidate bytes were not changed;
  • hidden cases, weak controls, expected outcomes, normative projection, SPEC and schema were not changed;
  • only successor evaluator import plumbing was repaired at 1f509b36d3ca61dfd3dcf808d1da27ef34b05a8c;
  • the failed run and artifact 9922852466 remain historical evidence.

Production-profile review

Separate production-profile review commit: 131cbcd4dcccdba024e273c27c8aa0bddf5fae89

Original disposition: NOT_READY.

The original review identified six unestablished domains:

  • trusted authority origin / authenticated configuration machinery;
  • identified real production consumer and integration boundary;
  • production security/threat-model controls;
  • operational failure, retry/recovery/rollback handling;
  • downstream executor/verifier handoff;
  • operational ownership/change authority.

Subsequent research below narrows several technical subproblems but does not establish a production consumer or production trust/ownership envelope, so the production disposition remains NOT_READY.

Independent recoverability — subsequent bounded evidence

The clean three-file aperture in Research Scaffold Harness Draft PR #18 at 91e3970caf7e8b03836df0882158e9e23ff3eb36 was consumed by a fresh independent context on branch research/contract-e-v1-rc3-fresh-independent-execution-20260904.

Frozen independent implementation evidence:

  • implementation freeze commit 60e2872c61bf098142c5bea4f547f4f7e7707f98
  • freeze receipt ed18b8898c73c2721e894ccffbdd40b67df60714
  • implementation blob 9019abd8ade820988de1f899b2ccef9e57e9a908
  • prereveal-test blob 818c44ad377d95344d158a7698d625548c0f5397
  • prereveal tests 33/33, OK
  • contamination CLEAN_PRE_FREEZE_APERTURE

Accepted post-freeze comparison:

  • Research Scaffold Harness Draft PR Release: Contract C 1.0.0 immutable lock and publication #21
  • final reproduction seal 9feb44d8c8ea96176f797fe0ef692cc8e4d13656
  • accepted run 33890626280
  • job 101081122887
  • artifact 9943671179
  • digest sha256:9f50f655f0638bec3a96dfd8d3a05a1a85256c16b03af5b99bcbe8613a5a31bc
  • hidden corpus 62
  • normative exact 62/62
  • predecessor cases 59/59
  • target-cardinality cases 3/3
  • false permits / false rejects / exceptions / preservation failures / diagnostic-shape failures: none
  • scientific state SUPPORTED

A preceding hosted comparison run 33890524011 remains APPARATUS_FAILURE_BEFORE_SCIENTIFIC_COMPARISON because the hosted environment lacked the sealed reference's rfc8785 dependency. Only exact dependency plumbing changed.

Fresh independent recoverability is SUPPORTED FOR THIS BOUNDED REPRODUCTION. Universal recoverability is not claimed.

Production-envelope shadow RC0 — subsequent bounded evidence

Research Scaffold Harness Draft PR #22 tested only point-of-use binding/order on disposable state. It did not modify Contract E and performed no real knowledge mutation.

Operator-provided local MainFrame archaeology found no existing exact knowledge.add_verified_tag@1 handler and no globally enforced Contract E production consumer. It did identify reusable local atomic-mutation, provenance, and reconciliation techniques, but those are not themselves Authorization.

Frozen RC0 lineage:

  • preregistration d879dddb07e0c4f4f1b6588cebddefa662e15829
  • amendments 038702cb5aacfbb42e6fee0848d98eb8d7cb6d1a, 436edca34a88d7ad85057c6c800ebc3f339a518c, baff5409bc08ca2a513f7917f1061ec09134b5dd
  • candidate freeze b9d8e93ac414d37bb3288669526aab9bc28a9f5a
  • candidate blob bd60ba1da3e1098d4d1a82d6b99bae6255843529
  • evaluator freeze 96a5ef58b199fad22bfe46875b6074f6aab36f71
  • evaluator blob b274b963603612ed3ff2993f76c067fa7c09ec31
  • freeze receipt 4480438a8069e5d040ad9221c05be52e63c94f04
  • terminal record b3efa9289714f48bcedebed5a11f56e3015c0895

Primary accepted hosted run:

  • run 33939307886
  • job 101233414092
  • artifact 9961243481
  • digest sha256:ea7fb2e4bc499d6c7e083043f2d3cbd754b8acfd59fbfe693b980be2e6762833
  • cases 26/26
  • false allows 0
  • target-integrity failures 0
  • weak controls 6/6 caught
  • scientific state SUPPORTED_FOR_BOUNDED_SHADOW_CLAIM

Evidence-only re-verification run 33939376401 also completed successfully with frozen candidate/evaluator unchanged.

RC0 supports the tested ordering: exact Contract D applicability -> exact consuming-intent and target/pre-state binding -> path confinement/target lock -> fresh current Contract E evaluation -> target re-observation -> replay reservation -> shadow decision. A historical authorized=true receipt was insufficient when current authority was revoked or expired.

RC0 does not establish real execution, production trust, a real consumer, or concrete effect serialization.

Disposable execution/recovery RC1 — subsequent bounded evidence

Research Scaffold Harness Draft PR #23 extended the supported RC0 ordering into one research-only exact-byte mutation on explicitly marked temporary state. The bytes were fixture data and did not define knowledge.add_verified_tag@1 production semantics.

Frozen RC1 lineage:

  • preregistration 997ea4696bf1b5de24c2187eeb72c76bcb1ed5c4
  • candidate freeze a69c3ac13ec0c0fd7f72fb77c1987c2bc5306588
  • candidate blob 2f7f4678f6f92de1e7ced733d324fa9b234e95fc
  • independent verifier freeze 23732a1adec7a63f7a52f277ff53c5b0914fce95
  • verifier blob 18e59803ba2e316b16564d1fe26d839c71b82ff7
  • evaluator freeze ad2da092a041750a55e06cdf97657dc9112300e9
  • evaluator blob db6ce20ef9a1f8fe83336d670306de3307524812
  • freeze receipt a9cba052bedacea5829ea513afb2742c1d8bab52
  • terminal record bbf19bfdca94efb6f7d362f19781d85f5c9c3875

Primary accepted hosted run:

  • run 33939733370
  • job 101234666188
  • head e3a665e2a81d6ed20c8c428a3000594b32fbf7ba
  • artifact 9961390590
  • digest sha256:5514fb8202b414f089e56d9bb8dfcde4ae31ee829724a17a0f721d09fb802632
  • cases 23/23
  • weak controls 6/6 caught
  • scientific state SUPPORTED_FOR_BOUNDED_DISPOSABLE_EXECUTION_RECOVERY_CLAIM

The terminal evidence commit re-verification run 33939801797 also completed successfully with frozen candidate/verifier/evaluator unchanged.

Bounded observations:

  • normal exact-byte mutation required fresh current Contract E authorization, durable PREPARED, atomic replacement, exact post-state observation, then durable APPLIED;
  • independent verifier reread target+journal and explicitly did not claim Authorization or authenticated actor identity;
  • retry after durable APPLIED performed no rewrite;
  • retry after PREPARED required fresh current authorization before a new write;
  • revocation after PREPARED caused retry denial and no mutation, so PREPARED/AuthorizationReceipt did not become reusable permission;
  • interruption after replacement but before APPLIED recovered without rewriting and recorded RECOVERED_POSTSTATE with execution attribution unknown;
  • target change between authorization and replacement was detected and not overwritten;
  • post-execution tamper was caught by the independent verifier;
  • journal tamper and a forged APPLIED journal with real target still at pre-state were rejected.

RC1 therefore gives bounded support for local execution/recovery/post-state-verification mechanics, but it deliberately preserves the harder facts: the journal is unsigned; actor attribution is not authenticated; injected interruptions are not real power-loss testing; no distributed exactly-once claim is made; and the real MainFrame consumer/effect representation remain absent.

Current disposition

  • Contract E RC3 target-cardinality successor: SUPPORTED
  • fresh independent recoverability: SUPPORTED FOR THIS BOUNDED REPRODUCTION
  • production-envelope point-of-use binding/order: SUPPORTED FOR THE BOUNDED SHADOW CLAIM
  • disposable local execution/recovery/post-state verification mechanics: SUPPORTED FOR THE BOUNDED DISPOSABLE EXECUTION/RECOVERY CLAIM
  • production profile: NOT_READY
  • production authorization: false
  • merge/tag/release/promotion: not authorized

The technical uncertainty has narrowed. The remaining promotion blockers are now concentrated in production-specific decisions/evidence that these research fixtures intentionally do not supply:

  1. the real production consumer and operational owner;
  2. the exact persisted meaning/representation of knowledge.add_verified_tag@1 and its target mapping;
  3. authenticated AuthorityState/configuration origin and authenticated principal/workload identity;
  4. the production threat model, especially whether unrestricted same-user writers must be prevented by OS/service mediation rather than cooperative application controls;
  5. production-grade failure/recovery/rollback evidence on the actual filesystem/store/runtime;
  6. operational ownership and authority to change trust/config/effect policy.

Do not seek production promotion approval yet. Further work must be a separately bounded production-specific experiment after the relevant operator/governance choices are made. The sealed Contract E successor and fresh-independent reproduction bytes remain immutable.

Copy link
Copy Markdown
Owner Author

Production-envelope Deep Research reconciliation — 2026-09-04

The completed external Production Authorization Envelope research is now available and materially sharpens the interpretation of RSH PRs #22 and #23.

Contract E RC3 itself remains unchanged and correctly bounded: it decides whether the supplied immutable AuthorityState authorizes the request at the request's exact evaluation_time. Its authority_state_id is a content identity, not proof that the state is the latest authoritative generation.

Accordingly:

  • RC0 remains supported for point-of-use intent/target/replay binding, but not authority-source freshness/serialization.
  • RC1 remains supported for disposable execution/recovery/post-state verification, but its “fresh authorization” means fresh evaluation of the supplied state, not proof of latest standing authority at commit.
  • Neither result establishes the stronger production property identified by the research: an authorization-and-use linearization point across current authority generation, target version, intent dedupe, mutation, and durable execution fact.

The next bounded experiment should therefore hold trust origin fixed and test one non-epistemic reversible single-object transition in one transaction/serialization domain using A0→A1 authority generations. It should deterministically force the interleaving evaluate A0 -> PAUSE -> install A1 revocation -> RESUME and show that a known-broken check-then-write control can commit stale authority while the serialized candidate cannot.

This reconciliation does not alter the sealed Contract E successor or any frozen RSH candidate/evaluator bytes. Production profile remains NOT_READY and production authorization remains false.

Copy link
Copy Markdown
Owner Author

Authority/use linearization RC2 — subsequent bounded evidence

The completed Production Authorization Envelope Deep Research identified that “fresh authorization immediately before execution” is weaker than an authorization-and-use linearization point when the supplied AuthorityState itself can be stale relative to a revocation. Frozen Contract E RC3 was re-inspected and remains correctly narrower: it decides currentness within the exact supplied immutable AuthorityState at request evaluation_time; authority_state_id is content identity, not latest-generation/causal-freshness proof.

Research Scaffold Harness Draft PR #24 now records the bounded successor experiment that tests this missing property without changing Contract E or touching live MainFrame state.

Frozen RC2 lineage:

  • base preregistration 2cd26654bb082f94597a4a980eeb8e44c65b3c56
  • preregistration amendments f2a38348e43a5df79fbab496c74fbc23f7c4abc3, 91fdaf8068b2a8ecc3f6b9ad02e8e4e0c598c3f0, 7978a613a8f73b9187fdf23bb3d8640cbe0b0969, 6741e7011ea112c5d13d733c48702c61054c2d7c
  • evaluator freeze 48f22a50eae49ca241a50739b7e7212617e4e94f
  • freeze receipt e608bb3d96d04fe74d5112e10ebd05ad2c4e9db7
  • fixtures blob b46fd61e285c6bd9923d638086c593d7aa2a7f6b
  • candidate core blob e3683d0d1f41224b4084c6e3f980eba9ae736276
  • anti-rollback wrapper blob ca07a6a9622da596958e55151dfcac9613036484
  • independent verifier blob 0e1cc0a058258601014bfdacca42ace201602391
  • process worker blob 709ef81baaf122f73d00820e247654956c935d24
  • evaluator blob 8ac02df2a5970db34367fbd875123b3524abe24c
  • terminal result commit a702012014cc7c170f74e6f5ebc0e12bc90beb10

Primary accepted run:

  • run 33941257564
  • job 101239016602
  • head 8f2f03498ea5765964fba5d4f8813a55685e2346
  • artifact 9961889922
  • digest sha256:85f42894290ad55be944b2363edf5ce25d293bd798fc85d0d3ba3e1f7bb3323e
  • cases 20/20
  • known-broken controls 6/6 caught
  • scientific state SUPPORTED_FOR_BOUNDED_AUTHORIZATION_USE_LINEARIZATION_CLAIM

Terminal evidence re-verification run 33941362336 at PR #24 head also completed successfully with frozen scientific bytes unchanged.

Decisive observations:

  • If execution E owns the SQLite write-serialization domain first while A0/generation 0 is current, a competing A1 authority update is blocked; E may commit under recorded generation 0, then A1 installs. Observable order: E < A1.
  • If A1 installs first, E reads store generation 1 and Contract E denies; target remains unchanged. Observable order: A1 < E.
  • A deliberately broken check-A0-then-write control obtained a real A0 allow, installed A1, then still mutated under the stale allow. This falsifies temporal proximity as a sufficient property.
  • Caller-supplied historical A0/receipt material cannot override the store-selected current generation.
  • Target version/state CAS, target mutation, intent-result memory, and ExecutionRecord participate in the same transaction.
  • Process-isolated competing distinct intents against version 17 produce one transition; same-intent concurrency produces one transition plus one exact prior-outcome return.
  • Response loss after commit is resolved from the durable intent/ExecutionRecord without a second transition; failure before commit rolls target + ledger + ExecutionRecord back together.
  • The independent verifier directly queries the authoritative store and rejects forged executor success or post-commit target tamper.
  • Supported authority installation rejects rollback/fork. Direct current-pointer rollback with newer history present is detected by the sealed PEP. A known-broken candidate without the highest-generation invariant regains A0 permission and commits, demonstrating anti-rollback is independently material.

Bounded interpretation:

RC2 supports a single-store authorization/use linearization mechanism while Contract E remains a pure evaluator. It does not establish authenticated Decision/AuthorityState origin, a real production consumer, distributed authority/resource consistency, production knowledge.add_verified_tag@1 semantics, workload identity/PKI, or production store/runtime behavior.

Current production disposition therefore remains NOT_READY and production authorization remains false. The remaining blockers are now more sharply concentrated in real production facts/choices: consumer/owner and target store, concrete operation representation, source/principal trust model, bypass-resistance threat boundary, and whether the actual topology can provide an equivalent authority/target consistency contract. No sealed Contract E byte is changed by this evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant