Status: implementation and verification plan; this document is not gate evidence
Authoritative baseline: specification.md, requirements.md, and final-verification.md in this repository’s docs directory
Current handoff hashes: concept d55c90e71721e7e4f9001a531b65531077c9786adffb7b361bb2500690583042; requirements e45d2d8fc6afcee9d1c150cfc9ceea5c9b77f07f0f076673ce6c7929614cc3e8
This plan converts the nineteen must-not-ship gates into concrete unit, contract, property/model, fuzz, integration, privileged-host, interoperability, chaos, red-team, supply-chain, and operational tests.
The core proof rule is strict:
- implementation coverage is not verification;
- a mock or local simulation cannot satisfy a real-harness, independent-device, cross-domain, physical-failure-domain, independent-administration, or owner-approval requirement;
- a skipped, deselected, quarantined, or expected-failing test is not passing evidence;
- a lower evidence tier cannot satisfy a gate that requires a higher tier;
- any unauthorized effect or exfiltration, active-session injection, positive-authority expansion, false durability/completion claim, missing required audit intent, public-gateway containment failure, or silent security downgrade blocks release regardless of aggregate pass rate.
docs/GATE_EVIDENCE.md is the release ledger. It starts with every gate unverified or owner-blocked. Nothing in this plan marks a gate passed.
| Tier | Name | What it can prove | What it cannot prove |
|---|---|---|---|
H |
Hermetic | Pure functions, schema contracts, deterministic state machines, property invariants, parser/signature vectors, and fuzz findings in an isolated test process. | OS/process isolation, real harness behavior, physical durability, external interoperability, independent administration, or human policy. |
L |
Local integration | Multi-process/container behavior on one development host, local PostgreSQL/object-store interactions, process killpoints, retries, and mocked dependency failures. | Independent failure domains, target-host assurance, public peers, independently controlled devices/accounts, or production RPO/RTO. |
P |
Privileged target-host | Exact target OS/kernel/architecture behavior, peer credentials, UID/process boundaries, namespaces, seccomp/LSM policy, ptrace/proc restrictions, key custody, installer lifecycle, and real harness escape probes. | Cross-domain independence, public interoperability, separate physical failure domains, or owner/legal approval. |
E |
External/lab | Real version-pinned harnesses, external SDKs/peers, multi-node failure domains, real IdP/WebAuthn/device ceremonies, partner domains, supported model configurations, and production-like failure/recovery drills. | Accountable owner policy or independent governance approval unless explicitly supplied. |
O |
Owner/independent authority | Signed PD-001 through PD-011 decisions, privacy/legal/retention choices, independently administered KMS/audit/update roots, and accepted operational consequences. | Technical correctness by itself; technical gates still require their own evidence. |
Every evidence record must include the source commit, dependency and harness versions, test command, selected tests, environment fingerprint, seed/corpus, start/end time, result, logs/artifacts, and signer or responsible operator. Evidence expires when a relevant model, harness, prompt, parser, policy, dependency, launch profile, OS/kernel, or security configuration changes.
Ordinary self-hosted onboarding may colocate Core, PostgreSQL, and approval on
the existing server under distinct OS identities, credentials, storage roots,
and loopback services. Human confirmation remains independent of the enrolling
harness through an owner-controlled WebAuthn authenticator and automatic
possession-bound broker delivery to exact waiting process. This profile reports
independent_boundary_proven=false and makes no
independent-administration or production-certification claim.
The threat-model delta is explicit: a root-level compromise of the shared server can affect Core configuration, trust anchors, PostgreSQL state, and the approval service together. Distinct OS identities reduce ordinary process and operator mistakes but do not contain shared-host root compromise. Compensating controls are exact OIDC/PKCE and candidate-key proof, WebAuthn UV, transaction- bound challenges, hash-only possession binding, cumulative retrieval-attempt limits, expiry, replay custody, exact response-loss recovery, immutable audit facts, enrolled-harness inventory review, rapid revocation, and honest assurance labels. A separately administered approval host remains the optional high-assurance profile for organizations that require containment from shared-server compromise.
The default-profile adversarial verification pass must cover:
- an enrolling harness attempting to read or automate approval;
- same-UID, PID-reuse, process-signal, filesystem, and loopback-boundary attacks;
- forged approval receipts and approval-key/trust-anchor substitution;
- wrong transaction, domain, beneficiary, purpose, RP ID, origin, policy/key epoch, and candidate key;
- possession-secret mismatch, replay, expiry, cumulative-attempt exhaustion, conflicting retrieval digest, and response loss;
- legacy claim-code guess/replay/expiry/sixth-attempt behavior in explicit compatibility tests only;
- revoked authenticator or harness credential;
- duplicate-paste and restart recovery without a second identity;
- Core compromise simulations proving the assurance label never upgrades to independent administration.
The same-principal/two-harness C0 lane is a narrow local mechanism test, not a
new authority source or production certification. Its affected stable IDs are
ID-006, AUTH-001, AUTH-002, AUTH-003, AUTH-004, AUTH-007,
COM-001, COM-009, AVL-005, AVL-006, UX-001, UX-002, SEC-003,
SEC-005, and SEC-006. Every case below must preserve the higher-level
requirements rather than treating pilot success as family-level completion.
Required H/L adversarial cases:
- Approval internal broker routes mount only with both the runtime credential and stable owner-OIDC session service; fragment-based legacy profiles cannot broker guided enrollment or a bootstrap plan;
- generic policy, message, mailbox, ACK, and administrative revoke paths cannot consume any plan-issued communication or cleanup entitlement;
- request bodies reject peer, plan, recipient, direction, classification, payload, event, digest, receipt, acknowledgement, entitlement, and use-count selectors before protected use;
- exact domain/principal/policy/revocation and the exact two active harnesses, two active credentials, credential IDs, and credential epochs are rechecked at every phase; an authoritative added active harness or credential permanently invalidates the guard, while an unverified caller-selected credential cannot mutate it;
- request and reply use independent deterministic keys, fixed harmless C0 payloads, exact recipients, exact sender attribution, and one causal parent;
- duplicate, concurrent, crash-before-commit, response-loss, restart, audit outage, expiry, and cleanup-killpoint tests converge to one event per direction and zero or five communication revocations;
- all seven fact rows retain their exact issuer, event, receipt, envelope, and canonical evidence binding; terminal replay revalidates both encrypted events, recipient rows, custody receipts and accepting-boundary owners, acknowledgement receipts and exact harness owners, causal lineage, remaining uses, and cleanup state;
- stale/tampered actor, recipient, payload, event digest, envelope, receipt owner, mailbox presence, fact JSON, receipt, use count, entitlement, guard, attempt, or stored success blocks terminal success;
- only compare-and-swap races are retryable; ambiguity, tamper, stale authority, and durable inconsistency remain non-retryable;
- the owner responder constructs no semantic worker, model, general background queue, task, artifact, file, effect, tool, company-data, or A2A subsystem;
- public HTTP/CLI/supervisor output contains only sanitized stages,
invalidated, orCOMPLETED_C0_ROUND_TRIPand never protected identifiers/evidence.
Required external proof remains open: real workforce OIDC, real passkey, exact
two-laptop key custody, deployed TLS/Core/Approval/PostgreSQL behavior, failure
and restart across hosts, and production durability. Until then custody is
accepted_local; no gate or live C0 claim is promoted.
- human, guest, harness, session, workload, domain, credential, and key identities;
- positive human authority, task grants, approvals, relationship scopes, and revocation epochs;
- exact message, task, room, receipt, artifact, audit, and effect state;
- local inbox/outbox bytes, database rows, object versions, scanner attestations, and backup keys;
- active user conversation isolation and human attention;
- issuer, receipt, approval, federation, scanner, audit, update, and MLS signing purposes;
- model-provider credentials, corporate bearer credentials, download capabilities, and decryption keys;
- privacy-sensitive content, routing metadata, relationship graphs, presence, search indexes, and audit trails;
- safety capacity for cancellation, revocation, quarantine, and incident response.
- a malicious or compromised harness, adapter, plugin, hook, skill, workspace, or same-UID desktop process;
- a malicious enrolled peer, administrator, subordinate, sponsor, guest, partner domain, public A2A peer, or gateway operator;
- hostile signed content, prompt injection, tool output, web output, file bytes, metadata, or model output;
- a confused deputy, replaying caller, copied capability holder, signer-oracle client, or cross-domain credential user;
- a compromised core, PDP, issuer/KMS, approval service, database/object administrator, scanner, effect worker, audit exporter, or update channel;
- process crashes, torn writes, response loss, network partitions, clock rollback, stale caches, key rotation races, disk pressure, failover races, split brain, and restore errors;
- accidental operator misconfiguration, unsupported mixed versions, policy drift, dependency compromise, and silent feature downgrade;
- denial-of-service, fanout loops, reconnect storms, receipt loops, storage floods, model/tool cost loops, and resource starvation.
Authentication never makes content safe, and a separate conversation is not a sandbox. The test oracle must assume every remotely influenced byte is hostile.
The following are cross-cutting property assertions, not merely examples:
- Payload identity, email, role, harness ID, domain, route, or tenant fields never become authenticated actor identity.
- Positive authority originates only from the verified human principal. Harness, device, session, subagent, relationship, task, capability, and posture can only preserve or reduce it.
- A management edge grants only its explicit meta-actions; it never grants protected data access.
accepted_queuedproves durable task custody only; it never proves semantic-processing, read, disclosure, or effect authorization.recipient_committedproves exact durable recipient custody only; it never proves presentation, human reading, model processing, or completion.- A signed A2A Agent Card proves only authenticity of canonical discovery metadata under a locally trusted current key; it never grants corporate identity, membership, authority, or rollover.
- A home-domain federation assertion can create only a host-local guest candidate. Host-local identity, credential, and current policy remain authoritative.
- Authenticated content remains tainted. It cannot become system/developer instructions, policy, approval, signer preimage, security principal, or executable job.
- Model output remains a proposal until deterministic task-grant, source, sink, action, resource, budget, and current-revocation checks pass.
- A scanner attestation proves only its digest-bound scan fact; it cannot release an artifact.
- Presence and advertised capability are hints, never authorization, identity, delivery, or readiness.
- A receipt proves only the fact owned by its signer. Transport acceptance never implies recipient commit or an external effect.
- Sensitive bytes, capabilities, or keys are never released before the corresponding transactional audit intent commits.
- Revocation, deny, quarantine, and unknown state never degrade to stale allow, automatic retry, sibling reroute, or invented success.
- No identifier, signature, receipt, authorization rule, or mailbox interface may require a special service identity; ordinary server-agent custodian/mesh implementations must preserve the same authority boundaries.
| Boundary | Untrusted side and attack focus | Required invariant | Primary gates/tests |
|---|---|---|---|
B01 Active user session ↔ background worker |
Routine content, focus/input theft, approval prompts, terminal escapes | No routine content/context/turn/focus/input mutation; explicit human-open is the sole content bridge. | Gates 1–3; tests/integration/test_foreground_no_interference.py |
B02 Harness adapter ↔ supervisor IPC |
Claimed identity, sibling process, copied capability, PID reuse, socket replacement | Actor comes from authenticated peer/session binding; adapter has no long-lived corporate secret. | Gates 5 and 7; tests/host/test_local_ipc_attribution.py |
B03 Supervisor store/key custody ↔ same-user processes |
Queue theft, ptrace/proc dump, key extraction, rollback | Advertised assurance must match tested OS boundary; otherwise protected operations are disabled. | Gates 6, 7, 19 |
B04 Clean worker ↔ host and inherited workspace |
Project instructions, hooks, plugins, filesystem, process, secret, IPC, DNS/network escape | Exact clean launch manifest and deny-by-default sandbox. | Gate 3; tests/host/test_worker_escape.py |
B05 Clean worker ↔ model-egress broker |
Credential theft, generic proxy use, origin/budget smuggling, request replay | Worker-bound short capability, allowlisted model/origin, fixed framed inference, persistent per-capability one-use request nonce, no vendor credential in worker. | Gates 3, 14, and 19 |
B06 Supervisor ↔ corporate edge/core |
Payload identity, token replay, wrong audience/domain, stale epoch | Exact human/guest plus harness or scoped workload actor from DPoP/mTLS context. | Gates 6–8 and 19 |
B07 OIDC/WebAuthn/OOB ↔ enrollment authority |
Mix-up, substitution, agent automation, same-device false independence, private-URL leakage, anonymous activation initiation/traffic amplification, activation ambiguity, wrong-account binding, possession replay, premature poll-budget exhaustion, unsafe terminal-state reset | Exact transaction binding, phishing-resistant fresh authentication, one-time independent approval, local system-browser default, fixed unauthenticated/rate-limited public remote /activate accepting no selector/private value, exactly one encrypted remote pending transaction, exact server-staged approved owner identity, retryable wrong-account denial with no challenge/Approval staging, purpose-separated automatic possession-bound signed-broker delivery, pre-callback-only finite poll budget, challenge-expiry-bounded Approval polling, and Core-confirmed key-preserving terminal replacement that refuses nonterminal/drifted state. |
Gates 6, 17, 19 |
B08 Core PEP ↔ PDP/entity snapshot |
Missing/stale/incoherent revisions, diagnostics, positive harness authority | One coherent revision; missing or inconsistent state denies; human is sole positive source. | Gate 8 |
B09 Core transaction ↔ PostgreSQL/outbox |
Response loss, partial commit, stale read, split-brain writer | Accepted state, idempotency, recipient rows, audit intent, and outbox share one authoritative commit. | Gates 9, 10, 16 |
B10 PostgreSQL manifest ↔ artifact bytes |
Orphan, object swap, wrong version, cross-class dedup leak | No artifact acceptance/access without verified immutable object version plus authoritative manifest. | Gates 9 and 13 |
B11 Quarantine ↔ scanner/transformer ↔ release policy |
Parser escape, stale/substituted attestation, scanner self-release | Scanner is isolated and signs exact digest/profile facts; current independent policy releases. | Gate 13 |
B12 Core ↔ effect worker/reconciler |
Model proposal as job, duplicate effect, unknown commit, fabricated completion | Typed authorized reservation; effect_unknown reconciles and never blind-retries. |
Gates 8, 10, 14 |
B13 Public A2A gateway ↔ corporate core |
Card trust promotion, tenant spoofing, SSRF, callback replay, credential leakage | External-low-trust actor and exact standing grant; no broad core/KMS/object credential. | Gate 4 |
B14 Federation gateway/home assertion ↔ host guest authority |
Transitive trust, foreign role/group import, sponsor abuse, stale home revoke | Pairwise host-local identity/key/token/grant; next-decision host kill; no onward authority. | Gates 11, 16, 17 |
B15 Directory/capability metadata ↔ protected routing |
Enumeration, forged security capability, stale endpoint/key | Authorization-filtered non-enumerating discovery; registry epochs override hints. | Gate 18 |
B16 Room/application authority ↔ MLS membership/key epoch |
Owner loss, concurrent transfer, hidden inspection member, stale removal | One active owner; separate epochs; current room authorization precedes crypto membership. | Gates 11–13 and 17 |
B17 Core audit intent ↔ exporter/WORM/witness |
Omission, gap, fork, silent backlog, compromised operator | Pre-release committed intent, bounded publication policy, independent checkpoint reconciliation. | Gates 13, 16, 19 |
B18 Build/update roots ↔ installed extension |
Dependency substitution, rollback/freeze, compromised adapter, uninstall residue | Signed threshold update metadata, provenance/SBOM, canary, disable, credential cleanup. | Gate 15 |
B19 Current mailbox custodian ↔ future relay/mesh |
Relay authority promotion, stale policy/revocation, false custody | Transport-neutral encrypted custody only; no content/data authority or central-instance identity. | Gates 9, 11, 16, 18 |
Every boundary check must bind or reject the exact actor, harness/workload, domain, audience, purpose, resource, payload digest, policy/grant/key epoch, expiry, nonce/jti/sequence, and idempotency scope. Contradictory or missing values fail closed.
The following paths are planned. Their presence in this document is not evidence that the files exist or pass.
tests/
unit/ pure schema, authorization, crypto-boundary, and projection tests
contract/ binding-neutral API and component-contract tests
property/ stateful/generative invariants
model/ room/delivery model checking adapters
fuzz/ parser, protocol, frame, metadata, and semantic conversion fuzzers
integration/ local multi-process and storage integration
host/ privileged target-host and exact-harness isolation probes
security/ deterministic negative-security suites and corpora
chaos/ killpoint, partition, pressure, failover, and restore suites
interop/ A2A, harness, federation, and MLS interoperability
redteam/ adaptive model/content campaigns
supply_chain/ build, package, update, rollback, and cleanup tests
operations/ topology, SLO, kill-switch, backup, and compromise drills
bakeoff/ reusable-component contract and replacement tests
vectors/ cross-language canonicalization and cryptographic vectors
Planned Python-style test paths are intentionally runnable under a conventional command such as pytest <path> once implemented. If the implementation language changes, equivalent native test runners may replace the runner, but these logical filenames and gate mappings should remain stable in the evidence manifest.
Requirements: ARC-003, UX-001, UX-002, UX-004, UX-006
Required evidence: H, L, and exact-version E
Planned tests:
tests/unit/test_foreground_routing.pytests/property/test_foreground_isolation_machine.pytests/integration/test_foreground_no_interference.pytests/fuzz/test_indicator_payload_fuzz.py
Test routine route construction, explicit-human-open capabilities, integer-only indicators, transcript/input/focus/turn/approval sentinels, reconnect/compaction, concurrent user activity, and hostile ANSI/control/Unicode payloads. Arbitrary routine traffic must leave the complete foreground trace unchanged. Real Claude, Codex, Pi, and Antigravity evidence is mandatory; a fake harness cannot close the gate.
Requirements: AVL-003, AVL-005, AVL-006, UX-001, SEC-006
Required evidence: H, L, and real-harness E
Planned tests:
tests/property/test_worker_recovery_machine.pytests/integration/test_worker_killpoints.pytests/integration/test_compaction_recovery.py
Inject death before and after every local/core commit, receipt, cursor advance, processing lease, model result, and compaction edge. Recovery must reconstruct accepted state only from supervisor/core durable facts, preserve exact bytes, avoid cross-session state, and execute at most one reserved effect. Corrupt/truncate local queue pages and replay duplicate recovery records. Exact harness resume/compaction remains external evidence.
Requirements: ARC-003, SEC-001, SEC-006, SEC-007, OPS-005
Required evidence: H, P, and exact-version E
Planned tests:
tests/unit/test_clean_worker_manifest.pytests/host/test_worker_escape.pytests/integration/test_model_egress_broker.pytests/fuzz/test_broker_protocol_fuzz.py
Verify clean HOME/environment/workspace/session, no inherited hooks/plugins/skills/MCP/shell/profile, fixed supervisor binding, and denial of filesystem, process, ptrace/proc, IPC, browser/keychain, DNS, and arbitrary network access. Seed secret canaries. Verify worker-bound broker capability, exact model/origin/grant/budget, credential stripping, and no CONNECT/generic-proxy/redirect smuggling. A failing harness must be tested in deterministic-only mode with every semantic/effect path denied.
Requirements: ARC-004, ARC-006, OPS-002, OPS-003, SEC-005
Required evidence: H, L, and external E
Planned tests:
tests/unit/test_a2a_mapping.pytests/interop/test_a2a_tck.pytests/interop/test_a2a_cross_sdk.pytests/security/test_a2a_gateway_attacks.pytests/fuzz/test_a2a_protocol_fuzz.py
Cover Task versus direct Message, every StreamResponse variant, unspecified role/state, server-owned IDs, artifact direction, input/auth-required, per-agent Card/route, tenant mismatch, standing-grant revoke, push duplicates/gaps, direct-Message stream loss, callback replay, credential-origin confinement, key/cache rotation, enumeration, and SSRF/DNS/redirect attacks. securityRequirements alternatives are OR; all schemes and scopes inside the selected alternative are AND. Binding literals must match the official specification exactly. The pinned TCK must have zero MUST failures, and cross-SDK/public-peer evidence is external.
Requirements: ARC-002, ARC-005, AUTH-001, AUTH-002, AUTH-004, AUTH-007
Required evidence: H, L, and real-binding E
Planned tests:
tests/contract/test_local_binding_parity.pytests/integration/test_mcp_token_confinement.pytests/integration/test_pi_direct_ipc.pytests/fuzz/test_local_api_framing_fuzz.pytests/bindings/test_remote_manager.pytests/bindings/test_response_obligation_tools.py
Run one typed operation corpus through supervisor API, MCP bindings, and Pi direct IPC and compare canonical results. Spoofed identity arguments must not affect authenticated context. Corporate and A2A bearer tokens must never enter MCP. Fuzz JSON-RPC/framing, nested arguments, duplicate IDs, cancellation, partial writes, and reconnect. Replace an owner-only Unix bootstrap socket at the same path and generation under immediate inode reuse; the retained non-inheritable path descriptor must force re-registration, survive a retryable failed renewal without dropping the old pin, swap only after success, and close on stop, post-publication startup failure, or terminal restart exhaustion. Terminal renewal/restart failures must stop retry cycling, remove the locator, and expose a fixed content-free failure code. The interactive laptop Manager runner is part of this boundary. Verify that it passes only one non-inheritable/unlinked local binding descriptor, strips every AgentNet and A2A private-key environment variable, preserves terminal I/O, maps every canonical communication method to the existing signed HTTP contract, propagates remote denials exactly, returns child exit/signal status, and removes the process-bound socket/capability/session directory on every exit path. Canonical room and response-obligation tools must remain strict and parity- identical across MCP, Pi, and Manager rather than growing a privileged surface.
Requirements: ID-001 through ID-009, AUTH-001, AUTH-002, AUTH-007, SEC-002, SEC-005, SEC-006
Required evidence: H, L, real ceremony E, and policy O
Current hermetic tests:
tests/identity/test_enrollment.pytests/identity/test_oidc_enrollment.pytests/approval/test_webauthn_service.pytests/approval/test_internal_broker.pytests/approval/test_internal_client.pytests/approval/test_approval_store_migration.pytests/approval/test_approval_http.pytests/approval/test_approval_cli.pytests/identity/test_credential_rotation.pytests/identity/test_recovery.pytests/identity/test_revocation.py
Remaining fuzz/external plans include JOSE/WebAuthn malformed-object corpora, real browser/authenticator ceremonies, independent-host compromise attempts, platform key custody, signer/authenticator rotation and recovery, and cross-device response-loss drills.
Test exact transaction hashing, OIDC issuer/audience/state/nonce/PKCE, WebAuthn
origin/RP/user verification, proof of possession, DPoP
method/URI/audience/domain/jti, key epochs, refresh rotation, recovery, device
loss, and offline revocation. OIDC callback tests preserve decoded pairs through
global duplicate-name rejection, accept unique provider extension parameters,
reject mixed success/error and orphan metadata, terminally consume only the exact
bound provider-error transaction, and prove zero token exchange on every error
or malformed response. Attack mix-up, code/OOB substitution, reused
challenges, duplicate JSON, oversized streaming bodies, copied identifiers,
stolen capabilities/tokens, sibling/cross-domain replay, response loss,
Core→Approval Bearer-only downgrade, duplicate/ambiguous proof headers,
method/path/body/audience/purpose/key substitution, stale/future proof,
sequential/concurrent/restart replay, replay-store/migration failure, and
fresh-nonce retry with unchanged business idempotency. Also attack
schema/key tamper, stale sign count, revoked credentials, harness automation
of approval, headless no-TTY refusal before begin/materialization, private URL
absence from normal output/errors, control-byte rejection, partial terminal
writes without retry, and resume without a second enrollment begin. Hermetic WebAuthn seams prove logic only; real workforce IdP,
authenticator, independent channel/host/device/OS account/TLS administration,
platform custody, and owner-approved ceremony remain required. Approval broker TLS tests also require explicit system-trust wiring, certificate-required and hostname-mismatch rejection, untrusted-chain rejection, ambient SSL_CERT_FILE/SSL_CERT_DIR/SSLKEYLOGFILE denial before setup, sanitized context/transport failure, and a real ordinary-server system-CA public-route pass.
Requirements: ID-003, ID-004, ID-006, ID-007, AUTH-001, AUTH-002, AUTH-004, AUTH-007
Required evidence: H and target-host P; exact harness evidence may require E
Planned tests:
tests/unit/test_signer_purpose_schema.pytests/host/test_local_ipc_attribution.pytests/security/test_signing_oracle_attacks.pytests/fuzz/test_ipc_frame_fuzz.pytests/bindings/test_remote_manager.pytests/authorization/test_communication_scope_service.py
Reject arbitrary-byte signing, unknown critical fields, wrong purpose/audience/domain/session, stale capabilities, and raw caller identities. Attack wrong and sibling processes, same UID, capability copying, PID reuse, socket replacement/symlink, inherited file descriptors, ptrace/proc dump, replay, restart, and flood. If exact same-UID attribution is not proven, verify that the compromise-domain fallback allows only draft, explicit human viewing, and deterministic non-business control while every protected operation denies.
Requirements: AUTH-003 through AUTH-010, ORG-001 through ORG-006, COM-007
Required evidence: H, L, and owner policy O
Planned tests:
tests/unit/test_authorization_fail_closed.pytests/property/test_authority_lattice.pytests/integration/test_grant_reservation_atomicity.pytests/integration/test_directional_assignment.pytests/property/test_relationship_lifecycle.pytests/fuzz/test_policy_input_fuzz.pytests/authorization/test_communication_scope_contract.pytests/authorization/test_communication_scope_service.pytests/integration/test_persistent_communication_journey.py
Generate arbitrary humans, harnesses, grants, relationships, revisions, resources, and revocations. Only human entitlement may add authority; deny/revoke wins. Missing, stale, diagnostic, schema-invalid, or incoherent state denies. Verify one-use grant/reservation atomicity and next-decision revocation. Admin-to-subordinate matching assignments reach accepted_queued; expired, revoked, scope-mismatched, upward, and lateral assignments remain non-executable absent a separate exact directed edge. Test concurrent revoke/renew, multiple administrators, subject exit, fencing, incompatible commands, and legal/security override.
For the persistent same-principal communication scope, attempt action-set,
restriction, resource, harness, credential, principal, domain, expiry, and
Approval-purpose substitution; duplicate and response-loss completion; crash
before entitlement commit; partial-item persistence; stale policy/credential;
and revocation or rotation during active use. Pending/rejected/expired state
must create no entitlement. Completion must create exactly 26 permanently
nonexpiring action/harness items or none, while every out-of-pair peer,
artifact, task, effect, administration, federation, and A2A operation remains
denied. Restart preserves the committed scope but never bypasses current-state
checks.
Requirements: FILE-003, FILE-004, AVL-003, AVL-005, AVL-006, AVL-007, OPS-001
Required evidence: H, L, and multi-node/failure-domain E
Planned tests:
tests/property/test_durability_invariants.pytests/chaos/test_artifact_commit_killpoints.pytests/chaos/test_postgres_failover_restore.pytests/integration/test_offline_reconnect.pytests/integration/test_attachment_durability.py
Fault every reservation, object write/ack/verification, promotion, event/audit/outbox commit, response, dispatch, and receipt boundary. accepted_durable must imply exact recoverable bytes and, for required files, the verified immutable object version plus manifest. Test same-key/different-digest conflict, torn writes, disk full, concurrent retry, reservation expiry, orphan inventory, required/optional attachment behavior, fanout, pressure, 1-hour/7-day/30-day offline, reconnect storms, failover/fencing, PITR, and full restore. One-host containers cannot certify RPO=0 or independent failure domains.
Requirements: COM-011, AVL-005, AVL-006, SEC-003, SEC-005
Required evidence: H, L, and connector-specific E for real effects
Planned tests:
tests/property/test_delivery_effect_state_machine.pytests/integration/test_effect_unknown_reconciliation.pytests/integration/test_expiry_cancel_commit_races.pytests/fuzz/test_receipt_ordering_fuzz.py
Model every actor-owned fact and per-recipient branch. No actor may assert another actor's fact; partial delivery is computed; completion/cancellation/global success requires owning evidence. effect_unknown must reconcile and never blind-retry. Race response loss, cancellation, reservation, commit, expiry, late receipts, contradictory receipts, and clock failure. Retention is independent of delivery/effect expiry, and exact retry cannot reopen an expired branch.
Requirements: ID-007, ID-009, AUTH-007, FILE-002, FED-009, SEC-006
Required evidence: H, L, cross-domain E, and continuity policy O
Planned tests:
tests/property/test_revocation_matrix.pytests/integration/test_revocation_next_decision.pytests/integration/test_no_sibling_reroute.pytests/interop/test_federation_revocation_slo.py
Exercise acceptance, queue, presentation, read, download, key release, processing, reservation, effect, room membership, and streams for human, harness, sibling, recipient, room, guest, key epoch, compromise window, domain quarantine, stale policy, and MLS epoch. Revocation is monotonic at the committed decision epoch, cannot reroute through a sibling, and must apply during offline/cache/stream races. Partner signal SLO and host kill require real cross-domain evidence and PD-009.
Requirements: COM-008, COM-010, SEC-002, SEC-006
Required evidence: H, L, external MLS/domain E where enabled, and governance O
Planned tests:
tests/model/test_room_authority_model.pytests/property/test_room_membership_history.pytests/integration/test_room_transfer.pytests/interop/test_mls_lifecycle.py
Model-check one owner, monotonic control sequence, frozen immutability, transfer CAS, competing transfers, cutoff ownership, crash at every transfer phase, permanent-loss tombstone, and fork labeling. Test membership/history visibility, removal, guests, legal hold, owner/recovery threshold, and independent application/owner/MLS epochs. A two-domain transfer must reconcile every event, recipient, artifact, effect, cancellation, capability, key, and audit row before commit. C3 requires the selected maintained MLS implementation and real multi-device evidence.
Requirements: FILE-001 through FILE-006, SEC-002, SEC-003, SEC-004, SEC-006
Required evidence: H, L, production backend/scanner E, and legal/audit O
Planned tests:
tests/security/test_hostile_file_corpus.pytests/unit/test_artifact_attestations.pytests/security/test_dedup_non_disclosure.pytests/chaos/test_audit_release_order.pytests/integration/test_audit_witness.pytests/integration/test_artifact_restore.py
Use malware fixtures, polyglots, MIME/extension mismatch, archives, symlink/path traversal, decompression/parser bombs, macros, links, and secret canaries. Test digest/version/profile-bound attestations, substitution, staleness, broken lineage, object swap, and E2EE membership. Run statistical cross-domain/tenant/class timing, quota, and duplicate probes. Kill between authorize, audit-intent commit, and capability/key/bytes release; sensitive material must never release first. Test omission, gaps, forks, checkpoints, backlog ceiling, outage, deletion, legal hold, and restore.
Requirements: AUTH-005, AUTH-006, AUTH-007, SEC-001, SEC-004, SEC-006, OPS-005
Required evidence: H, L, and exact-model/config E
Planned tests:
tests/redteam/test_adaptive_signed_peer_abuse.pytests/security/test_source_sink_oracle.pytests/property/test_budget_safety_capacity.pytests/fuzz/test_semantic_to_typed_fuzz.py
Put deterministic source/sink oracles around every protected read, credential use, disclosure, and effect. Use independently generated adaptive prompt-injection/exfiltration trials with seeded canaries and data-class/effect/sink coverage. Run at least 1,000 trials per exact model, harness, prompt, tool, parser, policy, and launch profile and report seeds, coverage, and confidence bounds. Fuzz semantic-to-typed conversion and hostile tool/file/web/Card output. Loop, fanout, reconnect, and cost floods must remain inside budgets while cancellation/revocation/security capacity remains available. The campaign is empirical evidence, never universal proof.
Requirements: ARC-001, SEC-007, OPS-006
Required evidence: H, target-platform P/E, and independently administered roots O
Planned tests:
tests/supply_chain/test_reproducible_artifacts.pytests/supply_chain/test_update_metadata.pytests/supply_chain/test_install_uninstall_cleanup.pytests/fuzz/test_package_metadata_fuzz.py
Verify reproducible artifacts, signatures, provenance, SBOM, dependency pins, threshold metadata, and root rotation. Attack rollback, freeze, expiry, compromised-adapter disable, canary failure, partial update, reinstall, and uninstall credential residue. Fuzz metadata, package manifests, archive extraction, path handling, and version comparison. Every supported OS/architecture needs its actual installer/update channel and separately controlled signing roots.
Requirements: ARC-002, ARC-005, AVL-007, OPS-001, OPS-004, OPS-005, OPS-006, OPS-007
Required evidence: L, production-like E, and topology/adoption O
Planned tests:
tests/chaos/test_dependency_failure_contract.pytests/operations/test_backup_restore.pytests/operations/test_kill_switch_slo.pytests/bakeoff/test_component_contract.pytests/bakeoff/test_component_replacement.py
Automate every dependency row in concept §14.4 and assert the exact hold/degraded state; forbid alternate credentials, stale allows, false durability, and silent backlog. Exercise backup/restore, kill switches under load, ceilings, unsupported combinations, and recovery reconciliation. Run every reuse candidate through one canonical contract covering identity mapping, revocation, offline/duplicate behavior, failure, egress, upgrade/rollback, schema mapping, and replacement. Attach pinned version, license, provenance, SBOM, self-hosting, resource, and operational evidence. Physical/admin topology and operator procedures cannot be proven locally.
Requirements: every feature depending on PD-001 through PD-011
Required evidence: O; no technical substitute exists
Planned tests:
tests/unit/test_policy_decision_records.pytests/integration/test_feature_policy_gate.pytests/security/test_unsigned_policy_rejection.py
Use machine-readable owner records containing decision, consequence, scope, owner, version, effective time, and signature. Map each feature to required PD records. Startup/readiness must reject enabling a dependent feature when its record is absent, expired, unsigned, or mismatched. Safe defaults permit development only; they never satisfy this gate.
Requirements: OPS-002, OPS-003, OPS-006
Required evidence: H, L, and real mixed-version E
Planned tests:
tests/unit/test_directory_non_enumeration.pytests/integration/test_profile_handshake.pytests/integration/test_rolling_upgrade.pytests/integration/test_config_migration.pytests/fuzz/test_handshake_config_fuzz.py
Test authorization-filtered non-enumerating list/get, forged/stale capability denial, bounded hint freshness, and key/endpoint epoch rotation. Cover N/N-1, unknown major/critical fields, no security downgrade, unsupported event queue/rejection, and preservation of signed unknown fields. Run expand/migrate/verify/contract and rollback only inside the compatibility window; revocation state never rolls back. Config export redacts secrets, import requires rebinding, and unknown security settings deny.
Requirements: ID-004, ID-009, AUTH-002, AUTH-007, SEC-002, SEC-003, SEC-005, SEC-006
Required evidence: H, L, external infrastructure E, and independent roots O
Planned tests:
tests/vectors/test_cross_language_crypto_vectors.pytests/unit/test_freshness_boundaries.pytests/chaos/test_replay_cache_partition.pytests/integration/test_key_rotation_backup_restore.pytests/operations/test_compromise_rebuild.py
Publish exact cross-language vectors for canonical preimages, signatures, receipts, callbacks, approvals, and artifact statements. Test age/future-skew boundaries, clock rollback, nonce reuse, jti entropy, persistent replay cache, sequence gaps, and key activation/overlap/revocation. Inject cache loss/partition, KMS outage, stale/substituted keys, cross-class decrypt, ACL denial, offline rotation, and backup-key restore. Drill quarantine, protected-effect stop, independent-log comparison, authority rebind, restore, and adjudication. Hardware custody, separately administered KMS/audit roots, and catastrophic compromise recovery are external/owner evidence.
A runnable local build can implement and locally test all canonical schemas, state machines, APIs, denial paths, safe fallbacks, deterministic source/sink controls, and simulated failure behavior. It cannot honestly certify:
| Claim | Relevant requirements/gates | Evidence still required |
|---|---|---|
| Four real harnesses and zero active-session interference | ARC-003; UX-001 through UX-006; gates 1–3 and 5 | Exact version-pinned Claude, Codex, Pi, and Antigravity binaries, credentials, UI/session instrumentation, and target-host execution (P/E). |
| Native A2A compatibility and public isolation | ARC-004, ARC-006, OPS-002, OPS-003; gate 4 | Pinned TCK, independent SDKs, certificates/callbacks, cross-SDK runs, and public peers (E). |
| Real verified human and independently authenticated approval | ID-001, ID-002, ID-004, ID-009, AUTH-008, AUTH-009; gates 6, 17, 19 | Workforce IdP, phishing-resistant WebAuthn outside the enrolling harness, exact transaction/code binding, platform key custody, and owner policy (E/O). Separately administered hosting is additional high-assurance evidence, not the ordinary-profile prerequisite. |
| Same-UID exact harness attribution | ID-006, AUTH-001, AUTH-004; gate 7 | Target OS/LSM/container/measurement evidence (P/E), otherwise the documented deterministic-only fallback applies. |
| Production durability and HA | FILE-003, AVL-003, AVL-004, AVL-007, OPS-001; gates 9 and 16 | Separate physical failure domains, synchronous PostgreSQL topology, replicated artifact backend, fencing, PITR, restore, and measured RPO/RTO (E/O). |
| Cross-company federation and revocation SLO | FED-001 through FED-009; gates 11, 16, 17 | Independently administered domains, partner identity, sponsor lifecycle, host kill, outage, incident, and revocation drills (E/O). |
| Production file safety, retention, and audit independence | FILE-003 through FILE-006, SEC-003, SEC-004; gate 13 | Selected scanner/object/WORM systems, independent witness administration, legal hold/deletion policy, and restore evidence (E/O). |
| C3 MLS lifecycle and model-provider disclosure | COM-008, COM-010, SEC-002; gates 11–13 and 17 | Maintained MLS implementation, real multi-device lifecycle, visible inspection members, and PD-007 (E/O). |
| Zero observed unintended effect in the required campaign | SEC-001, OPS-005; gate 14 | At least 1,000 adaptive trials for every exact supported model/config and complete reruns after relevant changes (E). This remains empirical, not universal proof. |
| Signed distribution and independent update roots | SEC-007, OPS-006; gate 15 | Real package channels on every supported OS/architecture and independent threshold-root administration (P/E/O). |
| Production operational topology and component suitability | OPS-001, OPS-004 through OPS-007; gate 16 | Capacity/SLO/restore drills on the selected topology, operator procedures, and reviewed third-party adoption records (E/O). |
| Organizational policy | Gate 17 and all PD-dependent requirements | Signed accountable decisions for PD-001 through PD-011 (O). No mock, default, or code path can substitute. |
| Catastrophic-root recovery | SEC-002, SEC-003, SEC-006; gate 19 | Independent KMS, approval, audit, database/object, and witness roles plus a real compromise/rebuild exercise (E/O). |
Unblocked implementation and local negative testing should continue. Release certification remains blocked on:
- signed owner decisions PD-001 through PD-011;
- the qualifying independent enrollment/approval boundary and recovery owner;
- the exact production physical/admin topology, accepted durability name, RPO/RTO, backlog ceilings, and witness arrangement;
- PD-007 plus maintained MLS and provider policy if C3 is enabled;
- PD-008/009 and independently administered partner infrastructure if federation is enabled;
- exact supported harness versions, target OS/architectures, model configurations, public A2A peers/SDKs, and external lab credentials;
- independently administered KMS/audit/update roots and legal/privacy/retention authority.
These blockers restrict claims and feature enablement; they do not justify weakening a requirement or marking a simulation as release evidence.