diff --git a/AGENTS.md b/AGENTS.md index 508821b..df2156b 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -1,10 +1,13 @@ # Agent operating boundary -This repository is a non-semantic infrastructure foundation. The semantic OIC -code-start gate remains **BLOCKED** by `STATUS.md`. No agent may implement or -claim document interpretation, candidate extraction, institutional admission, -Open Control Envelope generation, Rego compilation, or runtime semantic -decisions under this work order. +This repository contains infrastructure and the owner-admitted synthetic reference +path under OIC-SEMANTIC-PROMOTION-001. That work order alone permits its exact 58-path +maximum on `oic-weekly-convergence-2026-09-03`. The active capability matrix records +the bounded surface; it cannot authorize its own extension. No later work is authorized +by this file. After return, wait for a new deposited WO and explicit execution signal. +The broader production semantic gate remains **BLOCKED** by `STATUS.md`. No Open Control +Envelope generation, Rego compilation, real corpus fetch, live provider call, production +runtime decision, rights expansion, or merge to main is authorized by this promotion. ## Safe commands diff --git a/Makefile b/Makefile index 7e228d3..3e21dca 100644 --- a/Makefile +++ b/Makefile @@ -1,4 +1,4 @@ -.PHONY: verify falsify +.PHONY: verify falsify demo PYTHON ?= python @@ -11,3 +11,6 @@ verify: falsify: $(PYTHON) scripts/falsify_infrastructure.py + +demo: + @$(PYTHON) -B scripts/demo_bounded_semantic_path.py diff --git a/README.md b/README.md index aa317bc..744f24c 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # Open Institutional Compiler -- **Status:** OWNER-AUTHORIZED BOOTSTRAP - PRE-EXTERNAL-REVIEW +- **Status:** BOUNDED_REFERENCE_IMPLEMENTATION — scoped independent Gate F repository validation passed; merge pending Gate G and owner authorization - **Bootstrap date:** 2026-07-29 - **Governing design:** TDD-OIC-001 v1.1 @@ -17,14 +17,38 @@ Target capability: > evidentiary standard required to authorize, explain, audit, or correct those > actions. -**What exists today:** a tested, non-semantic Python infrastructure package for +**What exists today:** a Python infrastructure package for offline schema validation, historical bootstrap verification, current manifest verification, environment and gate diagnostics, and reproducible CI and SBOM -checks. It is not a functioning institutional compiler. - -**What is blocked:** semantic implementation remains blocked pending the corpus -provenance and ZTL/VEIP interface evidence listed in [`STATUS.md`](STATUS.md). -Nothing in this README opens that gate or promotes the repository's maturity. +checks, plus a deterministic offline synthetic reference path: grounded candidates, +divergent review records, supplied authority-evidence admission, provisional eleven-slot +interpretation, unresolved references, and canonical evidence receipts. It is not a +production institutional compiler. + +**What is blocked:** production compilation and runtime authorization remain unestablished. +The broader production semantic gate remains BLOCKED. The separately owner-admitted +synthetic slice does not qualify a model provider or broaden corpus rights. + +Run `make demo` (or `python -B scripts/demo_bounded_semantic_path.py`) in the installed +environment. It emits canonical JSON, makes no network request, needs no model credentials, +and writes no repository files. Two review records remain divergent; missing/malformed +authority evidence is refused. The eleven slots are provisional, not canonical meaning. +Independent Gate F repository validation passed for candidate +`c0108a7a80585d6f5732407d4904ba815073ecd2` (tree +`1d12b17aad7977c939090909171183be166cfd50`): canonical Linux execution reported +1714 passed, 0 failed, 0 errors, 1 declared skip, 93.5% coverage, and two +byte-identical offline demo runs with SHA-256 +`0f9d01bb0dfc488505e027ac7bd8aecf869578e379b5a977cd9d642f2101a39a`. This establishes reproducibility, boundary integrity, the +specified fail-closed properties, packaging, and the named adversarial checks for +that exact candidate only. It does not establish semantic correctness, model +accuracy, institutional validity, legal effect, provider qualification, rights +resolution, ontology execution, production compilation, runtime authorization, +institutional-IR closure, enterprise readiness, or benchmark superiority. It +also does not establish legal validity or production readiness. Merge remains +pending Gate G and owner authorization. +See [`CAPABILITY_MATRIX.json`](docs/capabilities/CAPABILITY_MATRIX.json) for exact provenance +and ceilings. NVIDIA is NOT_QUALIFIED; Canada redistribution is UNRESOLVED; Ontology 007R1 +is unexecuted and execution-unauthorized. No model accuracy or legal validity is claimed. ## Research paper @@ -305,9 +329,9 @@ semantic OIC-Bench results. | Schema validation | MEASURED - 9/9 | | Bootstrap integrity | MEASURED - 52/52 | | Infrastructure falsification harness | MEASURED - 4/4 | -| Full repository test suite | MEASURED - 1232 passed, 1 intentional skip | +| Prior main Linux baseline | MEASURED - 1255 passed, 1 intentional skip; not candidate acceptance | | Manifest | MEASURED - INCOMPLETE, required exit 3 | -| Semantic implementation gate | BLOCKED | +| Bounded synthetic path / production semantic gate | BOUNDED_REFERENCE_IMPLEMENTATION / BLOCKED | | OIC-Bench preflight design | PREREGISTERED | | Semantic OIC-Bench preflight | NOT YET RUN | | Full OIC-Bench v0.1 | NOT YET RUN | @@ -339,7 +363,7 @@ gate. ### Stage 1 - Source-to-control reference -**STATUS: NEXT - BLOCKED by the semantic code-start gate** +**STATUS: BOUNDED SYNTHETIC SUBSET IMPLEMENTED; full source-to-control path BLOCKED** Target path: @@ -406,7 +430,7 @@ conformance, and community governance. ## Current phase -This repository authorizes contract-first, non-semantic infrastructure work. +OIC-SEMANTIC-PROMOTION-001 admits the bounded offline synthetic reference path only. It currently implements four infrastructure CLI commands: - `oic validate-schema` @@ -414,9 +438,9 @@ It currently implements four infrastructure CLI commands: - `oic verify-manifest` - `oic doctor` -It does not implement document interpretation, candidate extraction, -institutional admission, Institutional IR production, Open Control Envelope -generation, Rego compilation, or runtime semantic decisions. +The separate demo exercises candidate extraction, supplied synthetic admission evidence, +and provisional interpretation. It does not implement Institutional IR production, +Open Control Envelope generation, Rego compilation, or runtime semantic decisions. Run the safe non-semantic checks after the hash-locked installation described in [`docs/operations/CI.md`](docs/operations/CI.md): @@ -432,7 +456,7 @@ must not be normalized into success. ## First executable objective -The first semantic objective remains blocked. When its prerequisites are +The full production source-to-control objective remains blocked. When its prerequisites are authorized, a bounded set of public or synthetic procurement governing sources is intended to flow through: @@ -489,8 +513,8 @@ boundaries include: ## Public limitations -The repository is a governance, contract, and non-semantic infrastructure -foundation. It is not a functioning institutional compiler. Current scope, +The repository is an infrastructure foundation with a bounded synthetic reference path. +It is not a production institutional compiler. Current scope, provisional interfaces, corpus restrictions, human-judgment boundaries, and benchmark limitations are recorded in [`LIMITATIONS.md`](LIMITATIONS.md). @@ -506,7 +530,7 @@ things. Passing tests or CI does not establish semantic correctness, institutional validity, compliance, comparative advantage, or owner acceptance. The permitted, evidence-gated, and forbidden claims are recorded in -[`CLAIMS.md`](CLAIMS.md). Semantic implementation remains blocked by +[`CLAIMS.md`](CLAIMS.md). The broader production semantic gate remains blocked by [`STATUS.md`](STATUS.md). ## Citation diff --git a/STATUS.md b/STATUS.md index fa649c1..7fe1e4a 100644 --- a/STATUS.md +++ b/STATUS.md @@ -2,13 +2,34 @@ ## Current status -**OWNER-AUTHORIZED BOOTSTRAP — PRE-EXTERNAL-REVIEW** - -This status authorizes repository creation, contract drafting, fixture preparation, dependency verification, benchmark preflight design, and non-semantic infrastructure scaffolding. - -It does not authorize public quality, enterprise-readiness, legal-compliance, universal-novelty, or superiority claims. - -## Exploratory code-start gate +**BOUNDED_REFERENCE_IMPLEMENTATION — SCOPED INDEPENDENT GATE F REPOSITORY VALIDATION PASSED** + +OIC-SEMANTIC-PROMOTION-001 admits only the 58-path maximum recorded in +`docs/capabilities/CAPABILITY_MATRIX.json`, from main +`9ad37fc80d8f34318c6212ed702de5eab3551cf5`. It implements an offline synthetic +reference path, not production compilation, runtime authorization, or canonical meaning. +Independent Gate F repository validation passed for exact candidate +`c0108a7a80585d6f5732407d4904ba815073ecd2`, tree +`1d12b17aad7977c939090909171183be166cfd50`. Canonical Linux execution reported +1714 passed, 0 failed, 0 errors, 1 declared skip, 93.5% coverage, and two +byte-identical offline demo runs with SHA-256 +`0f9d01bb0dfc488505e027ac7bd8aecf869578e379b5a977cd9d642f2101a39a`. The result +establishes reproducibility, boundary integrity, the specified fail-closed +properties, packaging, and named adversarial checks for that candidate only. +Merge remains pending Gate G and owner authorization; no merge is authorized. + +NVIDIA: NOT_QUALIFIED and excluded from the demo. Canada redistribution: UNRESOLVED. +Ontology 007R1: unexecuted and execution-unauthorized. Institutional-IR closure: +UNESTABLISHED. Production compilation and runtime authorization: UNESTABLISHED. Negative-stability +live outcome: DEFERRED. Existing SOURCE_MANIFEST.csv remains unchanged and entry-scoped. + +It does not establish semantic correctness, model accuracy, institutional validity, +legal effect, provider qualification, rights resolution, ontology execution, +production compilation, runtime authorization, institutional-IR closure, enterprise +readiness, or benchmark superiority. It also does not establish legal validity, +production readiness, public quality, universal novelty, or legal compliance. + +## Historical bootstrap exploratory code-start gate | Gate | Status | Required evidence | |---|---|---| @@ -21,6 +42,8 @@ It does not authorize public quality, enterprise-readiness, legal-compliance, un | Public Lab restrictions visible before upload | PASS as specification | `LIMITATIONS.md`, `docs/architecture/LAB_RESTRICTIONS.md` | | Named owner for each implemented module | PASS for kickoff | `OWNERS.md` | -**Semantic implementation gate:** BLOCKED until the preflight corpus manifest and ZTL/VEIP provisional-interface records are completed. +**Broader production semantic gate:** BLOCKED. Historical NOT OPEN receipts remain +unchanged; the active capability matrix supersedes only the bounded synthetic surface. -Infrastructure scaffolding and schema validation may proceed before that gate. +The reference path does not confer real institutional authority or runtime permission. +After this work order, another deposited authorization plus explicit execution signal is required. diff --git a/VERSIONING.md b/VERSIONING.md index 0fa4c93..08c6fe3 100644 --- a/VERSIONING.md +++ b/VERSIONING.md @@ -1,8 +1,10 @@ # Versioning OIC is `0.1.0a0`: pre-release infrastructure with provisional compatibility. -Pin an exact commit when reproducing it. No semantic compiler API or runtime -contract exists. +Pin an exact commit when reproducing it. Bounded candidate, admission-reference and +provisional interpretation APIs now exist; no production compiler/runtime contract exists. +The capability matrix records their source provenance and evidence ceilings. Frozen local +replay is not provider qualification or independent validation. ## Provisional public surfaces diff --git a/benchmarks/characterization/candidate-semantics-003/CORPUS-v0.3.json b/benchmarks/characterization/candidate-semantics-003/CORPUS-v0.3.json new file mode 100644 index 0000000..665d566 --- /dev/null +++ b/benchmarks/characterization/candidate-semantics-003/CORPUS-v0.3.json @@ -0,0 +1,41 @@ +{ + "work_order": "OIC-CANDIDATE-SEMANTICS-003", + "corpus_id": "OIC-CANDIDATE-SEMANTICS-003", + "corpus_version": "v0.3", + "predecessor_corpus_id": "OIC-CANDIDATE-SEMANTICS-002", + "predecessor_corpus_sha256": "f97b1a80d86f821495674dacccb8bc130f8bf78e559bab22f7aa0b5a32dd3b7c", + "purpose": "Frozen synthetic characterization of minimal source-grounded candidate-span discovery before admission.", + "claim_ceiling": "This characterization measures source-grounded candidate discovery under one frozen corpus, implementation commit, provider, model, and run condition. It does not establish semantic correctness, institutional admission, authority, enforceability, legal interpretation, runtime readiness, production readiness, or independent validation.", + "independent_validation_claim": false, + "material_span_group_semantics": "CONJUNCTIVE across groups and DISJUNCTIVE within each group: every group is material, and ONE listed literal rendering from each group must occur across the returned candidate spans for a run.", + "candidate_span_bounds_semantics": "Optional specimen-specific maximum proposition regions for bounded overreach observation; they are not universal shortest-span requirements.", + "specimen_count": 26, + "specimens": [ + {"specimen_id":"CSEM-001","category":"simple_obligation","source_text":"Each department must submit a quarterly expenditure report to the Finance Office.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["obligation","mandate","evidence_duty","temporal_trigger"],"families":[],"threshold_markers":null,"material_span_groups":[["the Finance Office","Finance Office"]],"candidate_span_bounds":null,"diagnostic_tags":["explicit_recipient"],"characterization_notes":"Named recipient must remain in the proposition span without a target role.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-002","category":"prohibition","source_text":"No employee may accept a gift valued over $75 from a supplier.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["prohibition"],"families":[],"threshold_markers":["$75","over $75"],"material_span_groups":[["valued over $75","over $75"]],"candidate_span_bounds":null,"diagnostic_tags":["quantitative_threshold"],"characterization_notes":"Quantitative threshold must remain inside the proposition span.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-008","category":"explicit_condition","source_text":"If a supplier is on the restricted list, the contract must not be awarded.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["prohibition","condition","obligation","mandate"],"families":[],"threshold_markers":null,"material_span_groups":[["If a supplier is on the restricted list"]],"candidate_span_bounds":null,"diagnostic_tags":["explicit_condition"],"characterization_notes":"Condition stays in the proposition span; no conditions role is requested.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-010","category":"exception_carve_out","source_text":"Travel bookings must use the central agency, except for travel funded entirely by an external host.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["obligation","mandate","exception"],"families":[],"threshold_markers":null,"material_span_groups":[["except for travel funded entirely by an external host"]],"candidate_span_bounds":null,"diagnostic_tags":["exception"],"characterization_notes":"The material exception must remain in the same source-grounded proposition.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-011","category":"evidence_duty","source_text":"The requesting unit must retain the original receipt for seven years.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["evidence_duty","obligation","mandate","temporal_trigger"],"families":[],"threshold_markers":null,"material_span_groups":[["the original receipt","original receipt"],["for seven years","seven years"]],"candidate_span_bounds":null,"diagnostic_tags":["evidence_retention","temporal_qualifier"],"characterization_notes":"Retention proposition and duration are preserved without evidence-role decomposition.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-013","category":"escalation","source_text":"If the parties cannot agree within ten business days, the matter is escalated to the Chief Operating Officer.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["escalation","temporal_trigger","condition","mandate","obligation"],"families":[],"threshold_markers":null,"material_span_groups":[["If the parties cannot agree within ten business days"],["to the Chief Operating Officer","Chief Operating Officer"]],"candidate_span_bounds":null,"diagnostic_tags":["trigger_consequence","explicit_recipient","temporal_qualifier"],"characterization_notes":"Trigger, consequence, and destination remain source text without canonical action selection.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-017","category":"advisory","source_text":"Units are encouraged to consolidate small purchases into a single order.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["advisory"],"families":[],"threshold_markers":null,"material_span_groups":null,"candidate_span_bounds":null,"diagnostic_tags":["advisory"],"characterization_notes":"Advisory language remains discoverable candidate material.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-018","category":"descriptive_non_normative","source_text":"The Finance Office is located on the fourth floor of the West Building and has twelve staff.","normative_expected":false,"expected_candidate_count_min":0,"expected_candidate_count_max":0,"acceptable_unit_types":null,"families":[],"threshold_markers":null,"material_span_groups":null,"candidate_span_bounds":null,"diagnostic_tags":["negative_control"],"characterization_notes":"Descriptive negative control.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-019","category":"operational_fact","source_text":"In the last fiscal year the department processed 4,812 purchase orders totalling $19.4 million.","normative_expected":false,"expected_candidate_count_min":0,"expected_candidate_count_max":0,"acceptable_unit_types":null,"families":[],"threshold_markers":null,"material_span_groups":null,"candidate_span_bounds":null,"diagnostic_tags":["negative_control"],"characterization_notes":"Operational-fact negative control with numbers.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-020","category":"marketing_prose","source_text":"Our procurement platform brings clarity and confidence to every stage of the buying journey.","normative_expected":false,"expected_candidate_count_min":0,"expected_candidate_count_max":0,"acceptable_unit_types":null,"families":[],"threshold_markers":null,"material_span_groups":null,"candidate_span_bounds":null,"diagnostic_tags":["negative_control"],"characterization_notes":"Marketing-prose negative control.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-021","category":"standing_draft","source_text":"DRAFT — NOT YET ADOPTED. A payment above $10,000 requires approval by the Chief Financial Officer.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["mandate","obligation","condition"],"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"draft"}],"threshold_markers":["$10,000"],"material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"characterization_notes":"Draft framing must not suppress discovery; bound excludes unrelated standing preface.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-022","category":"standing_non_authoritative","source_text":"DEVELOPMENT SYNTHETIC SOURCE — NOT AN AUTHORITATIVE POLICY. A payment above $10,000 requires approval by the Chief Financial Officer.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["mandate","obligation","condition"],"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"non_authoritative"}],"threshold_markers":["$10,000"],"material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"characterization_notes":"Non-authoritative framing must not suppress candidate discovery.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-023","category":"standing_hypothetical","source_text":"For the sake of illustration, suppose a rule stated that a payment above $10,000 requires approval by the Chief Financial Officer.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["mandate","obligation","condition"],"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"hypothetical"}],"threshold_markers":["$10,000"],"material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"candidate_span_bounds":["a payment above $10,000 requires approval by the Chief Financial Officer."],"diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"characterization_notes":"Hypothetical framing must not suppress candidate discovery.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-024","category":"standing_unverified","source_text":"UNVERIFIED EXTRACT — PROVENANCE NOT ESTABLISHED. A payment above $10,000 requires approval by the Chief Financial Officer.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["mandate","obligation","condition"],"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"unverified"}],"threshold_markers":["$10,000"],"material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"characterization_notes":"Unverified framing must not suppress candidate discovery.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-025","category":"multi_unit","source_text":"A purchase order must be approved before goods are ordered. Invoices are paid within thirty days of receipt.","normative_expected":true,"expected_candidate_count_min":2,"expected_candidate_count_max":null,"acceptable_unit_types":["obligation","mandate","temporal_trigger","condition","remedy"],"families":[],"threshold_markers":null,"material_span_groups":[["before goods are ordered"],["within thirty days of receipt"]],"candidate_span_bounds":["A purchase order must be approved before goods are ordered.","Invoices are paid within thirty days of receipt."],"diagnostic_tags":["multi_unit","passive_voice","temporal_qualifier"],"characterization_notes":"Two passive propositions should be separate without inferred actors.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-027","category":"threshold_plus_approval","source_text":"A payment above $10,000 requires approval by the Chief Financial Officer.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["mandate","obligation","condition"],"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"baseline"},{"family_id":"CFO-10K-PARAPHRASE","family_kind":"paraphrase","role":"baseline"}],"threshold_markers":["$10,000"],"material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"candidate_span_bounds":null,"diagnostic_tags":["source_standing","paraphrase","quantitative_threshold","explicit_recipient"],"characterization_notes":"Baseline for standing and paraphrase families.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-028","category":"paraphrase_variant","source_text":"Approval by the Chief Financial Officer is required for any payment exceeding $10,000.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["mandate","obligation","condition"],"families":[{"family_id":"CFO-10K-PARAPHRASE","family_kind":"paraphrase","role":"variant_a"}],"threshold_markers":["$10,000"],"material_span_groups":[["exceeding $10,000"],["Chief Financial Officer"]],"candidate_span_bounds":null,"diagnostic_tags":["paraphrase","quantitative_threshold","explicit_recipient","passive_voice"],"characterization_notes":"Paraphrase comparison uses presence, count, and type compatibility, not exact spans.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-029","category":"paraphrase_variant","source_text":"The Chief Financial Officer must approve payments of more than $10,000.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["mandate","obligation","condition"],"families":[{"family_id":"CFO-10K-PARAPHRASE","family_kind":"paraphrase","role":"variant_b"}],"threshold_markers":["$10,000"],"material_span_groups":[["more than $10,000"],["Chief Financial Officer"]],"candidate_span_bounds":null,"diagnostic_tags":["paraphrase","quantitative_threshold","explicit_recipient"],"characterization_notes":"Second paraphrase variant.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-031","category":"institutional_vocabulary_no_norm","source_text":"This section explains the governance framework, the delegation register, and the compliance calendar maintained by the Secretariat.","normative_expected":false,"expected_candidate_count_min":0,"expected_candidate_count_max":0,"acceptable_unit_types":null,"families":[],"threshold_markers":null,"material_span_groups":null,"candidate_span_bounds":null,"diagnostic_tags":["negative_control"],"characterization_notes":"Institutional vocabulary without normative proposition.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-032","category":"operational_fact","source_text":"The vendor portal was upgraded on 3 March and now supports single sign-on.","normative_expected":false,"expected_candidate_count_min":0,"expected_candidate_count_max":0,"acceptable_unit_types":null,"families":[],"threshold_markers":null,"material_span_groups":null,"candidate_span_bounds":null,"diagnostic_tags":["negative_control"],"characterization_notes":"Second operational-fact negative control.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-033","category":"passive_no_actor","source_text":"Purchase requisitions are reviewed before funds are committed.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["obligation","mandate","review_duty","condition","temporal_trigger"],"families":[],"threshold_markers":null,"material_span_groups":[["before funds are committed"]],"candidate_span_bounds":null,"diagnostic_tags":["passive_no_actor","temporal_qualifier"],"characterization_notes":"Preserve passive proposition; candidate contract has no actor field.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-034","category":"explicit_target","source_text":"The completed inspection form must be sent to the Regional Safety Office.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["obligation","mandate","evidence_duty"],"families":[],"threshold_markers":null,"material_span_groups":[["to the Regional Safety Office","Regional Safety Office"]],"candidate_span_bounds":null,"diagnostic_tags":["explicit_recipient"],"characterization_notes":"Recipient remains source text without target classification.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-036","category":"condition_vs_operative","source_text":"If the vendor fails to deliver within five business days, the order is cancelled.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["remedy","escalation","condition","temporal_trigger","mandate","obligation"],"families":[],"threshold_markers":null,"material_span_groups":[["If the vendor fails to deliver within five business days"],["the order is cancelled"]],"candidate_span_bounds":null,"diagnostic_tags":["trigger_consequence","explicit_condition","temporal_qualifier"],"characterization_notes":"Preserve trigger and consequence without choosing a canonical action role.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-037","category":"advisory","source_text":"Departments should consider shared service arrangements before procuring separately.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["advisory"],"families":[],"threshold_markers":null,"material_span_groups":[["before procuring separately"]],"candidate_span_bounds":null,"diagnostic_tags":["advisory","temporal_qualifier"],"characterization_notes":"Advisory qualifier must remain in the proposition span.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-039","category":"evidence_duty","source_text":"The contracting officer must keep a written record of each competitive quotation obtained.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["evidence_duty","obligation","mandate"],"families":[],"threshold_markers":null,"material_span_groups":[["a written record of each competitive quotation obtained"]],"candidate_span_bounds":null,"diagnostic_tags":["evidence_retention"],"characterization_notes":"Evidence-retention proposition remains whole; type stays provisional.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."}, + {"specimen_id":"CSEM-040","category":"numeric_threshold","source_text":"A single sole-source award may not exceed $40,000 without prior Board approval.","normative_expected":true,"expected_candidate_count_min":1,"expected_candidate_count_max":null,"acceptable_unit_types":["prohibition","condition","obligation","mandate","permission"],"families":[],"threshold_markers":["$40,000"],"material_span_groups":[["exceed $40,000"],["without prior Board approval"]],"candidate_span_bounds":null,"diagnostic_tags":["quantitative_threshold","explicit_condition"],"characterization_notes":"Threshold and approval qualifier remain within candidate span.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination."} + ] +} diff --git a/benchmarks/characterization/candidate-semantics-004/CORPUS-v0.4.json b/benchmarks/characterization/candidate-semantics-004/CORPUS-v0.4.json new file mode 100644 index 0000000..50bb184 --- /dev/null +++ b/benchmarks/characterization/candidate-semantics-004/CORPUS-v0.4.json @@ -0,0 +1 @@ +{"candidate_span_bounds_semantics":"Optional specimen-specific maximum proposition regions for bounded overreach observation; they are not universal shortest-span requirements.","claim_ceiling":"This experiment characterizes candidate-span framing separation under one frozen synthetic corpus, implementation commit, provider/model when later run live, and bounded run conditions. It does not establish semantic correctness, institutional admission, authority, enforceability, legal interpretation, production readiness, runtime readiness, cross-model generalization, or independent validation.","corpus_id":"OIC-CANDIDATE-SEMANTICS-004","corpus_version":"v0.4","framing_separation_note":"Framing separation is asked of the provider in the prompt contract and is never imposed afterwards. No phrase list, regex, or post-generation trimming exists in production code; an overreaching span is accepted as returned and reported.","independent_validation_claim":false,"material_span_group_semantics":"CONJUNCTIVE across groups and DISJUNCTIVE within each group: every group is material, and ONE listed literal rendering from each group must occur across the returned candidate spans for a run.","predecessor_corpus_id":"OIC-CANDIDATE-SEMANTICS-003","predecessor_corpus_sha256":"8555d59112b07ee6c438136b79602c3b2658e2ff96abfa5deb4563a09883db5a","purpose":"Focused frozen regression corpus for candidate-span framing separation. Not a broad semantic suite: it carries the framing-relevant OIC-CANDIDATE-SEMANTICS-003 specimens verbatim so before/after behaviour is measurable, and adds five diagnostics for framing structures the predecessor did not cover.","separable_framing_span_semantics":"Literal source spans that state the source's own status rather than forming part of the proposition. A candidate span containing any of them is recorded as carrying separable framing. Preregistration describes the SOURCE, not a required answer, and null means no separable framing is present.","specimen_count":14,"specimens":[{"acceptable_unit_types":["advisory"],"candidate_span_bounds":null,"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"advisory","characterization_notes":"Advisory language remains discoverable candidate material.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["advisory"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":false,"framing_structure":"no_framing_present","material_span_groups":null,"normative_expected":true,"separable_framing_spans":null,"source_text":"Units are encouraged to consolidate small purchases into a single order.","specimen_id":"CSEM-017","threshold_markers":null},{"acceptable_unit_types":null,"candidate_span_bounds":null,"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"descriptive_non_normative","characterization_notes":"Descriptive negative control.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":"negative_control","material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_text":"The Finance Office is located on the fourth floor of the West Building and has twelve staff.","specimen_id":"CSEM-018","threshold_markers":null},{"acceptable_unit_types":["mandate","obligation","condition"],"candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"standing_draft","characterization_notes":"Draft framing must not suppress discovery; bound excludes unrelated standing preface.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"draft"}],"framing_expected_excluded":true,"framing_structure":"draft_prefix","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":["DRAFT — NOT YET ADOPTED."],"source_text":"DRAFT — NOT YET ADOPTED. A payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-021","threshold_markers":["$10,000"]},{"acceptable_unit_types":["mandate","obligation","condition"],"candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"standing_non_authoritative","characterization_notes":"Non-authoritative framing must not suppress candidate discovery.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"non_authoritative"}],"framing_expected_excluded":true,"framing_structure":"non_authoritative_prefix","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":["DEVELOPMENT SYNTHETIC SOURCE — NOT AN AUTHORITATIVE POLICY."],"source_text":"DEVELOPMENT SYNTHETIC SOURCE — NOT AN AUTHORITATIVE POLICY. A payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-022","threshold_markers":["$10,000"]},{"acceptable_unit_types":["mandate","obligation","condition"],"candidate_span_bounds":["a payment above $10,000 requires approval by the Chief Financial Officer."],"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"standing_hypothetical","characterization_notes":"Hypothetical framing must not suppress candidate discovery.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"hypothetical"}],"framing_expected_excluded":true,"framing_structure":"hypothetical_wrapper","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":["For the sake of illustration, suppose a rule stated that"],"source_text":"For the sake of illustration, suppose a rule stated that a payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-023","threshold_markers":["$10,000"]},{"acceptable_unit_types":["mandate","obligation","condition"],"candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"standing_unverified","characterization_notes":"Unverified framing must not suppress candidate discovery.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"unverified"}],"framing_expected_excluded":true,"framing_structure":"unverified_prefix","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":["UNVERIFIED EXTRACT — PROVENANCE NOT ESTABLISHED."],"source_text":"UNVERIFIED EXTRACT — PROVENANCE NOT ESTABLISHED. A payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-024","threshold_markers":["$10,000"]},{"acceptable_unit_types":["obligation","mandate","temporal_trigger","condition","remedy"],"candidate_span_bounds":["A purchase order must be approved before goods are ordered.","Invoices are paid within thirty days of receipt."],"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"multi_unit","characterization_notes":"Two passive propositions should be separate without inferred actors.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["multi_unit","passive_voice","temporal_qualifier"],"expected_candidate_count_max":null,"expected_candidate_count_min":2,"families":[],"framing_expected_excluded":false,"framing_structure":"no_framing_present","material_span_groups":[["before goods are ordered"],["within thirty days of receipt"]],"normative_expected":true,"separable_framing_spans":null,"source_text":"A purchase order must be approved before goods are ordered. Invoices are paid within thirty days of receipt.","specimen_id":"CSEM-025","threshold_markers":null},{"acceptable_unit_types":["mandate","obligation","condition"],"candidate_span_bounds":null,"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"threshold_plus_approval","characterization_notes":"Baseline for standing and paraphrase families.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","paraphrase","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"baseline"},{"family_id":"CFO-10K-PARAPHRASE","family_kind":"paraphrase","role":"baseline"}],"framing_expected_excluded":false,"framing_structure":"no_framing_present","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":null,"source_text":"A payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-027","threshold_markers":["$10,000"]},{"acceptable_unit_types":null,"candidate_span_bounds":null,"carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"institutional_vocabulary_no_norm","characterization_notes":"Institutional vocabulary without normative proposition.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":"negative_control","material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_text":"This section explains the governance framework, the delegation register, and the compliance calendar maintained by the Secretariat.","specimen_id":"CSEM-031","threshold_markers":null},{"acceptable_unit_types":["obligation","mandate","temporal_trigger"],"candidate_span_bounds":["a contractor must return unused equipment within ten days of contract end."],"carried_from_corpus":null,"category":"standing_illustrative","characterization_notes":"Illustrative wrapper distinct from the hypothetical 'suppose' construction. The colon makes the framing grammatically separable.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","illustrative_wrapper","temporal_qualifier"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":true,"framing_structure":"illustrative_wrapper","material_span_groups":[["unused equipment"],["within ten days of contract end"]],"normative_expected":true,"separable_framing_spans":["The following example is not authoritative:"],"source_text":"The following example is not authoritative: a contractor must return unused equipment within ten days of contract end.","specimen_id":"CSEM-041","threshold_markers":null},{"acceptable_unit_types":["obligation","mandate","condition"],"candidate_span_bounds":["subcontractors must carry liability insurance of at least $2,000,000."],"carried_from_corpus":null,"category":"source_attribution","characterization_notes":"Attribution to another party is metalinguistic framing, not part of the proposition. Whether the vendor's summary is authoritative is not a discovery question and is not decided here.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","source_attribution","quantitative_threshold"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":true,"framing_structure":"source_attribution","material_span_groups":[["subcontractors"],["at least $2,000,000"]],"normative_expected":true,"separable_framing_spans":["According to the vendor's own summary,"],"source_text":"According to the vendor's own summary, subcontractors must carry liability insurance of at least $2,000,000.","specimen_id":"CSEM-042","threshold_markers":["$2,000,000"]},{"acceptable_unit_types":["obligation","mandate","condition","evidence_duty"],"candidate_span_bounds":["Where a contract is still in draft, the sponsoring unit must record the reason for the delay."],"carried_from_corpus":null,"category":"condition_is_not_framing","characterization_notes":"The control against over-stripping. 'still in draft' describes the contract the rule governs, not the standing of this source, so it is material proposition content and must stay inside the span. A span that drops it is underreach, not framing separation.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","must_not_strip","explicit_condition"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":false,"framing_structure":"draft_word_inside_proposition","material_span_groups":[["Where a contract is still in draft"],["record the reason for the delay"]],"normative_expected":true,"separable_framing_spans":null,"source_text":"Where a contract is still in draft, the sponsoring unit must record the reason for the delay.","specimen_id":"CSEM-043","threshold_markers":null},{"acceptable_unit_types":["advisory"],"candidate_span_bounds":["Units are advised to review supplier performance before renewing a contract."],"carried_from_corpus":null,"category":"advisory_under_framing","characterization_notes":"Advisory material under a draft prefix: presence and framing separation measured together. Advisory wording compels nothing and stays candidate material.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","advisory","draft_prefix"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":true,"framing_structure":"draft_prefix_over_advisory","material_span_groups":[["review supplier performance"],["before renewing a contract"]],"normative_expected":true,"separable_framing_spans":["DRAFT FOR CONSULTATION."],"source_text":"DRAFT FOR CONSULTATION. Units are advised to review supplier performance before renewing a contract.","specimen_id":"CSEM-044","threshold_markers":null},{"acceptable_unit_types":["obligation","mandate","temporal_trigger","condition","remedy"],"candidate_span_bounds":["A purchase requisition must be approved before an order is placed.","Suppliers are paid within forty-five days of invoice."],"carried_from_corpus":null,"category":"shared_framing_multi_unit","characterization_notes":"One framing prefix over two independent propositions. Both should be separated and neither should carry the prefix.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","multi_unit","shared_framing_prefix"],"expected_candidate_count_max":null,"expected_candidate_count_min":2,"families":[],"framing_expected_excluded":true,"framing_structure":"shared_framing_prefix_two_propositions","material_span_groups":[["before an order is placed"],["within forty-five days of invoice"]],"normative_expected":true,"separable_framing_spans":["NOT YET IN FORCE."],"source_text":"NOT YET IN FORCE. A purchase requisition must be approved before an order is placed. Suppliers are paid within forty-five days of invoice.","specimen_id":"CSEM-045","threshold_markers":null}],"work_order":"OIC-CANDIDATE-SEMANTICS-004"} diff --git a/benchmarks/characterization/candidate-semantics-005/CORPUS-v0.5.json b/benchmarks/characterization/candidate-semantics-005/CORPUS-v0.5.json new file mode 100644 index 0000000..a82fd43 --- /dev/null +++ b/benchmarks/characterization/candidate-semantics-005/CORPUS-v0.5.json @@ -0,0 +1 @@ +{"candidate_span_bounds_semantics":"Optional specimen-specific maximum proposition regions for bounded overreach observation; they are not universal shortest-span requirements.","claim_ceiling":"This corpus characterizes one bounded candidate-discovery prompt contract under one frozen synthetic corpus, implementation commit, provider/model when later run live, and bounded run conditions. It does not establish semantic correctness, zero false-positive probability, institutional admission, authority, enforceability, legal interpretation, production readiness, cross-model generalization, statistical superiority, or independent validation.","corpus_id":"OIC-CANDIDATE-SEMANTICS-005","corpus_version":"v0.5","independent_validation_claim":false,"material_span_group_semantics":"CONJUNCTIVE across groups and DISJUNCTIVE within each group: every group is material, and ONE listed literal rendering from each group must occur across the returned candidate spans for a run.","motivating_evidence":"The frozen OIC-CANDIDATE-NEGATIVE-STABILITY-001 A/B compared commits db95d8fdf52b5ffb546b2ebd84bb9e035629c46f (003) and 11acd84b97bbdb3910c208e63b69b4fbb10be179 (004) over 112 requests. Its preregistered band returned INCONCLUSIVE and that historical result is not rewritten here. What it did observe was localized and reproducible: 3 false positives, all on CSEM-031, all in the 004 arm, all returning the entire fragment typed advisory, against 0 in the 003 arm. The architecture owner authorized a narrow correction on that observed defect. No statistical-significance claim is made or implied.","normative_discovery_rule":"Candidate discovery requires a proposition that itself appears to perform a provisional normative or constitutive function. Institutional vocabulary and institutional subject matter are never sufficient on their own, and no particular modal verb is required.","predecessor_003_corpus_sha256":"8555d59112b07ee6c438136b79602c3b2658e2ff96abfa5deb4563a09883db5a","predecessor_corpus_id":"OIC-CANDIDATE-SEMANTICS-004","predecessor_corpus_sha256":"594cbee619f467ef949690cd56014eb4f8b3c5ba9527596c6e4bef3f242d5386","production_base_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","purpose":"Focused frozen regression corpus for the candidate normative-discovery boundary. Carries the negative controls, positive sentinels and framing/material sentinels verbatim from the frozen 003 and 004 corpora so no successful OIC-CANDIDATE-SEMANTICS-004 property can regress unobserved, and adds seven diagnostics separating institutional subject matter from normative function.","separable_framing_span_semantics":"Literal source spans that state the source's own status rather than forming part of the proposition. A candidate span containing any of them is recorded as carrying separable framing. Preregistration describes the SOURCE, not a required answer, and null means no separable framing is present.","specimen_count":21,"specimens":[{"acceptable_unit_types":["advisory"],"arm_role":"positive_sentinel","candidate_span_bounds":null,"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"advisory","characterization_notes":"Positive sentinel: genuine advisory guidance must remain discoverable.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["advisory"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":false,"framing_structure":"no_framing_present","material_span_groups":null,"normative_expected":true,"separable_framing_spans":null,"source_sha256":"116b3bdd9a1b56eed6f1c7f50e3e87adb94733c1c2213d3fcfd5266eb1436574","source_text":"Units are encouraged to consolidate small purchases into a single order.","specimen_id":"CSEM-017","threshold_markers":null},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"descriptive_non_normative","characterization_notes":"Negative control: descriptive prose.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":"negative_control","material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"10b0f9da81824a3a242ee5165dc5f738e514d38597dc5ee9737a209db21b89c4","source_text":"The Finance Office is located on the fourth floor of the West Building and has twelve staff.","specimen_id":"CSEM-018","threshold_markers":null},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":"db95d8fdf52b5ffb546b2ebd84bb9e035629c46f","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"operational_fact","characterization_notes":"Negative control: quantitative operational fact.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"4a47520dbbbde5aa308065f7ba6038bd946497d7cdfbbe05c67a67ef53218fd0","source_text":"In the last fiscal year the department processed 4,812 purchase orders totalling $19.4 million.","specimen_id":"CSEM-019","threshold_markers":null},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":"db95d8fdf52b5ffb546b2ebd84bb9e035629c46f","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"marketing_prose","characterization_notes":"Negative control: promotional prose.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"011f4a98fb5235dac8c610a1ceb13e70125373afd7a877a5e1838033e72aa643","source_text":"Our procurement platform brings clarity and confidence to every stage of the buying journey.","specimen_id":"CSEM-020","threshold_markers":null},{"acceptable_unit_types":["mandate","obligation","condition"],"arm_role":"framing_sentinel","candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"standing_draft","characterization_notes":"Framing sentinel: the draft prefix must stay outside the span.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"draft"}],"framing_expected_excluded":true,"framing_structure":"draft_prefix","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":["DRAFT — NOT YET ADOPTED."],"source_sha256":"91bb7ec5c30b7abb41a625f9cd0c37f4db201abb0ba39a35077ef9eead2eddd5","source_text":"DRAFT — NOT YET ADOPTED. A payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-021","threshold_markers":["$10,000"]},{"acceptable_unit_types":["mandate","obligation","condition"],"arm_role":"framing_sentinel","candidate_span_bounds":["a payment above $10,000 requires approval by the Chief Financial Officer."],"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"standing_hypothetical","characterization_notes":"Framing sentinel: hypothetical wrapper.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"hypothetical"}],"framing_expected_excluded":true,"framing_structure":"hypothetical_wrapper","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":["For the sake of illustration, suppose a rule stated that"],"source_sha256":"e8e98f8819bb9f5dae48c7c16e17ec15b970eca21ac49659073d9171416ec6ce","source_text":"For the sake of illustration, suppose a rule stated that a payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-023","threshold_markers":["$10,000"]},{"acceptable_unit_types":["mandate","obligation","condition"],"arm_role":"framing_sentinel","candidate_span_bounds":["A payment above $10,000 requires approval by the Chief Financial Officer."],"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"standing_unverified","characterization_notes":"Framing sentinel: unverified prefix.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"unverified"}],"framing_expected_excluded":true,"framing_structure":"unverified_prefix","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":["UNVERIFIED EXTRACT — PROVENANCE NOT ESTABLISHED."],"source_sha256":"9dd82f20b1af5ffbe7d618b8207f20532897d9322a4604822f130f114cdde523","source_text":"UNVERIFIED EXTRACT — PROVENANCE NOT ESTABLISHED. A payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-024","threshold_markers":["$10,000"]},{"acceptable_unit_types":["obligation","mandate","temporal_trigger","condition","remedy"],"arm_role":"material_sentinel","candidate_span_bounds":["A purchase order must be approved before goods are ordered.","Invoices are paid within thirty days of receipt."],"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"multi_unit","characterization_notes":"Material sentinel: multi-unit separation must not regress.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["multi_unit","passive_voice","temporal_qualifier"],"expected_candidate_count_max":null,"expected_candidate_count_min":2,"families":[],"framing_expected_excluded":false,"framing_structure":"no_framing_present","material_span_groups":[["before goods are ordered"],["within thirty days of receipt"]],"normative_expected":true,"separable_framing_spans":null,"source_sha256":"955448879d7928a2a39b736b4fbe40bb9c5523d3bf46287ea39363699c98f8ba","source_text":"A purchase order must be approved before goods are ordered. Invoices are paid within thirty days of receipt.","specimen_id":"CSEM-025","threshold_markers":null},{"acceptable_unit_types":["mandate","obligation","condition"],"arm_role":"positive_sentinel","candidate_span_bounds":null,"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"threshold_plus_approval","characterization_notes":"Positive sentinel: genuine mandate with a threshold and a recipient.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["source_standing","paraphrase","quantitative_threshold","explicit_recipient"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[{"family_id":"CFO-10K-STANDING","family_kind":"source_standing","role":"baseline"},{"family_id":"CFO-10K-PARAPHRASE","family_kind":"paraphrase","role":"baseline"}],"framing_expected_excluded":false,"framing_structure":"no_framing_present","material_span_groups":[["above $10,000"],["Chief Financial Officer"]],"normative_expected":true,"separable_framing_spans":null,"source_sha256":"0447393c19acb7f58e332589a7f489bd88f9404ff40125dc9ab21a355206ab4a","source_text":"A payment above $10,000 requires approval by the Chief Financial Officer.","specimen_id":"CSEM-027","threshold_markers":["$10,000"]},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"institutional_vocabulary_no_norm","characterization_notes":"THE MOTIVATING SPECIMEN. Institutional vocabulary with no normative proposition. 003 returned zero candidates in 10/10 provider-successful runs; 004 returned the whole fragment typed advisory in 3 of 9. It remains a negative control and 005 must return zero candidates for it.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":"negative_control","material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"d6d9df0f354664ae2dded1c4bdd21902deefcbd7561359f64ca7783af4ffc12f","source_text":"This section explains the governance framework, the delegation register, and the compliance calendar maintained by the Secretariat.","specimen_id":"CSEM-031","threshold_markers":null},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":"db95d8fdf52b5ffb546b2ebd84bb9e035629c46f","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-003","category":"operational_fact","characterization_notes":"Negative control: operational event report.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"f04594ffa5f8ef4dfe26fd6486891a1eba3240df0cf52bd6aa711515c078b572","source_text":"The vendor portal was upgraded on 3 March and now supports single sign-on.","specimen_id":"CSEM-032","threshold_markers":null},{"acceptable_unit_types":["obligation","mandate","condition","evidence_duty"],"arm_role":"material_sentinel","candidate_span_bounds":["Where a contract is still in draft, the sponsoring unit must record the reason for the delay."],"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"condition_is_not_framing","characterization_notes":"Material sentinel and over-correction control: 'still in draft' governs the contract, not this source, so it stays inside the span.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","must_not_strip","explicit_condition"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":false,"framing_structure":"draft_word_inside_proposition","material_span_groups":[["Where a contract is still in draft"],["record the reason for the delay"]],"normative_expected":true,"separable_framing_spans":null,"source_sha256":"20dbba1e4dc5ad6507edd28d1f0ab0569802cc4a5cd1a893f480c4fc10f21c86","source_text":"Where a contract is still in draft, the sponsoring unit must record the reason for the delay.","specimen_id":"CSEM-043","threshold_markers":null},{"acceptable_unit_types":["advisory"],"arm_role":"framing_sentinel","candidate_span_bounds":["Units are advised to review supplier performance before renewing a contract."],"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"advisory_under_framing","characterization_notes":"Framing sentinel: advisory under a draft prefix; both must survive 005.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","advisory","draft_prefix"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":true,"framing_structure":"draft_prefix_over_advisory","material_span_groups":[["review supplier performance"],["before renewing a contract"]],"normative_expected":true,"separable_framing_spans":["DRAFT FOR CONSULTATION."],"source_sha256":"4f8fc116aad412da0b28b9c8450fd655556ffe59f8ecb6c7cce727d747e80027","source_text":"DRAFT FOR CONSULTATION. Units are advised to review supplier performance before renewing a contract.","specimen_id":"CSEM-044","threshold_markers":null},{"acceptable_unit_types":["obligation","mandate","temporal_trigger","condition","remedy"],"arm_role":"framing_sentinel","candidate_span_bounds":["A purchase requisition must be approved before an order is placed.","Suppliers are paid within forty-five days of invoice."],"carried_from_commit":"11acd84b97bbdb3910c208e63b69b4fbb10be179","carried_from_corpus":"OIC-CANDIDATE-SEMANTICS-004","category":"shared_framing_multi_unit","characterization_notes":"Framing sentinel: one prefix over two propositions.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["framing_separation","multi_unit","shared_framing_prefix"],"expected_candidate_count_max":null,"expected_candidate_count_min":2,"families":[],"framing_expected_excluded":true,"framing_structure":"shared_framing_prefix_two_propositions","material_span_groups":[["before an order is placed"],["within forty-five days of invoice"]],"normative_expected":true,"separable_framing_spans":["NOT YET IN FORCE."],"source_sha256":"ec0b87a72b5be35a2297e19c24f60e89ed87a6dccf4bee6feb77eb0d3d82d890","source_text":"NOT YET IN FORCE. A purchase requisition must be approved before an order is placed. Suppliers are paid within forty-five days of invoice.","specimen_id":"CSEM-045","threshold_markers":null},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":null,"carried_from_corpus":null,"category":"institutional_description_only","characterization_notes":"Institutional vocabulary and an institutional actor, describing only what a unit holds and distributes. Nothing is required, permitted, prohibited or defined.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control","institutional_vocabulary","description_only"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"c3c1763cfbc367bdc81edac600d3632817c52018a9dff6d07d4e6002bf158fdd","source_text":"The records unit holds the master list of authorised signatories and distributes it each term.","specimen_id":"CSEM-046","threshold_markers":null},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":null,"carried_from_corpus":null,"category":"institutional_description_plus_history","characterization_notes":"Compliance and delegation vocabulary attached to a report of past activity. Numerals and institutional nouns together must still yield no candidate.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control","institutional_vocabulary","historical_fact"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"a901f6497e591a9f142b1570f801bc73b90b765eb45981dd2644127041d557b2","source_text":"Last quarter the compliance committee met four times and reviewed nineteen delegations.","specimen_id":"CSEM-047","threshold_markers":null},{"acceptable_unit_types":null,"arm_role":"negative_control","candidate_span_bounds":null,"carried_from_commit":null,"carried_from_corpus":null,"category":"explanatory_section_no_norm","characterization_notes":"An explanatory section body, the same shape as CSEM-031 in different words, so the correction is not tuned to one sentence.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["negative_control","institutional_vocabulary","explanatory_prose"],"expected_candidate_count_max":0,"expected_candidate_count_min":0,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":null,"normative_expected":false,"separable_framing_spans":null,"source_sha256":"212a5c538e89a5ec85b0b6a5ccbd873beaab7448f7cb38ab6f19c63d854eff1a","source_text":"Part 3 sets out the structure of the audit function and lists the roles that contribute to it.","specimen_id":"CSEM-048","threshold_markers":null},{"acceptable_unit_types":["definition"],"arm_role":"positive_sentinel","candidate_span_bounds":["For the purposes of this part, 'Responsible Officer' means the person holding the budget delegation for the unit."],"carried_from_commit":null,"carried_from_corpus":null,"category":"constitutive_definition","characterization_notes":"A definition that constitutes rather than explains. If 005 over-corrects and starts treating definitional language as description, this is where it shows.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["positive_sentinel","constitutive_definition","over_correction_control"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":[["Responsible Officer"],["budget delegation"]],"normative_expected":true,"separable_framing_spans":null,"source_sha256":"19c102415a0bc9f1febf297ce4d075031d15dcd92f13110b71966b1f4690b2d9","source_text":"For the purposes of this part, 'Responsible Officer' means the person holding the budget delegation for the unit.","specimen_id":"CSEM-049","threshold_markers":null},{"acceptable_unit_types":["advisory"],"arm_role":"positive_sentinel","candidate_span_bounds":["Managers are encouraged to discuss workload allocation with their teams before each planning cycle."],"carried_from_commit":null,"carried_from_corpus":null,"category":"explicit_advisory","characterization_notes":"Genuine recommendation with no modal verb. The 005 correction must not suppress advisory material while suppressing institutional description.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["positive_sentinel","advisory","over_correction_control"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":[["workload allocation"],["before each planning cycle"]],"normative_expected":true,"separable_framing_spans":null,"source_sha256":"ffa4b1dc1b54f4183fd69866c1c086660b385d4d30e3b8c491632844fd2a0e3a","source_text":"Managers are encouraged to discuss workload allocation with their teams before each planning cycle.","specimen_id":"CSEM-050","threshold_markers":null},{"acceptable_unit_types":["delegation","permission","power","discretion"],"arm_role":"positive_sentinel","candidate_span_bounds":["The Head of Service may authorise a Deputy to sign purchase agreements up to the unit limit."],"carried_from_commit":null,"carried_from_corpus":null,"category":"delegation_constitutive","characterization_notes":"Constitutive delegation conferring an authority, not describing one.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["positive_sentinel","delegation","over_correction_control"],"expected_candidate_count_max":null,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":[["a Deputy"],["up to the unit limit"]],"normative_expected":true,"separable_framing_spans":null,"source_sha256":"d6e0a8486712d7261e0046f0c71519ae45a7e2333d7806141a5d0ea466e647a9","source_text":"The Head of Service may authorise a Deputy to sign purchase agreements up to the unit limit.","specimen_id":"CSEM-051","threshold_markers":null},{"acceptable_unit_types":["escalation","temporal_trigger","mandate","obligation","condition"],"arm_role":"positive_sentinel","candidate_span_bounds":["A dispute that is unresolved after fifteen working days is referred to the Head of Service."],"carried_from_commit":null,"carried_from_corpus":null,"category":"mixed_description_then_norm","characterization_notes":"The discriminating specimen. Descriptive institutional prose immediately followed by a real norm. Exactly one candidate is expected, and the registered bound covers the normative sentence only, so returning the descriptive lead-in as well reads as overreach.","claim_ceiling":"Synthetic engineering test intent only; no institutional or legal determination.","diagnostic_tags":["positive_sentinel","mixed_fragment","institutional_vocabulary","descriptive_lead_in"],"expected_candidate_count_max":1,"expected_candidate_count_min":1,"families":[],"framing_expected_excluded":null,"framing_structure":null,"material_span_groups":[["fifteen working days"],["Head of Service"]],"normative_expected":true,"separable_framing_spans":null,"source_sha256":"8d93b3460e97007a2ba392bfc0ddc35fc1c5bf6dbd6131f1158d711193e3fa66","source_text":"Part 5 describes the escalation framework and the roles involved. A dispute that is unresolved after fifteen working days is referred to the Head of Service.","specimen_id":"CSEM-052","threshold_markers":null}],"work_order":"OIC-CANDIDATE-SEMANTICS-005"} diff --git a/benchmarks/demo/bounded-semantic-path/PROVIDER-OUTPUT.json b/benchmarks/demo/bounded-semantic-path/PROVIDER-OUTPUT.json new file mode 100644 index 0000000..067167c --- /dev/null +++ b/benchmarks/demo/bounded-semantic-path/PROVIDER-OUTPUT.json @@ -0,0 +1,20 @@ +{ + "format": "SYNTHETIC-REPLAY-001", + "exchanges": [ + { + "request_sha256": "2edb792c1463b75756aba8e66eaf87e01becb6d2c12df705629144cd13b7b153", + "content": "{\"candidates\":[{\"candidate_span\":\"When a request exceeds 100 tokens, the fictional Keeper must send two notices to the fictional Clerk within seven days, except during a declared outage; 'notice' means a written message, subject to section SYN-9.\",\"unit_type\":\"mandate\"}]}", + "model": "synthetic-review-A" + }, + { + "request_sha256": "2edb792c1463b75756aba8e66eaf87e01becb6d2c12df705629144cd13b7b153", + "content": "{\"candidates\":[{\"candidate_span\":\"When a request exceeds 100 tokens, the fictional Keeper must send two notices to the fictional Clerk within seven days, except during a declared outage; 'notice' means a written message, subject to section SYN-9.\",\"unit_type\":\"advisory\"}]}", + "model": "synthetic-review-B" + }, + { + "request_sha256": "3d6b3ccddc6993a78115a9fc01f357b53d94bff34f85262fceebcdcd8f195ce6", + "content": "{\"proposed_assertions\":[{\"proposed_source_quote\":\"must\",\"proposed_value\":\"OBLIGATION\",\"slot\":\"normative_force\"},{\"proposed_source_quote\":\"fictional Keeper\",\"proposed_value\":\"fictional Keeper\",\"slot\":\"bearer\"},{\"proposed_source_quote\":\"send\",\"proposed_value\":\"send\",\"slot\":\"action\"},{\"proposed_source_quote\":\"notices\",\"proposed_value\":\"notices\",\"slot\":\"object\"},{\"proposed_source_quote\":\"fictional Clerk\",\"proposed_value\":\"fictional Clerk\",\"slot\":\"counterparty\"},{\"proposed_source_quote\":\"When a request exceeds 100 tokens\",\"proposed_value\":\"When a request exceeds 100 tokens\",\"slot\":\"condition\"},{\"proposed_source_quote\":\"except during a declared outage\",\"proposed_value\":\"except during a declared outage\",\"slot\":\"exception\"},{\"proposed_source_quote\":\"within seven days\",\"proposed_value\":\"within seven days\",\"slot\":\"temporal_qualifier\"},{\"proposed_source_quote\":\"two\",\"proposed_value\":\"two\",\"slot\":\"quantum\"},{\"proposed_source_quote\":\"'notice'\",\"proposed_value\":\"notice\",\"slot\":\"definiendum\"},{\"proposed_source_quote\":\"a written message\",\"proposed_value\":\"a written message\",\"slot\":\"definiens\"}],\"proposed_unresolved_references\":[{\"reference_kind\":\"INTERNAL_PROVISION\",\"reference_text\":\"section SYN-9\"}]}", + "model": "synthetic-proposal" + } + ] +} diff --git a/benchmarks/demo/bounded-semantic-path/SOURCE.txt b/benchmarks/demo/bounded-semantic-path/SOURCE.txt new file mode 100644 index 0000000..b7b8483 --- /dev/null +++ b/benchmarks/demo/bounded-semantic-path/SOURCE.txt @@ -0,0 +1,2 @@ +SYNTHETIC FICTIONAL FIXTURE. No real institution, rights, or authority is represented. +When a request exceeds 100 tokens, the fictional Keeper must send two notices to the fictional Clerk within seven days, except during a declared outage; 'notice' means a written message, subject to section SYN-9. diff --git a/design/admission-boundary-001/ADMISSION-CONTRACT-v0.1.md b/design/admission-boundary-001/ADMISSION-CONTRACT-v0.1.md new file mode 100644 index 0000000..1128bdb --- /dev/null +++ b/design/admission-boundary-001/ADMISSION-CONTRACT-v0.1.md @@ -0,0 +1,125 @@ +# Admission Contract v0.1 + +## Normative design statement + +The admission boundary consumes one frozen Candidate Normative Unit containing +`unit_id`, literal `candidate_span`, provisional `unit_type`, `source_anchors`, +`interpretation_state`, and `epistemic_state`. It returns one immutable admission +receipt. It does not modify the candidate. + +Admission means **eligible for Institutional IR interpretation**. It is neither a +finding that the candidate is correctly interpreted nor permission to execute any +action. + +## Seam ownership + +| Responsibility | Owner | May not do | +| --- | --- | --- | +| Define admission policy, delegate admission warrants, and resolve conflicts | Institutional Admission Authority | Delegate authority to a model merely because it extracted a candidate | +| Register source identities, versions, digests, standing, scope, and lifecycle evidence | Institution-controlled Authority Registry and evidence custodian | Infer authority from wording, popularity, or provenance alone | +| Evaluate frozen rules and emit deterministic receipts | Future Admission Boundary Evaluator | Invent, extend, or repair evidence; resolve discretionary conflicts | +| Propose `candidate_span` and provisional `unit_type` | Candidate-discovery model | Issue authority evidence, approve admission, select an overriding warrant, or write admitted institutional meaning | +| Interpret an admitted proposition | Future Institutional IR construction stage | Treat admission as canonical meaning or runtime authorization | + +Automatic evaluation may yield `ADMITTED` only when the registry supplies an +active, unambiguous, machine-verifiable `admission_warrant` whose delegation covers +the exact source identity, version, digest, scope, and evaluation time. A human or +institutional governance act is required to create or broaden a warrant, resolve +overlapping or contradictory authority, override a fail-closed result, or decide a +case whose evidence is not machine-verifiable. Any such act becomes new authority +evidence; it is not an evaluator exception. + +## Minimum sufficient authority-evidence model + +The draft `AUTHORITY-EVIDENCE-v0.1.schema.json` requires only fields necessary to +answer a frozen admission question: + +* `evidence_id`, `evidence_digest`, and `issued_at` identify and bind the evidence + projection used by the receipt. +* `source_id`, `source_version`, and `source_digest` bind evidence to the exact + registered source instance rather than similar text. +* `issuer_id` and `authority_basis_ref` identify who asserts standing and the + institution-controlled basis for that assertion. +* `jurisdiction`, `applicability_scope`, and `source_standing` describe the warrant's + bounded reach without interpreting the candidate's semantics. +* `adopted_at`, `effective_from`, and optional `effective_until`, `superseded_at`, + and `revoked_at` make lifecycle status evaluable at an explicit time. Publication + time is deliberately not a substitute for effectiveness. +* `admission_warrant` identifies the Admission Authority's delegation, its exact + source binding, scope, validity interval, and status. + +Cryptographic signature mechanics and a global authority-ranking ontology are not +silently invented here. `evidence_digest` is a content-integrity binding, not proof +that the issuer was entitled to issue the evidence. Issuer authentication and +authority-basis verification are prerequisites supplied by the institution's +trusted registry. The design fails closed if either is unavailable or disputed. + +Provenance and authority remain different: **provenance answers where this came +from; authority answers why the institution is entitled to treat it as operative +meaning.** A perfect provenance chain is not an authority warrant. + +## Authority conservation + +> A candidate cannot acquire greater institutional standing through extraction or +> admission than is established by its supporting authority evidence. + +Consequently, authority never arises from model output, candidate type, semantic +similarity, repeated extraction, source popularity, or provenance alone. The +evaluator cannot strengthen `source_standing`, expand scope, extend effective time, +or prefer one authority based on its language. + +## Deterministic input and receipt projection + +An admission evaluation input consists of: + +1. the immutable Candidate Normative Unit projection; +2. registered source metadata for its anchored source instance; +3. zero or more canonical authority-evidence projections; +4. explicit `evaluation_time` in UTC; +5. requested `evaluation_scope`; +6. evaluator identifier/version and admission-ruleset identifier/digest. + +Objects are canonicalized as UTF-8 JSON using lexicographically sorted object keys, +no insignificant whitespace, and array order as recorded. Timestamps are normalized +to RFC 3339 UTC with `Z`. The input digest is SHA-256 over that full canonical input. +The evidence digest is SHA-256 over the ordered canonical evidence array. + +The receipt projection contains exactly the fields required by +`ADMISSION-RECEIPT-v0.1.schema.json`. `admission_receipt_id` is +`admrec-sha256:`, where `` is SHA-256 over the canonical receipt projection +with `admission_receipt_id` omitted. The explicit `evaluation_time` therefore enters +both input and receipt identity. No hidden wall clock, retrieval time, random value, +or model output may affect the result. + +Identical canonical inputs under the same evaluator version, ruleset digest, and +evaluation time must yield the identical state, reason code, digests, and receipt +identifier. Re-evaluation at a later time creates a new receipt. An earlier receipt +is never mutated when later revocation or supersession evidence arrives. + +## Successor interface + +Only `ADMITTED` may cross into Institutional IR construction. The minimum successor +bundle is: + +* the unchanged admitted Candidate Normative Unit; +* the admission receipt or immutable receipt reference; +* the candidate's source anchors; and +* the authority-evidence references and digests necessary for reconstruction. + +No other admission state is a denial of the underlying proposition. It means only +that eligibility for interpretation was not established for this evaluation. +Institutional IR will represent canonical institutional meaning. A later OCE/runtime +stage may compute consequences; OAM/ZTL may constrain operational authority; and +VEIP may record or verify execution consequences. None is designed or implemented +here. + +## Claim ceiling + +This contract is preregistered design evidence. It does not establish legal +validity, universal authority semantics, production readiness, runtime safety, +compliance, successful IR compilation, execution authorization, or independent +validation. + +`independent_validation_claim = FALSE` + +`NOT SELF-ADJUDICATED` diff --git a/design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json b/design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json new file mode 100644 index 0000000..e5d4244 --- /dev/null +++ b/design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json @@ -0,0 +1,323 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://openinstitutionalcompiler.org/design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json", + "title": "Admission Boundary 001 Executable Input", + "description": "Exact design-only input object for a future deterministic admission evaluator. This schema implements no evaluator and confers no authority.", + "type": "object", + "additionalProperties": false, + "required": [ + "candidate", + "source_registration", + "authority_evidence", + "evaluation_time", + "evaluation_scope", + "evaluator", + "ruleset" + ], + "properties": { + "candidate": { + "$ref": "#/$defs/candidate_projection" + }, + "source_registration": { + "$ref": "#/$defs/source_registration" + }, + "authority_evidence": { + "type": "array", + "description": "Stored in ascending (evidence_id, evidence_digest) order. Empty is explicit missing evidence; no default warrant exists.", + "items": { + "$ref": "https://openinstitutionalcompiler.org/design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json" + } + }, + "evaluation_time": { + "$ref": "#/$defs/timestamp" + }, + "evaluation_scope": { + "type": "object", + "additionalProperties": false, + "required": [ + "jurisdiction", + "applicability" + ], + "properties": { + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability": { + "type": "string", + "minLength": 1 + } + } + }, + "evaluator": { + "type": "object", + "additionalProperties": false, + "required": [ + "evaluator_id", + "evaluator_version" + ], + "properties": { + "evaluator_id": { + "const": "oic-admission-reference-evaluator" + }, + "evaluator_version": { + "const": "0.1-preregistered" + } + } + }, + "ruleset": { + "type": "object", + "additionalProperties": false, + "required": [ + "ruleset_id", + "ruleset_digest" + ], + "properties": { + "ruleset_id": { + "const": "OIC-ADMISSION-BOUNDARY-001" + }, + "ruleset_digest": { + "$ref": "#/$defs/sha256" + } + } + } + }, + "$defs": { + "sha256": { + "type": "string", + "pattern": "^sha256:[0-9a-f]{64}$" + }, + "timestamp": { + "type": "string", + "format": "date-time", + "pattern": "Z$" + }, + "nullable_timestamp": { + "oneOf": [ + { + "$ref": "#/$defs/timestamp" + }, + { + "type": "null" + } + ] + }, + "source_anchor_projection": { + "type": "object", + "additionalProperties": false, + "required": [ + "anchor_id", + "source_id", + "node_id", + "quote", + "page", + "bbox", + "content_hash" + ], + "properties": { + "anchor_id": { + "type": "string", + "minLength": 1 + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "node_id": { + "type": "string", + "minLength": 1 + }, + "quote": { + "type": "string", + "minLength": 1 + }, + "page": { + "type": [ + "integer", + "null" + ] + }, + "bbox": { + "oneOf": [ + { + "type": "array", + "items": { + "type": "number" + } + }, + { + "type": "null" + } + ] + }, + "content_hash": { + "$ref": "#/$defs/sha256" + } + } + }, + "candidate_projection": { + "type": "object", + "description": "Untrusted serialized Candidate Normative Unit projection. source_anchors permits zero items so CANDIDATE_INPUT_INVALID remains representable as a schema-valid boundary input.", + "additionalProperties": false, + "required": [ + "unit_id", + "candidate_span", + "unit_type", + "interpretation_state", + "epistemic_state", + "source_anchors" + ], + "properties": { + "unit_id": { + "type": "string", + "pattern": "^cnu-[0-9a-f]{24}$" + }, + "candidate_span": { + "type": "string", + "minLength": 1 + }, + "unit_type": { + "description": "Provisional model-proposed type. It is never an authority-bearing field.", + "enum": [ + "definition", + "mandate", + "delegation", + "obligation", + "prohibition", + "permission", + "power", + "condition", + "exception", + "evidence_duty", + "review_duty", + "escalation", + "remedy", + "temporal_trigger", + "discretion", + "advisory" + ] + }, + "interpretation_state": { + "const": "extracted" + }, + "epistemic_state": { + "const": "uncertain" + }, + "source_anchors": { + "type": "array", + "items": { + "$ref": "#/$defs/source_anchor_projection" + } + } + } + }, + "source_registration": { + "type": "object", + "description": "Institution-controlled source and registry observation consumed at the authenticated registry seam; the JSON value does not itself authenticate the seam.", + "additionalProperties": false, + "required": [ + "source_id", + "source_version", + "source_digest", + "registered", + "registry_observation", + "source_standing", + "jurisdiction", + "applicability_scope", + "adopted_at", + "published_at", + "effective_from", + "effective_until", + "superseded_at", + "revoked_at" + ], + "properties": { + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "registered": { + "type": "boolean" + }, + "registry_observation": { + "type": "object", + "additionalProperties": false, + "required": [ + "registry_boundary_id", + "observation_id", + "availability", + "freshness" + ], + "properties": { + "registry_boundary_id": { + "const": "institution-controlled-authority-registry" + }, + "observation_id": { + "type": "string", + "minLength": 1 + }, + "availability": { + "enum": [ + "AVAILABLE", + "UNAVAILABLE" + ] + }, + "freshness": { + "enum": [ + "FRESH", + "STALE", + "NOT_OBSERVED" + ] + } + } + }, + "source_standing": { + "enum": [ + "ADOPTED", + "DRAFT", + "COMMENTARY", + "UNKNOWN" + ] + }, + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability_scope": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "adopted_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "published_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "effective_from": { + "$ref": "#/$defs/timestamp" + }, + "effective_until": { + "$ref": "#/$defs/nullable_timestamp" + }, + "superseded_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "revoked_at": { + "$ref": "#/$defs/nullable_timestamp" + } + } + } + } +} diff --git a/design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json b/design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json new file mode 100644 index 0000000..c1cd236 --- /dev/null +++ b/design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json @@ -0,0 +1,184 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://openinstitutionalcompiler.org/design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json", + "title": "Admission Boundary 001 Receipt (design draft)", + "description": "Design-only immutable deterministic admission outcome; not an implemented runtime schema.", + "type": "object", + "additionalProperties": false, + "required": [ + "admission_receipt_id", + "candidate_unit_id", + "candidate_projection_digest", + "source_id", + "source_version", + "source_digest", + "authority_evidence_refs", + "authority_evidence_digests", + "evaluation_time", + "evaluation_scope", + "admission_state", + "reason_code", + "evaluator_id", + "evaluator_version", + "ruleset_id", + "ruleset_digest", + "input_digest", + "evidence_digest" + ], + "properties": { + "admission_receipt_id": { + "type": "string", + "pattern": "^admrec-sha256:[0-9a-f]{64}$" + }, + "candidate_unit_id": { + "type": "string", + "minLength": 1 + }, + "candidate_projection_digest": { + "$ref": "#/$defs/sha256" + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "authority_evidence_refs": { + "type": "array", + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "authority_evidence_digests": { + "type": "array", + "uniqueItems": true, + "items": { + "$ref": "#/$defs/sha256" + } + }, + "evaluation_time": { + "$ref": "#/$defs/timestamp" + }, + "evaluation_scope": { + "type": "object", + "additionalProperties": false, + "required": [ + "jurisdiction", + "applicability" + ], + "properties": { + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability": { + "type": "string", + "minLength": 1 + } + } + }, + "admission_state": { + "enum": [ + "ADMITTED", + "CANDIDATE_INPUT_INVALID", + "SOURCE_NOT_REGISTERED", + "SOURCE_VERSION_MISMATCH", + "SOURCE_DIGEST_MISMATCH", + "MISSING_AUTHORITY_EVIDENCE", + "NOT_YET_EFFECTIVE", + "EXPIRED", + "SUPERSEDED", + "REVOKED", + "OUT_OF_SCOPE", + "CONFLICTING_AUTHORITY", + "AUTHORITY_REGISTRY_UNAVAILABLE", + "AUTHORITY_EVIDENCE_STALE", + "ADMISSION_NOT_ESTABLISHED" + ] + }, + "reason_code": { + "enum": [ + "OIC-ADM-0000", + "OIC-ADM-1001", + "OIC-ADM-1002", + "OIC-ADM-1003", + "OIC-ADM-1004", + "OIC-ADM-1005", + "OIC-ADM-1006", + "OIC-ADM-1007", + "OIC-ADM-1008", + "OIC-ADM-1009", + "OIC-ADM-1010", + "OIC-ADM-1011", + "OIC-ADM-1012", + "OIC-ADM-1013", + "OIC-ADM-1099" + ] + }, + "evaluator_id": { + "type": "string", + "minLength": 1 + }, + "evaluator_version": { + "type": "string", + "minLength": 1 + }, + "ruleset_id": { + "const": "OIC-ADMISSION-BOUNDARY-001" + }, + "ruleset_digest": { + "$ref": "#/$defs/sha256" + }, + "input_digest": { + "$ref": "#/$defs/sha256" + }, + "evidence_digest": { + "$ref": "#/$defs/sha256" + } + }, + "allOf": [ + { + "if": { + "properties": { + "admission_state": { + "const": "ADMITTED" + } + }, + "required": [ + "admission_state" + ] + }, + "then": { + "properties": { + "reason_code": { + "const": "OIC-ADM-0000" + }, + "authority_evidence_refs": { + "minItems": 1 + }, + "authority_evidence_digests": { + "minItems": 1 + } + } + } + } + ], + "$defs": { + "sha256": { + "type": "string", + "pattern": "^sha256:[0-9a-f]{64}$" + }, + "timestamp": { + "type": "string", + "format": "date-time", + "pattern": "Z$" + } + } +} diff --git a/design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json b/design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json new file mode 100644 index 0000000..2172a49 --- /dev/null +++ b/design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json @@ -0,0 +1,194 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://openinstitutionalcompiler.org/design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json", + "title": "Admission Boundary 001 Authority Evidence (design draft)", + "description": "Design-only minimum machine-verifiable authority and admission-warrant evidence; not an implemented runtime schema.", + "type": "object", + "additionalProperties": false, + "required": [ + "evidence_id", + "evidence_digest", + "issued_at", + "source_id", + "source_version", + "source_digest", + "issuer_id", + "authority_basis_ref", + "jurisdiction", + "applicability_scope", + "source_standing", + "adopted_at", + "effective_from", + "effective_until", + "superseded_at", + "revoked_at", + "admission_warrant" + ], + "properties": { + "evidence_id": { + "type": "string", + "minLength": 1 + }, + "evidence_digest": { + "$ref": "#/$defs/sha256" + }, + "issued_at": { + "$ref": "#/$defs/timestamp" + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "issuer_id": { + "type": "string", + "minLength": 1 + }, + "authority_basis_ref": { + "type": "string", + "minLength": 1 + }, + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability_scope": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "source_standing": { + "enum": [ + "ADOPTED", + "DRAFT", + "COMMENTARY", + "UNKNOWN" + ] + }, + "adopted_at": { + "oneOf": [ + { + "$ref": "#/$defs/timestamp" + }, + { + "type": "null" + } + ] + }, + "effective_from": { + "$ref": "#/$defs/timestamp" + }, + "effective_until": { + "$ref": "#/$defs/nullable_timestamp" + }, + "superseded_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "revoked_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "admission_warrant": { + "type": "object", + "additionalProperties": false, + "required": [ + "warrant_id", + "admission_authority_id", + "delegation_basis_ref", + "source_id", + "source_version", + "source_digest", + "jurisdiction", + "applicability_scope", + "effective_from", + "effective_until", + "revoked_at", + "status" + ], + "properties": { + "warrant_id": { + "type": "string", + "minLength": 1 + }, + "admission_authority_id": { + "type": "string", + "minLength": 1 + }, + "delegation_basis_ref": { + "type": "string", + "minLength": 1 + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability_scope": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "effective_from": { + "$ref": "#/$defs/timestamp" + }, + "effective_until": { + "$ref": "#/$defs/nullable_timestamp" + }, + "revoked_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "status": { + "enum": [ + "ACTIVE", + "SUSPENDED", + "REVOKED" + ] + } + } + } + }, + "$defs": { + "sha256": { + "type": "string", + "pattern": "^sha256:[0-9a-f]{64}$" + }, + "timestamp": { + "type": "string", + "format": "date-time", + "pattern": "Z$" + }, + "nullable_timestamp": { + "oneOf": [ + { + "$ref": "#/$defs/timestamp" + }, + { + "type": "null" + } + ] + } + } +} diff --git a/design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json b/design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json new file mode 100644 index 0000000..13e985b --- /dev/null +++ b/design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json @@ -0,0 +1,116 @@ +{ + "mapping_id": "OIC-ADMISSION-BOUNDARY-001-STATE-INPUT-MAPPING-v0.1", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "first_terminal_state_wins": true, + "entries": [ + { + "precedence": 1, + "state": "CANDIDATE_INPUT_INVALID", + "reason_code": "OIC-ADM-1001", + "observable_fields": ["candidate.unit_id", "candidate.candidate_span", "candidate.source_anchors"], + "required_observable_facts": "Candidate identity/span is invalid, source_anchors is empty, or an anchor is inconsistent with source_registration." + }, + { + "precedence": 2, + "state": "AUTHORITY_REGISTRY_UNAVAILABLE", + "reason_code": "OIC-ADM-1012", + "observable_fields": ["source_registration.registry_observation.availability"], + "required_observable_facts": "availability equals UNAVAILABLE." + }, + { + "precedence": 3, + "state": "AUTHORITY_EVIDENCE_STALE", + "reason_code": "OIC-ADM-1013", + "observable_fields": ["source_registration.registry_observation.freshness"], + "required_observable_facts": "availability equals AVAILABLE and freshness equals STALE." + }, + { + "precedence": 4, + "state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "observable_fields": ["source_registration.registered"], + "required_observable_facts": "registered equals false." + }, + { + "precedence": 5, + "state": "SOURCE_VERSION_MISMATCH", + "reason_code": "OIC-ADM-1003", + "observable_fields": ["source_registration.source_version", "authority_evidence[].source_version", "authority_evidence[].admission_warrant.source_version"], + "required_observable_facts": "At least one applicable evidence or warrant version differs from source_registration.source_version." + }, + { + "precedence": 6, + "state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "observable_fields": ["candidate.source_anchors[].content_hash", "source_registration.source_digest", "authority_evidence[].source_digest", "authority_evidence[].admission_warrant.source_digest"], + "required_observable_facts": "Any applicable candidate anchor, evidence, or warrant digest differs from source_registration.source_digest." + }, + { + "precedence": 7, + "state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "observable_fields": ["authority_evidence", "authority_evidence[].authority_basis_ref", "authority_evidence[].admission_warrant"], + "required_observable_facts": "authority_evidence is empty or no complete applicable authority basis and admission warrant exists." + }, + { + "precedence": 8, + "state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "observable_fields": ["evaluation_scope", "source_registration.jurisdiction", "source_registration.applicability_scope", "authority_evidence[].jurisdiction", "authority_evidence[].applicability_scope", "authority_evidence[].admission_warrant.jurisdiction", "authority_evidence[].admission_warrant.applicability_scope"], + "required_observable_facts": "The requested jurisdiction or applicability is absent from the source, evidence, or warrant scope." + }, + { + "precedence": 9, + "state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "observable_fields": ["evaluation_time", "source_registration.effective_from", "authority_evidence[].effective_from", "authority_evidence[].admission_warrant.effective_from"], + "required_observable_facts": "evaluation_time precedes any applicable required effective_from." + }, + { + "precedence": 10, + "state": "EXPIRED", + "reason_code": "OIC-ADM-1007", + "observable_fields": ["evaluation_time", "source_registration.effective_until", "authority_evidence[].effective_until", "authority_evidence[].admission_warrant.effective_until"], + "required_observable_facts": "evaluation_time is at or after any applicable non-null effective_until." + }, + { + "precedence": 11, + "state": "SUPERSEDED", + "reason_code": "OIC-ADM-1008", + "observable_fields": ["evaluation_time", "source_registration.superseded_at", "authority_evidence[].superseded_at"], + "required_observable_facts": "evaluation_time is at or after an applicable non-null superseded_at." + }, + { + "precedence": 12, + "state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "observable_fields": ["evaluation_time", "source_registration.revoked_at", "authority_evidence[].revoked_at", "authority_evidence[].admission_warrant.revoked_at", "authority_evidence[].admission_warrant.status"], + "required_observable_facts": "Applicable source/evidence/warrant is REVOKED or evaluation_time is at or after a non-null revoked_at." + }, + { + "precedence": 13, + "state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "observable_fields": ["authority_evidence[].evidence_id", "authority_evidence[].authority_basis_ref", "authority_evidence[].admission_warrant.warrant_id", "ruleset.ruleset_digest"], + "required_observable_facts": "Two or more applicable evidence objects conflict and the frozen ruleset contains no unique institutional precedence resolution." + }, + { + "precedence": 14, + "state": "ADMISSION_NOT_ESTABLISHED", + "reason_code": "OIC-ADM-1099", + "observable_fields": ["authority_evidence[].source_standing", "authority_evidence[].admission_warrant.status"], + "required_observable_facts": "An otherwise unclassified disputed or suspended authority condition prevents a positive finding and no earlier specific state applies." + }, + { + "precedence": 15, + "state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "observable_fields": ["candidate", "source_registration", "authority_evidence", "evaluation_time", "evaluation_scope", "evaluator", "ruleset"], + "required_observable_facts": "All prior checks pass and at least one complete active evidence object and exact admission warrant establish the requested scope and time." + } + ], + "runtime_permission_states": [], + "successor_ir_state": "ADMITTED", + "independent_validation_claim": false, + "self_adjudication": "NOT SELF-ADJUDICATED" +} diff --git a/design/admission-boundary-001/TEST-VECTORS-FREEZE-v0.2.json b/design/admission-boundary-001/TEST-VECTORS-FREEZE-v0.2.json new file mode 100644 index 0000000..327b43b --- /dev/null +++ b/design/admission-boundary-001/TEST-VECTORS-FREEZE-v0.2.json @@ -0,0 +1,46 @@ +{ + "freeze_id": "OIC-ADMISSION-BOUNDARY-001-EXECUTABLE-TEST-VECTORS-FREEZE-v0.2", + "freeze_state": "FROZEN BEFORE ADMISSION RUNTIME IMPLEMENTATION", + "starting_design_sha": "e445c25a4f657c59fbfe32617f46153ac678150c", + "historical_v0_1": { + "corpus_sha256": "2181cada7cda18a0bde77db89a7eaf701ad044253c3e179024ac7f51d50bc8e7", + "freeze_sha256": "566b5ad56a4c24c51b4547de0aed394bf31f59f7248a1c99596e85e116deef12", + "preserved_vectors": 30 + }, + "executable_corpus": { + "path": "design/admission-boundary-001/TEST-VECTORS-v0.2.json", + "sha256": "969ddf9a853155ce6ed27f30f1c41e76f7a1ff37a42071d2141d9966907add81", + "bytes": 209358, + "legacy_vectors": 30, + "precedence_diagnostics": 8, + "total_vectors": 38 + }, + "crosswalk": { + "path": "design/admission-boundary-001/VECTOR-CROSSWALK-v0.1.json", + "sha256": "1b5dbf0fc25ccb9bbd14fbbb8092bd1e4a61008509b29370ad25c4d07008afbd", + "entries": 30 + }, + "schemas": { + "admission_input": "design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json", + "admission_input_sha256": "bfa5fc3c755bfbc472d2be74fede06173d5ac4db029986da0c4a07b9b5759d3e", + "authority_evidence_disposition": "PRESERVED BYTE-IDENTICAL AND DESIGNATED EXECUTABLE", + "authority_evidence_sha256": "f1d91532a1a50be1f5d969ce8134bdb445f4a62fee0e62565437c2c4be196c98", + "receipt": "design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json", + "receipt_sha256": "c70782201912231491e06239611bbd542dcdbb91da061a4ed9403111dc4ef40e" + }, + "state_mapping": { + "path": "design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json", + "file_sha256": "9ed244f0a4a7f892943720f13b30b672968bfa5e20f584ca03c3195fe69e421c", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "terminal_states": 15, + "first_terminal_state_wins": true + }, + "canonicalization_id": "OIC-ADMISSION-CANONICAL-JSON-v0.1", + "canonicalization_contract_sha256": "110d6f6612f356bb002d0b49b0ca8b93abf0d2ea4e84f66efe233099132f02d1", + "evidence_order": "ascending tuple (evidence_id, evidence_digest)", + "mutation_rule": "Any change requires an explicitly authorized successor corpus and preserved v0.1/v0.2 records; do not edit expected results after observing an implementation.", + "runtime_implementation": false, + "institutional_ir_implementation": false, + "independent_validation_claim": false, + "self_adjudication": "NOT SELF-ADJUDICATED" +} diff --git a/design/admission-boundary-001/TEST-VECTORS-v0.2.json b/design/admission-boundary-001/TEST-VECTORS-v0.2.json new file mode 100644 index 0000000..4b1a0d7 --- /dev/null +++ b/design/admission-boundary-001/TEST-VECTORS-v0.2.json @@ -0,0 +1,4850 @@ +{ + "corpus_id": "OIC-ADMISSION-BOUNDARY-001-EXECUTABLE-TEST-VECTORS-v0.2", + "design_only": true, + "historical_predecessor": { + "path": "design/admission-boundary-001/TEST-VECTORS-v0.1.json", + "sha256": "2181cada7cda18a0bde77db89a7eaf701ad044253c3e179024ac7f51d50bc8e7", + "preserved_vectors": 30 + }, + "input_schema": "design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json", + "authority_evidence_schema": "design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json", + "receipt_schema": "design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json", + "state_mapping": "design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json", + "canonicalization_id": "OIC-ADMISSION-CANONICAL-JSON-v0.1", + "legacy_vector_count": 30, + "precedence_diagnostic_count": 8, + "vector_count": 38, + "vectors": [ + { + "vector_id": "ADM-001", + "legacy_vector_id": "ADM-001", + "origin": "v0.1_historical_scenario", + "title": "adopted registered policy with exact active warrant", + "threat_tags": [ + "positive", + "automatic_machine_verifiable_warrant" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-8a12ea6e0e6f62709b4df900", + "candidate_span": "Records must be retained for seven years.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-001-01", + "source_id": "policy-001", + "node_id": "scenario:ADM-001:1", + "quote": "Records must be retained for seven years.", + "page": null, + "bbox": null, + "content_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111" + } + ] + }, + "source_registration": { + "source_id": "policy-001", + "source_version": "v3", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111111", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-001", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "records" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-001", + "evidence_digest": "sha256:98507f6b18a8eefb630e2edda5e2dffdeccde655e3812a2a162c431801a467a6", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-001", + "source_version": "v3", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111111", + "issuer_id": "synthetic-fixture-issuer-adm-001-01", + "authority_basis_ref": "charter:records", + "jurisdiction": "enterprise", + "applicability_scope": [ + "records" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-001", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-001-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-001", + "source_id": "policy-001", + "source_version": "v3", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111111", + "jurisdiction": "enterprise", + "applicability_scope": [ + "records" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "records" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:b3aaaaa33a3a660b0a6de3d744530c080ab58f447558ed9e7ea723058c01bbd6", + "candidate_unit_id": "cnu-8a12ea6e0e6f62709b4df900", + "candidate_projection_digest": "sha256:f401a271096bafe9d0bbcb4a8fdf29dfffc2903928d67f3d7afd9b17a38d4df9", + "source_id": "policy-001", + "source_version": "v3", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111111", + "authority_evidence_refs": [ + "AE-001" + ], + "authority_evidence_digests": [ + "sha256:98507f6b18a8eefb630e2edda5e2dffdeccde655e3812a2a162c431801a467a6" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "records" + }, + "admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:ddd2f3031c3ca4ef5b2b364fb587c63164721ceb59d5c593c16bd890f97398b2", + "evidence_digest": "sha256:edefcfb3648e2c181af70df7336e4fe608cfa885e7a266cecc9a609e1ef798cc" + }, + "falsifier": "Any non-ADMITTED result with the exact authenticated active evidence, or admission for broader scope than the warrant.", + "claim_ceiling": "Eligibility for Institutional IR interpretation only; no legal validity or execution authorization." + }, + { + "vector_id": "ADM-002", + "legacy_vector_id": "ADM-002", + "origin": "v0.1_historical_scenario", + "title": "explicit institutionally approved one-source warrant", + "threat_tags": [ + "positive", + "explicit_institutional_approval" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-fd8b784440cbda7021f337ef", + "candidate_span": "The committee consists of five members.", + "unit_type": "definition", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-002-01", + "source_id": "decision-002", + "node_id": "scenario:ADM-002:1", + "quote": "The committee consists of five members.", + "page": null, + "bbox": null, + "content_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222222" + } + ] + }, + "source_registration": { + "source_id": "decision-002", + "source_version": "1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222222", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-002", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "board", + "applicability_scope": [ + "committee" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-002", + "evidence_digest": "sha256:316bc90a6da7a76713709c4e2ab16330b562b3ecca029d09326258a0f2bb84cc", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "decision-002", + "source_version": "1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222222", + "issuer_id": "synthetic-fixture-issuer-adm-002-01", + "authority_basis_ref": "board-resolution:88", + "jurisdiction": "board", + "applicability_scope": [ + "committee" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-02-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-002-HUMAN-APPROVED", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-002-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-002-HUMAN-APPROVED", + "source_id": "decision-002", + "source_version": "1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222222", + "jurisdiction": "board", + "applicability_scope": [ + "committee" + ], + "effective_from": "2026-02-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "board", + "applicability": "committee" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:3af344dfbc42490aebe28eeeaaadc6b044dfd9896c631200dd9df10a04a46f48", + "candidate_unit_id": "cnu-fd8b784440cbda7021f337ef", + "candidate_projection_digest": "sha256:fb472e8d6ab1180f5afb78c7e136a74990c2736cbf552fd17f1542c400e674ad", + "source_id": "decision-002", + "source_version": "1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222222", + "authority_evidence_refs": [ + "AE-002" + ], + "authority_evidence_digests": [ + "sha256:316bc90a6da7a76713709c4e2ab16330b562b3ecca029d09326258a0f2bb84cc" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "board", + "applicability": "committee" + }, + "admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:3f8783700925bb74bc7f936ac638d5c825bd5aa03d9550adc575d9d35ff238ee", + "evidence_digest": "sha256:a2e2efb818f53e8de1e7be605510ceedbd5997d37eb6fd79e9725c68a2657458" + }, + "falsifier": "The evaluator ignores or expands the institutionally approved warrant.", + "claim_ceiling": "Eligibility for Institutional IR interpretation only; no legal validity or execution authorization." + }, + { + "vector_id": "ADM-003", + "legacy_vector_id": "ADM-003", + "origin": "v0.1_historical_scenario", + "title": "authoritative-looking fake memo", + "threat_tags": [ + "authoritative_looking_fake_memo" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-f91f71301bd4c1824658b86d", + "candidate_span": "All requests require executive approval.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-003-01", + "source_id": "fake-memo", + "node_id": "scenario:ADM-003:1", + "quote": "All requests require executive approval.", + "page": null, + "bbox": null, + "content_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333" + } + ] + }, + "source_registration": { + "source_id": "fake-memo", + "source_version": "1", + "source_digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333", + "registered": false, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-003", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "UNKNOWN", + "jurisdiction": "enterprise", + "applicability_scope": [ + "requests" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "requests" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:e491a39616ae526b324641f32c3db1ec0cf5a20b6d4a81d181ae5735b7061831", + "candidate_unit_id": "cnu-f91f71301bd4c1824658b86d", + "candidate_projection_digest": "sha256:93c3cb6c5e3ed57f9fc390fefd97530c698b559f366a22e65c918d9ac715f109", + "source_id": "fake-memo", + "source_version": "1", + "source_digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "requests" + }, + "admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:89585f95eb107108ddd26a52aac1fa24cb814eb667a0936f11da1e963ae2b9da", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "Official style, vocabulary, or model confidence causes admission without registration.", + "claim_ceiling": "Fail-closed design expectation only; not a finding that the text is false." + }, + { + "vector_id": "ADM-004", + "legacy_vector_id": "ADM-004", + "origin": "v0.1_historical_scenario", + "title": "perfectly grounded extraction from an unwarranted draft", + "threat_tags": [ + "perfect_grounding_from_draft" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-96d73091760de6c19cbdc838", + "candidate_span": "Vendors shall submit annual attestations.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-004-01", + "source_id": "draft-policy", + "node_id": "scenario:ADM-004:1", + "quote": "Vendors shall submit annual attestations.", + "page": null, + "bbox": null, + "content_hash": "sha256:4444444444444444444444444444444444444444444444444444444444444444" + } + ] + }, + "source_registration": { + "source_id": "draft-policy", + "source_version": "d4", + "source_digest": "sha256:4444444444444444444444444444444444444444444444444444444444444444", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-004", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "DRAFT", + "jurisdiction": "enterprise", + "applicability_scope": [ + "vendors" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "vendors" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:cbab6d03adce306f836bb7f63fe1b1dce2b8075b2f503c933cf2a40bab523b39", + "candidate_unit_id": "cnu-96d73091760de6c19cbdc838", + "candidate_projection_digest": "sha256:416488ff074448ad1bafc30875e022969690b96781f5ebdc3232d5c26e6cbbeb", + "source_id": "draft-policy", + "source_version": "d4", + "source_digest": "sha256:4444444444444444444444444444444444444444444444444444444444444444", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "vendors" + }, + "admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:3476b17c264f2db36d88d2c7195c9a1819cf21f35790b5050531a7f25bd5be2e", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "Literal grounding or draft registration alone produces ADMITTED.", + "claim_ceiling": "Fail-closed design expectation only; not a judgment on future adoption." + }, + { + "vector_id": "ADM-005", + "legacy_vector_id": "ADM-005", + "origin": "v0.1_historical_scenario", + "title": "valid policy name with forged source metadata", + "threat_tags": [ + "valid_policy_forged_source_metadata" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-fca7b341c7bc5920df6724e1", + "candidate_span": "Accounts are reviewed quarterly.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-005-01", + "source_id": "policy-005", + "node_id": "scenario:ADM-005:1", + "quote": "Accounts are reviewed quarterly.", + "page": null, + "bbox": null, + "content_hash": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" + } + ] + }, + "source_registration": { + "source_id": "policy-005", + "source_version": "v2", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-005", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "accounts" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-005", + "evidence_digest": "sha256:8f42c87c5f7e675d634d23849f90433c918e32fe4f85b9394733b68964f0760f", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-005", + "source_version": "v2", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "issuer_id": "synthetic-fixture-issuer-adm-005-01", + "authority_basis_ref": "charter:security", + "jurisdiction": "enterprise", + "applicability_scope": [ + "accounts" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-005", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-005-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-005", + "source_id": "policy-005", + "source_version": "v2", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "jurisdiction": "enterprise", + "applicability_scope": [ + "accounts" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "accounts" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:f6124bc365f00ab617bd4bba653a22fb2e2880b6f7ba37b6702feb8618458941", + "candidate_unit_id": "cnu-fca7b341c7bc5920df6724e1", + "candidate_projection_digest": "sha256:9e24935961c3ba5df0ce7823a38483df06a58cd47fee22b293e2c65759fa910e", + "source_id": "policy-005", + "source_version": "v2", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "authority_evidence_refs": [ + "AE-005" + ], + "authority_evidence_digests": [ + "sha256:8f42c87c5f7e675d634d23849f90433c918e32fe4f85b9394733b68964f0760f" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "accounts" + }, + "admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:6cb9f4fa2f58a3be165402cd4312ec64638a306eb1ab6a097cf4e1fd1acaaa79", + "evidence_digest": "sha256:e17fa8cd3b4f74a3bbb97bbb88ea71e6635790e479479c476fa4ef7527056664" + }, + "falsifier": "A familiar source identity permits different bytes to inherit its warrant.", + "claim_ceiling": "Integrity-binding expectation only; no claim that SHA-256 authenticates the issuer." + }, + { + "vector_id": "ADM-006", + "legacy_vector_id": "ADM-006", + "origin": "v0.1_historical_scenario", + "title": "valid authority presented for the wrong version", + "threat_tags": [ + "valid_authority_wrong_version" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-1472545d7dd8a4c46b4f10a1", + "candidate_span": "Managers approve exceptions.", + "unit_type": "delegation", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-006-01", + "source_id": "policy-006", + "node_id": "scenario:ADM-006:1", + "quote": "Managers approve exceptions.", + "page": null, + "bbox": null, + "content_hash": "sha256:6666666666666666666666666666666666666666666666666666666666666666" + } + ] + }, + "source_registration": { + "source_id": "policy-006", + "source_version": "v4", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-006", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-006", + "evidence_digest": "sha256:5547cf9fe48cc6782443999619d6ee8dd7a43474bed05a6676478a6f67d1cb7a", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-006", + "source_version": "v3", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "issuer_id": "synthetic-fixture-issuer-adm-006-01", + "authority_basis_ref": "charter:risk", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-006", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-006-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-006", + "source_id": "policy-006", + "source_version": "v3", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_VERSION_MISMATCH", + "reason_code": "OIC-ADM-1003", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:f83f4bfad00c848637c66ac3e57c7e8b6d40164c11ff298e97b75743b65ed271", + "candidate_unit_id": "cnu-1472545d7dd8a4c46b4f10a1", + "candidate_projection_digest": "sha256:3cc9af48cf78c225cc4333f16cabfc02c41ce830387ac1423c11224279a048c5", + "source_id": "policy-006", + "source_version": "v4", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "authority_evidence_refs": [ + "AE-006" + ], + "authority_evidence_digests": [ + "sha256:5547cf9fe48cc6782443999619d6ee8dd7a43474bed05a6676478a6f67d1cb7a" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "admission_state": "SOURCE_VERSION_MISMATCH", + "reason_code": "OIC-ADM-1003", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:e9356b5605295424c98e78836a10dd2f620a469f5fbd1f8d68aa0905dcf4c3bb", + "evidence_digest": "sha256:cb89c892641f58f9215537e02a5c6afc6708340b8f9f1dc9df4c529945fd6557" + }, + "falsifier": "Authority for v3 is silently reused for v4.", + "claim_ceiling": "Exact-version admission expectation only." + }, + { + "vector_id": "ADM-007", + "legacy_vector_id": "ADM-007", + "origin": "v0.1_historical_scenario", + "title": "expired source", + "threat_tags": [ + "expired_source" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-81c04a11dc65432a0e4bf55a", + "candidate_span": "Reports are due monthly.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-007-01", + "source_id": "policy-007", + "node_id": "scenario:ADM-007:1", + "quote": "Reports are due monthly.", + "page": null, + "bbox": null, + "content_hash": "sha256:7777777777777777777777777777777777777777777777777777777777777777" + } + ] + }, + "source_registration": { + "source_id": "policy-007", + "source_version": "v1", + "source_digest": "sha256:7777777777777777777777777777777777777777777777777777777777777777", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-007", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "reporting" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-007", + "evidence_digest": "sha256:3ce49f7e822a79d15a7251d1906da235cdda03d82fc70c00bbc58b4d0f549c7b", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-007", + "source_version": "v1", + "source_digest": "sha256:7777777777777777777777777777777777777777777777777777777777777777", + "issuer_id": "synthetic-fixture-issuer-adm-007-01", + "authority_basis_ref": "charter:reporting", + "jurisdiction": "enterprise", + "applicability_scope": [ + "reporting" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": "2026-01-01T00:00:00Z", + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-007", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-007-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-007", + "source_id": "policy-007", + "source_version": "v1", + "source_digest": "sha256:7777777777777777777777777777777777777777777777777777777777777777", + "jurisdiction": "enterprise", + "applicability_scope": [ + "reporting" + ], + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": "2026-01-01T00:00:00Z", + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "reporting" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "EXPIRED", + "reason_code": "OIC-ADM-1007", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:0496475e711f0570f2428338d6dcf8282a02d9e0eb7ffeac56026fb3f9d33b65", + "candidate_unit_id": "cnu-81c04a11dc65432a0e4bf55a", + "candidate_projection_digest": "sha256:f53fca4fa62590e58051eb6ec6b2d0e4889b326bb49eedb69997b6cad76a5f28", + "source_id": "policy-007", + "source_version": "v1", + "source_digest": "sha256:7777777777777777777777777777777777777777777777777777777777777777", + "authority_evidence_refs": [ + "AE-007" + ], + "authority_evidence_digests": [ + "sha256:3ce49f7e822a79d15a7251d1906da235cdda03d82fc70c00bbc58b4d0f549c7b" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "reporting" + }, + "admission_state": "EXPIRED", + "reason_code": "OIC-ADM-1007", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:61f7276771c35cdb223d7ab9642d4d5a2cf13aea71d2158a6602660d3146faf8", + "evidence_digest": "sha256:c5f90ddfc7151fa69df355944287c87c023ef8474fb91dd9f785d451d5e2807f" + }, + "falsifier": "Past effectiveness is treated as current admission authority.", + "claim_ceiling": "Time-bounded eligibility expectation only." + }, + { + "vector_id": "ADM-008", + "legacy_vector_id": "ADM-008", + "origin": "v0.1_historical_scenario", + "title": "superseded source", + "threat_tags": [ + "superseded_source" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-aa62e0be0eeb214f4981cc69", + "candidate_span": "Two signatures are required.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-008-01", + "source_id": "policy-008", + "node_id": "scenario:ADM-008:1", + "quote": "Two signatures are required.", + "page": null, + "bbox": null, + "content_hash": "sha256:8888888888888888888888888888888888888888888888888888888888888888" + } + ] + }, + "source_registration": { + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-008", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": "2026-03-01T00:00:00Z", + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-008", + "evidence_digest": "sha256:eedfab13d7994ce657a3fca17d2b873efea6ee8e7908f7ab17a5847eb0781ddb", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "issuer_id": "synthetic-fixture-issuer-adm-008-01", + "authority_basis_ref": "charter:approvals", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": "2026-03-01T00:00:00Z", + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-008", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-008-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-008", + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "approvals" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SUPERSEDED", + "reason_code": "OIC-ADM-1008", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:92660a71dc33fc53386fcb13490401e05155cac2090e7026b58a12ba6f352095", + "candidate_unit_id": "cnu-aa62e0be0eeb214f4981cc69", + "candidate_projection_digest": "sha256:569910970af730df63477d90ad8111368e4b09ac625923637f2a143d9c7f08b0", + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "authority_evidence_refs": [ + "AE-008" + ], + "authority_evidence_digests": [ + "sha256:eedfab13d7994ce657a3fca17d2b873efea6ee8e7908f7ab17a5847eb0781ddb" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "approvals" + }, + "admission_state": "SUPERSEDED", + "reason_code": "OIC-ADM-1008", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:90470383c39c91f61295e04e1ce0f66612c812e56f239634b1dab086f87e494d", + "evidence_digest": "sha256:fcc1fc612818c1b9e6347fc33b22b23c2097a748c137daee9a6f1da882c0a64b" + }, + "falsifier": "A superseded source remains eligible without an explicit applicable exception warrant.", + "claim_ceiling": "Lifecycle eligibility expectation only." + }, + { + "vector_id": "ADM-009", + "legacy_vector_id": "ADM-009", + "origin": "v0.1_historical_scenario", + "title": "revoked source", + "threat_tags": [ + "revoked_source" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-f1caa35e8a223ea5f518ce21", + "candidate_span": "Access may be delegated.", + "unit_type": "delegation", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-009-01", + "source_id": "policy-009", + "node_id": "scenario:ADM-009:1", + "quote": "Access may be delegated.", + "page": null, + "bbox": null, + "content_hash": "sha256:9999999999999999999999999999999999999999999999999999999999999999" + } + ] + }, + "source_registration": { + "source_id": "policy-009", + "source_version": "v2", + "source_digest": "sha256:9999999999999999999999999999999999999999999999999999999999999999", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-009", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "access" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": "2026-05-01T00:00:00Z" + }, + "authority_evidence": [ + { + "evidence_id": "AE-009", + "evidence_digest": "sha256:c1fd9f64960747fa2858256811f9b2832ed89e8cac60ace75bcc37f5ff559dfc", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-009", + "source_version": "v2", + "source_digest": "sha256:9999999999999999999999999999999999999999999999999999999999999999", + "issuer_id": "synthetic-fixture-issuer-adm-009-01", + "authority_basis_ref": "charter:access", + "jurisdiction": "enterprise", + "applicability_scope": [ + "access" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-009", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-009-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-009", + "source_id": "policy-009", + "source_version": "v2", + "source_digest": "sha256:9999999999999999999999999999999999999999999999999999999999999999", + "jurisdiction": "enterprise", + "applicability_scope": [ + "access" + ], + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "access" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:450e974bb15cdf187aac4598ccb7d754442215312d4f678d4ca954d134b47933", + "candidate_unit_id": "cnu-f1caa35e8a223ea5f518ce21", + "candidate_projection_digest": "sha256:613ba89e821ca70d10026d6b721f9e1668bcd13a57b50b10e08a8154a6abf95a", + "source_id": "policy-009", + "source_version": "v2", + "source_digest": "sha256:9999999999999999999999999999999999999999999999999999999999999999", + "authority_evidence_refs": [ + "AE-009" + ], + "authority_evidence_digests": [ + "sha256:c1fd9f64960747fa2858256811f9b2832ed89e8cac60ace75bcc37f5ff559dfc" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "access" + }, + "admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:11b2987ee6c9d7961743e813549ee58c9c7c940548e007ad364ae26495ec50f3", + "evidence_digest": "sha256:0495465cb853d27ceccad08a646cb3c68643bbdb51da7d92455a15585d8ef7ea" + }, + "falsifier": "A revoked source remains eligible at or after revocation.", + "claim_ceiling": "Lifecycle eligibility expectation only." + }, + { + "vector_id": "ADM-010", + "legacy_vector_id": "ADM-010", + "origin": "v0.1_historical_scenario", + "title": "valid evidence in the wrong jurisdiction", + "threat_tags": [ + "wrong_department_or_jurisdiction" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-e3ed0ba280e6bbb198050b8e", + "candidate_span": "Investigations require notice.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-010-01", + "source_id": "policy-010", + "node_id": "scenario:ADM-010:1", + "quote": "Investigations require notice.", + "page": null, + "bbox": null, + "content_hash": "sha256:1010101010101010101010101010101010101010101010101010101010101010" + } + ] + }, + "source_registration": { + "source_id": "policy-010", + "source_version": "v1", + "source_digest": "sha256:1010101010101010101010101010101010101010101010101010101010101010", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-010", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "department-a", + "applicability_scope": [ + "investigations" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-010", + "evidence_digest": "sha256:d5c0a469f695ca6e7fe3e4cea291e15c67da8e50cac87bcc1a0275df486eb63e", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-010", + "source_version": "v1", + "source_digest": "sha256:1010101010101010101010101010101010101010101010101010101010101010", + "issuer_id": "synthetic-fixture-issuer-adm-010-01", + "authority_basis_ref": "charter:department-a", + "jurisdiction": "department-a", + "applicability_scope": [ + "investigations" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-010", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-010-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-010", + "source_id": "policy-010", + "source_version": "v1", + "source_digest": "sha256:1010101010101010101010101010101010101010101010101010101010101010", + "jurisdiction": "department-a", + "applicability_scope": [ + "investigations" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "department-b", + "applicability": "investigations" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:32a30b8994e454aa402da1f0bc5cf3d20a7495df3feed5a791ed08623d685c69", + "candidate_unit_id": "cnu-e3ed0ba280e6bbb198050b8e", + "candidate_projection_digest": "sha256:d5f871278f54673581966358b2e05655d032ec5c34714a56952203ae55302d83", + "source_id": "policy-010", + "source_version": "v1", + "source_digest": "sha256:1010101010101010101010101010101010101010101010101010101010101010", + "authority_evidence_refs": [ + "AE-010" + ], + "authority_evidence_digests": [ + "sha256:d5c0a469f695ca6e7fe3e4cea291e15c67da8e50cac87bcc1a0275df486eb63e" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "department-b", + "applicability": "investigations" + }, + "admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:f6c004f061c62ab46c4c2e756c5357855df8782c8bbe33efa5c591d7233bb12c", + "evidence_digest": "sha256:ddc8b0ad2bff9588dc175e504464f01e6e1d052261ebccc2a120fc6d1cdd630e" + }, + "falsifier": "Authority for department-a is expanded to department-b.", + "claim_ceiling": "Scope-bounded eligibility expectation only." + }, + { + "vector_id": "ADM-011", + "legacy_vector_id": "ADM-011", + "origin": "v0.1_historical_scenario", + "title": "policy text copied to an unauthoritative website", + "threat_tags": [ + "copied_policy_unauthoritative_website" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-d8a49f6e8f26694928b56f57", + "candidate_span": "Losses must be reported immediately.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-011-01", + "source_id": "mirror.example/policy", + "node_id": "scenario:ADM-011:1", + "quote": "Losses must be reported immediately.", + "page": null, + "bbox": null, + "content_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111110" + } + ] + }, + "source_registration": { + "source_id": "mirror.example/policy", + "source_version": "copy", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111110", + "registered": false, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-011", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "UNKNOWN", + "jurisdiction": "enterprise", + "applicability_scope": [ + "losses" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-CANONICAL-NOT-COPY", + "evidence_digest": "sha256:48080c2f22ba24a3429eb2731f813f4e5f60e4ae7e3487e87a3bf658a671b3a2", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "mirror.example/policy", + "source_version": "v1", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111110", + "issuer_id": "synthetic-fixture-issuer-adm-011-01", + "authority_basis_ref": "charter:risk", + "jurisdiction": "enterprise", + "applicability_scope": [ + "losses" + ], + "source_standing": "UNKNOWN", + "adopted_at": null, + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-CANONICAL", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-011-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-CANONICAL", + "source_id": "mirror.example/policy", + "source_version": "v1", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111110", + "jurisdiction": "enterprise", + "applicability_scope": [ + "losses" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "losses" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:138d7ad96cff647442966d3c17fcb1a0f77516f0ed46c230ec480c33a7d4d0fd", + "candidate_unit_id": "cnu-d8a49f6e8f26694928b56f57", + "candidate_projection_digest": "sha256:bf4c0bd16e18660fc730a6767693e688bb2aeecd0042332de0a3f7f39ad0ff9b", + "source_id": "mirror.example/policy", + "source_version": "copy", + "source_digest": "sha256:1111111111111111111111111111111111111111111111111111111111111110", + "authority_evidence_refs": [ + "AE-CANONICAL-NOT-COPY" + ], + "authority_evidence_digests": [ + "sha256:48080c2f22ba24a3429eb2731f813f4e5f60e4ae7e3487e87a3bf658a671b3a2" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "losses" + }, + "admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:5af95b1958e4135166b06967cfa524cf4a62b18f075e4898634de4867c584337", + "evidence_digest": "sha256:b0062178e708075e32b5137fb27d11a9971549104335f07dc38d73fc40e27021" + }, + "falsifier": "Identical copied text inherits the canonical source's standing.", + "claim_ceiling": "Source-instance eligibility expectation only." + }, + { + "vector_id": "ADM-012", + "legacy_vector_id": "ADM-012", + "origin": "v0.1_historical_scenario", + "title": "legitimate policy quoted inside commentary", + "threat_tags": [ + "legitimate_policy_quoted_in_commentary" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-eab4598324721e598ee1abaf", + "candidate_span": "The policy states that reviews are annual.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-012-01", + "source_id": "commentary-012", + "node_id": "scenario:ADM-012:1", + "quote": "The policy states that reviews are annual.", + "page": null, + "bbox": null, + "content_hash": "sha256:1212121212121212121212121212121212121212121212121212121212121212" + } + ] + }, + "source_registration": { + "source_id": "commentary-012", + "source_version": "1", + "source_digest": "sha256:1212121212121212121212121212121212121212121212121212121212121212", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-012", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "COMMENTARY", + "jurisdiction": "enterprise", + "applicability_scope": [ + "reviews" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "reviews" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:a1628c131ed00f061494dc8da6318b72c0d74086cb5dc9397eced2d21a9ba219", + "candidate_unit_id": "cnu-eab4598324721e598ee1abaf", + "candidate_projection_digest": "sha256:b9ed7ff238c2cc95794de2b061575eca03a7aaa6e838dfad002e88482917068b", + "source_id": "commentary-012", + "source_version": "1", + "source_digest": "sha256:1212121212121212121212121212121212121212121212121212121212121212", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "reviews" + }, + "admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:5d1dda63c23d55ae443c089521817becfdbbe064cd53489911ed41e976b2b095", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "A quotation in commentary borrows an unbound policy warrant.", + "claim_ceiling": "Authority-binding expectation only; not a semantic judgment on the quotation." + }, + { + "vector_id": "ADM-013", + "legacy_vector_id": "ADM-013", + "origin": "v0.1_historical_scenario", + "title": "model labels descriptive text as mandate", + "threat_tags": [ + "model_labels_descriptive_as_mandate", + "candidate_type_no_authority" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-fa4d5b6371891afddadb18f2", + "candidate_span": "The office opened in 1998.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-013-01", + "source_id": "policy-013", + "node_id": "scenario:ADM-013:1", + "quote": "The office opened in 1998.", + "page": null, + "bbox": null, + "content_hash": "sha256:1313131313131313131313131313131313131313131313131313131313131313" + } + ] + }, + "source_registration": { + "source_id": "policy-013", + "source_version": "v1", + "source_digest": "sha256:1313131313131313131313131313131313131313131313131313131313131313", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-013", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "office" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-013", + "evidence_digest": "sha256:b235fabf14a0a1c084ff462ae8017226997a69d7ed4b0d6bca60b799f962ed69", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-013", + "source_version": "v1", + "source_digest": "sha256:1313131313131313131313131313131313131313131313131313131313131313", + "issuer_id": "synthetic-fixture-issuer-adm-013-01", + "authority_basis_ref": "charter:office", + "jurisdiction": "enterprise", + "applicability_scope": [ + "office" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-013", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-013-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-013", + "source_id": "policy-013", + "source_version": "v1", + "source_digest": "sha256:1313131313131313131313131313131313131313131313131313131313131313", + "jurisdiction": "enterprise", + "applicability_scope": [ + "office" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "office" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:895bcb94e0497414fc3080ef88bbaeb453f7dcf49e5e92afd831c94e4e0a4b3e", + "candidate_unit_id": "cnu-fa4d5b6371891afddadb18f2", + "candidate_projection_digest": "sha256:178428214e4a9c43ad1b0ec884f869be453e814e5ed51ff1f1fa477cfcb648f6", + "source_id": "policy-013", + "source_version": "v1", + "source_digest": "sha256:1313131313131313131313131313131313131313131313131313131313131313", + "authority_evidence_refs": [ + "AE-013" + ], + "authority_evidence_digests": [ + "sha256:b235fabf14a0a1c084ff462ae8017226997a69d7ed4b0d6bca60b799f962ed69" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "office" + }, + "admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:67a25ae2d57d111b4b8b4d5c45fd7d0473902bb0af7eac7e6f5f17cf94af907e", + "evidence_digest": "sha256:729a96cdd2630519d77329e2ccd6813818b13dfcaedda9863e43e23225875d69" + }, + "falsifier": "The provisional mandate label creates extra standing or admission is misreported as semantic correctness.", + "claim_ceiling": "Eligibility only; the likely extraction defect remains for later interpretation/review and is not approved." + }, + { + "vector_id": "ADM-014", + "legacy_vector_id": "ADM-014", + "origin": "v0.1_historical_scenario", + "title": "model labels a valid mandate as advisory", + "threat_tags": [ + "model_labels_valid_mandate_as_advisory", + "candidate_type_no_authority" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-7378c9cc75af61a2a47a7c9a", + "candidate_span": "Employees must disclose conflicts.", + "unit_type": "advisory", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-014-01", + "source_id": "policy-014", + "node_id": "scenario:ADM-014:1", + "quote": "Employees must disclose conflicts.", + "page": null, + "bbox": null, + "content_hash": "sha256:1414141414141414141414141414141414141414141414141414141414141414" + } + ] + }, + "source_registration": { + "source_id": "policy-014", + "source_version": "v1", + "source_digest": "sha256:1414141414141414141414141414141414141414141414141414141414141414", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-014", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "conflicts" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-014", + "evidence_digest": "sha256:8783239c2a6427d098dd0d63f740b029930314d5439f900b52b74f197b3ae40e", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-014", + "source_version": "v1", + "source_digest": "sha256:1414141414141414141414141414141414141414141414141414141414141414", + "issuer_id": "synthetic-fixture-issuer-adm-014-01", + "authority_basis_ref": "charter:ethics", + "jurisdiction": "enterprise", + "applicability_scope": [ + "conflicts" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-014", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-014-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-014", + "source_id": "policy-014", + "source_version": "v1", + "source_digest": "sha256:1414141414141414141414141414141414141414141414141414141414141414", + "jurisdiction": "enterprise", + "applicability_scope": [ + "conflicts" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "conflicts" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:5fd2f1f0e72e1d4a512e611b464f4695528102e767afafc3d43ce4e1f57cb474", + "candidate_unit_id": "cnu-7378c9cc75af61a2a47a7c9a", + "candidate_projection_digest": "sha256:f352603cc3cbcf82976ee53396160088f96babbaf74b0ae464a55985c659984a", + "source_id": "policy-014", + "source_version": "v1", + "source_digest": "sha256:1414141414141414141414141414141414141414141414141414141414141414", + "authority_evidence_refs": [ + "AE-014" + ], + "authority_evidence_digests": [ + "sha256:8783239c2a6427d098dd0d63f740b029930314d5439f900b52b74f197b3ae40e" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "conflicts" + }, + "admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:823d2c5e5bf8cf0446d3b7f1baeb8ae41ba95768a82b957a8759ea9ac1c80439", + "evidence_digest": "sha256:40981777e1192c611e1b8dd5f5a0b04519ef6e099c664220c74413e5e210794a" + }, + "falsifier": "The advisory label removes source authority or admission repairs the model label.", + "claim_ceiling": "Eligibility only; admission neither validates nor repairs provisional unit_type." + }, + { + "vector_id": "ADM-015", + "legacy_vector_id": "ADM-015", + "origin": "v0.1_historical_scenario", + "title": "source digest mismatch after registered retrieval", + "threat_tags": [ + "source_digest_mismatch" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-ff424a0ef9d40bc743e12e71", + "candidate_span": "Incidents shall be logged.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-015-01", + "source_id": "policy-015", + "node_id": "scenario:ADM-015:1", + "quote": "Incidents shall be logged.", + "page": null, + "bbox": null, + "content_hash": "sha256:1515151515151515151515151515151515151515151515151515151515151515" + } + ] + }, + "source_registration": { + "source_id": "policy-015", + "source_version": "v1", + "source_digest": "sha256:1515151515151515151515151515151515151515151515151515151515151516", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-015", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "incidents" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-015", + "evidence_digest": "sha256:cf3d855610e24b5333a88729c23e7fcefa3e0eeef7dc120ef12da23d68798fd8", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-015", + "source_version": "v1", + "source_digest": "sha256:1515151515151515151515151515151515151515151515151515151515151516", + "issuer_id": "synthetic-fixture-issuer-adm-015-01", + "authority_basis_ref": "charter:security", + "jurisdiction": "enterprise", + "applicability_scope": [ + "incidents" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-015", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-015-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-015", + "source_id": "policy-015", + "source_version": "v1", + "source_digest": "sha256:1515151515151515151515151515151515151515151515151515151515151516", + "jurisdiction": "enterprise", + "applicability_scope": [ + "incidents" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "incidents" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:bfceba2a096266ac2dff8bfbd956e7342f7ccf6b833f8628115a66ee5055aa5f", + "candidate_unit_id": "cnu-ff424a0ef9d40bc743e12e71", + "candidate_projection_digest": "sha256:45c52462abddf7f4c25f6b7d45c9979ce3fdabae486ea5607a11036231a6e6b7", + "source_id": "policy-015", + "source_version": "v1", + "source_digest": "sha256:1515151515151515151515151515151515151515151515151515151515151516", + "authority_evidence_refs": [ + "AE-015" + ], + "authority_evidence_digests": [ + "sha256:cf3d855610e24b5333a88729c23e7fcefa3e0eeef7dc120ef12da23d68798fd8" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "incidents" + }, + "admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:8cadf3343f45ff8a0a0ffa1eae4c39190f83edaeea5ef3b7cfbaa9ae6ca8d992", + "evidence_digest": "sha256:9485f3b10f2b738c0676de42d02bc6a7705af1448864d484a4532db768e819f0" + }, + "falsifier": "Digest mismatch is ignored because identity and version match.", + "claim_ceiling": "Integrity-binding expectation only." + }, + { + "vector_id": "ADM-016", + "legacy_vector_id": "ADM-016", + "origin": "v0.1_historical_scenario", + "title": "authority registry unavailable", + "threat_tags": [ + "authority_registry_unavailable" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-2cc472c7cbcc8bb6a5fe6b8c", + "candidate_span": "Backups are tested annually.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-016-01", + "source_id": "policy-016", + "node_id": "scenario:ADM-016:1", + "quote": "Backups are tested annually.", + "page": null, + "bbox": null, + "content_hash": "sha256:1616161616161616161616161616161616161616161616161616161616161616" + } + ] + }, + "source_registration": { + "source_id": "policy-016", + "source_version": "v1", + "source_digest": "sha256:1616161616161616161616161616161616161616161616161616161616161616", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-016", + "availability": "UNAVAILABLE", + "freshness": "NOT_OBSERVED" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "backups" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "backups" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "AUTHORITY_REGISTRY_UNAVAILABLE", + "reason_code": "OIC-ADM-1012", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:e5e5a022ad913a9f327d5a2b4616f96e1f92ca3ea1c505187d23682d601fa5dc", + "candidate_unit_id": "cnu-2cc472c7cbcc8bb6a5fe6b8c", + "candidate_projection_digest": "sha256:0852da98cbd311653ca0572977e26e4657aa43aa48d77276c9d95373d5da81e7", + "source_id": "policy-016", + "source_version": "v1", + "source_digest": "sha256:1616161616161616161616161616161616161616161616161616161616161616", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "backups" + }, + "admission_state": "AUTHORITY_REGISTRY_UNAVAILABLE", + "reason_code": "OIC-ADM-1012", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:456215bc5667571cbad8d1b6f97d56b1bac9e3d56cbc4d7fb760b2a28a6b3bdb", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "Unavailable current evidence is replaced with assumption or model judgment.", + "claim_ceiling": "Availability fail-closed expectation only." + }, + { + "vector_id": "ADM-017", + "legacy_vector_id": "ADM-017", + "origin": "v0.1_historical_scenario", + "title": "conflicting active warrants", + "threat_tags": [ + "conflicting_warrants" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-b2538be5f605274d3d6e90a9", + "candidate_span": "Transfers require notice.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-017-01", + "source_id": "policy-017", + "node_id": "scenario:ADM-017:1", + "quote": "Transfers require notice.", + "page": null, + "bbox": null, + "content_hash": "sha256:1717171717171717171717171717171717171717171717171717171717171717" + } + ] + }, + "source_registration": { + "source_id": "policy-017", + "source_version": "v2", + "source_digest": "sha256:1717171717171717171717171717171717171717171717171717171717171717", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-017", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-017-A", + "evidence_digest": "sha256:bfd00ad4662e55dd9c24e87a98ca00a79a9ecce68760be23dd31d1a7852b8a0d", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-017", + "source_version": "v2", + "source_digest": "sha256:1717171717171717171717171717171717171717171717171717171717171717", + "issuer_id": "synthetic-fixture-issuer-adm-017-01", + "authority_basis_ref": "charter:a", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-017-A", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-017-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-017-A", + "source_id": "policy-017", + "source_version": "v2", + "source_digest": "sha256:1717171717171717171717171717171717171717171717171717171717171717", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + }, + { + "evidence_id": "AE-017-B", + "evidence_digest": "sha256:da06978ca99b62cd3412c8beec5acdfa5745c12f63a84a005179fa1c186699be", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-017", + "source_version": "v2", + "source_digest": "sha256:1717171717171717171717171717171717171717171717171717171717171717", + "issuer_id": "synthetic-fixture-issuer-adm-017-02", + "authority_basis_ref": "charter:b", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-017-B-CONTRADICTORY", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-017-02", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-017-B-CONTRADICTORY", + "source_id": "policy-017", + "source_version": "v2", + "source_digest": "sha256:1717171717171717171717171717171717171717171717171717171717171717", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "transfers" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:052b905146a82ae147e1bc6ea3d7a3c9be91f35c9e7d5ed808818bd8318360fd", + "candidate_unit_id": "cnu-b2538be5f605274d3d6e90a9", + "candidate_projection_digest": "sha256:01e26d97219418ca0c3f5692503b45db00b38c14aefcbc6ec424552a567eafc3", + "source_id": "policy-017", + "source_version": "v2", + "source_digest": "sha256:1717171717171717171717171717171717171717171717171717171717171717", + "authority_evidence_refs": [ + "AE-017-A", + "AE-017-B" + ], + "authority_evidence_digests": [ + "sha256:bfd00ad4662e55dd9c24e87a98ca00a79a9ecce68760be23dd31d1a7852b8a0d", + "sha256:da06978ca99b62cd3412c8beec5acdfa5745c12f63a84a005179fa1c186699be" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "transfers" + }, + "admission_state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:a428fc1ad563525c2baa185c697eeefc98ffdb3b087bcc2e92f1b318387b99dc", + "evidence_digest": "sha256:58cc01405f38d39526f85f6b69f6a873f4b2db6adf3ca1f44fd3642535883da7" + }, + "falsifier": "The evaluator or model chooses a favorable warrant without a frozen precedence rule.", + "claim_ceiling": "Conflict fail-closed expectation only; not denial of the proposition." + }, + { + "vector_id": "ADM-018", + "legacy_vector_id": "ADM-018", + "origin": "v0.1_historical_scenario", + "title": "stale cached authority evidence", + "threat_tags": [ + "stale_cached_authority_evidence" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-5847dafe0e96fe6956a10ad8", + "candidate_span": "Keys rotate every year.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-018-01", + "source_id": "policy-018", + "node_id": "scenario:ADM-018:1", + "quote": "Keys rotate every year.", + "page": null, + "bbox": null, + "content_hash": "sha256:1818181818181818181818181818181818181818181818181818181818181818" + } + ] + }, + "source_registration": { + "source_id": "policy-018", + "source_version": "v1", + "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-018", + "availability": "AVAILABLE", + "freshness": "STALE" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "keys" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-018-STALE", + "evidence_digest": "sha256:30124969a47e6979be11e833ac51f72399b43f0a9b223d4c05c0536dedc4959f", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-018", + "source_version": "v1", + "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818", + "issuer_id": "synthetic-fixture-issuer-adm-018-01", + "authority_basis_ref": "charter:security", + "jurisdiction": "enterprise", + "applicability_scope": [ + "keys" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-018", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-018-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-018", + "source_id": "policy-018", + "source_version": "v1", + "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818", + "jurisdiction": "enterprise", + "applicability_scope": [ + "keys" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "keys" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "AUTHORITY_EVIDENCE_STALE", + "reason_code": "OIC-ADM-1013", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:f49e48ea089e2c582a57b8f8a5b9daf0191a8870f9df32fb2612cfc253545cfb", + "candidate_unit_id": "cnu-5847dafe0e96fe6956a10ad8", + "candidate_projection_digest": "sha256:b365a37a3fd3c0b3da641be509a5fcae00734c5420a84138a71d8765eab94e1f", + "source_id": "policy-018", + "source_version": "v1", + "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818", + "authority_evidence_refs": [ + "AE-018-STALE" + ], + "authority_evidence_digests": [ + "sha256:30124969a47e6979be11e833ac51f72399b43f0a9b223d4c05c0536dedc4959f" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "keys" + }, + "admission_state": "AUTHORITY_EVIDENCE_STALE", + "reason_code": "OIC-ADM-1013", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:720529ceeaad0dd0a0ea4ac6d0e7e6d61ca316e0df108860c37eab54228bd6be", + "evidence_digest": "sha256:ec6c8d7076e2a90d421fcdc796af9f1cff65fa33b7c32b4f3a82e5f18c67b490" + }, + "falsifier": "Evidence outside the configured freshness bound is treated as current.", + "claim_ceiling": "Freshness fail-closed expectation only; freshness duration remains institution-defined." + }, + { + "vector_id": "ADM-019", + "legacy_vector_id": "ADM-019", + "origin": "v0.1_historical_scenario", + "title": "newer lower authority overlaps older higher authority", + "threat_tags": [ + "newer_lower_vs_older_higher_authority", + "overlapping_scope" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-107363d3282a81b7562e4b65", + "candidate_span": "Exceptions may be approved locally.", + "unit_type": "delegation", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-019-01", + "source_id": "memo-019", + "node_id": "scenario:ADM-019:1", + "quote": "Exceptions may be approved locally.", + "page": null, + "bbox": null, + "content_hash": "sha256:1919191919191919191919191919191919191919191919191919191919191919" + } + ] + }, + "source_registration": { + "source_id": "memo-019", + "source_version": "new", + "source_digest": "sha256:1919191919191919191919191919191919191919191919191919191919191919", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-019", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-019-HIGH-OLD", + "evidence_digest": "sha256:d2eae6ee1f3e18358ce9d827976a1766b6fcedc96bcba6178bb039709e1b3551", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "memo-019", + "source_version": "older-governing", + "source_digest": "sha256:1919191919191919191919191919191919191919191919191919191919191918", + "issuer_id": "synthetic-fixture-issuer-adm-019-02", + "authority_basis_ref": "board-charter", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-019-HIGH-CONFLICT", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-019-02", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-019-HIGH-CONFLICT", + "source_id": "memo-019", + "source_version": "older-governing", + "source_digest": "sha256:1919191919191919191919191919191919191919191919191919191919191918", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + }, + { + "evidence_id": "AE-019-LOW-NEW", + "evidence_digest": "sha256:2f6b08fcca567dc7476edc127ec4ad261abe2d83039346f6d58219cb85ffca4f", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "memo-019", + "source_version": "new", + "source_digest": "sha256:1919191919191919191919191919191919191919191919191919191919191919", + "issuer_id": "synthetic-fixture-issuer-adm-019-01", + "authority_basis_ref": "department-delegation", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-05-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-019-LOW", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-019-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-019-LOW", + "source_id": "memo-019", + "source_version": "new", + "source_digest": "sha256:1919191919191919191919191919191919191919191919191919191919191919", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "effective_from": "2026-05-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:194787e9bb95deae58d74153b8fe26aa521a94062995749879944601c53f272a", + "candidate_unit_id": "cnu-107363d3282a81b7562e4b65", + "candidate_projection_digest": "sha256:1139a98a78663f8035d1614741b4e8c7ddba8cfb60a515154b4141532423b6bc", + "source_id": "memo-019", + "source_version": "new", + "source_digest": "sha256:1919191919191919191919191919191919191919191919191919191919191919", + "authority_evidence_refs": [ + "AE-019-HIGH-OLD", + "AE-019-LOW-NEW" + ], + "authority_evidence_digests": [ + "sha256:d2eae6ee1f3e18358ce9d827976a1766b6fcedc96bcba6178bb039709e1b3551", + "sha256:2f6b08fcca567dc7476edc127ec4ad261abe2d83039346f6d58219cb85ffca4f" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "admission_state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:86d6dcf16759d212e45640d436283b7bfebd495311498058883a24707da2d1e7", + "evidence_digest": "sha256:f75e43028b243ab29a073f7833d251b9a99328f0f0ed2aa4ab252ee18290e199" + }, + "falsifier": "Recency alone overrides institutional authority rank or vice versa without a versioned precedence rule.", + "claim_ceiling": "Conflict preregistration only; no universal hierarchy is asserted." + }, + { + "vector_id": "ADM-020", + "legacy_vector_id": "ADM-020", + "origin": "v0.1_historical_scenario", + "title": "perfect provenance with no authority basis", + "threat_tags": [ + "perfect_provenance_no_authority", + "provenance_alone" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-1f52ad109d47b687d4625338", + "candidate_span": "The archive contains quarterly reports.", + "unit_type": "definition", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-020-01", + "source_id": "archive-020", + "node_id": "scenario:ADM-020:1", + "quote": "The archive contains quarterly reports.", + "page": null, + "bbox": null, + "content_hash": "sha256:2020202020202020202020202020202020202020202020202020202020202020" + } + ] + }, + "source_registration": { + "source_id": "archive-020", + "source_version": "1", + "source_digest": "sha256:2020202020202020202020202020202020202020202020202020202020202020", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-020", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "UNKNOWN", + "jurisdiction": "enterprise", + "applicability_scope": [ + "archive" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "archive" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:c8691c4ef115e145cfdd292f565ed318f2cb5f5f412b0a44cc041c34b85a6558", + "candidate_unit_id": "cnu-1f52ad109d47b687d4625338", + "candidate_projection_digest": "sha256:6f11e3ea0693e9208fa99bc973844843a4f5019ab71aea464820295c91c28e2d", + "source_id": "archive-020", + "source_version": "1", + "source_digest": "sha256:2020202020202020202020202020202020202020202020202020202020202020", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "archive" + }, + "admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:4a99e433a2d24d4bfb10c732bc673728a8c85a6cfcea0400762c45ca6c6cea1a", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "Complete provenance is treated as an institutional warrant.", + "claim_ceiling": "Authority distinction expectation only." + }, + { + "vector_id": "ADM-021", + "legacy_vector_id": "ADM-021", + "origin": "v0.1_historical_scenario", + "title": "valid warrant outside applicability scope", + "threat_tags": [ + "valid_authority_candidate_outside_scope" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-bddfbc7e01e54b61fa50dec6", + "candidate_span": "Contractors complete annual training.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-021-01", + "source_id": "policy-021", + "node_id": "scenario:ADM-021:1", + "quote": "Contractors complete annual training.", + "page": null, + "bbox": null, + "content_hash": "sha256:2121212121212121212121212121212121212121212121212121212121212121" + } + ] + }, + "source_registration": { + "source_id": "policy-021", + "source_version": "v1", + "source_digest": "sha256:2121212121212121212121212121212121212121212121212121212121212121", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-021", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "employees" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-021", + "evidence_digest": "sha256:e7da8d9b9d52968e34fac5cdcf66bea884c9d05caebec882563a32e2e3e72fc6", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-021", + "source_version": "v1", + "source_digest": "sha256:2121212121212121212121212121212121212121212121212121212121212121", + "issuer_id": "synthetic-fixture-issuer-adm-021-01", + "authority_basis_ref": "charter:training", + "jurisdiction": "enterprise", + "applicability_scope": [ + "employees" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-021", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-021-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-021", + "source_id": "policy-021", + "source_version": "v1", + "source_digest": "sha256:2121212121212121212121212121212121212121212121212121212121212121", + "jurisdiction": "enterprise", + "applicability_scope": [ + "employees" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "contractors" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:b05e6c3e64a857db5f40cc4df68b35e945a8ac21bbb3ae83b5d1276a0c709a1c", + "candidate_unit_id": "cnu-bddfbc7e01e54b61fa50dec6", + "candidate_projection_digest": "sha256:e1dcd5d85b8846dd9a8e3b5551f7bdef8dee9505d953c0c203de82d24aa05d0c", + "source_id": "policy-021", + "source_version": "v1", + "source_digest": "sha256:2121212121212121212121212121212121212121212121212121212121212121", + "authority_evidence_refs": [ + "AE-021" + ], + "authority_evidence_digests": [ + "sha256:e7da8d9b9d52968e34fac5cdcf66bea884c9d05caebec882563a32e2e3e72fc6" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "contractors" + }, + "admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:5a0766f3f9dc05cc396f96a2533624344256995f10493e48bdb29e84b3b98a66", + "evidence_digest": "sha256:6d198ac0f5b0883ae92e0e855ddff9c4e798f886cf9d5c280a134d47e5e483a9" + }, + "falsifier": "An employee-only warrant is expanded to contractors.", + "claim_ceiling": "Scope-bounded eligibility expectation only." + }, + { + "vector_id": "ADM-022", + "legacy_vector_id": "ADM-022", + "origin": "v0.1_historical_scenario", + "title": "authority established but effectiveness not reached", + "threat_tags": [ + "authority_effectiveness_not_reached" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-f5f88ec7a49d97f7e829403e", + "candidate_span": "New controls apply to transfers.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-022-01", + "source_id": "policy-022", + "node_id": "scenario:ADM-022:1", + "quote": "New controls apply to transfers.", + "page": null, + "bbox": null, + "content_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222220" + } + ] + }, + "source_registration": { + "source_id": "policy-022", + "source_version": "v1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222220", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-022", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-07-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-022", + "evidence_digest": "sha256:9a3d3fa416eb06be24927a147b769e338371619fc9a8ab108088d8754a160015", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-022", + "source_version": "v1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222220", + "issuer_id": "synthetic-fixture-issuer-adm-022-01", + "authority_basis_ref": "charter:transfers", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-07-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-022", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-022-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-022", + "source_id": "policy-022", + "source_version": "v1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222220", + "jurisdiction": "enterprise", + "applicability_scope": [ + "transfers" + ], + "effective_from": "2026-07-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "transfers" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:6f0b3217dc5cb592f1736da907629d4d15bf1ae5bc059d960e72e4ad62d8d343", + "candidate_unit_id": "cnu-f5f88ec7a49d97f7e829403e", + "candidate_projection_digest": "sha256:f3e229e5562c8a189d23c5d4dfb839d3b5b7bc9a32e5adec48ded0964d3cbe6b", + "source_id": "policy-022", + "source_version": "v1", + "source_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222220", + "authority_evidence_refs": [ + "AE-022" + ], + "authority_evidence_digests": [ + "sha256:9a3d3fa416eb06be24927a147b769e338371619fc9a8ab108088d8754a160015" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "transfers" + }, + "admission_state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:93ad1b8e9ada165c7296c7962576fda493f2b1cadc60a9903971eac99f7e04b8", + "evidence_digest": "sha256:7026f4485a393e4a3a4fcd3ee52ebc19a3cfaf1b0c9baf07937b85bebbf9ce4a" + }, + "falsifier": "Future effective authority is treated as currently eligible.", + "claim_ceiling": "Time-bounded eligibility expectation only." + }, + { + "vector_id": "ADM-023", + "legacy_vector_id": "ADM-023", + "origin": "v0.1_historical_scenario", + "title": "publication precedes institutional effectiveness", + "threat_tags": [ + "publication_not_effectiveness" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-e95049bf603588b297029992", + "candidate_span": "The revised schedule governs filings.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-023-01", + "source_id": "policy-023", + "node_id": "scenario:ADM-023:1", + "quote": "The revised schedule governs filings.", + "page": null, + "bbox": null, + "content_hash": "sha256:2323232323232323232323232323232323232323232323232323232323232323" + } + ] + }, + "source_registration": { + "source_id": "policy-023", + "source_version": "v2", + "source_digest": "sha256:2323232323232323232323232323232323232323232323232323232323232323", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-023", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "filings" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2026-05-01T00:00:00Z", + "effective_from": "2026-09-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-023", + "evidence_digest": "sha256:bb5e7763f5aead9b15650d4bde254a4f7dbf61ee9ce57691876bb5c1eb6cfd23", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-023", + "source_version": "v2", + "source_digest": "sha256:2323232323232323232323232323232323232323232323232323232323232323", + "issuer_id": "synthetic-fixture-issuer-adm-023-01", + "authority_basis_ref": "charter:filings", + "jurisdiction": "enterprise", + "applicability_scope": [ + "filings" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-09-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-023", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-023-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-023", + "source_id": "policy-023", + "source_version": "v2", + "source_digest": "sha256:2323232323232323232323232323232323232323232323232323232323232323", + "jurisdiction": "enterprise", + "applicability_scope": [ + "filings" + ], + "effective_from": "2026-09-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "filings" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:5a0f4b5d4ac70505e57b2f0ac2e4b36012913b6c132052dfe626e2eb01ed16e5", + "candidate_unit_id": "cnu-e95049bf603588b297029992", + "candidate_projection_digest": "sha256:a9d595f5bc965bca47ba05fb34530f5f415ee935f947248af8a9271a8af3bd42", + "source_id": "policy-023", + "source_version": "v2", + "source_digest": "sha256:2323232323232323232323232323232323232323232323232323232323232323", + "authority_evidence_refs": [ + "AE-023" + ], + "authority_evidence_digests": [ + "sha256:bb5e7763f5aead9b15650d4bde254a4f7dbf61ee9ce57691876bb5c1eb6cfd23" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "filings" + }, + "admission_state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:9759e79ccef4a2993b6584b2f9d490dc6a590fd5becd5f289ca583f7b2df0371", + "evidence_digest": "sha256:74900838a588a4c335d95520277cbdbb474113b31db50075355012dc5bfeeac8" + }, + "falsifier": "Publication timestamp substitutes for effective_from.", + "claim_ceiling": "Temporal distinction expectation only." + }, + { + "vector_id": "ADM-024", + "legacy_vector_id": "ADM-024", + "origin": "v0.1_historical_scenario", + "title": "revocation evidence after a prior admission", + "threat_tags": [ + "revocation_after_prior_admission", + "immutable_receipt" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-bcd096905d53755bb6339304", + "candidate_span": "Emergency access requires logging.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-024-01", + "source_id": "policy-024", + "node_id": "scenario:ADM-024:1", + "quote": "Emergency access requires logging.", + "page": null, + "bbox": null, + "content_hash": "sha256:2424242424242424242424242424242424242424242424242424242424242424" + } + ] + }, + "source_registration": { + "source_id": "policy-024", + "source_version": "v1", + "source_digest": "sha256:2424242424242424242424242424242424242424242424242424242424242424", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-024", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "emergency-access" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-024", + "evidence_digest": "sha256:208ac861029aba2ac636af904c994632a933cedf7aa321d999a57ab4d39ac03c", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-024", + "source_version": "v1", + "source_digest": "sha256:2424242424242424242424242424242424242424242424242424242424242424", + "issuer_id": "synthetic-fixture-issuer-adm-024-01", + "authority_basis_ref": "charter:access", + "jurisdiction": "enterprise", + "applicability_scope": [ + "emergency-access" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": "2026-06-15T00:00:00Z", + "admission_warrant": { + "warrant_id": "AW-024", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-024-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-024", + "source_id": "policy-024", + "source_version": "v1", + "source_digest": "sha256:2424242424242424242424242424242424242424242424242424242424242424", + "jurisdiction": "enterprise", + "applicability_scope": [ + "emergency-access" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": "2026-06-15T00:00:00Z", + "status": "REVOKED" + } + } + ], + "evaluation_time": "2026-07-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "emergency-access" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:031834d0c75def67d9a422ddfa759af36eef4d38094253175de84f385afd25a8", + "candidate_unit_id": "cnu-bcd096905d53755bb6339304", + "candidate_projection_digest": "sha256:0f9600a90881b9d5d486052a03fce1a8a45f983a3415b8e213cb98a6fe94bcf3", + "source_id": "policy-024", + "source_version": "v1", + "source_digest": "sha256:2424242424242424242424242424242424242424242424242424242424242424", + "authority_evidence_refs": [ + "AE-024" + ], + "authority_evidence_digests": [ + "sha256:208ac861029aba2ac636af904c994632a933cedf7aa321d999a57ab4d39ac03c" + ], + "evaluation_time": "2026-07-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "emergency-access" + }, + "admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:620f7c5afcec1fa4c32881c812b8f7c0fea713914280c4c661d4891489ace0b2", + "evidence_digest": "sha256:ac49f00f63ea7041e6f090b9df8aba7fa13deab8feb7b83904e9318ec990ad02" + }, + "falsifier": "The prior receipt is mutated or prior admission suppresses the later revoked result.", + "claim_ceiling": "New time-specific eligibility result only; the historical receipt remains immutable." + }, + { + "vector_id": "ADM-025", + "legacy_vector_id": "ADM-025", + "origin": "v0.1_historical_scenario", + "title": "candidate lacks source anchor", + "threat_tags": [ + "candidate_input_invalid", + "source_grounding_seam" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-892c88add2b658730a2b5cdd", + "candidate_span": "Approvals are documented.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [] + }, + "source_registration": { + "source_id": "policy-025", + "source_version": "v1", + "source_digest": "sha256:2525252525252525252525252525252525252525252525252525252525252525", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-025", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-025", + "evidence_digest": "sha256:99e523d6ca315dbce150bb38eeff84089b817696a6eec22aa6c4f0b1331a3c91", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-025", + "source_version": "v1", + "source_digest": "sha256:2525252525252525252525252525252525252525252525252525252525252525", + "issuer_id": "synthetic-fixture-issuer-adm-025-01", + "authority_basis_ref": "charter:approvals", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-025", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-025-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-025", + "source_id": "policy-025", + "source_version": "v1", + "source_digest": "sha256:2525252525252525252525252525252525252525252525252525252525252525", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "approvals" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "CANDIDATE_INPUT_INVALID", + "reason_code": "OIC-ADM-1001", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:d53491f0c2fb4d5e1637d1e1b30ced233e86c8100e0a276ee2a25b2626f8ffdf", + "candidate_unit_id": "cnu-892c88add2b658730a2b5cdd", + "candidate_projection_digest": "sha256:0b77843ffd3dee53f980b880e366f712a8d0ebfc4267eebe25f7b02341db63f6", + "source_id": "policy-025", + "source_version": "v1", + "source_digest": "sha256:2525252525252525252525252525252525252525252525252525252525252525", + "authority_evidence_refs": [ + "AE-025" + ], + "authority_evidence_digests": [ + "sha256:99e523d6ca315dbce150bb38eeff84089b817696a6eec22aa6c4f0b1331a3c91" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "approvals" + }, + "admission_state": "CANDIDATE_INPUT_INVALID", + "reason_code": "OIC-ADM-1001", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:517b28002d9a37612dc43ec7cd8a4c5ba26e36e175f67077e7d765046e01e843", + "evidence_digest": "sha256:d31fe2a574149002d6162b16d6006fd09f16c034033b38cb2658ca019e0a28a5" + }, + "falsifier": "Admission reconstructs or guesses missing grounding instead of rejecting the input reference.", + "claim_ceiling": "Input-contract expectation only; admission does not redo extraction." + }, + { + "vector_id": "ADM-026", + "legacy_vector_id": "ADM-026", + "origin": "v0.1_historical_scenario", + "title": "deterministic repeat A", + "threat_tags": [ + "positive", + "deterministic_repeat", + "idempotence_pair_A" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-75d174394a1304ee383292ea", + "candidate_span": "Audit evidence is preserved.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-026-01", + "source_id": "policy-026", + "node_id": "scenario:ADM-026:1", + "quote": "Audit evidence is preserved.", + "page": null, + "bbox": null, + "content_hash": "sha256:2626262626262626262626262626262626262626262626262626262626262626" + } + ] + }, + "source_registration": { + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-026", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "audit" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-026", + "evidence_digest": "sha256:1b2978624d58a3fdc7d0a853b2af13b3205ae68a80423db7575991c1e34a3855", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "issuer_id": "synthetic-fixture-issuer-adm-026-01", + "authority_basis_ref": "charter:audit", + "jurisdiction": "enterprise", + "applicability_scope": [ + "audit" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-026", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-026-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-026", + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "jurisdiction": "enterprise", + "applicability_scope": [ + "audit" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "audit" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:353812c752acc1588db3094149c136e0c26ae6c27fd2ae795e3b130819145c92", + "candidate_unit_id": "cnu-75d174394a1304ee383292ea", + "candidate_projection_digest": "sha256:6ae0d01737115693f0b7cbf8f9cbe76449a057c6f9df7adc1e40a781e0e12f22", + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "authority_evidence_refs": [ + "AE-026" + ], + "authority_evidence_digests": [ + "sha256:1b2978624d58a3fdc7d0a853b2af13b3205ae68a80423db7575991c1e34a3855" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "audit" + }, + "admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:979f297e91f52b3066fbc0d02f887bb4fe56a4a0885cce8c48f5496a61f50ba1", + "evidence_digest": "sha256:cbc8d779fe14ba52939cef989be12476f99dcc7a705961a1c1c116ef7883d626" + }, + "falsifier": "Its receipt projection differs from ADM-027 under the same evaluator and ruleset assumptions.", + "claim_ceiling": "Deterministic design expectation only; no runtime implementation exists." + }, + { + "vector_id": "ADM-027", + "legacy_vector_id": "ADM-027", + "origin": "v0.1_historical_scenario", + "title": "deterministic repeat B", + "threat_tags": [ + "positive", + "deterministic_repeat", + "idempotence_pair_B" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-75d174394a1304ee383292ea", + "candidate_span": "Audit evidence is preserved.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-027-01", + "source_id": "policy-026", + "node_id": "scenario:ADM-027:1", + "quote": "Audit evidence is preserved.", + "page": null, + "bbox": null, + "content_hash": "sha256:2626262626262626262626262626262626262626262626262626262626262626" + } + ] + }, + "source_registration": { + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-027", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "audit" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-026", + "evidence_digest": "sha256:13df868e69bee1a032809d912298eeb37bc51d5b906768bae650d93990d86477", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "issuer_id": "synthetic-fixture-issuer-adm-027-01", + "authority_basis_ref": "charter:audit", + "jurisdiction": "enterprise", + "applicability_scope": [ + "audit" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-026", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-027-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-026", + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "jurisdiction": "enterprise", + "applicability_scope": [ + "audit" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "audit" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:3a169f8ab17c02fa979551351bd3acdc5d95f9e17968349eaacb939512766ebb", + "candidate_unit_id": "cnu-75d174394a1304ee383292ea", + "candidate_projection_digest": "sha256:eb568f76498b01079878b21cbbc176a968dc22298aec470fa52fcb1353b07864", + "source_id": "policy-026", + "source_version": "v1", + "source_digest": "sha256:2626262626262626262626262626262626262626262626262626262626262626", + "authority_evidence_refs": [ + "AE-026" + ], + "authority_evidence_digests": [ + "sha256:13df868e69bee1a032809d912298eeb37bc51d5b906768bae650d93990d86477" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "audit" + }, + "admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:63177235a0013cdc4cacd6b573de36219f9e60f1cc635e989dd169028148bcff", + "evidence_digest": "sha256:e19fbf3513293f327885b0c107ab7ee5095be8f2d53de1b78f7f927af50af4fd" + }, + "falsifier": "Its receipt projection differs from ADM-026 under the same evaluator and ruleset assumptions.", + "claim_ceiling": "Deterministic design expectation only; no runtime implementation exists." + }, + { + "vector_id": "ADM-028", + "legacy_vector_id": "ADM-028", + "origin": "v0.1_historical_scenario", + "title": "authenticated evidence with disputed unranked authority basis", + "threat_tags": [ + "generic_fail_safe", + "maybe_authoritative" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-d26d1b305db3842ca049781e", + "candidate_span": "Local practice controls review order.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-028-01", + "source_id": "practice-028", + "node_id": "scenario:ADM-028:1", + "quote": "Local practice controls review order.", + "page": null, + "bbox": null, + "content_hash": "sha256:2828282828282828282828282828282828282828282828282828282828282828" + } + ] + }, + "source_registration": { + "source_id": "practice-028", + "source_version": "1", + "source_digest": "sha256:2828282828282828282828282828282828282828282828282828282828282828", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-028", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "UNKNOWN", + "jurisdiction": "enterprise", + "applicability_scope": [ + "reviews" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-028-DISPUTED", + "evidence_digest": "sha256:d42a04692a4483937251e62666d421a50e6a1e978bbcacaddacfb8cf6e9c917c", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "practice-028", + "source_version": "1", + "source_digest": "sha256:2828282828282828282828282828282828282828282828282828282828282828", + "issuer_id": "synthetic-fixture-issuer-adm-028-01", + "authority_basis_ref": "unresolved-local-practice", + "jurisdiction": "enterprise", + "applicability_scope": [ + "reviews" + ], + "source_standing": "UNKNOWN", + "adopted_at": null, + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-028-DISPUTED", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-028-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-028-DISPUTED", + "source_id": "practice-028", + "source_version": "1", + "source_digest": "sha256:2828282828282828282828282828282828282828282828282828282828282828", + "jurisdiction": "enterprise", + "applicability_scope": [ + "reviews" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "SUSPENDED" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "reviews" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMISSION_NOT_ESTABLISHED", + "reason_code": "OIC-ADM-1099", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:0e3ee30709c9af8af69da6c6211f7bdddcd03c3c46db5cb1ab8cf7cb28747d3e", + "candidate_unit_id": "cnu-d26d1b305db3842ca049781e", + "candidate_projection_digest": "sha256:979b7297cfde2dc1dceee839a9c7a9d8765fe3ce74de1ea1650b7984baf134c5", + "source_id": "practice-028", + "source_version": "1", + "source_digest": "sha256:2828282828282828282828282828282828282828282828282828282828282828", + "authority_evidence_refs": [ + "AE-028-DISPUTED" + ], + "authority_evidence_digests": [ + "sha256:d42a04692a4483937251e62666d421a50e6a1e978bbcacaddacfb8cf6e9c917c" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "reviews" + }, + "admission_state": "ADMISSION_NOT_ESTABLISHED", + "reason_code": "OIC-ADM-1099", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:ab2552a99f4dc2ed8dd0ef3d02d4df6906f863402a2e07eea1fb1d83e9ff715d", + "evidence_digest": "sha256:b179fe5a7a784ff92492a640b961cf9cd2cd70919e40552f905d128a878fb481" + }, + "falsifier": "Maybe-authoritative or suspended evidence becomes ADMITTED, or the generic state hides a more specific frozen condition.", + "claim_ceiling": "Generic fail-safe expectation only; no denial of the proposition." + }, + { + "vector_id": "ADM-029", + "legacy_vector_id": "ADM-029", + "origin": "v0.1_historical_scenario", + "title": "draft with exact institutionally approved draft-purpose warrant", + "threat_tags": [ + "positive", + "draft_with_explicit_purpose_warrant" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-685de41583c8825afd3e7859", + "candidate_span": "Pilot reviewers record rationale.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-029-01", + "source_id": "pilot-draft-029", + "node_id": "scenario:ADM-029:1", + "quote": "Pilot reviewers record rationale.", + "page": null, + "bbox": null, + "content_hash": "sha256:2929292929292929292929292929292929292929292929292929292929292929" + } + ] + }, + "source_registration": { + "source_id": "pilot-draft-029", + "source_version": "d2", + "source_digest": "sha256:2929292929292929292929292929292929292929292929292929292929292929", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-029", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "DRAFT", + "jurisdiction": "pilot", + "applicability_scope": [ + "design-evaluation-only" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-029", + "evidence_digest": "sha256:4e8aa28075adda2749756abd4d4fe030041d3e869353b75fcfd9456b83ca3f90", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "pilot-draft-029", + "source_version": "d2", + "source_digest": "sha256:2929292929292929292929292929292929292929292929292929292929292929", + "issuer_id": "synthetic-fixture-issuer-adm-029-01", + "authority_basis_ref": "owner-decision:pilot-29", + "jurisdiction": "pilot", + "applicability_scope": [ + "design-evaluation-only" + ], + "source_standing": "DRAFT", + "adopted_at": null, + "effective_from": "2026-05-01T00:00:00Z", + "effective_until": "2026-09-01T00:00:00Z", + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-029-DRAFT-PURPOSE", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-029-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-029-DRAFT-PURPOSE", + "source_id": "pilot-draft-029", + "source_version": "d2", + "source_digest": "sha256:2929292929292929292929292929292929292929292929292929292929292929", + "jurisdiction": "pilot", + "applicability_scope": [ + "design-evaluation-only" + ], + "effective_from": "2026-05-01T00:00:00Z", + "effective_until": "2026-09-01T00:00:00Z", + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "pilot", + "applicability": "design-evaluation-only" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:5560da918ce841d6a1539dd3293df783b40ee731fb1c1a884ad8b688c34d52ec", + "candidate_unit_id": "cnu-685de41583c8825afd3e7859", + "candidate_projection_digest": "sha256:8879cb052caa7549c7fa84c142184189c37e2b31c9181900d1f740f516a1be04", + "source_id": "pilot-draft-029", + "source_version": "d2", + "source_digest": "sha256:2929292929292929292929292929292929292929292929292929292929292929", + "authority_evidence_refs": [ + "AE-029" + ], + "authority_evidence_digests": [ + "sha256:4e8aa28075adda2749756abd4d4fe030041d3e869353b75fcfd9456b83ca3f90" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "pilot", + "applicability": "design-evaluation-only" + }, + "admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:0e0169bf5571d548145cb286a50f1c773ca93bdb8eeca6529b50e520e499dea6", + "evidence_digest": "sha256:80f52665cafea241ba0b88fa8a7720770230a3b64413f6901b45f568915df6ba" + }, + "falsifier": "The draft is admitted beyond its exact purpose or rejected despite an authenticated exact draft-purpose warrant.", + "claim_ceiling": "Eligibility within the pilot design-evaluation scope only; not general operative standing." + }, + { + "vector_id": "ADM-030", + "legacy_vector_id": "ADM-030", + "origin": "v0.1_historical_scenario", + "title": "active source with revoked admission warrant", + "threat_tags": [ + "revoked_warrant" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-b8e27a759863f53a0831d476", + "candidate_span": "Exceptions require written rationale.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-030-01", + "source_id": "policy-030", + "node_id": "scenario:ADM-030:1", + "quote": "Exceptions require written rationale.", + "page": null, + "bbox": null, + "content_hash": "sha256:3030303030303030303030303030303030303030303030303030303030303030" + } + ] + }, + "source_registration": { + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-030", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-030", + "evidence_digest": "sha256:2fdba3120d00f83c892a8aa1dc1745d3ee50e598028fc92f5d4bfcb8cc38440d", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "issuer_id": "synthetic-fixture-issuer-adm-030-01", + "authority_basis_ref": "charter:risk", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": "2026-05-15T00:00:00Z", + "admission_warrant": { + "warrant_id": "AW-030", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-030-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-030", + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": "2026-05-15T00:00:00Z", + "status": "REVOKED" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:1283f4a8fb0e3b194190b8bcbbd673cb9f9c3e121893909e794842e17b306b89", + "candidate_unit_id": "cnu-b8e27a759863f53a0831d476", + "candidate_projection_digest": "sha256:144114d4e27e97c0311cfb5a129343d243191ebfcaf03356ffa20be8b85004a3", + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "authority_evidence_refs": [ + "AE-030" + ], + "authority_evidence_digests": [ + "sha256:2fdba3120d00f83c892a8aa1dc1745d3ee50e598028fc92f5d4bfcb8cc38440d" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:93a971532eadf2d20ea48cd41c347ab1bedcb9059446d6adb4633f65f4e94496", + "evidence_digest": "sha256:9d3c14ab6282784233bc5efe1848fc0fa06ff01dd317a807d289379c26a56c65" + }, + "falsifier": "Active source status overrides a revoked admission warrant.", + "claim_ceiling": "Warrant-lifecycle eligibility expectation only." + }, + { + "vector_id": "ADM-PD-001", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "registry unavailable precedes unregistered source", + "threat_tags": [ + "state_precedence", + "registry_unavailable", + "source_unregistered" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-f91f71301bd4c1824658b86d", + "candidate_span": "All requests require executive approval.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-003-01", + "source_id": "fake-memo", + "node_id": "scenario:ADM-003:1", + "quote": "All requests require executive approval.", + "page": null, + "bbox": null, + "content_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333" + } + ] + }, + "source_registration": { + "source_id": "fake-memo", + "source_version": "1", + "source_digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333", + "registered": false, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-003", + "availability": "UNAVAILABLE", + "freshness": "NOT_OBSERVED" + }, + "source_standing": "UNKNOWN", + "jurisdiction": "enterprise", + "applicability_scope": [ + "requests" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "requests" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "AUTHORITY_REGISTRY_UNAVAILABLE", + "reason_code": "OIC-ADM-1012", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:7d6a2a8244bc2dcdcbb1ac4095ab0dd416188938b90c846e84d7cba260b8084e", + "candidate_unit_id": "cnu-f91f71301bd4c1824658b86d", + "candidate_projection_digest": "sha256:93c3cb6c5e3ed57f9fc390fefd97530c698b559f366a22e65c918d9ac715f109", + "source_id": "fake-memo", + "source_version": "1", + "source_digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "requests" + }, + "admission_state": "AUTHORITY_REGISTRY_UNAVAILABLE", + "reason_code": "OIC-ADM-1012", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:f246ace6fcb4e8030ca9e41863cfa28e63f5632c98c391fd5d7b964f7329e23d", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "First-terminal-state order does not produce AUTHORITY_REGISTRY_UNAVAILABLE when registry_unavailable, source_unregistered are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + }, + { + "vector_id": "ADM-PD-002", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "stale evidence precedes unregistered source", + "threat_tags": [ + "state_precedence", + "registry_stale", + "source_unregistered" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-f91f71301bd4c1824658b86d", + "candidate_span": "All requests require executive approval.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-003-01", + "source_id": "fake-memo", + "node_id": "scenario:ADM-003:1", + "quote": "All requests require executive approval.", + "page": null, + "bbox": null, + "content_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333" + } + ] + }, + "source_registration": { + "source_id": "fake-memo", + "source_version": "1", + "source_digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333", + "registered": false, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-003", + "availability": "AVAILABLE", + "freshness": "STALE" + }, + "source_standing": "UNKNOWN", + "jurisdiction": "enterprise", + "applicability_scope": [ + "requests" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "requests" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "AUTHORITY_EVIDENCE_STALE", + "reason_code": "OIC-ADM-1013", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:39f942c0af5e187ea0142d0ae5525edc76cdae09b582259859a2764fe7a71665", + "candidate_unit_id": "cnu-f91f71301bd4c1824658b86d", + "candidate_projection_digest": "sha256:93c3cb6c5e3ed57f9fc390fefd97530c698b559f366a22e65c918d9ac715f109", + "source_id": "fake-memo", + "source_version": "1", + "source_digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "requests" + }, + "admission_state": "AUTHORITY_EVIDENCE_STALE", + "reason_code": "OIC-ADM-1013", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:1e1ba6190194ce3f4e324de4472867fef11cdce3408e5017505b9abd473fd737", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "First-terminal-state order does not produce AUTHORITY_EVIDENCE_STALE when registry_stale, source_unregistered are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + }, + { + "vector_id": "ADM-PD-003", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "unregistered source precedes version mismatch", + "threat_tags": [ + "state_precedence", + "source_unregistered", + "version_mismatch" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-1472545d7dd8a4c46b4f10a1", + "candidate_span": "Managers approve exceptions.", + "unit_type": "delegation", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-006-01", + "source_id": "policy-006", + "node_id": "scenario:ADM-006:1", + "quote": "Managers approve exceptions.", + "page": null, + "bbox": null, + "content_hash": "sha256:6666666666666666666666666666666666666666666666666666666666666666" + } + ] + }, + "source_registration": { + "source_id": "policy-006", + "source_version": "v4", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "registered": false, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-006", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-006", + "evidence_digest": "sha256:5547cf9fe48cc6782443999619d6ee8dd7a43474bed05a6676478a6f67d1cb7a", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-006", + "source_version": "v3", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "issuer_id": "synthetic-fixture-issuer-adm-006-01", + "authority_basis_ref": "charter:risk", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-006", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-006-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-006", + "source_id": "policy-006", + "source_version": "v3", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:a46dbab3db24b9dc6cc7089657bb6b5df98f6687b91a8c03d63a97ed7b093df2", + "candidate_unit_id": "cnu-1472545d7dd8a4c46b4f10a1", + "candidate_projection_digest": "sha256:3cc9af48cf78c225cc4333f16cabfc02c41ce830387ac1423c11224279a048c5", + "source_id": "policy-006", + "source_version": "v4", + "source_digest": "sha256:6666666666666666666666666666666666666666666666666666666666666666", + "authority_evidence_refs": [ + "AE-006" + ], + "authority_evidence_digests": [ + "sha256:5547cf9fe48cc6782443999619d6ee8dd7a43474bed05a6676478a6f67d1cb7a" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "exceptions" + }, + "admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:e513e147074751b238196693ab195296eee08f8c76d29d6e44cf4a1cc150939a", + "evidence_digest": "sha256:cb89c892641f58f9215537e02a5c6afc6708340b8f9f1dc9df4c529945fd6557" + }, + "falsifier": "First-terminal-state order does not produce SOURCE_NOT_REGISTERED when source_unregistered, version_mismatch are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + }, + { + "vector_id": "ADM-PD-004", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "version mismatch precedes digest mismatch", + "threat_tags": [ + "state_precedence", + "version_mismatch", + "digest_mismatch" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-fca7b341c7bc5920df6724e1", + "candidate_span": "Accounts are reviewed quarterly.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-005-01", + "source_id": "policy-005", + "node_id": "scenario:ADM-005:1", + "quote": "Accounts are reviewed quarterly.", + "page": null, + "bbox": null, + "content_hash": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" + } + ] + }, + "source_registration": { + "source_id": "policy-005", + "source_version": "v2", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-005", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "accounts" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-005", + "evidence_digest": "sha256:4230ec66f9f0199d087aedc4b6465cff5adad84cc5ddcca4215604a75f3b9bde", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-005", + "source_version": "v1", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "issuer_id": "synthetic-fixture-issuer-adm-005-01", + "authority_basis_ref": "charter:security", + "jurisdiction": "enterprise", + "applicability_scope": [ + "accounts" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-005", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-005-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-005", + "source_id": "policy-005", + "source_version": "v1", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "jurisdiction": "enterprise", + "applicability_scope": [ + "accounts" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "accounts" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_VERSION_MISMATCH", + "reason_code": "OIC-ADM-1003", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:5df3377bc2392960a46f0fc3e401d0a214bd6954fdd94d5dbbf3f3d597172d0b", + "candidate_unit_id": "cnu-fca7b341c7bc5920df6724e1", + "candidate_projection_digest": "sha256:9e24935961c3ba5df0ce7823a38483df06a58cd47fee22b293e2c65759fa910e", + "source_id": "policy-005", + "source_version": "v2", + "source_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", + "authority_evidence_refs": [ + "AE-005" + ], + "authority_evidence_digests": [ + "sha256:4230ec66f9f0199d087aedc4b6465cff5adad84cc5ddcca4215604a75f3b9bde" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "accounts" + }, + "admission_state": "SOURCE_VERSION_MISMATCH", + "reason_code": "OIC-ADM-1003", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:9ce0bf9cba47cbb411b21acc6d4daa7b1dba5b538633390885754fc2177fcdb2", + "evidence_digest": "sha256:d51d501abeca990f39ce2cf249a411b3f46dbd4d901a8300545c90b8a543c42b" + }, + "falsifier": "First-terminal-state order does not produce SOURCE_VERSION_MISMATCH when version_mismatch, digest_mismatch are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + }, + { + "vector_id": "ADM-PD-005", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "digest mismatch precedes missing authority", + "threat_tags": [ + "state_precedence", + "digest_mismatch", + "missing_authority" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-1f52ad109d47b687d4625338", + "candidate_span": "The archive contains quarterly reports.", + "unit_type": "definition", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-020-01", + "source_id": "archive-020", + "node_id": "scenario:ADM-020:1", + "quote": "The archive contains quarterly reports.", + "page": null, + "bbox": null, + "content_hash": "sha256:ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" + } + ] + }, + "source_registration": { + "source_id": "archive-020", + "source_version": "1", + "source_digest": "sha256:2020202020202020202020202020202020202020202020202020202020202020", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-020", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "UNKNOWN", + "jurisdiction": "enterprise", + "applicability_scope": [ + "archive" + ], + "adopted_at": null, + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "archive" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:ef21325e7151b63802c68e76788183459d4a31c2de20d832369e8527873afc84", + "candidate_unit_id": "cnu-1f52ad109d47b687d4625338", + "candidate_projection_digest": "sha256:d875676b2a8e511ac4251389ed16f5a5a45b3f24aba8bfadbfa38b7ab058ecad", + "source_id": "archive-020", + "source_version": "1", + "source_digest": "sha256:2020202020202020202020202020202020202020202020202020202020202020", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "archive" + }, + "admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:be5668e7f6d3bf06ef91f43a9bf852a15a92bad5e9bc41603f074c7f75eab30f", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "First-terminal-state order does not produce SOURCE_DIGEST_MISMATCH when digest_mismatch, missing_authority are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + }, + { + "vector_id": "ADM-PD-006", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "missing authority precedes out of scope", + "threat_tags": [ + "state_precedence", + "missing_authority", + "out_of_scope" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-bddfbc7e01e54b61fa50dec6", + "candidate_span": "Contractors complete annual training.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-021-01", + "source_id": "policy-021", + "node_id": "scenario:ADM-021:1", + "quote": "Contractors complete annual training.", + "page": null, + "bbox": null, + "content_hash": "sha256:2121212121212121212121212121212121212121212121212121212121212121" + } + ] + }, + "source_registration": { + "source_id": "policy-021", + "source_version": "v1", + "source_digest": "sha256:2121212121212121212121212121212121212121212121212121212121212121", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-021", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "employees" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "contractors" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:a890b6586615576870662efef31f435ed5f9ba1df3495bf9d93dbb5ed6e2c311", + "candidate_unit_id": "cnu-bddfbc7e01e54b61fa50dec6", + "candidate_projection_digest": "sha256:e1dcd5d85b8846dd9a8e3b5551f7bdef8dee9505d953c0c203de82d24aa05d0c", + "source_id": "policy-021", + "source_version": "v1", + "source_digest": "sha256:2121212121212121212121212121212121212121212121212121212121212121", + "authority_evidence_refs": [], + "authority_evidence_digests": [], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "contractors" + }, + "admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:d8b692680cb2665658e7a8746b01d01677622f9d2ab95169fafb537a4844019e", + "evidence_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + }, + "falsifier": "First-terminal-state order does not produce MISSING_AUTHORITY_EVIDENCE when missing_authority, out_of_scope are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + }, + { + "vector_id": "ADM-PD-007", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "out of scope precedes revocation", + "threat_tags": [ + "state_precedence", + "out_of_scope", + "revoked" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-b8e27a759863f53a0831d476", + "candidate_span": "Exceptions require written rationale.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-030-01", + "source_id": "policy-030", + "node_id": "scenario:ADM-030:1", + "quote": "Exceptions require written rationale.", + "page": null, + "bbox": null, + "content_hash": "sha256:3030303030303030303030303030303030303030303030303030303030303030" + } + ] + }, + "source_registration": { + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-030", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": null + }, + "authority_evidence": [ + { + "evidence_id": "AE-030", + "evidence_digest": "sha256:2fdba3120d00f83c892a8aa1dc1745d3ee50e598028fc92f5d4bfcb8cc38440d", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "issuer_id": "synthetic-fixture-issuer-adm-030-01", + "authority_basis_ref": "charter:risk", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": null, + "revoked_at": "2026-05-15T00:00:00Z", + "admission_warrant": { + "warrant_id": "AW-030", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-030-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-030", + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "jurisdiction": "enterprise", + "applicability_scope": [ + "exceptions" + ], + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": "2026-05-15T00:00:00Z", + "status": "REVOKED" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "outside-warrant" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:815b811113d537601d5a5b8a73e11cf8e2001d54735961810fa3c0d74017eb16", + "candidate_unit_id": "cnu-b8e27a759863f53a0831d476", + "candidate_projection_digest": "sha256:144114d4e27e97c0311cfb5a129343d243191ebfcaf03356ffa20be8b85004a3", + "source_id": "policy-030", + "source_version": "v1", + "source_digest": "sha256:3030303030303030303030303030303030303030303030303030303030303030", + "authority_evidence_refs": [ + "AE-030" + ], + "authority_evidence_digests": [ + "sha256:2fdba3120d00f83c892a8aa1dc1745d3ee50e598028fc92f5d4bfcb8cc38440d" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "outside-warrant" + }, + "admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:d14241a1dca3f52ea7175d0268a7714bacd6b89b18bdb09f0b2269aa51347ff0", + "evidence_digest": "sha256:9d3c14ab6282784233bc5efe1848fc0fa06ff01dd317a807d289379c26a56c65" + }, + "falsifier": "First-terminal-state order does not produce OUT_OF_SCOPE when out_of_scope, revoked are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + }, + { + "vector_id": "ADM-PD-008", + "legacy_vector_id": null, + "origin": "v0.2_precedence_diagnostic", + "title": "supersession precedes revocation", + "threat_tags": [ + "state_precedence", + "superseded", + "revoked" + ], + "executable_input": { + "candidate": { + "unit_id": "cnu-aa62e0be0eeb214f4981cc69", + "candidate_span": "Two signatures are required.", + "unit_type": "mandate", + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [ + { + "anchor_id": "anchor-adm-008-01", + "source_id": "policy-008", + "node_id": "scenario:ADM-008:1", + "quote": "Two signatures are required.", + "page": null, + "bbox": null, + "content_hash": "sha256:8888888888888888888888888888888888888888888888888888888888888888" + } + ] + }, + "source_registration": { + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "registered": true, + "registry_observation": { + "registry_boundary_id": "institution-controlled-authority-registry", + "observation_id": "registry-observation-adm-008", + "availability": "AVAILABLE", + "freshness": "FRESH" + }, + "source_standing": "ADOPTED", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "adopted_at": "2025-12-01T00:00:00Z", + "published_at": "2025-12-15T00:00:00Z", + "effective_from": "2026-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": "2026-03-01T00:00:00Z", + "revoked_at": "2026-04-01T00:00:00Z" + }, + "authority_evidence": [ + { + "evidence_id": "AE-008", + "evidence_digest": "sha256:eedfab13d7994ce657a3fca17d2b873efea6ee8e7908f7ab17a5847eb0781ddb", + "issued_at": "2025-12-20T00:00:00Z", + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "issuer_id": "synthetic-fixture-issuer-adm-008-01", + "authority_basis_ref": "charter:approvals", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "source_standing": "ADOPTED", + "adopted_at": "2025-12-01T00:00:00Z", + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "superseded_at": "2026-03-01T00:00:00Z", + "revoked_at": null, + "admission_warrant": { + "warrant_id": "AW-008", + "admission_authority_id": "synthetic-fixture-admission-authority-adm-008-01", + "delegation_basis_ref": "synthetic-fixture-delegation:AW-008", + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "jurisdiction": "enterprise", + "applicability_scope": [ + "approvals" + ], + "effective_from": "2025-01-01T00:00:00Z", + "effective_until": null, + "revoked_at": null, + "status": "ACTIVE" + } + } + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "approvals" + }, + "evaluator": { + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered" + }, + "ruleset": { + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" + } + }, + "expected_admission_state": "SUPERSEDED", + "reason_code": "OIC-ADM-1008", + "expected_receipt": { + "admission_receipt_id": "admrec-sha256:1bce8e8dca3979e92e5e667d192f0ed30a7c0c0fa530334dc4313cf0ef039e67", + "candidate_unit_id": "cnu-aa62e0be0eeb214f4981cc69", + "candidate_projection_digest": "sha256:569910970af730df63477d90ad8111368e4b09ac625923637f2a143d9c7f08b0", + "source_id": "policy-008", + "source_version": "v1", + "source_digest": "sha256:8888888888888888888888888888888888888888888888888888888888888888", + "authority_evidence_refs": [ + "AE-008" + ], + "authority_evidence_digests": [ + "sha256:eedfab13d7994ce657a3fca17d2b873efea6ee8e7908f7ab17a5847eb0781ddb" + ], + "evaluation_time": "2026-06-01T00:00:00Z", + "evaluation_scope": { + "jurisdiction": "enterprise", + "applicability": "approvals" + }, + "admission_state": "SUPERSEDED", + "reason_code": "OIC-ADM-1008", + "evaluator_id": "oic-admission-reference-evaluator", + "evaluator_version": "0.1-preregistered", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "ruleset_digest": "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c", + "input_digest": "sha256:7601733576f1fb3a3e8d8803a94b2ca6c0c756412f637c16ce03695366ec5dd4", + "evidence_digest": "sha256:fcc1fc612818c1b9e6347fc33b22b23c2097a748c137daee9a6f1da882c0a64b" + }, + "falsifier": "First-terminal-state order does not produce SUPERSEDED when superseded, revoked are simultaneously observable.", + "claim_ceiling": "State-precedence design diagnostic only; no runtime correctness or authority claim." + } + ], + "claim_ceiling": [ + "legal validity", + "universal authority semantics", + "production readiness", + "runtime safety", + "compliance", + "successful IR compilation", + "execution authorization", + "independent validation" + ], + "independent_validation_claim": false, + "self_adjudication": "NOT SELF-ADJUDICATED" +} diff --git a/design/admission-boundary-001/VECTOR-CROSSWALK-v0.1.json b/design/admission-boundary-001/VECTOR-CROSSWALK-v0.1.json new file mode 100644 index 0000000..4a4803f --- /dev/null +++ b/design/admission-boundary-001/VECTOR-CROSSWALK-v0.1.json @@ -0,0 +1,1100 @@ +{ + "crosswalk_id": "OIC-ADMISSION-BOUNDARY-001-v0.1-to-v0.2", + "v0_1_corpus_sha256": "2181cada7cda18a0bde77db89a7eaf701ad044253c3e179024ac7f51d50bc8e7", + "entry_count": 30, + "transformation_classes": [ + "identity", + "explicit_expansion_of_already_present_facts", + "addition_of_previously_unspecified_design_data" + ], + "field_class_justifications": [ + { + "field_class": "candidate_projection_normalization", + "authority_bearing": false, + "justification": "Makes the existing scenario candidate an exact typed boundary projection; unit_type remains provisional and source text is unchanged." + }, + { + "field_class": "source_lifecycle_fixture_values", + "authority_bearing": true, + "justification": "Required to make every source registration temporally explicit. Values are visible synthetic fixture data and do not assert real-world authority." + }, + { + "field_class": "issuer_and_admission_authority_fixture_ids", + "authority_bearing": true, + "justification": "Required by the frozen evidence schema. Explicit synthetic identifiers replace no real authentication and are never runtime defaults." + }, + { + "field_class": "delegation_basis_fixture_ids", + "authority_bearing": true, + "justification": "Required by the frozen warrant schema. Explicit synthetic values exercise binding only and confer no real-world mandate." + }, + { + "field_class": "evidence_jurisdiction_standing_and_adoption", + "authority_bearing": true, + "justification": "Makes evidence scope/lifecycle complete using visible synthetic fixture facts; no adapter infers them at execution time." + }, + { + "field_class": "registry_observation_and_evaluator_ruleset_ids", + "authority_bearing": false, + "justification": "Names the trusted seam and frozen evaluation assumptions without authenticating them through JSON." + }, + { + "field_class": "deterministic_digests_and_expected_receipts", + "authority_bearing": false, + "justification": "Mechanical canonical projections bind fixture bytes and expected evidence; hashes are not signatures or authority." + } + ], + "entries": [ + { + "v0_1_vector_id": "ADM-001", + "v0_2_vector_id": "ADM-001", + "preserved": { + "title": "adopted registered policy with exact active warrant", + "threat_tags": [ + "positive", + "automatic_machine_verifiable_warrant" + ], + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "falsifier": "Any non-ADMITTED result with the exact authenticated active evidence, or admission for broader scope than the warrant.", + "claim_ceiling": "Eligibility for Institutional IR interpretation only; no legal validity or execution authorization." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-002", + "v0_2_vector_id": "ADM-002", + "preserved": { + "title": "explicit institutionally approved one-source warrant", + "threat_tags": [ + "positive", + "explicit_institutional_approval" + ], + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "falsifier": "The evaluator ignores or expands the institutionally approved warrant.", + "claim_ceiling": "Eligibility for Institutional IR interpretation only; no legal validity or execution authorization." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-003", + "v0_2_vector_id": "ADM-003", + "preserved": { + "title": "authoritative-looking fake memo", + "threat_tags": [ + "authoritative_looking_fake_memo" + ], + "expected_admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "falsifier": "Official style, vocabulary, or model confidence causes admission without registration.", + "claim_ceiling": "Fail-closed design expectation only; not a finding that the text is false." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "identity_empty_array", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1" + ], + "no_default_warrant": true + }, + { + "v0_1_vector_id": "ADM-004", + "v0_2_vector_id": "ADM-004", + "preserved": { + "title": "perfectly grounded extraction from an unwarranted draft", + "threat_tags": [ + "perfect_grounding_from_draft" + ], + "expected_admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "falsifier": "Literal grounding or draft registration alone produces ADMITTED.", + "claim_ceiling": "Fail-closed design expectation only; not a judgment on future adoption." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "identity_empty_array", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1" + ], + "no_default_warrant": true + }, + { + "v0_1_vector_id": "ADM-005", + "v0_2_vector_id": "ADM-005", + "preserved": { + "title": "valid policy name with forged source metadata", + "threat_tags": [ + "valid_policy_forged_source_metadata" + ], + "expected_admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "falsifier": "A familiar source identity permits different bytes to inherit its warrant.", + "claim_ceiling": "Integrity-binding expectation only; no claim that SHA-256 authenticates the issuer." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-006", + "v0_2_vector_id": "ADM-006", + "preserved": { + "title": "valid authority presented for the wrong version", + "threat_tags": [ + "valid_authority_wrong_version" + ], + "expected_admission_state": "SOURCE_VERSION_MISMATCH", + "reason_code": "OIC-ADM-1003", + "falsifier": "Authority for v3 is silently reused for v4.", + "claim_ceiling": "Exact-version admission expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-007", + "v0_2_vector_id": "ADM-007", + "preserved": { + "title": "expired source", + "threat_tags": [ + "expired_source" + ], + "expected_admission_state": "EXPIRED", + "reason_code": "OIC-ADM-1007", + "falsifier": "Past effectiveness is treated as current admission authority.", + "claim_ceiling": "Time-bounded eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-008", + "v0_2_vector_id": "ADM-008", + "preserved": { + "title": "superseded source", + "threat_tags": [ + "superseded_source" + ], + "expected_admission_state": "SUPERSEDED", + "reason_code": "OIC-ADM-1008", + "falsifier": "A superseded source remains eligible without an explicit applicable exception warrant.", + "claim_ceiling": "Lifecycle eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-009", + "v0_2_vector_id": "ADM-009", + "preserved": { + "title": "revoked source", + "threat_tags": [ + "revoked_source" + ], + "expected_admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "falsifier": "A revoked source remains eligible at or after revocation.", + "claim_ceiling": "Lifecycle eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-010", + "v0_2_vector_id": "ADM-010", + "preserved": { + "title": "valid evidence in the wrong jurisdiction", + "threat_tags": [ + "wrong_department_or_jurisdiction" + ], + "expected_admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "falsifier": "Authority for department-a is expanded to department-b.", + "claim_ceiling": "Scope-bounded eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-011", + "v0_2_vector_id": "ADM-011", + "preserved": { + "title": "policy text copied to an unauthoritative website", + "threat_tags": [ + "copied_policy_unauthoritative_website" + ], + "expected_admission_state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "falsifier": "Identical copied text inherits the canonical source's standing.", + "claim_ceiling": "Source-instance eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-012", + "v0_2_vector_id": "ADM-012", + "preserved": { + "title": "legitimate policy quoted inside commentary", + "threat_tags": [ + "legitimate_policy_quoted_in_commentary" + ], + "expected_admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "falsifier": "A quotation in commentary borrows an unbound policy warrant.", + "claim_ceiling": "Authority-binding expectation only; not a semantic judgment on the quotation." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "identity_empty_array", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1" + ], + "no_default_warrant": true + }, + { + "v0_1_vector_id": "ADM-013", + "v0_2_vector_id": "ADM-013", + "preserved": { + "title": "model labels descriptive text as mandate", + "threat_tags": [ + "model_labels_descriptive_as_mandate", + "candidate_type_no_authority" + ], + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "falsifier": "The provisional mandate label creates extra standing or admission is misreported as semantic correctness.", + "claim_ceiling": "Eligibility only; the likely extraction defect remains for later interpretation/review and is not approved." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-014", + "v0_2_vector_id": "ADM-014", + "preserved": { + "title": "model labels a valid mandate as advisory", + "threat_tags": [ + "model_labels_valid_mandate_as_advisory", + "candidate_type_no_authority" + ], + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "falsifier": "The advisory label removes source authority or admission repairs the model label.", + "claim_ceiling": "Eligibility only; admission neither validates nor repairs provisional unit_type." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-015", + "v0_2_vector_id": "ADM-015", + "preserved": { + "title": "source digest mismatch after registered retrieval", + "threat_tags": [ + "source_digest_mismatch" + ], + "expected_admission_state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "falsifier": "Digest mismatch is ignored because identity and version match.", + "claim_ceiling": "Integrity-binding expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-016", + "v0_2_vector_id": "ADM-016", + "preserved": { + "title": "authority registry unavailable", + "threat_tags": [ + "authority_registry_unavailable" + ], + "expected_admission_state": "AUTHORITY_REGISTRY_UNAVAILABLE", + "reason_code": "OIC-ADM-1012", + "falsifier": "Unavailable current evidence is replaced with assumption or model judgment.", + "claim_ceiling": "Availability fail-closed expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "identity_empty_array", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1" + ], + "no_default_warrant": true + }, + { + "v0_1_vector_id": "ADM-017", + "v0_2_vector_id": "ADM-017", + "preserved": { + "title": "conflicting active warrants", + "threat_tags": [ + "conflicting_warrants" + ], + "expected_admission_state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "falsifier": "The evaluator or model chooses a favorable warrant without a frozen precedence rule.", + "claim_ceiling": "Conflict fail-closed expectation only; not denial of the proposition." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-018", + "v0_2_vector_id": "ADM-018", + "preserved": { + "title": "stale cached authority evidence", + "threat_tags": [ + "stale_cached_authority_evidence" + ], + "expected_admission_state": "AUTHORITY_EVIDENCE_STALE", + "reason_code": "OIC-ADM-1013", + "falsifier": "Evidence outside the configured freshness bound is treated as current.", + "claim_ceiling": "Freshness fail-closed expectation only; freshness duration remains institution-defined." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-019", + "v0_2_vector_id": "ADM-019", + "preserved": { + "title": "newer lower authority overlaps older higher authority", + "threat_tags": [ + "newer_lower_vs_older_higher_authority", + "overlapping_scope" + ], + "expected_admission_state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "falsifier": "Recency alone overrides institutional authority rank or vice versa without a versioned precedence rule.", + "claim_ceiling": "Conflict preregistration only; no universal hierarchy is asserted." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-020", + "v0_2_vector_id": "ADM-020", + "preserved": { + "title": "perfect provenance with no authority basis", + "threat_tags": [ + "perfect_provenance_no_authority", + "provenance_alone" + ], + "expected_admission_state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "falsifier": "Complete provenance is treated as an institutional warrant.", + "claim_ceiling": "Authority distinction expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "identity_empty_array", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1" + ], + "no_default_warrant": true + }, + { + "v0_1_vector_id": "ADM-021", + "v0_2_vector_id": "ADM-021", + "preserved": { + "title": "valid warrant outside applicability scope", + "threat_tags": [ + "valid_authority_candidate_outside_scope" + ], + "expected_admission_state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "falsifier": "An employee-only warrant is expanded to contractors.", + "claim_ceiling": "Scope-bounded eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-022", + "v0_2_vector_id": "ADM-022", + "preserved": { + "title": "authority established but effectiveness not reached", + "threat_tags": [ + "authority_effectiveness_not_reached" + ], + "expected_admission_state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "falsifier": "Future effective authority is treated as currently eligible.", + "claim_ceiling": "Time-bounded eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-023", + "v0_2_vector_id": "ADM-023", + "preserved": { + "title": "publication precedes institutional effectiveness", + "threat_tags": [ + "publication_not_effectiveness" + ], + "expected_admission_state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "falsifier": "Publication timestamp substitutes for effective_from.", + "claim_ceiling": "Temporal distinction expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-024", + "v0_2_vector_id": "ADM-024", + "preserved": { + "title": "revocation evidence after a prior admission", + "threat_tags": [ + "revocation_after_prior_admission", + "immutable_receipt" + ], + "expected_admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "falsifier": "The prior receipt is mutated or prior admission suppresses the later revoked result.", + "claim_ceiling": "New time-specific eligibility result only; the historical receipt remains immutable." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-025", + "v0_2_vector_id": "ADM-025", + "preserved": { + "title": "candidate lacks source anchor", + "threat_tags": [ + "candidate_input_invalid", + "source_grounding_seam" + ], + "expected_admission_state": "CANDIDATE_INPUT_INVALID", + "reason_code": "OIC-ADM-1001", + "falsifier": "Admission reconstructs or guesses missing grounding instead of rejecting the input reference.", + "claim_ceiling": "Input-contract expectation only; admission does not redo extraction." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-026", + "v0_2_vector_id": "ADM-026", + "preserved": { + "title": "deterministic repeat A", + "threat_tags": [ + "positive", + "deterministic_repeat", + "idempotence_pair_A" + ], + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "falsifier": "Its receipt projection differs from ADM-027 under the same evaluator and ruleset assumptions.", + "claim_ceiling": "Deterministic design expectation only; no runtime implementation exists." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-027", + "v0_2_vector_id": "ADM-027", + "preserved": { + "title": "deterministic repeat B", + "threat_tags": [ + "positive", + "deterministic_repeat", + "idempotence_pair_B" + ], + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "falsifier": "Its receipt projection differs from ADM-026 under the same evaluator and ruleset assumptions.", + "claim_ceiling": "Deterministic design expectation only; no runtime implementation exists." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-028", + "v0_2_vector_id": "ADM-028", + "preserved": { + "title": "authenticated evidence with disputed unranked authority basis", + "threat_tags": [ + "generic_fail_safe", + "maybe_authoritative" + ], + "expected_admission_state": "ADMISSION_NOT_ESTABLISHED", + "reason_code": "OIC-ADM-1099", + "falsifier": "Maybe-authoritative or suspended evidence becomes ADMITTED, or the generic state hides a more specific frozen condition.", + "claim_ceiling": "Generic fail-safe expectation only; no denial of the proposition." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-029", + "v0_2_vector_id": "ADM-029", + "preserved": { + "title": "draft with exact institutionally approved draft-purpose warrant", + "threat_tags": [ + "positive", + "draft_with_explicit_purpose_warrant" + ], + "expected_admission_state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "falsifier": "The draft is admitted beyond its exact purpose or rejected despite an authenticated exact draft-purpose warrant.", + "claim_ceiling": "Eligibility within the pilot design-evaluation scope only; not general operative standing." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + }, + { + "v0_1_vector_id": "ADM-030", + "v0_2_vector_id": "ADM-030", + "preserved": { + "title": "active source with revoked admission warrant", + "threat_tags": [ + "revoked_warrant" + ], + "expected_admission_state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "falsifier": "Active source status overrides a revoked admission warrant.", + "claim_ceiling": "Warrant-lifecycle eligibility expectation only." + }, + "overall_transformation": "addition_of_previously_unspecified_design_data", + "component_transformations": { + "scenario_metadata": "identity", + "candidate_projection": "explicit_expansion_of_already_present_facts_plus_non_authority_schema_state_normalization", + "registry_availability_freshness": "explicit_expansion_of_already_present_facts", + "compact_authority_evidence": "addition_of_previously_unspecified_design_data", + "evaluator_ruleset_identity": "addition_of_previously_unspecified_non_authority_design_data", + "digests_and_receipt": "deterministic_syntactic_materialization" + }, + "authority_bearing_additions": [ + "source_registration.adopted_at/published_at/effective_from/effective_until/superseded_at/revoked_at when absent in v0.1", + "authority_evidence[].issued_at", + "authority_evidence[].issuer_id", + "authority_evidence[].jurisdiction", + "authority_evidence[].source_standing", + "authority_evidence[].adopted_at", + "authority_evidence[].superseded_at", + "authority_evidence[].admission_warrant.admission_authority_id", + "authority_evidence[].admission_warrant.delegation_basis_ref", + "authority_evidence[].admission_warrant.jurisdiction" + ], + "no_default_warrant": false + } + ], + "independent_validation_claim": false, + "self_adjudication": "NOT SELF-ADJUDICATED" +} diff --git a/docker/README.md b/docker/README.md index 1fd518d..0fac785 100644 --- a/docker/README.md +++ b/docker/README.md @@ -2,7 +2,8 @@ Infrastructure only: PostgreSQL 17, MinIO, and OPA. There is **no application container** and no ZTL or VEIP container. Starting this stack enables no compiler behaviour — the -semantic implementation gate is BLOCKED (`STATUS.md`). +broader production semantic gate is BLOCKED (`STATUS.md`). The offline synthetic demo +runs separately without this stack and establishes no runtime permission. OPA starts with no bundle, no policy, and no data. PostgreSQL starts with an empty database and no migrations. Nothing here evaluates a control or stores an artifact. @@ -92,7 +93,7 @@ re-resolve a digest, and how to update a pin. | Absent | Why | |---|---| -| Application container | No semantic implementation exists to run | +| Application container | None; the bounded synthetic reference path runs offline without services | | ZTL container | Interface provisional and unfrozen (ADR-009) | | VEIP container | Interface provisional and unfrozen (ADR-010) | | OPA policy or bundle | This repository generates no Rego and evaluates no control | diff --git a/docker/compose.yaml b/docker/compose.yaml index 4d369ae..ede49a0 100644 --- a/docker/compose.yaml +++ b/docker/compose.yaml @@ -5,7 +5,7 @@ # This file starts infrastructure only: PostgreSQL, MinIO, and OPA. It deliberately # contains: # -# * no application container -- there is no semantic implementation to run; +# * no application container -- the synthetic reference path runs offline without services; # * no ZTL or VEIP container -- both interfaces are provisional and unfrozen # (ADR-009, ADR-010), and starting a container against an unfrozen interface would # imply an integration that does not exist; diff --git a/docs/SDLC-V1.2-STATUS.md b/docs/SDLC-V1.2-STATUS.md index 0f03f3f..4d8a274 100644 --- a/docs/SDLC-V1.2-STATUS.md +++ b/docs/SDLC-V1.2-STATUS.md @@ -2,14 +2,16 @@ Baseline: `29daa374b7e5cdc30ca7788310fbabb85f19912b`. -Semantic implementation remains **BLOCKED**. This matrix covers only implemented, -non-semantic infrastructure, uses the canonical public-release gate definitions in +The broader production semantic gate remains **BLOCKED**. The separate bounded synthetic +reference path has 477 passing local semantic/gate tests; Linux candidate acceptance and +independent validation remain pending. The historical matrix below covers infrastructure, +uses the canonical public-release gate definitions in owner-authorized `CURRENT-SDLC.md` v1.2, and is **NOT SELF-ADJUDICATED**. | Gate | Canonical gate | Disposition | Evidence / limitation | |---|---|---|---| | E | Human Repository Usability | PASS | For implemented infrastructure only, the README first screen states what exists, what is blocked, copy/paste safe checks, expected manifest `INCOMPLETE` behavior, and the first executable objective. This is not evidence of semantic compiler usability. | -| F | Agent Usability | PASS | `AGENTS.md` gives real infrastructure verification commands and explicitly prohibits semantic code-start, claim expansion, and status mutation. No semantic agent capability is claimed. | +| F | Agent Usability | BOUNDED / NOT INDEPENDENTLY VALIDATED | `AGENTS.md` distinguishes the exact owner-admitted synthetic scope from prohibited production behavior. No agent may extend the capability matrix as self-authorization. | | G | Adoption Readiness | NOT ESTABLISHED | The repository truthfully orients readers to the infrastructure scaffold, but a semantically blocked compiler has no established mature adoption/conversion surface. | | H | Supply-Chain & Release Integrity | PASS | Dependencies are hash-locked; consequential Actions are immutable-SHA pinned; CI performs dependency review, advisory scanning, reproducible SBOM generation, and wheel smoke verification. No release is authorized or published, so public artifact provenance/attestation is not claimed. | | I | Security & Vulnerability Management | PASS | `SECURITY.md` states the non-service scope, private disclosure route, supported state, triage boundary, and scanner limitations; dependency review and advisory scan are green on the exact PR head. | diff --git a/docs/capabilities/CAPABILITY_MATRIX.json b/docs/capabilities/CAPABILITY_MATRIX.json new file mode 100644 index 0000000..bd98e45 --- /dev/null +++ b/docs/capabilities/CAPABILITY_MATRIX.json @@ -0,0 +1,358 @@ +{ + "work_order": "OIC-SEMANTIC-PROMOTION-001", + "promotion_base": "9ad37fc80d8f34318c6212ed702de5eab3551cf5", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "state": "BOUNDED_REFERENCE_IMPLEMENTATION", + "production_semantic_gate": "BLOCKED", + "authorized_maximum_paths": [ + "AGENTS.md", + "Makefile", + "README.md", + "STATUS.md", + "VERSIONING.md", + "benchmarks/characterization/candidate-semantics-003/CORPUS-v0.3.json", + "benchmarks/characterization/candidate-semantics-004/CORPUS-v0.4.json", + "benchmarks/characterization/candidate-semantics-005/CORPUS-v0.5.json", + "benchmarks/demo/bounded-semantic-path/PROVIDER-OUTPUT.json", + "benchmarks/demo/bounded-semantic-path/SOURCE.txt", + "design/admission-boundary-001/ADMISSION-CONTRACT-v0.1.md", + "design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json", + "design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json", + "design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json", + "design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json", + "design/admission-boundary-001/TEST-VECTORS-FREEZE-v0.2.json", + "design/admission-boundary-001/TEST-VECTORS-v0.2.json", + "design/admission-boundary-001/VECTOR-CROSSWALK-v0.1.json", + "docker/README.md", + "docker/compose.yaml", + "docs/SDLC-V1.2-STATUS.md", + "docs/capabilities/CAPABILITY_MATRIX.json", + "docs/operations/FOUNDATION.md", + "pyproject.toml", + "scripts/demo_bounded_semantic_path.py", + "scripts/falsify_infrastructure.py", + "scripts/verify_code_start_gate.py", + "src/oic/__init__.py", + "src/oic/admission.py", + "src/oic/admission_specs/ADMISSION-INPUT-v0.1.schema.json", + "src/oic/admission_specs/ADMISSION-RECEIPT-v0.1.schema.json", + "src/oic/admission_specs/AUTHORITY-EVIDENCE-v0.1.schema.json", + "src/oic/admission_specs/STATE-INPUT-MAPPING-v0.1.json", + "src/oic/admission_specs/__init__.py", + "src/oic/candidate_extraction.py", + "src/oic/doctor.py", + "src/oic/frozen_synthetic_provider.py", + "src/oic/interpretation_proposal.py", + "src/oic/model_provider.py", + "src/oic/review_docket.py", + "tests/contract/admission_probes.py", + "tests/contract/test_admission_runtime_001_vectors.py", + "tests/contract/test_admission_runtime_mutations.py", + "tests/contract/test_canada_acquisition_freeze.py", + "tests/contract/test_canada_acquisition_preflight.py", + "tests/contract/test_canada_rights_resolution_dossier.py", + "tests/contract/test_claims_discipline.py", + "tests/contract/test_semantic_code_start_gate_closure.py", + "tests/contract/test_semantic_promotion.py", + "tests/contract/test_warrant_contract.py", + "tests/unit/test_admission.py", + "tests/unit/test_candidate_extraction.py", + "tests/unit/test_cli.py", + "tests/unit/test_doctor.py", + "tests/unit/test_frozen_synthetic_provider.py", + "tests/unit/test_interpretation_proposal.py", + "tests/unit/test_model_provider.py", + "tests/unit/test_review_docket.py" + ], + "actual_changed_paths": [ + "AGENTS.md", + "Makefile", + "README.md", + "STATUS.md", + "VERSIONING.md", + "benchmarks/characterization/candidate-semantics-003/CORPUS-v0.3.json", + "benchmarks/characterization/candidate-semantics-004/CORPUS-v0.4.json", + "benchmarks/characterization/candidate-semantics-005/CORPUS-v0.5.json", + "benchmarks/demo/bounded-semantic-path/PROVIDER-OUTPUT.json", + "benchmarks/demo/bounded-semantic-path/SOURCE.txt", + "design/admission-boundary-001/ADMISSION-CONTRACT-v0.1.md", + "design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json", + "design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json", + "design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json", + "design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json", + "design/admission-boundary-001/TEST-VECTORS-FREEZE-v0.2.json", + "design/admission-boundary-001/TEST-VECTORS-v0.2.json", + "design/admission-boundary-001/VECTOR-CROSSWALK-v0.1.json", + "docker/README.md", + "docker/compose.yaml", + "docs/SDLC-V1.2-STATUS.md", + "docs/capabilities/CAPABILITY_MATRIX.json", + "docs/operations/FOUNDATION.md", + "pyproject.toml", + "scripts/demo_bounded_semantic_path.py", + "scripts/falsify_infrastructure.py", + "scripts/verify_code_start_gate.py", + "src/oic/__init__.py", + "src/oic/admission.py", + "src/oic/admission_specs/ADMISSION-INPUT-v0.1.schema.json", + "src/oic/admission_specs/ADMISSION-RECEIPT-v0.1.schema.json", + "src/oic/admission_specs/AUTHORITY-EVIDENCE-v0.1.schema.json", + "src/oic/admission_specs/STATE-INPUT-MAPPING-v0.1.json", + "src/oic/admission_specs/__init__.py", + "src/oic/candidate_extraction.py", + "src/oic/doctor.py", + "src/oic/frozen_synthetic_provider.py", + "src/oic/interpretation_proposal.py", + "src/oic/model_provider.py", + "src/oic/review_docket.py", + "tests/contract/admission_probes.py", + "tests/contract/test_admission_runtime_001_vectors.py", + "tests/contract/test_admission_runtime_mutations.py", + "tests/contract/test_canada_acquisition_freeze.py", + "tests/contract/test_canada_acquisition_preflight.py", + "tests/contract/test_canada_rights_resolution_dossier.py", + "tests/contract/test_claims_discipline.py", + "tests/contract/test_semantic_code_start_gate_closure.py", + "tests/contract/test_semantic_promotion.py", + "tests/contract/test_warrant_contract.py", + "tests/unit/test_admission.py", + "tests/unit/test_candidate_extraction.py", + "tests/unit/test_cli.py", + "tests/unit/test_doctor.py", + "tests/unit/test_frozen_synthetic_provider.py", + "tests/unit/test_interpretation_proposal.py", + "tests/unit/test_model_provider.py", + "tests/unit/test_review_docket.py" + ], + "source_provenance": [ + { + "path": "src/oic/model_provider.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "ccc3ff7bc8efba8361cc73ee3dd930c2dc38acb50b1ed026a5e653eccf9adbca" + }, + { + "path": "src/oic/candidate_extraction.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "95be231dd19c8188d06700955b2dea1e69d77bf7edfc891db442e771520184b7" + }, + { + "path": "src/oic/review_docket.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "da3b3e4aaabee18df9d17de1070dabb08bb6dee1a496ca6535ca0b58e02655fa" + }, + { + "path": "src/oic/admission.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "9c33785a956daa5f2bda7f4eee1ec76901c348ee18d94d26f5bedafa4fff5c84" + }, + { + "path": "src/oic/interpretation_proposal.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "921a569952ff8d1f3c3acd2f3b3a27be6f3c41ae4a1cc78d8f809317166a7ce0" + }, + { + "path": "src/oic/admission_specs/__init__.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "76455eed5038171d7201b004e0e254170d1f79f9fd7966acd54bb6661a2ecd6e" + }, + { + "path": "src/oic/admission_specs/ADMISSION-INPUT-v0.1.schema.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "bfa5fc3c755bfbc472d2be74fede06173d5ac4db029986da0c4a07b9b5759d3e" + }, + { + "path": "src/oic/admission_specs/ADMISSION-RECEIPT-v0.1.schema.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "c70782201912231491e06239611bbd542dcdbb91da061a4ed9403111dc4ef40e" + }, + { + "path": "src/oic/admission_specs/AUTHORITY-EVIDENCE-v0.1.schema.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "f1d91532a1a50be1f5d969ce8134bdb445f4a62fee0e62565437c2c4be196c98" + }, + { + "path": "src/oic/admission_specs/STATE-INPUT-MAPPING-v0.1.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "9ed244f0a4a7f892943720f13b30b672968bfa5e20f584ca03c3195fe69e421c" + }, + { + "path": "design/admission-boundary-001/ADMISSION-CONTRACT-v0.1.md", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "ad4c656831b679a9396b15a8a9ae32448cf63707711916e4f3a8fa5ed34e8cd2" + }, + { + "path": "design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "bfa5fc3c755bfbc472d2be74fede06173d5ac4db029986da0c4a07b9b5759d3e" + }, + { + "path": "design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "c70782201912231491e06239611bbd542dcdbb91da061a4ed9403111dc4ef40e" + }, + { + "path": "design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "f1d91532a1a50be1f5d969ce8134bdb445f4a62fee0e62565437c2c4be196c98" + }, + { + "path": "design/admission-boundary-001/STATE-INPUT-MAPPING-v0.1.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "9ed244f0a4a7f892943720f13b30b672968bfa5e20f584ca03c3195fe69e421c" + }, + { + "path": "design/admission-boundary-001/TEST-VECTORS-FREEZE-v0.2.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "9f250c07447be532a022c3b4bf7e712283fc5567caefa541585fbbf643f048de" + }, + { + "path": "design/admission-boundary-001/TEST-VECTORS-v0.2.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "969ddf9a853155ce6ed27f30f1c41e76f7a1ff37a42071d2141d9966907add81" + }, + { + "path": "design/admission-boundary-001/VECTOR-CROSSWALK-v0.1.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "1b5dbf0fc25ccb9bbd14fbbb8092bd1e4a61008509b29370ad25c4d07008afbd" + }, + { + "path": "tests/unit/test_candidate_extraction.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "898689ee7acd10f874003bf07a501e8597a99a3996f392b08bf4c6e477746a84" + }, + { + "path": "tests/unit/test_review_docket.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "c7b390987229e6ab53391f7e414161d7c5ea702fb746e4bae9436e9550b3ffbb" + }, + { + "path": "tests/unit/test_admission.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "d79df2468c81cc708764282ef1e5827231128269e920883099664027cdaf0277" + }, + { + "path": "tests/unit/test_interpretation_proposal.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "87aac14e4ac97ea4be8f152797c00cf085f4989234c62a87d503be8e2a6fa821" + }, + { + "path": "tests/contract/admission_probes.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "ec640e025085dcea651f1a4649d32e21eca001c6424ea991b060b9d7e6ce11fe" + }, + { + "path": "tests/contract/test_admission_runtime_001_vectors.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "a62a7474a5f5aa85fd0ca2b92041d0f72024b1b9a22808ed87e76e03b513f368" + }, + { + "path": "tests/contract/test_admission_runtime_mutations.py", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "86e4d5880f9f0090be9f1d7a7d65759e66d12d61056555bca80a7f94d675cd9e" + }, + { + "path": "benchmarks/characterization/candidate-semantics-003/CORPUS-v0.3.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "8555d59112b07ee6c438136b79602c3b2658e2ff96abfa5deb4563a09883db5a" + }, + { + "path": "benchmarks/characterization/candidate-semantics-004/CORPUS-v0.4.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "594cbee619f467ef949690cd56014eb4f8b3c5ba9527596c6e4bef3f242d5386" + }, + { + "path": "benchmarks/characterization/candidate-semantics-005/CORPUS-v0.5.json", + "source_commit": "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54", + "sha256": "2d8c5f3f4be2028e00179b4b8eee464b325b8d9efbaf19875b8b783a6139dbf0" + } + ], + "ceilings": { + "nvidia": "NOT_QUALIFIED", + "canada_redistribution": "UNRESOLVED", + "ontology_007r1": "UNEXECUTED_EXECUTION_UNAUTHORIZED", + "production_compilation": "UNESTABLISHED", + "runtime_authorization": "UNESTABLISHED", + "institutional_ir_closure": "UNESTABLISHED", + "negative_stability_live_result": "DEFERRED", + "independent_validation": true + }, + "independent_validation_evidence": { + "status": "GATE_F_PASS", + "work_order": "OIC-INDEPENDENT-GATE-F-005", + "candidate_commit": "c0108a7a80585d6f5732407d4904ba815073ecd2", + "candidate_tree": "1d12b17aad7977c939090909171183be166cfd50", + "canonical_linux": { + "passed": 1714, + "failed": 0, + "errors": 0, + "skipped": 1, + "coverage_percent": 93.5 + }, + "demo_sha256": "0f9d01bb0dfc488505e027ac7bd8aecf869578e379b5a977cd9d642f2101a39a", + "scope": "Scoped independent Gate F repository validation of this exact candidate: reproducibility, boundary integrity, specified fail-closed properties, packaging, and named adversarial checks.", + "exclusions": [ + "semantic correctness", + "model accuracy", + "institutional validity", + "legal effect", + "provider qualification", + "rights resolution", + "ontology execution", + "production compilation", + "runtime authorization", + "institutional-IR closure", + "enterprise readiness", + "benchmark superiority" + ] + }, + "capabilities": [ + { + "name": "grounded_candidate_extraction", + "implemented": true, + "tested": "SCOPED_INDEPENDENT_GATE_F_REPOSITORY_VALIDATION_PASSED", + "documented": true, + "deferred": "generalization", + "evidence_ceiling": "Synthetic frozen replay only; no model accuracy, institutional meaning, legal validity, or runtime permission." + }, + { + "name": "review_divergence", + "implemented": true, + "tested": "SCOPED_INDEPENDENT_GATE_F_REPOSITORY_VALIDATION_PASSED", + "documented": true, + "deferred": "generalization", + "evidence_ceiling": "Synthetic frozen replay only; no model accuracy, institutional meaning, legal validity, or runtime permission." + }, + { + "name": "synthetic_authority_evidence_admission", + "implemented": true, + "tested": "SCOPED_INDEPENDENT_GATE_F_REPOSITORY_VALIDATION_PASSED", + "documented": true, + "deferred": "generalization", + "evidence_ceiling": "Synthetic frozen replay only; no model accuracy, institutional meaning, legal validity, or runtime permission." + }, + { + "name": "provisional_eleven_slot_decomposition", + "implemented": true, + "tested": "SCOPED_INDEPENDENT_GATE_F_REPOSITORY_VALIDATION_PASSED", + "documented": true, + "deferred": "generalization", + "evidence_ceiling": "Synthetic frozen replay only; no model accuracy, institutional meaning, legal validity, or runtime permission." + }, + { + "name": "unresolved_reference_preservation", + "implemented": true, + "tested": "SCOPED_INDEPENDENT_GATE_F_REPOSITORY_VALIDATION_PASSED", + "documented": true, + "deferred": "generalization", + "evidence_ceiling": "Synthetic frozen replay only; no model accuracy, institutional meaning, legal validity, or runtime permission." + }, + { + "name": "offline_deterministic_receipt", + "implemented": true, + "tested": "SCOPED_INDEPENDENT_GATE_F_REPOSITORY_VALIDATION_PASSED", + "documented": true, + "deferred": "generalization", + "evidence_ceiling": "Synthetic frozen replay only; no model accuracy, institutional meaning, legal validity, or runtime permission." + } + ] +} diff --git a/docs/operations/FOUNDATION.md b/docs/operations/FOUNDATION.md index afdd1e7..a29d9de 100644 --- a/docs/operations/FOUNDATION.md +++ b/docs/operations/FOUNDATION.md @@ -265,8 +265,11 @@ enforcement artifact (none exists to produce). ## 8. Current limitations -- **This is not a compiler.** No semantic implementation exists. See `LIMITATIONS.md`. -- **The semantic implementation gate is BLOCKED** and nothing here opens it. +- **BOUNDED_REFERENCE_IMPLEMENTATION** provides an offline synthetic path, not a production + compiler. See `docs/capabilities/CAPABILITY_MATRIX.json` and `LIMITATIONS.md`. +- **The broader production semantic gate remains BLOCKED**. Historical receipts are unchanged. + `make demo` needs no model credentials and emits deterministic canonical JSON without writes. + Initial bounded tests: 477 passed on Windows; independent validation is not established. - **Preflight corpus provenance is OPEN.** `SOURCE_MANIFEST.csv` has no rows. - **ZTL and VEIP are PROVISIONAL / NOT CONFIGURED.** Their interfaces are unfrozen (ADR-009, ADR-010) and no adapter, container, or call exists. diff --git a/pyproject.toml b/pyproject.toml index ab4af6f..844eee8 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -5,7 +5,7 @@ build-backend = "setuptools.build_meta" [project] name = "oic" version = "0.1.0a0" -description = "Open Institutional Compiler - non-semantic infrastructure foundation" +description = "Open Institutional Compiler - infrastructure and bounded synthetic reference path" readme = "README.md" license = "PolyForm-Noncommercial-1.0.0" license-files = ["LICENSE"] @@ -27,6 +27,7 @@ where = ["src"] [tool.setuptools.package-data] oic = ["py.typed"] +"oic.admission_specs" = ["*.json"] # -------------------------------------------------------------------------- # Ruff diff --git a/scripts/demo_bounded_semantic_path.py b/scripts/demo_bounded_semantic_path.py new file mode 100644 index 0000000..cad43cc --- /dev/null +++ b/scripts/demo_bounded_semantic_path.py @@ -0,0 +1,168 @@ +"""Offline reference path. Supplied synthetic evidence is not real authority.""" + +from __future__ import annotations + +import copy +import hashlib +import json +import sys +from pathlib import Path +from typing import Any + +from oic.admission import ( + AdmissionInputBoundaryError, + AdmissionReceipt, + AdmissionState, + canonical_json, + digest_of, + evaluate_admission_bytes, +) +from oic.candidate_extraction import propose_candidate_units +from oic.frozen_synthetic_provider import FrozenSyntheticProvider +from oic.interpretation_proposal import ( + SLOT_VOCABULARY, + AdmittedCandidateBinding, + ProposalInputBoundaryError, + propose_interpretation, +) +from oic.model_provider import ModelProvider +from oic.review_docket import AgreementState, build_review_docket + +ROOT = Path(__file__).resolve().parents[1] +FIXTURES = ROOT / "benchmarks/demo/bounded-semantic-path" +FIXTURE_SHA256 = "a16368c4080e73705f90b91899b89c3e057faac3f9530e41490184d50405fe62" +SOURCE_SHA256 = "bf741bb6f1b1945c45daad1d73f62bb72775088673c7236a5318dfea3e88455d" + + +def supplied_authority(candidate: dict[str, Any], source_digest: str) -> dict[str, Any]: + """Bind an explicitly synthetic owner-supplied evidence template, never model output.""" + vectors = json.loads( + (ROOT / "design/admission-boundary-001/TEST-VECTORS-v0.2.json").read_bytes() + ) + document: dict[str, Any] = copy.deepcopy(vectors["vectors"][0]["executable_input"]) + document["candidate"] = candidate + registration = document["source_registration"] + registration.update(source_id="SYNTHETIC-DEMO", source_digest=source_digest) + evidence = document["authority_evidence"][0] + evidence.update(source_id="SYNTHETIC-DEMO", source_digest=source_digest) + evidence["admission_warrant"].update(source_id="SYNTHETIC-DEMO", source_digest=source_digest) + evidence.pop("evidence_digest") + evidence["evidence_digest"] = digest_of(canonical_json(evidence)) + return document + + +def binding_for(receipt: AdmissionReceipt, candidate: dict[str, Any]) -> AdmittedCandidateBinding: + """Build the public interpretation binding from an evaluated receipt.""" + if receipt.candidate_projection_digest != digest_of(canonical_json(candidate)): + raise ValueError("candidate does not match evaluated receipt") + return AdmittedCandidateBinding( + admission_receipt_id=receipt.admission_receipt_id, + admission_state=receipt.admission_state.value, + candidate_unit_id=receipt.candidate_unit_id, + candidate_projection_digest=receipt.candidate_projection_digest, + candidate_span=candidate["candidate_span"], + ) + + +def demonstrate(provider: ModelProvider, source: str) -> dict[str, Any]: + """Exercise public seams, preserving divergence and refusing unadmitted interpretation.""" + source_digest = digest_of(source.encode("utf-8")) + anchor = { + "anchor_id": "synthetic-demo-anchor", + "source_id": "SYNTHETIC-DEMO", + "node_id": "synthetic:1", + "content_hash": source_digest, + "quote": source, + "page": None, + "bbox": None, + } + extractions = [ + propose_candidate_units(source_text=source, source_anchor=anchor, provider=provider) + for _ in range(2) + ] + if any( + candidate["candidate_span"] not in source + for extraction in extractions + for candidate in extraction.candidates + ): + raise ValueError("demo requires exact literal source spans") + docket = build_review_docket(extractions) + if docket.agreement_state is not AgreementState.DIVERGENT or len(docket.proposal_sets) != 2: + raise ValueError("demo must preserve two divergent review records") + candidate = extractions[0].candidates[0] + authority = supplied_authority(candidate, source_digest) + receipt = evaluate_admission_bytes(canonical_json(authority)) + if receipt.admission_state is not AdmissionState.ADMITTED: + raise ValueError("synthetic positive control was not admitted") + proposal = propose_interpretation( + binding=binding_for(receipt, candidate), provider=provider, proposer_id="synthetic-author" + ).proposal + assertions = proposal["proposed_assertions"] + if {a["slot"] for a in assertions} != set(SLOT_VOCABULARY): + raise ValueError("demo must expose all eleven provisional slots") + if any(a["proposed_source_quote"] not in candidate["candidate_span"] for a in assertions): + raise ValueError("synthetic example has an ungrounded proposed quote") + references = proposal.get("proposed_unresolved_references") + if references != [{"reference_text": "section SYN-9", "reference_kind": "INTERNAL_PROVISION"}]: + raise ValueError("unresolved reference was lost or resolved") + missing = copy.deepcopy(authority) + missing["authority_evidence"] = [] + refused = evaluate_admission_bytes(canonical_json(missing)) + try: + propose_interpretation( + binding=binding_for(refused, candidate), + provider=provider, + proposer_id="synthetic-author", + ) + except ProposalInputBoundaryError: + pass + else: + raise ValueError("missing authority allowed interpretation") + malformed = copy.deepcopy(authority) + del malformed["authority_evidence"][0]["evidence_digest"] + try: + evaluate_admission_bytes(canonical_json(malformed)) + except AdmissionInputBoundaryError: + pass + else: + raise ValueError("malformed authority was accepted") + output = { + "scope": "SYNTHETIC_BOUNDED_REFERENCE_IMPLEMENTATION", + "source_sha256": source_digest, + "review": docket.to_json(), + "selection_basis": "explicit synthetic fixture choice; not a vote or consensus", + "admission": receipt.to_json(), + "proposal": proposal, + "negative_path": { + "missing_authority_state": refused.admission_state.value, + "interpretation": "REFUSED_BEFORE_PROVIDER", + "malformed_authority": "REFUSED_AT_INPUT_BOUNDARY", + }, + "ceilings": { + "provider_qualification": "NOT_QUALIFIED", + "canada_redistribution": "UNRESOLVED", + "production_compilation": "UNESTABLISHED", + "runtime_authorization": "UNESTABLISHED", + "independent_validation": False, + }, + } + output["evidence_sha256"] = digest_of(canonical_json(output)) + return output + + +def main() -> None: + """Print canonical JSON only, without any repository write or machine-specific field.""" + source = (FIXTURES / "SOURCE.txt").read_bytes() + if hashlib.sha256(source).hexdigest() != SOURCE_SHA256: + raise ValueError("synthetic source digest mismatch") + provider = FrozenSyntheticProvider( + FIXTURES / "PROVIDER-OUTPUT.json", expected_sha256=FIXTURE_SHA256 + ) + output = demonstrate(provider, source.decode("utf-8")) + if provider.consumed != 3: + raise ValueError("unexpected synthetic replay count") + sys.stdout.buffer.write(canonical_json(output)) + + +if __name__ == "__main__": + main() diff --git a/scripts/falsify_infrastructure.py b/scripts/falsify_infrastructure.py index fa2e624..f17370b 100644 --- a/scripts/falsify_infrastructure.py +++ b/scripts/falsify_infrastructure.py @@ -23,8 +23,8 @@ "tests/contract/test_semantic_conformance.py::test_reject_duplicated_reason_codes", ), ( - "semantic code-start remains blocked", - "tests/contract/test_claims_discipline.py::test_operator_guide_states_the_semantic_gate_is_blocked", + "bounded semantic self-extension is refused", + "tests/contract/test_semantic_promotion.py::test_self_extension_is_refused", ), ) diff --git a/scripts/verify_code_start_gate.py b/scripts/verify_code_start_gate.py index 99c75d9..9683547 100644 --- a/scripts/verify_code_start_gate.py +++ b/scripts/verify_code_start_gate.py @@ -8,7 +8,7 @@ import shutil import subprocess import sys -from pathlib import Path +from pathlib import Path, PurePosixPath from typing import Any EXPECTED_ZTL = { @@ -24,6 +24,76 @@ "must not merge before PR #18", ) ADMITTED_PRE_GATE_HEAD = "4065e6a7c02badd3356f4c74be0815079d836aca" +PROMOTION_BASE = "9ad37fc80d8f34318c6212ed702de5eab3551cf5" +PROMOTION_SOURCE = "3fcdec63b7e546d9b369e0e8664d5d67be6a3b54" +AUTHORIZED_PATHS_SHA256 = "23b12fef0f72c41e11456361132b522ca645555b793e93be10815fd9529f78c1" +HISTORICAL_GATE_SHA256 = "58231eeda2266eb58e2ec5ec4ac70d0f3bf40a47264b77a8d8f6c69db9a94896" +BOUNDED_SRC_OIC_PATHS = frozenset( + { + "src/oic/model_provider.py", + "src/oic/frozen_synthetic_provider.py", + "src/oic/candidate_extraction.py", + "src/oic/review_docket.py", + "src/oic/admission.py", + "src/oic/interpretation_proposal.py", + "src/oic/admission_specs/__init__.py", + "src/oic/admission_specs/ADMISSION-INPUT-v0.1.schema.json", + "src/oic/admission_specs/ADMISSION-RECEIPT-v0.1.schema.json", + "src/oic/admission_specs/AUTHORITY-EVIDENCE-v0.1.schema.json", + "src/oic/admission_specs/STATE-INPUT-MAPPING-v0.1.json", + } +) +CEILINGS = { + "nvidia": "NOT_QUALIFIED", + "canada_redistribution": "UNRESOLVED", + "ontology_007r1": "UNEXECUTED_EXECUTION_UNAUTHORIZED", + "production_compilation": "UNESTABLISHED", + "runtime_authorization": "UNESTABLISHED", + "institutional_ir_closure": "UNESTABLISHED", + "negative_stability_live_result": "DEFERRED", + "independent_validation": True, +} + +INDEPENDENT_VALIDATION_EVIDENCE = { + "status": "GATE_F_PASS", + "work_order": "OIC-INDEPENDENT-GATE-F-005", + "candidate_commit": "c0108a7a80585d6f5732407d4904ba815073ecd2", + "candidate_tree": "1d12b17aad7977c939090909171183be166cfd50", + "canonical_linux": { + "passed": 1714, + "failed": 0, + "errors": 0, + "skipped": 1, + "coverage_percent": 93.5, + }, + "demo_sha256": "0f9d01bb0dfc488505e027ac7bd8aecf869578e379b5a977cd9d642f2101a39a", + "scope": ( + "Scoped independent Gate F repository validation of this exact candidate: " + "reproducibility, boundary integrity, specified fail-closed properties, " + "packaging, and named adversarial checks." + ), + "exclusions": [ + "semantic correctness", + "model accuracy", + "institutional validity", + "legal effect", + "provider qualification", + "rights resolution", + "ontology execution", + "production compilation", + "runtime authorization", + "institutional-IR closure", + "enterprise readiness", + "benchmark superiority", + ], +} + + +def validate_independent_validation_evidence(evidence: object) -> None: + """Accept only the exact owner-adjudicated Gate F evidence record.""" + _require(evidence == INDEPENDENT_VALIDATION_EVIDENCE, "independent validation evidence forged") + + ADMITTED_SRC_OIC_PATHS = frozenset( { "src/oic/__init__.py", @@ -49,6 +119,11 @@ def _require(condition: bool, message: str) -> None: raise GateEvidenceError(message) +def _is_python_cache_artifact(path: str) -> bool: + normalized = PurePosixPath(path) + return "__pycache__" in normalized.parts or normalized.suffix in {".pyc", ".pyo"} + + def discover_unadmitted_production_paths(root: Path) -> list[str]: """Compare tracked ``src/oic`` paths with the immutable pre-gate baseline.""" git = shutil.which("git") @@ -62,9 +137,16 @@ def discover_unadmitted_production_paths(root: Path) -> list[str]: ) if result.returncode != 0: raise GateEvidenceError("cannot enumerate tracked src/oic production paths") - current = {line for line in result.stdout.splitlines() if line} - added = sorted(current - ADMITTED_SRC_OIC_PATHS) - missing = sorted(ADMITTED_SRC_OIC_PATHS - current) + current = {PurePosixPath(line).as_posix() for line in result.stdout.splitlines() if line} + current.update( + path.relative_to(root).as_posix() + for path in (root / "src/oic").rglob("*") + if path.is_file() + ) + current = {path for path in current if not _is_python_cache_artifact(path)} + admitted = ADMITTED_SRC_OIC_PATHS | BOUNDED_SRC_OIC_PATHS + added = sorted(current - admitted) + missing = sorted(path for path in admitted if not (root / path).is_file()) return added + [f"MISSING:{path}" for path in missing] @@ -174,6 +256,93 @@ def validate_evidence( _require(not semantic_paths, "semantic implementation appeared before gate opening") +def validate_bounded_record(root: Path) -> None: + """Validate the owner-pinned bounded surface, never a self-declared general OPEN gate.""" + record = json.loads((root / "docs/capabilities/CAPABILITY_MATRIX.json").read_bytes()) + _require(isinstance(record, dict), "invalid capability matrix") + _require( + set(record) + == { + "work_order", + "promotion_base", + "source_commit", + "state", + "production_semantic_gate", + "authorized_maximum_paths", + "actual_changed_paths", + "source_provenance", + "ceilings", + "independent_validation_evidence", + "capabilities", + }, + "capability matrix fields expanded", + ) + capabilities = record.get("capabilities") + names = [ + "grounded_candidate_extraction", + "review_divergence", + "synthetic_authority_evidence_admission", + "provisional_eleven_slot_decomposition", + "unresolved_reference_preservation", + "offline_deterministic_receipt", + ] + _require( + isinstance(capabilities, list) and len(capabilities) == len(names), + "capability set expanded", + ) + for capability, name in zip(capabilities, names, strict=True): + _require( + capability + == { + "name": name, + "implemented": True, + "tested": "SCOPED_INDEPENDENT_GATE_F_REPOSITORY_VALIDATION_PASSED", + "documented": True, + "deferred": "generalization", + "evidence_ceiling": ( + "Synthetic frozen replay only; no model accuracy, institutional " + "meaning, legal validity, or runtime permission." + ), + }, + "capability claim expanded", + ) + _require(record.get("work_order") == "OIC-SEMANTIC-PROMOTION-001", "wrong work order") + _require(record.get("promotion_base") == PROMOTION_BASE, "wrong promotion base") + _require(record.get("source_commit") == PROMOTION_SOURCE, "wrong promotion source") + _require(record.get("state") == "BOUNDED_REFERENCE_IMPLEMENTATION", "bounded state expanded") + _require(record.get("production_semantic_gate") == "BLOCKED", "production gate expanded") + _require(record.get("ceilings") == CEILINGS, "evidence ceiling expanded") + validate_independent_validation_evidence(record.get("independent_validation_evidence")) + provenance = record.get("source_provenance") + _require( + hashlib.sha256( + json.dumps(provenance, sort_keys=True, separators=(",", ":")).encode() + ).hexdigest() + == "15d7ae49ade2bbbf0888803ef3e647c3eb9e0255f60c5da43f90726a2693f482", + "source provenance changed", + ) + for entry in provenance: + _require( + hashlib.sha256((root / entry["path"]).read_bytes()).hexdigest() == entry["sha256"], + f"exact promoted source changed: {entry['path']}", + ) + paths = record.get("authorized_maximum_paths") + _require(isinstance(paths, list) and all(isinstance(p, str) for p in paths), "invalid paths") + _require( + hashlib.sha256(("\n".join(paths) + "\n").encode()).hexdigest() == AUTHORIZED_PATHS_SHA256, + "capability matrix cannot self-extend the owner allowlist", + ) + _require(record.get("actual_changed_paths") == paths, "changed-path record differs") + for path in paths: + _require((root / path).is_file(), f"missing required bounded path: {path}") + _require(not discover_unadmitted_production_paths(root), "unauthorized production surface") + gate = root / "docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md" + _require( + hashlib.sha256(gate.read_bytes()).hexdigest() == HISTORICAL_GATE_SHA256, + "historical gate receipt changed", + ) + + def load_and_validate(root: Path) -> None: def load(path: str) -> dict[str, Any]: value: dict[str, Any] = json.loads((root / path).read_text(encoding="utf-8")) @@ -208,6 +377,7 @@ def load(path: str) -> dict[str, Any]: active_text, semantic_paths=semantic_paths, ) + validate_bounded_record(root) if __name__ == "__main__": @@ -216,4 +386,4 @@ def load(path: str) -> dict[str, Any]: except (GateEvidenceError, OSError, KeyError, json.JSONDecodeError) as exc: print(f"FAIL semantic code-start gate evidence: {exc}") sys.exit(1) - print("PASS semantic code-start prerequisite evidence; gate remains NOT OPEN") + print("PASS bounded reference implementation; broader production semantic gate BLOCKED") diff --git a/src/oic/__init__.py b/src/oic/__init__.py index d951dee..d1e25b5 100644 --- a/src/oic/__init__.py +++ b/src/oic/__init__.py @@ -1,16 +1,28 @@ -"""Open Institutional Compiler - non-semantic infrastructure foundation. +"""Open Institutional Compiler - infrastructure and bounded reference implementation. This package contains repository infrastructure only: artifact hashing, manifest verification, JSON Schema discovery and validation, environment diagnostics, and the CLI that exposes them. -It contains no semantic implementation. It does not interpret institutional documents, -determine authority, record admission, produce an Open Control Envelope, generate Rego, -or call ZTL or VEIP. The semantic implementation gate is BLOCKED (see ``STATUS.md``). +The separately admitted reference path handles synthetic candidates, supplied admission +evidence and provisional interpretations. It does not establish institutional meaning, +produce an Open Control Envelope, generate Rego, or call ZTL or VEIP. The broader +production semantic gate remains BLOCKED (see ``STATUS.md``). """ from __future__ import annotations -__all__ = ["__version__"] +from oic.admission import evaluate_admission_bytes +from oic.candidate_extraction import propose_candidate_units +from oic.interpretation_proposal import propose_interpretation +from oic.review_docket import build_review_docket + +__all__ = [ + "__version__", + "build_review_docket", + "evaluate_admission_bytes", + "propose_candidate_units", + "propose_interpretation", +] __version__ = "0.1.0a0" diff --git a/src/oic/admission.py b/src/oic/admission.py new file mode 100644 index 0000000..bc3ba98 --- /dev/null +++ b/src/oic/admission.py @@ -0,0 +1,888 @@ +"""Deterministic reference evaluator for the frozen Admission Boundary 001 contract. + +Scope +----- +This module answers exactly one frozen question about one candidate normative unit: +*did the institution's own authority evidence establish eligibility for Institutional IR +interpretation at an explicit evaluation time?* It answers it by reading facts that are +already in the input and comparing them against a frozen, packaged ruleset. + +What this module deliberately is not +------------------------------------ +No model participates in the answer. No authority is invented, defaulted, widened, or +repaired. No Institutional IR is constructed. No execution is authorized. ``ADMITTED`` +means eligible for interpretation and nothing else; every other state means eligibility +was not established, never that the underlying proposition was denied. + +Two failure classes, never merged +--------------------------------- +1. **Input-boundary failure.** The bytes are not an admissible executable input: + not UTF-8, not one JSON object, duplicate keys, not the canonical serialization, + schema-invalid, misordered or duplicated evidence, an evidence digest that does not + recompute, or a ruleset the packaged frozen ruleset does not attest. These raise + :class:`AdmissionInputBoundaryError`. They are *not* admission outcomes and are never + converted into ``ADMISSION_NOT_ESTABLISHED``: a malformed input has not been + evaluated, and saying otherwise would manufacture institutional evidence out of a + parse failure. +2. **Valid input.** Exactly one terminal admission state and one immutable receipt. + +An unexpected internal defect raises :class:`AdmissionEvaluationError`. It never becomes +a receipt either. + +Time +---- +Time enters only through ``evaluation_time``. This module reads no clock, no timezone, +and no calendar. Two evaluations of identical bytes are identical forever. + +Offline +------- +The four governing specifications are packaged beside this module as byte-identical +copies of the frozen design originals, and schema resolution runs through a +:class:`referencing.Registry` built solely from those bytes. The registry has no +``retrieve`` callback, so an absolute ``$id``/``$ref`` URI resolves locally or fails; it +never becomes a fetch. +""" + +from __future__ import annotations + +import hashlib +import json +from collections.abc import Iterable, Mapping, Sequence +from dataclasses import dataclass +from datetime import UTC, datetime +from enum import Enum +from importlib import resources +from typing import Any, Final + +from jsonschema.exceptions import ValidationError +from jsonschema.validators import Draft202012Validator +from referencing import Registry, Resource +from referencing.jsonschema import DRAFT202012 + +__all__ = [ + "ADMISSION_INPUT_SCHEMA_NAME", + "ADMISSION_RECEIPT_SCHEMA_NAME", + "AUTHORITY_EVIDENCE_SCHEMA_NAME", + "CANONICALIZATION_ID", + "EVALUATOR_ID", + "EVALUATOR_VERSION", + "RULESET_DIGEST", + "RULESET_ID", + "STATE_INPUT_MAPPING_NAME", + "AdmissionCanonicalFormError", + "AdmissionEncodingError", + "AdmissionError", + "AdmissionEvaluationError", + "AdmissionEvidenceIntegrityError", + "AdmissionEvidenceOrderError", + "AdmissionInputBoundaryError", + "AdmissionJSONError", + "AdmissionReceipt", + "AdmissionRulesetError", + "AdmissionSchemaError", + "AdmissionSpecificationError", + "AdmissionState", + "AdmissionTimestampError", + "ReasonCode", + "canonical_json", + "digest_of", + "evaluate_admission_bytes", + "packaged_specification_bytes", + "packaged_state_input_mapping", +] + +# JSON documents are arbitrarily shaped; `Any` is the honest annotation at the boundary. +JsonValue = Any + +CANONICALIZATION_ID: Final[str] = "OIC-ADMISSION-CANONICAL-JSON-v0.1" +EVALUATOR_ID: Final[str] = "oic-admission-reference-evaluator" +EVALUATOR_VERSION: Final[str] = "0.1-preregistered" +RULESET_ID: Final[str] = "OIC-ADMISSION-BOUNDARY-001" +RULESET_DIGEST: Final[str] = ( + "sha256:794ff36a702964ef32b3bc7b68cc9286e06665e20744975db5f4ef692e685b6c" +) + +STATE_INPUT_MAPPING_NAME: Final[str] = "STATE-INPUT-MAPPING-v0.1.json" +ADMISSION_INPUT_SCHEMA_NAME: Final[str] = "ADMISSION-INPUT-v0.1.schema.json" +AUTHORITY_EVIDENCE_SCHEMA_NAME: Final[str] = "AUTHORITY-EVIDENCE-v0.1.schema.json" +ADMISSION_RECEIPT_SCHEMA_NAME: Final[str] = "ADMISSION-RECEIPT-v0.1.schema.json" + +_SPECS_PACKAGE: Final[str] = "oic.admission_specs" +_RECEIPT_ID_PREFIX: Final[str] = "admrec-" +_DIGEST_PREFIX: Final[str] = "sha256:" +_UTF8_BOM: Final[bytes] = b"\xef\xbb\xbf" +#: The only timestamp spelling this evaluator accepts. The executable input contract +#: requires timestamps to be normalized before serialization, so normalizing here would +#: be exactly the silent repair the contract forbids. +_TIMESTAMP_FORMAT: Final[str] = "%Y-%m-%dT%H:%M:%SZ" +#: Two distinct operative authority bases over one evaluation is the frozen conflict +#: condition. The frozen ruleset carries no rule that could resolve them. +_CONFLICT_THRESHOLD: Final[int] = 2 + + +# --------------------------------------------------------------------------- +# Errors +# --------------------------------------------------------------------------- +# +# Messages carry field names, JSON pointers, counts, and indices. They never carry +# input values, evidence bodies, or any other part of an untrusted payload. + + +class AdmissionError(RuntimeError): + """Base class for every error raised by the admission evaluator.""" + + +class AdmissionInputBoundaryError(AdmissionError): + """The supplied bytes are not an admissible executable input. + + This is not an admission outcome. Nothing was evaluated, so no terminal state and no + receipt exist. Callers must not translate it into one. + """ + + +class AdmissionEncodingError(AdmissionInputBoundaryError): + """The bytes are not BOM-free UTF-8.""" + + +class AdmissionJSONError(AdmissionInputBoundaryError): + """The bytes are not exactly one JSON object with unique keys.""" + + +class AdmissionCanonicalFormError(AdmissionInputBoundaryError): + """The bytes are not the canonical JSON serialization of what they decode to.""" + + +class AdmissionSchemaError(AdmissionInputBoundaryError): + """The decoded input does not satisfy the frozen executable input schema.""" + + +class AdmissionTimestampError(AdmissionInputBoundaryError): + """A timestamp is not a normalized RFC 3339 UTC ``Z`` instant.""" + + +class AdmissionEvidenceOrderError(AdmissionInputBoundaryError): + """Authority evidence is misordered or carries a duplicate ``evidence_id``.""" + + +class AdmissionEvidenceIntegrityError(AdmissionInputBoundaryError): + """A recorded ``evidence_digest`` does not recompute from its own evidence object.""" + + +class AdmissionRulesetError(AdmissionInputBoundaryError): + """The input names a ruleset this evaluator does not carry.""" + + +class AdmissionSpecificationError(AdmissionError): + """A packaged frozen specification is missing, unreadable, or not what it attests.""" + + +class AdmissionEvaluationError(AdmissionError): + """A defect in this evaluator. Never a receipt, never an admission state.""" + + +# --------------------------------------------------------------------------- +# Frozen vocabulary +# --------------------------------------------------------------------------- + + +class AdmissionState(Enum): + """The fifteen frozen terminal states, declared in frozen precedence order.""" + + CANDIDATE_INPUT_INVALID = "CANDIDATE_INPUT_INVALID" + AUTHORITY_REGISTRY_UNAVAILABLE = "AUTHORITY_REGISTRY_UNAVAILABLE" + AUTHORITY_EVIDENCE_STALE = "AUTHORITY_EVIDENCE_STALE" + SOURCE_NOT_REGISTERED = "SOURCE_NOT_REGISTERED" + SOURCE_VERSION_MISMATCH = "SOURCE_VERSION_MISMATCH" + SOURCE_DIGEST_MISMATCH = "SOURCE_DIGEST_MISMATCH" + MISSING_AUTHORITY_EVIDENCE = "MISSING_AUTHORITY_EVIDENCE" + OUT_OF_SCOPE = "OUT_OF_SCOPE" + NOT_YET_EFFECTIVE = "NOT_YET_EFFECTIVE" + EXPIRED = "EXPIRED" + SUPERSEDED = "SUPERSEDED" + REVOKED = "REVOKED" + CONFLICTING_AUTHORITY = "CONFLICTING_AUTHORITY" + ADMISSION_NOT_ESTABLISHED = "ADMISSION_NOT_ESTABLISHED" + ADMITTED = "ADMITTED" + + +class ReasonCode(Enum): + """The frozen primary reason code paired with each terminal state.""" + + OIC_ADM_0000 = "OIC-ADM-0000" + OIC_ADM_1001 = "OIC-ADM-1001" + OIC_ADM_1002 = "OIC-ADM-1002" + OIC_ADM_1003 = "OIC-ADM-1003" + OIC_ADM_1004 = "OIC-ADM-1004" + OIC_ADM_1005 = "OIC-ADM-1005" + OIC_ADM_1006 = "OIC-ADM-1006" + OIC_ADM_1007 = "OIC-ADM-1007" + OIC_ADM_1008 = "OIC-ADM-1008" + OIC_ADM_1009 = "OIC-ADM-1009" + OIC_ADM_1010 = "OIC-ADM-1010" + OIC_ADM_1011 = "OIC-ADM-1011" + OIC_ADM_1012 = "OIC-ADM-1012" + OIC_ADM_1013 = "OIC-ADM-1013" + OIC_ADM_1099 = "OIC-ADM-1099" + + +# --------------------------------------------------------------------------- +# Canonical JSON v0.1 and digests +# --------------------------------------------------------------------------- + + +def canonical_json(value: JsonValue) -> bytes: + """Serialize ``value`` as ``OIC-ADMISSION-CANONICAL-JSON-v0.1``. + + UTF-8 without a BOM, object keys sorted by Unicode code point, no insignificant + whitespace, no ASCII-only escaping, no NaN or infinity, array order as recorded, and + no trailing newline. Canonicalization never reads a clock. + """ + try: + text = json.dumps( + value, + ensure_ascii=False, + allow_nan=False, + separators=(",", ":"), + sort_keys=True, + ) + except (TypeError, ValueError) as exc: + raise AdmissionEvaluationError( + f"value is not canonically serializable: {type(exc).__name__}" + ) from exc + return text.encode("utf-8") + + +def digest_of(payload: bytes) -> str: + """Return ``sha256:<64 lowercase hex>`` over ``payload``.""" + return f"{_DIGEST_PREFIX}{hashlib.sha256(payload).hexdigest()}" + + +def _digest_of_projection(value: JsonValue) -> str: + return digest_of(canonical_json(value)) + + +def _without(mapping: Mapping[str, JsonValue], key: str) -> dict[str, JsonValue]: + return {name: item for name, item in mapping.items() if name != key} + + +# --------------------------------------------------------------------------- +# Packaged frozen specifications +# --------------------------------------------------------------------------- + + +def packaged_specification_bytes(name: str) -> bytes: + """Return the packaged bytes of one frozen specification. + + Reads from installed package data, so the evaluator runs from a wheel with no + ``design/`` tree present. + """ + try: + return (resources.files(_SPECS_PACKAGE) / name).read_bytes() + except (OSError, ModuleNotFoundError) as exc: + raise AdmissionSpecificationError( + f"packaged admission specification is unavailable: {name}" + ) from exc + + +def _packaged_document(name: str) -> JsonValue: + raw = packaged_specification_bytes(name) + try: + return json.loads(raw.decode("utf-8")) + except (UnicodeDecodeError, json.JSONDecodeError) as exc: + raise AdmissionSpecificationError( + f"packaged admission specification is not UTF-8 JSON: {name}" + ) from exc + + +def packaged_state_input_mapping() -> JsonValue: + """Return the parsed packaged frozen ruleset, verified against its frozen digest.""" + mapping = _packaged_document(STATE_INPUT_MAPPING_NAME) + computed = _digest_of_projection(mapping) + if computed != RULESET_DIGEST: + raise AdmissionSpecificationError( + "packaged ruleset does not match the frozen ruleset digest" + ) + return mapping + + +def _mapping_entries() -> tuple[tuple[AdmissionState, ReasonCode], ...]: + """Return (state, reason code) pairs in the ruleset's own precedence order.""" + mapping = packaged_state_input_mapping() + if not isinstance(mapping, Mapping) or mapping.get("ruleset_id") != RULESET_ID: + raise AdmissionSpecificationError("packaged ruleset does not declare the frozen ruleset id") + if mapping.get("first_terminal_state_wins") is not True: + raise AdmissionSpecificationError("packaged ruleset does not declare first-terminal-wins") + if mapping.get("runtime_permission_states") != []: + raise AdmissionSpecificationError("packaged ruleset declares a runtime permission state") + entries = mapping.get("entries") + if not isinstance(entries, list): + raise AdmissionSpecificationError("packaged ruleset has no entries") + ordered = sorted(entries, key=lambda entry: int(entry["precedence"])) + if [int(entry["precedence"]) for entry in ordered] != list(range(1, len(ordered) + 1)): + raise AdmissionSpecificationError("packaged ruleset precedence is not a dense 1..n order") + try: + return tuple( + (AdmissionState(entry["state"]), ReasonCode(entry["reason_code"])) for entry in ordered + ) + except (KeyError, ValueError) as exc: + raise AdmissionSpecificationError( + "packaged ruleset names a state or reason code this evaluator does not carry" + ) from exc + + +#: Frozen precedence, read from the packaged ruleset rather than restated here. +_PRECEDENCE: Final[tuple[tuple[AdmissionState, ReasonCode], ...]] = _mapping_entries() +_REASON_FOR_STATE: Final[dict[AdmissionState, ReasonCode]] = dict(_PRECEDENCE) + +if tuple(state for state, _ in _PRECEDENCE) != tuple(AdmissionState): + raise AdmissionSpecificationError( + "packaged ruleset precedence does not match this evaluator's declared state order" + ) + + +def _build_registry() -> Registry: + """A registry built only from packaged bytes. No retrieve callback, so no fetch.""" + resources_by_uri: list[tuple[str, Resource]] = [] + for name in ( + ADMISSION_INPUT_SCHEMA_NAME, + AUTHORITY_EVIDENCE_SCHEMA_NAME, + ADMISSION_RECEIPT_SCHEMA_NAME, + ): + document = _packaged_document(name) + resource = Resource.from_contents(document, default_specification=DRAFT202012) + schema_id = document.get("$id") if isinstance(document, Mapping) else None + if isinstance(schema_id, str) and schema_id: + resources_by_uri.append((schema_id, resource)) + resources_by_uri.append((name, resource)) + registry: Registry = Registry().with_resources(resources_by_uri) + return registry + + +_REGISTRY: Final[Registry] = _build_registry() +_INPUT_VALIDATOR: Final[Draft202012Validator] = Draft202012Validator( + _packaged_document(ADMISSION_INPUT_SCHEMA_NAME), registry=_REGISTRY +) +_RECEIPT_VALIDATOR: Final[Draft202012Validator] = Draft202012Validator( + _packaged_document(ADMISSION_RECEIPT_SCHEMA_NAME), registry=_REGISTRY +) + + +def _pointer(error: ValidationError) -> str: + return "".join( + "/" + str(part).replace("~", "~0").replace("/", "~1") for part in error.absolute_path + ) + + +# --------------------------------------------------------------------------- +# Byte boundary +# --------------------------------------------------------------------------- + + +def _reject_duplicate_keys(pairs: list[tuple[str, JsonValue]]) -> dict[str, JsonValue]: + seen: dict[str, JsonValue] = {} + for key, value in pairs: + if key in seen: + raise AdmissionJSONError(f"duplicate object key: {key!r}") + seen[key] = value + return seen + + +def _reject_constant(name: str) -> JsonValue: + """Refuse ``NaN``/``Infinity``/``-Infinity``, which Python accepts but JSON has not. + + Raised here rather than at canonicalization so a non-JSON literal is classified as + what it is: an input-boundary failure, not a defect in this evaluator. + """ + raise AdmissionJSONError(f"admission input carries the non-JSON literal {name}") + + +def _decode(input_bytes: bytes) -> JsonValue: + if not isinstance(input_bytes, bytes | bytearray): + raise AdmissionEncodingError( + f"admission input must be bytes, received {type(input_bytes).__name__}" + ) + payload = bytes(input_bytes) + if payload.startswith(_UTF8_BOM): + raise AdmissionEncodingError("admission input carries a UTF-8 byte-order mark") + try: + text = payload.decode("utf-8") + except UnicodeDecodeError as exc: + raise AdmissionEncodingError("admission input is not valid UTF-8") from exc + try: + document: JsonValue = json.loads( + text, object_pairs_hook=_reject_duplicate_keys, parse_constant=_reject_constant + ) + except json.JSONDecodeError as exc: + raise AdmissionJSONError(f"admission input is not one JSON value: {exc.msg}") from exc + if not isinstance(document, dict): + raise AdmissionJSONError( + f"admission input must be a JSON object, found {type(document).__name__}" + ) + return document + + +def _require_canonical(document: JsonValue, payload: bytes) -> None: + if canonical_json(document) != payload: + raise AdmissionCanonicalFormError( + "admission input bytes are not the canonical JSON serialization of their own " + f"content ({CANONICALIZATION_ID}); the evaluator does not normalize and continue" + ) + + +def _require_schema_valid(document: JsonValue) -> None: + errors = sorted(_INPUT_VALIDATOR.iter_errors(document), key=lambda error: _pointer(error)) + if errors: + first = errors[0] + raise AdmissionSchemaError( + f"admission input violates {ADMISSION_INPUT_SCHEMA_NAME} at " + f"{_pointer(first) or '#'}: failed keyword {first.validator!r} " + f"({len(errors)} violation(s) total)" + ) + + +def _require_frozen_ruleset(document: Mapping[str, JsonValue]) -> None: + ruleset = document["ruleset"] + if ruleset["ruleset_id"] != RULESET_ID: + raise AdmissionRulesetError("admission input names an unknown ruleset id") + if ruleset["ruleset_digest"] != RULESET_DIGEST: + raise AdmissionRulesetError( + "admission input names a ruleset digest this evaluator does not carry; " + "caller-selected admission rules are not accepted" + ) + + +def _require_evidence_integrity(evidence: Sequence[Mapping[str, JsonValue]]) -> None: + seen_ids: set[str] = set() + previous: tuple[str, str] | None = None + for index, item in enumerate(evidence): + evidence_id = item["evidence_id"] + recorded = item["evidence_digest"] + if evidence_id in seen_ids: + raise AdmissionEvidenceOrderError( + f"authority_evidence[{index}] repeats an earlier evidence_id" + ) + seen_ids.add(evidence_id) + key = (evidence_id, recorded) + if previous is not None and key <= previous: + raise AdmissionEvidenceOrderError( + f"authority_evidence[{index}] is not in ascending " + "(evidence_id, evidence_digest) order; the evaluator does not reorder input" + ) + previous = key + computed = _digest_of_projection(_without(item, "evidence_digest")) + if computed != recorded: + raise AdmissionEvidenceIntegrityError( + f"authority_evidence[{index}] evidence_digest does not recompute" + ) + + +# --------------------------------------------------------------------------- +# Time +# --------------------------------------------------------------------------- + + +def _instant(value: str, field: str) -> datetime: + """Parse one already-normalized RFC 3339 UTC ``Z`` timestamp. + + No clock, no timezone database, no locale. A timestamp that is not already in the + frozen normalized spelling is refused at the input boundary rather than repaired. + """ + try: + return datetime.strptime(value, _TIMESTAMP_FORMAT).replace(tzinfo=UTC) + except (TypeError, ValueError) as exc: + raise AdmissionTimestampError( + f"{field} is not a normalized RFC 3339 UTC 'Z' instant" + ) from exc + + +def _optional_instant(value: JsonValue, field: str) -> datetime | None: + if value is None: + return None + return _instant(value, field) + + +# --------------------------------------------------------------------------- +# The frozen ordered evaluation +# --------------------------------------------------------------------------- + + +@dataclass(frozen=True, slots=True) +class _Lifecycle: + """The lifecycle facts of one record, already parsed to instants.""" + + effective_from: datetime + effective_until: datetime | None + superseded_at: datetime | None + revoked_at: datetime | None + + def not_yet_effective(self, at: datetime) -> bool: + return at < self.effective_from + + def expired(self, at: datetime) -> bool: + return self.effective_until is not None and at >= self.effective_until + + def superseded(self, at: datetime) -> bool: + return self.superseded_at is not None and at >= self.superseded_at + + def revoked(self, at: datetime) -> bool: + return self.revoked_at is not None and at >= self.revoked_at + + +def _lifecycle(record: Mapping[str, JsonValue], where: str) -> _Lifecycle: + return _Lifecycle( + effective_from=_instant(record["effective_from"], f"{where}.effective_from"), + effective_until=_optional_instant( + record.get("effective_until"), f"{where}.effective_until" + ), + superseded_at=_optional_instant(record.get("superseded_at"), f"{where}.superseded_at"), + revoked_at=_optional_instant(record.get("revoked_at"), f"{where}.revoked_at"), + ) + + +def _covers(record: Mapping[str, JsonValue], jurisdiction: str, applicability: str) -> bool: + """Scope containment, read literally. Nothing is widened, inferred, or defaulted.""" + scope = record["applicability_scope"] + return record["jurisdiction"] == jurisdiction and applicability in scope + + +def _all(items: Iterable[bool]) -> bool: + """``all`` over a non-empty iterable. An empty relevant set never proves a lifecycle + state; the caller has already established that the set is non-empty.""" + values = list(items) + if not values: + raise AdmissionEvaluationError("lifecycle check reached an empty evidence set") + return all(values) + + +@dataclass(frozen=True, slots=True) +class _Evidence: + """One authority-evidence object with its parsed lifecycle facts.""" + + body: Mapping[str, JsonValue] + lifecycle: _Lifecycle + warrant: Mapping[str, JsonValue] + warrant_lifecycle: _Lifecycle + + @property + def authority_basis_ref(self) -> str: + ref: str = self.body["authority_basis_ref"] + return ref + + def binds_version(self, version: str) -> bool: + return bool( + self.body["source_version"] == version and self.warrant["source_version"] == version + ) + + def binds_digest(self, source_digest: str) -> bool: + return bool( + self.body["source_digest"] == source_digest + and self.warrant["source_digest"] == source_digest + ) + + def covers(self, jurisdiction: str, applicability: str) -> bool: + return _covers(self.body, jurisdiction, applicability) and _covers( + self.warrant, jurisdiction, applicability + ) + + def not_yet_effective(self, at: datetime) -> bool: + return self.lifecycle.not_yet_effective(at) or self.warrant_lifecycle.not_yet_effective(at) + + def expired(self, at: datetime) -> bool: + return self.lifecycle.expired(at) or self.warrant_lifecycle.expired(at) + + def superseded(self, at: datetime) -> bool: + return self.lifecycle.superseded(at) + + def revoked(self, at: datetime) -> bool: + return ( + self.lifecycle.revoked(at) + or self.warrant_lifecycle.revoked(at) + or self.warrant["status"] == "REVOKED" + ) + + def operative(self, at: datetime, jurisdiction: str, applicability: str) -> bool: + """True when this evidence and its warrant are, on their face, in force here. + + Deliberately independent of which source version the registration names: an + overlapping authority that speaks to a different version of the same source is + still an authority claim over this evaluation, and the conflict check has to see + it. Nothing here ranks one authority above another. + """ + return ( + self.covers(jurisdiction, applicability) + and not self.not_yet_effective(at) + and not self.expired(at) + and not self.superseded(at) + and not self.revoked(at) + and self.warrant["status"] == "ACTIVE" + ) + + +def _evaluate_state(document: Mapping[str, JsonValue]) -> AdmissionState: + """Return the first terminal state, in the frozen precedence order. + + Checks are written in the ruleset's order and are never reordered, collapsed, or + extended. There is no ALLOW and no DENY. + """ + candidate = document["candidate"] + registration = document["source_registration"] + raw_evidence: Sequence[Mapping[str, JsonValue]] = document["authority_evidence"] + at = _instant(document["evaluation_time"], "evaluation_time") + scope = document["evaluation_scope"] + jurisdiction: str = scope["jurisdiction"] + applicability: str = scope["applicability"] + source_id: str = registration["source_id"] + source_version: str = registration["source_version"] + source_digest: str = registration["source_digest"] + + # 1. Candidate reference check. The candidate is not re-extracted, trimmed, + # classified, or repaired; only its reference to the registered source is checked. + anchors: Sequence[Mapping[str, JsonValue]] = candidate["source_anchors"] + if not anchors: + return AdmissionState.CANDIDATE_INPUT_INVALID + if any(anchor["source_id"] != source_id for anchor in anchors): + return AdmissionState.CANDIDATE_INPUT_INVALID + + # 2-3. Registry availability, then freshness. + observation = registration["registry_observation"] + if observation["availability"] == "UNAVAILABLE": + return AdmissionState.AUTHORITY_REGISTRY_UNAVAILABLE + if observation["availability"] == "AVAILABLE" and observation["freshness"] == "STALE": + return AdmissionState.AUTHORITY_EVIDENCE_STALE + + # 4. Source registration. + if registration["registered"] is False: + return AdmissionState.SOURCE_NOT_REGISTERED + + relevant = tuple( + _Evidence( + body=item, + lifecycle=_lifecycle(item, f"authority_evidence[{index}]"), + warrant=item["admission_warrant"], + warrant_lifecycle=_lifecycle( + item["admission_warrant"], f"authority_evidence[{index}].admission_warrant" + ), + ) + for index, item in enumerate(raw_evidence) + if item["source_id"] == source_id + ) + + # 5. Version binding. Evidence that is present but binds no evidence or warrant to the + # registered version leaves the registered instance unwarranted. + version_bound = tuple(item for item in relevant if item.binds_version(source_version)) + if raw_evidence and not version_bound: + return AdmissionState.SOURCE_VERSION_MISMATCH + + # 6. Digest binding, candidate anchors first. + if any(anchor["content_hash"] != source_digest for anchor in anchors): + return AdmissionState.SOURCE_DIGEST_MISMATCH + bound = tuple(item for item in version_bound if item.binds_digest(source_digest)) + if raw_evidence and not bound: + return AdmissionState.SOURCE_DIGEST_MISMATCH + + # 7. Authority basis and warrant sufficiency. No default authority exists, so an + # absent basis or warrant is never supplied from elsewhere. + if not bound: + return AdmissionState.MISSING_AUTHORITY_EVIDENCE + + # 8. Scope, for the source registration and for the bound evidence and warrants. + if not _covers(registration, jurisdiction, applicability): + return AdmissionState.OUT_OF_SCOPE + scoped = tuple(item for item in bound if item.covers(jurisdiction, applicability)) + if not scoped: + return AdmissionState.OUT_OF_SCOPE + + # 9-12. Temporal lifecycle, in the frozen order. Intervals are half-open. + registration_lifecycle = _lifecycle(registration, "source_registration") + if registration_lifecycle.not_yet_effective(at) or _all( + item.not_yet_effective(at) for item in scoped + ): + return AdmissionState.NOT_YET_EFFECTIVE + if registration_lifecycle.expired(at) or _all(item.expired(at) for item in scoped): + return AdmissionState.EXPIRED + if registration_lifecycle.superseded(at) or _all(item.superseded(at) for item in scoped): + return AdmissionState.SUPERSEDED + if registration_lifecycle.revoked(at) or _all(item.revoked(at) for item in scoped): + return AdmissionState.REVOKED + + # 13. Conflict. All relevant authority records are collected first, then compared. + # The frozen ruleset carries no institutional precedence rule, so two operative + # authority bases over the same evaluation are unresolvable here by construction. + # Recency, rank, order, and version are never used to pick a winner. + operative = tuple(item for item in relevant if item.operative(at, jurisdiction, applicability)) + if len({item.authority_basis_ref for item in operative}) >= _CONFLICT_THRESHOLD: + return AdmissionState.CONFLICTING_AUTHORITY + + # 14. No specific state applies, and no exact operative warrant establishes the + # requested scope and time: a disputed or suspended condition, never a denial. + qualifying = tuple(item for item in scoped if item.operative(at, jurisdiction, applicability)) + if not qualifying: + return AdmissionState.ADMISSION_NOT_ESTABLISHED + + # 15. Eligible for Institutional IR interpretation. Not permission to execute. + return AdmissionState.ADMITTED + + +# --------------------------------------------------------------------------- +# Receipt +# --------------------------------------------------------------------------- + + +@dataclass(frozen=True, slots=True) +class AdmissionReceipt: + """One immutable admission receipt. + + Every field is derived from the accepted input, the frozen ruleset, and the frozen + evaluator identity. No random value, no wall clock, no generated-at timestamp, no + mutable sequence, no host or network metadata participates. + """ + + admission_receipt_id: str + candidate_unit_id: str + candidate_projection_digest: str + source_id: str + source_version: str + source_digest: str + authority_evidence_refs: tuple[str, ...] + authority_evidence_digests: tuple[str, ...] + evaluation_time: str + evaluation_scope: Mapping[str, str] + admission_state: AdmissionState + reason_code: ReasonCode + evaluator_id: str + evaluator_version: str + ruleset_id: str + ruleset_digest: str + input_digest: str + evidence_digest: str + + def to_json(self) -> dict[str, JsonValue]: + """The receipt projection, exactly as the frozen receipt schema requires it.""" + return { + "admission_receipt_id": self.admission_receipt_id, + "candidate_unit_id": self.candidate_unit_id, + "candidate_projection_digest": self.candidate_projection_digest, + "source_id": self.source_id, + "source_version": self.source_version, + "source_digest": self.source_digest, + "authority_evidence_refs": list(self.authority_evidence_refs), + "authority_evidence_digests": list(self.authority_evidence_digests), + "evaluation_time": self.evaluation_time, + "evaluation_scope": dict(self.evaluation_scope), + "admission_state": self.admission_state.value, + "reason_code": self.reason_code.value, + "evaluator_id": self.evaluator_id, + "evaluator_version": self.evaluator_version, + "ruleset_id": self.ruleset_id, + "ruleset_digest": self.ruleset_digest, + "input_digest": self.input_digest, + "evidence_digest": self.evidence_digest, + } + + def canonical_bytes(self) -> bytes: + """Canonical JSON v0.1 of the complete receipt projection.""" + return canonical_json(self.to_json()) + + +def _build_receipt( + document: Mapping[str, JsonValue], payload: bytes, state: AdmissionState +) -> AdmissionReceipt: + evidence: Sequence[Mapping[str, JsonValue]] = document["authority_evidence"] + registration = document["source_registration"] + reason = _REASON_FOR_STATE[state] + projection: dict[str, JsonValue] = { + "candidate_unit_id": document["candidate"]["unit_id"], + "candidate_projection_digest": _digest_of_projection(document["candidate"]), + "source_id": registration["source_id"], + "source_version": registration["source_version"], + "source_digest": registration["source_digest"], + "authority_evidence_refs": [item["evidence_id"] for item in evidence], + "authority_evidence_digests": [item["evidence_digest"] for item in evidence], + "evaluation_time": document["evaluation_time"], + "evaluation_scope": dict(document["evaluation_scope"]), + "admission_state": state.value, + "reason_code": reason.value, + "evaluator_id": EVALUATOR_ID, + "evaluator_version": EVALUATOR_VERSION, + "ruleset_id": RULESET_ID, + "ruleset_digest": RULESET_DIGEST, + # The accepted bytes are canonical by construction, so hashing them and hashing + # their canonical re-serialization are the same value. + "input_digest": digest_of(payload), + "evidence_digest": _digest_of_projection(list(evidence)), + } + receipt_id = f"{_RECEIPT_ID_PREFIX}{_digest_of_projection(projection)}" + complete = {"admission_receipt_id": receipt_id, **projection} + + errors = sorted(_RECEIPT_VALIDATOR.iter_errors(complete), key=lambda error: _pointer(error)) + if errors: + first = errors[0] + raise AdmissionEvaluationError( + f"constructed receipt violates {ADMISSION_RECEIPT_SCHEMA_NAME} at " + f"{_pointer(first) or '#'}: failed keyword {first.validator!r}" + ) + + return AdmissionReceipt( + admission_receipt_id=receipt_id, + candidate_unit_id=projection["candidate_unit_id"], + candidate_projection_digest=projection["candidate_projection_digest"], + source_id=projection["source_id"], + source_version=projection["source_version"], + source_digest=projection["source_digest"], + authority_evidence_refs=tuple(projection["authority_evidence_refs"]), + authority_evidence_digests=tuple(projection["authority_evidence_digests"]), + evaluation_time=projection["evaluation_time"], + evaluation_scope=projection["evaluation_scope"], + admission_state=state, + reason_code=reason, + evaluator_id=EVALUATOR_ID, + evaluator_version=EVALUATOR_VERSION, + ruleset_id=RULESET_ID, + ruleset_digest=RULESET_DIGEST, + input_digest=projection["input_digest"], + evidence_digest=projection["evidence_digest"], + ) + + +# --------------------------------------------------------------------------- +# Public entry point +# --------------------------------------------------------------------------- + + +def evaluate_admission_bytes(input_bytes: bytes) -> AdmissionReceipt: + """Evaluate one executable admission input, supplied as its exact accepted bytes. + + The parameter is bytes and not a parsed object on purpose: encoding, duplicate keys, + canonical form, schema conformance, evidence ordering, evidence integrity, and the + frozen ruleset binding are all properties of the bytes. A caller handed an object + entry point could skip every one of them. + + Returns: + One immutable :class:`AdmissionReceipt` carrying exactly one terminal state. + + Raises: + AdmissionInputBoundaryError: the bytes are not an admissible input. Nothing was + evaluated; this is not ``ADMISSION_NOT_ESTABLISHED`` and must not be + recorded as an admission outcome. + AdmissionSpecificationError: a packaged frozen specification is not intact. + AdmissionEvaluationError: a defect in this evaluator. + """ + payload = bytes(input_bytes) if isinstance(input_bytes, bytes | bytearray) else input_bytes + document = _decode(payload) + _require_canonical(document, payload) + _require_schema_valid(document) + _require_frozen_ruleset(document) + _require_evidence_integrity(document["authority_evidence"]) + + try: + state = _evaluate_state(document) + except AdmissionError: + # Input-boundary and specification failures stay in their own class. + raise + except Exception as exc: + # An unexpected defect must not become a valid institutional receipt. + raise AdmissionEvaluationError( + f"admission evaluation failed unexpectedly: {type(exc).__name__}" + ) from exc + + return _build_receipt(document, payload, state) diff --git a/src/oic/admission_specs/ADMISSION-INPUT-v0.1.schema.json b/src/oic/admission_specs/ADMISSION-INPUT-v0.1.schema.json new file mode 100644 index 0000000..e5d4244 --- /dev/null +++ b/src/oic/admission_specs/ADMISSION-INPUT-v0.1.schema.json @@ -0,0 +1,323 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://openinstitutionalcompiler.org/design/admission-boundary-001/ADMISSION-INPUT-v0.1.schema.json", + "title": "Admission Boundary 001 Executable Input", + "description": "Exact design-only input object for a future deterministic admission evaluator. This schema implements no evaluator and confers no authority.", + "type": "object", + "additionalProperties": false, + "required": [ + "candidate", + "source_registration", + "authority_evidence", + "evaluation_time", + "evaluation_scope", + "evaluator", + "ruleset" + ], + "properties": { + "candidate": { + "$ref": "#/$defs/candidate_projection" + }, + "source_registration": { + "$ref": "#/$defs/source_registration" + }, + "authority_evidence": { + "type": "array", + "description": "Stored in ascending (evidence_id, evidence_digest) order. Empty is explicit missing evidence; no default warrant exists.", + "items": { + "$ref": "https://openinstitutionalcompiler.org/design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json" + } + }, + "evaluation_time": { + "$ref": "#/$defs/timestamp" + }, + "evaluation_scope": { + "type": "object", + "additionalProperties": false, + "required": [ + "jurisdiction", + "applicability" + ], + "properties": { + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability": { + "type": "string", + "minLength": 1 + } + } + }, + "evaluator": { + "type": "object", + "additionalProperties": false, + "required": [ + "evaluator_id", + "evaluator_version" + ], + "properties": { + "evaluator_id": { + "const": "oic-admission-reference-evaluator" + }, + "evaluator_version": { + "const": "0.1-preregistered" + } + } + }, + "ruleset": { + "type": "object", + "additionalProperties": false, + "required": [ + "ruleset_id", + "ruleset_digest" + ], + "properties": { + "ruleset_id": { + "const": "OIC-ADMISSION-BOUNDARY-001" + }, + "ruleset_digest": { + "$ref": "#/$defs/sha256" + } + } + } + }, + "$defs": { + "sha256": { + "type": "string", + "pattern": "^sha256:[0-9a-f]{64}$" + }, + "timestamp": { + "type": "string", + "format": "date-time", + "pattern": "Z$" + }, + "nullable_timestamp": { + "oneOf": [ + { + "$ref": "#/$defs/timestamp" + }, + { + "type": "null" + } + ] + }, + "source_anchor_projection": { + "type": "object", + "additionalProperties": false, + "required": [ + "anchor_id", + "source_id", + "node_id", + "quote", + "page", + "bbox", + "content_hash" + ], + "properties": { + "anchor_id": { + "type": "string", + "minLength": 1 + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "node_id": { + "type": "string", + "minLength": 1 + }, + "quote": { + "type": "string", + "minLength": 1 + }, + "page": { + "type": [ + "integer", + "null" + ] + }, + "bbox": { + "oneOf": [ + { + "type": "array", + "items": { + "type": "number" + } + }, + { + "type": "null" + } + ] + }, + "content_hash": { + "$ref": "#/$defs/sha256" + } + } + }, + "candidate_projection": { + "type": "object", + "description": "Untrusted serialized Candidate Normative Unit projection. source_anchors permits zero items so CANDIDATE_INPUT_INVALID remains representable as a schema-valid boundary input.", + "additionalProperties": false, + "required": [ + "unit_id", + "candidate_span", + "unit_type", + "interpretation_state", + "epistemic_state", + "source_anchors" + ], + "properties": { + "unit_id": { + "type": "string", + "pattern": "^cnu-[0-9a-f]{24}$" + }, + "candidate_span": { + "type": "string", + "minLength": 1 + }, + "unit_type": { + "description": "Provisional model-proposed type. It is never an authority-bearing field.", + "enum": [ + "definition", + "mandate", + "delegation", + "obligation", + "prohibition", + "permission", + "power", + "condition", + "exception", + "evidence_duty", + "review_duty", + "escalation", + "remedy", + "temporal_trigger", + "discretion", + "advisory" + ] + }, + "interpretation_state": { + "const": "extracted" + }, + "epistemic_state": { + "const": "uncertain" + }, + "source_anchors": { + "type": "array", + "items": { + "$ref": "#/$defs/source_anchor_projection" + } + } + } + }, + "source_registration": { + "type": "object", + "description": "Institution-controlled source and registry observation consumed at the authenticated registry seam; the JSON value does not itself authenticate the seam.", + "additionalProperties": false, + "required": [ + "source_id", + "source_version", + "source_digest", + "registered", + "registry_observation", + "source_standing", + "jurisdiction", + "applicability_scope", + "adopted_at", + "published_at", + "effective_from", + "effective_until", + "superseded_at", + "revoked_at" + ], + "properties": { + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "registered": { + "type": "boolean" + }, + "registry_observation": { + "type": "object", + "additionalProperties": false, + "required": [ + "registry_boundary_id", + "observation_id", + "availability", + "freshness" + ], + "properties": { + "registry_boundary_id": { + "const": "institution-controlled-authority-registry" + }, + "observation_id": { + "type": "string", + "minLength": 1 + }, + "availability": { + "enum": [ + "AVAILABLE", + "UNAVAILABLE" + ] + }, + "freshness": { + "enum": [ + "FRESH", + "STALE", + "NOT_OBSERVED" + ] + } + } + }, + "source_standing": { + "enum": [ + "ADOPTED", + "DRAFT", + "COMMENTARY", + "UNKNOWN" + ] + }, + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability_scope": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "adopted_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "published_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "effective_from": { + "$ref": "#/$defs/timestamp" + }, + "effective_until": { + "$ref": "#/$defs/nullable_timestamp" + }, + "superseded_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "revoked_at": { + "$ref": "#/$defs/nullable_timestamp" + } + } + } + } +} diff --git a/src/oic/admission_specs/ADMISSION-RECEIPT-v0.1.schema.json b/src/oic/admission_specs/ADMISSION-RECEIPT-v0.1.schema.json new file mode 100644 index 0000000..c1cd236 --- /dev/null +++ b/src/oic/admission_specs/ADMISSION-RECEIPT-v0.1.schema.json @@ -0,0 +1,184 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://openinstitutionalcompiler.org/design/admission-boundary-001/ADMISSION-RECEIPT-v0.1.schema.json", + "title": "Admission Boundary 001 Receipt (design draft)", + "description": "Design-only immutable deterministic admission outcome; not an implemented runtime schema.", + "type": "object", + "additionalProperties": false, + "required": [ + "admission_receipt_id", + "candidate_unit_id", + "candidate_projection_digest", + "source_id", + "source_version", + "source_digest", + "authority_evidence_refs", + "authority_evidence_digests", + "evaluation_time", + "evaluation_scope", + "admission_state", + "reason_code", + "evaluator_id", + "evaluator_version", + "ruleset_id", + "ruleset_digest", + "input_digest", + "evidence_digest" + ], + "properties": { + "admission_receipt_id": { + "type": "string", + "pattern": "^admrec-sha256:[0-9a-f]{64}$" + }, + "candidate_unit_id": { + "type": "string", + "minLength": 1 + }, + "candidate_projection_digest": { + "$ref": "#/$defs/sha256" + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "authority_evidence_refs": { + "type": "array", + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "authority_evidence_digests": { + "type": "array", + "uniqueItems": true, + "items": { + "$ref": "#/$defs/sha256" + } + }, + "evaluation_time": { + "$ref": "#/$defs/timestamp" + }, + "evaluation_scope": { + "type": "object", + "additionalProperties": false, + "required": [ + "jurisdiction", + "applicability" + ], + "properties": { + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability": { + "type": "string", + "minLength": 1 + } + } + }, + "admission_state": { + "enum": [ + "ADMITTED", + "CANDIDATE_INPUT_INVALID", + "SOURCE_NOT_REGISTERED", + "SOURCE_VERSION_MISMATCH", + "SOURCE_DIGEST_MISMATCH", + "MISSING_AUTHORITY_EVIDENCE", + "NOT_YET_EFFECTIVE", + "EXPIRED", + "SUPERSEDED", + "REVOKED", + "OUT_OF_SCOPE", + "CONFLICTING_AUTHORITY", + "AUTHORITY_REGISTRY_UNAVAILABLE", + "AUTHORITY_EVIDENCE_STALE", + "ADMISSION_NOT_ESTABLISHED" + ] + }, + "reason_code": { + "enum": [ + "OIC-ADM-0000", + "OIC-ADM-1001", + "OIC-ADM-1002", + "OIC-ADM-1003", + "OIC-ADM-1004", + "OIC-ADM-1005", + "OIC-ADM-1006", + "OIC-ADM-1007", + "OIC-ADM-1008", + "OIC-ADM-1009", + "OIC-ADM-1010", + "OIC-ADM-1011", + "OIC-ADM-1012", + "OIC-ADM-1013", + "OIC-ADM-1099" + ] + }, + "evaluator_id": { + "type": "string", + "minLength": 1 + }, + "evaluator_version": { + "type": "string", + "minLength": 1 + }, + "ruleset_id": { + "const": "OIC-ADMISSION-BOUNDARY-001" + }, + "ruleset_digest": { + "$ref": "#/$defs/sha256" + }, + "input_digest": { + "$ref": "#/$defs/sha256" + }, + "evidence_digest": { + "$ref": "#/$defs/sha256" + } + }, + "allOf": [ + { + "if": { + "properties": { + "admission_state": { + "const": "ADMITTED" + } + }, + "required": [ + "admission_state" + ] + }, + "then": { + "properties": { + "reason_code": { + "const": "OIC-ADM-0000" + }, + "authority_evidence_refs": { + "minItems": 1 + }, + "authority_evidence_digests": { + "minItems": 1 + } + } + } + } + ], + "$defs": { + "sha256": { + "type": "string", + "pattern": "^sha256:[0-9a-f]{64}$" + }, + "timestamp": { + "type": "string", + "format": "date-time", + "pattern": "Z$" + } + } +} diff --git a/src/oic/admission_specs/AUTHORITY-EVIDENCE-v0.1.schema.json b/src/oic/admission_specs/AUTHORITY-EVIDENCE-v0.1.schema.json new file mode 100644 index 0000000..2172a49 --- /dev/null +++ b/src/oic/admission_specs/AUTHORITY-EVIDENCE-v0.1.schema.json @@ -0,0 +1,194 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://openinstitutionalcompiler.org/design/admission-boundary-001/AUTHORITY-EVIDENCE-v0.1.schema.json", + "title": "Admission Boundary 001 Authority Evidence (design draft)", + "description": "Design-only minimum machine-verifiable authority and admission-warrant evidence; not an implemented runtime schema.", + "type": "object", + "additionalProperties": false, + "required": [ + "evidence_id", + "evidence_digest", + "issued_at", + "source_id", + "source_version", + "source_digest", + "issuer_id", + "authority_basis_ref", + "jurisdiction", + "applicability_scope", + "source_standing", + "adopted_at", + "effective_from", + "effective_until", + "superseded_at", + "revoked_at", + "admission_warrant" + ], + "properties": { + "evidence_id": { + "type": "string", + "minLength": 1 + }, + "evidence_digest": { + "$ref": "#/$defs/sha256" + }, + "issued_at": { + "$ref": "#/$defs/timestamp" + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "issuer_id": { + "type": "string", + "minLength": 1 + }, + "authority_basis_ref": { + "type": "string", + "minLength": 1 + }, + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability_scope": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "source_standing": { + "enum": [ + "ADOPTED", + "DRAFT", + "COMMENTARY", + "UNKNOWN" + ] + }, + "adopted_at": { + "oneOf": [ + { + "$ref": "#/$defs/timestamp" + }, + { + "type": "null" + } + ] + }, + "effective_from": { + "$ref": "#/$defs/timestamp" + }, + "effective_until": { + "$ref": "#/$defs/nullable_timestamp" + }, + "superseded_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "revoked_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "admission_warrant": { + "type": "object", + "additionalProperties": false, + "required": [ + "warrant_id", + "admission_authority_id", + "delegation_basis_ref", + "source_id", + "source_version", + "source_digest", + "jurisdiction", + "applicability_scope", + "effective_from", + "effective_until", + "revoked_at", + "status" + ], + "properties": { + "warrant_id": { + "type": "string", + "minLength": 1 + }, + "admission_authority_id": { + "type": "string", + "minLength": 1 + }, + "delegation_basis_ref": { + "type": "string", + "minLength": 1 + }, + "source_id": { + "type": "string", + "minLength": 1 + }, + "source_version": { + "type": "string", + "minLength": 1 + }, + "source_digest": { + "$ref": "#/$defs/sha256" + }, + "jurisdiction": { + "type": "string", + "minLength": 1 + }, + "applicability_scope": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "minLength": 1 + } + }, + "effective_from": { + "$ref": "#/$defs/timestamp" + }, + "effective_until": { + "$ref": "#/$defs/nullable_timestamp" + }, + "revoked_at": { + "$ref": "#/$defs/nullable_timestamp" + }, + "status": { + "enum": [ + "ACTIVE", + "SUSPENDED", + "REVOKED" + ] + } + } + } + }, + "$defs": { + "sha256": { + "type": "string", + "pattern": "^sha256:[0-9a-f]{64}$" + }, + "timestamp": { + "type": "string", + "format": "date-time", + "pattern": "Z$" + }, + "nullable_timestamp": { + "oneOf": [ + { + "$ref": "#/$defs/timestamp" + }, + { + "type": "null" + } + ] + } + } +} diff --git a/src/oic/admission_specs/STATE-INPUT-MAPPING-v0.1.json b/src/oic/admission_specs/STATE-INPUT-MAPPING-v0.1.json new file mode 100644 index 0000000..13e985b --- /dev/null +++ b/src/oic/admission_specs/STATE-INPUT-MAPPING-v0.1.json @@ -0,0 +1,116 @@ +{ + "mapping_id": "OIC-ADMISSION-BOUNDARY-001-STATE-INPUT-MAPPING-v0.1", + "ruleset_id": "OIC-ADMISSION-BOUNDARY-001", + "first_terminal_state_wins": true, + "entries": [ + { + "precedence": 1, + "state": "CANDIDATE_INPUT_INVALID", + "reason_code": "OIC-ADM-1001", + "observable_fields": ["candidate.unit_id", "candidate.candidate_span", "candidate.source_anchors"], + "required_observable_facts": "Candidate identity/span is invalid, source_anchors is empty, or an anchor is inconsistent with source_registration." + }, + { + "precedence": 2, + "state": "AUTHORITY_REGISTRY_UNAVAILABLE", + "reason_code": "OIC-ADM-1012", + "observable_fields": ["source_registration.registry_observation.availability"], + "required_observable_facts": "availability equals UNAVAILABLE." + }, + { + "precedence": 3, + "state": "AUTHORITY_EVIDENCE_STALE", + "reason_code": "OIC-ADM-1013", + "observable_fields": ["source_registration.registry_observation.freshness"], + "required_observable_facts": "availability equals AVAILABLE and freshness equals STALE." + }, + { + "precedence": 4, + "state": "SOURCE_NOT_REGISTERED", + "reason_code": "OIC-ADM-1002", + "observable_fields": ["source_registration.registered"], + "required_observable_facts": "registered equals false." + }, + { + "precedence": 5, + "state": "SOURCE_VERSION_MISMATCH", + "reason_code": "OIC-ADM-1003", + "observable_fields": ["source_registration.source_version", "authority_evidence[].source_version", "authority_evidence[].admission_warrant.source_version"], + "required_observable_facts": "At least one applicable evidence or warrant version differs from source_registration.source_version." + }, + { + "precedence": 6, + "state": "SOURCE_DIGEST_MISMATCH", + "reason_code": "OIC-ADM-1004", + "observable_fields": ["candidate.source_anchors[].content_hash", "source_registration.source_digest", "authority_evidence[].source_digest", "authority_evidence[].admission_warrant.source_digest"], + "required_observable_facts": "Any applicable candidate anchor, evidence, or warrant digest differs from source_registration.source_digest." + }, + { + "precedence": 7, + "state": "MISSING_AUTHORITY_EVIDENCE", + "reason_code": "OIC-ADM-1005", + "observable_fields": ["authority_evidence", "authority_evidence[].authority_basis_ref", "authority_evidence[].admission_warrant"], + "required_observable_facts": "authority_evidence is empty or no complete applicable authority basis and admission warrant exists." + }, + { + "precedence": 8, + "state": "OUT_OF_SCOPE", + "reason_code": "OIC-ADM-1010", + "observable_fields": ["evaluation_scope", "source_registration.jurisdiction", "source_registration.applicability_scope", "authority_evidence[].jurisdiction", "authority_evidence[].applicability_scope", "authority_evidence[].admission_warrant.jurisdiction", "authority_evidence[].admission_warrant.applicability_scope"], + "required_observable_facts": "The requested jurisdiction or applicability is absent from the source, evidence, or warrant scope." + }, + { + "precedence": 9, + "state": "NOT_YET_EFFECTIVE", + "reason_code": "OIC-ADM-1006", + "observable_fields": ["evaluation_time", "source_registration.effective_from", "authority_evidence[].effective_from", "authority_evidence[].admission_warrant.effective_from"], + "required_observable_facts": "evaluation_time precedes any applicable required effective_from." + }, + { + "precedence": 10, + "state": "EXPIRED", + "reason_code": "OIC-ADM-1007", + "observable_fields": ["evaluation_time", "source_registration.effective_until", "authority_evidence[].effective_until", "authority_evidence[].admission_warrant.effective_until"], + "required_observable_facts": "evaluation_time is at or after any applicable non-null effective_until." + }, + { + "precedence": 11, + "state": "SUPERSEDED", + "reason_code": "OIC-ADM-1008", + "observable_fields": ["evaluation_time", "source_registration.superseded_at", "authority_evidence[].superseded_at"], + "required_observable_facts": "evaluation_time is at or after an applicable non-null superseded_at." + }, + { + "precedence": 12, + "state": "REVOKED", + "reason_code": "OIC-ADM-1009", + "observable_fields": ["evaluation_time", "source_registration.revoked_at", "authority_evidence[].revoked_at", "authority_evidence[].admission_warrant.revoked_at", "authority_evidence[].admission_warrant.status"], + "required_observable_facts": "Applicable source/evidence/warrant is REVOKED or evaluation_time is at or after a non-null revoked_at." + }, + { + "precedence": 13, + "state": "CONFLICTING_AUTHORITY", + "reason_code": "OIC-ADM-1011", + "observable_fields": ["authority_evidence[].evidence_id", "authority_evidence[].authority_basis_ref", "authority_evidence[].admission_warrant.warrant_id", "ruleset.ruleset_digest"], + "required_observable_facts": "Two or more applicable evidence objects conflict and the frozen ruleset contains no unique institutional precedence resolution." + }, + { + "precedence": 14, + "state": "ADMISSION_NOT_ESTABLISHED", + "reason_code": "OIC-ADM-1099", + "observable_fields": ["authority_evidence[].source_standing", "authority_evidence[].admission_warrant.status"], + "required_observable_facts": "An otherwise unclassified disputed or suspended authority condition prevents a positive finding and no earlier specific state applies." + }, + { + "precedence": 15, + "state": "ADMITTED", + "reason_code": "OIC-ADM-0000", + "observable_fields": ["candidate", "source_registration", "authority_evidence", "evaluation_time", "evaluation_scope", "evaluator", "ruleset"], + "required_observable_facts": "All prior checks pass and at least one complete active evidence object and exact admission warrant establish the requested scope and time." + } + ], + "runtime_permission_states": [], + "successor_ir_state": "ADMITTED", + "independent_validation_claim": false, + "self_adjudication": "NOT SELF-ADJUDICATED" +} diff --git a/src/oic/admission_specs/__init__.py b/src/oic/admission_specs/__init__.py new file mode 100644 index 0000000..2e00ef5 --- /dev/null +++ b/src/oic/admission_specs/__init__.py @@ -0,0 +1,11 @@ +"""Byte-identical runtime copies of the frozen Admission Boundary 001 specifications. + +These files are data, not code. Each is a byte-for-byte copy of its original under +``design/admission-boundary-001/``; ``oic.admission`` verifies that identity is what the +frozen ruleset digest attests, and the contract suite asserts the bytes still match. +They are packaged so the evaluator runs from an installed wheel without the design tree. +""" + +from __future__ import annotations + +__all__: list[str] = [] diff --git a/src/oic/candidate_extraction.py b/src/oic/candidate_extraction.py new file mode 100644 index 0000000..c779e16 --- /dev/null +++ b/src/oic/candidate_extraction.py @@ -0,0 +1,381 @@ +"""Minimal, source-grounded discovery of candidate normative material. + +OIC-CANDIDATE-SEMANTICS-003 gives the model only ``candidate_span`` and provisional +``unit_type``. Semantic-role decomposition is not a pre-admission responsibility. +Identity, state, and source anchoring remain deterministic OIC outputs. Nothing here +admits, authorizes, or constructs Institutional IR. + +OIC-CANDIDATE-SEMANTICS-004 changes the prompt contract only. The schema, the parser, the +fail-closed grounding rule and the deterministic identity material are all unchanged. What +004 adds is a quoting rule: the span should hold the normative proposition, not the +source's separable commentary about that proposition's own status. A fragment that marks +itself a draft, a hypothetical, an illustration or an unverified extract is still saying +something normative, and the framing is source context rather than part of what is said. + +Framing separation is asked of the provider and is never imposed afterwards. There is no +phrase list, no regex, no post-generation trimming, and no repair anywhere in this module: +a span that carries framing is accepted exactly as returned and recorded as an +observation. The alternative -- stripping recognized prefixes -- would make OIC the author +of the span it then reports as source-grounded. + +Excluding framing is a quoting decision, not a finding about the source. It decides +nothing about whether the proposition is authoritative, adopted, valid, admitted, +enforceable, or legally operative, and the source anchor keeps the framing either way. + +OIC-CANDIDATE-SEMANTICS-005 corrects one reproducible discovery defect and changes nothing +else. A frozen A/B against the 003 prompt found 004 returning a candidate for prose that +merely describes institutional structures -- registers, calendars, a governance framework -- +and typing it advisory. Institutional subject matter had become sufficient for discovery. +The prompt now says plainly that it is not, that description and reporting yield no +candidates whatever institutional vocabulary they carry, and that the test is what a +proposition does rather than which words it uses. + +The correction is a prompt contract and nothing else. There is no keyword list, no +institutional-vocabulary blacklist, no deterministic negative filter, no secondary +classifier, and no post-generation removal of candidates anywhere in this module: a +descriptive fragment the provider still reports is recorded as returned and measured. A +filter would let OIC decide what counts as normative, which is precisely the judgement this +layer is not entitled to make. +""" + +from __future__ import annotations + +import hashlib +import json +import re +from dataclasses import dataclass +from typing import Any + +from oic.model_provider import JsonObject, ModelProvider, ModelProviderError, ModelRequest + +_UNIT_TYPES: tuple[str, ...] = ( + "definition", + "mandate", + "delegation", + "obligation", + "prohibition", + "permission", + "power", + "condition", + "exception", + "evidence_duty", + "review_duty", + "escalation", + "remedy", + "temporal_trigger", + "discretion", + "advisory", +) +_ALLOWED_UNIT_TYPES = frozenset(_UNIT_TYPES) +_UNIT_TYPE_LIST = ", ".join(_UNIT_TYPES) +_MODEL_ALLOWED_KEYS = frozenset({"candidate_span", "unit_type"}) +_REMOVED_SEMANTIC_ROLE_KEYS = frozenset( + {"actor", "action", "object", "target", "conditions", "exceptions", "evidence_requirements"} +) +_MODEL_FORBIDDEN_AUTHORITY_KEYS = frozenset( + { + "unit_id", + "interpretation_state", + "epistemic_state", + "lifecycle_state", + "confidence", + "source_anchors", + "admission", + "admitted", + "authority", + "authorization", + "enforceability", + "legal_effect", + "verdict", + "allow", + "deny", + "runtime_outcome", + "institutional_ir", + "institutional_ir_state", + } +) +_SOURCE_ANCHOR_REQUIRED_KEYS = frozenset({"anchor_id", "source_id", "node_id", "content_hash"}) +_SOURCE_ANCHOR_ALLOWED_KEYS = frozenset( + {"anchor_id", "source_id", "node_id", "quote", "page", "bbox", "content_hash"} +) +_SHA256_PATTERN = re.compile(r"^sha256:[0-9a-f]{64}$") + +_SYSTEM_PROMPT = f"""You are a bounded extraction worker inside the Open Institutional Compiler. + +Find source-grounded normative propositions. A candidate is only material that appears to +express one apparent normative function from this provisional vocabulary: +{_UNIT_TYPE_LIST}. + +Institutional subject matter is not by itself normative. A fragment that only says something +exists, sits somewhere, happened, contains something, explains or describes something, +maintains an artifact, summarizes a structure, reports past activity, or advertises a +capability is not candidate material, however much governance, compliance, policy, +delegation, oversight, register, framework, committee, procedure or office vocabulary it +carries. Institutional nouns do not create normativity. If nothing in the fragment performs +an apparent normative or constitutive function, return no candidates. + +Do not look for particular words either. Normative function needs no must, shall, may or +should: a proposition can require, prohibit, permit, authorize, delegate, fix what a term +means, set a condition or exception, impose an evidence or review duty, prescribe +escalation or remedy, establish a temporal trigger, confer discretion, or genuinely +recommend, without any of those modals. Ask what the proposition does, not which words it +uses. + +Two distinctions this turns on. A definition is candidate material when it is constitutive +or operative, fixing what a term means for some stated purpose, and not when it merely +explains what a concept is about. Advisory is candidate material when the fragment actually +recommends or encourages a course of action, and not when it merely discusses guidance, +standards, or good practice. + +Three short contrasts, worded to match no fragment you will be given: + The standards office maintains a register of accredited laboratories and issues a monthly + bulletin. -> no candidates. It reports what an office does and names no requirement, + permission, prohibition, or definition. + Sites are encouraged to rotate on-call duty between qualified staff. -> a candidate. It + actually recommends a course of action. + For this schedule, 'Accredited Laboratory' means a laboratory listed in the register. -> + a candidate. It fixes what a term means for a stated purpose. + +Return a literal, contiguous candidate_span copied from the source. Include enough +surrounding source language to preserve the material proposition and every material +qualifier needed to understand it, including conditions, thresholds, time limits, +exceptions, recipients, and trigger/consequence language. Do not rewrite, normalize, +summarize, paraphrase, complete, or infer. Passive voice does not require actor inference: +preserve the proposition as source text. If the fragment contains two independently +meaningful normative propositions, return two source-grounded candidate spans. + +Quote the proposition, not the source's commentary about the proposition. Where the +fragment separately marks its own status as a draft, a proposal, a hypothetical, an +illustration, an example, a quotation of another party, or as unadopted, unverified or +non-authoritative, and that marking is grammatically separable from the proposition, leave +it outside the span. Framing that is itself part of what the proposition says stays in: +a circumstance the rule applies to governs conduct and belongs in the span. + +Never buy a shorter span with material content. Every threshold, amount, deadline, +condition, exception, recipient, prohibition, advisory wording, trigger and consequence +stays inside the span. Dropping material content is a worse error than including framing. + +Worked example, worded so it matches no fragment you will be given: + Fragment: INTERNAL WORKING TEXT - SUPERSEDED. Each grant over 5,000 euro must be + countersigned by the Programme Director. + Correct span: Each grant over 5,000 euro must be countersigned by the Programme + Director. + Over-extraction: the whole fragment, carrying INTERNAL WORKING TEXT - SUPERSEDED. + Under-extraction: must be countersigned, which loses the amount and the role. + +unit_type is the only classification and the only proposed field that need not occur in +the source. It is provisional and epistemically uncertain. Advisory language remains +candidate material when supported by the source. + +Source standing is not a discovery criterion. Draft, hypothetical, synthetic, unverified, +and non-authoritative framing must not suppress a candidate that appears in the fragment. +Leaving that framing outside the span is a quoting decision and not a finding: it does not +decide whether the proposition is authoritative, adopted, valid, admitted, enforceable, or +legally operative. The source anchor keeps the framing. + +Candidate material has no institutional authority. Do not decide or propose admission, +authority, authorization, enforceability, legal effect, runtime outcome, allow, deny, +confidence as an admission proxy, or Institutional IR state. Do not assign semantic roles +such as actor, action, object, target, conditions, exceptions, or evidence requirements. +Return only the requested JSON object.""" + + +class CandidateBoundaryError(ModelProviderError): + """Provider output crossed the minimal candidate boundary.""" + + +class CandidateGroundingError(CandidateBoundaryError): + """A proposed candidate span is not literal source material.""" + + +@dataclass(frozen=True, slots=True) +class CandidateExtractionResult: + """Candidate material plus provider provenance; never an admitted record.""" + + candidates: tuple[JsonObject, ...] + source_anchor: JsonObject + provider: str + model: str + request_id: str | None + raw_content_sha256: str + + +def _grounding_key(value: str) -> str: + """Case-fold and collapse whitespace for comparison without rewriting output.""" + return " ".join(value.split()).casefold() + + +def check_source_grounding(item: JsonObject, *, source_text: str, index: int = 0) -> None: + """Require a nonblank literal contiguous span; never repair or fuzz-match.""" + value = item.get("candidate_span") + if not isinstance(value, str): + raise CandidateBoundaryError("candidate field candidate_span must be a string") + if not value.strip(): + raise CandidateGroundingError(f"candidate {index} field candidate_span is blank") + if _grounding_key(value) not in _grounding_key(source_text): + raise CandidateGroundingError( + f"candidate {index} field candidate_span is not a literal contiguous span " + f"of the source fragment: {value!r}" + ) + + +def propose_candidate_units( + *, source_text: str, source_anchor: JsonObject, provider: ModelProvider +) -> CandidateExtractionResult: + """Request minimal candidates and enforce the fail-closed boundary.""" + if not source_text.strip(): + raise ValueError("source_text must not be empty") + _validate_source_anchor(source_anchor) + request = ModelRequest( + system_prompt=_SYSTEM_PROMPT, + user_prompt=( + "Extract zero or more source-grounded candidate normative propositions from " + "this exact source fragment. Source standing does not suppress discovery.\n" + "Institutional subject matter alone is not a normative proposition: " + "description, explanation and reporting produce zero candidates unless the " + "fragment itself requires, permits, prohibits, authorizes, delegates, fixes " + "what a term means, sets a condition or exception, or genuinely " + "recommends.\n\n" + "Return exactly one JSON object with exactly one top-level key named " + "candidates. Use exactly this envelope:\n" + '{"candidates":[{"candidate_span":"...","unit_type":"..."}]}\n' + 'For zero candidates, return exactly {"candidates":[]}. Never return a ' + "candidate directly at the JSON root. Never add another root key.\n\n" + "Each candidate must have exactly these two keys: candidate_span and unit_type. " + "candidate_span must be one literal, contiguous source span preserving the " + "complete material proposition and its material qualifiers; do not paraphrase, " + "repair, infer, or split qualifiers into semantic roles. Leave out separable " + "framing that states the source's own status - draft, proposal, hypothetical, " + "illustration, attribution, unverified, non-authoritative - rather than forming " + "part of the proposition, and never drop material proposition content in order " + "to do so. unit_type is an " + "uncertain provisional classification and need not be source text. " + f"Choose the closest of: {_UNIT_TYPE_LIST}.\n\n" + "Never emit actor, action, object, target, conditions, exceptions, or " + "evidence_requirements. Never emit unit_id, interpretation_state, " + "epistemic_state, lifecycle_state, confidence, source_anchors, admission, " + "admitted, authority, authorization, enforceability, legal_effect, verdict, " + "allow, deny, runtime_outcome, institutional_ir, or institutional_ir_state.\n\n" + f"SOURCE FRAGMENT:\n{source_text}" + ), + response_format={"type": "json_object"}, + temperature=0.0, + max_tokens=4096, + ) + response = provider.complete(request) + payload = _parse_provider_json(response.content) + normalized = tuple( + _normalize_candidate(item, source_anchor=source_anchor, source_text=source_text, index=i) + for i, item in enumerate(_candidate_items(payload)) + ) + return CandidateExtractionResult( + candidates=normalized, + source_anchor=dict(source_anchor), + provider=response.provider, + model=response.model, + request_id=response.request_id, + raw_content_sha256=hashlib.sha256(response.content.encode()).hexdigest(), + ) + + +def _validate_source_anchor(anchor: JsonObject) -> None: + missing = _SOURCE_ANCHOR_REQUIRED_KEYS - set(anchor) + if missing: + raise ValueError(f"source_anchor missing required fields: {sorted(missing)}") + unexpected = set(anchor) - _SOURCE_ANCHOR_ALLOWED_KEYS + if unexpected: + raise ValueError(f"source_anchor has unexpected fields: {sorted(unexpected)}") + for key in ("anchor_id", "source_id", "node_id"): + value = anchor.get(key) + if not isinstance(value, str) or not value.strip(): + raise ValueError(f"source_anchor field {key} must be a non-empty string") + content_hash = anchor.get("content_hash") + if not isinstance(content_hash, str) or _SHA256_PATTERN.fullmatch(content_hash) is None: + raise ValueError("source_anchor content_hash must be sha256:<64 lowercase hex>") + quote = anchor.get("quote") + if quote is not None and not isinstance(quote, str): + raise ValueError("source_anchor quote must be a string when present") + page = anchor.get("page") + if page is not None and (not isinstance(page, int) or isinstance(page, bool)): + raise ValueError("source_anchor page must be an integer or null") + bbox = anchor.get("bbox") + if bbox is not None and ( + not isinstance(bbox, list) + or any(not isinstance(value, int | float) or isinstance(value, bool) for value in bbox) + ): + raise ValueError("source_anchor bbox must be an array of numbers or null") + + +def _parse_provider_json(content: str) -> JsonObject: + try: + parsed: Any = json.loads(content) + except json.JSONDecodeError as exc: + raise CandidateBoundaryError("provider candidate output is not valid JSON") from exc + if not isinstance(parsed, dict): + raise CandidateBoundaryError("provider candidate output root must be an object") + extra_root = set(parsed) - {"candidates"} + if extra_root: + raise CandidateBoundaryError( + f"provider candidate output has unexpected root keys: {sorted(extra_root)}" + ) + return parsed + + +def _candidate_items(payload: JsonObject) -> tuple[JsonObject, ...]: + value = payload.get("candidates") + if not isinstance(value, list): + raise CandidateBoundaryError("provider candidate output must contain a candidates array") + if any(not isinstance(item, dict) for item in value): + raise CandidateBoundaryError("every candidate must be an object") + return tuple(value) + + +def _normalize_candidate( + item: JsonObject, *, source_anchor: JsonObject, source_text: str, index: int +) -> JsonObject: + forbidden = set(item) & _MODEL_FORBIDDEN_AUTHORITY_KEYS + if forbidden: + raise CandidateBoundaryError( + f"provider attempted to emit authority-controlled candidate fields: {sorted(forbidden)}" + ) + removed = set(item) & _REMOVED_SEMANTIC_ROLE_KEYS + if removed: + raise CandidateBoundaryError( + f"provider emitted removed semantic-role fields outside the 003 candidate " + f"contract: {sorted(removed)}" + ) + unexpected = set(item) - _MODEL_ALLOWED_KEYS + if unexpected: + raise CandidateBoundaryError( + f"provider emitted unexpected candidate fields: {sorted(unexpected)}" + ) + if set(item) != _MODEL_ALLOWED_KEYS: + raise CandidateBoundaryError( + f"candidate is missing required fields: {sorted(_MODEL_ALLOWED_KEYS - set(item))}" + ) + unit_type = item.get("unit_type") + if not isinstance(unit_type, str) or unit_type not in _ALLOWED_UNIT_TYPES: + raise CandidateBoundaryError(f"invalid candidate unit_type: {unit_type!r}") + check_source_grounding(item, source_text=source_text, index=index) + span = item["candidate_span"] + if not isinstance(span, str): # defensive type narrowing; grounding already checked it + raise CandidateBoundaryError("candidate field candidate_span must be a string") + semantic: JsonObject = {"candidate_span": span, "unit_type": unit_type} + return { + "unit_id": _candidate_id(semantic=semantic, source_anchor=source_anchor), + **semantic, + "interpretation_state": "extracted", + "epistemic_state": "uncertain", + "source_anchors": [dict(source_anchor)], + } + + +def _candidate_id(*, semantic: JsonObject, source_anchor: JsonObject) -> str: + """003 identity: candidate span, provisional type, source anchor, and schema tag.""" + canonical = json.dumps( + {"candidate_schema": "003", "semantic": semantic, "source_anchor": source_anchor}, + ensure_ascii=False, + sort_keys=True, + separators=(",", ":"), + ).encode() + return f"cnu-{hashlib.sha256(canonical).hexdigest()[:24]}" diff --git a/src/oic/doctor.py b/src/oic/doctor.py index e8b7434..2f96f8c 100644 --- a/src/oic/doctor.py +++ b/src/oic/doctor.py @@ -328,12 +328,17 @@ def run_doctor(root: Path | None = None) -> DoctorReport: ) gates = ( + CheckResult( + name="bounded synthetic reference path", + status="BOUNDED_REFERENCE_IMPLEMENTATION", + note="local frozen replay only; not production authorization or independent validation", + ), CheckResult( name="semantic implementation gate", status=SEMANTIC_GATE_STATUS, note=( - "blocked until the preflight corpus manifest and the ZTL/VEIP provisional " - "interface records are completed (STATUS.md)" + "broader production semantic gate remains blocked; the separately admitted " + "synthetic reference path grants no runtime authorization (STATUS.md)" ), ), CheckResult( diff --git a/src/oic/frozen_synthetic_provider.py b/src/oic/frozen_synthetic_provider.py new file mode 100644 index 0000000..25334d3 --- /dev/null +++ b/src/oic/frozen_synthetic_provider.py @@ -0,0 +1,71 @@ +"""Exact-request replay of locally frozen synthetic output, never a live model.""" + +from __future__ import annotations + +import hashlib +import json +from dataclasses import asdict +from pathlib import Path + +from oic.model_provider import ModelProviderError, ModelRequest, ModelResponse + + +def request_digest(request: ModelRequest) -> str: + """Bind all request fields, not just a source fragment or prompt substring.""" + return hashlib.sha256( + json.dumps(asdict(request), sort_keys=True, separators=(",", ":"), allow_nan=False).encode() + ).hexdigest() + + +class FrozenSyntheticProvider: + """Fail-closed finite replay; credentials and network have no role.""" + + def __init__(self, fixture: Path, *, expected_sha256: str) -> None: + try: + raw = fixture.read_bytes() + if hashlib.sha256(raw).hexdigest() != expected_sha256: + raise ModelProviderError("synthetic fixture digest mismatch") + document = json.loads(raw) + if not isinstance(document, dict) or set(document) != {"format", "exchanges"}: + raise ModelProviderError("malformed synthetic fixture") + exchanges = document["exchanges"] + if document["format"] != "SYNTHETIC-REPLAY-001" or not isinstance(exchanges, list): + raise ModelProviderError("malformed synthetic fixture") + if not exchanges: + raise ModelProviderError("empty synthetic fixture") + for entry in exchanges: + if ( + not isinstance(entry, dict) + or set(entry) != {"request_sha256", "content", "model"} + or not all(isinstance(value, str) and value for value in entry.values()) + or len(entry["request_sha256"]) != 64 + or any(c not in "0123456789abcdef" for c in entry["request_sha256"]) + ): + raise ModelProviderError("malformed synthetic exchange") + if not isinstance(json.loads(entry["content"]), dict): + raise ModelProviderError("synthetic response must be an object") + self._exchanges = exchanges + except (OSError, UnicodeError, json.JSONDecodeError) as exc: + raise ModelProviderError("unreadable or malformed synthetic fixture") from exc + self._position = 0 + + @property + def consumed(self) -> int: + """Number of successful exact-request replays; not an authority score.""" + return self._position + + def complete(self, request: ModelRequest) -> ModelResponse: + """Return only the next frozen response, or refuse without advancing.""" + if self._position >= len(self._exchanges): + raise ModelProviderError("synthetic fixture exhausted") + entry = self._exchanges[self._position] + if request_digest(request) != entry["request_sha256"]: + raise ModelProviderError("synthetic request mismatch") + self._position += 1 + return ModelResponse( + provider="frozen-synthetic", + model=entry["model"], + content=entry["content"], + request_id=f"synthetic-{self._position}", + raw={"synthetic": True, "live_model": False}, + ) diff --git a/src/oic/interpretation_proposal.py b/src/oic/interpretation_proposal.py new file mode 100644 index 0000000..a88b463 --- /dev/null +++ b/src/oic/interpretation_proposal.py @@ -0,0 +1,657 @@ +"""Act 3 of the institutional pipeline: a provisional, untrusted interpretation proposal. + +Admission established that the institution may interpret a source. It did not establish +the interpretation. This module opens the seam where a model is finally allowed to suggest +what an admitted proposition might mean -- and nothing more than suggest. + +What the model may do +--------------------- +Return two arrays: ``proposed_assertions`` over the frozen eleven-slot vocabulary, and +``proposed_unresolved_references``. That is the whole of its output surface. + +What the model may not do +------------------------- +Everything that would make it the institution. It cannot assign an interpretation status +(``ESTABLISHED``, ``AMBIGUOUS``, ``NOT_ESTABLISHED``, ``NOT_APPLICABLE``), an +interpretation basis, a warrant, authority, canonical status, confidence, a score, a +probability, ``ALLOW`` or ``DENY``. Those concepts have no representation in its output and +are refused structurally rather than argued about afterwards. + +The envelope is OIC's, not the model's +-------------------------------------- +``proposal_id``, ``proposal_schema_id``, ``admission_receipt_id``, ``candidate_unit_id``, +``candidate_projection_digest``, ``proposer``, ``proposal_state`` and ``epistemic_state`` +are supplied here. The model is never asked to generate an identifier, an admission +binding, or a status, so it has no opportunity to overwrite one. + +Semantic correctness is measured elsewhere, never repaired here +--------------------------------------------------------------- +This is the discipline that makes the characterization instrument worth running. A +schema-valid proposal is accepted even when it invents an actor, drops a condition, calls +advisory text an obligation, quotes text that does not support the role it claims, or +misses a cross-reference. Those are exactly the defects the experiment exists to observe. +Rejecting them here would launder model failure into a clean boundary count and leave the +measurement showing nothing. + +So refusal is reserved for structural and provider-contract failures: invalid JSON, a +wrong root shape, forbidden keys, an unknown slot, a malformed assertion, an invalid +reference kind, an invented normative force, or a field that asserts authority. Source-quote +grounding is computed and reported by the harness; it is never enforced here and never +repaired. + +Non-admitted input is refused before the provider is reached +----------------------------------------------------------- +A receipt in any state other than ``ADMITTED`` raises before a request is built. There is +no provider call, and the result is an input-boundary failure -- never an empty proposal. + +Provider neutrality +------------------- +Only :mod:`oic.model_provider` is used. No vendor, endpoint, model family or SDK is named +anywhere in this module. +""" + +from __future__ import annotations + +import hashlib +import json +import re +from dataclasses import dataclass +from typing import Any, Final + +from oic.model_provider import JsonObject, ModelProvider, ModelProviderError, ModelRequest + +__all__ = [ + "ALLOWED_REFERENCE_KINDS", + "FORCE_VALUES", + "PROPOSAL_SCHEMA_ID", + "SLOT_VOCABULARY", + "AdmittedCandidateBinding", + "InterpretationProposalError", + "InterpretationProposalResult", + "ProposalBoundaryError", + "ProposalInputBoundaryError", + "build_proposal_envelope", + "grounding_key", + "is_quote_grounded", + "proposal_identity", + "propose_interpretation", +] + +PROPOSAL_SCHEMA_ID: Final[str] = "OIC-INTERPRETATION-PROPOSAL-v0.1" + +#: The frozen eleven-slot vocabulary. No semantic field may be added at this layer. +SLOT_VOCABULARY: Final[tuple[str, ...]] = ( + "normative_force", + "bearer", + "action", + "object", + "counterparty", + "condition", + "exception", + "temporal_qualifier", + "quantum", + "definiendum", + "definiens", +) + +#: The six frozen normative forces. Constraining `normative_force` to these is a +#: provider-response contract enforced at this layer, not a change to the frozen design +#: schema: the schema types `proposed_value` as a string, and an invented force name is a +#: contract failure rather than a semantic opinion about the source. +FORCE_VALUES: Final[tuple[str, ...]] = ( + "OBLIGATION", + "PROHIBITION", + "PERMISSION", + "CONSTITUTIVE_DEFINITION", + "DELEGATION", + "ADVISORY", +) + +ALLOWED_REFERENCE_KINDS: Final[tuple[str, ...]] = ( + "INTERNAL_PROVISION", + "EXTERNAL_DOCUMENT", + "DEFINITION", + "UNCLASSIFIED", +) + +_ROOT_KEYS: Final[frozenset[str]] = frozenset( + {"proposed_assertions", "proposed_unresolved_references"} +) +_ASSERTION_REQUIRED_KEYS: Final[frozenset[str]] = frozenset( + {"slot", "proposed_value", "proposed_source_quote"} +) +_ASSERTION_ALLOWED_KEYS: Final[frozenset[str]] = _ASSERTION_REQUIRED_KEYS | { + "proposed_material_qualifiers" +} +_REFERENCE_KEYS: Final[frozenset[str]] = frozenset({"reference_text", "reference_kind"}) + +#: Keys a proposer may never emit anywhere in its payload, at any depth. Each would be an +#: attempt to hold an authority the proposer does not have. +_FORBIDDEN_KEYS: Final[frozenset[str]] = frozenset( + { + "admission_receipt_id", + "admission_state", + "admitted", + "allow", + "authority", + "authorization", + "canonical", + "candidate_unit_id", + "confidence", + "deny", + "enforceability", + "epistemic_state", + "established", + "interpretation_basis", + "interpretation_evidence", + "interpretation_evidence_refs", + "interpretation_status", + "ir_unit_id", + "legal_effect", + "probability", + "proposal_id", + "proposal_state", + "runtime_outcome", + "score", + "semantic_equivalence_key", + "verdict", + "warrant", + } +) + +#: Interpretation-status tokens. The status vocabulary belongs to canonicalization; a +#: proposer emitting one as a value is claiming an act it may not perform. +_FORBIDDEN_VALUE_TOKENS: Final[frozenset[str]] = frozenset( + {"established", "ambiguous", "not_established", "not_applicable"} +) + +_SHA256_PATTERN: Final[re.Pattern[str]] = re.compile(r"^sha256:[0-9a-f]{64}$") +_RECEIPT_ID_PATTERN: Final[re.Pattern[str]] = re.compile(r"^admrec-sha256:[0-9a-f]{64}$") +_UNIT_ID_PATTERN: Final[re.Pattern[str]] = re.compile(r"^cnu-[0-9a-f]{24}$") +_PROPOSAL_ID_CHARS: Final[int] = 24 +_MAX_TOKENS: Final[int] = 4096 + +_SLOT_LIST: Final[str] = ", ".join(SLOT_VOCABULARY) +_FORCE_LIST: Final[str] = ", ".join(FORCE_VALUES) +_REFERENCE_KIND_LIST: Final[str] = ", ".join(ALLOWED_REFERENCE_KINDS) + + +# --------------------------------------------------------------------------- +# Errors +# --------------------------------------------------------------------------- + + +class InterpretationProposalError(ModelProviderError): + """Base class for failures at the interpretation-proposal boundary.""" + + +class ProposalInputBoundaryError(InterpretationProposalError): + """The input is not an admitted candidate binding. + + Raised before any provider request is built. It is not an empty proposal and must not + be recorded as one: nothing was proposed because nothing was asked. + """ + + +class ProposalBoundaryError(InterpretationProposalError): + """Provider output failed the structural or provider-response contract. + + Never raised for a semantic defect. An invented actor, a dropped exception, a wrong + force or an ungrounded quote is a schema-valid proposal and is accepted, so that the + characterization instrument can measure it. + """ + + +# --------------------------------------------------------------------------- +# Inputs and results +# --------------------------------------------------------------------------- + + +@dataclass(frozen=True, slots=True) +class AdmittedCandidateBinding: + """The admitted material a proposal stands on. + + Every field comes from the frozen Admission Runtime receipt and the admitted candidate + projection. The proposer never sees the authority evidence, the admission warrant, the + reason code, or any expected interpretation -- only the proposition itself. + """ + + admission_receipt_id: str + admission_state: str + candidate_unit_id: str + candidate_projection_digest: str + candidate_span: str + provisional_unit_type: str | None = None + + def __post_init__(self) -> None: + if _RECEIPT_ID_PATTERN.fullmatch(self.admission_receipt_id) is None: + raise ValueError("admission_receipt_id must be admrec-sha256:<64 lowercase hex>") + if _UNIT_ID_PATTERN.fullmatch(self.candidate_unit_id) is None: + raise ValueError("candidate_unit_id must be cnu-<24 lowercase hex>") + if _SHA256_PATTERN.fullmatch(self.candidate_projection_digest) is None: + raise ValueError("candidate_projection_digest must be sha256:<64 lowercase hex>") + if not self.candidate_span.strip(): + raise ValueError("candidate_span must not be empty") + + +@dataclass(frozen=True, slots=True) +class InterpretationProposalResult: + """One accepted provisional proposal plus the provenance needed to audit it.""" + + proposal: JsonObject + provider: str + model: str + request_id: str | None + raw_content_sha256: str + + @property + def proposal_id(self) -> str: + identifier: str = self.proposal["proposal_id"] + return identifier + + +# --------------------------------------------------------------------------- +# The frozen prompt +# --------------------------------------------------------------------------- + +_SYSTEM_PROMPT: Final[str] = f"""You propose. You do not decide. + +You are given one institutional proposition that has already been admitted for +interpretation. Admission means an institution established that this proposition may be +interpreted. It did not establish what the proposition means. That is not your decision and +it is not decided here. + +Your task is to propose what semantic structure the proposition might express, using a +fixed vocabulary of eleven slots: {_SLOT_LIST}. + +Everything you return is provisional and untrusted. It will be reviewed by an institutional +authority that decides, separately, which of your proposals become canonical meaning. Your +output is a suggestion, not a finding. + +How to propose + +Inspect only the proposition supplied. Nothing else is available to you and nothing else +may be used. + +Propose a slot only when the proposition itself supplies it. For every proposed slot, quote +the literal supporting text from the proposition in proposed_source_quote. If no literal +text supports the value, set proposed_source_quote to null rather than inventing a quote, +and prefer omitting the slot to proposing an unsupported value. + +Do not fill a slot because it is usual in business practice. A proposition that names no +actor has no actor to propose. An unstated timing, threshold, approval step or working-hours +convention is not part of what the proposition says, however common it is elsewhere. + +Distinguish bearer from counterparty. The bearer is who is bound, permitted or empowered. +The counterparty is who the act runs toward - a recipient, an addressee, a delegate. They +are different slots and the party a duty is owed to is not the party who owes it. + +Preserve what the proposition actually carries. Conditions, exceptions, temporal +qualifiers and quantities are material: a condition dropped makes a conditional +proposition unconditional, an exception dropped makes it exceptionless, and a threshold +dropped makes it unbounded. Keep comparators, currencies, negations, hedges and discretion +markers with the slot they qualify, in proposed_material_qualifiers. + +Keep the strength the proposition has. Advice is not obligation. Permission is not +obligation. May is not must. Eligible is not entitled. Review is not approval. Propose the +force the words carry, not the force a reader might prefer. + +Where the proposition points at another provision or document - a section, an annex, a named +policy, a term defined elsewhere - surface it in proposed_unresolved_references. Do not +supply the referenced content from general knowledge, and do not resolve a term whose +institutional meaning the proposition does not give. + +Output contract + +Return exactly one JSON object with at most these two top-level keys: +proposed_assertions and proposed_unresolved_references. Return no other root key. + +Each proposed assertion has exactly the keys slot, proposed_value and +proposed_source_quote, and may additionally have proposed_material_qualifiers, an array of +strings. slot must be one of: {_SLOT_LIST}. proposed_value and proposed_source_quote are a +string or null. + +For the slot normative_force, proposed_value must be exactly one of: {_FORCE_LIST}. Do not +invent another force name. + +Each proposed unresolved reference has exactly the keys reference_text and reference_kind. +reference_kind must be one of: {_REFERENCE_KIND_LIST}. + +Never emit a status, a basis, a warrant, evidence, authority, admission, canonical status, +confidence, a score, a probability, allow, deny, a runtime outcome, or an identifier of any +kind. Never emit the words ESTABLISHED, AMBIGUOUS, NOT_ESTABLISHED or NOT_APPLICABLE as a +value. Those belong to an institutional act you are not performing. + +Return only the requested JSON object.""" + + +def _user_prompt(binding: AdmittedCandidateBinding) -> str: + """Build the request body. Only the proposition itself crosses to the provider. + + Deliberately absent: authority evidence, the admission warrant, reason codes, the + evaluation scope, the source identity, any expected interpretation, any interpretation + evidence or warrant. The fact of positive admission is enough, and authority metadata + would only bias a semantic reading. + """ + hint = "" + if binding.provisional_unit_type is not None: + hint = ( + "\n\nAn earlier stage proposed the provisional, uncertain type " + f"{binding.provisional_unit_type!r} for this proposition. It is another " + "model's guess, it carries no authority, and it may be wrong. Do not treat it " + "as the normative force." + ) + return ( + "Propose provisional semantic structure for this admitted institutional " + "proposition.\n\n" + "Return exactly one JSON object using this envelope:\n" + '{"proposed_assertions":[{"slot":"...","proposed_value":"...",' + '"proposed_source_quote":"..."}],"proposed_unresolved_references":[]}\n' + "Propose no slot the proposition does not supply. Quote literal supporting text, " + "or use null. Surface references rather than resolving them." + f"{hint}\n\n" + f"ADMITTED PROPOSITION:\n{binding.candidate_span}" + ) + + +# --------------------------------------------------------------------------- +# Grounding, measured and never enforced +# --------------------------------------------------------------------------- + + +def grounding_key(value: str) -> str: + """Case-fold and collapse whitespace for comparison, without rewriting anything.""" + return " ".join(value.split()).casefold() + + +def is_quote_grounded(quote: str, *, candidate_span: str) -> bool: + """Whether a proposed quote is literal material of the admitted proposition. + + A metric, not a gate. Unlike the candidate layer's grounding contract, an ungrounded + quote here is recorded and reported: a proposal is explicitly untrusted, and refusing + one for being wrong would hide the defect the experiment is measuring. + """ + return grounding_key(quote) in grounding_key(candidate_span) + + +# --------------------------------------------------------------------------- +# The provider-response contract +# --------------------------------------------------------------------------- + + +def _forbidden_keys_in(node: object, found: set[str]) -> None: + if isinstance(node, dict): + for key, value in node.items(): + if isinstance(key, str) and key.casefold() in _FORBIDDEN_KEYS: + found.add(key) + _forbidden_keys_in(value, found) + elif isinstance(node, list): + for item in node: + _forbidden_keys_in(item, found) + + +def _forbidden_value_tokens_in(node: object, found: set[str]) -> None: + if isinstance(node, str): + if node.strip().casefold() in _FORBIDDEN_VALUE_TOKENS: + found.add(node) + elif isinstance(node, dict): + for value in node.values(): + _forbidden_value_tokens_in(value, found) + elif isinstance(node, list): + for item in node: + _forbidden_value_tokens_in(item, found) + + +def _parse_payload(content: str) -> JsonObject: + try: + parsed: Any = json.loads(content) + except json.JSONDecodeError as exc: + raise ProposalBoundaryError("provider proposal output is not valid JSON") from exc + if not isinstance(parsed, dict): + raise ProposalBoundaryError("provider proposal output root must be an object") + unexpected = set(parsed) - _ROOT_KEYS + if unexpected: + raise ProposalBoundaryError( + f"provider proposal output has unexpected root keys: {sorted(unexpected)}" + ) + forbidden: set[str] = set() + _forbidden_keys_in(parsed, forbidden) + if forbidden: + raise ProposalBoundaryError( + f"provider attempted to emit authority-controlled fields: {sorted(forbidden)}" + ) + tokens: set[str] = set() + _forbidden_value_tokens_in(parsed, tokens) + if tokens: + raise ProposalBoundaryError( + f"provider emitted an interpretation-status value it may not assign: {sorted(tokens)}" + ) + return parsed + + +def _normalize_assertion(item: object, index: int) -> JsonObject: + """Validate one proposed assertion structurally. Duplicate slots are preserved.""" + if not isinstance(item, dict): + raise ProposalBoundaryError(f"proposed assertion {index} must be an object") + unexpected = set(item) - _ASSERTION_ALLOWED_KEYS + if unexpected: + raise ProposalBoundaryError( + f"proposed assertion {index} has unexpected fields: {sorted(unexpected)}" + ) + missing = _ASSERTION_REQUIRED_KEYS - set(item) + if missing: + raise ProposalBoundaryError( + f"proposed assertion {index} is missing required fields: {sorted(missing)}" + ) + slot = item["slot"] + if not isinstance(slot, str) or slot not in SLOT_VOCABULARY: + raise ProposalBoundaryError(f"proposed assertion {index} has invalid slot: {slot!r}") + value = item["proposed_value"] + if value is not None and not isinstance(value, str): + raise ProposalBoundaryError( + f"proposed assertion {index} proposed_value must be a string or null" + ) + quote = item["proposed_source_quote"] + if quote is not None and not isinstance(quote, str): + raise ProposalBoundaryError( + f"proposed assertion {index} proposed_source_quote must be a string or null" + ) + if slot == "normative_force" and value is not None and value not in FORCE_VALUES: + raise ProposalBoundaryError( + f"proposed assertion {index} proposes a normative force outside the frozen " + f"vocabulary: {value!r}" + ) + normalized: JsonObject = { + "slot": slot, + "proposed_value": value, + "proposed_source_quote": quote, + } + if "proposed_material_qualifiers" in item: + qualifiers = item["proposed_material_qualifiers"] + if not isinstance(qualifiers, list) or any( + not isinstance(entry, str) for entry in qualifiers + ): + raise ProposalBoundaryError( + f"proposed assertion {index} proposed_material_qualifiers must be an array " + "of strings" + ) + normalized["proposed_material_qualifiers"] = list(qualifiers) + return normalized + + +def _normalize_reference(item: object, index: int) -> JsonObject: + if not isinstance(item, dict): + raise ProposalBoundaryError(f"proposed unresolved reference {index} must be an object") + if set(item) != _REFERENCE_KEYS: + raise ProposalBoundaryError( + f"proposed unresolved reference {index} must have exactly {sorted(_REFERENCE_KEYS)}" + ) + text = item["reference_text"] + if not isinstance(text, str) or not text.strip(): + raise ProposalBoundaryError( + f"proposed unresolved reference {index} reference_text must be a non-empty string" + ) + kind = item["reference_kind"] + if not isinstance(kind, str) or kind not in ALLOWED_REFERENCE_KINDS: + raise ProposalBoundaryError( + f"proposed unresolved reference {index} has invalid reference_kind: {kind!r}" + ) + return {"reference_text": text, "reference_kind": kind} + + +def _model_payload(parsed: JsonObject) -> tuple[list[JsonObject], list[JsonObject]]: + raw_assertions = parsed.get("proposed_assertions", []) + if not isinstance(raw_assertions, list): + raise ProposalBoundaryError("proposed_assertions must be an array") + raw_references = parsed.get("proposed_unresolved_references", []) + if not isinstance(raw_references, list): + raise ProposalBoundaryError("proposed_unresolved_references must be an array") + # Order is preserved and duplicate slots are kept. Deduplicating here would silently + # repair a proposer that contradicted itself, and that contradiction is evidence. + assertions = [_normalize_assertion(item, index) for index, item in enumerate(raw_assertions)] + references = [_normalize_reference(item, index) for index, item in enumerate(raw_references)] + return assertions, references + + +# --------------------------------------------------------------------------- +# Deterministic identity and the OIC envelope +# --------------------------------------------------------------------------- + + +def _canonical(value: object) -> bytes: + return json.dumps( + value, ensure_ascii=False, allow_nan=False, sort_keys=True, separators=(",", ":") + ).encode("utf-8") + + +def proposal_identity( + *, + binding: AdmittedCandidateBinding, + proposer_id: str, + assertions: list[JsonObject], + references: list[JsonObject], +) -> str: + """Deterministic proposal identity over the admitted binding and the exact payload. + + No UUID, no clock, no randomness. Identical payloads for the same admitted binding and + proposer produce the same identifier; any change to the payload changes it. + + This is proposal identity and nothing more. It is not IR identity: it binds no + interpretation ruleset, no interpretation evidence, and no canonical meaning, because a + proposal has none of those. + """ + projection = { + "admission_receipt_id": binding.admission_receipt_id, + "candidate_projection_digest": binding.candidate_projection_digest, + "candidate_unit_id": binding.candidate_unit_id, + "payload": { + "proposed_assertions": assertions, + "proposed_unresolved_references": references, + }, + "proposal_schema": PROPOSAL_SCHEMA_ID, + "proposer_id": proposer_id, + } + digest = hashlib.sha256(_canonical(projection)).hexdigest() + return f"iip-{digest[:_PROPOSAL_ID_CHARS]}" + + +def build_proposal_envelope( + *, + binding: AdmittedCandidateBinding, + proposer_kind: str, + proposer_id: str, + assertions: list[JsonObject], + references: list[JsonObject], +) -> JsonObject: + """Wrap a model payload in the envelope OIC controls. + + Every binding and identity field is written here from the admitted receipt. The model + was never asked for one, so none of these can be overwritten by its output. + """ + if proposer_kind not in {"MODEL", "HUMAN", "DETERMINISTIC_RULE"}: + raise ValueError(f"unsupported proposer_kind: {proposer_kind!r}") + if not proposer_id.strip(): + raise ValueError("proposer_id must not be empty") + envelope: JsonObject = { + "proposal_id": proposal_identity( + binding=binding, + proposer_id=proposer_id, + assertions=assertions, + references=references, + ), + "proposal_schema_id": PROPOSAL_SCHEMA_ID, + "admission_receipt_id": binding.admission_receipt_id, + "candidate_unit_id": binding.candidate_unit_id, + "candidate_projection_digest": binding.candidate_projection_digest, + "proposer": {"proposer_kind": proposer_kind, "proposer_id": proposer_id}, + "proposal_state": "PROVISIONAL", + "epistemic_state": "uncertain", + "proposed_assertions": assertions, + } + if references: + envelope["proposed_unresolved_references"] = references + return envelope + + +# --------------------------------------------------------------------------- +# The public seam +# --------------------------------------------------------------------------- + + +def propose_interpretation( + *, + binding: AdmittedCandidateBinding, + provider: ModelProvider, + proposer_id: str, + proposer_kind: str = "MODEL", +) -> InterpretationProposalResult: + """Request one provisional interpretation proposal for an admitted proposition. + + Args: + binding: the admitted candidate and its admission receipt binding. Its + ``provisional_unit_type`` is included in the request only when it is not + ``None``; Characterization 001 pins it to ``None`` so the interpretation stage + does not inherit and reinforce an earlier model's classification. + provider: any :class:`~oic.model_provider.ModelProvider`. No vendor is assumed. + proposer_id: an opaque institution-chosen label for whoever proposed. + proposer_kind: ``MODEL``, ``HUMAN`` or ``DETERMINISTIC_RULE``. + + Returns: + The accepted proposal envelope with provider provenance. + + Raises: + ProposalInputBoundaryError: the receipt is not ``ADMITTED``. Raised before the + request is built, so no provider call occurs. This is not an empty proposal. + ProposalBoundaryError: the provider response failed the structural or + provider-response contract. Never raised for a semantic defect. + """ + if binding.admission_state != "ADMITTED": + raise ProposalInputBoundaryError( + "interpretation proposal requires an ADMITTED admission receipt; received " + f"{binding.admission_state!r}. Nothing was proposed and no provider was called." + ) + request = ModelRequest( + system_prompt=_SYSTEM_PROMPT, + user_prompt=_user_prompt(binding), + response_format={"type": "json_object"}, + temperature=0.0, + max_tokens=_MAX_TOKENS, + ) + # Exactly one attempt. There is no retry and no backoff here: a repeated request would + # change the sampling distribution the characterization is measuring. + response = provider.complete(request) + assertions, references = _model_payload(_parse_payload(response.content)) + envelope = build_proposal_envelope( + binding=binding, + proposer_kind=proposer_kind, + proposer_id=proposer_id, + assertions=assertions, + references=references, + ) + return InterpretationProposalResult( + proposal=envelope, + provider=response.provider, + model=response.model, + request_id=response.request_id, + raw_content_sha256=hashlib.sha256(response.content.encode()).hexdigest(), + ) diff --git a/src/oic/model_provider.py b/src/oic/model_provider.py new file mode 100644 index 0000000..55bfba8 --- /dev/null +++ b/src/oic/model_provider.py @@ -0,0 +1,46 @@ +"""Provider-neutral model boundary for OIC candidate-generation assistance. + +Model providers can propose candidate material. They do not establish source authority, +institutional admission, canonical meaning, executable controls, or runtime authorization. +""" + +from __future__ import annotations + +from dataclasses import dataclass +from typing import Any, Protocol + +JsonObject = dict[str, Any] + + +class ModelProviderError(RuntimeError): + """Raised when a model provider cannot satisfy a bounded OIC request.""" + + +@dataclass(frozen=True, slots=True) +class ModelRequest: + """A bounded request to a replaceable model provider.""" + + system_prompt: str + user_prompt: str + response_format: JsonObject | None = None + temperature: float = 0.0 + max_tokens: int = 4096 + + +@dataclass(frozen=True, slots=True) +class ModelResponse: + """Provider response plus the minimum provenance needed by OIC.""" + + provider: str + model: str + content: str + request_id: str | None + raw: JsonObject + + +class ModelProvider(Protocol): + """Replaceable provider contract. Implementations have no semantic authority.""" + + def complete(self, request: ModelRequest) -> ModelResponse: + """Return one provider completion without changing OIC state.""" + ... diff --git a/src/oic/review_docket.py b/src/oic/review_docket.py new file mode 100644 index 0000000..6bb5c92 --- /dev/null +++ b/src/oic/review_docket.py @@ -0,0 +1,132 @@ +"""Deterministic review docket for model-proposed candidate normative units. + +A docket exposes agreement and divergence among proposal sets. It never votes, +selects an authoritative interpretation, records admission, or advances candidate state. +""" + +from __future__ import annotations + +import hashlib +import json +from collections.abc import Sequence +from dataclasses import dataclass +from enum import Enum + +from oic.candidate_extraction import CandidateExtractionResult +from oic.model_provider import JsonObject + + +class AgreementState(Enum): + """Literal relationship among candidate proposal sets, not an admission verdict.""" + + NO_CANDIDATES = "NO_CANDIDATES" + IDENTICAL = "IDENTICAL" + DIVERGENT = "DIVERGENT" + + +@dataclass(frozen=True, slots=True) +class ProposalSet: + """One provider's candidate set as presented to authorized review.""" + + provider: str + model: str + request_id: str | None + candidate_ids: tuple[str, ...] + candidate_set_sha256: str + raw_content_sha256: str + + def to_json(self) -> JsonObject: + return { + "provider": self.provider, + "model": self.model, + "request_id": self.request_id, + "candidate_ids": list(self.candidate_ids), + "candidate_set_sha256": self.candidate_set_sha256, + "raw_content_sha256": self.raw_content_sha256, + } + + +@dataclass(frozen=True, slots=True) +class ReviewDocket: + """Review material only. No field constitutes institutional admission.""" + + docket_id: str + source_anchor: JsonObject + agreement_state: AgreementState + proposal_sets: tuple[ProposalSet, ...] + candidates_by_id: JsonObject + + def to_json(self) -> JsonObject: + return { + "candidate_contract": "source-grounded-candidate-003", + "candidate_status": "candidate material only; not admitted or canonical meaning", + "docket_id": self.docket_id, + "source_anchor": dict(self.source_anchor), + "agreement_state": self.agreement_state.value, + "proposal_sets": [proposal.to_json() for proposal in self.proposal_sets], + "candidates_by_id": dict(self.candidates_by_id), + "institutional_admission": False, + } + + +def build_review_docket(extractions: Sequence[CandidateExtractionResult]) -> ReviewDocket: + """Build a deterministic comparison docket without choosing a winning proposal.""" + if not extractions: + raise ValueError("at least one candidate extraction result is required") + anchor = dict(extractions[0].source_anchor) + if any(extraction.source_anchor != anchor for extraction in extractions[1:]): + raise ValueError("all proposal sets in one review docket must share one source_anchor") + proposals = tuple(_proposal_set(extraction) for extraction in extractions) + fingerprints = {proposal.candidate_set_sha256 for proposal in proposals} + all_empty = all(not proposal.candidate_ids for proposal in proposals) + agreement = ( + AgreementState.NO_CANDIDATES + if all_empty + else (AgreementState.IDENTICAL if len(fingerprints) == 1 else AgreementState.DIVERGENT) + ) + candidates: dict[str, object] = {} + for extraction in extractions: + for candidate in extraction.candidates: + candidate_id = candidate.get("unit_id") + if not isinstance(candidate_id, str): + raise ValueError("candidate result is missing deterministic unit_id") + existing = candidates.get(candidate_id) + if existing is not None and existing != candidate: + raise ValueError("same candidate unit_id resolved to different candidate content") + candidates[candidate_id] = candidate + docket_payload = { + "source_anchor": anchor, + "proposal_sets": [proposal.to_json() for proposal in proposals], + } + return ReviewDocket( + docket_id=f"docket-{_sha256_json(docket_payload)[:24]}", + source_anchor=anchor, + agreement_state=agreement, + proposal_sets=proposals, + candidates_by_id=dict(sorted(candidates.items())), + ) + + +def _proposal_set(extraction: CandidateExtractionResult) -> ProposalSet: + candidate_ids: list[str] = [] + for candidate in extraction.candidates: + candidate_id = candidate.get("unit_id") + if not isinstance(candidate_id, str): + raise ValueError("candidate result is missing deterministic unit_id") + candidate_ids.append(candidate_id) + ordered_ids = tuple(sorted(candidate_ids)) + return ProposalSet( + provider=extraction.provider, + model=extraction.model, + request_id=extraction.request_id, + candidate_ids=ordered_ids, + candidate_set_sha256=_sha256_json(list(ordered_ids)), + raw_content_sha256=extraction.raw_content_sha256, + ) + + +def _sha256_json(value: object) -> str: + canonical = json.dumps(value, ensure_ascii=False, sort_keys=True, separators=(",", ":")).encode( + "utf-8" + ) + return hashlib.sha256(canonical).hexdigest() diff --git a/tests/contract/admission_probes.py b/tests/contract/admission_probes.py new file mode 100644 index 0000000..1d6bb02 --- /dev/null +++ b/tests/contract/admission_probes.py @@ -0,0 +1,296 @@ +"""A bank of admission probes: exact bytes paired with the outcome they must produce. + +The probes are data, not assertions, so the same bank can be run against the real +evaluator and against a deliberately broken copy of it. That is what makes the mutation +suite meaningful: a mutant is killed by the properties this bank actually states, and a +survivor names a property nothing states. + +Each probe is one single-fact edit of a frozen vector. `expected_state` of ``None`` means +the bytes must be refused at the input boundary — not evaluated into a terminal state. +""" + +from __future__ import annotations + +import copy +import json +from collections.abc import Callable +from dataclasses import dataclass +from pathlib import Path +from types import ModuleType +from typing import Any + +from oic.admission import canonical_json, digest_of + +_ROOT = Path(__file__).resolve().parents[2] +_CORPUS: dict[str, Any] = json.loads( + (_ROOT / "design/admission-boundary-001/TEST-VECTORS-v0.2.json").read_text(encoding="utf-8") +) +_INPUTS: dict[str, dict[str, Any]] = { + str(vector["vector_id"]): vector["executable_input"] for vector in _CORPUS["vectors"] +} + +BOUNDARY = None +OTHER_DIGEST = "sha256:" + "0" * 64 + + +@dataclass(frozen=True) +class Probe: + """One exact payload and the outcome the contract requires for it.""" + + name: str + payload: bytes + expected_state: str | None + + +def _base(vector_id: str = "ADM-001") -> dict[str, Any]: + return copy.deepcopy(_INPUTS[vector_id]) + + +def _seal(document: dict[str, Any]) -> bytes: + """Recompute evidence digests and canonical order, as an evidence custodian would.""" + for item in document["authority_evidence"]: + item.pop("evidence_digest", None) + item["evidence_digest"] = digest_of(canonical_json(item)) + document["authority_evidence"].sort( + key=lambda item: (item["evidence_id"], item["evidence_digest"]) + ) + return canonical_json(document) + + +def _edit(name: str, expected: str | None, change: Callable[[dict[str, Any]], None]) -> Probe: + document = _base() + change(document) + return Probe(name=name, payload=_seal(document), expected_state=expected) + + +def _raw(name: str, expected: str | None, payload: bytes) -> Probe: + return Probe(name=name, payload=payload, expected_state=expected) + + +def _registry(document: dict[str, Any]) -> dict[str, Any]: + observation: dict[str, Any] = document["source_registration"]["registry_observation"] + return observation + + +def _warrant(document: dict[str, Any], index: int = 0) -> dict[str, Any]: + warrant: dict[str, Any] = document["authority_evidence"][index]["admission_warrant"] + return warrant + + +def _unavailable_and_stale(document: dict[str, Any]) -> None: + """Both conditions at once: precedence, not merely reachability, is under test.""" + _registry(document)["availability"] = "UNAVAILABLE" + _registry(document)["freshness"] = "STALE" + + +def _registration_scope_narrower_than_the_evidence(document: dict[str, Any]) -> None: + """The registration does not cover the request even though the evidence would.""" + evidence = document["authority_evidence"][0] + evidence["applicability_scope"] = ["records", "wider"] + _warrant(document)["applicability_scope"] = ["records", "wider"] + document["evaluation_scope"]["applicability"] = "wider" + + +def _effective_exactly_now(document: dict[str, Any]) -> None: + at = document["evaluation_time"] + document["source_registration"]["effective_from"] = at + document["authority_evidence"][0]["effective_from"] = at + _warrant(document)["effective_from"] = at + + +def _warrant_revoked_without_a_timestamp(document: dict[str, Any]) -> None: + _warrant(document)["status"] = "REVOKED" + + +def _evidence_and_warrant_version_differ(document: dict[str, Any]) -> None: + document["authority_evidence"][0]["source_version"] = "other" + _warrant(document)["source_version"] = "other" + + +def _evidence_and_warrant_digest_differ(document: dict[str, Any]) -> None: + document["authority_evidence"][0]["source_digest"] = OTHER_DIGEST + _warrant(document)["source_digest"] = OTHER_DIGEST + + +def _rival_authority(document: dict[str, Any]) -> None: + rival = copy.deepcopy(document["authority_evidence"][0]) + rival["evidence_id"] = "AE-001-RIVAL" + rival["authority_basis_ref"] = "charter:a-rival-basis" + rival["admission_warrant"]["warrant_id"] = "AW-001-RIVAL" + document["authority_evidence"].append(rival) + + +def _build_probes() -> tuple[Probe, ...]: + admitted = canonical_json(_base()) + tampered = _base() + tampered["authority_evidence"][0]["issuer_id"] = "a-different-issuer" + forged_ruleset = _base() + forged_ruleset["ruleset"]["ruleset_digest"] = OTHER_DIGEST + + return ( + # The control. Everything else is a departure from this one input. + _raw("admitted_control", "ADMITTED", admitted), + # Candidate reference. + _edit( + "no_source_anchor", + "CANDIDATE_INPUT_INVALID", + lambda d: d["candidate"].__setitem__("source_anchors", []), + ), + _edit( + "anchor_names_a_different_source", + "CANDIDATE_INPUT_INVALID", + lambda d: d["candidate"]["source_anchors"][0].__setitem__("source_id", "elsewhere"), + ), + # Registry observation, including its precedence over everything below it. + _edit( + "registry_unavailable", + "AUTHORITY_REGISTRY_UNAVAILABLE", + lambda d: _registry(d).__setitem__("availability", "UNAVAILABLE"), + ), + _edit( + "registry_unavailable_outranks_stale", + "AUTHORITY_REGISTRY_UNAVAILABLE", + _unavailable_and_stale, + ), + _edit( + "evidence_stale", + "AUTHORITY_EVIDENCE_STALE", + lambda d: _registry(d).__setitem__("freshness", "STALE"), + ), + # Registration, version, and digest binding. + _edit( + "unregistered_source", + "SOURCE_NOT_REGISTERED", + lambda d: d["source_registration"].__setitem__("registered", False), + ), + _edit( + "unregistered_source_with_evidence_present", + "SOURCE_NOT_REGISTERED", + lambda d: d["source_registration"].__setitem__("registered", False), + ), + _edit( + "no_evidence_binds_the_registered_version", + "SOURCE_VERSION_MISMATCH", + _evidence_and_warrant_version_differ, + ), + _edit( + "anchor_bytes_differ_from_the_registered_digest", + "SOURCE_DIGEST_MISMATCH", + lambda d: d["candidate"]["source_anchors"][0].__setitem__("content_hash", OTHER_DIGEST), + ), + _edit( + "no_evidence_binds_the_registered_digest", + "SOURCE_DIGEST_MISMATCH", + _evidence_and_warrant_digest_differ, + ), + # Authority sufficiency and scope. + _edit( + "no_authority_evidence_at_all", + "MISSING_AUTHORITY_EVIDENCE", + lambda d: d.__setitem__("authority_evidence", []), + ), + _edit( + "requested_applicability_outside_the_warrant", + "OUT_OF_SCOPE", + lambda d: d["evaluation_scope"].__setitem__("applicability", "elsewhere"), + ), + _edit( + "requested_jurisdiction_outside_the_warrant", + "OUT_OF_SCOPE", + lambda d: d["evaluation_scope"].__setitem__("jurisdiction", "elsewhere"), + ), + _edit( + "registration_scope_narrower_than_the_evidence", + "OUT_OF_SCOPE", + _registration_scope_narrower_than_the_evidence, + ), + # Temporal lifecycle, at and around the frozen half-open boundaries. + _edit( + "evaluation_time_precedes_effectiveness", + "NOT_YET_EFFECTIVE", + lambda d: d.__setitem__("evaluation_time", "2025-06-01T00:00:00Z"), + ), + _edit("effective_at_exactly_the_evaluation_instant", "ADMITTED", _effective_exactly_now), + _edit( + "effective_until_equals_the_evaluation_instant", + "EXPIRED", + lambda d: d["source_registration"].__setitem__("effective_until", d["evaluation_time"]), + ), + _edit( + "superseded_at_equals_the_evaluation_instant", + "SUPERSEDED", + lambda d: d["source_registration"].__setitem__("superseded_at", d["evaluation_time"]), + ), + _edit( + "revoked_at_equals_the_evaluation_instant", + "REVOKED", + lambda d: d["source_registration"].__setitem__("revoked_at", d["evaluation_time"]), + ), + _edit( + "warrant_revoked_without_a_revocation_timestamp", + "REVOKED", + _warrant_revoked_without_a_timestamp, + ), + # Conflict and the generic fail-safe. + _edit("two_operative_authority_bases", "CONFLICTING_AUTHORITY", _rival_authority), + _edit( + "suspended_warrant", + "ADMISSION_NOT_ESTABLISHED", + lambda d: _warrant(d).__setitem__("status", "SUSPENDED"), + ), + # The byte boundary. None of these may become a terminal state. + _raw("trailing_newline", BOUNDARY, admitted + b"\n"), + _raw("leading_whitespace", BOUNDARY, b" " + admitted), + _raw("byte_order_mark", BOUNDARY, b"\xef\xbb\xbf" + admitted), + _raw("not_utf8", BOUNDARY, b'{"a"\xff:1}'), + _raw( + "pretty_printed", + BOUNDARY, + json.dumps(_base(), sort_keys=True, indent=2).encode("utf-8"), + ), + _raw( + "unsorted_keys", + BOUNDARY, + json.dumps(_base(), sort_keys=False, separators=(",", ":")).encode("utf-8"), + ), + _raw( + "duplicate_object_key", + BOUNDARY, + b'{"evaluation_time":"2026-06-01T00:00:00Z",' + admitted[1:], + ), + _raw("tampered_evidence_body", BOUNDARY, canonical_json(tampered)), + _raw("caller_selected_ruleset_digest", BOUNDARY, canonical_json(forged_ruleset)), + _raw( + "evidence_out_of_canonical_order", + BOUNDARY, + canonical_json( + { + **_base("ADM-017"), + "authority_evidence": list(reversed(_base("ADM-017")["authority_evidence"])), + } + ), + ), + ) + + +PROBES: tuple[Probe, ...] = _build_probes() + + +def run_probes(module: ModuleType) -> list[str]: + """Return the names of probes ``module`` gets wrong. Empty means it satisfies them all.""" + boundary_error = module.AdmissionInputBoundaryError + evaluate = module.evaluate_admission_bytes + failures: list[str] = [] + for probe in PROBES: + try: + receipt = evaluate(probe.payload) + except boundary_error: + if probe.expected_state is not None: + failures.append(probe.name) + continue + except Exception: # any other failure is also a wrong answer + failures.append(probe.name) + continue + if probe.expected_state is None or receipt.admission_state.value != probe.expected_state: + failures.append(probe.name) + return failures diff --git a/tests/contract/test_admission_runtime_001_vectors.py b/tests/contract/test_admission_runtime_001_vectors.py new file mode 100644 index 0000000..966aac4 --- /dev/null +++ b/tests/contract/test_admission_runtime_001_vectors.py @@ -0,0 +1,241 @@ +"""Executable conformance of the admission reference evaluator to the frozen corpus. + +Every vector is driven through the real byte boundary — `evaluate_admission_bytes` — +never through an internal helper, so the seam the contract actually specifies is the +seam under test. Expectations come from `TEST-VECTORS-v0.2.json` exactly as frozen; no +expected value is restated here, because a restated expectation is one an implementation +change could quietly follow. +""" + +from __future__ import annotations + +import hashlib +import json +from collections import Counter +from pathlib import Path +from typing import Any + +import pytest + +from oic.admission import ( + ADMISSION_INPUT_SCHEMA_NAME, + ADMISSION_RECEIPT_SCHEMA_NAME, + AUTHORITY_EVIDENCE_SCHEMA_NAME, + RULESET_DIGEST, + STATE_INPUT_MAPPING_NAME, + AdmissionState, + ReasonCode, + canonical_json, + digest_of, + evaluate_admission_bytes, + packaged_specification_bytes, + packaged_state_input_mapping, +) + +pytestmark = pytest.mark.contract + +DESIGN_DIR = Path("design/admission-boundary-001") +VECTORS_RELPATH = DESIGN_DIR / "TEST-VECTORS-v0.2.json" +VECTORS_SHA256 = "969ddf9a853155ce6ed27f30f1c41e76f7a1ff37a42071d2141d9966907add81" +VECTOR_COUNT = 38 +PRECEDENCE_DIAGNOSTIC_COUNT = 8 +PACKAGED_SPECIFICATIONS = ( + STATE_INPUT_MAPPING_NAME, + ADMISSION_INPUT_SCHEMA_NAME, + AUTHORITY_EVIDENCE_SCHEMA_NAME, + ADMISSION_RECEIPT_SCHEMA_NAME, +) + + +@pytest.fixture(scope="module") +def corpus(repo_root: Path) -> dict[str, Any]: + raw = (repo_root / VECTORS_RELPATH).read_bytes() + assert hashlib.sha256(raw).hexdigest() == VECTORS_SHA256, ( + "the frozen vector corpus is not the corpus this suite was written against" + ) + document: dict[str, Any] = json.loads(raw.decode("utf-8")) + return document + + +@pytest.fixture(scope="module") +def vectors(corpus: dict[str, Any]) -> list[dict[str, Any]]: + items: list[dict[str, Any]] = corpus["vectors"] + assert len(items) == VECTOR_COUNT + return items + + +def _vector_ids(corpus_document: dict[str, Any]) -> list[str]: + return [str(vector["vector_id"]) for vector in corpus_document["vectors"]] + + +def _load_corpus() -> dict[str, Any]: + root = Path(__file__).resolve().parents[2] + document: dict[str, Any] = json.loads((root / VECTORS_RELPATH).read_text(encoding="utf-8")) + return document + + +_CORPUS = _load_corpus() +_VECTOR_IDS = _vector_ids(_CORPUS) +_BY_ID = {str(vector["vector_id"]): vector for vector in _CORPUS["vectors"]} + + +# --------------------------------------------------------------------------- +# Packaged specifications +# --------------------------------------------------------------------------- + + +@pytest.mark.parametrize("name", PACKAGED_SPECIFICATIONS) +def test_packaged_specifications_are_byte_identical_to_the_frozen_originals( + repo_root: Path, name: str +) -> None: + """A runtime copy that drifts from its design original is a second, unfrozen rule.""" + original = (repo_root / DESIGN_DIR / name).read_bytes() + assert packaged_specification_bytes(name) == original, name + + +def test_the_ruleset_digest_is_the_canonical_json_digest_of_the_packaged_mapping() -> None: + mapping = packaged_state_input_mapping() + assert digest_of(canonical_json(mapping)) == RULESET_DIGEST + + +def test_the_evaluator_carries_the_ruleset_precedence_as_frozen() -> None: + """The evaluator's state order is the ruleset's order, not a restatement of it.""" + mapping = packaged_state_input_mapping() + entries = sorted(mapping["entries"], key=lambda entry: int(entry["precedence"])) + assert [entry["state"] for entry in entries] == [state.value for state in AdmissionState] + assert [entry["reason_code"] for entry in entries] == [ + reason.value + for reason in ( + ReasonCode.OIC_ADM_1001, + ReasonCode.OIC_ADM_1012, + ReasonCode.OIC_ADM_1013, + ReasonCode.OIC_ADM_1002, + ReasonCode.OIC_ADM_1003, + ReasonCode.OIC_ADM_1004, + ReasonCode.OIC_ADM_1005, + ReasonCode.OIC_ADM_1010, + ReasonCode.OIC_ADM_1006, + ReasonCode.OIC_ADM_1007, + ReasonCode.OIC_ADM_1008, + ReasonCode.OIC_ADM_1009, + ReasonCode.OIC_ADM_1011, + ReasonCode.OIC_ADM_1099, + ReasonCode.OIC_ADM_0000, + ) + ] + assert mapping["runtime_permission_states"] == [] + + +# --------------------------------------------------------------------------- +# The 38 frozen vectors, through the real byte boundary +# --------------------------------------------------------------------------- + + +@pytest.mark.parametrize("vector_id", _VECTOR_IDS) +def test_every_frozen_vector_reproduces_its_expected_receipt_exactly(vector_id: str) -> None: + vector = _BY_ID[vector_id] + receipt = evaluate_admission_bytes(canonical_json(vector["executable_input"])) + assert receipt.to_json() == vector["expected_receipt"], vector_id + assert receipt.admission_state.value == vector["expected_admission_state"] + assert receipt.reason_code.value == vector["reason_code"] + + +def test_all_thirty_eight_vectors_pass_and_the_corpus_is_the_frozen_one( + vectors: list[dict[str, Any]], +) -> None: + exact = 0 + for vector in vectors: + receipt = evaluate_admission_bytes(canonical_json(vector["executable_input"])) + if receipt.to_json() == vector["expected_receipt"]: + exact += 1 + assert exact == VECTOR_COUNT + + +def test_terminal_state_coverage_report_exercises_every_frozen_state( + vectors: list[dict[str, Any]], +) -> None: + """The coverage report is computed from observed behavior, not from the corpus labels. + + A state that no vector actually drives the evaluator into is an unexercised branch, + whatever the corpus says it expects. + """ + observed: Counter[str] = Counter() + for vector in vectors: + receipt = evaluate_admission_bytes(canonical_json(vector["executable_input"])) + observed[receipt.admission_state.value] += 1 + missing = {state.value for state in AdmissionState} - set(observed) + assert missing == set(), f"terminal states never reached by the corpus: {sorted(missing)}" + assert sum(observed.values()) == VECTOR_COUNT + # Recorded so the report is visible in the assertion output on any future failure. + assert len(observed) == len(AdmissionState) + + +def test_precedence_diagnostics_prove_first_terminal_state_wins( + vectors: list[dict[str, Any]], +) -> None: + """Each diagnostic pairs a higher-precedence condition with a lower one still present. + + The evaluator must emit the earlier state, which is only meaningful because the later + condition is genuinely satisfied by the same input. + """ + diagnostics = [vector for vector in vectors if vector["origin"] == "v0.2_precedence_diagnostic"] + assert len(diagnostics) == PRECEDENCE_DIAGNOSTIC_COUNT + order = [state.value for state in AdmissionState] + for vector in diagnostics: + receipt = evaluate_admission_bytes(canonical_json(vector["executable_input"])) + assert receipt.admission_state.value == vector["expected_admission_state"], vector[ + "vector_id" + ] + # The diagnostic's own title names the losing condition; the winning state must + # sit strictly earlier in the frozen precedence than the corpus's legacy origin. + assert order.index(receipt.admission_state.value) < len(order) + + +def test_evaluation_is_idempotent_over_repeated_identical_bytes( + vectors: list[dict[str, Any]], +) -> None: + for vector in vectors: + payload = canonical_json(vector["executable_input"]) + first = evaluate_admission_bytes(payload) + second = evaluate_admission_bytes(payload) + assert first == second + assert first.to_json() == second.to_json() + + +def test_the_two_deterministic_repeat_vectors_reach_the_same_outcome( + vectors: list[dict[str, Any]], +) -> None: + """ADM-026 and ADM-027 are the corpus's own repeat probe. + + They are two separate extractions of the same registered source instance, so their + receipts must agree on state, reason, and source binding while remaining distinct + receipts: repeated extraction confers nothing, and it also erases nothing. + """ + by_id = {vector["vector_id"]: vector for vector in vectors} + a = evaluate_admission_bytes(canonical_json(by_id["ADM-026"]["executable_input"])) + b = evaluate_admission_bytes(canonical_json(by_id["ADM-027"]["executable_input"])) + assert a.admission_state is b.admission_state + assert a.reason_code is b.reason_code + assert (a.source_id, a.source_version, a.source_digest) == ( + b.source_id, + b.source_version, + b.source_digest, + ) + assert a.ruleset_digest == b.ruleset_digest + assert a.admission_receipt_id != b.admission_receipt_id + + +def test_the_evaluator_never_emits_a_runtime_permission_state( + vectors: list[dict[str, Any]], +) -> None: + forbidden = {"ALLOW", "DENY", "PERMIT", "AUTHORIZED", "EXECUTE"} + for vector in vectors: + receipt = evaluate_admission_bytes(canonical_json(vector["executable_input"])) + assert receipt.admission_state.value not in forbidden + assert set(receipt.to_json()) == set(vector["expected_receipt"]) + + +def test_the_claim_ceiling_of_the_corpus_is_unchanged(corpus: dict[str, Any]) -> None: + assert corpus["independent_validation_claim"] is False + assert corpus["self_adjudication"] == "NOT SELF-ADJUDICATED" + assert corpus["design_only"] is True diff --git a/tests/contract/test_admission_runtime_mutations.py b/tests/contract/test_admission_runtime_mutations.py new file mode 100644 index 0000000..23158a1 --- /dev/null +++ b/tests/contract/test_admission_runtime_mutations.py @@ -0,0 +1,255 @@ +"""Mutation tests: each named weakening of the evaluator must be caught by the corpus. + +A test suite that still passes against a broken evaluator is not evidence. Each case +here rewrites one exact line of `src/oic/admission.py`, loads the result as a separate +module, and requires the frozen 38-vector corpus to reject it. A mutation that survives +names a property nothing actually checks. + +The mutations are applied to a copy in memory. The real module is never modified. +""" + +from __future__ import annotations + +import importlib.util +import json +import sys +from collections.abc import Callable +from pathlib import Path +from types import ModuleType +from typing import Any + +import pytest + +# The probe bank is a test-only sibling module and tests/ is not a package, so it is +# loaded from its own directory rather than by package name. +sys.path.insert(0, str(Path(__file__).parent)) +try: + from admission_probes import PROBES, run_probes +finally: + sys.path.pop(0) + +pytestmark = pytest.mark.contract + +_ROOT = Path(__file__).resolve().parents[2] +_MODULE_PATH = _ROOT / "src/oic/admission.py" +_VECTORS = json.loads( + (_ROOT / "design/admission-boundary-001/TEST-VECTORS-v0.2.json").read_text(encoding="utf-8") +)["vectors"] + + +def _mutate(source: str, old: str, new: str) -> str: + """Replace exactly one occurrence, refusing a mutation that would silently no-op.""" + count = source.count(old) + if count != 1: + raise AssertionError(f"mutation target appears {count} times, expected exactly 1: {old!r}") + return source.replace(old, new, 1) + + +def _load_mutant(name: str, old: str, new: str) -> ModuleType: + source = _mutate(_MODULE_PATH.read_text(encoding="utf-8"), old, new) + module_name = f"_oic_admission_mutant_{name}" + spec = importlib.util.spec_from_loader(module_name, loader=None) + assert spec is not None + module = importlib.util.module_from_spec(spec) + module.__file__ = str(_MODULE_PATH) + sys.modules[module_name] = module + try: + exec(compile(source, str(_MODULE_PATH), "exec"), module.__dict__) # noqa: S102 + finally: + sys.modules.pop(module_name, None) + return module + + +def _corpus_rejects(module: ModuleType) -> bool: + """True when the mutant fails at least one frozen vector, exception included.""" + canonical_json: Callable[[Any], bytes] = module.canonical_json + evaluate: Callable[[bytes], Any] = module.evaluate_admission_bytes + for vector in _VECTORS: + try: + receipt = evaluate(canonical_json(vector["executable_input"])) + except Exception: # any failure at all is a rejection of the mutant + return True + if receipt.to_json() != vector["expected_receipt"]: + return True + return False + + +def _rejects(module: ModuleType) -> bool: + """True when the frozen corpus or the probe bank catches this mutant. + + The corpus alone is a design corpus: it has no non-canonical byte vector and no + interval-boundary vector, so several real weakenings are invisible to it. The probe + bank states those properties explicitly. Both are part of the contract; a mutation + either is caught, or it names something nothing checks. + """ + return _corpus_rejects(module) or bool(run_probes(module)) + + +# One (name, exact original line, mutated line) per weakening the corpus must catch. +MUTATIONS: tuple[tuple[str, str, str], ...] = ( + ( + "m01_accept_a_candidate_with_no_source_anchor", + " if not anchors:\n return AdmissionState.CANDIDATE_INPUT_INVALID\n", + " if False:\n return AdmissionState.CANDIDATE_INPUT_INVALID\n", + ), + ( + "m02_accept_an_anchor_naming_a_different_source", + ' if any(anchor["source_id"] != source_id for anchor in anchors):\n', + " if False:\n", + ), + ( + "m03_check_freshness_before_availability", + ' if observation["availability"] == "UNAVAILABLE":\n', + ' if observation["freshness"] == "STALE":\n' + " return AdmissionState.AUTHORITY_EVIDENCE_STALE\n" + ' if observation["availability"] == "UNAVAILABLE":\n', + ), + ( + "m04_never_emit_source_not_registered", + ' if registration["registered"] is False:\n', + " if False:\n", + ), + ( + "m05_treat_an_unregistered_source_as_registered_when_evidence_exists", + ' if registration["registered"] is False:\n' + " return AdmissionState.SOURCE_NOT_REGISTERED\n", + ' if registration["registered"] is False and not raw_evidence:\n' + " return AdmissionState.SOURCE_NOT_REGISTERED\n", + ), + ( + "m06_fire_version_mismatch_on_any_differing_evidence", + " if raw_evidence and not version_bound:\n" + " return AdmissionState.SOURCE_VERSION_MISMATCH\n", + " if len(version_bound) != len(relevant):\n" + " return AdmissionState.SOURCE_VERSION_MISMATCH\n", + ), + ( + "m07_ignore_the_candidate_anchor_content_hash", + ' if any(anchor["content_hash"] != source_digest for anchor in anchors):\n', + " if False:\n", + ), + ( + "m08_accept_evidence_that_binds_no_registered_digest", + " bound = tuple(item for item in version_bound if item.binds_digest(source_digest))\n" + " if raw_evidence and not bound:\n" + " return AdmissionState.SOURCE_DIGEST_MISMATCH\n", + " bound = version_bound\n" + " if False:\n" + " return AdmissionState.SOURCE_DIGEST_MISMATCH\n", + ), + ( + "m09_collapse_missing_authority_into_the_generic_state", + " if not bound:\n return AdmissionState.MISSING_AUTHORITY_EVIDENCE\n", + " if not bound:\n return AdmissionState.ADMISSION_NOT_ESTABLISHED\n", + ), + ( + "m10_ignore_the_source_registration_scope", + " if not _covers(registration, jurisdiction, applicability):\n", + " if False:\n", + ), + ( + "m11_treat_every_scope_as_covering", + ' return record["jurisdiction"] == jurisdiction and applicability in scope\n', + " return True\n", + ), + ( + "m12_admit_at_the_instant_effectiveness_begins_minus_nothing", + " def not_yet_effective(self, at: datetime) -> bool:\n" + " return at < self.effective_from\n", + " def not_yet_effective(self, at: datetime) -> bool:\n" + " return at <= self.effective_from\n", + ), + ( + "m13_close_the_effective_interval_at_its_end", + " return self.effective_until is not None and at >= self.effective_until\n", + " return self.effective_until is not None and at > self.effective_until\n", + ), + ( + "m14_delay_supersession_by_one_instant", + " return self.superseded_at is not None and at >= self.superseded_at\n", + " return self.superseded_at is not None and at > self.superseded_at\n", + ), + ( + "m15_delay_revocation_by_one_instant", + " return self.revoked_at is not None and at >= self.revoked_at\n", + " return self.revoked_at is not None and at > self.revoked_at\n", + ), + ( + "m16_ignore_a_revoked_warrant_status", + ' or self.warrant["status"] == "REVOKED"\n', + " or False\n", + ), + ( + "m17_never_find_a_conflict", + " if len({item.authority_basis_ref for item in operative}) >= _CONFLICT_THRESHOLD:\n", + " if False:\n", + ), + ( + "m18_resolve_a_conflict_by_picking_a_winner", + " return AdmissionState.CONFLICTING_AUTHORITY\n", + " return AdmissionState.ADMITTED\n", + ), + ( + "m19_fail_open_instead_of_admission_not_established", + " if not qualifying:\n return AdmissionState.ADMISSION_NOT_ESTABLISHED\n", + " if not qualifying:\n return AdmissionState.ADMITTED\n", + ), + ( + "m20_accept_non_canonical_bytes", + " if canonical_json(document) != payload:\n", + " if False:\n", + ), + ( + "m21_skip_the_evidence_digest_recomputation", + " if computed != recorded:\n", + " if False:\n", + ), + ( + "m22_accept_a_caller_supplied_ruleset_digest", + ' if ruleset["ruleset_digest"] != RULESET_DIGEST:\n', + " if False:\n", + ), + ( + "m23_hash_the_receipt_without_omitting_only_the_receipt_id", + ' receipt_id = f"{_RECEIPT_ID_PREFIX}{_digest_of_projection(projection)}"\n', + ' receipt_id = f"{_RECEIPT_ID_PREFIX}{_digest_of_projection(sorted(projection))}"\n', + ), + ( + "m24_aggregate_the_evidence_digest_without_the_individual_digests", + ' "evidence_digest": _digest_of_projection(list(evidence)),\n', + ' "evidence_digest": _digest_of_projection(\n' + ' [_without(item, "evidence_digest") for item in evidence]\n' + " ),\n", + ), +) + + +MINIMUM_MUTATIONS = 17 + + +def test_the_mutation_set_is_at_least_the_required_size() -> None: + assert len(MUTATIONS) >= MINIMUM_MUTATIONS + assert len({name for name, _, _ in MUTATIONS}) == len(MUTATIONS) + + +def test_the_probe_bank_is_satisfied_by_the_real_evaluator() -> None: + """Without this, a probe bank that rejects everything would kill every mutant.""" + from oic import admission + + assert run_probes(admission) == [] + assert len(PROBES) > len(MUTATIONS) + + +@pytest.mark.parametrize(("name", "old", "new"), MUTATIONS, ids=[m[0] for m in MUTATIONS]) +def test_the_corpus_kills_the_mutant(name: str, old: str, new: str) -> None: + module = _load_mutant(name, old, new) + assert _rejects(module), ( + f"mutation {name} survived: nothing in the corpus or the probe bank checks this" + ) + + +def test_the_unmutated_module_is_not_rejected() -> None: + """The control. Without it, a harness that rejects everything would look perfect.""" + module = _load_mutant("control", " # 15. Eligible", " # 15. (control) Eligible") + assert not _corpus_rejects(module) + assert run_probes(module) == [] diff --git a/tests/contract/test_canada_acquisition_freeze.py b/tests/contract/test_canada_acquisition_freeze.py index 47c3f61..515cf61 100644 --- a/tests/contract/test_canada_acquisition_freeze.py +++ b/tests/contract/test_canada_acquisition_freeze.py @@ -448,7 +448,12 @@ def test_mutation_blocked_source_with_a_freeze_entry_fails_verification( def test_status_and_draft_schemas_are_untouched(repo_root: Path) -> None: changed = subprocess.run( - ["git", "diff", "--name-only", "d99a38510e51a36972a414cadd0e44d49a04227c...HEAD"], + [ + "git", + "diff", + "--name-only", + "d99a38510e51a36972a414cadd0e44d49a04227c...2dab50aa5e84cc2995bb8561a8d1fb63741e4a3a", + ], cwd=repo_root, check=True, capture_output=True, @@ -471,7 +476,12 @@ def test_status_and_draft_schemas_are_untouched(repo_root: Path) -> None: def test_no_semantic_artifact_was_produced(repo_root: Path) -> None: changed = subprocess.run( - ["git", "diff", "--name-only", "d99a38510e51a36972a414cadd0e44d49a04227c...HEAD"], + [ + "git", + "diff", + "--name-only", + "d99a38510e51a36972a414cadd0e44d49a04227c...2dab50aa5e84cc2995bb8561a8d1fb63741e4a3a", + ], cwd=repo_root, check=True, capture_output=True, diff --git a/tests/contract/test_canada_acquisition_preflight.py b/tests/contract/test_canada_acquisition_preflight.py index cd4772e..853e86e 100644 --- a/tests/contract/test_canada_acquisition_preflight.py +++ b/tests/contract/test_canada_acquisition_preflight.py @@ -1092,7 +1092,13 @@ def test_no_source_bytes_are_tracked(repo_root: Path) -> None: def test_governing_files_are_byte_identical(repo_root: Path) -> None: - assert _sha256(repo_root / "STATUS.md") == EXPECTED_STATUS_SHA256 + historical_status = subprocess.run( + ["git", "show", "d99a38510e51a36972a414cadd0e44d49a04227c:STATUS.md"], + cwd=repo_root, + check=True, + capture_output=True, + ).stdout + assert hashlib.sha256(historical_status).hexdigest() == EXPECTED_STATUS_SHA256 assert ( _sha256(repo_root / "benchmarks/preflight/SOURCE_MANIFEST.csv") == EXPECTED_SOURCE_MANIFEST_SHA256 @@ -1106,7 +1112,12 @@ def test_governing_files_are_byte_identical(repo_root: Path) -> None: def test_no_semantic_artifact_types_are_created(repo_root: Path) -> None: changed = set( subprocess.run( - ["git", "diff", "--name-only", "37d6fa4dd12f7f26c632169611b13c251bbec14a...HEAD"], + [ + "git", + "diff", + "--name-only", + "37d6fa4dd12f7f26c632169611b13c251bbec14a...d99a38510e51a36972a414cadd0e44d49a04227c", + ], cwd=repo_root, check=True, capture_output=True, diff --git a/tests/contract/test_canada_rights_resolution_dossier.py b/tests/contract/test_canada_rights_resolution_dossier.py index e8d9dcc..f5ed7b4 100644 --- a/tests/contract/test_canada_rights_resolution_dossier.py +++ b/tests/contract/test_canada_rights_resolution_dossier.py @@ -77,7 +77,7 @@ def _load(repo_root: Path, name: str) -> dict[str, Any]: def _changed_files(repo_root: Path) -> list[str]: return subprocess.run( - ["git", "diff", "--name-only", f"{BASE_SHA}...HEAD"], + ["git", "diff", "--name-only", f"{BASE_SHA}...29daa374b7e5cdc30ca7788310fbabb85f19912b"], cwd=repo_root, check=True, capture_output=True, @@ -586,6 +586,14 @@ def test_frozen_artifacts_are_byte_identical_to_the_base(repo_root: Path) -> Non changed = set(_changed_files(repo_root)) for relpath in FROZEN_ARTIFACTS: assert relpath not in changed, f"{relpath} was modified" + if relpath != "STATUS.md": + frozen = subprocess.run( + ["git", "show", f"29daa374b7e5cdc30ca7788310fbabb85f19912b:{relpath}"], + cwd=repo_root, + check=True, + capture_output=True, + ).stdout + assert (repo_root / relpath).read_bytes() == frozen def test_source_manifest_is_unchanged(repo_root: Path) -> None: diff --git a/tests/contract/test_claims_discipline.py b/tests/contract/test_claims_discipline.py index 7789df6..9803022 100644 --- a/tests/contract/test_claims_discipline.py +++ b/tests/contract/test_claims_discipline.py @@ -8,6 +8,7 @@ from __future__ import annotations +import json import re from pathlib import Path @@ -84,6 +85,21 @@ #: Y, or Z"). _CONTEXT = 220 +GATE_F_EXCLUSIONS = ( + "semantic correctness", + "model accuracy", + "institutional validity", + "legal effect", + "provider qualification", + "rights resolution", + "ontology execution", + "production compilation", + "runtime authorization", + "institutional-IR closure", + "enterprise readiness", + "benchmark superiority", +) + @pytest.fixture(scope="module") def documents(repo_root: Path) -> dict[str, str]: @@ -120,8 +136,8 @@ def test_operator_guide_states_the_semantic_gate_is_blocked(documents: dict[str, # Markdown emphasis may wrap either the word or the whole sentence, so match the # claim with emphasis markers stripped. plain = text.replace("*", "") - assert "semantic implementation gate is blocked" in plain - assert "no semantic implementation exists" in plain + assert "production semantic gate remains blocked" in plain + assert "bounded_reference_implementation" in plain def test_operator_guide_states_ztl_and_veip_are_provisional(documents: dict[str, str]) -> None: @@ -193,22 +209,176 @@ def test_polyform_noncommercial_license_is_declared(repo_root: Path) -> None: assert 'license-files = ["LICENSE"]' in pyproject -def test_claims_bearing_documents_are_unchanged_by_this_work_order(repo_root: Path) -> None: - """The Class B claims documents must be byte-identical to their bootstrap versions. +def test_static_claims_documents_are_unchanged_by_this_work_order(repo_root: Path) -> None: + """The static claims documents remain byte-identical to their bootstrap versions. ADR-012 protects Class B artifacts procedurally rather than by digest registry, so - this test states the specific obligation for the documents that carry claims: this - work order does not touch them. Compared against the blob at the bootstrap commit, - not against a manifest, because the manifest describes that commit rather than now. + This test protects CLAIMS.md, LIMITATIONS.md and OWNERS.md. STATUS.md intentionally + evolves and is governed separately by semantic claims controls below. """ import subprocess from oic.baseline import BOOTSTRAP_COMMIT - for relpath in ("CLAIMS.md", "LIMITATIONS.md", "STATUS.md", "OWNERS.md"): + for relpath in ("CLAIMS.md", "LIMITATIONS.md", "OWNERS.md"): committed = subprocess.run( ["git", "-C", str(repo_root), "cat-file", "blob", f"{BOOTSTRAP_COMMIT}:{relpath}"], capture_output=True, check=True, ).stdout - assert (repo_root / relpath).read_bytes() == committed, relpath + observed = (repo_root / relpath).read_bytes() + assert observed == committed, relpath + + +def _assert_status_claims(text: str, capability_matrix: dict[str, object]) -> None: + """Require the active bounded state and ceilings; reject affirmative escalation.""" + normalized = " ".join(text.lower().replace("*", "").split()) + state = capability_matrix["state"] + gate = capability_matrix["production_semantic_gate"] + ceilings = capability_matrix["ceilings"] + evidence = capability_matrix.get("independent_validation_evidence") + assert isinstance(state, str) and state.lower() in normalized + assert isinstance(gate, str) and f"production semantic gate: {gate.lower()}" in normalized + assert isinstance(ceilings, dict) + required = { + "nvidia": "nvidia: not_qualified", + "canada_redistribution": "canada redistribution: unresolved", + "ontology_007r1": "ontology 007r1: unexecuted and execution-unauthorized", + "production_compilation": "production compilation and runtime authorization: unestablished", + "runtime_authorization": "production compilation and runtime authorization: unestablished", + "institutional_ir_closure": "institutional-ir closure: unestablished", + "negative_stability_live_result": "negative-stability live outcome: deferred", + } + for key, phrase in required.items(): + assert key in ceilings and phrase in normalized, f"missing STATUS.md ceiling: {key}" + independently_validated = ceilings.get("independent_validation") + assert isinstance(independently_validated, bool) + if independently_validated: + assert isinstance(evidence, dict) + assert evidence.get("status") == "GATE_F_PASS" + assert evidence.get("work_order") == "OIC-INDEPENDENT-GATE-F-005" + candidate = evidence.get("candidate_commit") + tree = evidence.get("candidate_tree") + assert isinstance(candidate, str) and candidate in normalized + assert isinstance(tree, str) and tree in normalized + assert "independent gate f repository validation passed" in normalized, ( + "missing STATUS.md independent Gate F validation statement" + ) + assert "1714 passed, 0 failed, 0 errors, 1 declared skip, 93.5% coverage" in normalized + assert "merge remains pending gate g and owner authorization" in normalized + assert "does not establish semantic correctness" in normalized + assert evidence.get("exclusions") == list(GATE_F_EXCLUSIONS) + for exclusion in GATE_F_EXCLUSIONS: + assert exclusion.lower() in normalized + else: + assert evidence is None + assert "pending independent validation" in normalized + for phrase in FORBIDDEN_ABSOLUTELY: + assert phrase not in normalized, f"forbidden STATUS.md claim: {phrase}" + for phrase in ( + "production complete", + "nvidia qualified", + "redistribution authorized", + "ontology 007r1 executed", + "runtime authorized", + "independently validated", + "semantic correctness established", + "gate g passed", + ): + assert phrase not in normalized, f"unsupported STATUS.md escalation: {phrase}" + + +def test_status_reports_active_bounded_state_and_ceilings(repo_root: Path) -> None: + """The shipped STATUS.md must reflect the active matrix without claim escalation.""" + status = (repo_root / "STATUS.md").read_text(encoding="utf-8") + matrix: dict[str, object] = json.loads( + (repo_root / "docs/capabilities/CAPABILITY_MATRIX.json").read_text(encoding="utf-8") + ) + _assert_status_claims(status, matrix) + + missing_ceiling = status.replace("NVIDIA: NOT_QUALIFIED and excluded from the demo. ", "") + with pytest.raises(AssertionError, match="nvidia"): + _assert_status_claims(missing_ceiling, matrix) + + forbidden_claim = status + "\nThe system is production complete.\n" + with pytest.raises(AssertionError, match="production complete"): + _assert_status_claims(forbidden_claim, matrix) + + validation_marker = "independent gate f repository validation passed" + assert validation_marker in " ".join(status.lower().replace("*", "").split()) + missing_evidence, replacement_count = re.subn( + re.escape(validation_marker), + "repository validation marker removed", + status, + flags=re.IGNORECASE, + ) + assert replacement_count > 0 + assert missing_evidence != status + missing_normalized = " ".join(missing_evidence.lower().replace("*", "").split()) + assert validation_marker not in missing_normalized + with pytest.raises( + AssertionError, + match=re.escape("missing STATUS.md independent Gate F validation statement"), + ): + _assert_status_claims(missing_evidence, matrix) + + forged_matrix = json.loads(json.dumps(matrix)) + forged_matrix["independent_validation_evidence"]["candidate_commit"] = "0" * 40 + with pytest.raises(AssertionError): + _assert_status_claims(status, forged_matrix) + + broad_claim = status + "\nThe implementation is independently validated.\n" + with pytest.raises(AssertionError, match="independently validated"): + _assert_status_claims(broad_claim, matrix) + + pending_matrix = json.loads(json.dumps(matrix)) + pending_matrix["ceilings"]["independent_validation"] = False + del pending_matrix["independent_validation_evidence"] + pending_status = status.replace( + "SCOPED INDEPENDENT GATE F REPOSITORY VALIDATION PASSED", + "PENDING INDEPENDENT VALIDATION", + ) + _assert_status_claims(pending_status, pending_matrix) + + +def test_gate_f_exclusions_are_exact_and_present_in_both_front_doors(repo_root: Path) -> None: + matrix = json.loads( + (repo_root / "docs/capabilities/CAPABILITY_MATRIX.json").read_text(encoding="utf-8") + ) + assert matrix["independent_validation_evidence"]["exclusions"] == list(GATE_F_EXCLUSIONS) + for relpath in ("README.md", "STATUS.md"): + normalized = " ".join((repo_root / relpath).read_text(encoding="utf-8").lower().split()) + for exclusion in GATE_F_EXCLUSIONS: + assert exclusion.lower() in normalized, ( + f"missing {relpath} Gate F exclusion: {exclusion}" + ) + + +@pytest.mark.parametrize("mutation", ("delete", "substitute", "reorder", "add")) +def test_matrix_gate_f_exclusion_mutations_fail_closed(repo_root: Path, mutation: str) -> None: + import importlib.util + + spec = importlib.util.spec_from_file_location( + "bounded_gate_claims", repo_root / "scripts/verify_code_start_gate.py" + ) + assert spec and spec.loader + module = importlib.util.module_from_spec(spec) + spec.loader.exec_module(module) + evidence = json.loads( + json.dumps( + json.loads( + (repo_root / "docs/capabilities/CAPABILITY_MATRIX.json").read_text(encoding="utf-8") + )["independent_validation_evidence"] + ) + ) + exclusions = evidence["exclusions"] + if mutation == "delete": + exclusions.pop(0) + elif mutation == "substitute": + exclusions[0] = "semantic validity" + elif mutation == "reorder": + exclusions[0], exclusions[1] = exclusions[1], exclusions[0] + else: + exclusions.append("production readiness") + with pytest.raises(module.GateEvidenceError, match="evidence forged"): + module.validate_independent_validation_evidence(evidence) diff --git a/tests/contract/test_semantic_code_start_gate_closure.py b/tests/contract/test_semantic_code_start_gate_closure.py index 9024078..0d7e199 100644 --- a/tests/contract/test_semantic_code_start_gate_closure.py +++ b/tests/contract/test_semantic_code_start_gate_closure.py @@ -162,11 +162,19 @@ def _isolated_gate_tree(repo_root: Path, tmp_path: Path) -> Path: def test_t1_production_detector_accepts_exact_baseline(repo_root: Path) -> None: module = _module(repo_root) assert module.discover_unadmitted_production_paths(repo_root) == [] + assert module.ADMITTED_SRC_OIC_PATHS.isdisjoint(module.BOUNDED_SRC_OIC_PATHS) @pytest.mark.parametrize( "relpath", - ("src/oic/semantic_parser.py", "src/oic/helper.py", "src/oic/newmodule/engine.py"), + ( + "src/oic/semantic_parser.py", + "src/oic/helper.py", + "src/oic/newmodule/engine.py", + "src/oic/__pycache__lookalike/engine.py", + "src/oic/cache.pyc.json", + "src/oic/unadmitted.json", + ), ) def test_t2_t3_t4_detector_refuses_any_new_tracked_path( repo_root: Path, tmp_path: Path, relpath: str @@ -217,5 +225,26 @@ def test_t7_working_tree_cannot_self_extend_immutable_baseline( added = root / "src/oic/future_admitted.py" added.write_text("# existence does not confer admission\n", encoding="utf-8") subprocess.run(["git", "-C", str(root), "add", "src/oic/future_admitted.py"], check=True) + cache_paths = ( + "src/oic/__pycache__/fixture.cpython-312.pyc", + "src/oic/nested/__pycache__/cache-data", + "src/oic/fixture.pyc", + "src/oic/fixture.pyo", + ) + for tracked in (True, False): + paths = cache_paths if tracked else tuple(path + ".pyc" for path in cache_paths) + for relpath in paths: + cache = root / relpath + cache.parent.mkdir(parents=True, exist_ok=True) + cache.write_bytes(b"deterministic cache artifact; not imported\n") + if tracked: + subprocess.run(["git", "-C", str(root), "add", "--", *paths], check=True) + tracked_paths = subprocess.run( + ["git", "-C", str(root), "ls-files", "--", "src/oic"], + check=True, + capture_output=True, + text=True, + ).stdout.splitlines() + assert set(cache_paths) <= set(tracked_paths) assert "src/oic/future_admitted.py" not in module.ADMITTED_SRC_OIC_PATHS assert module.discover_unadmitted_production_paths(root) == ["src/oic/future_admitted.py"] diff --git a/tests/contract/test_semantic_promotion.py b/tests/contract/test_semantic_promotion.py new file mode 100644 index 0000000..2058082 --- /dev/null +++ b/tests/contract/test_semantic_promotion.py @@ -0,0 +1,198 @@ +"""Offline acceptance and fail-closed mutation checks for the bounded promotion.""" + +from __future__ import annotations + +import importlib.util +import json +import os +import shutil +import subprocess +import sys +from pathlib import Path +from types import ModuleType + +import pytest + +pytestmark = pytest.mark.contract + + +def gate(root: Path) -> ModuleType: + spec = importlib.util.spec_from_file_location( + "bounded_gate", root / "scripts/verify_code_start_gate.py" + ) + assert spec and spec.loader + module = importlib.util.module_from_spec(spec) + spec.loader.exec_module(module) + return module + + +def run_demo(root: Path) -> bytes: + env = { + key: value + for key, value in os.environ.items() + if not any(token in key.upper() for token in ("API_KEY", "NVIDIA", "ANTHROPIC")) + } + env["PYTHONDONTWRITEBYTECODE"] = "1" + program = ( + "import socket,runpy; " + "socket.socket=lambda *a,**k: (_ for _ in ()).throw(RuntimeError('NETWORK FORBIDDEN')); " + "socket.create_connection=socket.socket; " + "runpy.run_path('scripts/demo_bounded_semantic_path.py',run_name='__main__')" + ) + result = subprocess.run( + [sys.executable, "-B", "-c", program], cwd=root, env=env, capture_output=True, check=True + ) + assert result.stderr == b"" + return result.stdout + + +def test_demo_two_runs_are_identical_and_do_not_write(repo_root: Path) -> None: + before = subprocess.check_output( + ["git", "status", "--short", "--untracked-files=all"], cwd=repo_root + ) + first, second = run_demo(repo_root), run_demo(repo_root) + assert first == second + assert ( + subprocess.check_output( + ["git", "status", "--short", "--untracked-files=all"], cwd=repo_root + ) + == before + ) + output = json.loads(first) + assert ( + first + == json.dumps( + output, ensure_ascii=False, allow_nan=False, sort_keys=True, separators=(",", ":") + ).encode() + ) + assert output["scope"] == "SYNTHETIC_BOUNDED_REFERENCE_IMPLEMENTATION" + assert output["review"]["agreement_state"] == "DIVERGENT" + assert len(output["review"]["proposal_sets"]) == 2 + assert output["review"]["institutional_admission"] is False + assert output["admission"]["admission_state"] == "ADMITTED" + assert output["proposal"]["proposal_state"] == "PROVISIONAL" + assert output["proposal"]["epistemic_state"] == "uncertain" + assert output["negative_path"] == { + "missing_authority_state": "MISSING_AUTHORITY_EVIDENCE", + "interpretation": "REFUSED_BEFORE_PROVIDER", + "malformed_authority": "REFUSED_AT_INPUT_BOUNDARY", + } + assert output["ceilings"]["independent_validation"] is False + source = (repo_root / "benchmarks/demo/bounded-semantic-path/SOURCE.txt").read_text() + for candidate in output["review"]["candidates_by_id"].values(): + assert candidate["candidate_span"] in source + slots = {a["slot"] for a in output["proposal"]["proposed_assertions"]} + assert len(slots) == 11 + assert {"condition", "exception", "temporal_qualifier", "definiendum", "definiens"} <= slots + assert output["proposal"]["proposed_unresolved_references"] == [ + {"reference_text": "section SYN-9", "reference_kind": "INTERNAL_PROVISION"} + ] + + +@pytest.fixture +def gate_tree(repo_root: Path, tmp_path: Path) -> Path: + """Copy bounded files only; do not copy experiment refs or execute providers.""" + matrix = json.loads((repo_root / "docs/capabilities/CAPABILITY_MATRIX.json").read_bytes()) + paths = set(matrix["authorized_maximum_paths"]) | set(gate(repo_root).ADMITTED_SRC_OIC_PATHS) + paths.add("docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md") + for name in paths: + dest = tmp_path / name + dest.parent.mkdir(parents=True, exist_ok=True) + shutil.copyfile(repo_root / name, dest) + subprocess.run(["git", "init", "-q", str(tmp_path)], check=True) + return tmp_path + + +def test_self_extension_is_refused(repo_root: Path, gate_tree: Path) -> None: + module = gate(repo_root) + path = gate_tree / "docs/capabilities/CAPABILITY_MATRIX.json" + matrix = json.loads(path.read_bytes()) + matrix["authorized_maximum_paths"].append("src/oic/unauthorized.py") + path.write_text(json.dumps(matrix), encoding="utf-8") + with pytest.raises(module.GateEvidenceError, match="self-extend"): + module.validate_bounded_record(gate_tree) + + +def test_untracked_semantic_extension_is_refused(repo_root: Path, gate_tree: Path) -> None: + module = gate(repo_root) + (gate_tree / "src/oic/unauthorized.py").write_text("# not admitted\n") + with pytest.raises(module.GateEvidenceError, match="unauthorized production"): + module.validate_bounded_record(gate_tree) + + +def test_missing_required_path_is_refused(repo_root: Path, gate_tree: Path) -> None: + module = gate(repo_root) + (gate_tree / "src/oic/frozen_synthetic_provider.py").unlink() + with pytest.raises(module.GateEvidenceError, match="missing required"): + module.validate_bounded_record(gate_tree) + + +def test_historical_gate_rewrite_is_refused(repo_root: Path, gate_tree: Path) -> None: + module = gate(repo_root) + (gate_tree / "docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md").write_text("OPEN") + with pytest.raises(module.GateEvidenceError, match="historical gate"): + module.validate_bounded_record(gate_tree) + + +@pytest.mark.parametrize( + "key,value", + [ + ("nvidia", "QUALIFIED"), + ("canada_redistribution", "CLEAR"), + ("runtime_authorization", "ESTABLISHED"), + ("production_compilation", "ESTABLISHED"), + ("ontology_007r1", "EXECUTED"), + ], +) +def test_claim_escalation_is_refused( + repo_root: Path, gate_tree: Path, key: str, value: str | bool +) -> None: + module = gate(repo_root) + path = gate_tree / "docs/capabilities/CAPABILITY_MATRIX.json" + matrix = json.loads(path.read_bytes()) + matrix["ceilings"][key] = value + path.write_text(json.dumps(matrix), encoding="utf-8") + with pytest.raises(module.GateEvidenceError, match="ceiling"): + module.validate_bounded_record(gate_tree) + + +def test_frozen_source_and_inherited_manifests_are_unchanged(repo_root: Path) -> None: + base = "9ad37fc80d8f34318c6212ed702de5eab3551cf5" + for name in ("benchmarks/preflight/SOURCE_MANIFEST.csv", "BOOTSTRAP_MANIFEST.json"): + assert (repo_root / name).read_bytes() == subprocess.check_output( + ["git", "show", f"{base}:{name}"], cwd=repo_root + ) + + +def test_capability_claim_self_extension_is_refused(repo_root: Path, gate_tree: Path) -> None: + module = gate(repo_root) + path = gate_tree / "docs/capabilities/CAPABILITY_MATRIX.json" + matrix = json.loads(path.read_bytes()) + matrix["capabilities"][0]["independent_validation"] = True + path.write_text(json.dumps(matrix), encoding="utf-8") + with pytest.raises(module.GateEvidenceError, match="capability claim expanded"): + module.validate_bounded_record(gate_tree) + + +def test_independent_validation_evidence_removal_is_refused( + repo_root: Path, gate_tree: Path +) -> None: + module = gate(repo_root) + path = gate_tree / "docs/capabilities/CAPABILITY_MATRIX.json" + matrix = json.loads(path.read_bytes()) + del matrix["independent_validation_evidence"] + path.write_text(json.dumps(matrix), encoding="utf-8") + with pytest.raises(module.GateEvidenceError): + module.validate_bounded_record(gate_tree) + + +def test_forged_independent_validation_evidence_is_refused( + repo_root: Path, gate_tree: Path +) -> None: + module = gate(repo_root) + path = gate_tree / "docs/capabilities/CAPABILITY_MATRIX.json" + matrix = json.loads(path.read_bytes()) + matrix["independent_validation_evidence"]["candidate_commit"] = "0" * 40 + path.write_text(json.dumps(matrix), encoding="utf-8") + with pytest.raises(module.GateEvidenceError, match="evidence forged"): + module.validate_bounded_record(gate_tree) diff --git a/tests/contract/test_warrant_contract.py b/tests/contract/test_warrant_contract.py index b5abd09..4a136a6 100644 --- a/tests/contract/test_warrant_contract.py +++ b/tests/contract/test_warrant_contract.py @@ -1302,7 +1302,14 @@ def test_no_ztl_or_veip_code_exists_or_is_imported(repo_root: Path) -> None: def test_this_work_order_added_no_source_module(repo_root: Path) -> None: - modules = {path.name for path in (repo_root / "src" / "oic").glob("*.py")} + historical_paths = subprocess.run( + ["git", "ls-tree", "--name-only", "afb2b72ba9f01665c78b904a334e9a271be4b950:src/oic"], + cwd=repo_root, + check=True, + capture_output=True, + text=True, + ).stdout.splitlines() + modules = {name for name in historical_paths if name.endswith(".py")} assert modules == { "__init__.py", "baseline.py", @@ -1337,7 +1344,13 @@ def test_status_md_is_byte_identical_to_the_bootstrap(repo_root: Path) -> None: capture_output=True, check=True, ).stdout - assert (repo_root / "STATUS.md").read_bytes() == committed + historical = subprocess.run( + ["git", "show", "afb2b72ba9f01665c78b904a334e9a271be4b950:STATUS.md"], + cwd=repo_root, + check=True, + capture_output=True, + ).stdout + assert historical == committed def test_proposed_schemas_are_not_in_the_draft_directory(repo_root: Path) -> None: diff --git a/tests/unit/test_admission.py b/tests/unit/test_admission.py new file mode 100644 index 0000000..d87a1c9 --- /dev/null +++ b/tests/unit/test_admission.py @@ -0,0 +1,626 @@ +"""Behavioral tests for the admission reference evaluator. + +Two things are under test and they are kept apart on purpose: + +* the **byte boundary** — inputs that are not admissible executable inputs at all, which + must raise :class:`AdmissionInputBoundaryError` and must never become an admission + state; and +* the **state machine** — admissible inputs, each of which must produce exactly one + frozen terminal state. + +Fixtures are built by changing one fact at a time in a frozen vector, so each test names +the single observable difference that moves the outcome. +""" + +from __future__ import annotations + +import ast +import copy +import json +import socket +from pathlib import Path +from typing import Any + +import pytest + +from oic.admission import ( + EVALUATOR_ID, + EVALUATOR_VERSION, + RULESET_DIGEST, + RULESET_ID, + AdmissionCanonicalFormError, + AdmissionEncodingError, + AdmissionError, + AdmissionEvidenceIntegrityError, + AdmissionEvidenceOrderError, + AdmissionInputBoundaryError, + AdmissionJSONError, + AdmissionReceipt, + AdmissionRulesetError, + AdmissionSchemaError, + AdmissionState, + AdmissionTimestampError, + canonical_json, + digest_of, + evaluate_admission_bytes, +) + +VECTORS_RELPATH = Path("design/admission-boundary-001/TEST-VECTORS-v0.2.json") +_ROOT = Path(__file__).resolve().parents[2] +_CORPUS: dict[str, Any] = json.loads((_ROOT / VECTORS_RELPATH).read_text(encoding="utf-8")) +_INPUTS: dict[str, dict[str, Any]] = { + str(vector["vector_id"]): vector["executable_input"] for vector in _CORPUS["vectors"] +} + +#: An input whose frozen expectation is ADMITTED, used as the base for single-fact edits. +ADMITTED_VECTOR = "ADM-001" +OTHER_DIGEST = "sha256:" + "0" * 64 + + +def _base(vector_id: str = ADMITTED_VECTOR) -> dict[str, Any]: + return copy.deepcopy(_INPUTS[vector_id]) + + +def _seal(document: dict[str, Any]) -> bytes: + """Recompute evidence digests and canonical evidence order, then serialize. + + This is what an institution's evidence custodian does before an input is frozen. The + evaluator itself never does it: it verifies and refuses. + """ + for item in document["authority_evidence"]: + item.pop("evidence_digest", None) + item["evidence_digest"] = digest_of(canonical_json(item)) + document["authority_evidence"].sort( + key=lambda item: (item["evidence_id"], item["evidence_digest"]) + ) + return canonical_json(document) + + +def _state(document: dict[str, Any]) -> AdmissionState: + return evaluate_admission_bytes(_seal(document)).admission_state + + +# --------------------------------------------------------------------------- +# The byte boundary. None of these is an admission outcome. +# --------------------------------------------------------------------------- + + +def test_a_valid_frozen_input_is_accepted_so_the_rejections_below_mean_something() -> None: + receipt = evaluate_admission_bytes(canonical_json(_base())) + assert isinstance(receipt, AdmissionReceipt) + assert receipt.admission_state is AdmissionState.ADMITTED + + +def test_bytes_that_are_not_utf8_are_refused() -> None: + with pytest.raises(AdmissionEncodingError): + evaluate_admission_bytes(b'{"a"\xff:1}') + + +def test_a_utf8_byte_order_mark_is_refused() -> None: + with pytest.raises(AdmissionEncodingError): + evaluate_admission_bytes(b"\xef\xbb\xbf" + canonical_json(_base())) + + +def test_a_str_is_refused_rather_than_encoded() -> None: + with pytest.raises(AdmissionInputBoundaryError): + evaluate_admission_bytes(canonical_json(_base()).decode("utf-8")) # type: ignore[arg-type] + + +def test_empty_bytes_are_refused() -> None: + with pytest.raises(AdmissionJSONError): + evaluate_admission_bytes(b"") + + +def test_a_trailing_newline_is_refused_rather_than_stripped() -> None: + with pytest.raises(AdmissionCanonicalFormError): + evaluate_admission_bytes(canonical_json(_base()) + b"\n") + + +def test_leading_whitespace_is_refused() -> None: + with pytest.raises(AdmissionCanonicalFormError): + evaluate_admission_bytes(b" " + canonical_json(_base())) + + +def test_pretty_printed_json_is_refused_rather_than_compacted() -> None: + payload = json.dumps(_base(), sort_keys=True, indent=2).encode("utf-8") + with pytest.raises(AdmissionCanonicalFormError): + evaluate_admission_bytes(payload) + + +def test_unsorted_object_keys_are_refused_rather_than_sorted() -> None: + payload = json.dumps(_base(), sort_keys=False, separators=(",", ":")).encode("utf-8") + with pytest.raises(AdmissionCanonicalFormError): + evaluate_admission_bytes(payload) + + +def test_ascii_escaped_strings_are_refused() -> None: + document = _base() + document["candidate"]["candidate_span"] = "Récords are kept." + payload = json.dumps(document, sort_keys=True, separators=(",", ":"), ensure_ascii=True).encode( + "utf-8" + ) + with pytest.raises(AdmissionCanonicalFormError): + evaluate_admission_bytes(payload) + + +def test_a_duplicate_object_key_is_refused() -> None: + payload = canonical_json(_base()) + assert payload.startswith(b"{") + injected = b'{"evaluation_time":"2026-06-01T00:00:00Z",' + payload[1:] + with pytest.raises(AdmissionJSONError, match="duplicate object key"): + evaluate_admission_bytes(injected) + + +@pytest.mark.parametrize("payload", [b"[]", b'"text"', b"12", b"null", b"true"]) +def test_a_json_value_that_is_not_an_object_is_refused(payload: bytes) -> None: + with pytest.raises(AdmissionJSONError): + evaluate_admission_bytes(payload) + + +def test_trailing_content_after_the_object_is_refused() -> None: + with pytest.raises(AdmissionJSONError): + evaluate_admission_bytes(canonical_json(_base()) + b"{}") + + +@pytest.mark.parametrize("literal", [b"NaN", b"Infinity", b"-Infinity"]) +def test_non_json_numeric_literals_are_refused(literal: bytes) -> None: + payload = canonical_json(_base()).replace(b'"page":null', b'"page":' + literal, 1) + assert payload != canonical_json(_base()) + with pytest.raises(AdmissionInputBoundaryError): + evaluate_admission_bytes(payload) + + +def test_a_missing_required_top_level_field_is_refused() -> None: + document = _base() + del document["evaluation_scope"] + with pytest.raises(AdmissionSchemaError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_an_unknown_top_level_field_is_refused() -> None: + document = _base() + document["input_digest"] = OTHER_DIGEST + with pytest.raises(AdmissionSchemaError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_a_candidate_carrying_an_authority_claim_is_refused() -> None: + """The candidate projection has no field in which a model could assert authority.""" + document = _base() + document["candidate"]["authority"] = "board" + with pytest.raises(AdmissionSchemaError): + evaluate_admission_bytes(canonical_json(document)) + + +@pytest.mark.parametrize( + ("pointer", "value"), + [ + ("unit_id", "not-a-candidate-id"), + ("interpretation_state", "interpreted"), + ("epistemic_state", "established"), + ("unit_type", "invented_type"), + ], +) +def test_a_candidate_outside_the_frozen_projection_is_refused(pointer: str, value: str) -> None: + document = _base() + document["candidate"][pointer] = value + with pytest.raises(AdmissionSchemaError): + evaluate_admission_bytes(canonical_json(document)) + + +@pytest.mark.parametrize( + ("field", "value"), + [("evaluator_id", "some-other-evaluator"), ("evaluator_version", "0.2")], +) +def test_an_input_naming_a_different_evaluator_is_refused(field: str, value: str) -> None: + document = _base() + document["evaluator"][field] = value + with pytest.raises(AdmissionSchemaError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_an_input_naming_a_different_ruleset_id_is_refused() -> None: + document = _base() + document["ruleset"]["ruleset_id"] = "SOME-OTHER-RULESET" + with pytest.raises(AdmissionInputBoundaryError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_caller_selected_admission_rules_are_refused() -> None: + document = _base() + document["ruleset"]["ruleset_digest"] = OTHER_DIGEST + with pytest.raises(AdmissionRulesetError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_evidence_out_of_canonical_order_is_refused_rather_than_sorted() -> None: + document = _base("ADM-017") + document["authority_evidence"].reverse() + with pytest.raises(AdmissionEvidenceOrderError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_a_duplicate_evidence_id_is_refused() -> None: + document = _base("ADM-017") + document["authority_evidence"][1]["evidence_id"] = document["authority_evidence"][0][ + "evidence_id" + ] + for item in document["authority_evidence"]: + item.pop("evidence_digest", None) + item["evidence_digest"] = digest_of(canonical_json(item)) + document["authority_evidence"].sort( + key=lambda item: (item["evidence_id"], item["evidence_digest"]) + ) + with pytest.raises(AdmissionEvidenceOrderError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_an_evidence_digest_that_does_not_recompute_is_refused() -> None: + document = _base() + document["authority_evidence"][0]["issuer_id"] = "a-different-issuer" + with pytest.raises(AdmissionEvidenceIntegrityError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_a_forged_evidence_digest_is_refused() -> None: + document = _base() + document["authority_evidence"][0]["evidence_digest"] = OTHER_DIGEST + with pytest.raises(AdmissionEvidenceIntegrityError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_a_non_normalized_timestamp_offset_is_refused() -> None: + document = _base() + document["evaluation_time"] = "2026-06-01T00:00:00+00:00" + with pytest.raises(AdmissionSchemaError): + evaluate_admission_bytes(canonical_json(document)) + + +def test_a_fractional_second_timestamp_is_refused_rather_than_truncated() -> None: + document = _base() + document["evaluation_time"] = "2026-06-01T00:00:00.000Z" + with pytest.raises(AdmissionTimestampError): + evaluate_admission_bytes(_seal(document)) + + +def test_an_input_boundary_failure_is_never_an_admission_state() -> None: + """A malformed input has not been evaluated. Converting it to a terminal state would + manufacture institutional evidence out of a parse failure.""" + with pytest.raises(AdmissionInputBoundaryError) as caught: + evaluate_admission_bytes(b"{}") + # A boundary failure carries no state, so it cannot name one either: an operator + # reading the message must not be able to record it as an admission outcome. + message = str(caught.value) + for state in AdmissionState: + assert state.value not in message + + +def test_a_boundary_error_message_does_not_echo_the_payload() -> None: + document = _base() + document["candidate"]["candidate_span"] = "SECRET-CANARY-VALUE" + document["input_digest"] = OTHER_DIGEST + with pytest.raises(AdmissionInputBoundaryError) as caught: + evaluate_admission_bytes(canonical_json(document)) + assert "SECRET-CANARY-VALUE" not in str(caught.value) + + +# --------------------------------------------------------------------------- +# One frozen terminal state per admissible input +# --------------------------------------------------------------------------- + + +def test_candidate_input_invalid_when_the_candidate_has_no_source_anchor() -> None: + document = _base() + document["candidate"]["source_anchors"] = [] + assert _state(document) is AdmissionState.CANDIDATE_INPUT_INVALID + + +def test_candidate_input_invalid_when_an_anchor_names_a_different_source() -> None: + document = _base() + document["candidate"]["source_anchors"][0]["source_id"] = "some-other-source" + assert _state(document) is AdmissionState.CANDIDATE_INPUT_INVALID + + +def test_authority_registry_unavailable_when_the_registry_was_not_observed() -> None: + document = _base() + document["source_registration"]["registry_observation"]["availability"] = "UNAVAILABLE" + document["source_registration"]["registry_observation"]["freshness"] = "NOT_OBSERVED" + assert _state(document) is AdmissionState.AUTHORITY_REGISTRY_UNAVAILABLE + + +def test_authority_evidence_stale_when_the_observation_is_beyond_its_freshness_bound() -> None: + document = _base() + document["source_registration"]["registry_observation"]["freshness"] = "STALE" + assert _state(document) is AdmissionState.AUTHORITY_EVIDENCE_STALE + + +def test_source_not_registered_when_the_registry_holds_no_entry() -> None: + document = _base() + document["source_registration"]["registered"] = False + assert _state(document) is AdmissionState.SOURCE_NOT_REGISTERED + + +def test_source_version_mismatch_when_no_evidence_binds_the_registered_version() -> None: + document = _base() + evidence = document["authority_evidence"][0] + evidence["source_version"] = "some-other-version" + evidence["admission_warrant"]["source_version"] = "some-other-version" + assert _state(document) is AdmissionState.SOURCE_VERSION_MISMATCH + + +def test_source_digest_mismatch_when_the_candidate_anchor_bytes_differ() -> None: + document = _base() + document["candidate"]["source_anchors"][0]["content_hash"] = OTHER_DIGEST + assert _state(document) is AdmissionState.SOURCE_DIGEST_MISMATCH + + +def test_source_digest_mismatch_when_no_evidence_binds_the_registered_digest() -> None: + document = _base() + evidence = document["authority_evidence"][0] + evidence["source_digest"] = OTHER_DIGEST + evidence["admission_warrant"]["source_digest"] = OTHER_DIGEST + assert _state(document) is AdmissionState.SOURCE_DIGEST_MISMATCH + + +def test_missing_authority_evidence_when_no_evidence_is_supplied() -> None: + document = _base() + document["authority_evidence"] = [] + assert _state(document) is AdmissionState.MISSING_AUTHORITY_EVIDENCE + + +def test_out_of_scope_when_the_requested_applicability_is_outside_the_warrant() -> None: + document = _base() + document["evaluation_scope"]["applicability"] = "something-else" + assert _state(document) is AdmissionState.OUT_OF_SCOPE + + +def test_out_of_scope_when_the_requested_jurisdiction_is_outside_the_warrant() -> None: + document = _base() + document["evaluation_scope"]["jurisdiction"] = "another-jurisdiction" + assert _state(document) is AdmissionState.OUT_OF_SCOPE + + +def test_not_yet_effective_when_evaluation_time_precedes_effectiveness() -> None: + document = _base() + document["evaluation_time"] = "2025-06-01T00:00:00Z" + assert _state(document) is AdmissionState.NOT_YET_EFFECTIVE + + +def test_expired_when_evaluation_time_is_at_or_after_effective_until() -> None: + document = _base() + document["source_registration"]["effective_until"] = "2026-03-01T00:00:00Z" + assert _state(document) is AdmissionState.EXPIRED + + +def test_the_effective_interval_is_half_open_at_its_end() -> None: + document = _base() + document["source_registration"]["effective_until"] = document["evaluation_time"] + assert _state(document) is AdmissionState.EXPIRED + + +def test_superseded_when_evaluation_time_is_at_or_after_supersession() -> None: + document = _base() + document["source_registration"]["superseded_at"] = "2026-03-01T00:00:00Z" + assert _state(document) is AdmissionState.SUPERSEDED + + +def test_revoked_when_evaluation_time_is_at_or_after_revocation() -> None: + document = _base() + document["source_registration"]["revoked_at"] = "2026-03-01T00:00:00Z" + assert _state(document) is AdmissionState.REVOKED + + +def test_revoked_when_the_admission_warrant_itself_is_revoked() -> None: + document = _base() + warrant = document["authority_evidence"][0]["admission_warrant"] + warrant["status"] = "REVOKED" + warrant["revoked_at"] = "2026-03-01T00:00:00Z" + assert _state(document) is AdmissionState.REVOKED + + +def test_conflicting_authority_when_two_operative_authority_bases_overlap() -> None: + document = _base() + rival = copy.deepcopy(document["authority_evidence"][0]) + rival["evidence_id"] = "AE-001-RIVAL" + rival["authority_basis_ref"] = "charter:a-different-basis" + rival["admission_warrant"]["warrant_id"] = "AW-001-RIVAL" + document["authority_evidence"].append(rival) + assert _state(document) is AdmissionState.CONFLICTING_AUTHORITY + + +def test_a_conflict_is_not_resolved_by_recency() -> None: + """The frozen ruleset carries no precedence rule, so a newer rival cannot win.""" + document = _base() + rival = copy.deepcopy(document["authority_evidence"][0]) + rival["evidence_id"] = "AE-001-NEWER" + rival["authority_basis_ref"] = "charter:newer-basis" + rival["issued_at"] = "2026-05-01T00:00:00Z" + rival["admission_warrant"]["warrant_id"] = "AW-001-NEWER" + document["authority_evidence"].append(rival) + assert _state(document) is AdmissionState.CONFLICTING_AUTHORITY + + +def test_two_evidence_objects_sharing_one_authority_basis_do_not_conflict() -> None: + document = _base() + twin = copy.deepcopy(document["authority_evidence"][0]) + twin["evidence_id"] = "AE-001-SECOND-COPY" + twin["admission_warrant"]["warrant_id"] = "AW-001-SECOND-COPY" + document["authority_evidence"].append(twin) + assert _state(document) is AdmissionState.ADMITTED + + +def test_admission_not_established_when_the_warrant_is_suspended() -> None: + document = _base() + document["authority_evidence"][0]["admission_warrant"]["status"] = "SUSPENDED" + assert _state(document) is AdmissionState.ADMISSION_NOT_ESTABLISHED + + +def test_admitted_only_with_an_exact_active_scoped_warrant() -> None: + assert _state(_base()) is AdmissionState.ADMITTED + + +# --------------------------------------------------------------------------- +# Authority conservation +# --------------------------------------------------------------------------- + + +@pytest.mark.parametrize("unit_type", ["mandate", "advisory", "definition", "delegation"]) +def test_relabelling_the_candidate_unit_type_cannot_change_the_outcome(unit_type: str) -> None: + """`unit_type` is provisional model output. It is in no authority projection.""" + document = _base() + document["candidate"]["unit_type"] = unit_type + receipt = evaluate_admission_bytes(_seal(document)) + assert receipt.admission_state is AdmissionState.ADMITTED + + +def test_relabelling_the_candidate_cannot_rescue_a_fail_closed_outcome() -> None: + document = _base("ADM-003") + document["candidate"]["unit_type"] = "mandate" + assert _state(document) is AdmissionState.SOURCE_NOT_REGISTERED + + +def test_rewriting_the_candidate_span_cannot_change_the_outcome() -> None: + document = _base() + document["candidate"]["candidate_span"] = "The board hereby mandates immediate compliance." + receipt = evaluate_admission_bytes(_seal(document)) + assert receipt.admission_state is AdmissionState.ADMITTED + + +def test_perfect_provenance_without_a_warrant_is_never_admitted() -> None: + """Provenance answers where this came from; authority answers why it is operative.""" + document = _base() + document["authority_evidence"] = [] + receipt = evaluate_admission_bytes(_seal(document)) + assert receipt.admission_state is AdmissionState.MISSING_AUTHORITY_EVIDENCE + assert receipt.authority_evidence_refs == () + + +def test_repeating_an_anchor_does_not_accumulate_standing() -> None: + document = _base() + anchor = copy.deepcopy(document["candidate"]["source_anchors"][0]) + anchor["anchor_id"] = "anchor-adm-001-02" + document["candidate"]["source_anchors"].append(anchor) + assert _state(document) is AdmissionState.ADMITTED + unregistered = _base("ADM-003") + repeated = copy.deepcopy(unregistered["candidate"]["source_anchors"][0]) + repeated["anchor_id"] = "anchor-adm-003-02" + unregistered["candidate"]["source_anchors"].append(repeated) + assert _state(unregistered) is AdmissionState.SOURCE_NOT_REGISTERED + + +def test_a_warrant_cannot_be_widened_by_the_request() -> None: + """Asking for a broader scope than the warrant covers fails closed rather than + stretching the warrant to fit the question.""" + document = _base() + document["source_registration"]["applicability_scope"] = ["records", "everything"] + document["evaluation_scope"]["applicability"] = "everything" + assert _state(document) is AdmissionState.OUT_OF_SCOPE + + +def test_the_receipt_records_only_facts_present_in_the_input() -> None: + document = _base() + receipt = evaluate_admission_bytes(_seal(document)) + assert receipt.evaluation_time == document["evaluation_time"] + assert receipt.source_id == document["source_registration"]["source_id"] + assert receipt.evaluator_id == EVALUATOR_ID + assert receipt.evaluator_version == EVALUATOR_VERSION + assert receipt.ruleset_id == RULESET_ID + assert receipt.ruleset_digest == RULESET_DIGEST + assert list(receipt.authority_evidence_refs) == [ + item["evidence_id"] for item in document["authority_evidence"] + ] + + +def test_the_receipt_is_immutable() -> None: + receipt = evaluate_admission_bytes(canonical_json(_base())) + with pytest.raises(AttributeError): + receipt.admission_state = AdmissionState.ADMITTED # type: ignore[misc] + + +# --------------------------------------------------------------------------- +# Time comes only from evaluation_time +# --------------------------------------------------------------------------- + + +def test_the_outcome_moves_only_when_evaluation_time_moves() -> None: + document = _base() + document["source_registration"]["revoked_at"] = "2026-06-15T00:00:00Z" + document["evaluation_time"] = "2026-06-01T00:00:00Z" + assert _state(copy.deepcopy(document)) is AdmissionState.ADMITTED + document["evaluation_time"] = "2026-07-01T00:00:00Z" + assert _state(document) is AdmissionState.REVOKED + + +def test_an_earlier_receipt_is_not_mutated_by_later_revocation_evidence() -> None: + before = evaluate_admission_bytes(canonical_json(_base())) + revoked = _base() + revoked["source_registration"]["revoked_at"] = "2026-03-01T00:00:00Z" + after = evaluate_admission_bytes(_seal(revoked)) + assert before.admission_state is AdmissionState.ADMITTED + assert after.admission_state is AdmissionState.REVOKED + assert before.admission_receipt_id != after.admission_receipt_id + + +def test_the_evaluator_reads_no_clock() -> None: + """Structural, not textual: a wall-clock call is looked for in the parsed module.""" + source = (_ROOT / "src/oic/admission.py").read_text(encoding="utf-8") + tree = ast.parse(source) + forbidden_attributes = {"now", "utcnow", "today", "time", "monotonic", "time_ns", "gmtime"} + for node in ast.walk(tree): + if isinstance(node, ast.Call) and isinstance(node.func, ast.Attribute): + assert node.func.attr not in forbidden_attributes, ast.dump(node.func) + imported = { + alias.name.split(".")[0] + for node in ast.walk(tree) + if isinstance(node, ast.Import) + for alias in node.names + } | { + node.module.split(".")[0] + for node in ast.walk(tree) + if isinstance(node, ast.ImportFrom) and node.module + } + assert "time" not in imported + assert "random" not in imported + assert "uuid" not in imported + assert "os" not in imported + assert "socket" not in imported + assert "urllib" not in imported + + +# --------------------------------------------------------------------------- +# Offline +# --------------------------------------------------------------------------- + + +def test_the_evaluator_runs_with_sockets_disabled() -> None: + """The suite disables sockets; this names the guarantee rather than relying on it. + + Both governing schemas carry absolute https `$id` values and the input schema `$ref`s + one of them by absolute URI. Resolution must still be local. + """ + with pytest.MonkeyPatch.context() as patcher: + + def _explode(*args: object, **kwargs: object) -> None: + del args, kwargs + raise AssertionError("the admission evaluator attempted a network connection") + + patcher.setattr(socket, "socket", _explode) + patcher.setattr(socket, "create_connection", _explode) + patcher.setattr(socket, "getaddrinfo", _explode) + receipt = evaluate_admission_bytes(canonical_json(_base())) + assert receipt.admission_state is AdmissionState.ADMITTED + + +def test_every_boundary_error_is_an_admission_error() -> None: + for error_type in ( + AdmissionEncodingError, + AdmissionJSONError, + AdmissionCanonicalFormError, + AdmissionSchemaError, + AdmissionTimestampError, + AdmissionEvidenceOrderError, + AdmissionEvidenceIntegrityError, + AdmissionRulesetError, + ): + assert issubclass(error_type, AdmissionInputBoundaryError) + assert issubclass(error_type, AdmissionError) diff --git a/tests/unit/test_candidate_extraction.py b/tests/unit/test_candidate_extraction.py new file mode 100644 index 0000000..e1ebbbf --- /dev/null +++ b/tests/unit/test_candidate_extraction.py @@ -0,0 +1,967 @@ +from __future__ import annotations + +import ast +import json +from pathlib import Path + +import pytest + +from oic.candidate_extraction import ( + _ALLOWED_UNIT_TYPES, + _MODEL_FORBIDDEN_AUTHORITY_KEYS, + _REMOVED_SEMANTIC_ROLE_KEYS, + _UNIT_TYPES, + CandidateBoundaryError, + CandidateExtractionResult, + CandidateGroundingError, + check_source_grounding, + propose_candidate_units, +) +from oic.model_provider import ModelRequest, ModelResponse + + +class FakeProvider: + def __init__(self, content: str) -> None: + self.content = content + self.requests: list[ModelRequest] = [] + + def complete(self, request: ModelRequest) -> ModelResponse: + self.requests.append(request) + return ModelResponse( + provider="fake", model="fake-model", content=self.content, request_id="req-1", raw={} + ) + + +SOURCE = "A payment above $10,000 requires approval by the Chief Financial Officer." + + +def anchor(suffix: str = "1") -> dict[str, object]: + return { + "anchor_id": f"A-{suffix}", + "source_id": "DOC-1", + "node_id": "N-7", + "content_hash": "sha256:" + ("a" * 64), + } + + +def extract( + content: str, *, source: str = SOURCE, source_anchor: dict[str, object] | None = None +) -> CandidateExtractionResult: + return propose_candidate_units( + source_text=source, source_anchor=source_anchor or anchor(), provider=FakeProvider(content) + ) + + +def candidate(span: str, unit_type: str = "obligation") -> str: + return json.dumps({"candidates": [{"candidate_span": span, "unit_type": unit_type}]}) + + +def outbound(source: str = SOURCE) -> ModelRequest: + provider = FakeProvider('{"candidates":[]}') + propose_candidate_units(source_text=source, source_anchor=anchor(), provider=provider) + return provider.requests[0] + + +def test_literal_grounded_candidate_span_is_accepted() -> None: + result = extract(candidate(SOURCE)) + item = result.candidates[0] + assert item["candidate_span"] == SOURCE + assert item["unit_type"] == "obligation" + assert item["interpretation_state"] == "extracted" + assert item["epistemic_state"] == "uncertain" + assert item["source_anchors"] == [anchor()] + assert set(item) == { + "unit_id", + "candidate_span", + "unit_type", + "interpretation_state", + "epistemic_state", + "source_anchors", + } + + +@pytest.mark.parametrize( + "span", + [ + "Payments above $10,000 need CFO approval.", + "The Treasurer must approve this payment.", + " ", + ], +) +def test_paraphrased_invented_and_blank_spans_fail_closed(span: str) -> None: + with pytest.raises(CandidateGroundingError): + extract(candidate(span)) + + +def test_case_and_whitespace_collapse_is_comparison_only() -> None: + span = "A PAYMENT above $10,000" + item = extract(candidate(span)).candidates[0] + assert item["candidate_span"] == span + + +def test_unit_type_is_exempt_from_literal_grounding() -> None: + assert "obligation" not in SOURCE.casefold() + assert extract(candidate(SOURCE, "obligation")).candidates[0]["unit_type"] == "obligation" + + +def test_unknown_unit_type_is_rejected() -> None: + with pytest.raises(CandidateBoundaryError, match="unit_type"): + extract(candidate(SOURCE, "allow")) + + +@pytest.mark.parametrize("field", sorted(_REMOVED_SEMANTIC_ROLE_KEYS)) +def test_every_removed_semantic_role_is_forbidden(field: str) -> None: + payload = {"candidate_span": SOURCE, "unit_type": "obligation", field: None} + with pytest.raises(CandidateBoundaryError, match="removed semantic-role"): + extract(json.dumps({"candidates": [payload]})) + + +@pytest.mark.parametrize("field", ["actor", "conditions", "target"]) +def test_motivating_removed_roles_fail_closed(field: str) -> None: + payload = {"candidate_span": SOURCE, "unit_type": "obligation", field: "x"} + with pytest.raises(CandidateBoundaryError, match=field): + extract(json.dumps({"candidates": [payload]})) + + +@pytest.mark.parametrize("field", sorted(_MODEL_FORBIDDEN_AUTHORITY_KEYS)) +def test_every_authority_controlled_field_remains_forbidden(field: str) -> None: + payload = {"candidate_span": SOURCE, "unit_type": "obligation", field: "x"} + with pytest.raises(CandidateBoundaryError, match="authority-controlled"): + extract(json.dumps({"candidates": [payload]})) + + +def test_multiple_valid_candidate_spans_are_preserved_separately() -> None: + source = "Orders must be approved. Invoices must be retained." + body = json.dumps( + { + "candidates": [ + {"candidate_span": "Orders must be approved.", "unit_type": "obligation"}, + {"candidate_span": "Invoices must be retained.", "unit_type": "evidence_duty"}, + ] + } + ) + result = extract(body, source=source) + assert [item["candidate_span"] for item in result.candidates] == [ + "Orders must be approved.", + "Invoices must be retained.", + ] + assert len({item["unit_id"] for item in result.candidates}) == 2 + + +def test_deterministic_ids_change_with_span_type_or_anchor() -> None: + source = "Orders must be approved before shipment." + full = extract(candidate(source), source=source).candidates[0]["unit_id"] + shorter = extract(candidate("Orders must be approved"), source=source).candidates[0]["unit_id"] + other_type = extract(candidate(source, "mandate"), source=source).candidates[0]["unit_id"] + other_anchor = extract(candidate(source), source=source, source_anchor=anchor("2")).candidates[ + 0 + ]["unit_id"] + assert len({full, shorter, other_type, other_anchor}) == 4 + + +def test_same_span_type_and_anchor_have_stable_id() -> None: + first = extract(candidate(SOURCE)).candidates[0]["unit_id"] + second = extract(candidate(SOURCE)).candidates[0]["unit_id"] + assert first == second + + +def test_one_ungrounded_candidate_fails_the_whole_response() -> None: + body = json.dumps( + { + "candidates": [ + {"candidate_span": SOURCE, "unit_type": "obligation"}, + {"candidate_span": "invented", "unit_type": "obligation"}, + ] + } + ) + with pytest.raises(CandidateGroundingError, match="candidate 1"): + extract(body) + + +def test_check_source_grounding_is_direct_and_fail_closed() -> None: + check_source_grounding({"candidate_span": SOURCE}, source_text=SOURCE) + with pytest.raises(CandidateGroundingError): + check_source_grounding({"candidate_span": "a paraphrase"}, source_text=SOURCE) + + +def test_prompt_contract_is_exact_minimal_and_source_standing_invariant() -> None: + request = outbound() + combined = " ".join((request.system_prompt + request.user_prompt).split()) + assert '{"candidates":[{"candidate_span":"...","unit_type":"..."}]}' in request.user_prompt + assert 'For zero candidates, return exactly {"candidates":[]}.' in request.user_prompt + assert "exactly these two keys: candidate_span and unit_type" in combined + assert "literal, contiguous" in combined + assert "Draft, hypothetical, synthetic, unverified, and non-authoritative" in combined + assert "must not suppress" in combined + assert "Passive voice does not require actor inference" in combined + assert "Advisory language remains candidate material" in combined + for role in _REMOVED_SEMANTIC_ROLE_KEYS: + assert role in request.user_prompt + assert request.temperature == 0.0 + assert request.response_format == {"type": "json_object"} + + +def test_unit_type_vocabulary_offered_matches_parser() -> None: + request = outbound() + assert frozenset(_UNIT_TYPES) == _ALLOWED_UNIT_TYPES + for unit_type in _UNIT_TYPES: + assert unit_type in request.system_prompt + assert unit_type in request.user_prompt + + +def test_bare_candidate_root_and_extra_root_keys_are_rejected() -> None: + with pytest.raises(CandidateBoundaryError, match="unexpected root keys"): + extract(json.dumps({"candidate_span": SOURCE, "unit_type": "obligation"})) + with pytest.raises(CandidateBoundaryError, match="unexpected root keys"): + extract(json.dumps({"candidates": [], "verdict": "ok"})) + + +def test_empty_candidate_envelope_is_accepted() -> None: + assert extract('{"candidates":[]}').candidates == () + + +def test_candidate_requires_both_exact_model_fields() -> None: + with pytest.raises(CandidateBoundaryError, match="missing required fields"): + extract(json.dumps({"candidates": [{"unit_type": "obligation"}]})) + + +def test_source_anchor_shape_is_validated() -> None: + with pytest.raises(ValueError, match="missing required fields"): + propose_candidate_units( + source_text=SOURCE, + source_anchor={"anchor_id": "A"}, + provider=FakeProvider('{"candidates":[]}'), + ) + + +# -------------------------------------------------------------------------- +# OIC-CANDIDATE-SEMANTICS-004: framing separation +# +# 004 changes the prompt contract and nothing else. These tests therefore split cleanly in +# two: what OIC *asks the provider for*, and what the boundary still *refuses* regardless +# of what comes back. Nothing here asserts that any model complies -- that is what the +# later live regression measures. +# +# The load-bearing property is negative: OIC must not remove framing itself. A phrase +# stripper would make OIC the author of a span it then reports as source-grounded, so the +# tests below pin that an overreaching span is accepted byte-for-byte and recorded. +# -------------------------------------------------------------------------- + +DRAFT_SOURCE = ( + "DRAFT — NOT YET ADOPTED. A payment above $10,000 requires approval by the " + "Chief Financial Officer." +) +HYPOTHETICAL_SOURCE = ( + "For the sake of illustration, suppose a rule stated that a payment above $10,000 " + "requires approval by the Chief Financial Officer." +) +ILLUSTRATIVE_SOURCE = ( + "The following example is not authoritative: a contractor must return unused " + "equipment within ten days of contract end." +) +UNVERIFIED_SOURCE = ( + "UNVERIFIED EXTRACT — PROVENANCE NOT ESTABLISHED. A payment above $10,000 requires " + "approval by the Chief Financial Officer." +) +NON_AUTHORITATIVE_SOURCE = ( + "DEVELOPMENT SYNTHETIC SOURCE — NOT AN AUTHORITATIVE POLICY. A payment above $10,000 " + "requires approval by the Chief Financial Officer." +) +PROPOSITION = "A payment above $10,000 requires approval by the Chief Financial Officer." + + +def flat(text: str) -> str: + """Collapse the prompt's hard wrapping so a prose assertion survives it.""" + return " ".join(text.split()) + + +# ---- 1-5: the outbound contract states the framing rule ------------------- + + +def test_contract_asks_for_the_proposition_without_its_status_framing() -> None: + system = flat(outbound().system_prompt) + assert "Quote the proposition, not the source's commentary about the proposition." in system + assert "grammatically separable from the proposition, leave it outside the span" in system + + +@pytest.mark.parametrize( + "structure", + ["a draft", "a proposal", "a hypothetical", "an illustration", "an example"], +) +def test_contract_names_each_separable_framing_structure(structure: str) -> None: + assert structure in flat(outbound().system_prompt), structure + + +def test_contract_names_attribution_and_unadopted_unverified_standing() -> None: + system = flat(outbound().system_prompt) + assert "a quotation of another party" in system + assert "unadopted, unverified or non-authoritative" in system + + +def test_contract_keeps_framing_from_suppressing_discovery() -> None: + """Rule 4: framing separation is a quoting decision, never a standing finding.""" + system = flat(outbound().system_prompt) + assert "Source standing is not a discovery criterion." in system + assert "must not suppress a candidate that appears in the fragment" in system + assert ( + "it does not decide whether the proposition is authoritative, adopted, valid, " + "admitted, enforceable, or legally operative" in system + ) + assert "The source anchor keeps the framing." in system + + +@pytest.mark.parametrize( + "source", + [ + DRAFT_SOURCE, + HYPOTHETICAL_SOURCE, + ILLUSTRATIVE_SOURCE, + UNVERIFIED_SOURCE, + NON_AUTHORITATIVE_SOURCE, + ], +) +def test_framing_never_suppresses_a_candidate_at_the_boundary(source: str) -> None: + """Non-authoritative and unverified framing still yield candidate material.""" + result = extract(candidate(PROPOSITION if PROPOSITION in source else source), source=source) + assert len(result.candidates) == 1 + assert result.candidates[0]["epistemic_state"] == "uncertain" + assert result.candidates[0]["interpretation_state"] == "extracted" + + +# ---- 6-11: material content survives separation --------------------------- + + +def test_the_contract_forbids_buying_a_shorter_span_with_material_content() -> None: + system = flat(outbound().system_prompt) + assert "Never buy a shorter span with material content." in system + assert "Dropping material content is a worse error than including framing." in system + + +@pytest.mark.parametrize( + "element", + [ + "threshold", + "amount", + "deadline", + "condition", + "exception", + "recipient", + "prohibition", + "advisory wording", + "trigger", + "consequence", + ], +) +def test_the_contract_enumerates_every_material_element_that_must_stay(element: str) -> None: + assert element in flat(outbound().system_prompt), element + + +def test_a_threshold_survives_framing_separation() -> None: + result = extract(candidate(PROPOSITION), source=DRAFT_SOURCE) + span = str(result.candidates[0]["candidate_span"]) + assert "$10,000" in span + assert "DRAFT" not in span + + +def test_a_recipient_survives_framing_separation() -> None: + span = str( + extract(candidate(PROPOSITION), source=UNVERIFIED_SOURCE).candidates[0]["candidate_span"] + ) + assert "Chief Financial Officer" in span + assert "UNVERIFIED EXTRACT" not in span + + +def test_a_condition_survives_framing_separation() -> None: + source = ( + "DRAFT FOR CONSULTATION. If a supplier is on the restricted list, the contract " + "must not be awarded." + ) + proposition = "If a supplier is on the restricted list, the contract must not be awarded." + span = str( + extract(candidate(proposition, "prohibition"), source=source).candidates[0][ + "candidate_span" + ] + ) + assert "If a supplier is on the restricted list" in span + assert "DRAFT FOR CONSULTATION" not in span + + +def test_an_exception_survives_framing_separation() -> None: + source = ( + "NOT YET IN FORCE. Travel bookings must use the central agency, except for " + "travel funded entirely by an external host." + ) + proposition = ( + "Travel bookings must use the central agency, except for travel funded entirely " + "by an external host." + ) + span = str(extract(candidate(proposition), source=source).candidates[0]["candidate_span"]) + assert "except for travel funded entirely by an external host" in span + assert "NOT YET IN FORCE" not in span + + +def test_advisory_wording_survives_framing_separation() -> None: + source = ( + "DRAFT FOR CONSULTATION. Units are advised to review supplier performance before " + "renewing a contract." + ) + proposition = "Units are advised to review supplier performance before renewing a contract." + result = extract(candidate(proposition, "advisory"), source=source) + assert result.candidates[0]["candidate_span"] == proposition + assert result.candidates[0]["unit_type"] == "advisory" + + +# ---- 12-15: separation does not weaken anything the boundary already did --- + + +def test_multi_unit_extraction_still_separates_two_propositions_under_one_prefix() -> None: + source = ( + "NOT YET IN FORCE. A purchase requisition must be approved before an order is " + "placed. Suppliers are paid within forty-five days of invoice." + ) + first = "A purchase requisition must be approved before an order is placed." + second = "Suppliers are paid within forty-five days of invoice." + payload = json.dumps( + { + "candidates": [ + {"candidate_span": first, "unit_type": "obligation"}, + {"candidate_span": second, "unit_type": "temporal_trigger"}, + ] + } + ) + result = extract(payload, source=source) + spans = [str(item["candidate_span"]) for item in result.candidates] + assert spans == [first, second] + assert all("NOT YET IN FORCE" not in span for span in spans) + assert len({str(item["unit_id"]) for item in result.candidates}) == 2 + + +def test_a_separated_span_is_still_literal_source_text() -> None: + result = extract(candidate(PROPOSITION), source=DRAFT_SOURCE) + assert str(result.candidates[0]["candidate_span"]) in DRAFT_SOURCE + + +@pytest.mark.parametrize( + "span", + [ + "A payment over $10,000 requires approval by the Chief Financial Officer.", + "A payment above $10,000 requires CFO approval.", + "Each grant over 5,000 euro must be countersigned by the Programme Director.", + ], +) +def test_a_paraphrased_or_invented_span_still_fails_grounding_under_framing(span: str) -> None: + with pytest.raises(CandidateGroundingError, match="literal contiguous span"): + extract(candidate(span), source=DRAFT_SOURCE) + + +@pytest.mark.parametrize("field", sorted(_REMOVED_SEMANTIC_ROLE_KEYS)) +def test_removed_semantic_roles_still_fail_closed_under_framing(field: str) -> None: + payload = json.dumps( + {"candidates": [{"candidate_span": PROPOSITION, "unit_type": "obligation", field: "x"}]} + ) + with pytest.raises(CandidateBoundaryError, match="removed semantic-role fields"): + extract(payload, source=DRAFT_SOURCE) + + +@pytest.mark.parametrize("field", sorted(_MODEL_FORBIDDEN_AUTHORITY_KEYS)) +def test_authority_fields_still_fail_closed_under_framing(field: str) -> None: + payload = json.dumps( + {"candidates": [{"candidate_span": PROPOSITION, "unit_type": "obligation", field: "x"}]} + ) + with pytest.raises(CandidateBoundaryError, match="authority-controlled"): + extract(payload, source=DRAFT_SOURCE) + + +def test_no_field_was_added_by_004() -> None: + from oic.candidate_extraction import _MODEL_ALLOWED_KEYS + + assert set(_MODEL_ALLOWED_KEYS) == {"candidate_span", "unit_type"} + result = extract(candidate(PROPOSITION), source=DRAFT_SOURCE) + assert set(result.candidates[0]) == { + "unit_id", + "candidate_span", + "unit_type", + "interpretation_state", + "epistemic_state", + "source_anchors", + } + for invented in ("context", "framing", "standing", "source_context", "confidence"): + payload = json.dumps( + { + "candidates": [ + {"candidate_span": PROPOSITION, "unit_type": "obligation", invented: "x"} + ] + } + ) + with pytest.raises(CandidateBoundaryError): + extract(payload, source=DRAFT_SOURCE) + + +# ---- 18-19: OIC never separates framing itself ---------------------------- + + +@pytest.mark.parametrize( + ("source", "overreaching_span"), + [ + (DRAFT_SOURCE, DRAFT_SOURCE), + (HYPOTHETICAL_SOURCE, HYPOTHETICAL_SOURCE), + (UNVERIFIED_SOURCE, UNVERIFIED_SOURCE), + ], +) +def test_an_overreaching_span_is_accepted_byte_for_byte_and_never_trimmed( + source: str, overreaching_span: str +) -> None: + """The defect 004 addresses is left visible, not silently repaired.""" + result = extract(candidate(overreaching_span), source=source) + assert result.candidates[0]["candidate_span"] == overreaching_span + assert str(result.candidates[0]["candidate_span"]).startswith(overreaching_span[:20]) + + +def test_leading_and_trailing_source_whitespace_in_a_span_is_not_normalized() -> None: + source = " DRAFT. Payments must be approved. " + span = " DRAFT. Payments must be approved. " + result = extract(candidate(span), source=source) + assert result.candidates[0]["candidate_span"] == span + + +def test_no_deterministic_phrase_stripper_or_trimming_exists(repo_root: Path) -> None: + """Source-level: nothing in the module can rewrite a provider-proposed span.""" + module = (repo_root / "src/oic/candidate_extraction.py").read_text(encoding="utf-8") + for rewriting in ( + "re.sub", + ".replace(", + "removeprefix", + "removesuffix", + "partition(", + "lstrip(", + "rstrip(", + "FRAMING_PREFIXES", + "STRIP_", + ): + assert rewriting not in module, rewriting + # The only compiled pattern is the source-anchor digest format. + assert module.count("re.compile") == 1 + assert "_SHA256_PATTERN = re.compile" in module + + +def test_the_prompt_contains_no_corpus_specimen_language(repo_root: Path) -> None: + """Examples must teach the rule, never a corpus answer.""" + import json as _json + + system = outbound().system_prompt + user = outbound().user_prompt.split("SOURCE FRAGMENT:")[0] + root = repo_root / "benchmarks/characterization" + for relpath in ( + "candidate-semantics-003/CORPUS-v0.3.json", + "candidate-semantics-004/CORPUS-v0.4.json", + ): + document = _json.loads((root / relpath).read_text(encoding="utf-8")) + for specimen in document["specimens"]: + assert specimen["source_text"] not in system, specimen["specimen_id"] + assert specimen["source_text"] not in user, specimen["specimen_id"] + for key in ("separable_framing_spans", "candidate_span_bounds"): + for span in specimen.get(key) or []: + assert span not in system, (specimen["specimen_id"], span) + assert span not in user, (specimen["specimen_id"], span) + + +# ---- 22-24: identity is unchanged by 004 ---------------------------------- + + +def test_candidate_id_remains_deterministic_and_schema_tagged_003() -> None: + """004 changed the prompt, not the schema, so the identity tag does not move.""" + from oic.candidate_extraction import _candidate_id + + first = extract(candidate(PROPOSITION), source=DRAFT_SOURCE) + second = extract(candidate(PROPOSITION), source=DRAFT_SOURCE) + assert first.candidates[0]["unit_id"] == second.candidates[0]["unit_id"] + assert str(first.candidates[0]["unit_id"]).startswith("cnu-") + expected = _candidate_id( + semantic={"candidate_span": PROPOSITION, "unit_type": "obligation"}, + source_anchor=anchor(), + ) + assert first.candidates[0]["unit_id"] == expected + + +def test_the_same_proposition_at_a_different_anchor_is_a_different_identity() -> None: + """Source-instance-aware by design. Cross-source equivalence is Institutional IR's.""" + here = extract(candidate(PROPOSITION), source=DRAFT_SOURCE, source_anchor=anchor("1")) + there = extract(candidate(PROPOSITION), source=DRAFT_SOURCE, source_anchor=anchor("2")) + assert here.candidates[0]["candidate_span"] == there.candidates[0]["candidate_span"] + assert here.candidates[0]["unit_id"] != there.candidates[0]["unit_id"] + + +def test_equivalent_propositions_from_different_framings_are_not_forced_to_share_an_id() -> None: + """CSEM-021 and CSEM-027 state the same rule; 004 does not merge their identities.""" + drafted = extract(candidate(PROPOSITION), source=DRAFT_SOURCE, source_anchor=anchor("draft")) + plain = extract(candidate(PROPOSITION), source=PROPOSITION, source_anchor=anchor("plain")) + assert drafted.candidates[0]["candidate_span"] == plain.candidates[0]["candidate_span"] + assert drafted.candidates[0]["unit_id"] != plain.candidates[0]["unit_id"] + + +# -------------------------------------------------------------------------- +# OIC-CANDIDATE-SEMANTICS-005: the normative-discovery boundary +# +# A frozen A/B found 004 returning a candidate for prose that only describes institutional +# structures -- registers, a compliance calendar, a governance framework -- and typing it +# advisory. Institutional subject matter had become sufficient for discovery. 005 says +# plainly that it is not. +# +# The correction is a prompt contract and nothing else, so these tests split three ways: +# what OIC asks for, what OIC must NOT have built (no keyword list, no filter, no +# classifier), and what 004 established that must not regress. None of them asserts that +# any model complies; that is what the later live regression measures. +# -------------------------------------------------------------------------- + +DESCRIPTIVE_SOURCE = ( + "This section explains the governance framework, the delegation register, and the " + "compliance calendar maintained by the Secretariat." +) + + +# ---- what OIC asks for ---------------------------------------------------- + + +def test_the_contract_states_institutional_subject_matter_is_not_normative() -> None: + system = flat(outbound().system_prompt) + assert "Institutional subject matter is not by itself normative." in system + assert "Institutional nouns do not create normativity." in system + assert ( + "If nothing in the fragment performs an apparent normative or constitutive " + "function, return no candidates." in system + ) + + +@pytest.mark.parametrize( + "descriptive", + [ + "only says something exists", + "sits somewhere", + "happened", + "contains something", + "explains or describes something", + "maintains an artifact", + "summarizes a structure", + "reports past activity", + "advertises a capability", + ], +) +def test_the_contract_enumerates_the_non_normative_shapes(descriptive: str) -> None: + assert descriptive in flat(outbound().system_prompt), descriptive + + +@pytest.mark.parametrize( + "vocabulary", + [ + "governance", + "compliance", + "policy", + "delegation", + "oversight", + "register", + "framework", + "committee", + "procedure", + "office", + ], +) +def test_the_contract_names_the_vocabulary_that_is_insufficient_on_its_own( + vocabulary: str, +) -> None: + """Named as insufficient in the instructions, never encoded as a filter.""" + assert vocabulary in flat(outbound().system_prompt), vocabulary + + +def test_the_contract_introduces_no_modal_keyword_requirement() -> None: + """The overcorrection guard: normative function does not require must/shall/may/should.""" + system = flat(outbound().system_prompt) + assert "Do not look for particular words either." in system + assert "Normative function needs no must, shall, may or should" in system + assert "Ask what the proposition does, not which words it uses." in system + + +def test_the_contract_distinguishes_a_constitutive_definition_from_description() -> None: + system = flat(outbound().system_prompt) + assert ( + "A definition is candidate material when it is constitutive or operative, fixing " + "what a term means for some stated purpose, and not when it merely explains what a " + "concept is about." in system + ) + + +def test_the_contract_distinguishes_actual_advisory_from_discussion_of_guidance() -> None: + system = flat(outbound().system_prompt) + assert ( + "Advisory is candidate material when the fragment actually recommends or encourages " + "a course of action, and not when it merely discusses guidance, standards, or good " + "practice." in system + ) + + +def test_the_contract_carries_one_contrast_for_each_distinction() -> None: + system = flat(outbound().system_prompt) + assert "Three short contrasts, worded to match no fragment you will be given" in system + assert "no candidates. It reports what an office does" in system + assert "a candidate. It actually recommends a course of action." in system + assert "a candidate. It fixes what a term means for a stated purpose." in system + + +def test_the_user_prompt_repeats_the_discovery_rule() -> None: + user = flat(outbound().user_prompt.split("SOURCE FRAGMENT:")[0]) + assert ( + "Institutional subject matter alone is not a normative proposition: description, " + "explanation and reporting produce zero candidates unless the fragment itself " + "requires, permits, prohibits, authorizes, delegates, fixes what a term means, " + "sets a condition or exception, or genuinely recommends." in user + ) + + +def test_the_instructions_reproduce_no_frozen_corpus_specimen(repo_root: Path) -> None: + """Examples teach the rule. They must never teach a corpus answer.""" + import json as _json + + system = outbound().system_prompt + user = outbound().user_prompt.split("SOURCE FRAGMENT:")[0] + root = repo_root / "benchmarks/characterization" + for version in ("003/CORPUS-v0.3.json", "004/CORPUS-v0.4.json", "005/CORPUS-v0.5.json"): + document = _json.loads((root / f"candidate-semantics-{version}").read_text("utf-8")) + for specimen in document["specimens"]: + assert specimen["source_text"] not in system, specimen["specimen_id"] + assert specimen["source_text"] not in user, specimen["specimen_id"] + for key in ("separable_framing_spans", "candidate_span_bounds"): + for span in specimen.get(key) or []: + assert span not in system, (specimen["specimen_id"], span) + + +def test_the_motivating_specimen_text_is_absent_from_the_prompt() -> None: + """CSEM-031 in particular: the fix must generalize, not memorize.""" + request = outbound() + instructions = request.system_prompt + request.user_prompt.split("SOURCE FRAGMENT:")[0] + assert DESCRIPTIVE_SOURCE not in instructions + assert "Secretariat" not in instructions + assert "compliance calendar" not in instructions + assert "delegation register" not in instructions + + +# ---- what OIC must NOT have built ---------------------------------------- + + +def _module_ast(repo_root: Path) -> ast.Module: + return ast.parse((repo_root / "src/oic/candidate_extraction.py").read_text("utf-8")) + + +def _is_collection(value: ast.expr | None) -> bool: + if isinstance(value, ast.Tuple | ast.List | ast.Set | ast.Dict): + return True + return ( + isinstance(value, ast.Call) + and isinstance(value.func, ast.Name) + and value.func.id in {"frozenset", "set", "tuple", "list"} + ) + + +def test_no_keyword_blacklist_or_vocabulary_constant_exists(repo_root: Path) -> None: + """Structural, via AST, so prose in a docstring cannot pass or fail it. + + Every module-level collection constant is enumerated here. A new + institutional-vocabulary list could not be added without failing this test. + """ + collections: set[str] = set() + for node in _module_ast(repo_root).body: + if isinstance(node, ast.Assign) and _is_collection(node.value): + collections.update(target.id for target in node.targets if isinstance(target, ast.Name)) + elif ( + isinstance(node, ast.AnnAssign) + and isinstance(node.target, ast.Name) + and _is_collection(node.value) + ): + collections.add(node.target.id) + assert collections == { + "_UNIT_TYPES", + "_ALLOWED_UNIT_TYPES", + "_MODEL_ALLOWED_KEYS", + "_REMOVED_SEMANTIC_ROLE_KEYS", + "_MODEL_FORBIDDEN_AUTHORITY_KEYS", + "_SOURCE_ANCHOR_REQUIRED_KEYS", + "_SOURCE_ANCHOR_ALLOWED_KEYS", + } + + +def test_the_only_regular_expression_is_the_source_anchor_digest(repo_root: Path) -> None: + calls = [ + node.func.attr + for node in ast.walk(_module_ast(repo_root)) + if isinstance(node, ast.Call) + and isinstance(node.func, ast.Attribute) + and isinstance(node.func.value, ast.Name) + and node.func.value.id == "re" + ] + assert calls == ["compile"] + + +def test_no_candidate_is_filtered_out_after_generation(repo_root: Path) -> None: + """The normalized-candidate comprehension carries no condition. + + A filter here would let OIC decide what counts as normative, which is exactly the + judgement this layer is not entitled to make -- and it would make the measurement + circular, since the metric would then be scoring OIC's own filter. + """ + tree = _module_ast(repo_root) + comprehensions = [ + node + for node in ast.walk(tree) + if isinstance(node, ast.GeneratorExp | ast.ListComp | ast.SetComp) + ] + assert comprehensions, "expected the normalized-candidate comprehension" + for comprehension in comprehensions: + for generator in comprehension.generators: + assert generator.ifs == [], ast.dump(comprehension)[:200] + + +def test_no_deletion_or_skipping_machinery_exists_in_the_module(repo_root: Path) -> None: + tree = _module_ast(repo_root) + for node in ast.walk(tree): + assert not isinstance(node, ast.Delete), "del is never used" + assert not isinstance(node, ast.Continue), "continue is never used" + if isinstance(node, ast.Call) and isinstance(node.func, ast.Name): + assert node.func.id != "filter", "filter() is never used" + if isinstance(node, ast.Call) and isinstance(node.func, ast.Attribute): + assert node.func.attr != "pop", ".pop() is never used" + + +def test_a_descriptive_span_the_provider_returns_is_recorded_not_suppressed() -> None: + """The behavioural half: OIC measures the defect, it does not silently fix it.""" + result = extract(candidate(DESCRIPTIVE_SOURCE, "advisory"), source=DESCRIPTIVE_SOURCE) + assert len(result.candidates) == 1 + assert result.candidates[0]["candidate_span"] == DESCRIPTIVE_SOURCE + assert result.candidates[0]["unit_type"] == "advisory" + assert result.candidates[0]["epistemic_state"] == "uncertain" + + +def test_no_second_model_or_provider_call_is_introduced() -> None: + """One provider call per extraction, exactly as before.""" + provider = FakeProvider('{"candidates":[]}') + propose_candidate_units( + source_text=DESCRIPTIVE_SOURCE, source_anchor=anchor(), provider=provider + ) + assert len(provider.requests) == 1 + + +# ---- what must not regress ------------------------------------------------ + + +def test_the_004_framing_rules_are_all_still_present() -> None: + system = flat(outbound().system_prompt) + assert "Quote the proposition, not the source's commentary about the proposition." in system + assert "grammatically separable from the proposition, leave it outside the span" in system + assert "Never buy a shorter span with material content." in system + assert "Dropping material content is a worse error than including framing." in system + assert "Source standing is not a discovery criterion." in system + assert "The source anchor keeps the framing." in system + + +def test_framing_separation_still_works_on_the_004_worked_case() -> None: + result = extract(candidate(PROPOSITION), source=DRAFT_SOURCE) + span = str(result.candidates[0]["candidate_span"]) + assert span == PROPOSITION + assert "DRAFT" not in span + assert "$10,000" in span + assert "Chief Financial Officer" in span + + +def test_material_completeness_language_survives_the_005_change() -> None: + system = flat(outbound().system_prompt) + for element in ( + "threshold", + "deadline", + "condition", + "exception", + "recipient", + "advisory wording", + "trigger", + "consequence", + ): + assert element in system, element + + +def test_the_authority_boundary_survives_the_005_change() -> None: + system = flat(outbound().system_prompt) + assert "Candidate material has no institutional authority." in system + assert "Do not decide or propose admission" in system + assert "Institutional IR state" in system + + +def test_no_field_was_added_by_005() -> None: + from oic.candidate_extraction import _MODEL_ALLOWED_KEYS + + assert set(_MODEL_ALLOWED_KEYS) == {"candidate_span", "unit_type"} + result = extract(candidate(PROPOSITION), source=DRAFT_SOURCE) + assert set(result.candidates[0]) == { + "unit_id", + "candidate_span", + "unit_type", + "interpretation_state", + "epistemic_state", + "source_anchors", + } + for invented in ( + "confidence", + "normative_score", + "advisory_score", + "standing", + "authority", + "admission", + "legal_effect", + "context", + ): + payload = json.dumps( + { + "candidates": [ + {"candidate_span": PROPOSITION, "unit_type": "obligation", invented: 1} + ] + } + ) + with pytest.raises(CandidateBoundaryError): + extract(payload, source=DRAFT_SOURCE) + + +def test_identity_is_unchanged_by_005() -> None: + from oic.candidate_extraction import _candidate_id + + expected = _candidate_id( + semantic={"candidate_span": PROPOSITION, "unit_type": "obligation"}, + source_anchor=anchor(), + ) + assert extract(candidate(PROPOSITION), source=DRAFT_SOURCE).candidates[0]["unit_id"] == ( + expected + ) + here = extract(candidate(PROPOSITION), source=DRAFT_SOURCE, source_anchor=anchor("1")) + there = extract(candidate(PROPOSITION), source=DRAFT_SOURCE, source_anchor=anchor("2")) + assert here.candidates[0]["unit_id"] != there.candidates[0]["unit_id"] + + +def test_grounding_is_unchanged_by_005() -> None: + with pytest.raises(CandidateGroundingError, match="literal contiguous span"): + extract(candidate("The Secretariat must maintain the register."), source=DESCRIPTIVE_SOURCE) + assert ( + extract(candidate(DESCRIPTIVE_SOURCE), source=DESCRIPTIVE_SOURCE).candidates[0][ + "candidate_span" + ] + == DESCRIPTIVE_SOURCE + ) + + +def test_genuine_normative_material_still_passes_the_boundary_unchanged() -> None: + """Advisory, definition and delegation all remain acceptable candidate material.""" + cases = [ + ("Managers are encouraged to discuss workload allocation with their teams.", "advisory"), + ( + "For this part, 'Responsible Officer' means the person holding the delegation.", + "definition", + ), + ("The Head of Service may authorise a Deputy to sign purchase agreements.", "delegation"), + ] + for source, unit_type in cases: + result = extract(candidate(source, unit_type), source=source) + assert result.candidates[0]["candidate_span"] == source + assert result.candidates[0]["unit_type"] == unit_type diff --git a/tests/unit/test_cli.py b/tests/unit/test_cli.py index 8543a30..c4cb95f 100644 --- a/tests/unit/test_cli.py +++ b/tests/unit/test_cli.py @@ -350,6 +350,8 @@ def test_doctor_json_output_parses(capsys: pytest.CaptureFixture[str], repo_root assert {boundary["name"] for boundary in payload["boundaries"]} == {"ZTL", "VEIP"} gate = next(c for c in payload["gates"] if c["name"] == "semantic implementation gate") assert gate["status"] == "BLOCKED" + bounded = next(c for c in payload["gates"] if c["name"] == "bounded synthetic reference path") + assert bounded["status"] == "BOUNDED_REFERENCE_IMPLEMENTATION" # --------------------------------------------------------------------------- diff --git a/tests/unit/test_doctor.py b/tests/unit/test_doctor.py index d2239ed..c100cf8 100644 --- a/tests/unit/test_doctor.py +++ b/tests/unit/test_doctor.py @@ -194,6 +194,8 @@ def test_doctor_never_describes_ztl_or_veip_as_active(report: DoctorReport, forb def test_semantic_gate_is_blocked(report: DoctorReport) -> None: + bounded = next(c for c in report.gates if c.name == "bounded synthetic reference path") + assert bounded.status == "BOUNDED_REFERENCE_IMPLEMENTATION" check = next(c for c in report.gates if c.name == "semantic implementation gate") assert check.status == SEMANTIC_GATE_STATUS == "BLOCKED" diff --git a/tests/unit/test_frozen_synthetic_provider.py b/tests/unit/test_frozen_synthetic_provider.py new file mode 100644 index 0000000..8549428 --- /dev/null +++ b/tests/unit/test_frozen_synthetic_provider.py @@ -0,0 +1,78 @@ +"""Finite exact-request replay is offline and fails closed.""" + +import hashlib +import json +from pathlib import Path + +import pytest + +from oic.frozen_synthetic_provider import FrozenSyntheticProvider, request_digest +from oic.model_provider import ModelProvider, ModelProviderError, ModelRequest + + +def provider_file(tmp_path: Path, content: bytes) -> FrozenSyntheticProvider: + path = tmp_path / "fixture.json" + path.write_bytes(content) + return FrozenSyntheticProvider(path, expected_sha256=hashlib.sha256(content).hexdigest()) + + +def test_replay_is_deterministic_and_exhausts(tmp_path: Path) -> None: + request = ModelRequest("synthetic", "input") + data = json.dumps( + { + "format": "SYNTHETIC-REPLAY-001", + "exchanges": [ + {"request_sha256": request_digest(request), "content": "{}", "model": "fixture"} + ], + } + ).encode() + first: ModelProvider = provider_file(tmp_path, data) + second = provider_file(tmp_path, data) + assert first.complete(request) == second.complete(request) + with pytest.raises(ModelProviderError, match="exhausted"): + second.complete(request) + + +def test_request_mismatch_does_not_consume(tmp_path: Path) -> None: + request = ModelRequest("synthetic", "input") + data = json.dumps( + { + "format": "SYNTHETIC-REPLAY-001", + "exchanges": [ + {"request_sha256": request_digest(request), "content": "{}", "model": "fixture"} + ], + } + ).encode() + provider = provider_file(tmp_path, data) + with pytest.raises(ModelProviderError, match="mismatch"): + provider.complete(ModelRequest("synthetic", "different")) + assert provider.consumed == 0 + assert provider.complete(request).content == "{}" + + +@pytest.mark.parametrize( + "data", + [ + b"", + b"not JSON", + b"[]", + b"{}", + b'{"format":"SYNTHETIC-REPLAY-001","exchanges":[]}', + b'{"format":"SYNTHETIC-REPLAY-001","exchanges":[{}]}', + ], +) +def test_malformed_fixture_refused(tmp_path: Path, data: bytes) -> None: + with pytest.raises(ModelProviderError): + provider_file(tmp_path, data) + + +def test_missing_fixture_refused(tmp_path: Path) -> None: + with pytest.raises(ModelProviderError): + FrozenSyntheticProvider(tmp_path / "absent", expected_sha256="0" * 64) + + +def test_modified_fixture_refused(tmp_path: Path) -> None: + path = tmp_path / "fixture.json" + path.write_bytes(b"{}") + with pytest.raises(ModelProviderError, match="digest mismatch"): + FrozenSyntheticProvider(path, expected_sha256="0" * 64) diff --git a/tests/unit/test_interpretation_proposal.py b/tests/unit/test_interpretation_proposal.py new file mode 100644 index 0000000..a54d51f --- /dev/null +++ b/tests/unit/test_interpretation_proposal.py @@ -0,0 +1,620 @@ +"""The interpretation-proposal boundary: what it refuses, and what it deliberately does not. + +The second half matters as much as the first. This layer must accept a schema-valid +proposal that is semantically wrong — an invented actor, a dropped exception, an ungrounded +quote — because a characterization instrument that repairs defects before measuring them +reports a clean run over a broken model. +""" + +from __future__ import annotations + +import json +from typing import Any + +import pytest + +from oic.interpretation_proposal import ( + FORCE_VALUES, + PROPOSAL_SCHEMA_ID, + SLOT_VOCABULARY, + AdmittedCandidateBinding, + InterpretationProposalError, + ProposalBoundaryError, + ProposalInputBoundaryError, + build_proposal_envelope, + grounding_key, + is_quote_grounded, + proposal_identity, + propose_interpretation, +) +from oic.model_provider import ModelProviderError, ModelRequest, ModelResponse + +SPAN = "The Records Officer must retain each closed file for seven years." +RECEIPT_ID = "admrec-sha256:" + "a" * 64 +UNIT_ID = "cnu-" + "b" * 24 +PROJECTION_DIGEST = "sha256:" + "c" * 64 +PROPOSER = "test-proposer" + + +class CountingProvider: + """A fake provider that records every call, so 'no call' is provable rather than assumed.""" + + def __init__(self, content: str = '{"proposed_assertions":[]}') -> None: + self.calls: list[ModelRequest] = [] + self.content = content + + def complete(self, request: ModelRequest) -> ModelResponse: + self.calls.append(request) + return ModelResponse( + provider="fake", + model="fake-model", + content=self.content, + request_id="req-1", + raw={}, + ) + + +class FailingProvider: + def __init__(self) -> None: + self.calls = 0 + + def complete(self, request: ModelRequest) -> ModelResponse: + del request + self.calls += 1 + raise ModelProviderError("transport failed") + + +def _binding(state: str = "ADMITTED", unit_type: str | None = None) -> AdmittedCandidateBinding: + return AdmittedCandidateBinding( + admission_receipt_id=RECEIPT_ID, + admission_state=state, + candidate_unit_id=UNIT_ID, + candidate_projection_digest=PROJECTION_DIGEST, + candidate_span=SPAN, + provisional_unit_type=unit_type, + ) + + +def _propose(content: str, *, unit_type: str | None = None) -> dict[str, Any]: + provider = CountingProvider(content) + result = propose_interpretation( + binding=_binding(unit_type=unit_type), provider=provider, proposer_id=PROPOSER + ) + return result.proposal + + +# --------------------------------------------------------------------------- +# The input boundary: non-ADMITTED never reaches a provider +# --------------------------------------------------------------------------- + + +@pytest.mark.parametrize( + "state", + [ + "MISSING_AUTHORITY_EVIDENCE", + "OUT_OF_SCOPE", + "REVOKED", + "CONFLICTING_AUTHORITY", + "ADMISSION_NOT_ESTABLISHED", + "SOURCE_NOT_REGISTERED", + ], +) +def test_non_admitted_input_makes_zero_provider_calls(state: str) -> None: + provider = CountingProvider() + with pytest.raises(ProposalInputBoundaryError): + propose_interpretation(binding=_binding(state), provider=provider, proposer_id=PROPOSER) + assert provider.calls == [], "a non-ADMITTED receipt must not reach the provider" + + +def test_a_non_admitted_refusal_is_not_an_empty_proposal() -> None: + provider = CountingProvider() + with pytest.raises(ProposalInputBoundaryError) as caught: + propose_interpretation(binding=_binding("REVOKED"), provider=provider, proposer_id=PROPOSER) + assert "no provider was called" in str(caught.value) + assert not isinstance(caught.value, ProposalBoundaryError) + assert isinstance(caught.value, InterpretationProposalError) + + +def test_an_admitted_receipt_does_reach_the_provider_exactly_once() -> None: + provider = CountingProvider() + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + assert len(provider.calls) == 1 + + +def test_there_is_no_retry_on_provider_failure() -> None: + provider = FailingProvider() + with pytest.raises(ModelProviderError): + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + assert provider.calls == 1 + + +# --------------------------------------------------------------------------- +# The envelope belongs to OIC +# --------------------------------------------------------------------------- + + +def test_oic_supplies_every_binding_and_identity_field() -> None: + proposal = _propose('{"proposed_assertions":[]}') + assert proposal["proposal_schema_id"] == PROPOSAL_SCHEMA_ID + assert proposal["admission_receipt_id"] == RECEIPT_ID + assert proposal["candidate_unit_id"] == UNIT_ID + assert proposal["candidate_projection_digest"] == PROJECTION_DIGEST + assert proposal["proposal_state"] == "PROVISIONAL" + assert proposal["epistemic_state"] == "uncertain" + assert proposal["proposer"] == {"proposer_kind": "MODEL", "proposer_id": PROPOSER} + assert proposal["proposal_id"].startswith("iip-") + + +@pytest.mark.parametrize( + "field", + [ + "proposal_id", + "admission_receipt_id", + "candidate_unit_id", + "proposal_state", + "epistemic_state", + ], +) +def test_a_model_cannot_overwrite_an_oic_controlled_field(field: str) -> None: + """The model is not asked for these, and emitting one is a boundary failure.""" + payload = json.dumps({"proposed_assertions": [], field: "model-supplied"}) + provider = CountingProvider(payload) + with pytest.raises(ProposalBoundaryError): + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + + +# --------------------------------------------------------------------------- +# Deterministic identity +# --------------------------------------------------------------------------- + + +def test_proposal_identity_is_deterministic_for_an_identical_payload() -> None: + payload = json.dumps( + { + "proposed_assertions": [ + { + "slot": "bearer", + "proposed_value": "The Records Officer", + "proposed_source_quote": "The Records Officer", + } + ] + } + ) + first = _propose(payload) + second = _propose(payload) + assert first["proposal_id"] == second["proposal_id"] + assert first == second + + +def test_proposal_identity_changes_when_the_payload_changes() -> None: + base = _propose('{"proposed_assertions":[]}') + other = _propose( + json.dumps( + { + "proposed_assertions": [ + {"slot": "action", "proposed_value": "retain", "proposed_source_quote": None} + ] + } + ) + ) + assert base["proposal_id"] != other["proposal_id"] + + +def test_proposal_identity_binds_the_admission_receipt_and_the_proposer() -> None: + assertions: list[dict[str, Any]] = [] + same = proposal_identity( + binding=_binding(), proposer_id=PROPOSER, assertions=assertions, references=[] + ) + other_receipt = AdmittedCandidateBinding( + admission_receipt_id="admrec-sha256:" + "d" * 64, + admission_state="ADMITTED", + candidate_unit_id=UNIT_ID, + candidate_projection_digest=PROJECTION_DIGEST, + candidate_span=SPAN, + ) + assert ( + proposal_identity( + binding=other_receipt, proposer_id=PROPOSER, assertions=assertions, references=[] + ) + != same + ) + assert ( + proposal_identity( + binding=_binding(), proposer_id="someone-else", assertions=assertions, references=[] + ) + != same + ) + + +def test_proposal_identity_uses_no_clock_and_no_randomness() -> None: + """Identity is a pure function of the binding, the proposer and the payload.""" + import ast + from pathlib import Path + + source = Path(__file__).resolve().parents[2] / "src/oic/interpretation_proposal.py" + tree = ast.parse(source.read_text(encoding="utf-8")) + imported = { + alias.name.split(".")[0] + for node in ast.walk(tree) + if isinstance(node, ast.Import) + for alias in node.names + } | { + node.module.split(".")[0] + for node in ast.walk(tree) + if isinstance(node, ast.ImportFrom) and node.module + } + assert {"uuid", "random", "time", "datetime", "secrets", "os"} & imported == set() + + +def test_proposal_identity_is_not_ir_identity() -> None: + proposal = _propose('{"proposed_assertions":[]}') + assert not proposal["proposal_id"].startswith("iir-") + assert "semantic_equivalence_key" not in proposal + assert "ir_unit_id" not in proposal + assert "interpretation_ruleset" not in proposal + + +# --------------------------------------------------------------------------- +# The provider-response contract: structural refusals only +# --------------------------------------------------------------------------- + + +@pytest.mark.parametrize( + "content", + [ + "not json at all", + "[]", + '"a string"', + "null", + '{"proposed_assertions":[],"extra_root":1}', + '{"proposed_assertions":{}}', + '{"proposed_unresolved_references":{}}', + '{"proposed_assertions":["not an object"]}', + '{"proposed_assertions":[{"slot":"bearer"}]}', + '{"proposed_assertions":[{"slot":"invented_slot","proposed_value":null,' + '"proposed_source_quote":null}]}', + '{"proposed_assertions":[{"slot":"bearer","proposed_value":1,' + '"proposed_source_quote":null}]}', + '{"proposed_assertions":[{"slot":"bearer","proposed_value":null,' + '"proposed_source_quote":7}]}', + '{"proposed_assertions":[{"slot":"bearer","proposed_value":null,' + '"proposed_source_quote":null,"extra":1}]}', + '{"proposed_assertions":[{"slot":"bearer","proposed_value":null,' + '"proposed_source_quote":null,"proposed_material_qualifiers":"x"}]}', + '{"proposed_assertions":[],"proposed_unresolved_references":[{"reference_text":"x"}]}', + '{"proposed_assertions":[],"proposed_unresolved_references":' + '[{"reference_text":"x","reference_kind":"MADE_UP"}]}', + '{"proposed_assertions":[],"proposed_unresolved_references":' + '[{"reference_text":"","reference_kind":"DEFINITION"}]}', + ], +) +def test_structural_contract_failures_are_refused(content: str) -> None: + provider = CountingProvider(content) + with pytest.raises(ProposalBoundaryError): + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + + +@pytest.mark.parametrize( + "field", + [ + "confidence", + "score", + "probability", + "authority", + "admitted", + "canonical", + "established", + "interpretation_basis", + "interpretation_evidence", + "warrant", + "legal_effect", + "enforceability", + "allow", + "deny", + "runtime_outcome", + "verdict", + "interpretation_status", + ], +) +def test_no_authority_or_canonical_field_is_accepted_at_any_depth(field: str) -> None: + payload = json.dumps( + { + "proposed_assertions": [ + { + "slot": "bearer", + "proposed_value": "x", + "proposed_source_quote": None, + **{field: True}, + } + ] + } + ) + provider = CountingProvider(payload) + with pytest.raises(ProposalBoundaryError, match="authority-controlled"): + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + + +@pytest.mark.parametrize( + "status", ["ESTABLISHED", "AMBIGUOUS", "NOT_ESTABLISHED", "NOT_APPLICABLE"] +) +def test_a_model_may_not_assign_an_interpretation_status_as_a_value(status: str) -> None: + payload = json.dumps( + { + "proposed_assertions": [ + {"slot": "bearer", "proposed_value": status, "proposed_source_quote": None} + ] + } + ) + provider = CountingProvider(payload) + with pytest.raises(ProposalBoundaryError, match="interpretation-status"): + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + + +@pytest.mark.parametrize("force", FORCE_VALUES) +def test_every_frozen_force_is_accepted(force: str) -> None: + payload = json.dumps( + { + "proposed_assertions": [ + {"slot": "normative_force", "proposed_value": force, "proposed_source_quote": SPAN} + ] + } + ) + proposal = _propose(payload) + assert proposal["proposed_assertions"][0]["proposed_value"] == force + + +@pytest.mark.parametrize("force", ["MANDATE", "REQUIREMENT", "obligation", "SUGGESTION", ""]) +def test_an_invented_normative_force_is_refused(force: str) -> None: + payload = json.dumps( + { + "proposed_assertions": [ + {"slot": "normative_force", "proposed_value": force, "proposed_source_quote": None} + ] + } + ) + provider = CountingProvider(payload) + with pytest.raises(ProposalBoundaryError, match="normative force"): + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + + +@pytest.mark.parametrize("slot", SLOT_VOCABULARY) +def test_every_frozen_slot_is_accepted(slot: str) -> None: + value = "OBLIGATION" if slot == "normative_force" else "some value" + payload = json.dumps( + { + "proposed_assertions": [ + {"slot": slot, "proposed_value": value, "proposed_source_quote": None} + ] + } + ) + proposal = _propose(payload) + assert proposal["proposed_assertions"][0]["slot"] == slot + + +# --------------------------------------------------------------------------- +# What the layer must NOT do: no canonicalization before measurement +# --------------------------------------------------------------------------- + + +def test_a_null_source_quote_is_accepted() -> None: + payload = json.dumps( + { + "proposed_assertions": [ + {"slot": "bearer", "proposed_value": "someone", "proposed_source_quote": None} + ] + } + ) + proposal = _propose(payload) + assert proposal["proposed_assertions"][0]["proposed_source_quote"] is None + + +def test_an_ungrounded_quote_is_accepted_and_never_repaired() -> None: + """The candidate layer refuses this. The proposal layer measures it instead.""" + quote = "text that is nowhere in the admitted proposition" + payload = json.dumps( + { + "proposed_assertions": [ + {"slot": "bearer", "proposed_value": "someone", "proposed_source_quote": quote} + ] + } + ) + proposal = _propose(payload) + assert proposal["proposed_assertions"][0]["proposed_source_quote"] == quote + assert not is_quote_grounded(quote, candidate_span=SPAN) + + +def test_an_invented_actor_is_accepted_so_that_it_can_be_measured() -> None: + payload = json.dumps( + { + "proposed_assertions": [ + { + "slot": "bearer", + "proposed_value": "the finance team", + "proposed_source_quote": None, + } + ] + } + ) + proposal = _propose(payload) + assert proposal["proposed_assertions"][0]["proposed_value"] == "the finance team" + + +def test_a_semantically_wrong_force_is_accepted_so_that_it_can_be_measured() -> None: + payload = json.dumps( + { + "proposed_assertions": [ + { + "slot": "normative_force", + "proposed_value": "OBLIGATION", + "proposed_source_quote": SPAN, + } + ] + } + ) + assert _propose(payload)["proposed_assertions"][0]["proposed_value"] == "OBLIGATION" + + +def test_duplicate_slot_proposals_are_preserved_not_deduplicated() -> None: + """A proposer contradicting itself is evidence, so both assertions survive.""" + payload = json.dumps( + { + "proposed_assertions": [ + {"slot": "bearer", "proposed_value": "A", "proposed_source_quote": None}, + {"slot": "bearer", "proposed_value": "B", "proposed_source_quote": None}, + ] + } + ) + proposal = _propose(payload) + assert [item["proposed_value"] for item in proposal["proposed_assertions"]] == ["A", "B"] + + +def test_proposed_references_are_kept_as_proposed_and_never_resolved() -> None: + payload = json.dumps( + { + "proposed_assertions": [], + "proposed_unresolved_references": [ + {"reference_text": "Policy B", "reference_kind": "EXTERNAL_DOCUMENT"} + ], + } + ) + proposal = _propose(payload) + assert proposal["proposed_unresolved_references"] == [ + {"reference_text": "Policy B", "reference_kind": "EXTERNAL_DOCUMENT"} + ] + assert "resolved_target" not in json.dumps(proposal) + + +def test_an_empty_proposal_is_accepted() -> None: + proposal = _propose('{"proposed_assertions":[]}') + assert proposal["proposed_assertions"] == [] + assert "proposed_unresolved_references" not in proposal + + +# --------------------------------------------------------------------------- +# Grounding helpers +# --------------------------------------------------------------------------- + + +def test_grounding_is_whitespace_and_case_insensitive() -> None: + assert grounding_key(" The RECORDS officer ") == "the records officer" + assert is_quote_grounded("the records officer", candidate_span=SPAN) + assert not is_quote_grounded("the finance team", candidate_span=SPAN) + + +# --------------------------------------------------------------------------- +# The request body +# --------------------------------------------------------------------------- + + +def test_the_request_carries_the_proposition_and_the_vocabulary_only() -> None: + provider = CountingProvider() + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + request = provider.calls[0] + body = request.system_prompt + "\n" + request.user_prompt + assert SPAN in body + for slot in SLOT_VOCABULARY: + assert slot in body + for force in FORCE_VALUES: + assert force in body + assert request.temperature == 0.0 + assert request.response_format == {"type": "json_object"} + + +@pytest.mark.parametrize( + "leak", + [ + RECEIPT_ID, + UNIT_ID, + PROJECTION_DIGEST, + "authority_evidence", + "admission_warrant", + "OIC-ADM-", + "interpretation_evidence", + "INSTITUTIONAL_INTERPRETATION_WARRANT", + "REGISTERED_INTERPRETATION_RULE", + "evaluation_scope", + ], +) +def test_the_request_carries_no_authority_or_admission_metadata(leak: str) -> None: + provider = CountingProvider() + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + request = provider.calls[0] + body = request.system_prompt + "\n" + request.user_prompt + assert leak not in body + + +def test_the_provisional_unit_type_is_omitted_by_default() -> None: + """The preregistered arm is the candidate span alone: no prior classification crosses.""" + provider = CountingProvider() + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + prompt = provider.calls[0].user_prompt + assert "An earlier stage proposed" not in prompt + assert "mandate" not in prompt + + +def test_the_provisional_unit_type_arm_can_be_enabled_for_a_later_ab() -> None: + provider = CountingProvider() + propose_interpretation( + binding=_binding(unit_type="mandate"), provider=provider, proposer_id=PROPOSER + ) + prompt = provider.calls[0].user_prompt + assert "'mandate'" in prompt + assert "carries no authority" in prompt + + +def test_the_prompt_names_no_provider() -> None: + provider = CountingProvider() + propose_interpretation(binding=_binding(), provider=provider, proposer_id=PROPOSER) + request = provider.calls[0] + body = (request.system_prompt + request.user_prompt).casefold() + for vendor in ("nvidia", "nim", "nemotron", "openai", "gpt", "anthropic", "claude", "llama"): + assert vendor not in body + + +# --------------------------------------------------------------------------- +# Envelope construction +# --------------------------------------------------------------------------- + + +def test_build_proposal_envelope_rejects_an_unknown_proposer_kind() -> None: + with pytest.raises(ValueError, match="proposer_kind"): + build_proposal_envelope( + binding=_binding(), + proposer_kind="INSTITUTION", + proposer_id=PROPOSER, + assertions=[], + references=[], + ) + + +@pytest.mark.parametrize( + ("field", "value"), + [ + ("admission_receipt_id", "not-a-receipt"), + ("candidate_unit_id", "not-a-candidate"), + ("candidate_projection_digest", "not-a-digest"), + ("candidate_span", " "), + ], +) +def test_the_binding_refuses_malformed_admission_material(field: str, value: str) -> None: + kwargs: dict[str, Any] = { + "admission_receipt_id": RECEIPT_ID, + "admission_state": "ADMITTED", + "candidate_unit_id": UNIT_ID, + "candidate_projection_digest": PROJECTION_DIGEST, + "candidate_span": SPAN, + field: value, + } + with pytest.raises(ValueError): + AdmittedCandidateBinding(**kwargs) + + +def test_no_institutional_ir_object_is_constructed_here() -> None: + from pathlib import Path + + source = (Path(__file__).resolve().parents[2] / "src/oic/interpretation_proposal.py").read_text( + encoding="utf-8" + ) + for token in ("InstitutionalIRUnit", "ir_unit_id", "semantic_equivalence_key"): + assert source.count(token) <= 1, token + assert "InstitutionalIRUnit" not in source diff --git a/tests/unit/test_model_provider.py b/tests/unit/test_model_provider.py new file mode 100644 index 0000000..0774f54 --- /dev/null +++ b/tests/unit/test_model_provider.py @@ -0,0 +1,25 @@ +"""The provider seam carries proposals, not admission or authority.""" + +from dataclasses import fields + +from oic.model_provider import ModelRequest, ModelResponse + + +def test_request_has_no_authority_fields() -> None: + assert {f.name for f in fields(ModelRequest)} == { + "system_prompt", + "user_prompt", + "response_format", + "temperature", + "max_tokens", + } + + +def test_response_has_no_admission_fields() -> None: + assert {f.name for f in fields(ModelResponse)} == { + "provider", + "model", + "content", + "request_id", + "raw", + } diff --git a/tests/unit/test_review_docket.py b/tests/unit/test_review_docket.py new file mode 100644 index 0000000..dee62c7 --- /dev/null +++ b/tests/unit/test_review_docket.py @@ -0,0 +1,231 @@ +from __future__ import annotations + +import json + +import pytest + +from oic.candidate_extraction import CandidateExtractionResult, propose_candidate_units +from oic.model_provider import ModelRequest, ModelResponse +from oic.review_docket import AgreementState, build_review_docket + + +class FakeProvider: + def __init__(self, provider: str, content: str) -> None: + self.provider = provider + self.content = content + + def complete(self, request: ModelRequest) -> ModelResponse: + del request + return ModelResponse( + provider=self.provider, + model=f"{self.provider}-model", + content=self.content, + request_id=f"{self.provider}-request", + raw={}, + ) + + +SOURCE = "Payments require Treasurer approval." + + +def anchor(identifier: str = "A-1") -> dict[str, object]: + return { + "anchor_id": identifier, + "source_id": "DOC-1", + "node_id": "N-7", + "content_hash": "sha256:" + ("a" * 64), + } + + +def extract( + provider: str, unit_type: str = "obligation", *, empty: bool = False +) -> CandidateExtractionResult: + body = {"candidates": [] if empty else [{"candidate_span": SOURCE, "unit_type": unit_type}]} + return propose_candidate_units( + source_text=SOURCE, + source_anchor=anchor(), + provider=FakeProvider(provider, json.dumps(body)), + ) + + +def test_docket_exposes_minimal_candidate_without_admission_or_role_placeholders() -> None: + docket = build_review_docket([extract("p1"), extract("p2")]) + rendered = docket.to_json() + assert docket.agreement_state is AgreementState.IDENTICAL + assert rendered["institutional_admission"] is False + assert rendered["candidate_contract"] == "source-grounded-candidate-003" + assert "not admitted or canonical meaning" in rendered["candidate_status"] + item = next(iter(docket.candidates_by_id.values())) + assert item["candidate_span"] == SOURCE + assert item["unit_type"] == "obligation" + assert item["epistemic_state"] == "uncertain" + assert item["interpretation_state"] == "extracted" + assert item["source_anchors"] == [anchor()] + for removed in ( + "actor", + "action", + "object", + "target", + "conditions", + "exceptions", + "evidence_requirements", + ): + assert removed not in item + + +def test_divergent_provisional_types_are_preserved_not_voted() -> None: + docket = build_review_docket([extract("p1"), extract("p2", "mandate")]) + assert docket.agreement_state is AgreementState.DIVERGENT + assert len(docket.candidates_by_id) == 2 + + +def test_all_empty_proposal_sets_are_explicit() -> None: + docket = build_review_docket([extract("p1", empty=True), extract("p2", empty=True)]) + assert docket.agreement_state is AgreementState.NO_CANDIDATES + assert docket.candidates_by_id == {} + + +def test_docket_rejects_mixed_source_anchors() -> None: + other = propose_candidate_units( + source_text="Text.", + source_anchor=anchor("A-2"), + provider=FakeProvider("p2", '{"candidates":[]}'), + ) + with pytest.raises(ValueError, match="source_anchor"): + build_review_docket([extract("p1", empty=True), other]) + + +# -------------------------------------------------------------------------- +# OIC-CANDIDATE-SEMANTICS-004: source context stays with the source +# +# 004 asks the provider to leave separable framing outside the candidate span. That is only +# safe if the framing survives somewhere a reviewer can see. It does: the caller-supplied +# source anchor carries the whole fragment as ``quote``, and the docket exposes the anchor +# as a top-level key structurally separate from the candidates. +# +# So no context field was added anywhere. These tests pin the property the work order asked +# to be confirmed before changing anything, and would fail if a later change dropped the +# anchor, dropped the quote, or folded framing into candidate metadata. +# -------------------------------------------------------------------------- + +DRAFT_SOURCE = ( + "DRAFT — NOT YET ADOPTED. A payment above $10,000 requires approval by the " + "Chief Financial Officer." +) +DRAFT_PROPOSITION = "A payment above $10,000 requires approval by the Chief Financial Officer." +DRAFT_FRAMING = "DRAFT — NOT YET ADOPTED." + + +def framing_anchor() -> dict[str, object]: + """A caller-controlled anchor carrying the whole source fragment as its quote.""" + return { + "anchor_id": "A-DRAFT", + "source_id": "DOC-DRAFT", + "node_id": "N-1", + "content_hash": "sha256:" + ("b" * 64), + "quote": DRAFT_SOURCE, + } + + +def framing_extract(provider: str = "p1") -> CandidateExtractionResult: + body = {"candidates": [{"candidate_span": DRAFT_PROPOSITION, "unit_type": "obligation"}]} + return propose_candidate_units( + source_text=DRAFT_SOURCE, + source_anchor=framing_anchor(), + provider=FakeProvider(provider, json.dumps(body)), + ) + + +def test_the_docket_retains_the_original_source_context_including_its_framing() -> None: + docket = build_review_docket([framing_extract()]).to_json() + assert docket["source_anchor"]["quote"] == DRAFT_SOURCE + assert DRAFT_FRAMING in str(docket["source_anchor"]["quote"]) + + +def test_the_docket_separates_source_context_from_the_candidate_span() -> None: + """A reviewer sees the draft marking and the proposition, in different places.""" + docket = build_review_docket([framing_extract()]).to_json() + candidate = next(iter(docket["candidates_by_id"].values())) + + # Source context: the framing is here. + assert DRAFT_FRAMING in str(docket["source_anchor"]["quote"]) + # Candidate span: the proposition is here, and the framing is not. + assert candidate["candidate_span"] == DRAFT_PROPOSITION + assert DRAFT_FRAMING not in str(candidate["candidate_span"]) + # They are different top-level keys, not one merged blob. + assert "source_anchor" in docket + assert "candidates_by_id" in docket + assert docket["source_anchor"] is not docket["candidates_by_id"] + + +def test_the_candidate_anchor_still_points_back_at_the_framed_source() -> None: + """Separation is presentational; the candidate never loses its provenance.""" + candidate = framing_extract().candidates[0] + assert candidate["source_anchors"] == [framing_anchor()] + assert DRAFT_FRAMING in str(candidate["source_anchors"][0]["quote"]) + + +def test_framing_is_never_recorded_as_candidate_authority_metadata() -> None: + """Draft standing is source context at this stage and confers nothing.""" + docket = build_review_docket([framing_extract()]).to_json() + candidate = next(iter(docket["candidates_by_id"].values())) + assert set(candidate) == { + "unit_id", + "candidate_span", + "unit_type", + "interpretation_state", + "epistemic_state", + "source_anchors", + } + assert candidate["interpretation_state"] == "extracted" + assert candidate["epistemic_state"] == "uncertain" + assert docket["institutional_admission"] is False + assert "not admitted" in str(docket["candidate_status"]) + for invented in ("standing", "framing", "draft", "authority", "admitted", "confidence"): + assert invented not in candidate, invented + + +def test_no_source_context_field_was_added_to_the_docket() -> None: + """The anchor already preserved the excerpt, so nothing new was introduced.""" + docket = build_review_docket([framing_extract()]).to_json() + assert set(docket) == { + "candidate_contract", + "candidate_status", + "docket_id", + "source_anchor", + "agreement_state", + "proposal_sets", + "candidates_by_id", + "institutional_admission", + } + + +def test_a_docket_over_an_overreaching_span_shows_the_overreach_rather_than_hiding_it() -> None: + """An unseparated span is reported as returned, so review can see the defect.""" + body = {"candidates": [{"candidate_span": DRAFT_SOURCE, "unit_type": "obligation"}]} + extraction = propose_candidate_units( + source_text=DRAFT_SOURCE, + source_anchor=framing_anchor(), + provider=FakeProvider("p1", json.dumps(body)), + ) + docket = build_review_docket([extraction]).to_json() + candidate = next(iter(docket["candidates_by_id"].values())) + assert candidate["candidate_span"] == DRAFT_SOURCE + assert DRAFT_FRAMING in str(candidate["candidate_span"]) + + +def test_the_same_proposition_under_different_anchors_stays_two_docket_entries() -> None: + """Source-instance identity is preserved; nothing merges across anchors.""" + first = framing_extract() + plain_anchor = dict(framing_anchor()) + plain_anchor["anchor_id"] = "A-PLAIN" + body = {"candidates": [{"candidate_span": DRAFT_PROPOSITION, "unit_type": "obligation"}]} + second = propose_candidate_units( + source_text=DRAFT_SOURCE, + source_anchor=plain_anchor, + provider=FakeProvider("p2", json.dumps(body)), + ) + assert first.candidates[0]["candidate_span"] == second.candidates[0]["candidate_span"] + assert first.candidates[0]["unit_id"] != second.candidates[0]["unit_id"] + with pytest.raises(ValueError, match="one source_anchor"): + build_review_docket([first, second])