Skip to content

0.7.1g1P2: authority model reconciliation (design record, no implementation) - #469

Merged
GionaGranchelli merged 4 commits into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1P2-authority-model-reconciliation
Oct 1, 2026
Merged

GionaGranchelli merged 4 commits into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1P2-authority-model-reconciliation

Conversation

@GionaGranchelli

@GionaGranchelli GionaGranchelli commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Base

689e8b65472d41f240add5bfb4a3cc4bb2b2baf7. Design only — no rule, code, authority, baseline, admissions, classification or configuration change. P2 is not performed. Stop before implementation.

Empirical result (four complete unrestricted campaigns, same effective PIT inputs)

Four distinct raw-status digests (9aebd320…, 31fc3b0e…, f83b0feb…, 8e00fd7e…) while the canonical authority projection is identical in all four: e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad. Raw reports preserved, SHA-256 manifest-verified, independently re-aggregated from XML.

Stable in all four: 2544 identities with identical identity set in every pair, all seven family/module counts (918/808/382/209/155/57/15), 1836 KILLED, 190 NO_COVERAGE, 1836/708 outcomes, shared 2195, base-only 189, candidate-only 349, candidate-only NON_KILLED 67, and the 67 authorized rows byte-identical including raw status (36 TIMED_OUT / 27 SURVIVED / 4 NO_COVERAGE). Unstable: only SURVIVED↔TIMED_OUT, only ever 3 identities of 2544 (0.118%), all NON_KILLED in every run.

Contract, from code

BaselineModel.kt:348-354 (C7): raw PIT status is diagnostic evidence, NOT authority — "TIMED_OUT↔SURVIVED scheduler races must not churn the ratchet". MutationPopulationAdmissionCeremony.kt: M32 binds the authorized row's exact status, M33 the analyzer, M34 the whole-population digest via projectionHash — the measurement-proof projection. Reconciliation: M34 did not deliberately override C7; one hash was reused for two different trust questions, and a diagnostic rode into the authority path by construction.

Three independent trust questions

  • A — fresh ↔ committed candidate: raw-exact, no relaxation. That is raw status's proper home.
  • B — individual admission rows: keep status-inclusive binding. Empirically free (the 67 are stable in all four campaigns) and protects real content: G5b TOOLING_LIMITATION asserts a timeout mechanism, G5d UNREACHABLE asserts the code cannot execute, G5c EQUIVALENT rests on a surviving observation. All four candidate transitions invalidate one of them.
  • C — whole-population context: the defect. It must stop binding unrelated neighbouring raw status.

Threat model

All twelve attacks map to rejecting rules (M01; M06/M20; identity recomputation + M12/M19; M32/M14; M33 + M16-M18 with the analyzer staying inside the authority digest; M21; exactComparison(); M31; M38; M37/M38; M32 retained; M13 + canonical() unchanged). None becomes admissible.

Option A (recommended) vs Option B

M34 retains a property no other rule provides: the authorization stays bound to the population context it was adjudicated against, blocking stale-context replay. Option B discards that property to remove a defect Option A removes anyway.

Migration of the 67 — base-side certificate, not an admission rewrite

The earlier revision of this record proposed migrating digest semantics in place on the 67 records while claiming M36 stayed unchanged. That claim was false and is withdrawn (§6.1 records it rather than erasing it): MutationPopulationAdmissions.kt:75-88 puts populationDigest inside enforcedPayload(), and MutationPopulationAdmissionCeremony.kt:314-317 (isRetainedRewrite()) fails M36 on any enforced-payload change.

Corrected design: not one byte of the 67 admissions changes. A separate base-authoritative digest-migration certificate carries fromAlgorithm: raw-v1, fromDigest: 9aebd320…, toAlgorithm: authority-v2, toDigest: e6ad01dc…, admissionSetDigest (the exact 67), fromBaseSha, reason.

P1 merged (67 v1 authorizations, byte-identical and untouched)
    ↓
P1M — mint the bounded certificate (touches only the certificate ledger; no population transition, no consumption)
    ↓
certificate exists in BASE
    ↓
P2 — consume the original 67 using exact row (M32), analyzer (M33), base-certified authority-v2 context;
     then remove the admissions and the certificate

Full fail-closed lifecycle — consumption rules alone are insufficient, so each step has its own rule and discriminator:

mint against the exact base        (M45)
  → retain byte-identically        (M46)
  → consume only from base         (M43 + M42 + M41 + M40)
  → remove in the valid consuming transition  (M44 + M47)
  • M40 cited certificate's toDigest ≠ the verifier's fresh authority projection → fail
  • M41 fromAlgorithm/fromDigest ≠ the cited admission's populationDigest → fail
  • M42 admissionSetDigest ≠ the exact base authorization set → fail (this is what bounds it)
  • M43 certificate introduced by the same transition that consumes it → fail (the M31 analogue)
  • M44 certificate retained after the consumption it authorised → fail (single use, the M38 analogue)
  • M45 newly introduced certificate whose fromBaseSha ≠ the authority base → fail (mint-time base binding, the M35 analogue)
  • M46 base-retained certificate whose enforced payload differs from the base copy → fail (retained immutability, the M36 analogue; the enforced payload is stated explicitly: fromAlgorithm, fromDigest, toAlgorithm, toDigest, admissionSetDigest, fromBaseSha, reason, audit-only metadata excluded)
  • M47 base certificate absent without a valid consumption in that same transition → fail (removal custody, the M37 analogue — never silent cancellation)

These are explicit and not assumed from existing machinery. The existing loaders validate shape only (required fields, canonical 64-hex identity, 40-hex fromBaseSha, duplicate ids, schemaVersion) and cannot enforce mint binding, immutability or removal custody; for admissions those guarantees come from the ceremony rules themselves. A new ledger left to generic loader validation would have none of them.

M36 and M37 stay literally unchanged — no exception branch, no permitted-field list.

Discriminator matrix required before implementation — T1-T19

Each attack needs a pure-verifier test and a real-task authority-transport test (per AGENTS.md, a verifier-level discriminator cannot detect a missing loader call site).

T1 neighbour raw status flips, outcome/family/module unchanged → authority digest unchanged, M34 pass (the Case-3 discriminator) · T2 neighbour outcome flips → digest changes, M34 fail · T3 authorized row's own status changes → M32 fail · T4 v1 record under v2 semantics → fail closed · T5 certificate names an identity absent from the v1 ledger → fail · T6 certificate omits/misstates its digests → fail · T7 authority digest from candidate-supplied data → fail (transport proves the fresh path) · T8 analyzer/mutator/timeout drift → fail · T9 family/module re-homing → M32 fail · T10 unknown status or outcome contradicting canonical(status) → M13 fail · T11 KILLED→NON_KILLED → M01 fail · T12 unauthorized appearing NON_KILLED → M06 fail · T13 migration cannot rewrite admission authority (enforced payload byte-identical; only a base-minted certificate may translate context) → M36 fail · T14 same-transition self-migration → M43 fail · T15 certificate not matching the cited admission's fromDigest or the exact authorization set → M41/M42 fail · T16 certificate retained after consumption → M44 fail · T17 mint-time base binding violated → M45 fail · T18 retained certificate rewritten → M46 fail · T19 base certificate removed without valid consumption → M47 fail.

Files in scope / out of scope

Would change: the verifier's projection split (keep projectionHash raw-exact, add the authority projection); the admissions ceremony (authority-projection M34 + certificate-aware consumption + M40-M47), with isRetainedRewrite() and the M36 path untouched; a new certificate ledger with its own loader; the T1-T19 tests; docs.

Not changed: MutationPopulationAdmissions.kt payload (no new enforced field), the admissions loader, mutation-population-admissions.yml (byte-identical), the committed baseline, classifications, evolution records, analyzer semantics, roadmap. Out of scope: P2 consumption, M21 records, PIT timeouts, mutator targets, the canonical outcome mapping, M06/M13/M36/M37, and killing the three oscillating mutants or otherwise seeking to recover 9aebd320….

Not done

No campaign rerun, no timeout tuning, no mutant killing, no baseline/P1/M21/classification change, no P2. Evidence envelopes stay local with local SHA-256 manifests, deliberately uncommitted. The nondeterminism itself remains unresolved; this record only establishes that raw status is the wrong thing for the authority digest to bind, which is what C7 already said.

…esign record)

Four complete unrestricted campaigns at the same effective PIT inputs produced four
distinct raw-status population digests while the canonical authority projection
(identity|outcome|family|module + topology + analyzer) was byte-identical in all four:
e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad

Establishes from repository code that C7 (BaselineModel.kt:348-354) declares raw PIT
status diagnostic and non-authority while M34 binds it for the whole population through
the measurement-proof projection; that the 67 authorized rows are exactly stable across
all four campaigns (so M32's status-inclusive binding is not the defect and is retained);
and that the instability is 3 of 2544 non-authorized neighbours.

Recommends Option A (canonical authority digest) over Option B, and specifies a bounded
versioned migration for the existing 67 v1 authorizations that preserves provenance.

Design only: no rule, code, authority or configuration change; P2 not performed.
Copilot AI balanced review requested due to automatic review settings October 1, 2026 12:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Although docs-only and factually accurate, it is a governance/authority-model design record whose reasoning will drive sensitive mutation-ratchet authority changes and warrants expert human review.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR adds a single documentation file — a design record under docs/roadmap/0.7.0/ — that analyzes and reconciles the mutation-ratchet authority model. It establishes, from four preserved PIT campaigns, that only the raw SURVIVED↔TIMED_OUT status of 3 non-authorized identities (0.118%) is unstable while the canonical authority projection is identical across all runs. It diagnoses that the M34 whole-population digest reuses the raw measurement-proof projection (projectionHash), importing diagnostic raw status into the authority path in contradiction with contract C7, and specifies (but deliberately does not implement) a corrective split plus a bounded, versioned migration for the existing 67 v1 admissions. It is explicitly design-only: no rule, code, baseline, admissions, or configuration change.

Changes:

  • Adds the authority-model reconciliation design record with empirical evidence, the C7/M32/M34 contract reconciliation, a three-trust-question split, a threat model, Option A vs B recommendation, and a migration design.
  • Specifies a required T1–T12 adversarial discriminator matrix (verifier-level and real-task level) and the implementation slice (files/rules) to be performed later.
  • No production code, analyzer, baseline, or config is touched (verified: mutation-population-admissions.yml unchanged).
File Description
docs/​roadmap/​0.7.0/​TASK-0.7.1g1P2-AUTHORITY-MODEL-RECONCILIATION.md New design-only record reconciling the raw-status vs canonical-authority digest issue; its code references (C7 at BaselineModel.kt:348-354, MutationRatchetVerifier projection recipe, MutationPopulationAdmissionCeremony M30–M39) and the 67-admission facts were verified accurate, with one internal cross-reference inconsistency ("Attacks 1-13" vs the 12-attack table).

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/roadmap/0.7.0/TASK-0.7.1g1P2-AUTHORITY-MODEL-RECONCILIATION.md Outdated
…igration certificate

Review finding, proven from code: MutationPopulationAdmissions.kt:75-88 enforcedPayload()
includes populationDigest, and MutationPopulationAdmissionCeremony.kt:314-317 isRetainedRewrite()
compares it -- so the earlier revision's in-place digest migration would have been a retained
authority rewrite, and its claim that M36 stayed unchanged was false.

The corrected design keeps M36 and M37 literally unchanged: the 67 admissions stay byte-identical,
and the raw-v1 -> authority-v2 semantic upgrade is carried by a separate bounded base-side
digest-migration certificate (fromAlgorithm/fromDigest/toAlgorithm/toDigest/admissionSetDigest/
fromBaseSha/reason), minted in a P1M transition that touches only the certificate ledger and
consumed in P2, then removed with the admissions. Adds M40-M44 and discriminators T13-T16
(including the M31 analogue: a candidate cannot mint and consume the certificate in one
transition). Section 6.1 records the withdrawn proposal rather than erasing it.

Empirical conclusion, C7 reconciliation, Option A, authority-v2 projection and individual-row
binding unchanged.
@GionaGranchelli

Copy link
Copy Markdown
Owner Author

Design correction applied at f8b95df6 — the finding was right, and it is proven from the repository's own code, not taken on trust:

  • MutationPopulationAdmissions.kt:75-88 — enforcedPayload() includes populationDigest.
  • MutationPopulationAdmissionCeremony.kt:314-317 — isRetainedRewrite() is candidate.enforcedPayload() != base.enforcedPayload(), and M36 fails on it.

So the earlier revision's in-place digest migration would have been a retained-authority rewrite, and its claim that M36 stayed unchanged was false. Section 6.1 now records the withdrawn proposal rather than erasing it.

Corrected design — a bounded base-side digest-migration certificate. Not one byte of the 67 admissions changes. A separate ledger carries fromAlgorithm: raw-v1, fromDigest: 9aebd320…, toAlgorithm: authority-v2, toDigest: e6ad01dc…, admissionSetDigest (the exact 67), fromBaseSha, reason; it is minted in a P1M transition that touches only the certificate ledger, must already exist in the base before P2 consumes the 67 with it, and is removed together with the admissions. New fail-closed rules M40-M44, including M43 — a candidate cannot mint and consume the certificate in one transition (the M31 analogue).

M36 and M37 stay literally unchanged: no exception branch, no permitted-field list.

The Copilot typo became the right place for the missing discriminators, so T13-T16 were added instead of just renumbering: T13 migration cannot rewrite admission authority (any enforced-payload change → M36), T14 same-transition self-migration → M43, T15 certificate bound to the cited admission's fromDigest and the exact authorization set → M41/M42, T16 retained certificate after consumption → M44.

Unchanged: the empirical four-run result, e6ad01dc…, the C7 reconciliation, Option A, the authority-v2 projection, individual status-inclusive row binding, and the new ledgers/rules/scope lists in §8-§9.

The certificate is base authority in its own right, so consumption rules alone are
insufficient. Added explicit lifecycle rules and discriminators rather than relying on
generic loader validation, which for the existing ledgers covers shape only (required
fields, canonical 64-hex identity, 40-hex fromBaseSha, duplicate ids, schemaVersion) and
cannot enforce transition guarantees.

Lifecycle: mint against the exact base (M45, the M35 analogue) -> retain byte-identically
(M46, the M36 analogue, judged over an explicitly stated enforced payload: fromAlgorithm,
fromDigest, toAlgorithm, toDigest, admissionSetDigest, fromBaseSha, reason; audit-only
metadata excluded) -> consume only from base (M43+M42+M41+M40) -> remove in the valid
consuming transition (M44+M47, M47 being the M37 analogue: a certificate may only disappear
by being consumed, never by silent cancellation). Discriminators T17-T19 added; the matrix
is now T1-T19.
@GionaGranchelli
GionaGranchelli merged commit ec8b4da into epic/0.7.1-control-plane-authority Oct 1, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants