0.7.1g1P2: authority model reconciliation (design record, no implementation) - #469
Conversation
…esign record) Four complete unrestricted campaigns at the same effective PIT inputs produced four distinct raw-status population digests while the canonical authority projection (identity|outcome|family|module + topology + analyzer) was byte-identical in all four: e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad Establishes from repository code that C7 (BaselineModel.kt:348-354) declares raw PIT status diagnostic and non-authority while M34 binds it for the whole population through the measurement-proof projection; that the 67 authorized rows are exactly stable across all four campaigns (so M32's status-inclusive binding is not the defect and is retained); and that the instability is 3 of 2544 non-authorized neighbours. Recommends Option A (canonical authority digest) over Option B, and specifies a bounded versioned migration for the existing 67 v1 authorizations that preserves provenance. Design only: no rule, code, authority or configuration change; P2 not performed.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Although docs-only and factually accurate, it is a governance/authority-model design record whose reasoning will drive sensitive mutation-ratchet authority changes and warrants expert human review.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This PR adds a single documentation file — a design record under docs/roadmap/0.7.0/ — that analyzes and reconciles the mutation-ratchet authority model. It establishes, from four preserved PIT campaigns, that only the raw SURVIVED↔TIMED_OUT status of 3 non-authorized identities (0.118%) is unstable while the canonical authority projection is identical across all runs. It diagnoses that the M34 whole-population digest reuses the raw measurement-proof projection (projectionHash), importing diagnostic raw status into the authority path in contradiction with contract C7, and specifies (but deliberately does not implement) a corrective split plus a bounded, versioned migration for the existing 67 v1 admissions. It is explicitly design-only: no rule, code, baseline, admissions, or configuration change.
Changes:
- Adds the authority-model reconciliation design record with empirical evidence, the C7/M32/M34 contract reconciliation, a three-trust-question split, a threat model, Option A vs B recommendation, and a migration design.
- Specifies a required T1–T12 adversarial discriminator matrix (verifier-level and real-task level) and the implementation slice (files/rules) to be performed later.
- No production code, analyzer, baseline, or config is touched (verified:
mutation-population-admissions.ymlunchanged).
| File | Description |
|---|---|
| docs/roadmap/0.7.0/TASK-0.7.1g1P2-AUTHORITY-MODEL-RECONCILIATION.md | New design-only record reconciling the raw-status vs canonical-authority digest issue; its code references (C7 at BaselineModel.kt:348-354, MutationRatchetVerifier projection recipe, MutationPopulationAdmissionCeremony M30–M39) and the 67-admission facts were verified accurate, with one internal cross-reference inconsistency ("Attacks 1-13" vs the 12-attack table). |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…igration certificate Review finding, proven from code: MutationPopulationAdmissions.kt:75-88 enforcedPayload() includes populationDigest, and MutationPopulationAdmissionCeremony.kt:314-317 isRetainedRewrite() compares it -- so the earlier revision's in-place digest migration would have been a retained authority rewrite, and its claim that M36 stayed unchanged was false. The corrected design keeps M36 and M37 literally unchanged: the 67 admissions stay byte-identical, and the raw-v1 -> authority-v2 semantic upgrade is carried by a separate bounded base-side digest-migration certificate (fromAlgorithm/fromDigest/toAlgorithm/toDigest/admissionSetDigest/ fromBaseSha/reason), minted in a P1M transition that touches only the certificate ledger and consumed in P2, then removed with the admissions. Adds M40-M44 and discriminators T13-T16 (including the M31 analogue: a candidate cannot mint and consume the certificate in one transition). Section 6.1 records the withdrawn proposal rather than erasing it. Empirical conclusion, C7 reconciliation, Option A, authority-v2 projection and individual-row binding unchanged.
|
Design correction applied at
So the earlier revision's in-place digest migration would have been a retained-authority rewrite, and its claim that M36 stayed unchanged was false. Section 6.1 now records the withdrawn proposal rather than erasing it. Corrected design — a bounded base-side digest-migration certificate. Not one byte of the 67 admissions changes. A separate ledger carries M36 and M37 stay literally unchanged: no exception branch, no permitted-field list. The Copilot typo became the right place for the missing discriminators, so T13-T16 were added instead of just renumbering: T13 migration cannot rewrite admission authority (any enforced-payload change → M36), T14 same-transition self-migration → M43, T15 certificate bound to the cited admission's Unchanged: the empirical four-run result, |
The certificate is base authority in its own right, so consumption rules alone are insufficient. Added explicit lifecycle rules and discriminators rather than relying on generic loader validation, which for the existing ledgers covers shape only (required fields, canonical 64-hex identity, 40-hex fromBaseSha, duplicate ids, schemaVersion) and cannot enforce transition guarantees. Lifecycle: mint against the exact base (M45, the M35 analogue) -> retain byte-identically (M46, the M36 analogue, judged over an explicitly stated enforced payload: fromAlgorithm, fromDigest, toAlgorithm, toDigest, admissionSetDigest, fromBaseSha, reason; audit-only metadata excluded) -> consume only from base (M43+M42+M41+M40) -> remove in the valid consuming transition (M44+M47, M47 being the M37 analogue: a certificate may only disappear by being consumed, never by silent cancellation). Discriminators T17-T19 added; the matrix is now T1-T19.
ec8b4da
into
epic/0.7.1-control-plane-authority

Base
689e8b65472d41f240add5bfb4a3cc4bb2b2baf7. Design only — no rule, code, authority, baseline, admissions, classification or configuration change. P2 is not performed. Stop before implementation.Empirical result (four complete unrestricted campaigns, same effective PIT inputs)
Four distinct raw-status digests (
9aebd320…,31fc3b0e…,f83b0feb…,8e00fd7e…) while the canonical authority projection is identical in all four:e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad. Raw reports preserved, SHA-256 manifest-verified, independently re-aggregated from XML.Stable in all four: 2544 identities with identical identity set in every pair, all seven family/module counts (918/808/382/209/155/57/15), 1836 KILLED, 190 NO_COVERAGE, 1836/708 outcomes, shared 2195, base-only 189, candidate-only 349, candidate-only NON_KILLED 67, and the 67 authorized rows byte-identical including raw status (36 TIMED_OUT / 27 SURVIVED / 4 NO_COVERAGE). Unstable: only SURVIVED↔TIMED_OUT, only ever 3 identities of 2544 (0.118%), all NON_KILLED in every run.
Contract, from code
BaselineModel.kt:348-354(C7): raw PIT status is diagnostic evidence, NOT authority — "TIMED_OUT↔SURVIVED scheduler races must not churn the ratchet".MutationPopulationAdmissionCeremony.kt: M32 binds the authorized row's exact status, M33 the analyzer, M34 the whole-population digest viaprojectionHash— the measurement-proof projection. Reconciliation: M34 did not deliberately override C7; one hash was reused for two different trust questions, and a diagnostic rode into the authority path by construction.Three independent trust questions
Threat model
All twelve attacks map to rejecting rules (M01; M06/M20; identity recomputation + M12/M19; M32/M14; M33 + M16-M18 with the analyzer staying inside the authority digest; M21;
exactComparison(); M31; M38; M37/M38; M32 retained; M13 +canonical()unchanged). None becomes admissible.Option A (recommended) vs Option B
M34 retains a property no other rule provides: the authorization stays bound to the population context it was adjudicated against, blocking stale-context replay. Option B discards that property to remove a defect Option A removes anyway.
Migration of the 67 — base-side certificate, not an admission rewrite
The earlier revision of this record proposed migrating digest semantics in place on the 67 records while claiming M36 stayed unchanged. That claim was false and is withdrawn (§6.1 records it rather than erasing it):
MutationPopulationAdmissions.kt:75-88putspopulationDigestinsideenforcedPayload(), andMutationPopulationAdmissionCeremony.kt:314-317(isRetainedRewrite()) fails M36 on any enforced-payload change.Corrected design: not one byte of the 67 admissions changes. A separate base-authoritative digest-migration certificate carries
fromAlgorithm: raw-v1,fromDigest: 9aebd320…,toAlgorithm: authority-v2,toDigest: e6ad01dc…,admissionSetDigest(the exact 67),fromBaseSha,reason.Full fail-closed lifecycle — consumption rules alone are insufficient, so each step has its own rule and discriminator:
toDigest≠ the verifier's fresh authority projection → failfromAlgorithm/fromDigest≠ the cited admission'spopulationDigest→ failadmissionSetDigest≠ the exact base authorization set → fail (this is what bounds it)fromBaseSha≠ the authority base → fail (mint-time base binding, the M35 analogue)fromAlgorithm, fromDigest, toAlgorithm, toDigest, admissionSetDigest, fromBaseSha, reason, audit-only metadata excluded)These are explicit and not assumed from existing machinery. The existing loaders validate shape only (required fields, canonical 64-hex identity, 40-hex
fromBaseSha, duplicate ids,schemaVersion) and cannot enforce mint binding, immutability or removal custody; for admissions those guarantees come from the ceremony rules themselves. A new ledger left to generic loader validation would have none of them.M36 and M37 stay literally unchanged — no exception branch, no permitted-field list.
Discriminator matrix required before implementation — T1-T19
Each attack needs a pure-verifier test and a real-task authority-transport test (per
AGENTS.md, a verifier-level discriminator cannot detect a missing loader call site).T1 neighbour raw status flips, outcome/family/module unchanged → authority digest unchanged, M34 pass (the Case-3 discriminator) · T2 neighbour outcome flips → digest changes, M34 fail · T3 authorized row's own status changes → M32 fail · T4 v1 record under v2 semantics → fail closed · T5 certificate names an identity absent from the v1 ledger → fail · T6 certificate omits/misstates its digests → fail · T7 authority digest from candidate-supplied data → fail (transport proves the fresh path) · T8 analyzer/mutator/timeout drift → fail · T9 family/module re-homing → M32 fail · T10 unknown status or outcome contradicting
canonical(status)→ M13 fail · T11 KILLED→NON_KILLED → M01 fail · T12 unauthorized appearing NON_KILLED → M06 fail · T13 migration cannot rewrite admission authority (enforced payload byte-identical; only a base-minted certificate may translate context) → M36 fail · T14 same-transition self-migration → M43 fail · T15 certificate not matching the cited admission'sfromDigestor the exact authorization set → M41/M42 fail · T16 certificate retained after consumption → M44 fail · T17 mint-time base binding violated → M45 fail · T18 retained certificate rewritten → M46 fail · T19 base certificate removed without valid consumption → M47 fail.Files in scope / out of scope
Would change: the verifier's projection split (keep
projectionHashraw-exact, add the authority projection); the admissions ceremony (authority-projection M34 + certificate-aware consumption + M40-M47), withisRetainedRewrite()and the M36 path untouched; a new certificate ledger with its own loader; the T1-T19 tests; docs.Not changed:
MutationPopulationAdmissions.ktpayload (no new enforced field), the admissions loader,mutation-population-admissions.yml(byte-identical), the committed baseline, classifications, evolution records, analyzer semantics, roadmap. Out of scope: P2 consumption, M21 records, PIT timeouts, mutator targets, the canonical outcome mapping, M06/M13/M36/M37, and killing the three oscillating mutants or otherwise seeking to recover9aebd320….Not done
No campaign rerun, no timeout tuning, no mutant killing, no baseline/P1/M21/classification change, no P2. Evidence envelopes stay local with local SHA-256 manifests, deliberately uncommitted. The nondeterminism itself remains unresolved; this record only establishes that raw status is the wrong thing for the authority digest to bind, which is what C7 already said.