authority(0.7.1g1P2-P1M): mint the base-side raw-v1 -> authority-v2 migration certificate - #472
Conversation
…igration certificate P1M: the single isolated transition between Step 2 and Step 3. It establishes certificate authority; it does not consume it. One certificate, derived from repository truth rather than chosen: - fromAlgorithm raw-v1 / fromDigest 9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0 This is the digest every one of the 67 committed P1 admissions is bound to. The ledger holds exactly one distinct populationDigest value across 67 admissions, so the historical authority source is coherent; nothing was changed to make it match. - toAlgorithm authority-v2 / toDigest e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad Recomputed independently over the frozen unrestricted measurement (2544 identities, the population the raw-v1 digest was taken over) from the canonical authority projection semantics: identity, canonical outcome, family, module, topology, analyzer. The same value was byte-identical across all four preserved campaigns. It is not copied from any candidate. - admissionSetDigest 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c Reproduced from the exact 67 committed identities using the Step-2 contract (sorted, joined with a newline plus the trailing newline, SHA-256). It equals the value pinned by the Step-2 test. - fromBaseSha 64d0545 - the exact post-#471 epic tip, so M45's mint-time binding is against the real authority base and not a provisional preview SHA. - reason records the migration without implying any historical admission was upgraded or rewritten. The certificate ledger is the only changed path. The 67 admissions are byte-identical: no admission was modified, no digest rewritten, no metadata touched, and no mutation authority was re-measured. Ordering this preserves: a candidate may only consume migration authority that already existed in its base. A later transition (Step 3) consumes this certificate; P1M minting and consuming its own authority in one transition is exactly what the M43 analogue forbids. Mechanical gate P1-P8 (changed-path isolation, admission byte identity, semantic population identity, certificate cardinality, M45 binding, bounded admission set, source binding, independent target recomputation) is recorded in the pull request. No permanent rule was added for this migration, and no gate, threshold, suppression or baseline was weakened.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
This is a trust-critical governance authority artifact whose central toDigest authority-v2 projection and base-SHA binding cannot be independently re-derived in this environment and require human verification before merge.
Review effort: Balanced
Findings: None
What changed in this PR
This PR mints the single base-side authority artifact for the P1M transition in the 0.7.1g1P2 authority-model reconciliation: it adds one digest-migration certificate to a new ledger, config/quality/mutation-authority-digest-certificates.yml. The certificate records, in base authority, that the raw-v1 whole-population authority digest of the 67 P1 admissions is semantically equal to its authority-v2 projection, without rewriting any historical admission. It consumes the machinery introduced in #471 (certificate type, loader, and M45–M47 ceremony) and leaves actual consumption to Step 3.
Changes:
- Adds a new YAML ledger containing exactly one certificate (
raw-v1→authority-v2) withfromDigest,toDigest,admissionSetDigest,fromBaseSha, and a provenancereason. - Binds the certificate to the 67 committed admissions via
admissionSetDigestand to the post-#471 base viafromBaseSha, per the M42/M45 contracts. - Touches no other file: the 67 admissions, baselines, loader/ceremony code, and static-analysis baseline are unchanged.
| File | Description |
|---|---|
| config/quality/mutation-authority-digest-certificates.yml | New single-entry certificate ledger establishing the raw-v1 → authority-v2 digest-migration authority for the P1M transition. |
Verification performed during review:
- All field formats satisfy the loader's regexes (
fromDigest/toDigest/admissionSetDigestare 64-hex;fromBaseShais 40-hex), algorithms are both in the allowed set and distinct,reasonis non-blank, andschemaVersion: "1"matches; the file parses cleanly. - The pinned
admissionSetDigest(98a9587a…) reproduces the sorted-identities-with-trailing-newline SHA-256 over the committed 67 admissions. fromDigest(9aebd320…) equals the single distinctpopulationDigestacross all 67 admissions, consistent with M41's later expectation.- The declared
fromBaseShamatches the M45 base-binding the ceremony enforces.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
9ebe7b4
into
epic/0.7.1-control-plane-authority
…igration certificate (#472) P1M: the single isolated transition between Step 2 and Step 3. It establishes certificate authority; it does not consume it. One certificate, derived from repository truth rather than chosen: - fromAlgorithm raw-v1 / fromDigest 9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0 This is the digest every one of the 67 committed P1 admissions is bound to. The ledger holds exactly one distinct populationDigest value across 67 admissions, so the historical authority source is coherent; nothing was changed to make it match. - toAlgorithm authority-v2 / toDigest e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad Recomputed independently over the frozen unrestricted measurement (2544 identities, the population the raw-v1 digest was taken over) from the canonical authority projection semantics: identity, canonical outcome, family, module, topology, analyzer. The same value was byte-identical across all four preserved campaigns. It is not copied from any candidate. - admissionSetDigest 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c Reproduced from the exact 67 committed identities using the Step-2 contract (sorted, joined with a newline plus the trailing newline, SHA-256). It equals the value pinned by the Step-2 test. - fromBaseSha 64d0545 - the exact post-#471 epic tip, so M45's mint-time binding is against the real authority base and not a provisional preview SHA. - reason records the migration without implying any historical admission was upgraded or rewritten. The certificate ledger is the only changed path. The 67 admissions are byte-identical: no admission was modified, no digest rewritten, no metadata touched, and no mutation authority was re-measured. Ordering this preserves: a candidate may only consume migration authority that already existed in its base. A later transition (Step 3) consumes this certificate; P1M minting and consuming its own authority in one transition is exactly what the M43 analogue forbids. Mechanical gate P1-P8 (changed-path isolation, admission byte identity, semantic population identity, certificate cardinality, M45 binding, bounded admission set, source binding, independent target recomputation) is recorded in the pull request. No permanent rule was added for this migration, and no gate, threshold, suppression or baseline was weakened.
…igration certificate (#472) P1M: the single isolated transition between Step 2 and Step 3. It establishes certificate authority; it does not consume it. One certificate, derived from repository truth rather than chosen: - fromAlgorithm raw-v1 / fromDigest 9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0 This is the digest every one of the 67 committed P1 admissions is bound to. The ledger holds exactly one distinct populationDigest value across 67 admissions, so the historical authority source is coherent; nothing was changed to make it match. - toAlgorithm authority-v2 / toDigest e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad Recomputed independently over the frozen unrestricted measurement (2544 identities, the population the raw-v1 digest was taken over) from the canonical authority projection semantics: identity, canonical outcome, family, module, topology, analyzer. The same value was byte-identical across all four preserved campaigns. It is not copied from any candidate. - admissionSetDigest 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c Reproduced from the exact 67 committed identities using the Step-2 contract (sorted, joined with a newline plus the trailing newline, SHA-256). It equals the value pinned by the Step-2 test. - fromBaseSha 64d0545 - the exact post-#471 epic tip, so M45's mint-time binding is against the real authority base and not a provisional preview SHA. - reason records the migration without implying any historical admission was upgraded or rewritten. The certificate ledger is the only changed path. The 67 admissions are byte-identical: no admission was modified, no digest rewritten, no metadata touched, and no mutation authority was re-measured. Ordering this preserves: a candidate may only consume migration authority that already existed in its base. A later transition (Step 3) consumes this certificate; P1M minting and consuming its own authority in one transition is exactly what the M43 analogue forbids. Mechanical gate P1-P8 (changed-path isolation, admission byte identity, semantic population identity, certificate cardinality, M45 binding, bounded admission set, source binding, independent target recomputation) is recorded in the pull request. No permanent rule was added for this migration, and no gate, threshold, suppression or baseline was weakened.
Base
64d05450c285ecd9cf3635ca2935da816f649856— the exact post-#471 epic tip. Obtained from the merge record, not assumed, and not a provisional preview SHA.P1M: the single isolated authority transition between Step 2 and Step 3. It establishes certificate authority. It does not consume it.
Required evidence
Mechanical gate P1-P8: ALL PASS (eleven checks). No permanent generic rule was added for this migration.
How each value was sourced
fromDigest— the ledger carries exactly one distinctpopulationDigestacross all 67 admissions, so the historical authority source is single and coherent. Nothing was changed to make this match; the value is read from the committed admissions.toDigest— recomputed by a from-scratch implementation of the canonical authority-v2 projection (identity, canonical outcome, family, module, topology, analyzer) over the frozen unrestricted measurement of 2544 identities — the same population the raw-v1 digest was taken over. Cross-checked against a second independent source (a raw-PIT aggregator built directly from the raw reports). It was never taken from YAML and treated as truth, and never supplied by a candidate.admissionSetDigest— reproduced from the exact 67 committed identities with the Step-2 contract (sorted, joined with a newline plus the trailing newline, SHA-256); equals the value pinned by the Step-2 test.fromBaseSha— M45's mint-time binding against the real post-merge base.authorizedBy/authorizedAtfields, so the certificate matches repository convention rather than inventing fields.reasoncarries the provenance as free text and states explicitly that no admission was upgraded, rewritten or re-minted.Verification
:build-logic:test --tests 'dev.tramai.build.quality.MutationAuthorityDigestCertificate*' --rerun-tasks— BUILD SUCCESSFUL:build-logic:canonicalProbeIntegrationTest --tests 'dev.tramai.build.quality.MutationPopulationAdmissionIntegrationTest' --rerun-tasks— BUILD SUCCESSFUL (the real authority-transport lane, run against the exact P1M base)spotlessKotlinCheck(ratchet-scoped to the P1M base) — BUILD SUCCESSFULverifyStaticAnalysis— BUILD SUCCESSFUL, no new findings, Detekt baseline unchangedverifyChangePolicy -PchangePolicyBase=64d05450…— PASSED, 1 changed file, no policy violationsNo rule, expectation, threshold, suppression, baseline or historical authority record was weakened or modified to obtain this result.
Reported limitation
The certificate loader is not yet wired to this ledger by any build task — that arrives with Step 3. So the ledger's load is validated here by an independent re-implementation of the loader's shape rules, not by the Kotlin loader itself. Per this task's non-goals, no test or rule was added to force that path early.
Scope boundaries honoured
Only
config/quality/mutation-authority-digest-certificates.ymlchanged. Untouched:mutation-population-admissions.ymland all 67 records, admission digests and metadata, mutation baselines and results, M34, M36, M37, M40-M44, M45-M47 implementation, the certificate type/loader/ceremony, classifications, evolution rules, runtime and production code, and the static-analysis baseline.Not in this PR (Step 3 or later)
Consumption, M40-M44, certificate-aware M34, the M47 consumption exception, task wiring/transport for certificates, the T1-T19 matrix, and P2. Also deferred deliberately: a
config/quality/AGENTS.mdfile-roles row for the new ledger, which would be a second changed path.Remaining risk
The 67 admissions remain bound to their raw-v1 digest and stay unconsumable under authority-v2 until Step 3 consumes this certificate. That is the intended ordering, and the point of the transition: the certificate now exists in the base, so Step 3 consumes authority that already existed rather than minting its own.