Skip to content

authority(0.7.1g1P2-P1M): mint the base-side raw-v1 -> authority-v2 migration certificate - #472

Merged
GionaGranchelli merged 1 commit into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1P2-p1m-certificate
Oct 2, 2026
Merged

GionaGranchelli merged 1 commit into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1P2-p1m-certificate

Conversation

@GionaGranchelli

Copy link
Copy Markdown
Owner

Base

64d05450c285ecd9cf3635ca2935da816f649856 — the exact post-#471 epic tip. Obtained from the merge record, not assumed, and not a provisional preview SHA.

P1M: the single isolated authority transition between Step 2 and Step 3. It establishes certificate authority. It does not consume it.

Required evidence

P1M base SHA: 64d05450c285ecd9cf3635ca2935da816f649856
candidate SHA: (this head)

changed paths:
  config/quality/mutation-authority-digest-certificates.yml

admission ledger:
  base SHA-256:      314b9c1853614f5cd013015e3c5c3841b15509482d021922cbc3ce8a67bb839e
  candidate SHA-256: 314b9c1853614f5cd013015e3c5c3841b15509482d021922cbc3ce8a67bb839e
  byte-identical: true

admission population:
  base count: 67   candidate count: 67
  added: 0   removed: 0   rewritten: 0

certificate ledger:
  base count: 0    candidate count: 1

certificate:
  fromAlgorithm:      raw-v1
  fromDigest:         9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0
  toAlgorithm:        authority-v2
  toDigest:           e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad
  admissionSetDigest: 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c
  fromBaseSha:        64d05450c285ecd9cf3635ca2935da816f649856

independent recomputation:
  raw-v1 source digest matches:       true
  authority-v2 target digest matches: true
  67-admission set digest matches:    true
  M45 exact-base binding matches:     true

Mechanical gate P1-P8: ALL PASS (eleven checks). No permanent generic rule was added for this migration.

How each value was sourced

  • fromDigest — the ledger carries exactly one distinct populationDigest across all 67 admissions, so the historical authority source is single and coherent. Nothing was changed to make this match; the value is read from the committed admissions.
  • toDigest — recomputed by a from-scratch implementation of the canonical authority-v2 projection (identity, canonical outcome, family, module, topology, analyzer) over the frozen unrestricted measurement of 2544 identities — the same population the raw-v1 digest was taken over. Cross-checked against a second independent source (a raw-PIT aggregator built directly from the raw reports). It was never taken from YAML and treated as truth, and never supplied by a candidate.
  • admissionSetDigest — reproduced from the exact 67 committed identities with the Step-2 contract (sorted, joined with a newline plus the trailing newline, SHA-256); equals the value pinned by the Step-2 test.
  • fromBaseSha — M45's mint-time binding against the real post-merge base.
  • Audit metadata omitted deliberately: the committed admission ledger has no authorizedBy/authorizedAt fields, so the certificate matches repository convention rather than inventing fields. reason carries the provenance as free text and states explicitly that no admission was upgraded, rewritten or re-minted.

Verification

  • :build-logic:test --tests 'dev.tramai.build.quality.MutationAuthorityDigestCertificate*' --rerun-tasks — BUILD SUCCESSFUL
  • :build-logic:canonicalProbeIntegrationTest --tests 'dev.tramai.build.quality.MutationPopulationAdmissionIntegrationTest' --rerun-tasks — BUILD SUCCESSFUL (the real authority-transport lane, run against the exact P1M base)
  • spotlessKotlinCheck (ratchet-scoped to the P1M base) — BUILD SUCCESSFUL
  • verifyStaticAnalysis — BUILD SUCCESSFUL, no new findings, Detekt baseline unchanged
  • verifyChangePolicy -PchangePolicyBase=64d05450… — PASSED, 1 changed file, no policy violations

No rule, expectation, threshold, suppression, baseline or historical authority record was weakened or modified to obtain this result.

Reported limitation

The certificate loader is not yet wired to this ledger by any build task — that arrives with Step 3. So the ledger's load is validated here by an independent re-implementation of the loader's shape rules, not by the Kotlin loader itself. Per this task's non-goals, no test or rule was added to force that path early.

Scope boundaries honoured

Only config/quality/mutation-authority-digest-certificates.yml changed. Untouched: mutation-population-admissions.yml and all 67 records, admission digests and metadata, mutation baselines and results, M34, M36, M37, M40-M44, M45-M47 implementation, the certificate type/loader/ceremony, classifications, evolution rules, runtime and production code, and the static-analysis baseline.

Not in this PR (Step 3 or later)

Consumption, M40-M44, certificate-aware M34, the M47 consumption exception, task wiring/transport for certificates, the T1-T19 matrix, and P2. Also deferred deliberately: a config/quality/AGENTS.md file-roles row for the new ledger, which would be a second changed path.

Remaining risk

The 67 admissions remain bound to their raw-v1 digest and stay unconsumable under authority-v2 until Step 3 consumes this certificate. That is the intended ordering, and the point of the transition: the certificate now exists in the base, so Step 3 consumes authority that already existed rather than minting its own.

…igration certificate

P1M: the single isolated transition between Step 2 and Step 3. It establishes certificate authority;
it does not consume it.

One certificate, derived from repository truth rather than chosen:

- fromAlgorithm raw-v1 / fromDigest 9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0
  This is the digest every one of the 67 committed P1 admissions is bound to. The ledger holds
  exactly one distinct populationDigest value across 67 admissions, so the historical authority
  source is coherent; nothing was changed to make it match.
- toAlgorithm authority-v2 / toDigest e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad
  Recomputed independently over the frozen unrestricted measurement (2544 identities, the population
  the raw-v1 digest was taken over) from the canonical authority projection semantics: identity,
  canonical outcome, family, module, topology, analyzer. The same value was byte-identical across all
  four preserved campaigns. It is not copied from any candidate.
- admissionSetDigest 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c
  Reproduced from the exact 67 committed identities using the Step-2 contract (sorted, joined with a
  newline plus the trailing newline, SHA-256). It equals the value pinned by the Step-2 test.
- fromBaseSha 64d0545 - the exact post-#471 epic tip, so M45's
  mint-time binding is against the real authority base and not a provisional preview SHA.
- reason records the migration without implying any historical admission was upgraded or rewritten.

The certificate ledger is the only changed path. The 67 admissions are byte-identical: no admission
was modified, no digest rewritten, no metadata touched, and no mutation authority was re-measured.

Ordering this preserves: a candidate may only consume migration authority that already existed in
its base. A later transition (Step 3) consumes this certificate; P1M minting and consuming its own
authority in one transition is exactly what the M43 analogue forbids.

Mechanical gate P1-P8 (changed-path isolation, admission byte identity, semantic population
identity, certificate cardinality, M45 binding, bounded admission set, source binding, independent
target recomputation) is recorded in the pull request. No permanent rule was added for this
migration, and no gate, threshold, suppression or baseline was weakened.
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:28

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

This is a trust-critical governance authority artifact whose central toDigest authority-v2 projection and base-SHA binding cannot be independently re-derived in this environment and require human verification before merge.

Review effort: Balanced
Findings: None

What changed in this PR

This PR mints the single base-side authority artifact for the P1M transition in the 0.7.1g1P2 authority-model reconciliation: it adds one digest-migration certificate to a new ledger, config/quality/mutation-authority-digest-certificates.yml. The certificate records, in base authority, that the raw-v1 whole-population authority digest of the 67 P1 admissions is semantically equal to its authority-v2 projection, without rewriting any historical admission. It consumes the machinery introduced in #471 (certificate type, loader, and M45–M47 ceremony) and leaves actual consumption to Step 3.

Changes:

  • Adds a new YAML ledger containing exactly one certificate (raw-v1 → authority-v2) with fromDigest, toDigest, admissionSetDigest, fromBaseSha, and a provenance reason.
  • Binds the certificate to the 67 committed admissions via admissionSetDigest and to the post-#471 base via fromBaseSha, per the M42/M45 contracts.
  • Touches no other file: the 67 admissions, baselines, loader/ceremony code, and static-analysis baseline are unchanged.
File Description
config/​quality/​mutation-authority-digest-certificates.yml New single-entry certificate ledger establishing the raw-v1 → authority-v2 digest-migration authority for the P1M transition.

Verification performed during review:

  • All field formats satisfy the loader's regexes (fromDigest/toDigest/admissionSetDigest are 64-hex; fromBaseSha is 40-hex), algorithms are both in the allowed set and distinct, reason is non-blank, and schemaVersion: "1" matches; the file parses cleanly.
  • The pinned admissionSetDigest (98a9587a…) reproduces the sorted-identities-with-trailing-newline SHA-256 over the committed 67 admissions.
  • fromDigest (9aebd320…) equals the single distinct populationDigest across all 67 admissions, consistent with M41's later expectation.
  • The declared fromBaseSha matches the M45 base-binding the ceremony enforces.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@GionaGranchelli
GionaGranchelli merged commit 9ebe7b4 into epic/0.7.1-control-plane-authority Oct 2, 2026
19 checks passed
GionaGranchelli added a commit that referenced this pull request Oct 2, 2026
…igration certificate (#472)

P1M: the single isolated transition between Step 2 and Step 3. It establishes certificate authority;
it does not consume it.

One certificate, derived from repository truth rather than chosen:

- fromAlgorithm raw-v1 / fromDigest 9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0
  This is the digest every one of the 67 committed P1 admissions is bound to. The ledger holds
  exactly one distinct populationDigest value across 67 admissions, so the historical authority
  source is coherent; nothing was changed to make it match.
- toAlgorithm authority-v2 / toDigest e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad
  Recomputed independently over the frozen unrestricted measurement (2544 identities, the population
  the raw-v1 digest was taken over) from the canonical authority projection semantics: identity,
  canonical outcome, family, module, topology, analyzer. The same value was byte-identical across all
  four preserved campaigns. It is not copied from any candidate.
- admissionSetDigest 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c
  Reproduced from the exact 67 committed identities using the Step-2 contract (sorted, joined with a
  newline plus the trailing newline, SHA-256). It equals the value pinned by the Step-2 test.
- fromBaseSha 64d0545 - the exact post-#471 epic tip, so M45's
  mint-time binding is against the real authority base and not a provisional preview SHA.
- reason records the migration without implying any historical admission was upgraded or rewritten.

The certificate ledger is the only changed path. The 67 admissions are byte-identical: no admission
was modified, no digest rewritten, no metadata touched, and no mutation authority was re-measured.

Ordering this preserves: a candidate may only consume migration authority that already existed in
its base. A later transition (Step 3) consumes this certificate; P1M minting and consuming its own
authority in one transition is exactly what the M43 analogue forbids.

Mechanical gate P1-P8 (changed-path isolation, admission byte identity, semantic population
identity, certificate cardinality, M45 binding, bounded admission set, source binding, independent
target recomputation) is recorded in the pull request. No permanent rule was added for this
migration, and no gate, threshold, suppression or baseline was weakened.
GionaGranchelli added a commit that referenced this pull request Oct 2, 2026
…igration certificate (#472)

P1M: the single isolated transition between Step 2 and Step 3. It establishes certificate authority;
it does not consume it.

One certificate, derived from repository truth rather than chosen:

- fromAlgorithm raw-v1 / fromDigest 9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0
  This is the digest every one of the 67 committed P1 admissions is bound to. The ledger holds
  exactly one distinct populationDigest value across 67 admissions, so the historical authority
  source is coherent; nothing was changed to make it match.
- toAlgorithm authority-v2 / toDigest e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad
  Recomputed independently over the frozen unrestricted measurement (2544 identities, the population
  the raw-v1 digest was taken over) from the canonical authority projection semantics: identity,
  canonical outcome, family, module, topology, analyzer. The same value was byte-identical across all
  four preserved campaigns. It is not copied from any candidate.
- admissionSetDigest 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c
  Reproduced from the exact 67 committed identities using the Step-2 contract (sorted, joined with a
  newline plus the trailing newline, SHA-256). It equals the value pinned by the Step-2 test.
- fromBaseSha 64d0545 - the exact post-#471 epic tip, so M45's
  mint-time binding is against the real authority base and not a provisional preview SHA.
- reason records the migration without implying any historical admission was upgraded or rewritten.

The certificate ledger is the only changed path. The 67 admissions are byte-identical: no admission
was modified, no digest rewritten, no metadata touched, and no mutation authority was re-measured.

Ordering this preserves: a candidate may only consume migration authority that already existed in
its base. A later transition (Step 3) consumes this certificate; P1M minting and consuming its own
authority in one transition is exactly what the M43 analogue forbids.

Mechanical gate P1-P8 (changed-path isolation, admission byte identity, semantic population
identity, certificate cardinality, M45 binding, bounded admission set, source binding, independent
target recomputation) is recorded in the pull request. No permanent rule was added for this
migration, and no gate, threshold, suppression or baseline was weakened.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants