From ac2b3b13d04b7e25ee69111ee890214d5e708797 Mon Sep 17 00:00:00 2001 From: gionag Date: Fri, 2 Oct 2026 00:26:06 +0200 Subject: [PATCH] authority(0.7.1g1P2-P1M): mint the base-side raw-v1 -> authority-v2 migration certificate P1M: the single isolated transition between Step 2 and Step 3. It establishes certificate authority; it does not consume it. One certificate, derived from repository truth rather than chosen: - fromAlgorithm raw-v1 / fromDigest 9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0 This is the digest every one of the 67 committed P1 admissions is bound to. The ledger holds exactly one distinct populationDigest value across 67 admissions, so the historical authority source is coherent; nothing was changed to make it match. - toAlgorithm authority-v2 / toDigest e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad Recomputed independently over the frozen unrestricted measurement (2544 identities, the population the raw-v1 digest was taken over) from the canonical authority projection semantics: identity, canonical outcome, family, module, topology, analyzer. The same value was byte-identical across all four preserved campaigns. It is not copied from any candidate. - admissionSetDigest 98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c Reproduced from the exact 67 committed identities using the Step-2 contract (sorted, joined with a newline plus the trailing newline, SHA-256). It equals the value pinned by the Step-2 test. - fromBaseSha 64d05450c285ecd9cf3635ca2935da816f649856 - the exact post-#471 epic tip, so M45's mint-time binding is against the real authority base and not a provisional preview SHA. - reason records the migration without implying any historical admission was upgraded or rewritten. The certificate ledger is the only changed path. The 67 admissions are byte-identical: no admission was modified, no digest rewritten, no metadata touched, and no mutation authority was re-measured. Ordering this preserves: a candidate may only consume migration authority that already existed in its base. A later transition (Step 3) consumes this certificate; P1M minting and consuming its own authority in one transition is exactly what the M43 analogue forbids. Mechanical gate P1-P8 (changed-path isolation, admission byte identity, semantic population identity, certificate cardinality, M45 binding, bounded admission set, source binding, independent target recomputation) is recorded in the pull request. No permanent rule was added for this migration, and no gate, threshold, suppression or baseline was weakened. --- ...mutation-authority-digest-certificates.yml | 31 +++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 config/quality/mutation-authority-digest-certificates.yml diff --git a/config/quality/mutation-authority-digest-certificates.yml b/config/quality/mutation-authority-digest-certificates.yml new file mode 100644 index 00000000..07afeb81 --- /dev/null +++ b/config/quality/mutation-authority-digest-certificates.yml @@ -0,0 +1,31 @@ +# Digest-migration certificate ledger (0.7.1g1P2, M40-M47). +# +# Base-side authority: a certificate here records that one exact raw whole-population authority +# digest is semantically equal to one exact authority-projections digest, for one exact bounded set +# of population admissions. It exists so a semantic upgrade of the authority digest never requires +# rewriting historical authority (M36 stays literally unchanged). +# +# Lifecycle: mint against the exact base (M45) -> retain byte-identically (M46) -> consume only from +# base (M43 + M42 + M41 + M40) -> remove in the valid consuming transition (M44 + M47). Rules live in +# MutationAuthorityDigestCertificateCeremony; this file carries only the certificate itself. +# +# The certificate below is minted by the P1M transition and changes nothing else: the 67 P1 +# population admissions remain byte-identical and keep their historical raw-v1 digest. +schemaVersion: "1" + +certificates: + - fromAlgorithm: "raw-v1" + fromDigest: "9aebd3202288c82ff006f2db33c95cac0772746fa3c3061569167cd3f45df9b0" + toAlgorithm: "authority-v2" + toDigest: "e6ad01dc1d2966894a6555304bc8ca9a04c8174e3c83ae88760fcfebf1464dad" + admissionSetDigest: "98a9587a1068ec0cd7158a05ba6909c61c522308c272e7fa9cb27d5edd93a79c" + fromBaseSha: "64d05450c285ecd9cf3635ca2935da816f649856" + reason: >- + Bounds the semantic migration of the P1 whole-population authority digest from raw-v1 to + authority-v2, per C7: raw PIT status is diagnostic evidence and not authority. The 67 P1 + population admissions are unchanged and remain bound to their historical raw-v1 digest + (fromDigest); this certificate states that the same frozen unrestricted measurement, whose + canonical authority-v2 projection was byte-identical across all four preserved campaigns, + projects to toDigest. It authorizes a later transition to consume that pre-existing + population-context authority; it does not upgrade, rewrite, re-mint or re-adjudicate any + admission, and it changes no mutation outcome.