From 1ac7d34a3ee6e7eefb9d4ad8fc24d5ecd297ad83 Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sun, 27 Sep 2026 19:22:52 +0200 Subject: [PATCH 1/8] feat(formal): add independent participant crossing models --- .../invalid/incomplete-crossing-domain.json | 123 ++++ .../invalid/overlapping-crossing-labels.json | 124 ++++ .../invalid/shared-crossing-authority.json | 124 ++++ .../valid/participant-crossing.json | 124 ++++ .../participant-crossing-dpbb-finite-v1.json | 124 ++++ .../behavioral-relation-profile-v1.json | 6 +- .../behavioral-relation-profile-v1.json | 553 +++++++++++++++++- ...r-100-participant-crossing-bisimulation.md | 31 +- docs/decisions/adrs/adr-index.yaml | 6 +- ...1-participant-crossing-models-preflight.md | 201 +++++++ docs/requirements/API-423/requirement.md | 8 + docs/requirements/RUN-319/requirement.md | 8 + docs/requirements/SEM-230/requirement.md | 8 + docs/requirements/SEM-232/requirement.md | 14 + .../candidate-comparison.md | 3 + .../current-state-assessment.md | 3 + .../implementation-program.json | 14 +- .../participant-bisimulation/index.md | 2 + .../model-construction.md | 102 ++++ .../theorem-selection.md | 16 +- .../formal/participant_crossing/__init__.py | 1 + .../formal/participant_crossing/__main__.py | 31 + .../formal/participant_crossing/abstract.py | 148 +++++ .../formal/participant_crossing/aut.py | 61 ++ .../formal/participant_crossing/concrete.py | 176 ++++++ .../formal/participant_crossing/export.py | 235 ++++++++ .../formal/participant_crossing/graph.py | 10 + .../formal/participant_crossing/ingress.py | 57 ++ .../_behavioral_profile_loader.py | 113 ++++ .../_participant_crossing_profile.py | 153 +++++ .../behavioral_relation_profiles.py | 142 ++--- .../raes_contracts/behavioral_relations.py | 6 + .../_model_check_admission.py | 3 + .../participant_opacity/_service.py | 3 + .../python/tests/crossing_model_fixtures.py | 88 +++ .../tests/test_issue_971_crossing_export.py | 176 ++++++ .../tests/test_issue_971_crossing_models.py | 105 ++++ .../tests/test_issue_971_crossing_profile.py | 202 +++++++ .../crossing-models/rev2/abstract.aut | 108 ++++ .../crossing-models/rev2/abstract.json | 1 + .../crossing-models/rev2/concrete.aut | 198 +++++++ .../crossing-models/rev2/concrete.json | 1 + .../crossing-models/rev2/manifest.json | 1 + .../participant-crossing-bisimulation.md | 12 +- .../participant-crossing-models.md | 132 +++++ 45 files changed, 3631 insertions(+), 126 deletions(-) create mode 100644 contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/incomplete-crossing-domain.json create mode 100644 contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/overlapping-crossing-labels.json create mode 100644 contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/shared-crossing-authority.json create mode 100644 contracts/fixtures/profiles/behavioral-relation-profile-v1/valid/participant-crossing.json create mode 100644 contracts/profiles/behavioral-relation/participant-crossing-dpbb-finite-v1.json create mode 100644 docs/decisions/issue-971-participant-crossing-models-preflight.md create mode 100644 docs/research/participant-bisimulation/model-construction.md create mode 100644 implementations/formal/participant_crossing/__init__.py create mode 100644 implementations/formal/participant_crossing/__main__.py create mode 100644 implementations/formal/participant_crossing/abstract.py create mode 100644 implementations/formal/participant_crossing/aut.py create mode 100644 implementations/formal/participant_crossing/concrete.py create mode 100644 implementations/formal/participant_crossing/export.py create mode 100644 implementations/formal/participant_crossing/graph.py create mode 100644 implementations/formal/participant_crossing/ingress.py create mode 100644 implementations/python/packages/raes_contracts/_behavioral_profile_loader.py create mode 100644 implementations/python/packages/raes_contracts/_participant_crossing_profile.py create mode 100644 implementations/python/tests/crossing_model_fixtures.py create mode 100644 implementations/python/tests/test_issue_971_crossing_export.py create mode 100644 implementations/python/tests/test_issue_971_crossing_models.py create mode 100644 implementations/python/tests/test_issue_971_crossing_profile.py create mode 100644 specs/formal/participant-semantics/crossing-models/rev2/abstract.aut create mode 100644 specs/formal/participant-semantics/crossing-models/rev2/abstract.json create mode 100644 specs/formal/participant-semantics/crossing-models/rev2/concrete.aut create mode 100644 specs/formal/participant-semantics/crossing-models/rev2/concrete.json create mode 100644 specs/formal/participant-semantics/crossing-models/rev2/manifest.json create mode 100644 specs/formal/participant-semantics/participant-crossing-models.md diff --git a/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/incomplete-crossing-domain.json b/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/incomplete-crossing-domain.json new file mode 100644 index 000000000..16177d1a0 --- /dev/null +++ b/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/incomplete-crossing-domain.json @@ -0,0 +1,123 @@ +{ + "schema_version": "behavioral-relation-profile/v1", + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_id": "raes-behavioral-relations", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": "sem-230-participant-crossing-abstract", + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + "parameters": { + "kind": "participant-crossing-dpbb/v1", + "domains": { + "participant": [ + "participant-0" + ], + "audience": [ + "audience-0" + ], + "controller": [ + "controller-0" + ], + "episode": [ + "episode-0" + ], + "request_id": [ + "request-0" + ], + "policy_cut": [ + "p0", + "p1" + ], + "input_class": [ + "plain", + "transform", + "declassify", + "unsupported" + ], + "decision": [ + "none", + "permit", + "deny", + "unsupported", + "transform", + "declassify" + ], + "replay": [ + "fresh", + "same-cut", + "later-cut" + ], + "delivery": [ + "none", + "pending", + "delivered", + "withheld" + ], + "history_head": [ + "h0", + "h1", + "h2", + "h3" + ] + }, + "left": { + "model_id": "sem-230-participant-crossing-abstract", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/abstract.py", + "source_digest": "sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531", + "initial_state_ordinal": 0 + }, + "right": { + "model_id": "api-423-run-319-crossing-kernel", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/concrete.py", + "source_digest": "sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5", + "initial_state_ordinal": 0 + }, + "visible_labels": [ + "crossing.request", + "crossing.decision.permit", + "crossing.decision.deny", + "crossing.decision.unsupported", + "crossing.transform", + "crossing.declassify", + "crossing.delivery", + "crossing.observation", + "crossing.replay.reject", + "policy.cut.advance" + ], + "hidden_labels": [ + "internal.validate", + "internal.resolve-policy-cut", + "internal.resolve-capability", + "internal.prepare-record", + "internal.atomic-commit" + ], + "checker_tau": "internal", + "complete_carrier": true, + "depth_or_sample_bound": null, + "fresh_operations": 1, + "identity_reuse": "excluded", + "order": "sequential-total-order", + "time": "untimed", + "probability": "excluded", + "concurrency": "excluded", + "controller_handoff": "excluded", + "completion": "per-crossing-visible-outcome" + }, + "source_refs": [ + { + "source_ref": "specs/formal/participant-semantics/participant-crossing-models.md", + "source_digest": "sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29" + } + ], + "limitations": [ + "One fresh operation and retries; no identity recycling." + ], + "explicit_non_claims": [ + "No equivalence or live-runtime result is established by construction." + ] +} diff --git a/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/overlapping-crossing-labels.json b/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/overlapping-crossing-labels.json new file mode 100644 index 000000000..01941d694 --- /dev/null +++ b/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/overlapping-crossing-labels.json @@ -0,0 +1,124 @@ +{ + "schema_version": "behavioral-relation-profile/v1", + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_id": "raes-behavioral-relations", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": "sem-230-participant-crossing-abstract", + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + "parameters": { + "kind": "participant-crossing-dpbb/v1", + "domains": { + "participant": [ + "participant-0" + ], + "audience": [ + "audience-0" + ], + "controller": [ + "controller-0" + ], + "episode": [ + "episode-0" + ], + "request_id": [ + "request-0" + ], + "policy_cut": [ + "p0", + "p1" + ], + "input_class": [ + "plain", + "transform", + "declassify", + "unsupported", + "forbidden" + ], + "decision": [ + "none", + "permit", + "deny", + "unsupported", + "transform", + "declassify" + ], + "replay": [ + "fresh", + "same-cut", + "later-cut" + ], + "delivery": [ + "none", + "pending", + "delivered", + "withheld" + ], + "history_head": [ + "h0", + "h1", + "h2", + "h3" + ] + }, + "left": { + "model_id": "sem-230-participant-crossing-abstract", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/abstract.py", + "source_digest": "sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531", + "initial_state_ordinal": 0 + }, + "right": { + "model_id": "api-423-run-319-crossing-kernel", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/concrete.py", + "source_digest": "sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5", + "initial_state_ordinal": 0 + }, + "visible_labels": [ + "crossing.request", + "crossing.decision.permit", + "crossing.decision.deny", + "crossing.decision.unsupported", + "crossing.transform", + "crossing.declassify", + "crossing.delivery", + "crossing.observation", + "crossing.replay.reject", + "policy.cut.advance" + ], + "hidden_labels": [ + "crossing.request", + "internal.resolve-policy-cut", + "internal.resolve-capability", + "internal.prepare-record", + "internal.atomic-commit" + ], + "checker_tau": "internal", + "complete_carrier": true, + "depth_or_sample_bound": null, + "fresh_operations": 1, + "identity_reuse": "excluded", + "order": "sequential-total-order", + "time": "untimed", + "probability": "excluded", + "concurrency": "excluded", + "controller_handoff": "excluded", + "completion": "per-crossing-visible-outcome" + }, + "source_refs": [ + { + "source_ref": "specs/formal/participant-semantics/participant-crossing-models.md", + "source_digest": "sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29" + } + ], + "limitations": [ + "One fresh operation and retries; no identity recycling." + ], + "explicit_non_claims": [ + "No equivalence or live-runtime result is established by construction." + ] +} diff --git a/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/shared-crossing-authority.json b/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/shared-crossing-authority.json new file mode 100644 index 000000000..d2dd8d6ad --- /dev/null +++ b/contracts/fixtures/profiles/behavioral-relation-profile-v1/invalid/shared-crossing-authority.json @@ -0,0 +1,124 @@ +{ + "schema_version": "behavioral-relation-profile/v1", + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_id": "raes-behavioral-relations", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": "sem-230-participant-crossing-abstract", + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + "parameters": { + "kind": "participant-crossing-dpbb/v1", + "domains": { + "participant": [ + "participant-0" + ], + "audience": [ + "audience-0" + ], + "controller": [ + "controller-0" + ], + "episode": [ + "episode-0" + ], + "request_id": [ + "request-0" + ], + "policy_cut": [ + "p0", + "p1" + ], + "input_class": [ + "plain", + "transform", + "declassify", + "unsupported", + "forbidden" + ], + "decision": [ + "none", + "permit", + "deny", + "unsupported", + "transform", + "declassify" + ], + "replay": [ + "fresh", + "same-cut", + "later-cut" + ], + "delivery": [ + "none", + "pending", + "delivered", + "withheld" + ], + "history_head": [ + "h0", + "h1", + "h2", + "h3" + ] + }, + "left": { + "model_id": "sem-230-participant-crossing-abstract", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/abstract.py", + "source_digest": "sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531", + "initial_state_ordinal": 0 + }, + "right": { + "model_id": "sem-230-participant-crossing-abstract", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/abstract.py", + "source_digest": "sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531", + "initial_state_ordinal": 0 + }, + "visible_labels": [ + "crossing.request", + "crossing.decision.permit", + "crossing.decision.deny", + "crossing.decision.unsupported", + "crossing.transform", + "crossing.declassify", + "crossing.delivery", + "crossing.observation", + "crossing.replay.reject", + "policy.cut.advance" + ], + "hidden_labels": [ + "internal.validate", + "internal.resolve-policy-cut", + "internal.resolve-capability", + "internal.prepare-record", + "internal.atomic-commit" + ], + "checker_tau": "internal", + "complete_carrier": true, + "depth_or_sample_bound": null, + "fresh_operations": 1, + "identity_reuse": "excluded", + "order": "sequential-total-order", + "time": "untimed", + "probability": "excluded", + "concurrency": "excluded", + "controller_handoff": "excluded", + "completion": "per-crossing-visible-outcome" + }, + "source_refs": [ + { + "source_ref": "specs/formal/participant-semantics/participant-crossing-models.md", + "source_digest": "sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29" + } + ], + "limitations": [ + "One fresh operation and retries; no identity recycling." + ], + "explicit_non_claims": [ + "No equivalence or live-runtime result is established by construction." + ] +} diff --git a/contracts/fixtures/profiles/behavioral-relation-profile-v1/valid/participant-crossing.json b/contracts/fixtures/profiles/behavioral-relation-profile-v1/valid/participant-crossing.json new file mode 100644 index 000000000..fca39a19c --- /dev/null +++ b/contracts/fixtures/profiles/behavioral-relation-profile-v1/valid/participant-crossing.json @@ -0,0 +1,124 @@ +{ + "schema_version": "behavioral-relation-profile/v1", + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_id": "raes-behavioral-relations", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": "sem-230-participant-crossing-abstract", + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + "parameters": { + "kind": "participant-crossing-dpbb/v1", + "domains": { + "participant": [ + "participant-0" + ], + "audience": [ + "audience-0" + ], + "controller": [ + "controller-0" + ], + "episode": [ + "episode-0" + ], + "request_id": [ + "request-0" + ], + "policy_cut": [ + "p0", + "p1" + ], + "input_class": [ + "plain", + "transform", + "declassify", + "unsupported", + "forbidden" + ], + "decision": [ + "none", + "permit", + "deny", + "unsupported", + "transform", + "declassify" + ], + "replay": [ + "fresh", + "same-cut", + "later-cut" + ], + "delivery": [ + "none", + "pending", + "delivered", + "withheld" + ], + "history_head": [ + "h0", + "h1", + "h2", + "h3" + ] + }, + "left": { + "model_id": "sem-230-participant-crossing-abstract", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/abstract.py", + "source_digest": "sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531", + "initial_state_ordinal": 0 + }, + "right": { + "model_id": "api-423-run-319-crossing-kernel", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/concrete.py", + "source_digest": "sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5", + "initial_state_ordinal": 0 + }, + "visible_labels": [ + "crossing.request", + "crossing.decision.permit", + "crossing.decision.deny", + "crossing.decision.unsupported", + "crossing.transform", + "crossing.declassify", + "crossing.delivery", + "crossing.observation", + "crossing.replay.reject", + "policy.cut.advance" + ], + "hidden_labels": [ + "internal.validate", + "internal.resolve-policy-cut", + "internal.resolve-capability", + "internal.prepare-record", + "internal.atomic-commit" + ], + "checker_tau": "internal", + "complete_carrier": true, + "depth_or_sample_bound": null, + "fresh_operations": 1, + "identity_reuse": "excluded", + "order": "sequential-total-order", + "time": "untimed", + "probability": "excluded", + "concurrency": "excluded", + "controller_handoff": "excluded", + "completion": "per-crossing-visible-outcome" + }, + "source_refs": [ + { + "source_ref": "specs/formal/participant-semantics/participant-crossing-models.md", + "source_digest": "sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29" + } + ], + "limitations": [ + "One fresh operation and retries; no identity recycling." + ], + "explicit_non_claims": [ + "No equivalence or live-runtime result is established by construction." + ] +} diff --git a/contracts/profiles/behavioral-relation/participant-crossing-dpbb-finite-v1.json b/contracts/profiles/behavioral-relation/participant-crossing-dpbb-finite-v1.json new file mode 100644 index 000000000..fca39a19c --- /dev/null +++ b/contracts/profiles/behavioral-relation/participant-crossing-dpbb-finite-v1.json @@ -0,0 +1,124 @@ +{ + "schema_version": "behavioral-relation-profile/v1", + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_id": "raes-behavioral-relations", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": "sem-230-participant-crossing-abstract", + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + "parameters": { + "kind": "participant-crossing-dpbb/v1", + "domains": { + "participant": [ + "participant-0" + ], + "audience": [ + "audience-0" + ], + "controller": [ + "controller-0" + ], + "episode": [ + "episode-0" + ], + "request_id": [ + "request-0" + ], + "policy_cut": [ + "p0", + "p1" + ], + "input_class": [ + "plain", + "transform", + "declassify", + "unsupported", + "forbidden" + ], + "decision": [ + "none", + "permit", + "deny", + "unsupported", + "transform", + "declassify" + ], + "replay": [ + "fresh", + "same-cut", + "later-cut" + ], + "delivery": [ + "none", + "pending", + "delivered", + "withheld" + ], + "history_head": [ + "h0", + "h1", + "h2", + "h3" + ] + }, + "left": { + "model_id": "sem-230-participant-crossing-abstract", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/abstract.py", + "source_digest": "sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531", + "initial_state_ordinal": 0 + }, + "right": { + "model_id": "api-423-run-319-crossing-kernel", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/concrete.py", + "source_digest": "sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5", + "initial_state_ordinal": 0 + }, + "visible_labels": [ + "crossing.request", + "crossing.decision.permit", + "crossing.decision.deny", + "crossing.decision.unsupported", + "crossing.transform", + "crossing.declassify", + "crossing.delivery", + "crossing.observation", + "crossing.replay.reject", + "policy.cut.advance" + ], + "hidden_labels": [ + "internal.validate", + "internal.resolve-policy-cut", + "internal.resolve-capability", + "internal.prepare-record", + "internal.atomic-commit" + ], + "checker_tau": "internal", + "complete_carrier": true, + "depth_or_sample_bound": null, + "fresh_operations": 1, + "identity_reuse": "excluded", + "order": "sequential-total-order", + "time": "untimed", + "probability": "excluded", + "concurrency": "excluded", + "controller_handoff": "excluded", + "completion": "per-crossing-visible-outcome" + }, + "source_refs": [ + { + "source_ref": "specs/formal/participant-semantics/participant-crossing-models.md", + "source_digest": "sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29" + } + ], + "limitations": [ + "One fresh operation and retries; no identity recycling." + ], + "explicit_non_claims": [ + "No equivalence or live-runtime result is established by construction." + ] +} diff --git a/contracts/schema-publication/entries/behavioral-relation-profile-v1.json b/contracts/schema-publication/entries/behavioral-relation-profile-v1.json index d7948d417..fb85520bf 100644 --- a/contracts/schema-publication/entries/behavioral-relation-profile-v1.json +++ b/contracts/schema-publication/entries/behavioral-relation-profile-v1.json @@ -2,9 +2,9 @@ "contract_id": "behavioral-relation-profile-v1", "schema_path": "contracts/schemas/profiles/behavioral-relation-profile-v1.json", "stability": "draft", - "content_hash": "b718945e218c75749b7377902e67854ea01c23d4e52e89e504b4c3d4b2d1e4d1", + "content_hash": "a1cfddabde6cb363e4514808b31110631a4e147bd9e83fe262f4a9763dcd5aa1", "last_change": { - "summary": "Added the abstract theorem-carrier variant, encoded carrier joins, and rebound the schema namespace to OpenRAE for issue #963.", - "content_hash": "b718945e218c75749b7377902e67854ea01c23d4e52e89e504b4c3d4b2d1e4d1" + "summary": "Add the closed single-operation DPBB profile variant, complete domains and both carrier identities; preserve opacity profiles (issue #971).", + "content_hash": "a1cfddabde6cb363e4514808b31110631a4e147bd9e83fe262f4a9763dcd5aa1" } } diff --git a/contracts/schemas/profiles/behavioral-relation-profile-v1.json b/contracts/schemas/profiles/behavioral-relation-profile-v1.json index e923bd1e6..c3369c1fc 100644 --- a/contracts/schemas/profiles/behavioral-relation-profile-v1.json +++ b/contracts/schemas/profiles/behavioral-relation-profile-v1.json @@ -1,5 +1,46 @@ { "$defs": { + "AbstractCrossingCarrierModel": { + "additionalProperties": false, + "properties": { + "initial_state_ordinal": { + "maximum": 0, + "minimum": 0, + "title": "Initial State Ordinal", + "type": "integer" + }, + "model_id": { + "const": "sem-230-participant-crossing-abstract", + "title": "Model Id", + "type": "string" + }, + "revision": { + "const": "rev2", + "title": "Revision", + "type": "string" + }, + "source_digest": { + "minLength": 1, + "pattern": "^(?:sha256:[A-Fa-f0-9]{64}|sha384:[A-Fa-f0-9]{96}|sha512:[A-Fa-f0-9]{128}|blake3:[A-Fa-f0-9]{64})$", + "title": "Source Digest", + "type": "string" + }, + "source_path": { + "const": "implementations/formal/participant_crossing/abstract.py", + "title": "Source Path", + "type": "string" + } + }, + "required": [ + "model_id", + "revision", + "source_path", + "source_digest", + "initial_state_ordinal" + ], + "title": "AbstractCrossingCarrierModel", + "type": "object" + }, "AbstractOpacityCarrierModel": { "additionalProperties": false, "description": "An abstract carrier whose proof obligations are discharged by a theorem session.", @@ -158,6 +199,271 @@ "title": "CoalitionOpacityObserverModel", "type": "object" }, + "ConcreteCrossingCarrierModel": { + "additionalProperties": false, + "properties": { + "initial_state_ordinal": { + "maximum": 0, + "minimum": 0, + "title": "Initial State Ordinal", + "type": "integer" + }, + "model_id": { + "const": "api-423-run-319-crossing-kernel", + "title": "Model Id", + "type": "string" + }, + "revision": { + "const": "rev2", + "title": "Revision", + "type": "string" + }, + "source_digest": { + "minLength": 1, + "pattern": "^(?:sha256:[A-Fa-f0-9]{64}|sha384:[A-Fa-f0-9]{96}|sha512:[A-Fa-f0-9]{128}|blake3:[A-Fa-f0-9]{64})$", + "title": "Source Digest", + "type": "string" + }, + "source_path": { + "const": "implementations/formal/participant_crossing/concrete.py", + "title": "Source Path", + "type": "string" + } + }, + "required": [ + "model_id", + "revision", + "source_path", + "source_digest", + "initial_state_ordinal" + ], + "title": "ConcreteCrossingCarrierModel", + "type": "object" + }, + "CrossingDomainsModel": { + "additionalProperties": false, + "properties": { + "audience": { + "maxItems": 1, + "minItems": 1, + "prefixItems": [ + { + "const": "audience-0", + "type": "string" + } + ], + "title": "Audience", + "type": "array" + }, + "controller": { + "maxItems": 1, + "minItems": 1, + "prefixItems": [ + { + "const": "controller-0", + "type": "string" + } + ], + "title": "Controller", + "type": "array" + }, + "decision": { + "maxItems": 6, + "minItems": 6, + "prefixItems": [ + { + "const": "none", + "type": "string" + }, + { + "const": "permit", + "type": "string" + }, + { + "const": "deny", + "type": "string" + }, + { + "const": "unsupported", + "type": "string" + }, + { + "const": "transform", + "type": "string" + }, + { + "const": "declassify", + "type": "string" + } + ], + "title": "Decision", + "type": "array" + }, + "delivery": { + "maxItems": 4, + "minItems": 4, + "prefixItems": [ + { + "const": "none", + "type": "string" + }, + { + "const": "pending", + "type": "string" + }, + { + "const": "delivered", + "type": "string" + }, + { + "const": "withheld", + "type": "string" + } + ], + "title": "Delivery", + "type": "array" + }, + "episode": { + "maxItems": 1, + "minItems": 1, + "prefixItems": [ + { + "const": "episode-0", + "type": "string" + } + ], + "title": "Episode", + "type": "array" + }, + "history_head": { + "maxItems": 4, + "minItems": 4, + "prefixItems": [ + { + "const": "h0", + "type": "string" + }, + { + "const": "h1", + "type": "string" + }, + { + "const": "h2", + "type": "string" + }, + { + "const": "h3", + "type": "string" + } + ], + "title": "History Head", + "type": "array" + }, + "input_class": { + "maxItems": 5, + "minItems": 5, + "prefixItems": [ + { + "const": "plain", + "type": "string" + }, + { + "const": "transform", + "type": "string" + }, + { + "const": "declassify", + "type": "string" + }, + { + "const": "unsupported", + "type": "string" + }, + { + "const": "forbidden", + "type": "string" + } + ], + "title": "Input Class", + "type": "array" + }, + "participant": { + "maxItems": 1, + "minItems": 1, + "prefixItems": [ + { + "const": "participant-0", + "type": "string" + } + ], + "title": "Participant", + "type": "array" + }, + "policy_cut": { + "maxItems": 2, + "minItems": 2, + "prefixItems": [ + { + "const": "p0", + "type": "string" + }, + { + "const": "p1", + "type": "string" + } + ], + "title": "Policy Cut", + "type": "array" + }, + "replay": { + "maxItems": 3, + "minItems": 3, + "prefixItems": [ + { + "const": "fresh", + "type": "string" + }, + { + "const": "same-cut", + "type": "string" + }, + { + "const": "later-cut", + "type": "string" + } + ], + "title": "Replay", + "type": "array" + }, + "request_id": { + "maxItems": 1, + "minItems": 1, + "prefixItems": [ + { + "const": "request-0", + "type": "string" + } + ], + "title": "Request Id", + "type": "array" + } + }, + "required": [ + "participant", + "audience", + "controller", + "episode", + "request_id", + "policy_cut", + "input_class", + "decision", + "replay", + "delivery", + "history_head" + ], + "title": "CrossingDomainsModel", + "type": "object" + }, "FiniteOpacityCarrierModel": { "additionalProperties": false, "properties": { @@ -606,6 +912,177 @@ "title": "OpacityTimeModel", "type": "object" }, + "ParticipantCrossingParametersModel": { + "additionalProperties": false, + "properties": { + "checker_tau": { + "const": "internal", + "title": "Checker Tau", + "type": "string" + }, + "complete_carrier": { + "const": true, + "title": "Complete Carrier", + "type": "boolean" + }, + "completion": { + "const": "per-crossing-visible-outcome", + "title": "Completion", + "type": "string" + }, + "concurrency": { + "const": "excluded", + "title": "Concurrency", + "type": "string" + }, + "controller_handoff": { + "const": "excluded", + "title": "Controller Handoff", + "type": "string" + }, + "depth_or_sample_bound": { + "title": "Depth Or Sample Bound", + "type": "null" + }, + "domains": { + "$ref": "#/$defs/CrossingDomainsModel" + }, + "fresh_operations": { + "maximum": 1, + "minimum": 1, + "title": "Fresh Operations", + "type": "integer" + }, + "hidden_labels": { + "maxItems": 5, + "minItems": 5, + "prefixItems": [ + { + "const": "internal.validate", + "type": "string" + }, + { + "const": "internal.resolve-policy-cut", + "type": "string" + }, + { + "const": "internal.resolve-capability", + "type": "string" + }, + { + "const": "internal.prepare-record", + "type": "string" + }, + { + "const": "internal.atomic-commit", + "type": "string" + } + ], + "title": "Hidden Labels", + "type": "array" + }, + "identity_reuse": { + "const": "excluded", + "title": "Identity Reuse", + "type": "string" + }, + "kind": { + "const": "participant-crossing-dpbb/v1", + "title": "Kind", + "type": "string" + }, + "left": { + "$ref": "#/$defs/AbstractCrossingCarrierModel" + }, + "order": { + "const": "sequential-total-order", + "title": "Order", + "type": "string" + }, + "probability": { + "const": "excluded", + "title": "Probability", + "type": "string" + }, + "right": { + "$ref": "#/$defs/ConcreteCrossingCarrierModel" + }, + "time": { + "const": "untimed", + "title": "Time", + "type": "string" + }, + "visible_labels": { + "maxItems": 10, + "minItems": 10, + "prefixItems": [ + { + "const": "crossing.request", + "type": "string" + }, + { + "const": "crossing.decision.permit", + "type": "string" + }, + { + "const": "crossing.decision.deny", + "type": "string" + }, + { + "const": "crossing.decision.unsupported", + "type": "string" + }, + { + "const": "crossing.transform", + "type": "string" + }, + { + "const": "crossing.declassify", + "type": "string" + }, + { + "const": "crossing.delivery", + "type": "string" + }, + { + "const": "crossing.observation", + "type": "string" + }, + { + "const": "crossing.replay.reject", + "type": "string" + }, + { + "const": "policy.cut.advance", + "type": "string" + } + ], + "title": "Visible Labels", + "type": "array" + } + }, + "required": [ + "kind", + "domains", + "left", + "right", + "visible_labels", + "hidden_labels", + "checker_tau", + "complete_carrier", + "depth_or_sample_bound", + "fresh_operations", + "identity_reuse", + "order", + "time", + "probability", + "concurrency", + "controller_handoff", + "completion" + ], + "title": "ParticipantCrossingParametersModel", + "type": "object" + }, "ParticipantPredicateOpacityParametersModel": { "additionalProperties": false, "allOf": [ @@ -835,6 +1312,60 @@ "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "allOf": [ + { + "else": { + "properties": { + "relation_id": { + "const": "participant-predicate-opacity" + } + } + }, + "if": { + "properties": { + "parameters": { + "properties": { + "kind": { + "const": "participant-crossing-dpbb/v1" + } + }, + "required": [ + "kind" + ] + } + }, + "required": [ + "parameters" + ] + }, + "then": { + "properties": { + "finite_analysis_scope": { + "const": "declared-complete-finite-carrier" + }, + "left_carrier_ref": { + "const": "sem-230-participant-crossing-abstract" + }, + "observation_projection_ref": { + "const": "participant-crossing-projection" + }, + "observation_projection_revision": { + "const": "rev1" + }, + "profile_id": { + "const": "participant-crossing-dpbb-finite-v1" + }, + "profile_revision": { + "const": "rev2" + }, + "relation_id": { + "const": "divergence-preserving-branching-bisimulation" + }, + "taxonomy_revision": { + "const": "rev8" + } + } + } + }, { "if": { "properties": { @@ -951,7 +1482,22 @@ "type": "string" }, "parameters": { - "$ref": "#/$defs/ParticipantPredicateOpacityParametersModel" + "discriminator": { + "mapping": { + "participant-crossing-dpbb/v1": "#/$defs/ParticipantCrossingParametersModel", + "participant-predicate-opacity/v1": "#/$defs/ParticipantPredicateOpacityParametersModel" + }, + "propertyName": "kind" + }, + "oneOf": [ + { + "$ref": "#/$defs/ParticipantPredicateOpacityParametersModel" + }, + { + "$ref": "#/$defs/ParticipantCrossingParametersModel" + } + ], + "title": "Parameters" }, "profile_id": { "maxLength": 64, @@ -966,7 +1512,10 @@ "type": "string" }, "relation_id": { - "const": "participant-predicate-opacity", + "enum": [ + "participant-predicate-opacity", + "divergence-preserving-branching-bisimulation" + ], "title": "Relation Id", "type": "string" }, diff --git a/docs/decisions/adrs/adr-100-participant-crossing-bisimulation.md b/docs/decisions/adrs/adr-100-participant-crossing-bisimulation.md index fd306d893..640e6c9d9 100644 --- a/docs/decisions/adrs/adr-100-participant-crossing-bisimulation.md +++ b/docs/decisions/adrs/adr-100-participant-crossing-bisimulation.md @@ -54,16 +54,22 @@ runtime mapping authorities. The first target is the complete finite abstract SEM-230 participant-crossing LTS versus an independently derived formal concrete API-423/RUN-319 crossing-kernel LTS. The exact theorem profile is -`participant-crossing-dpbb-finite-v1@rev1`. +`participant-crossing-dpbb-finite-v1@rev2`. The theorem to be machine-checked by downstream work is: > The declared initial states of -> `sem-230-participant-crossing-abstract@rev1` and -> `api-423-run-319-crossing-kernel@rev1` are +> `sem-230-participant-crossing-abstract@rev2` and +> `api-423-run-319-crossing-kernel@rev2` are > divergence-preserving branching bisimilar under > `participant-crossing-projection@rev1`, over the complete reachable carrier -> of `participant-crossing-dpbb-finite-v1@rev1`. +> of `participant-crossing-dpbb-finite-v1@rev2`. + +The #971 refinement closes request reuse, history advancement, event order, +and crossing completion in the [executable model authority](../../../specs/formal/participant-semantics/participant-crossing-models.md). +Rev1 remains the historical design sketch; downstream #972–#976 use rev2 of +both models and the profile, retaining projection rev1 and taxonomy rev8. +No rev1 executable bundle or equivalence result was published. This is a theorem about two formal systems. A separate runtime-realization claim must show that the live reference runtime maps to the concrete formal @@ -102,6 +108,17 @@ fairness, true concurrency, and partial order are excluded. The carrier is the complete reachable fixed point of the declared finite transition schemas, not a depth limit or sample. +One fresh operation uses the sole request identity once and retains its input. +Same-cut retries repeat the formal outcome protocol without another logical +commit; later-cut retries reject. One atomic result advances history h0 to h1; +h2/h3 are declared but unreachable. No identity recycling or head saturation +is admitted. Multiple fresh operations require the separate #1395 profile. +Transformation and declassification emit permit, change, delivery, then +observation. Refusal completes on its visible abstract decision. Terminal +means completion of one crossing, with retry/cut actions still enabled, rather +than global LTS termination. These are offline model semantics: no runtime +retry change, mandatory author proof work, or request-time checker is added. + The visible alphabet includes request, permit, deny, unsupported, transformation, declassification, delivery, observation, later-cut replay rejection, and policy-cut advance. A redacted occurrence remains visible. @@ -234,3 +251,9 @@ program publishes its evidence. - R. van Glabbeek, B. Luttik, and N. Trčka, “Branching Bisimilarity with Explicit Divergence,” *Fundamenta Informaticae* 93(4), 2009, [doi:10.3233/FI-2009-109](https://doi.org/10.3233/FI-2009-109). + +## Amendments + +| Date | Commit/PR | Summary | +|------|-----------|---------| +| 2026-09-27 | #971 | Select executable profile/model rev2 and close the approved single-operation retry, history, ordering, and completion semantics; retain projection rev1 and separate runtime mapping. | diff --git a/docs/decisions/adrs/adr-index.yaml b/docs/decisions/adrs/adr-index.yaml index 2716cce36..f66ec41a5 100644 --- a/docs/decisions/adrs/adr-index.yaml +++ b/docs/decisions/adrs/adr-index.yaml @@ -563,7 +563,11 @@ adrs: pin: 61a5ea9d72a0afa1033d46131913f45b140286b6ddddcb59e0e1f6914b721cb9 - id: ADR-100 path: docs/decisions/adrs/adr-100-participant-crossing-bisimulation.md - pin: b7e17e58fc01e8f07a972ee5abc65e6a8470e2a6d51c2480334a3777df079e98 + pin: 8a406230189370e90c5fcab4e29459f3bcb7dc71321a7b4da007e7011bf6f4fb + amendments: + - date: 2026-09-27 + ref: "#971" + summary: "Select executable rev2 and close single-operation retry, history, ordering, and completion semantics." - id: ADR-101 path: docs/decisions/adrs/adr-101-adversarial-participant-flow-control.md pin: 7a579c1f66ee66285465e261f5e740414986c393fd57fbde3c490be3653711b9 diff --git a/docs/decisions/issue-971-participant-crossing-models-preflight.md b/docs/decisions/issue-971-participant-crossing-models-preflight.md new file mode 100644 index 000000000..e04d7260a --- /dev/null +++ b/docs/decisions/issue-971-participant-crossing-models-preflight.md @@ -0,0 +1,201 @@ +# Issue 971: Independent Participant-Crossing Models Preflight + +Date: 2026-09-27. Requirement: SEM-232; supporting authorities: SEM-230, +API-423, RUN-319. Scope: #971 only. + +Resolution: the user approved one fresh operation and retries; #1395 records +the separate multiple-operation scope. The [executable rev2 rules](../../specs/formal/participant-semantics/participant-crossing-models.md) +and [construction record](../research/participant-bisimulation/model-construction.md) +resolve the design gates recorded below. ADR-100's #971 amendment records the +rev2 target and these semantics. Runtime behavior is unchanged. + +The crossing-kernel boundary in [ADR-100](adrs/adr-100-participant-crossing-bisimulation.md) +stands. The original preflight found the rev1 design **not ready for mechanical +transcription into two exporters**. The historical design gates below are now +resolved by the linked rev2 authority and the ADR amendment. This note records +architecture constraints; the ADR amendment is the revision authority. It supplements the historical [#811 preflight](issue-811-participant-bisimulation-preflight.md). + +## Design gates + +### Transition labels and state updates must be unambiguous + +The [formal authority](../../specs/formal/participant-semantics/participant-crossing-bisimulation.md) +has decision values `transform` and `declassify`, but visible decision labels +only for permit, deny, and unsupported. Abstract schema 2 says to emit the +decision selected by the policy table; schema 3 separately emits the change. +The concrete schemas instead describe permit followed by change. Pin whether +these outcomes mean permit-then-change, and give the corresponding phase and +delivery-coordinate updates. Do not invent extra decision labels, silently +emit a change twice, or let a change remain indefinitely enabled in `decided`. + +Likewise, reconcile the abstract `decided` invariant with refusal becoming +terminal after its visible decision. An unlabeled implementation update cannot +be an extra abstract transition: this profile declares no abstract hidden +steps. Every schema needs guards and target coordinates sufficient to determine +the reachable graph, including when `Pending`/`Intent` and gate state reset. +Internal rank decrease must hold on actual concrete edges; naming phases in a +rank list is not evidence that every hidden transition decreases it. + +### Replay and history must actually admit a complete finite carrier + +The design permits fresh requests from `terminal`, has one request id, stores +`Last = Rid x K x D`, and bounds `Head` to four values. It does not specify when +that request is fresh again, how a changed input under the same identity is +distinguished from replay, or what a fresh commit does at `h3`. Resolve these +questions together. Declare whether identity reuse is excluded by the finite +environment or represented with an input/fingerprint coordinate; do not +silently assume either. Bound the logical commits by semantics, or govern a +justified finite abstraction of history. Saturation, wraparound, dropping the +next request, or stopping exploration at `h3` is not an acceptable implicit +solution. Repeated idempotent replay may produce infinite visible paths in a +finite graph; that is different from hidden divergence. + +Same-cut replay repeats the declared observations without another logical +commit; later-cut rejection preserves the recorded result. Real runtime +fingerprints, history heads, and replay checks remain mapping obligations, +not facts established by using the same names in the model. + +### Termination must survive the export + +The profile calls states `terminal` while enabling subsequent requests and +possibly cut advance. Distinguish completion of one crossing from global LTS +termination. Ordinary `.aut` contains an initial state, counts, and labelled +edges; it has no terminal-state predicate field. Thus a sidecar flag alone +cannot make success, refusal, and deadlock distinguishable to the checker. +Explain how the governed observable behavior represents each promised +distinction, or revise the claim/profile through normal governance. Do not add +an undeclared success label or silently equate an unexpected dead end with +successful completion. See the official [AUT format](https://www.mcrl2.org/web/user_manual/tools/lts.html). + +The candidate abstraction `alpha` and witness `B0` are proposals. In particular, +commit/refusal phases must map into reachable abstract states. Neither exporter +may prune or rewrite its transitions to satisfy that proposed correspondence. +The greatest-fixed-point equivalence decision belongs to #974, not #971; +graph fixed-point enumeration in #971 is a different operation. + +### Extend the existing profile boundary, including its consumers + +`raes_contracts.behavioral_relation_profiles.BehavioralRelationProfileModel` +currently fixes `relation_id` to opacity, has opacity-specific `parameters`, +and resolves only three opacity ids. The theorem object in +`docs/research/participant-bisimulation/implementation-program.json` is design +data, not a loadable relation profile. Use a closed DPBB parameter variant in +the existing profile family, resolver and corpus; no parallel registry, +arbitrary dictionary, opacity placeholder, or skipped join validation. + +The DPBB variant must bind both model carriers, their revisions/digests and +initial states, complete domains, projection and label partition, and supported +dimensions. `behavioral_relations._validate_binding_profile()` currently joins +only the left carrier. Its shared validation boundary must also check the right +carrier when admitting binary profiles. Preserve unary opacity behavior. +Opacity processor admission and `participant_opacity_runtime.py` directly +access opacity parameter fields: they must reject an incompatible variant +before those accesses. Do not turn a new profile into an `AttributeError` or +accidentally route it through the opacity kernel. + +Current catalog authority is `rev12`; the theorem design explicitly pins +`rev8`, which is retained in `contracts/concept-authority/history/` and supported +by `load_behavioral_relation_catalog_revision()`. Use exact revision loaders +for catalog and profile. Do not downgrade the current catalog, substitute +ambient latest, or rewrite historical artifacts. If semantic clarification +changes the named profile/model/projection, record the revision decision and +new digests; never silently change bytes under an established identity. + +Published profile evolution uses ADR-061 compatibility assessment, +`contracts/schemas/profiles/behavioral-relation-profile-v1.json`, +`schema_bundle()`, schema invariants, valid/invalid fixtures, publication +entries and manifest `last_change`, and corpus wheel/sdist parity. A local +Pydantic change alone is insufficient. Any necessary accepted-ADR amendment +uses ADR-059; the #971 amendment and updated acceptance pin now record it. + +### Export is a semantic boundary + +Each model independently determines enabledness, successors and reachability. +They share only governed profile/projection data and nonsemantic plumbing +(ingress, canonical bytes, serialization). Do not share a decision/transition +oracle, generate one graph from the other, use the candidate witness as a +generator, or promote `tests/sem230_information_flow_model.py` to normative +authority. Different function names and source hashes do not establish +independent construction; review must inspect transition dependencies. + +For each graph, enumerate until the reachable set and edges close, then check +initial-state membership, endpoint closure, domain membership and exact counts. +Completeness means closure under every admitted transition rule, not merely +that a supplied edge list references existing nodes. Resource limits terminate +with failure and no complete artifact. Do not use depth/sample bounds, +epsilon elimination, minimization, or a selected schedule to hide missing work. + +Pin state numbering, edge order, encoding/newlines and duplicate-edge handling. +Keep a digest-bound ordinal-to-synthetic-state map for review. Validate the +`.aut` header against emitted bytes, including isolated states and the declared +initial state, and check export/readback agreement. Reject duplicate labels, +visible/hidden overlap, unknown labels, unsafe strings and unsupported format +features. Preserve the five original hidden classes in review data before +their deliberate many-to-one conversion to `internal`. + +`--tau=internal` hides actions **in addition to** internal actions already in +the input. The exporter must therefore exclude undeclared native internal +encodings, not just validate that flag. Do not assume DPBB diagnostic-formula +support from another equivalence mode; the official documentation lists tested +counterexamples for other modes. Those result/counterexample obligations belong +to #973/#974. See [`ltscompare`](https://www.mcrl2.org/web/user_manual/tools/release/ltscompare.html). + +## Cross-cutting layers and incumbents + +Paths below are repository-relative; Python module names are under +`implementations/python/packages/`. These are required boundaries for the +intended implementation, not claims of checks delivered by this preflight. + +| Layer | Canonical incumbent and required behavior | +| --- | --- | +| File and JSON ingress | `raes_contracts.json_ingress.parse_bounded_json_object()` rejects duplicate members, invalid roots and nonfinite numbers; supply nesting and byte bounds. It accepts already-read bytes, so bound regular-file reads before parsing. Use `tools.policy.common.safe_repo_path()` for repo containment and the no-follow bounded-file pattern in `raes_operations.run_artifacts.RunMaterializationArchive` where writable input paths require race protection. Reject absolute/traversing/symlink-escaping paths, special files and oversized inputs. A `SafeRef` string is not filesystem authorization. | +| Schema and semantic admission | Reuse `ContractModel(extra="forbid")`, bounded field types, shared profile loaders, catalog loaders and `validate_behavioral_claim_binding()`. Closure does not imply strict scalar types: require genuine integer ordinals/counts, not booleans or coerced strings. Keep cross-field joins in one owner and expose published invariants through the existing schema machinery. New internal bundle metadata needs one closed checker, not an unsolicited public proof DTO. | +| Participant carrier ownership | The published `participant-crossing-occurrence-v1` schema and `ParticipantCrossingOccurrenceModel` use `ParticipantRuntimeBaseEnvelopeModel`; `validate_participant_crossing_occurrence_context()` owns the typed subject, policy, evidence and predecessor joins. API-406 owns observation, history and outcome carriers; API-409 owns control occurrences; DSL-142 owns inject-delivery identity. The finite LTS represents selected crossing facts by reference and projection. It must not duplicate payloads, mint a generic message carrier, or treat a valid occurrence as proof that delivery or observation happened. | +| Source and artifact identity | Reuse `raes_contracts.canonical.canonical_json_bytes()` / `canonical_json_digest()` for semantic JSON identities. Bind source and `.aut` file identities to exact bytes separately. `serialize_run_artifact()` writes pretty sorted JSON, not RFC 8785 bytes: do not interchange those digests. Record both independent source closures, exporter, profile, projection, revisions, counts and generated artifacts. Compute identities from bytes actually consumed; a commit id alone misses dirty files. Keep digest dependencies acyclic rather than hashing a manifest into itself. | +| Authentication and policy | #971 is an offline repository model producer; it traverses no HTTP, backend or live control-plane authorization boundary. Its singleton identity and finite gates do not establish authentication. Concrete derivation must account for `participant_crossing_policy.py` identity/role/subject binding, independent semantic gates and effective API-407 support. Required unresolved gates fail closed. Later mapping uses `ControlPlaneSecurityConfig.strict_defaults()`, verified identities, request bounds and the existing boundaries, not a new auth route. | +| Runtime context and persistence | API-423 `validate_participant_crossing_occurrence_context()`, `participant_crossing_history.py`, `RuntimeSnapshot` and `ControlPlaneStore.commit_participant_transition()` already own subject/policy/predecessor joins, append-only history and expected-head atomic commit. Reuse them for typed fixtures and later mapping, not as an abstract transition oracle. Refusal may commit safe refusal evidence while preserving unrelated state. No proof fields in snapshots, audit events or backend reports, and no new store. | +| Current runtime boundary | `participant_crossing_boundary.py`, `participant_crossing_egress.py`, `participant_crossing_records.py` and `participant_crossing_commit.py` now include flow-sink, opacity and modular-control interactions. Pin the source inventory and explicitly bound which behaviors the formal kernel represents. Visible effects of newer gates cannot be hidden by calling them bookkeeping. Source drift must fail review; #972 owns evidence that a selected runtime configuration realizes the model. | +| Secrets, errors and observability | Synthetic bounded ids, safe ordinals, counts and public digests only in models, fixtures, maps, diagnostics and artifacts. No secret file access, dotenv loading, runtime payloads, policy bodies, memory, environment dumps or host paths. Hashing secrets is not redaction. Use `Diagnostic`/`DiagnosticModel` and existing `sanitized_failure_message()` at appropriate outer boundaries, with fixed messages/known schema addresses. Some incumbent profile errors interpolate rejected ids: sanitize those too. No raw exception/Pydantic input/traceback/tool output in CLI errors or retained evidence. Progress summaries are not proof evidence; add no logger or exception hierarchy. Any future HTTP wrapper retains the generic internal-error envelope. | +| Environment and host process | Model/profile contents are file inputs, never env overrides, import paths, expressions or shell arguments. Reproducibility uses fixed safe path/id arguments and explicit nonsecret operational settings. No shell, network, credentials, daemon or privilege is required for export. Keep CPU/memory/output limits distinct from semantic domains; exhaustion is failure. Never acquire or run the equivalence checker just to construct models. | +| Artifact publication | `run_artifact_path()` validates only the run-id component, not `subdir`, `filename`, symlinks or output-root containment; callers must constrain these. Reuse `atomic_write_json_artifact()` for suitable JSON after complete validation. It provides per-file replacement, not a multi-file transaction or immutable revision guarantee. Publish a bundle only once every digest/count matches, using the existing verified-tree publication pattern if transactional directory publication is needed. Avoid mixed old/new files and never expose a partial graph as complete. | +| Tool/config admission | Later mCRL2 acquisition follows `implementations/tooling/README.md`: `artifacts.lock.json` is authority; `tools/tool_versions.py` is a checked projection. Reuse `tools/tooling_policy_gate.py`, `maintained_client_acquisition.py`, `verified_tree_installation.py`, tooling schemas, admission policy, development profiles and selector bindings. `isabelle_tool.py` / `isabelle_sandbox.py` demonstrate verified acquisition and isolated offline execution, not a DPBB wrapper to copy wholesale. No floating version, PATH-discovered binary, live checksum trust, shell installer or unvalidated environment selector. | +| Workflow and governance | Reuse `.ground-control.yaml`, `.gc/plan-rules.md`, `tools/check_repo_policy.py`, authority/concept/behavioral-claim gates, schema generation/publication/JSON gates, and assurance policy. Canonical execution is `noxfile.py`, `tools/nox_support/{graph,policy_lanes}.py`, `tools/verification_plan.py` and `.github/workflows/ci.yml`; the older note's `tools/verify_all.py` no longer exists. Use `RAES_REQUIREMENT_UID=SEM-232` when required. Targeted tests locally; full/integration/fuzz/completion lanes remain CI-only. | + +## Verification and extensibility boundaries + +Existing test incumbents include `test_issue_811_participant_bisimulation_design.py` +(design structure only), `test_behavioral_relations.py`, +`test_behavioral_relation_claims.py`, `test_json_ingress.py`, +`test_corpus_packaging.py`, `test_api_423_participant_crossing_contracts.py`, +and `test_run_319_participant_flow_policy.py`. Opacity model-check admission +offers count/domain/unsupported-result patterns, not a reusable bisimulation +algorithm. No new general graph framework or opacity evidence reuse is needed. + +Model acceptance must exercise each issue negative case independently, plus +export/readback agreement, source-order determinism, no partial publication, +resource exhaustion, safe error output, and cross-profile rejection. Regeneration +must compare against retained expected bytes/digests rather than blessing both +new output and new expectations in the same check. Passing design-structure +tests or matching two traces does not establish either model's completeness. + +The extensibility seam is the resolved, revisioned relation-profile variant +and independent transition authorities feeding a deterministic export boundary. +Observer, complete domains, label/projection rules, order, policy cuts and +supported dimensions belong in that profile, not environment defaults or +hardcoded assumptions in a generic serializer. A larger carrier or another +audience gets an explicit profile/model revision; exact historical replay +remains possible. Time, probability, concurrency, controller handoff and new +policy gates require reviewed semantics and capability admission, not merely +larger resource limits. Do not generalize the first finite result across them. + +## Non-goals + +#971 supplies independent complete finite models and reproducible export +evidence only. #972 owns runtime realization; #973 counterexamples; #974 the +equivalence decision; #975 independent reproduction; #976 publication of +reproduced assurance. Do not import those tasks into the model exporter or +fabricate placeholder positive claims to satisfy downstream evidence fields. +Formal equivalence, live realization, backend conformance, policy +noninterference and predicate opacity remain distinct. No new SDL, endpoint, +controller, backend service, policy engine, persistence layer, exception tree, +logging system, generic proof schema or workflow is justified here. diff --git a/docs/requirements/API-423/requirement.md b/docs/requirements/API-423/requirement.md index 49f465c01..c7f242d84 100644 --- a/docs/requirements/API-423/requirement.md +++ b/docs/requirements/API-423/requirement.md @@ -21,6 +21,14 @@ API-406 and API-409 provide adjacent carriers, but no common contract records th ## Traceability +- IMPLEMENTS → GITHUB_ISSUE `OpenRAE/rae#971` (Independent single-operation formal model construction) + +- DOCUMENTS → DOCUMENTATION `docs/research/participant-bisimulation/model-construction.md` (Construction boundary and source derivation) + +- TESTS → TEST `implementations/python/tests/test_issue_971_crossing_models.py` (Complete single-operation transition, retry and atomicity construction tests) + +- IMPLEMENTS → CODE_FILE `implementations/formal/participant_crossing/concrete.py` (Issue #971 single-operation formal model construction only; no equivalence or runtime-realization result) + - IMPLEMENTS → GITHUB_ISSUE `OpenRAE/rae#1016` (Bind mixed-runtime dispatch to exact participant crossing facts) - IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_runtime/participant_result_contracts.py` (Append-only composition evidence validation across backend results) - TESTS → TEST `implementations/python/tests/test_issue_1016_mixed_runtime_coordination.py` (Crossing, policy, delivery, observation, weakening, and failure evidence witnesses) diff --git a/docs/requirements/RUN-319/requirement.md b/docs/requirements/RUN-319/requirement.md index 1385e0b98..c26537cb2 100644 --- a/docs/requirements/RUN-319/requirement.md +++ b/docs/requirements/RUN-319/requirement.md @@ -21,6 +21,14 @@ Current admission, retrieval, lifecycle, and persistence surfaces do not yet for ## Traceability +- IMPLEMENTS → GITHUB_ISSUE `OpenRAE/rae#971` (Independent single-operation formal model construction) + +- DOCUMENTS → DOCUMENTATION `docs/research/participant-bisimulation/model-construction.md` (Construction boundary and source derivation) + +- TESTS → TEST `implementations/python/tests/test_issue_971_crossing_models.py` (Complete single-operation transition, retry and atomicity construction tests) + +- IMPLEMENTS → CODE_FILE `implementations/formal/participant_crossing/concrete.py` (Issue #971 single-operation formal model construction only; no equivalence or runtime-realization result) + - IMPLEMENTS → GITHUB_ISSUE `OpenRAE/rae#1016` (Coordinate mixed participant runtimes behind the incumbent crossing decision) - IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_runtime/participant_action_validation.py` (Protect runtime-owned composition state from provider mutation) - IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_runtime/participant_control.py` (Admit mixed participant actions without a logical provider fallback) diff --git a/docs/requirements/SEM-230/requirement.md b/docs/requirements/SEM-230/requirement.md index a421a2306..0b44ff595 100644 --- a/docs/requirements/SEM-230/requirement.md +++ b/docs/requirements/SEM-230/requirement.md @@ -21,6 +21,14 @@ Existing participant action, observation, visibility, runtime, and behavioral-re ## Traceability +- IMPLEMENTS → GITHUB_ISSUE `OpenRAE/rae#971` (Independent single-operation formal model construction) + +- DOCUMENTS → DOCUMENTATION `docs/research/participant-bisimulation/model-construction.md` (Construction boundary and source derivation) + +- TESTS → TEST `implementations/python/tests/test_issue_971_crossing_models.py` (Complete single-operation transition, retry and atomicity construction tests) + +- IMPLEMENTS → CODE_FILE `implementations/formal/participant_crossing/abstract.py` (Issue #971 single-operation formal model construction only; no equivalence or runtime-realization result) + - DOCUMENTS → GITHUB_ISSUE `OpenRAE/rae#1013` (Compose the existing SEM-230 authority in SEM-234 without changing its runtime contract) - DOCUMENTS → SPEC `specs/formal/participant-semantics/cross-backend-participant-control.md` (Revisioned mixed-composition compatibility boundary) - TESTS → TEST `implementations/python/tests/test_sem_234_mixed_composition.py` (Bounded composition with incumbent SEM-230 authority) diff --git a/docs/requirements/SEM-232/requirement.md b/docs/requirements/SEM-232/requirement.md index 0f62f0d7c..12c6da491 100644 --- a/docs/requirements/SEM-232/requirement.md +++ b/docs/requirements/SEM-232/requirement.md @@ -21,6 +21,20 @@ SEM-230 defines participant information-flow labels and projection, API-423 and ## Traceability +- DOCUMENTS → GITHUB_ISSUE `OpenRAE/rae#1395` (Model multiple operations and interleaved retries) + +- TESTS → TEST `implementations/python/tests/test_issue_971_crossing_profile.py` (Closed carrier and binary profile validation tests) + +- TESTS → TEST `implementations/python/tests/test_issue_971_crossing_export.py` (Complete export, drift and safe publication tests) + +- DOCUMENTS → CODE_FILE `implementations/python/packages/raes_contracts/_participant_crossing_profile.py` (Closed construction profile; theorem remains unestablished) + +- DOCUMENTS → DOCUMENTATION `docs/research/participant-bisimulation/model-construction.md` (Construction boundary and source derivation) + +- TESTS → TEST `implementations/python/tests/test_issue_971_crossing_models.py` (Complete single-operation transition, retry and atomicity construction tests) + +- DOCUMENTS → CODE_FILE `implementations/formal/participant_crossing/export.py` (Issue #971 single-operation formal model construction only; no equivalence or runtime-realization result) + - DOCUMENTS → GITHUB_ISSUE `OpenRAE/rae#971` (Implement independent participant-crossing proof models) - DOCUMENTS → GITHUB_ISSUE `OpenRAE/rae#972` (Map the reference runtime to the participant-crossing proof model) - DOCUMENTS → GITHUB_ISSUE `OpenRAE/rae#973` (Build the participant-crossing bisimulation counterexample corpus) diff --git a/docs/research/participant-bisimulation/candidate-comparison.md b/docs/research/participant-bisimulation/candidate-comparison.md index a57a98384..747040c23 100644 --- a/docs/research/participant-bisimulation/candidate-comparison.md +++ b/docs/research/participant-bisimulation/candidate-comparison.md @@ -1,5 +1,8 @@ # Participant Bisimulation Candidate Comparison +Historical #811 assessment. ADR-100’s #971 amendment selects the +[executable rev2 target](theorem-selection.md) for downstream work. + Date: 2026-07-29 Every candidate is evaluated against the same minimum surface: explicit state diff --git a/docs/research/participant-bisimulation/current-state-assessment.md b/docs/research/participant-bisimulation/current-state-assessment.md index f5bb0f0cd..bf2a84f8f 100644 --- a/docs/research/participant-bisimulation/current-state-assessment.md +++ b/docs/research/participant-bisimulation/current-state-assessment.md @@ -1,5 +1,8 @@ # Participant Bisimulation Current-State Assessment +Historical #811 assessment. ADR-100’s #971 amendment selects the +[executable rev2 target](theorem-selection.md) for downstream work. + Date: 2026-07-29 Parent issue: [#811](https://github.com/OpenRAE/rae/issues/811). diff --git a/docs/research/participant-bisimulation/implementation-program.json b/docs/research/participant-bisimulation/implementation-program.json index 0a128233c..b781a9ec7 100644 --- a/docs/research/participant-bisimulation/implementation-program.json +++ b/docs/research/participant-bisimulation/implementation-program.json @@ -51,8 +51,8 @@ }, { "id": "abstract-crossing-vs-concrete-crossing-kernel", - "left_carrier": "Complete reachable finite sem-230-participant-crossing-abstract@rev1 LTS.", - "right_carrier": "Independently derived complete reachable finite api-423-run-319-crossing-kernel@rev1 LTS.", + "left_carrier": "Complete reachable finite sem-230-participant-crossing-abstract@rev2 LTS.", + "right_carrier": "Independently derived complete reachable finite api-423-run-319-crossing-kernel@rev2 LTS.", "state_space": "Closed singleton participant, audience, controller, episode, and request domains; two policy cuts; five input classes; finite decision, delivery, history, replay, and stage coordinates.", "initial_relation": "The profile idle p0 states are related; the candidate witness family is induced by the concrete-to-abstract semantic abstraction.", "transitions_and_enabledness": "Closed request, policy decision, transform/declassify, delivery/observation, cut-advance, and replay schemas plus finite concrete mediation stages.", @@ -94,7 +94,7 @@ ], "theorem_profile": { "profile_id": "participant-crossing-dpbb-finite-v1", - "profile_revision": "rev1", + "profile_revision": "rev2", "relation_id": "divergence-preserving-branching-bisimulation", "taxonomy_ref": "raes-behavioral-relations@rev8", "projection_ref": "participant-crossing-projection@rev1", @@ -115,8 +115,8 @@ }, "left_model": { "model_id": "sem-230-participant-crossing-abstract", - "revision": "rev1", - "authority": "specs/formal/participant-semantics/participant-crossing-bisimulation.md#abstract-states", + "revision": "rev2", + "authority": "specs/formal/participant-semantics/participant-crossing-models.md#abstract-rules", "transition_source": "SEM-230 abstract crossing transition schemas", "independent_construction": true, "state_coordinates": ["phase", "policy_cut", "pending_request", "decision", "delivery", "last_result"], @@ -126,8 +126,8 @@ }, "right_model": { "model_id": "api-423-run-319-crossing-kernel", - "revision": "rev1", - "authority": "specs/formal/participant-semantics/participant-crossing-bisimulation.md#concrete-states", + "revision": "rev2", + "authority": "specs/formal/participant-semantics/participant-crossing-models.md#concrete-rules", "transition_source": "independently reviewed API-423/RUN-319 crossing-stage transition schemas", "independent_construction": true, "state_coordinates": ["phase", "policy_cut", "intent", "gate", "capability", "decision", "delivery", "history_head", "last_result"], diff --git a/docs/research/participant-bisimulation/index.md b/docs/research/participant-bisimulation/index.md index 920c7e9c0..d8ef7cb70 100644 --- a/docs/research/participant-bisimulation/index.md +++ b/docs/research/participant-bisimulation/index.md @@ -7,6 +7,8 @@ downstream. This delivery defines the target and program. It does not claim the result. - [Architecture preflight](../../decisions/issue-811-participant-bisimulation-preflight.md) +- [Independent model preflight (#971)](../../decisions/issue-971-participant-crossing-models-preflight.md) +- [Executable model construction (#971)](model-construction.md) - [ADR-100](../../decisions/adrs/adr-100-participant-crossing-bisimulation.md) - [Current-state assessment](current-state-assessment.md) - [Candidate comparison](candidate-comparison.md) diff --git a/docs/research/participant-bisimulation/model-construction.md b/docs/research/participant-bisimulation/model-construction.md new file mode 100644 index 000000000..692b17267 --- /dev/null +++ b/docs/research/participant-bisimulation/model-construction.md @@ -0,0 +1,102 @@ +# Independent Crossing Model Construction + +Issue: [#971](https://github.com/OpenRAE/rae/issues/971). + +The executable profile is `participant-crossing-dpbb-finite-v1@rev2`. +It covers one fresh operation and its retries. It does not change runtime retry +behavior, require scenario annotations, or run a checker on participant requests. +[Multiple operations](https://github.com/OpenRAE/rae/issues/1395) require their +own profile. The [formal rules](../../../specs/formal/participant-semantics/participant-crossing-models.md) +resolve the original design's request reuse, head exhaustion, decision/change +ordering and crossing-completion ambiguities. The user approved this scope. + +## Construction evidence + +| Model | States | Transitions | Initial states | +| --- | ---: | ---: | ---: | +| SEM-230 abstract, rev2 | 88 | 107 | 1 | +| API-423/RUN-319 concrete kernel, rev2 | 178 | 197 | 1 | + +Both are complete reachable fixed points, not depth-limited samples. The +[manifest](../../../specs/formal/participant-semantics/crossing-models/rev2/manifest.json) +records domain counts, initial coordinates, source/profile/catalog identities +and artifact digests. Each model has an AUT graph and a canonical JSON state +map retaining the original hidden label classes. The only checker tau name is +`internal`; no native tau encoding is accepted. + +The complete base domains have cardinalities participant=1, audience=1, +controller=1, episode=1, request=1, policy-cut=2, input=5, decision=6, replay=3, +delivery=4 and history-head=4. Intent has 31 ambient values (none plus the +request/input/cut/replay product); last has 13 (none plus request/cut/decision). +Abstract phase has 5 values; concrete phase has 9, gate and capability each 3. +Reachability removes inconsistent products. h2/h3 are declared but unreachable +because only one fresh logical result can commit. No history counter saturates. + +## Independent construction review + +| Boundary | Abstract authority | Concrete authority | +| --- | --- | --- | +| Decision | Own total cut/input policy table | Own deny-first gate and capability branches | +| Completion | Visible decision or observation records the abstract result | Prepare then atomic commit, followed by delivery/observation where applicable | +| Retry | Recorded abstract result; later-cut rejection | Intent/cut validation and reuse of durable result; no second commit | +| Exploration | Deque-based reachable closure | Separate cursor/worklist closure | + +The model modules import only the shared closed input vocabulary, dataclass/ +collection plumbing and inert graph storage. Neither imports the other, a +shared policy oracle, runtime executable code, or the candidate equivalence +witness. The exporter checks static dependencies, source identities and +transition ownership. These mechanical checks support source review; hashes +alone do not establish independent derivation. + +The concrete source inventory names API-423 occurrence/context validation and +RUN-319 gate, mediation, record, commit, history-head, boundary, egress and store +files. Their hashes detect changes requiring renewed mapping review. This +model does not claim to include every live gate, transformed-ingress +revalidation, crash state or backend interaction. #972 must establish the +mapping for a selected runtime configuration. An exact retry returns the +original runtime receipt without executing the action again; model outcome +observations must not be interpreted as a second effect. Runtime history can +advance without a policy revision change; that interaction belongs to #1395. + +## Reproduce and check + +From a checkout of the delivery revision, use its frozen Python environment: + +```sh +PYTHONPATH=implementations/python/packages uv run --project implementations/python --frozen \ + python -m implementations.formal.participant_crossing +``` + +The default command reconstructs both graphs and compares all retained bundle +bytes and digests. It does not update expectations. To create the bundle in a +clean checkout where the output directory is absent, pass `--write`. Publication +validates all inputs and builds all files before a single directory rename. +An existing identical bundle is accepted; an existing changed bundle is refused. +Model changes require reviewed source/profile identities and a new published +revision. The first delivery's source identity is a SHA-256 commitment to the +exact source inventory, avoiding a self-referential Git commit hash. + +No network, checker executable, credentials or environment-selected model is +used by export. `PYTHONPATH` selects the checkout's installed source packages; +it does not select policy behavior. The input domains are fixed by the profile. +Malformed JSON, special files, symlinks, oversized inputs, unknown labels, +truncated models, shared transition authorities and digest drift fail closed. +CLI failures use a fixed message without rejected input or host paths. + +## Contract compatibility and assurance + +The draft `behavioral-relation-profile/v1` schema adds a discriminated binary +profile variant. Existing opacity profile payloads and their canonical digests +retain their shape; old readers reject the new variant. No compatibility claim +is made for old readers consuming the new DPBB profile. The incumbent local-join +and claim-resolution invariants validate the new variant, including both +carriers. Existing opacity-only consumers reject it through their admission +and claim checks. Valid/invalid fixtures exercise the published schema and its +reference model, and the schema publication entry records the change. + +SEM-232 remains DRAFT: model construction is implemented, while its conditional +equivalence result and independent reproduction are not established. SEM-230, +API-423 and RUN-319 retain their existing ACTIVE contracts. This package adds +bounded formal representation and construction evidence, not new enforcement. +No equivalence, live-runtime realization, backend conformance, noninterference, +opacity, latency, probability, concurrency or controller-handoff result follows. diff --git a/docs/research/participant-bisimulation/theorem-selection.md b/docs/research/participant-bisimulation/theorem-selection.md index 76fc238e6..3175f1434 100644 --- a/docs/research/participant-bisimulation/theorem-selection.md +++ b/docs/research/participant-bisimulation/theorem-selection.md @@ -1,20 +1,22 @@ # Participant-Crossing Theorem And Profile Selection -Date: 2026-07-29 +Date: 2026-07-29. Amended by #971 on 2026-09-27 under ADR-100. ## Selected Statement The downstream proof obligation is to establish, for the complete reachable carrier of -`participant-crossing-dpbb-finite-v1@rev1`, the initial state of -`sem-230-participant-crossing-abstract@rev1` and the initial state of -`api-423-run-319-crossing-kernel@rev1` under +`participant-crossing-dpbb-finite-v1@rev2`, the initial state of +`sem-230-participant-crossing-abstract@rev2` and the initial state of +`api-423-run-319-crossing-kernel@rev2` under `participant-crossing-projection@rev1` satisfy relation id `divergence-preserving-branching-bisimulation`. The evidence boundary is that exact complete finite profile; this design does not report the result. -The normative state domains, transition schemas, policy table, label -partition, relation clauses, and abstraction map are in -[the formal specification](../../../specs/formal/participant-semantics/participant-crossing-bisimulation.md). +The executable domains, transition schemas, and completion semantics are in +[the rev2 model authority](../../../specs/formal/participant-semantics/participant-crossing-models.md). +The [original specification](../../../specs/formal/participant-semantics/participant-crossing-bisimulation.md) +retains the relation clauses and projection. Its candidate abstraction is +historical design input, not an established witness for the executable models. ## Why This Is A Final Finite Target diff --git a/implementations/formal/participant_crossing/__init__.py b/implementations/formal/participant_crossing/__init__.py new file mode 100644 index 000000000..12bd3202a --- /dev/null +++ b/implementations/formal/participant_crossing/__init__.py @@ -0,0 +1 @@ +"""Offline SEM-232 model construction; never imported by the runtime.""" diff --git a/implementations/formal/participant_crossing/__main__.py b/implementations/formal/participant_crossing/__main__.py new file mode 100644 index 000000000..f9179c447 --- /dev/null +++ b/implementations/formal/participant_crossing/__main__.py @@ -0,0 +1,31 @@ +"""Fixed-path offline producer: python -m implementations.formal.participant_crossing.""" + +import argparse +import sys +from pathlib import Path + + +def main(argv=None) -> int: + parser = argparse.ArgumentParser( + description="Construct or check the complete crossing model bundle." + ) + parser.add_argument( + "--write", + action="store_true", + help="Publish a new bundle; refuse existing drift.", + ) + args = parser.parse_args(argv) + root = Path(__file__).resolve().parents[3] + try: + from .export import check, publish + + (publish if args.write else check)(root) + except (OSError, ValueError): + print("participant-crossing model export failed validation", file=sys.stderr) + return 1 + print("participant-crossing model bundle verified; no equivalence result claimed") + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/implementations/formal/participant_crossing/abstract.py b/implementations/formal/participant_crossing/abstract.py new file mode 100644 index 000000000..bc598fadb --- /dev/null +++ b/implementations/formal/participant_crossing/abstract.py @@ -0,0 +1,148 @@ +"""SEM-230 transition authority, executable refinement rev2. + +Derivation: participant-crossing-models.md, Abstract rules. No concrete-stage +dependency or abstraction map is used to construct this graph. +""" + +from collections import deque +from dataclasses import dataclass, replace + +from raes_contracts.behavioral_relation_profiles import INPUT_CLASSES + +from .graph import Graph + + +@dataclass(frozen=True) +class State: + phase: str = "idle" + cut: str = "p0" + intent: tuple[str, str, str, str] | None = None + decision: str = "none" + delivery: str = "none" + last: tuple[str, str, str] | None = None + + +INITIAL = State() +_POLICY = { + "p0": dict( + zip( + INPUT_CLASSES, + ("permit", "transform", "deny", "unsupported", "deny"), + strict=True, + ) + ), + "p1": dict( + zip( + INPUT_CLASSES, + ("permit", "transform", "declassify", "unsupported", "deny"), + strict=True, + ) + ), +} + + +def successors(state: State) -> list[tuple[str, State]]: + """Exactly the abstract rules; no silent abstract transitions.""" + if state.phase in {"idle", "terminal"}: + choices = [] + if state.cut == "p0": + choices.append(("policy.cut.advance", replace(state, cut="p1"))) + if state.last is None: + for item in INPUT_CLASSES: + choices.append( + ( + "crossing.request", + State( + "offered", + state.cut, + ("request-0", item, state.cut, "fresh"), + ), + ) + ) + else: + mode = "same-cut" if state.last[1] == state.cut else "later-cut" + intent = ("request-0", state.intent[1], state.last[1], mode) + choices.append( + ( + "crossing.request", + State("offered", state.cut, intent, last=state.last), + ) + ) + return choices + if state.phase == "offered": + if state.intent[3] == "later-cut": + decision = state.last[2] + delivery = ( + "withheld" if decision in {"deny", "unsupported"} else "delivered" + ) + return [ + ( + "crossing.replay.reject", + replace( + state, phase="terminal", decision=decision, delivery=delivery + ), + ) + ] + decision = state.last[2] if state.last else _POLICY[state.cut][state.intent[1]] + if decision in {"deny", "unsupported"}: + return [ + ( + f"crossing.decision.{decision}", + replace( + state, + phase="terminal", + decision=decision, + delivery="withheld", + last=state.last or ("request-0", state.cut, decision), + ), + ) + ] + return [ + ( + "crossing.decision.permit", + replace( + state, + phase="decided", + decision=decision, + delivery="pending" if decision == "permit" else "none", + ), + ) + ] + if state.phase == "decided": + if state.delivery == "none": + return [(f"crossing.{state.decision}", replace(state, delivery="pending"))] + return [("crossing.delivery", replace(state, phase="delivery-pending"))] + if state.phase == "delivery-pending": + return [ + ( + "crossing.observation", + replace( + state, + phase="terminal", + delivery="delivered", + last=state.last or ("request-0", state.cut, state.decision), + ), + ) + ] + raise ValueError("invalid abstract phase") + + +def build(*, max_states: int = 4096) -> Graph: + """Least reachable fixed point, deterministic breadth-first enumeration.""" + states = [INITIAL] + ordinals = {INITIAL: 0} + work = deque([INITIAL]) + edges = set() + while work: + state = work.popleft() + for label, target in sorted( + successors(state), key=lambda edge: (edge[0], repr(edge[1])) + ): + if target not in ordinals: + if len(states) >= max_states: + raise ValueError("abstract resource limit exceeded") + ordinals[target] = len(states) + states.append(target) + work.append(target) + edges.add((ordinals[state], label, ordinals[target])) + return Graph(tuple(states), tuple(sorted(edges))) diff --git a/implementations/formal/participant_crossing/aut.py b/implementations/formal/participant_crossing/aut.py new file mode 100644 index 000000000..900f12dca --- /dev/null +++ b/implementations/formal/participant_crossing/aut.py @@ -0,0 +1,61 @@ +"""Strict deterministic AUT codec; contains no transition semantics.""" + +import re + +from raes_contracts.behavioral_relation_profiles import HIDDEN, VISIBLE + +from .graph import Graph +from .ingress import MAX_BYTES + + +def parse_aut(content: bytes) -> tuple[int, int, tuple[tuple[int, str, int], ...]]: + if len(content) > MAX_BYTES: + raise ValueError("AUT exceeds byte limit") + try: + lines = content.decode("ascii").splitlines() + except UnicodeDecodeError: + raise ValueError("invalid AUT encoding") from None + header = ( + re.fullmatch(r"des \((\d{1,5}), (\d{1,6}), (\d{1,5})\)", lines[0]) + if lines + else None + ) + if header is None: + raise ValueError("invalid AUT header") + initial, edge_count, state_count = map(int, header.groups()) + if not 0 <= initial < state_count <= 4096 or edge_count != len(lines) - 1: + raise ValueError("invalid AUT counts") + edges = [] + for line in lines[1:]: + edge = re.fullmatch(r'\((\d{1,5}),"([a-z.-]{1,48})",(\d{1,5})\)', line) + if edge is None: + raise ValueError("invalid AUT edge") + left, label, right = edge.groups() + if ( + label not in (*VISIBLE, "internal") + or max(int(left), int(right)) >= state_count + ): + raise ValueError("invalid AUT label or endpoint") + edges.append((int(left), label, int(right))) + if len(set(edges)) != len(edges): + raise ValueError("duplicate AUT edge") + return initial, state_count, tuple(edges) + + +def render_aut(graph: Graph) -> bytes: + projected = [] + for source, label, target in graph.edges: + if label not in (*VISIBLE, *HIDDEN): + raise ValueError("undeclared semantic label") + projected.append((source, "internal" if label in HIDDEN else label, target)) + projected.sort() + content = ( + f"des ({graph.initial}, {len(projected)}, {len(graph.states)})\n" + + "".join( + f'({source},"{label}",{target})\n' for source, label, target in projected + ) + ).encode("ascii") + initial, count, edges = parse_aut(content) + if (initial, count, edges) != (graph.initial, len(graph.states), tuple(projected)): + raise ValueError("AUT readback mismatch") + return content diff --git a/implementations/formal/participant_crossing/concrete.py b/implementations/formal/participant_crossing/concrete.py new file mode 100644 index 000000000..820465e04 --- /dev/null +++ b/implementations/formal/participant_crossing/concrete.py @@ -0,0 +1,176 @@ +"""Independent API-423/RUN-319 formal crossing kernel, rev2. + +Derivation: contract predecessor order and runtime gate/prepare/commit stages. +This is a formal kernel; it does not execute or certify the live runtime. +""" + +from dataclasses import dataclass, replace + +from raes_contracts.behavioral_relation_profiles import INPUT_CLASSES + +from .graph import Graph + + +@dataclass(frozen=True) +class State: + phase: str = "idle" + cut: str = "p0" + intent: tuple[str, str, str, str] | None = None + gate: str = "unresolved" + capability: str = "unresolved" + decision: str = "none" + delivery: str = "none" + head: str = "h0" + last: tuple[str, str, str] | None = None + + +INITIAL = State() + + +def _environment(state: State) -> list[tuple[str, State]]: + edges = [] + if state.cut == "p0": + edges.append(("policy.cut.advance", replace(state, cut="p1"))) + inputs = INPUT_CLASSES if state.last is None else (state.intent[1],) + for item in inputs: + if state.last is None: + intent = ("request-0", item, state.cut, "fresh") + else: + mode = "same-cut" if state.cut == state.last[1] else "later-cut" + intent = ("request-0", item, state.last[1], mode) + edges.append( + ( + "crossing.request", + State( + "validating", state.cut, intent, head=state.head, last=state.last + ), + ) + ) + return edges + + +def _gating(state: State) -> list[tuple[str, State]]: + # Independent deny-first gate derivation, not the abstract policy table. + if state.gate == "deny": + decision = "deny" + elif state.capability != "supported": + decision = "unsupported" + elif state.intent[1] in {"transform", "declassify"}: + decision = state.intent[1] + else: + decision = "permit" + refused = decision in {"deny", "unsupported"} + label = f"crossing.decision.{decision}" if refused else "crossing.decision.permit" + phase = "terminal" if refused and state.last else "preparing-record" + delivery = ( + "withheld" if refused else ("pending" if decision == "permit" else "none") + ) + return [(label, replace(state, phase=phase, decision=decision, delivery=delivery))] + + +def successors(state: State) -> list[tuple[str, State]]: + if state.phase in {"idle", "terminal"}: + return _environment(state) + if state.phase == "validating": + return [("internal.validate", replace(state, phase="resolving-cut"))] + if state.phase == "resolving-cut": + if state.intent[2] != state.cut: + decision = state.last[2] + delivery = ( + "withheld" if decision in {"deny", "unsupported"} else "delivered" + ) + return [ + ( + "crossing.replay.reject", + replace( + state, phase="terminal", decision=decision, delivery=delivery + ), + ) + ] + return [ + ( + "internal.resolve-policy-cut", + replace(state, phase="resolving-capability"), + ) + ] + if state.phase == "resolving-capability": + capability = "unsupported" if state.intent[1] == "unsupported" else "supported" + allowed = state.intent[1] != "forbidden" and not ( + state.intent[1] == "declassify" and state.cut == "p0" + ) + return [ + ( + "internal.resolve-capability", + replace( + state, + phase="gating", + capability=capability, + gate="permit" if allowed else "deny", + ), + ) + ] + if state.phase == "gating": + return _gating(state) + if state.phase == "preparing-record": + if state.decision in {"transform", "declassify"} and state.delivery == "none": + return [(f"crossing.{state.decision}", replace(state, delivery="pending"))] + return [("internal.prepare-record", replace(state, phase="committing"))] + if state.phase == "committing": + if state.last is None: + phase = ( + "terminal" + if state.decision in {"deny", "unsupported"} + else "committing" + ) + return [ + ( + "internal.atomic-commit", + replace( + state, + phase=phase, + head="h1", + last=("request-0", state.cut, state.decision), + ), + ) + ] + return [("crossing.delivery", replace(state, phase="delivery-pending"))] + if state.phase == "delivery-pending": + return [ + ( + "crossing.observation", + replace(state, phase="terminal", delivery="delivered"), + ) + ] + raise ValueError("invalid concrete phase") + + +def internal_rank(state: State) -> int: + if state.phase == "committing": + return 1 if state.last is None else 0 + return { + "validating": 6, + "resolving-cut": 5, + "resolving-capability": 4, + "gating": 3, + "preparing-record": 2, + }.get(state.phase, 0) + + +def build(*, max_states: int = 4096) -> Graph: + """Independently enumerate the kernel worklist until no new state exists.""" + queue = [INITIAL] + ids = {INITIAL: 0} + arcs = [] + cursor = 0 + while cursor < len(queue): + for action, successor in sorted( + successors(queue[cursor]), key=lambda edge: (edge[0], repr(edge[1])) + ): + if successor not in ids: + if len(queue) >= max_states: + raise ValueError("concrete resource limit exceeded") + ids[successor] = len(queue) + queue.append(successor) + arcs.append((cursor, action, ids[successor])) + cursor += 1 + return Graph(tuple(queue), tuple(sorted(set(arcs)))) diff --git a/implementations/formal/participant_crossing/export.py b/implementations/formal/participant_crossing/export.py new file mode 100644 index 000000000..89d9ed681 --- /dev/null +++ b/implementations/formal/participant_crossing/export.py @@ -0,0 +1,235 @@ +"""Offline, reproducible model bundles; no equivalence result is produced.""" + +import ast +import hashlib +import os +import tempfile +from dataclasses import asdict +from pathlib import Path + +from raes_contracts.behavioral_relation_profiles import ( + BehavioralRelationProfileModel, + ParticipantCrossingParametersModel, +) +from raes_contracts.behavioral_relations import ( + load_behavioral_relation_catalog_revision, +) +from raes_contracts.canonical import canonical_json_bytes, canonical_json_digest +from raes_contracts.json_ingress import parse_bounded_json_object + +from . import abstract, concrete +from .aut import parse_aut as parse_aut, render_aut +from .ingress import MAX_BYTES, read_bytes, safe_path + +PROFILE_PATH = ( + "contracts/profiles/behavioral-relation/participant-crossing-dpbb-finite-v1.json" +) +OUTPUT_PATH = "specs/formal/participant-semantics/crossing-models/rev2" +_PACKAGE = "implementations/python/packages/" +SOURCE_PATHS = ( + "implementations/formal/participant_crossing/__init__.py", + "implementations/formal/participant_crossing/__main__.py", + "implementations/formal/participant_crossing/abstract.py", + "implementations/formal/participant_crossing/concrete.py", + "implementations/formal/participant_crossing/graph.py", + "implementations/formal/participant_crossing/aut.py", + "implementations/formal/participant_crossing/ingress.py", + "implementations/formal/participant_crossing/export.py", + _PACKAGE + "raes_contracts/_participant_crossing_profile.py", + _PACKAGE + "raes_contracts/behavioral_relation_profiles.py", + _PACKAGE + "raes_contracts/_behavioral_profile_loader.py", + _PACKAGE + "raes_contracts/canonical.py", + _PACKAGE + "raes_contracts/_canonical.py", + _PACKAGE + "raes_contracts/json_ingress.py", + _PACKAGE + "raes_contracts/contracts/participant_crossing.py", + _PACKAGE + "raes_contracts/contracts/participant_crossing_validation.py", + _PACKAGE + "raes_runtime/participant_crossing_policy.py", + _PACKAGE + "raes_runtime/participant_crossing_mediation.py", + _PACKAGE + "raes_runtime/participant_crossing_records.py", + _PACKAGE + "raes_runtime/participant_crossing_commit.py", + _PACKAGE + "raes_runtime/participant_crossing_boundary.py", + _PACKAGE + "raes_runtime/participant_crossing_egress.py", + _PACKAGE + "raes_runtime/participant_crossing_state_cut.py", + _PACKAGE + "raes_runtime/control_plane_store.py", + "specs/formal/participant-semantics/participant-crossing-models.md", + "specs/formal/participant-semantics/information-flow-control.md", + "implementations/python/uv.lock", +) + + +def digest(content: bytes) -> str: + return "sha256:" + hashlib.sha256(content).hexdigest() + + +# The CLI starts a fresh interpreter in this checkout. A caller may export a +# copied tree only when its Python sources match that executing checkout. +_EXECUTING_SOURCE_DIGESTS = { + path: digest(read_bytes(Path(__file__).resolve().parents[3], path)) + for path in SOURCE_PATHS + if path.endswith(".py") +} + + +def _independence(sources: dict[str, bytes]) -> None: + allowed = { + "collections", + "dataclasses", + "raes_contracts.behavioral_relation_profiles", + "graph", + } + for module in (abstract, concrete): + if module.successors.__module__ != module.__name__: + raise ValueError("models must use independent transition authorities") + path = f"implementations/formal/participant_crossing/{module.__name__.rsplit('.', 1)[1]}.py" + tree = ast.parse(sources[path]) + for node in ast.walk(tree): + if ( + isinstance(node, ast.Import) + or isinstance(node, ast.ImportFrom) + and node.module not in allowed + ): + raise ValueError("models must use independent transition dependencies") + if ( + isinstance(node, ast.Call) + and isinstance(node.func, ast.Name) + and node.func.id in {"eval", "exec", "__import__"} + ): + raise ValueError( + "models must use independent static transition dependencies" + ) + if abstract.successors is concrete.successors or abstract.build is concrete.build: + raise ValueError("models must use independent transition authorities") + + +def _validate_graph(graph, module) -> None: + if not graph.states or graph.states[graph.initial] != module.INITIAL: + raise ValueError("invalid model initial state") + index = {state: ordinal for ordinal, state in enumerate(graph.states)} + if len(index) != len(graph.states): + raise ValueError("duplicate model states") + expected = set() + for ordinal, state in enumerate(graph.states): + for label, target in module.successors(state): + if target not in index: + raise ValueError("incomplete model transition closure") + expected.add((ordinal, label, index[target])) + if expected != set(graph.edges) or len(graph.edges) != len(expected): + raise ValueError("incomplete model transition closure") + reachable = {graph.initial} + while True: + expanded = reachable | { + target for source, _, target in graph.edges if source in reachable + } + if expanded == reachable: + break + reachable = expanded + if len(reachable) != len(graph.states): + raise ValueError("unreachable model states") + + +def build_bundle(root: Path) -> dict[str, bytes]: + payload = parse_bounded_json_object( + read_bytes(root, PROFILE_PATH), max_bytes=256 * 1024, max_depth=32 + ) + profile = BehavioralRelationProfileModel.model_validate(payload) + if not isinstance(profile.parameters, ParticipantCrossingParametersModel): + raise ValueError("expected crossing profile") + sources = {path: read_bytes(root, path) for path in SOURCE_PATHS} + identities = {path: digest(content) for path, content in sources.items()} + for carrier in (profile.parameters.left, profile.parameters.right): + if identities[carrier.source_path] != carrier.source_digest: + raise ValueError("model source digest drift") + for source in profile.source_refs: + if identities.get(source.source_ref) != source.source_digest: + raise ValueError("profile source digest drift") + if any( + identities[path] != value for path, value in _EXECUTING_SOURCE_DIGESTS.items() + ): + raise ValueError("executing source identity drift") + _independence(sources) + result = {} + counts = {} + for name, module in (("abstract", abstract), ("concrete", concrete)): + graph = module.build() + _validate_graph(graph, module) + result[f"{name}.aut"] = render_aut(graph) + result[f"{name}.json"] = ( + canonical_json_bytes( + { + "initial": graph.initial, + "states": [asdict(state) for state in graph.states], + "semantic_edges": [list(edge) for edge in graph.edges], + } + ) + + b"\n" + ) + counts[name] = { + "states": len(graph.states), + "transitions": len(graph.edges), + "initial_states": 1, + "initial_state": asdict(graph.states[graph.initial]), + "reachable_phases": sorted({state.phase for state in graph.states}), + } + catalog = load_behavioral_relation_catalog_revision(profile.taxonomy_revision) + manifest = { + "schema": "participant-crossing-model-bundle/v1", + "profile_id": profile.profile_id, + "profile_revision": profile.profile_revision, + "profile_digest": profile.canonical_digest, + "profile_file_digest": digest(read_bytes(root, PROFILE_PATH)), + "projection": "participant-crossing-projection@rev1", + "catalog_revision": profile.taxonomy_revision, + "catalog_digest": canonical_json_digest(catalog.model_dump(mode="json")), + "source_revision": canonical_json_digest(identities), + "source_digests": identities, + "domain_counts": { + key: len(values) + for key, values in profile.parameters.domains.model_dump().items() + }, + "models": counts, + "complete_reachable_fixed_point": True, + "artifact_digests": {key: digest(value) for key, value in result.items()}, + "equivalence_result": "not-established", + "runtime_realization": "not-established", + "limitations": list(profile.limitations), + "explicit_non_claims": list(profile.explicit_non_claims), + } + result["manifest.json"] = canonical_json_bytes(manifest) + b"\n" + if any(len(content) > MAX_BYTES for content in result.values()): + raise ValueError("model bundle exceeds resource limit") + return result + + +def _check_expected(root: Path, expected: dict[str, bytes]) -> None: + target = safe_path(root, OUTPUT_PATH) + if not target.is_dir() or {path.name for path in target.iterdir()} != set(expected): + raise ValueError("model bundle artifact drift") + for name, content in expected.items(): + if read_bytes(root, OUTPUT_PATH + "/" + name) != content: + raise ValueError("model bundle digest or count drift") + + +def check(root: Path) -> None: + _check_expected(root, build_bundle(root)) + + +def publish(root: Path) -> None: + """Publish a new complete directory atomically; never overwrite drift.""" + expected = build_bundle(root) + target = safe_path(root, OUTPUT_PATH) + if target.exists(): + _check_expected(root, expected) + return + target.parent.mkdir(parents=True, exist_ok=True) + with tempfile.TemporaryDirectory( + prefix=".crossing-stage-", dir=target.parent + ) as temporary: + stage = Path(temporary) / "bundle" + stage.mkdir() + for name, content in expected.items(): + with (stage / name).open("xb") as stream: + stream.write(content) + stream.flush() + os.fsync(stream.fileno()) + safe_path(root, OUTPUT_PATH) + os.rename(stage, target) diff --git a/implementations/formal/participant_crossing/graph.py b/implementations/formal/participant_crossing/graph.py new file mode 100644 index 000000000..94b02da22 --- /dev/null +++ b/implementations/formal/participant_crossing/graph.py @@ -0,0 +1,10 @@ +"""Nonsemantic graph storage shared by the independent model exporters.""" + +from dataclasses import dataclass + + +@dataclass(frozen=True) +class Graph: + states: tuple + edges: tuple[tuple[int, str, int], ...] + initial: int = 0 diff --git a/implementations/formal/participant_crossing/ingress.py b/implementations/formal/participant_crossing/ingress.py new file mode 100644 index 000000000..d17376131 --- /dev/null +++ b/implementations/formal/participant_crossing/ingress.py @@ -0,0 +1,57 @@ +"""Bounded repository file access for the offline model producer.""" + +import os +import stat +from pathlib import Path, PurePosixPath + +from tools.policy.common import safe_repo_path + +MAX_BYTES = 2 * 1024 * 1024 + + +def safe_path(root: Path, relative: str) -> Path: + parts = PurePosixPath(relative).parts + if ( + not parts + or len(relative) > 256 + or "\\" in relative + or any(part in {".", ".."} for part in parts) + ): + raise ValueError("unsafe model artifact path") + target = safe_repo_path(root, relative) + if target is None or target != root.resolve() / relative: + raise ValueError("unsafe model artifact path") + cursor = root.resolve() + for part in parts: + cursor /= part + if cursor.is_symlink(): + raise ValueError("unsafe model artifact path") + return target + + +def read_bytes(root: Path, relative: str) -> bytes: + safe_path(root, relative) + directory = os.open(root, os.O_RDONLY | os.O_DIRECTORY) + try: + parts = PurePosixPath(relative).parts + for part in parts[:-1]: + child = os.open( + part, os.O_RDONLY | os.O_DIRECTORY | os.O_NOFOLLOW, dir_fd=directory + ) + os.close(directory) + directory = child + descriptor = os.open( + parts[-1], os.O_RDONLY | os.O_NOFOLLOW | os.O_NONBLOCK, dir_fd=directory + ) + with os.fdopen(descriptor, "rb") as stream: + info = os.fstat(stream.fileno()) + if not stat.S_ISREG(info.st_mode) or info.st_size > MAX_BYTES: + raise ValueError("invalid model artifact file") + content = stream.read(MAX_BYTES + 1) + if len(content) > MAX_BYTES: + raise ValueError("model artifact exceeds byte limit") + return content + except OSError: + raise ValueError("model artifact is unavailable or unsafe") from None + finally: + os.close(directory) diff --git a/implementations/python/packages/raes_contracts/_behavioral_profile_loader.py b/implementations/python/packages/raes_contracts/_behavioral_profile_loader.py new file mode 100644 index 000000000..953653db7 --- /dev/null +++ b/implementations/python/packages/raes_contracts/_behavioral_profile_loader.py @@ -0,0 +1,113 @@ +"""Exact corpus-backed profile loading with bounded regular-file ingress.""" + +from __future__ import annotations + +import os +import stat +from functools import cache +from pathlib import Path +from typing import TYPE_CHECKING + +from raes.identifiers import is_portable_identifier + +if TYPE_CHECKING: + from .behavioral_relation_profiles import BehavioralRelationProfileModel +from .corpus import PROFILES, corpus_family_root +from .json_ingress import parse_bounded_json_object + +_MAX_PROFILE_BYTES = 256 * 1024 +SUPPORTED_BEHAVIORAL_RELATION_PROFILE_IDS = frozenset( + { + "participant-opacity-baseline-v1", + "participant-opacity-runtime-reference-v1", + "participant-opacity-theorem-v1", + "participant-crossing-dpbb-finite-v1", + } +) + + +def behavioral_relation_profiles_root() -> Path: + return corpus_family_root(PROFILES) / "behavioral-relation" + + +def _validate_profile_id(profile_id: str) -> None: + if not is_portable_identifier(profile_id): + raise ValueError("requested behavioral relation profile id must be a portable identifier") + if profile_id not in SUPPORTED_BEHAVIORAL_RELATION_PROFILE_IDS: + raise ValueError("requested behavioral relation profile is unsupported") + + +def behavioral_relation_profile_path(profile_id: str) -> Path: + _validate_profile_id(profile_id) + return behavioral_relation_profiles_root() / f"{profile_id}.json" + + +def load_behavioral_relation_profile_from_path( + profile_id: str, + path: Path, +) -> BehavioralRelationProfileModel: + """Load one trusted profile path after strict bounded JSON ingress.""" + + from .behavioral_relation_profiles import BehavioralRelationProfileModel + + _validate_profile_id(profile_id) + try: + descriptor = os.open(path, os.O_RDONLY | os.O_NOFOLLOW | os.O_NONBLOCK) + with os.fdopen(descriptor, "rb") as stream: + if not stat.S_ISREG(os.fstat(stream.fileno()).st_mode): + raise ValueError("profile must be a regular file") + content = stream.read(_MAX_PROFILE_BYTES + 1) + payload = parse_bounded_json_object( + content, + max_bytes=_MAX_PROFILE_BYTES, + ) + profile = BehavioralRelationProfileModel.model_validate(payload) + except (OSError, ValueError): + raise ValueError("behavioral relation profile JSON or contract is invalid") from None + if profile.profile_id != profile_id: + raise ValueError("behavioral relation profile artifact identity does not match the requested profile") + return profile + + +@cache +def load_behavioral_relation_profile( + profile_id: str, +) -> BehavioralRelationProfileModel: + return load_behavioral_relation_profile_from_path( + profile_id, + behavioral_relation_profile_path(profile_id), + ) + + +_HISTORICAL_PROFILE_PATHS = { + ( + "participant-opacity-baseline-v1", + "sem-231/rev2", + ): behavioral_relation_profiles_root() / "history" / "participant-opacity-baseline-v1-sem-231-rev2.json", + ( + "participant-opacity-runtime-reference-v1", + "sem-231/runtime-rev1", + ): behavioral_relation_profiles_root() + / "history" + / "participant-opacity-runtime-reference-v1-sem-231-runtime-rev1.json", +} + + +@cache +def load_behavioral_relation_profile_revision( + profile_id: str, + profile_revision: str, +) -> BehavioralRelationProfileModel: + """Resolve an exact immutable profile revision for evidence replay.""" + + _validate_profile_id(profile_id) + historical_path = _HISTORICAL_PROFILE_PATHS.get((profile_id, profile_revision)) + if historical_path is not None: + profile = load_behavioral_relation_profile_from_path(profile_id, historical_path) + if profile.profile_revision != profile_revision: + raise ValueError("historical behavioral relation profile revision does not match its registry entry") + return profile + current = load_behavioral_relation_profile(profile_id) + if current.profile_revision == profile_revision: + return current + raise ValueError("requested behavioral relation profile revision is unsupported") diff --git a/implementations/python/packages/raes_contracts/_participant_crossing_profile.py b/implementations/python/packages/raes_contracts/_participant_crossing_profile.py new file mode 100644 index 000000000..9ea9b89ae --- /dev/null +++ b/implementations/python/packages/raes_contracts/_participant_crossing_profile.py @@ -0,0 +1,153 @@ +"""Closed single-operation SEM-232 profile vocabulary and parameters.""" + +from typing import Literal + +from pydantic import Field, StrictInt, model_validator + +from .contracts.base import ContractModel, PrefixedDigestString + +INPUT_CLASSES = ("plain", "transform", "declassify", "unsupported", "forbidden") +VISIBLE = ( + "crossing.request", + "crossing.decision.permit", + "crossing.decision.deny", + "crossing.decision.unsupported", + "crossing.transform", + "crossing.declassify", + "crossing.delivery", + "crossing.observation", + "crossing.replay.reject", + "policy.cut.advance", +) +HIDDEN = ( + "internal.validate", + "internal.resolve-policy-cut", + "internal.resolve-capability", + "internal.prepare-record", + "internal.atomic-commit", +) + + +class CrossingDomainsModel(ContractModel): + participant: tuple[Literal["participant-0"]] + audience: tuple[Literal["audience-0"]] + controller: tuple[Literal["controller-0"]] + episode: tuple[Literal["episode-0"]] + request_id: tuple[Literal["request-0"]] + policy_cut: tuple[Literal["p0"], Literal["p1"]] + input_class: tuple[ + Literal["plain"], Literal["transform"], Literal["declassify"], Literal["unsupported"], Literal["forbidden"] + ] + decision: tuple[ + Literal["none"], + Literal["permit"], + Literal["deny"], + Literal["unsupported"], + Literal["transform"], + Literal["declassify"], + ] + replay: tuple[Literal["fresh"], Literal["same-cut"], Literal["later-cut"]] + delivery: tuple[Literal["none"], Literal["pending"], Literal["delivered"], Literal["withheld"]] + history_head: tuple[Literal["h0"], Literal["h1"], Literal["h2"], Literal["h3"]] + + +class AbstractCrossingCarrierModel(ContractModel): + model_id: Literal["sem-230-participant-crossing-abstract"] + revision: Literal["rev2"] + source_path: Literal["implementations/formal/participant_crossing/abstract.py"] + source_digest: PrefixedDigestString + initial_state_ordinal: StrictInt = Field(ge=0, le=0) + + +class ConcreteCrossingCarrierModel(ContractModel): + model_id: Literal["api-423-run-319-crossing-kernel"] + revision: Literal["rev2"] + source_path: Literal["implementations/formal/participant_crossing/concrete.py"] + source_digest: PrefixedDigestString + initial_state_ordinal: StrictInt = Field(ge=0, le=0) + + +class ParticipantCrossingParametersModel(ContractModel): + kind: Literal["participant-crossing-dpbb/v1"] + domains: CrossingDomainsModel + left: AbstractCrossingCarrierModel + right: ConcreteCrossingCarrierModel + visible_labels: tuple[ + Literal["crossing.request"], + Literal["crossing.decision.permit"], + Literal["crossing.decision.deny"], + Literal["crossing.decision.unsupported"], + Literal["crossing.transform"], + Literal["crossing.declassify"], + Literal["crossing.delivery"], + Literal["crossing.observation"], + Literal["crossing.replay.reject"], + Literal["policy.cut.advance"], + ] + hidden_labels: tuple[ + Literal["internal.validate"], + Literal["internal.resolve-policy-cut"], + Literal["internal.resolve-capability"], + Literal["internal.prepare-record"], + Literal["internal.atomic-commit"], + ] + checker_tau: Literal["internal"] + complete_carrier: Literal[True] + depth_or_sample_bound: None + fresh_operations: StrictInt = Field(ge=1, le=1) + identity_reuse: Literal["excluded"] + order: Literal["sequential-total-order"] + time: Literal["untimed"] + probability: Literal["excluded"] + concurrency: Literal["excluded"] + controller_handoff: Literal["excluded"] + completion: Literal["per-crossing-visible-outcome"] + + @model_validator(mode="after") + def _independent_sources(self): + if self.left.source_digest == self.right.source_digest: + raise ValueError("crossing transition authorities must have independent source identities") + return self + + +def validate_crossing_profile_join(profile) -> None: + expected = { + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": profile.parameters.left.model_id, + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + } + if any(getattr(profile, key) != value for key, value in expected.items()): + raise ValueError("crossing profile identity, projection or carrier does not match its parameters") + + +def crossing_profile_schema_join() -> dict: + """Publish the relation/variant join in the existing profile schema.""" + return { + "if": { + "properties": { + "parameters": {"properties": {"kind": {"const": "participant-crossing-dpbb/v1"}}, "required": ["kind"]} + }, + "required": ["parameters"], + }, + "then": { + "properties": { + key: {"const": value} + for key, value in { + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": "sem-230-participant-crossing-abstract", + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + }.items() + } + }, + "else": {"properties": {"relation_id": {"const": "participant-predicate-opacity"}}}, + } diff --git a/implementations/python/packages/raes_contracts/behavioral_relation_profiles.py b/implementations/python/packages/raes_contracts/behavioral_relation_profiles.py index b9cc540c3..077915f8c 100644 --- a/implementations/python/packages/raes_contracts/behavioral_relation_profiles.py +++ b/implementations/python/packages/raes_contracts/behavioral_relation_profiles.py @@ -2,15 +2,38 @@ from __future__ import annotations -from functools import cache -from pathlib import Path from typing import Annotated, Literal from pydantic import Field, GetJsonSchemaHandler, model_validator from pydantic.json_schema import JsonSchemaValue from pydantic_core import CoreSchema -from raes.identifiers import is_portable_identifier +from ._behavioral_profile_loader import ( + SUPPORTED_BEHAVIORAL_RELATION_PROFILE_IDS as SUPPORTED_BEHAVIORAL_RELATION_PROFILE_IDS, +) +from ._behavioral_profile_loader import ( + behavioral_relation_profile_path as behavioral_relation_profile_path, +) +from ._behavioral_profile_loader import ( + behavioral_relation_profiles_root as behavioral_relation_profiles_root, +) +from ._behavioral_profile_loader import ( + load_behavioral_relation_profile as load_behavioral_relation_profile, +) +from ._behavioral_profile_loader import ( + load_behavioral_relation_profile_from_path as load_behavioral_relation_profile_from_path, +) +from ._behavioral_profile_loader import ( + load_behavioral_relation_profile_revision as load_behavioral_relation_profile_revision, +) +from ._participant_crossing_profile import ( + HIDDEN, + INPUT_CLASSES, + VISIBLE, + ParticipantCrossingParametersModel, + crossing_profile_schema_join, + validate_crossing_profile_join, +) from .canonical import canonical_json_digest from .contracts.base import ( BehavioralTaxonomyRevision, @@ -18,19 +41,8 @@ NonEmptyString, PrefixedDigestString, ) -from .corpus import PROFILES, corpus_family_root -from .json_ingress import parse_bounded_json_object from .versions import BEHAVIORAL_RELATION_PROFILE_SCHEMA_VERSION -_MAX_PROFILE_BYTES = 256 * 1024 -SUPPORTED_BEHAVIORAL_RELATION_PROFILE_IDS = frozenset( - { - "participant-opacity-baseline-v1", - "participant-opacity-runtime-reference-v1", - "participant-opacity-theorem-v1", - } -) - ProfileId = Annotated[ str, Field(pattern=r"^[a-z0-9]+(?:-[a-z0-9]+)*$", max_length=64), @@ -337,7 +349,7 @@ class BehavioralRelationProfileModel(ContractModel): profile_revision: Revision taxonomy_id: Literal["raes-behavioral-relations"] taxonomy_revision: BehavioralTaxonomyRevision - relation_id: Literal["participant-predicate-opacity"] + relation_id: Literal["participant-predicate-opacity", "divergence-preserving-branching-bisimulation"] left_carrier_ref: SafeRef observation_projection_ref: SafeRef observation_projection_revision: Revision @@ -345,7 +357,10 @@ class BehavioralRelationProfileModel(ContractModel): "declared-complete-finite-carrier", "abstract-parameterized-theorem-carrier", ] - parameters: ParticipantPredicateOpacityParametersModel + parameters: Annotated[ + ParticipantPredicateOpacityParametersModel | ParticipantCrossingParametersModel, + Field(discriminator="kind"), + ] source_refs: tuple[BehavioralProfileSourceModel, ...] = Field( min_length=1, max_length=16, @@ -358,13 +373,18 @@ class BehavioralRelationProfileModel(ContractModel): @model_validator(mode="after") def _validate_profile_join(self) -> BehavioralRelationProfileModel: + source_ids = tuple(item.source_ref for item in self.source_refs) + _require_sorted_unique(source_ids, "profile source refs") + if isinstance(self.parameters, ParticipantCrossingParametersModel): + validate_crossing_profile_join(self) + return self + if self.relation_id != "participant-predicate-opacity": + raise ValueError("opacity parameters require the opacity relation") if ( self.parameters.observation.projection_ref != self.observation_projection_ref or self.parameters.observation.projection_revision != self.observation_projection_revision ): raise ValueError("profile observation projection must match the parameter projection") - source_ids = tuple(item.source_ref for item in self.source_refs) - _require_sorted_unique(source_ids, "profile source refs") finite_variant = isinstance(self.parameters.carrier, FiniteOpacityCarrierModel) if finite_variant != (self.finite_analysis_scope == "declared-complete-finite-carrier"): raise ValueError("profile assurance scope must match its carrier variant") @@ -377,7 +397,7 @@ def __get_pydantic_json_schema__( handler: GetJsonSchemaHandler, ) -> JsonSchemaValue: json_schema = handler.resolve_ref_schema(handler(core_schema)) - + json_schema.setdefault("allOf", []).append(crossing_profile_schema_join()) json_schema.setdefault("allOf", []).extend( [ { @@ -401,87 +421,11 @@ def canonical_digest(self) -> str: return canonical_json_digest(self.model_dump(mode="json")) -def behavioral_relation_profiles_root() -> Path: - return corpus_family_root(PROFILES) / "behavioral-relation" - - -def _validate_profile_id(profile_id: str) -> None: - if not is_portable_identifier(profile_id): - raise ValueError("requested behavioral relation profile id must be a portable identifier") - if profile_id not in SUPPORTED_BEHAVIORAL_RELATION_PROFILE_IDS: - raise ValueError(f"requested behavioral relation profile {profile_id!r} is unsupported") - - -def behavioral_relation_profile_path(profile_id: str) -> Path: - _validate_profile_id(profile_id) - return behavioral_relation_profiles_root() / f"{profile_id}.json" - - -def load_behavioral_relation_profile_from_path( - profile_id: str, - path: Path, -) -> BehavioralRelationProfileModel: - """Load one trusted profile path after strict bounded JSON ingress.""" - - _validate_profile_id(profile_id) - try: - payload = parse_bounded_json_object( - path.read_bytes(), - max_bytes=_MAX_PROFILE_BYTES, - ) - profile = BehavioralRelationProfileModel.model_validate(payload) - except (OSError, ValueError): - raise ValueError("behavioral relation profile JSON or contract is invalid") from None - if profile.profile_id != profile_id: - raise ValueError("behavioral relation profile artifact identity does not match the requested profile") - return profile - - -@cache -def load_behavioral_relation_profile( - profile_id: str, -) -> BehavioralRelationProfileModel: - return load_behavioral_relation_profile_from_path( - profile_id, - behavioral_relation_profile_path(profile_id), - ) - - -_HISTORICAL_PROFILE_PATHS = { - ( - "participant-opacity-baseline-v1", - "sem-231/rev2", - ): behavioral_relation_profiles_root() / "history" / "participant-opacity-baseline-v1-sem-231-rev2.json", - ( - "participant-opacity-runtime-reference-v1", - "sem-231/runtime-rev1", - ): behavioral_relation_profiles_root() - / "history" - / "participant-opacity-runtime-reference-v1-sem-231-runtime-rev1.json", -} - - -@cache -def load_behavioral_relation_profile_revision( - profile_id: str, - profile_revision: str, -) -> BehavioralRelationProfileModel: - """Resolve an exact immutable profile revision for evidence replay.""" - - _validate_profile_id(profile_id) - historical_path = _HISTORICAL_PROFILE_PATHS.get((profile_id, profile_revision)) - if historical_path is not None: - profile = load_behavioral_relation_profile_from_path(profile_id, historical_path) - if profile.profile_revision != profile_revision: - raise ValueError("historical behavioral relation profile revision does not match its registry entry") - return profile - current = load_behavioral_relation_profile(profile_id) - if current.profile_revision == profile_revision: - return current - raise ValueError("requested behavioral relation profile revision is unsupported") - - __all__ = [ + "HIDDEN", + "INPUT_CLASSES", + "VISIBLE", + "ParticipantCrossingParametersModel", "ActiveOpacityStrategyModel", "AbstractOpacityCarrierModel", "BehavioralRelationProfileModel", diff --git a/implementations/python/packages/raes_contracts/behavioral_relations.py b/implementations/python/packages/raes_contracts/behavioral_relations.py index 1200559f8..e331c71c7 100644 --- a/implementations/python/packages/raes_contracts/behavioral_relations.py +++ b/implementations/python/packages/raes_contracts/behavioral_relations.py @@ -394,6 +394,12 @@ def _validate_binding_profile( ) -> None: """Join a required profile to the exact catalog and claim coordinates.""" + from .behavioral_relation_profiles import ParticipantCrossingParametersModel + + if isinstance(profile.parameters, ParticipantCrossingParametersModel): + if binding.right_carrier_ref != profile.parameters.right.model_id: + raise ValueError("behavioral claim binding right carrier does not match the resolved profile") + expected = ( ( profile.profile_id, diff --git a/implementations/python/packages/raes_processor/participant_opacity/_model_check_admission.py b/implementations/python/packages/raes_processor/participant_opacity/_model_check_admission.py index 8aab36604..cbbd54a0a 100644 --- a/implementations/python/packages/raes_processor/participant_opacity/_model_check_admission.py +++ b/implementations/python/packages/raes_processor/participant_opacity/_model_check_admission.py @@ -9,6 +9,7 @@ ActiveOpacityStrategyModel, BehavioralRelationProfileModel, CoalitionOpacityObserverModel, + ParticipantPredicateOpacityParametersModel, ) from raes_contracts.behavioral_relations import ( BehavioralRelationCatalogModel, @@ -101,6 +102,8 @@ def validate_admission( ) -> None: if request.analysis_profile != ANALYSIS_PROFILE: raise ParticipantOpacityOperationalError("unknown participant-opacity model-check profile") + if not isinstance(profile.parameters, ParticipantPredicateOpacityParametersModel): + raise ParticipantOpacityOperationalError("expected an opacity parameter profile") if request.catalog_digest != _catalog_digest(catalog): raise ParticipantOpacityOperationalError("behavioral catalog digest does not match the transition model") if ( diff --git a/implementations/python/packages/raes_processor/participant_opacity/_service.py b/implementations/python/packages/raes_processor/participant_opacity/_service.py index 7b5aaf354..d9df07312 100644 --- a/implementations/python/packages/raes_processor/participant_opacity/_service.py +++ b/implementations/python/packages/raes_processor/participant_opacity/_service.py @@ -10,6 +10,7 @@ ActiveOpacityStrategyModel, BehavioralRelationProfileModel, CoalitionOpacityObserverModel, + ParticipantPredicateOpacityParametersModel, load_behavioral_relation_profile_revision, ) from raes_contracts.behavioral_relations import ( @@ -72,6 +73,8 @@ def _validate_profile_admission( ) -> None: if request.analysis_profile != ANALYSIS_PROFILE: raise ParticipantOpacityOperationalError("unknown opacity analysis profile") + if not isinstance(profile.parameters, ParticipantPredicateOpacityParametersModel): + raise ParticipantOpacityOperationalError("expected an opacity parameter profile") if ( request.profile_id != profile.profile_id or request.profile_revision != profile.profile_revision diff --git a/implementations/python/tests/crossing_model_fixtures.py b/implementations/python/tests/crossing_model_fixtures.py new file mode 100644 index 000000000..e38d0429d --- /dev/null +++ b/implementations/python/tests/crossing_model_fixtures.py @@ -0,0 +1,88 @@ +"""Synthetic complete profile and malformed variants for issue 971.""" + +from pathlib import Path + +ROOT = Path(__file__).resolve().parents[3] + + +def profile_payload(): + return { + "schema_version": "behavioral-relation-profile/v1", + "profile_id": "participant-crossing-dpbb-finite-v1", + "profile_revision": "rev2", + "taxonomy_id": "raes-behavioral-relations", + "taxonomy_revision": "rev8", + "relation_id": "divergence-preserving-branching-bisimulation", + "left_carrier_ref": "sem-230-participant-crossing-abstract", + "observation_projection_ref": "participant-crossing-projection", + "observation_projection_revision": "rev1", + "finite_analysis_scope": "declared-complete-finite-carrier", + "parameters": { + "kind": "participant-crossing-dpbb/v1", + "domains": { + "participant": ["participant-0"], + "audience": ["audience-0"], + "controller": ["controller-0"], + "episode": ["episode-0"], + "request_id": ["request-0"], + "policy_cut": ["p0", "p1"], + "input_class": ["plain", "transform", "declassify", "unsupported", "forbidden"], + "decision": ["none", "permit", "deny", "unsupported", "transform", "declassify"], + "replay": ["fresh", "same-cut", "later-cut"], + "delivery": ["none", "pending", "delivered", "withheld"], + "history_head": ["h0", "h1", "h2", "h3"], + }, + "left": { + "model_id": "sem-230-participant-crossing-abstract", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/abstract.py", + "source_digest": "sha256:" + "a" * 64, + "initial_state_ordinal": 0, + }, + "right": { + "model_id": "api-423-run-319-crossing-kernel", + "revision": "rev2", + "source_path": "implementations/formal/participant_crossing/concrete.py", + "source_digest": "sha256:" + "b" * 64, + "initial_state_ordinal": 0, + }, + "visible_labels": [ + "crossing.request", + "crossing.decision.permit", + "crossing.decision.deny", + "crossing.decision.unsupported", + "crossing.transform", + "crossing.declassify", + "crossing.delivery", + "crossing.observation", + "crossing.replay.reject", + "policy.cut.advance", + ], + "hidden_labels": [ + "internal.validate", + "internal.resolve-policy-cut", + "internal.resolve-capability", + "internal.prepare-record", + "internal.atomic-commit", + ], + "checker_tau": "internal", + "complete_carrier": True, + "depth_or_sample_bound": None, + "fresh_operations": 1, + "identity_reuse": "excluded", + "order": "sequential-total-order", + "time": "untimed", + "probability": "excluded", + "concurrency": "excluded", + "controller_handoff": "excluded", + "completion": "per-crossing-visible-outcome", + }, + "source_refs": [ + { + "source_ref": "specs/formal/participant-semantics/participant-crossing-models.md", + "source_digest": "sha256:" + "c" * 64, + } + ], + "limitations": ["One fresh operation and retries; no identity recycling."], + "explicit_non_claims": ["No equivalence or live-runtime result is established by construction."], + } diff --git a/implementations/python/tests/test_issue_971_crossing_export.py b/implementations/python/tests/test_issue_971_crossing_export.py new file mode 100644 index 000000000..05516e5f0 --- /dev/null +++ b/implementations/python/tests/test_issue_971_crossing_export.py @@ -0,0 +1,176 @@ +"""Exporter ingress, independence, drift and complete publication.""" + +import hashlib +import json +import shutil + +import pytest +from crossing_model_fixtures import ROOT, profile_payload +from implementations.formal.participant_crossing import abstract, concrete, export + + +def workspace(tmp_path): + for name in export.SOURCE_PATHS: + destination = tmp_path / name + destination.parent.mkdir(parents=True, exist_ok=True) + shutil.copyfile(ROOT / name, destination) + payload = profile_payload() + for carrier in (payload["parameters"]["left"], payload["parameters"]["right"]): + carrier["source_digest"] = ( + "sha256:" + hashlib.sha256((tmp_path / carrier["source_path"]).read_bytes()).hexdigest() + ) + for source in payload["source_refs"]: + source["source_digest"] = "sha256:" + hashlib.sha256((tmp_path / source["source_ref"]).read_bytes()).hexdigest() + path = tmp_path / export.PROFILE_PATH + path.parent.mkdir(parents=True, exist_ok=True) + path.write_text(json.dumps(payload)) + return tmp_path + + +def test_export_readback_and_counts(tmp_path): + root = workspace(tmp_path) + bundle = export.build_bundle(root) + manifest = json.loads(bundle["manifest.json"]) + for name, module in (("abstract", abstract), ("concrete", concrete)): + initial, states, edges = export.parse_aut(bundle[f"{name}.aut"]) + graph = module.build() + assert initial == 0 and states == len(graph.states) and len(edges) == len(graph.edges) + assert manifest["models"][name]["states"] == states + assert manifest["models"][name]["transitions"] == len(edges) + assert manifest["models"][name]["initial_states"] == 1 + assert ( + manifest["artifact_digests"][f"{name}.aut"] == "sha256:" + hashlib.sha256(bundle[f"{name}.aut"]).hexdigest() + ) + state_map = json.loads(bundle[f"{name}.json"]) + assert len(state_map["states"]) == states + assert len(state_map["semantic_edges"]) == len(edges) + assert manifest["domain_counts"]["input_class"] == 5 + assert manifest["domain_counts"]["history_head"] == 4 + assert manifest["equivalence_result"] == "not-established" + assert export.build_bundle(root) == bundle + export.publish(root) + export.check(root) + export.publish(root) # identical publication is idempotent + + +@pytest.mark.parametrize("drift", ["source", "profile", "artifact", "counts"]) +def test_drift_fails_without_replacing_published_bundle(tmp_path, drift): + root = workspace(tmp_path) + export.publish(root) + output = root / export.OUTPUT_PATH + if drift == "source": + path = root / "implementations/formal/participant_crossing/abstract.py" + path.write_bytes(path.read_bytes() + b"\n# source drift\n") + elif drift == "profile": + path = root / export.PROFILE_PATH + data = json.loads(path.read_bytes()) + data["limitations"] = ["Changed interpretation"] + path.write_text(json.dumps(data)) + elif drift == "artifact": + (output / "abstract.aut").write_bytes(b"des (0, 0, 1)\n") + else: + data = json.loads((output / "manifest.json").read_bytes()) + data["models"]["abstract"]["states"] = 1 + (output / "manifest.json").write_text(json.dumps(data)) + before = {path.name: path.read_bytes() for path in output.iterdir()} + with pytest.raises(ValueError, match="drift"): + export.check(root) + with pytest.raises(ValueError, match="drift"): + export.publish(root) + assert {path.name: path.read_bytes() for path in output.iterdir()} == before + + +def test_shared_transition_authority_is_rejected(tmp_path, monkeypatch): + root = workspace(tmp_path) + monkeypatch.setattr(concrete, "successors", abstract.successors) + with pytest.raises(ValueError, match="independent"): + export.build_bundle(root) + + +def test_rebound_source_cannot_describe_different_executing_code(tmp_path): + root = workspace(tmp_path) + path = root / "implementations/formal/participant_crossing/abstract.py" + path.write_bytes(path.read_bytes() + b"\n# different source identity\n") + profile_path = root / export.PROFILE_PATH + payload = json.loads(profile_path.read_bytes()) + payload["parameters"]["left"]["source_digest"] = export.digest(path.read_bytes()) + for source in payload["source_refs"]: + if source["source_ref"] == path.relative_to(root).as_posix(): + source["source_digest"] = export.digest(path.read_bytes()) + profile_path.write_text(json.dumps(payload)) + with pytest.raises(ValueError, match="executing source"): + export.publish(root) + assert not (root / export.OUTPUT_PATH).exists() + + +@pytest.mark.parametrize( + "value", + [ + b'des (0, 1, 1)\n(0,"tau",0)\n', + b"des (0, 0, 0)\n", + b'des (0, 1, 1)\n(0,"crossing.request",1)\n', + b'des (0, 2, 1)\n(0,"crossing.request",0)\n(0,"crossing.request",0)\n', + ], +) +def test_invalid_aut_is_rejected(value): + with pytest.raises(ValueError): + export.parse_aut(value) + + +def test_failed_generation_publishes_nothing(tmp_path, monkeypatch): + root = workspace(tmp_path) + + def exhausted(): + raise ValueError("resource limit exceeded") + + monkeypatch.setattr(concrete, "build", exhausted) + with pytest.raises(ValueError): + export.publish(root) + assert not (root / export.OUTPUT_PATH).exists() + + +def test_truncated_graph_is_rejected(tmp_path, monkeypatch): + from dataclasses import replace + + root = workspace(tmp_path) + graph = abstract.build() + monkeypatch.setattr(abstract, "build", lambda: replace(graph, edges=graph.edges[:-1])) + with pytest.raises(ValueError, match="closure"): + export.publish(root) + assert not (root / export.OUTPUT_PATH).exists() + + +def test_symlink_input_and_output_are_rejected(tmp_path): + root = workspace(tmp_path / "root") + path = root / export.PROFILE_PATH + path.unlink() + path.symlink_to(tmp_path / "unread-target") + with pytest.raises(ValueError): + export.build_bundle(root) + + +def test_published_repository_bundle_matches_sources(): + export.check(ROOT) + + +def test_symlink_output_cannot_publish_outside_root(tmp_path): + root = workspace(tmp_path / "root") + outside = tmp_path / "outside" + outside.mkdir() + target = root / export.OUTPUT_PATH + target.parent.mkdir(parents=True, exist_ok=True) + target.symlink_to(outside, target_is_directory=True) + with pytest.raises(ValueError): + export.publish(root) + assert list(outside.iterdir()) == [] + + +def test_cli_failure_does_not_echo_rejected_values(monkeypatch, capsys): + from implementations.formal.participant_crossing import __main__ + + def fail(_root): + raise ValueError("synthetic-private-value") + + monkeypatch.setattr(export, "check", fail) + assert __main__.main([]) == 1 + assert capsys.readouterr().err == "participant-crossing model export failed validation\n" diff --git a/implementations/python/tests/test_issue_971_crossing_models.py b/implementations/python/tests/test_issue_971_crossing_models.py new file mode 100644 index 000000000..1c19c8e77 --- /dev/null +++ b/implementations/python/tests/test_issue_971_crossing_models.py @@ -0,0 +1,105 @@ +"""Complete single-operation crossing models, independently constructed.""" + +from dataclasses import replace + +import pytest +from implementations.formal.participant_crossing import abstract, concrete + + +def finish(module, state): + labels = [] + visited = set() + while state.phase != "terminal": + assert state not in visited, "crossing must make finite progress" + visited.add(state) + edges = module.successors(state) + assert len(edges) == 1 + label, state = edges[0] + labels.append(label) + return labels, state + + +@pytest.mark.parametrize("module", [abstract, concrete]) +@pytest.mark.parametrize("cut", ["p0", "p1"]) +@pytest.mark.parametrize("input_class", ["plain", "transform", "declassify", "unsupported", "forbidden"]) +def test_policy_sequences_and_replay(module, cut, input_class): + start = replace(module.INITIAL, cut=cut) + requests = [(label, target) for label, target in module.successors(start) if label == "crossing.request"] + offered = next(target for _, target in requests if target.intent[1] == input_class) + labels, terminal = finish(module, offered) + visible = [label for label in labels if not label.startswith("internal.")] + if input_class == "unsupported": + expected = ["crossing.decision.unsupported"] + elif input_class == "forbidden" or (input_class == "declassify" and cut == "p0"): + expected = ["crossing.decision.deny"] + else: + expected = ["crossing.decision.permit"] + if input_class != "plain": + expected.append(f"crossing.{input_class}") + expected.extend(["crossing.delivery", "crossing.observation"]) + assert visible == expected + assert terminal.last == ("request-0", cut, terminal.decision) + replay = next(target for label, target in module.successors(terminal) if label == "crossing.request") + replay_labels, repeated = finish(module, replay) + assert [label for label in replay_labels if not label.startswith("internal.")] == expected + assert repeated.last == terminal.last + if module is concrete: + assert terminal.head == repeated.head == "h1" + assert "internal.atomic-commit" not in replay_labels + if cut == "p0": + advanced = next(target for label, target in module.successors(terminal) if label == "policy.cut.advance") + stale = next(target for label, target in module.successors(advanced) if label == "crossing.request") + rejected_labels, rejected = finish(module, stale) + assert [label for label in rejected_labels if not label.startswith("internal.")] == ["crossing.replay.reject"] + assert rejected.last == terminal.last + if module is concrete: + assert rejected.head == terminal.head + + +@pytest.mark.parametrize("module", [abstract, concrete]) +def test_exhaustive_reachable_closure(module): + graph = module.build() + assert graph.states[graph.initial] == module.INITIAL + assert len(graph.states) == len(set(graph.states)) + index = {state: i for i, state in enumerate(graph.states)} + expected = { + (index[state], label, index[target]) for state in graph.states for label, target in module.successors(state) + } + assert set(graph.edges) == expected + reachable = {graph.initial} + while True: + expanded = reachable | {target for source, _, target in graph.edges if source in reachable} + if expanded == reachable: + break + reachable = expanded + assert reachable == set(range(len(graph.states))) + assert all(module.successors(state) for state in graph.states) + assert module.build() == graph + + +def test_atomic_refusal_and_hidden_progress(): + graph = concrete.build() + for source, label, target in graph.edges: + before, after = graph.states[source], graph.states[target] + if label.startswith("internal."): + assert concrete.internal_rank(before) > concrete.internal_rank(after) + if before.head != after.head: + assert label == "internal.atomic-commit" + assert before.head == "h0" and after.head == "h1" + assert before.last is None and after.last is not None + if before.phase == "preparing-record" and before.intent[3] == "fresh": + assert before.head == "h0" and before.last is None + + +@pytest.mark.parametrize("module", [abstract, concrete]) +def test_resource_limit_fails_instead_of_returning_partial_graph(module): + with pytest.raises(ValueError, match="resource limit"): + module.build(max_states=1) + + +@pytest.mark.parametrize("module", [abstract, concrete]) +def test_transition_enumeration_order_does_not_change_export(module, monkeypatch): + expected = module.build() + original = module.successors + monkeypatch.setattr(module, "successors", lambda state: list(reversed(original(state)))) + assert module.build() == expected diff --git a/implementations/python/tests/test_issue_971_crossing_profile.py b/implementations/python/tests/test_issue_971_crossing_profile.py new file mode 100644 index 000000000..68e428259 --- /dev/null +++ b/implementations/python/tests/test_issue_971_crossing_profile.py @@ -0,0 +1,202 @@ +"""Admission of closed binary profiles and preservation of unary profiles.""" + +from copy import deepcopy + +import pytest +from crossing_model_fixtures import profile_payload +from raes_contracts.behavioral_relation_profiles import BehavioralRelationProfileModel +from raes_contracts.behavioral_relations import ( + load_behavioral_relation_catalog_revision, + validate_behavioral_claim_binding, +) +from raes_contracts.contracts.base import BehavioralClaimBindingModel + + +def test_admit_complete_profile(): + payload = profile_payload() + profile = BehavioralRelationProfileModel.model_validate(payload) + assert profile.model_dump(mode="json") == payload + + +@pytest.mark.parametrize( + "name,valid", + [ + ("valid/participant-crossing.json", True), + ("invalid/incomplete-crossing-domain.json", False), + ("invalid/overlapping-crossing-labels.json", False), + ("invalid/shared-crossing-authority.json", False), + ], +) +def test_published_crossing_fixtures(name, valid): + import json + + from crossing_model_fixtures import ROOT + from raes_conformance.conformance import _fixture_case_diagnostics + + payload = json.loads((ROOT / "contracts/fixtures/profiles/behavioral-relation-profile-v1" / name).read_bytes()) + diagnostics = _fixture_case_diagnostics("behavioral-relation-profile-v1", payload) + assert (not diagnostics) == valid + + +def test_profile_loader_rejects_symlink(tmp_path): + import json + + from raes_contracts.behavioral_relation_profiles import load_behavioral_relation_profile_from_path + + target = tmp_path / "profile.json" + target.write_text(json.dumps(profile_payload())) + link = tmp_path / "link.json" + link.symlink_to(target) + with pytest.raises(ValueError, match="invalid"): + load_behavioral_relation_profile_from_path("participant-crossing-dpbb-finite-v1", link) + + +@pytest.mark.parametrize( + "mutation", + [ + "missing-domain", + "truncated-inputs", + "sample", + "incomplete", + "duplicate-visible", + "overlap", + "native-tau", + "same-authority", + "same-source", + "unsafe-path", + "unsafe-id", + "long-id", + "bool-ordinal", + "wrong-left", + "wrong-relation", + "wrong-projection", + "wrong-revision", + ], +) +def test_reject_incomplete_or_unsafe_profile(mutation): + payload = deepcopy(profile_payload()) + params = payload["parameters"] + if mutation == "missing-domain": + del params["domains"]["audience"] + elif mutation == "truncated-inputs": + params["domains"]["input_class"].pop() + elif mutation == "sample": + params["depth_or_sample_bound"] = 2 + elif mutation == "incomplete": + params["complete_carrier"] = False + elif mutation == "duplicate-visible": + params["visible_labels"].append("crossing.request") + elif mutation == "overlap": + params["hidden_labels"][0] = "crossing.request" + elif mutation == "native-tau": + params["visible_labels"][0] = "tau" + elif mutation == "same-authority": + params["right"] = deepcopy(params["left"]) + elif mutation == "same-source": + params["right"]["source_digest"] = params["left"]["source_digest"] + elif mutation == "unsafe-path": + params["left"]["source_path"] = "../../private" + elif mutation in {"unsafe-id", "long-id"}: + params["left"]["model_id"] = "../unsafe" if mutation == "unsafe-id" else "x" * 500 + elif mutation == "bool-ordinal": + params["left"]["initial_state_ordinal"] = False + elif mutation == "wrong-left": + payload["left_carrier_ref"] = "different-carrier" + elif mutation == "wrong-relation": + payload["relation_id"] = "participant-predicate-opacity" + elif mutation == "wrong-projection": + payload["observation_projection_revision"] = "rev2" + else: + payload["profile_revision"] = "rev1" + with pytest.raises(ValueError): + BehavioralRelationProfileModel.model_validate(payload) + + +def crossing_binding(profile): + return BehavioralClaimBindingModel( + taxonomy_id=profile.taxonomy_id, + taxonomy_revision=profile.taxonomy_revision, + relation_id=profile.relation_id, + subject="Synthetic binding validation; no equivalence result.", + left_carrier_ref=profile.left_carrier_ref, + right_carrier_ref=profile.parameters.right.model_id, + observation_projection_ref=profile.observation_projection_ref, + observation_projection_revision=profile.observation_projection_revision, + relation_parameter_profile_ref=profile.profile_id, + relation_parameter_profile_revision=profile.profile_revision, + quantifier_scope="finite-cases", + evidence_scope="structural", + assurance_axis="definition", + evidence_boundary="Synthetic contract fixture only.", + assurance_status="defined", + limitations=["No comparison executed."], + explicit_non_claims=["No equivalence result."], + ) + + +def test_binary_binding_checks_both_carriers(): + profile = BehavioralRelationProfileModel.model_validate(profile_payload()) + binding = crossing_binding(profile) + catalog = load_behavioral_relation_catalog_revision("rev8") + validate_behavioral_claim_binding(binding, catalog=catalog, profile=profile) + with pytest.raises(ValueError, match="right carrier"): + validate_behavioral_claim_binding( + binding.model_copy(update={"right_carrier_ref": "wrong"}), catalog=catalog, profile=profile + ) + + +def test_opacity_consumers_reject_binary_profile_before_accessing_parameters(): + from types import SimpleNamespace + + from raes_contracts.participant_opacity_runtime import validate_participant_opacity_runtime_enforcement + from raes_processor.participant_opacity import ParticipantOpacityOperationalError, _model_check_admission, _service + from test_issue_964_participant_opacity_runtime import _binding, _support + + profile = BehavioralRelationProfileModel.model_validate(profile_payload()) + request = SimpleNamespace(analysis_profile=_service.ANALYSIS_PROFILE, profile_id="participant-opacity-baseline-v1") + with pytest.raises(ParticipantOpacityOperationalError, match="opacity parameter profile"): + _service._validate_profile_admission(request, profile) + catalog = load_behavioral_relation_catalog_revision("rev8") + request.analysis_profile = _model_check_admission.ANALYSIS_PROFILE + from raes_contracts.canonical import canonical_json_digest + + request.catalog_digest = canonical_json_digest(catalog.model_dump(mode="json")) + with pytest.raises(ParticipantOpacityOperationalError, match="opacity parameter profile"): + _model_check_admission.validate_admission(request, profile, catalog) + with pytest.raises(ValueError, match="profile"): + validate_participant_opacity_runtime_enforcement( + _binding(), + support=_support(), + participant_address="participant-0", + audience_scope_ref="audience-0", + profile=profile, + ) + + +@pytest.mark.parametrize("consumer", ["analysis", "model-check"]) +def test_opacity_rejects_crossing_profile_with_matching_claim_and_coordinates(consumer): + from types import SimpleNamespace + + from raes_contracts.canonical import canonical_json_digest + from raes_processor.participant_opacity import ParticipantOpacityOperationalError, _model_check_admission, _service + + profile = BehavioralRelationProfileModel.model_validate(profile_payload()) + catalog = load_behavioral_relation_catalog_revision("rev8") + request = SimpleNamespace( + analysis_profile=_service.ANALYSIS_PROFILE + if consumer == "analysis" + else _model_check_admission.ANALYSIS_PROFILE, + profile_id=profile.profile_id, + profile_revision=profile.profile_revision, + profile_digest=profile.canonical_digest, + claim=crossing_binding(profile), + catalog_digest=canonical_json_digest(catalog.model_dump(mode="json")), + assumptions=None, + declared_counts=None, + ) + with pytest.raises(ParticipantOpacityOperationalError, match="opacity parameter profile"): + if consumer == "analysis": + _service._validate_profile_admission(request, profile) + _service._validate_profile_domains(request, profile) + else: + _model_check_admission.validate_admission(request, profile, catalog) diff --git a/specs/formal/participant-semantics/crossing-models/rev2/abstract.aut b/specs/formal/participant-semantics/crossing-models/rev2/abstract.aut new file mode 100644 index 000000000..084c6a72c --- /dev/null +++ b/specs/formal/participant-semantics/crossing-models/rev2/abstract.aut @@ -0,0 +1,108 @@ +des (0, 107, 88) +(0,"crossing.request",1) +(0,"crossing.request",2) +(0,"crossing.request",3) +(0,"crossing.request",4) +(0,"crossing.request",5) +(0,"policy.cut.advance",6) +(1,"crossing.decision.deny",7) +(2,"crossing.decision.deny",8) +(3,"crossing.decision.permit",9) +(4,"crossing.decision.permit",10) +(5,"crossing.decision.unsupported",11) +(6,"crossing.request",12) +(6,"crossing.request",13) +(6,"crossing.request",14) +(6,"crossing.request",15) +(6,"crossing.request",16) +(7,"crossing.request",17) +(7,"policy.cut.advance",18) +(8,"crossing.request",19) +(8,"policy.cut.advance",20) +(9,"crossing.delivery",21) +(10,"crossing.transform",22) +(11,"crossing.request",23) +(11,"policy.cut.advance",24) +(12,"crossing.decision.permit",25) +(13,"crossing.decision.deny",26) +(14,"crossing.decision.permit",27) +(15,"crossing.decision.permit",28) +(16,"crossing.decision.unsupported",29) +(17,"crossing.decision.deny",30) +(18,"crossing.request",31) +(19,"crossing.decision.deny",32) +(20,"crossing.request",33) +(21,"crossing.observation",34) +(22,"crossing.delivery",35) +(23,"crossing.decision.unsupported",36) +(24,"crossing.request",37) +(25,"crossing.declassify",38) +(26,"crossing.request",39) +(27,"crossing.delivery",40) +(28,"crossing.transform",41) +(29,"crossing.request",42) +(30,"crossing.request",17) +(30,"policy.cut.advance",43) +(31,"crossing.replay.reject",44) +(32,"crossing.request",19) +(32,"policy.cut.advance",45) +(33,"crossing.replay.reject",46) +(34,"crossing.request",47) +(34,"policy.cut.advance",48) +(35,"crossing.observation",49) +(36,"crossing.request",23) +(36,"policy.cut.advance",50) +(37,"crossing.replay.reject",51) +(38,"crossing.delivery",52) +(39,"crossing.decision.deny",53) +(40,"crossing.observation",54) +(41,"crossing.delivery",55) +(42,"crossing.decision.unsupported",56) +(43,"crossing.request",31) +(44,"crossing.request",31) +(45,"crossing.request",33) +(46,"crossing.request",33) +(47,"crossing.decision.permit",57) +(48,"crossing.request",58) +(49,"crossing.request",59) +(49,"policy.cut.advance",60) +(50,"crossing.request",37) +(51,"crossing.request",37) +(52,"crossing.observation",61) +(53,"crossing.request",39) +(54,"crossing.request",62) +(55,"crossing.observation",63) +(56,"crossing.request",42) +(57,"crossing.delivery",64) +(58,"crossing.replay.reject",65) +(59,"crossing.decision.permit",66) +(60,"crossing.request",67) +(61,"crossing.request",68) +(62,"crossing.decision.permit",69) +(63,"crossing.request",70) +(64,"crossing.observation",71) +(65,"crossing.request",58) +(66,"crossing.transform",72) +(67,"crossing.replay.reject",73) +(68,"crossing.decision.permit",74) +(69,"crossing.delivery",75) +(70,"crossing.decision.permit",76) +(71,"crossing.request",47) +(71,"policy.cut.advance",77) +(72,"crossing.delivery",78) +(73,"crossing.request",67) +(74,"crossing.declassify",79) +(75,"crossing.observation",80) +(76,"crossing.transform",81) +(77,"crossing.request",58) +(78,"crossing.observation",82) +(79,"crossing.delivery",83) +(80,"crossing.request",62) +(81,"crossing.delivery",84) +(82,"crossing.request",59) +(82,"policy.cut.advance",85) +(83,"crossing.observation",86) +(84,"crossing.observation",87) +(85,"crossing.request",67) +(86,"crossing.request",68) +(87,"crossing.request",70) diff --git a/specs/formal/participant-semantics/crossing-models/rev2/abstract.json b/specs/formal/participant-semantics/crossing-models/rev2/abstract.json new file mode 100644 index 000000000..5c1f1f13b --- /dev/null +++ b/specs/formal/participant-semantics/crossing-models/rev2/abstract.json @@ -0,0 +1 @@ +{"initial":0,"semantic_edges":[[0,"crossing.request",1],[0,"crossing.request",2],[0,"crossing.request",3],[0,"crossing.request",4],[0,"crossing.request",5],[0,"policy.cut.advance",6],[1,"crossing.decision.deny",7],[2,"crossing.decision.deny",8],[3,"crossing.decision.permit",9],[4,"crossing.decision.permit",10],[5,"crossing.decision.unsupported",11],[6,"crossing.request",12],[6,"crossing.request",13],[6,"crossing.request",14],[6,"crossing.request",15],[6,"crossing.request",16],[7,"crossing.request",17],[7,"policy.cut.advance",18],[8,"crossing.request",19],[8,"policy.cut.advance",20],[9,"crossing.delivery",21],[10,"crossing.transform",22],[11,"crossing.request",23],[11,"policy.cut.advance",24],[12,"crossing.decision.permit",25],[13,"crossing.decision.deny",26],[14,"crossing.decision.permit",27],[15,"crossing.decision.permit",28],[16,"crossing.decision.unsupported",29],[17,"crossing.decision.deny",30],[18,"crossing.request",31],[19,"crossing.decision.deny",32],[20,"crossing.request",33],[21,"crossing.observation",34],[22,"crossing.delivery",35],[23,"crossing.decision.unsupported",36],[24,"crossing.request",37],[25,"crossing.declassify",38],[26,"crossing.request",39],[27,"crossing.delivery",40],[28,"crossing.transform",41],[29,"crossing.request",42],[30,"crossing.request",17],[30,"policy.cut.advance",43],[31,"crossing.replay.reject",44],[32,"crossing.request",19],[32,"policy.cut.advance",45],[33,"crossing.replay.reject",46],[34,"crossing.request",47],[34,"policy.cut.advance",48],[35,"crossing.observation",49],[36,"crossing.request",23],[36,"policy.cut.advance",50],[37,"crossing.replay.reject",51],[38,"crossing.delivery",52],[39,"crossing.decision.deny",53],[40,"crossing.observation",54],[41,"crossing.delivery",55],[42,"crossing.decision.unsupported",56],[43,"crossing.request",31],[44,"crossing.request",31],[45,"crossing.request",33],[46,"crossing.request",33],[47,"crossing.decision.permit",57],[48,"crossing.request",58],[49,"crossing.request",59],[49,"policy.cut.advance",60],[50,"crossing.request",37],[51,"crossing.request",37],[52,"crossing.observation",61],[53,"crossing.request",39],[54,"crossing.request",62],[55,"crossing.observation",63],[56,"crossing.request",42],[57,"crossing.delivery",64],[58,"crossing.replay.reject",65],[59,"crossing.decision.permit",66],[60,"crossing.request",67],[61,"crossing.request",68],[62,"crossing.decision.permit",69],[63,"crossing.request",70],[64,"crossing.observation",71],[65,"crossing.request",58],[66,"crossing.transform",72],[67,"crossing.replay.reject",73],[68,"crossing.decision.permit",74],[69,"crossing.delivery",75],[70,"crossing.decision.permit",76],[71,"crossing.request",47],[71,"policy.cut.advance",77],[72,"crossing.delivery",78],[73,"crossing.request",67],[74,"crossing.declassify",79],[75,"crossing.observation",80],[76,"crossing.transform",81],[77,"crossing.request",58],[78,"crossing.observation",82],[79,"crossing.delivery",83],[80,"crossing.request",62],[81,"crossing.delivery",84],[82,"crossing.request",59],[82,"policy.cut.advance",85],[83,"crossing.observation",86],[84,"crossing.observation",87],[85,"crossing.request",67],[86,"crossing.request",68],[87,"crossing.request",70]],"states":[{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","declassify","p0","fresh"],"last":null,"phase":"offered"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","forbidden","p0","fresh"],"last":null,"phase":"offered"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"offered"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"offered"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","unsupported","p0","fresh"],"last":null,"phase":"offered"},{"cut":"p1","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},{"cut":"p0","decision":"deny","delivery":"withheld","intent":["request-0","declassify","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p0","decision":"deny","delivery":"withheld","intent":["request-0","forbidden","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p0","decision":"permit","delivery":"pending","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"decided"},{"cut":"p0","decision":"transform","delivery":"none","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"decided"},{"cut":"p0","decision":"unsupported","delivery":"withheld","intent":["request-0","unsupported","p0","fresh"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"offered"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","forbidden","p1","fresh"],"last":null,"phase":"offered"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"offered"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"offered"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","unsupported","p1","fresh"],"last":null,"phase":"offered"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"offered"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","declassify","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"offered"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","forbidden","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p0","decision":"permit","delivery":"pending","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"delivery-pending"},{"cut":"p0","decision":"transform","delivery":"pending","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"decided"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"offered"},{"cut":"p1","decision":"unsupported","delivery":"withheld","intent":["request-0","unsupported","p0","fresh"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"cut":"p1","decision":"declassify","delivery":"none","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"decided"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","forbidden","p1","fresh"],"last":["request-0","p1","deny"],"phase":"terminal"},{"cut":"p1","decision":"permit","delivery":"pending","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"decided"},{"cut":"p1","decision":"transform","delivery":"none","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"decided"},{"cut":"p1","decision":"unsupported","delivery":"withheld","intent":["request-0","unsupported","p1","fresh"],"last":["request-0","p1","unsupported"],"phase":"terminal"},{"cut":"p0","decision":"deny","delivery":"withheld","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","declassify","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"offered"},{"cut":"p0","decision":"deny","delivery":"withheld","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","forbidden","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"offered"},{"cut":"p0","decision":"permit","delivery":"delivered","intent":["request-0","plain","p0","fresh"],"last":["request-0","p0","permit"],"phase":"terminal"},{"cut":"p0","decision":"transform","delivery":"pending","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"delivery-pending"},{"cut":"p0","decision":"unsupported","delivery":"withheld","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","unsupported","p0","later-cut"],"last":["request-0","p0","unsupported"],"phase":"offered"},{"cut":"p1","decision":"declassify","delivery":"pending","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"decided"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","forbidden","p1","same-cut"],"last":["request-0","p1","deny"],"phase":"offered"},{"cut":"p1","decision":"permit","delivery":"pending","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"delivery-pending"},{"cut":"p1","decision":"transform","delivery":"pending","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"decided"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","unsupported","p1","same-cut"],"last":["request-0","p1","unsupported"],"phase":"offered"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","declassify","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","forbidden","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"offered"},{"cut":"p1","decision":"permit","delivery":"delivered","intent":["request-0","plain","p0","fresh"],"last":["request-0","p0","permit"],"phase":"terminal"},{"cut":"p0","decision":"transform","delivery":"delivered","intent":["request-0","transform","p0","fresh"],"last":["request-0","p0","transform"],"phase":"terminal"},{"cut":"p1","decision":"unsupported","delivery":"withheld","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"cut":"p1","decision":"unsupported","delivery":"withheld","intent":["request-0","unsupported","p0","later-cut"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"cut":"p1","decision":"declassify","delivery":"pending","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"delivery-pending"},{"cut":"p1","decision":"deny","delivery":"withheld","intent":["request-0","forbidden","p1","same-cut"],"last":["request-0","p1","deny"],"phase":"terminal"},{"cut":"p1","decision":"permit","delivery":"delivered","intent":["request-0","plain","p1","fresh"],"last":["request-0","p1","permit"],"phase":"terminal"},{"cut":"p1","decision":"transform","delivery":"pending","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"delivery-pending"},{"cut":"p1","decision":"unsupported","delivery":"withheld","intent":["request-0","unsupported","p1","same-cut"],"last":["request-0","p1","unsupported"],"phase":"terminal"},{"cut":"p0","decision":"permit","delivery":"pending","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"decided"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","plain","p0","later-cut"],"last":["request-0","p0","permit"],"phase":"offered"},{"cut":"p0","decision":"none","delivery":"none","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"offered"},{"cut":"p1","decision":"transform","delivery":"delivered","intent":["request-0","transform","p0","fresh"],"last":["request-0","p0","transform"],"phase":"terminal"},{"cut":"p1","decision":"declassify","delivery":"delivered","intent":["request-0","declassify","p1","fresh"],"last":["request-0","p1","declassify"],"phase":"terminal"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"offered"},{"cut":"p1","decision":"transform","delivery":"delivered","intent":["request-0","transform","p1","fresh"],"last":["request-0","p1","transform"],"phase":"terminal"},{"cut":"p0","decision":"permit","delivery":"pending","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"delivery-pending"},{"cut":"p1","decision":"permit","delivery":"delivered","intent":["request-0","plain","p0","later-cut"],"last":["request-0","p0","permit"],"phase":"terminal"},{"cut":"p0","decision":"transform","delivery":"none","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"decided"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","transform","p0","later-cut"],"last":["request-0","p0","transform"],"phase":"offered"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"offered"},{"cut":"p1","decision":"permit","delivery":"pending","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"decided"},{"cut":"p1","decision":"none","delivery":"none","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"offered"},{"cut":"p0","decision":"permit","delivery":"delivered","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"terminal"},{"cut":"p0","decision":"transform","delivery":"pending","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"decided"},{"cut":"p1","decision":"transform","delivery":"delivered","intent":["request-0","transform","p0","later-cut"],"last":["request-0","p0","transform"],"phase":"terminal"},{"cut":"p1","decision":"declassify","delivery":"none","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"decided"},{"cut":"p1","decision":"permit","delivery":"pending","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"delivery-pending"},{"cut":"p1","decision":"transform","delivery":"none","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"decided"},{"cut":"p1","decision":"permit","delivery":"delivered","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"terminal"},{"cut":"p0","decision":"transform","delivery":"pending","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"delivery-pending"},{"cut":"p1","decision":"declassify","delivery":"pending","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"decided"},{"cut":"p1","decision":"permit","delivery":"delivered","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"terminal"},{"cut":"p1","decision":"transform","delivery":"pending","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"decided"},{"cut":"p0","decision":"transform","delivery":"delivered","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"terminal"},{"cut":"p1","decision":"declassify","delivery":"pending","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"delivery-pending"},{"cut":"p1","decision":"transform","delivery":"pending","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"delivery-pending"},{"cut":"p1","decision":"transform","delivery":"delivered","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"terminal"},{"cut":"p1","decision":"declassify","delivery":"delivered","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"terminal"},{"cut":"p1","decision":"transform","delivery":"delivered","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"terminal"}]} diff --git a/specs/formal/participant-semantics/crossing-models/rev2/concrete.aut b/specs/formal/participant-semantics/crossing-models/rev2/concrete.aut new file mode 100644 index 000000000..a977d690f --- /dev/null +++ b/specs/formal/participant-semantics/crossing-models/rev2/concrete.aut @@ -0,0 +1,198 @@ +des (0, 197, 178) +(0,"crossing.request",1) +(0,"crossing.request",2) +(0,"crossing.request",3) +(0,"crossing.request",4) +(0,"crossing.request",5) +(0,"policy.cut.advance",6) +(1,"internal",7) +(2,"internal",8) +(3,"internal",9) +(4,"internal",10) +(5,"internal",11) +(6,"crossing.request",12) +(6,"crossing.request",13) +(6,"crossing.request",14) +(6,"crossing.request",15) +(6,"crossing.request",16) +(7,"internal",17) +(8,"internal",18) +(9,"internal",19) +(10,"internal",20) +(11,"internal",21) +(12,"internal",22) +(13,"internal",23) +(14,"internal",24) +(15,"internal",25) +(16,"internal",26) +(17,"internal",27) +(18,"internal",28) +(19,"internal",29) +(20,"internal",30) +(21,"internal",31) +(22,"internal",32) +(23,"internal",33) +(24,"internal",34) +(25,"internal",35) +(26,"internal",36) +(27,"crossing.decision.deny",37) +(28,"crossing.decision.deny",38) +(29,"crossing.decision.permit",39) +(30,"crossing.decision.permit",40) +(31,"crossing.decision.unsupported",41) +(32,"internal",42) +(33,"internal",43) +(34,"internal",44) +(35,"internal",45) +(36,"internal",46) +(37,"internal",47) +(38,"internal",48) +(39,"internal",49) +(40,"crossing.transform",50) +(41,"internal",51) +(42,"crossing.decision.permit",52) +(43,"crossing.decision.deny",53) +(44,"crossing.decision.permit",54) +(45,"crossing.decision.permit",55) +(46,"crossing.decision.unsupported",56) +(47,"internal",57) +(48,"internal",58) +(49,"internal",59) +(50,"internal",60) +(51,"internal",61) +(52,"crossing.declassify",62) +(53,"internal",63) +(54,"internal",64) +(55,"crossing.transform",65) +(56,"internal",66) +(57,"crossing.request",67) +(57,"policy.cut.advance",68) +(58,"crossing.request",69) +(58,"policy.cut.advance",70) +(59,"crossing.delivery",71) +(60,"internal",72) +(61,"crossing.request",73) +(61,"policy.cut.advance",74) +(62,"internal",75) +(63,"internal",76) +(64,"internal",77) +(65,"internal",78) +(66,"internal",79) +(67,"internal",80) +(68,"crossing.request",81) +(69,"internal",82) +(70,"crossing.request",83) +(71,"crossing.observation",84) +(72,"crossing.delivery",85) +(73,"internal",86) +(74,"crossing.request",87) +(75,"internal",88) +(76,"crossing.request",89) +(77,"crossing.delivery",90) +(78,"internal",91) +(79,"crossing.request",92) +(80,"internal",93) +(81,"internal",94) +(82,"internal",95) +(83,"internal",96) +(84,"crossing.request",97) +(84,"policy.cut.advance",98) +(85,"crossing.observation",99) +(86,"internal",100) +(87,"internal",101) +(88,"crossing.delivery",102) +(89,"internal",103) +(90,"crossing.observation",104) +(91,"crossing.delivery",105) +(92,"internal",106) +(93,"internal",107) +(94,"crossing.replay.reject",108) +(95,"internal",109) +(96,"crossing.replay.reject",110) +(97,"internal",111) +(98,"crossing.request",112) +(99,"crossing.request",113) +(99,"policy.cut.advance",114) +(100,"internal",115) +(101,"crossing.replay.reject",116) +(102,"crossing.observation",117) +(103,"internal",118) +(104,"crossing.request",119) +(105,"crossing.observation",120) +(106,"internal",121) +(107,"crossing.decision.deny",122) +(108,"crossing.request",81) +(109,"crossing.decision.deny",123) +(110,"crossing.request",83) +(111,"internal",124) +(112,"internal",125) +(113,"internal",126) +(114,"crossing.request",127) +(115,"crossing.decision.unsupported",128) +(116,"crossing.request",87) +(117,"crossing.request",129) +(118,"internal",130) +(119,"internal",131) +(120,"crossing.request",132) +(121,"internal",133) +(122,"crossing.request",67) +(122,"policy.cut.advance",134) +(123,"crossing.request",69) +(123,"policy.cut.advance",135) +(124,"internal",136) +(125,"crossing.replay.reject",137) +(126,"internal",138) +(127,"internal",139) +(128,"crossing.request",73) +(128,"policy.cut.advance",140) +(129,"internal",141) +(130,"crossing.decision.deny",142) +(131,"internal",143) +(132,"internal",144) +(133,"crossing.decision.unsupported",145) +(134,"crossing.request",81) +(135,"crossing.request",83) +(136,"crossing.decision.permit",146) +(137,"crossing.request",112) +(138,"internal",147) +(139,"crossing.replay.reject",148) +(140,"crossing.request",87) +(141,"internal",149) +(142,"crossing.request",89) +(143,"internal",150) +(144,"internal",151) +(145,"crossing.request",92) +(146,"internal",152) +(147,"crossing.decision.permit",153) +(148,"crossing.request",127) +(149,"internal",154) +(150,"crossing.decision.permit",155) +(151,"internal",156) +(152,"crossing.delivery",157) +(153,"crossing.transform",158) +(154,"crossing.decision.permit",159) +(155,"internal",160) +(156,"crossing.decision.permit",161) +(157,"crossing.observation",162) +(158,"internal",163) +(159,"crossing.declassify",164) +(160,"crossing.delivery",165) +(161,"crossing.transform",166) +(162,"crossing.request",97) +(162,"policy.cut.advance",167) +(163,"crossing.delivery",168) +(164,"internal",169) +(165,"crossing.observation",170) +(166,"internal",171) +(167,"crossing.request",112) +(168,"crossing.observation",172) +(169,"crossing.delivery",173) +(170,"crossing.request",119) +(171,"crossing.delivery",174) +(172,"crossing.request",113) +(172,"policy.cut.advance",175) +(173,"crossing.observation",176) +(174,"crossing.observation",177) +(175,"crossing.request",127) +(176,"crossing.request",129) +(177,"crossing.request",132) diff --git a/specs/formal/participant-semantics/crossing-models/rev2/concrete.json b/specs/formal/participant-semantics/crossing-models/rev2/concrete.json new file mode 100644 index 000000000..b256a95a9 --- /dev/null +++ b/specs/formal/participant-semantics/crossing-models/rev2/concrete.json @@ -0,0 +1 @@ +{"initial":0,"semantic_edges":[[0,"crossing.request",1],[0,"crossing.request",2],[0,"crossing.request",3],[0,"crossing.request",4],[0,"crossing.request",5],[0,"policy.cut.advance",6],[1,"internal.validate",7],[2,"internal.validate",8],[3,"internal.validate",9],[4,"internal.validate",10],[5,"internal.validate",11],[6,"crossing.request",12],[6,"crossing.request",13],[6,"crossing.request",14],[6,"crossing.request",15],[6,"crossing.request",16],[7,"internal.resolve-policy-cut",17],[8,"internal.resolve-policy-cut",18],[9,"internal.resolve-policy-cut",19],[10,"internal.resolve-policy-cut",20],[11,"internal.resolve-policy-cut",21],[12,"internal.validate",22],[13,"internal.validate",23],[14,"internal.validate",24],[15,"internal.validate",25],[16,"internal.validate",26],[17,"internal.resolve-capability",27],[18,"internal.resolve-capability",28],[19,"internal.resolve-capability",29],[20,"internal.resolve-capability",30],[21,"internal.resolve-capability",31],[22,"internal.resolve-policy-cut",32],[23,"internal.resolve-policy-cut",33],[24,"internal.resolve-policy-cut",34],[25,"internal.resolve-policy-cut",35],[26,"internal.resolve-policy-cut",36],[27,"crossing.decision.deny",37],[28,"crossing.decision.deny",38],[29,"crossing.decision.permit",39],[30,"crossing.decision.permit",40],[31,"crossing.decision.unsupported",41],[32,"internal.resolve-capability",42],[33,"internal.resolve-capability",43],[34,"internal.resolve-capability",44],[35,"internal.resolve-capability",45],[36,"internal.resolve-capability",46],[37,"internal.prepare-record",47],[38,"internal.prepare-record",48],[39,"internal.prepare-record",49],[40,"crossing.transform",50],[41,"internal.prepare-record",51],[42,"crossing.decision.permit",52],[43,"crossing.decision.deny",53],[44,"crossing.decision.permit",54],[45,"crossing.decision.permit",55],[46,"crossing.decision.unsupported",56],[47,"internal.atomic-commit",57],[48,"internal.atomic-commit",58],[49,"internal.atomic-commit",59],[50,"internal.prepare-record",60],[51,"internal.atomic-commit",61],[52,"crossing.declassify",62],[53,"internal.prepare-record",63],[54,"internal.prepare-record",64],[55,"crossing.transform",65],[56,"internal.prepare-record",66],[57,"crossing.request",67],[57,"policy.cut.advance",68],[58,"crossing.request",69],[58,"policy.cut.advance",70],[59,"crossing.delivery",71],[60,"internal.atomic-commit",72],[61,"crossing.request",73],[61,"policy.cut.advance",74],[62,"internal.prepare-record",75],[63,"internal.atomic-commit",76],[64,"internal.atomic-commit",77],[65,"internal.prepare-record",78],[66,"internal.atomic-commit",79],[67,"internal.validate",80],[68,"crossing.request",81],[69,"internal.validate",82],[70,"crossing.request",83],[71,"crossing.observation",84],[72,"crossing.delivery",85],[73,"internal.validate",86],[74,"crossing.request",87],[75,"internal.atomic-commit",88],[76,"crossing.request",89],[77,"crossing.delivery",90],[78,"internal.atomic-commit",91],[79,"crossing.request",92],[80,"internal.resolve-policy-cut",93],[81,"internal.validate",94],[82,"internal.resolve-policy-cut",95],[83,"internal.validate",96],[84,"crossing.request",97],[84,"policy.cut.advance",98],[85,"crossing.observation",99],[86,"internal.resolve-policy-cut",100],[87,"internal.validate",101],[88,"crossing.delivery",102],[89,"internal.validate",103],[90,"crossing.observation",104],[91,"crossing.delivery",105],[92,"internal.validate",106],[93,"internal.resolve-capability",107],[94,"crossing.replay.reject",108],[95,"internal.resolve-capability",109],[96,"crossing.replay.reject",110],[97,"internal.validate",111],[98,"crossing.request",112],[99,"crossing.request",113],[99,"policy.cut.advance",114],[100,"internal.resolve-capability",115],[101,"crossing.replay.reject",116],[102,"crossing.observation",117],[103,"internal.resolve-policy-cut",118],[104,"crossing.request",119],[105,"crossing.observation",120],[106,"internal.resolve-policy-cut",121],[107,"crossing.decision.deny",122],[108,"crossing.request",81],[109,"crossing.decision.deny",123],[110,"crossing.request",83],[111,"internal.resolve-policy-cut",124],[112,"internal.validate",125],[113,"internal.validate",126],[114,"crossing.request",127],[115,"crossing.decision.unsupported",128],[116,"crossing.request",87],[117,"crossing.request",129],[118,"internal.resolve-capability",130],[119,"internal.validate",131],[120,"crossing.request",132],[121,"internal.resolve-capability",133],[122,"crossing.request",67],[122,"policy.cut.advance",134],[123,"crossing.request",69],[123,"policy.cut.advance",135],[124,"internal.resolve-capability",136],[125,"crossing.replay.reject",137],[126,"internal.resolve-policy-cut",138],[127,"internal.validate",139],[128,"crossing.request",73],[128,"policy.cut.advance",140],[129,"internal.validate",141],[130,"crossing.decision.deny",142],[131,"internal.resolve-policy-cut",143],[132,"internal.validate",144],[133,"crossing.decision.unsupported",145],[134,"crossing.request",81],[135,"crossing.request",83],[136,"crossing.decision.permit",146],[137,"crossing.request",112],[138,"internal.resolve-capability",147],[139,"crossing.replay.reject",148],[140,"crossing.request",87],[141,"internal.resolve-policy-cut",149],[142,"crossing.request",89],[143,"internal.resolve-capability",150],[144,"internal.resolve-policy-cut",151],[145,"crossing.request",92],[146,"internal.prepare-record",152],[147,"crossing.decision.permit",153],[148,"crossing.request",127],[149,"internal.resolve-capability",154],[150,"crossing.decision.permit",155],[151,"internal.resolve-capability",156],[152,"crossing.delivery",157],[153,"crossing.transform",158],[154,"crossing.decision.permit",159],[155,"internal.prepare-record",160],[156,"crossing.decision.permit",161],[157,"crossing.observation",162],[158,"internal.prepare-record",163],[159,"crossing.declassify",164],[160,"crossing.delivery",165],[161,"crossing.transform",166],[162,"crossing.request",97],[162,"policy.cut.advance",167],[163,"crossing.delivery",168],[164,"internal.prepare-record",169],[165,"crossing.observation",170],[166,"internal.prepare-record",171],[167,"crossing.request",112],[168,"crossing.observation",172],[169,"crossing.delivery",173],[170,"crossing.request",119],[171,"crossing.delivery",174],[172,"crossing.request",113],[172,"policy.cut.advance",175],[173,"crossing.observation",176],[174,"crossing.observation",177],[175,"crossing.request",127],[176,"crossing.request",129],[177,"crossing.request",132]],"states":[{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","declassify","p0","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","forbidden","p0","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","unsupported","p0","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","declassify","p0","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","forbidden","p0","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","unsupported","p0","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","forbidden","p1","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","unsupported","p1","fresh"],"last":null,"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","declassify","p0","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","forbidden","p0","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","unsupported","p0","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","forbidden","p1","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","unsupported","p1","fresh"],"last":null,"phase":"resolving-cut"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"deny","head":"h0","intent":["request-0","declassify","p0","fresh"],"last":null,"phase":"gating"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"deny","head":"h0","intent":["request-0","forbidden","p0","fresh"],"last":null,"phase":"gating"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"permit","head":"h0","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"gating"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"permit","head":"h0","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"gating"},{"capability":"unsupported","cut":"p0","decision":"none","delivery":"none","gate":"permit","head":"h0","intent":["request-0","unsupported","p0","fresh"],"last":null,"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","forbidden","p1","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":["request-0","unsupported","p1","fresh"],"last":null,"phase":"resolving-capability"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h0","intent":["request-0","declassify","p0","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h0","intent":["request-0","forbidden","p0","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"none","gate":"permit","head":"h0","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"preparing-record"},{"capability":"unsupported","cut":"p0","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h0","intent":["request-0","unsupported","p0","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h0","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"gating"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"deny","head":"h0","intent":["request-0","forbidden","p1","fresh"],"last":null,"phase":"gating"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h0","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"gating"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h0","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"gating"},{"capability":"unsupported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h0","intent":["request-0","unsupported","p1","fresh"],"last":null,"phase":"gating"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h0","intent":["request-0","declassify","p0","fresh"],"last":null,"phase":"committing"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h0","intent":["request-0","forbidden","p0","fresh"],"last":null,"phase":"committing"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","plain","p0","fresh"],"last":null,"phase":"committing"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"preparing-record"},{"capability":"unsupported","cut":"p0","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h0","intent":["request-0","unsupported","p0","fresh"],"last":null,"phase":"committing"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"none","gate":"permit","head":"h0","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h0","intent":["request-0","forbidden","p1","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"none","gate":"permit","head":"h0","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"preparing-record"},{"capability":"unsupported","cut":"p1","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h0","intent":["request-0","unsupported","p1","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","declassify","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","forbidden","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p0","fresh"],"last":["request-0","p0","permit"],"phase":"committing"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","transform","p0","fresh"],"last":null,"phase":"committing"},{"capability":"unsupported","cut":"p0","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h1","intent":["request-0","unsupported","p0","fresh"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h0","intent":["request-0","forbidden","p1","fresh"],"last":null,"phase":"committing"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","plain","p1","fresh"],"last":null,"phase":"committing"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"preparing-record"},{"capability":"unsupported","cut":"p1","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h0","intent":["request-0","unsupported","p1","fresh"],"last":null,"phase":"committing"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","declassify","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","forbidden","p0","fresh"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p0","fresh"],"last":["request-0","p0","permit"],"phase":"delivery-pending"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p0","fresh"],"last":["request-0","p0","transform"],"phase":"committing"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"validating"},{"capability":"unsupported","cut":"p1","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h1","intent":["request-0","unsupported","p0","fresh"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","declassify","p1","fresh"],"last":null,"phase":"committing"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","forbidden","p1","fresh"],"last":["request-0","p1","deny"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p1","fresh"],"last":["request-0","p1","permit"],"phase":"committing"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"pending","gate":"permit","head":"h0","intent":["request-0","transform","p1","fresh"],"last":null,"phase":"committing"},{"capability":"unsupported","cut":"p1","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h1","intent":["request-0","unsupported","p1","fresh"],"last":["request-0","p1","unsupported"],"phase":"terminal"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"validating"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","plain","p0","fresh"],"last":["request-0","p0","permit"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p0","fresh"],"last":["request-0","p0","transform"],"phase":"delivery-pending"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p0","later-cut"],"last":["request-0","p0","unsupported"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","declassify","p1","fresh"],"last":["request-0","p1","declassify"],"phase":"committing"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p1","same-cut"],"last":["request-0","p1","deny"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p1","fresh"],"last":["request-0","p1","permit"],"phase":"delivery-pending"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p1","fresh"],"last":["request-0","p1","transform"],"phase":"committing"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p1","same-cut"],"last":["request-0","p1","unsupported"],"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","plain","p0","fresh"],"last":["request-0","p0","permit"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","transform","p0","fresh"],"last":["request-0","p0","transform"],"phase":"terminal"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p0","later-cut"],"last":["request-0","p0","unsupported"],"phase":"resolving-cut"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","declassify","p1","fresh"],"last":["request-0","p1","declassify"],"phase":"delivery-pending"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p1","same-cut"],"last":["request-0","p1","deny"],"phase":"resolving-cut"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","plain","p1","fresh"],"last":["request-0","p1","permit"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p1","fresh"],"last":["request-0","p1","transform"],"phase":"delivery-pending"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p1","same-cut"],"last":["request-0","p1","unsupported"],"phase":"resolving-cut"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"deny","head":"h1","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"deny","delivery":"withheld","gate":"unresolved","head":"h1","intent":["request-0","declassify","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"deny","head":"h1","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"deny","delivery":"withheld","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p0","later-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p0","later-cut"],"last":["request-0","p0","permit"],"phase":"validating"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","transform","p0","fresh"],"last":["request-0","p0","transform"],"phase":"terminal"},{"capability":"unsupported","cut":"p0","decision":"none","delivery":"none","gate":"permit","head":"h1","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"unsupported","delivery":"withheld","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p0","later-cut"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","declassify","p1","fresh"],"last":["request-0","p1","declassify"],"phase":"terminal"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","forbidden","p1","same-cut"],"last":["request-0","p1","deny"],"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","transform","p1","fresh"],"last":["request-0","p1","transform"],"phase":"terminal"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","unsupported","p1","same-cut"],"last":["request-0","p1","unsupported"],"phase":"resolving-capability"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p0","later-cut"],"last":["request-0","p0","permit"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p0","later-cut"],"last":["request-0","p0","transform"],"phase":"validating"},{"capability":"unsupported","cut":"p0","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h1","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"validating"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"deny","head":"h1","intent":["request-0","forbidden","p1","same-cut"],"last":["request-0","p1","deny"],"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"resolving-cut"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"validating"},{"capability":"unsupported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h1","intent":["request-0","unsupported","p1","same-cut"],"last":["request-0","p1","unsupported"],"phase":"gating"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","declassify","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","forbidden","p0","same-cut"],"last":["request-0","p0","deny"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"permit","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"permit","delivery":"delivered","gate":"unresolved","head":"h1","intent":["request-0","plain","p0","later-cut"],"last":["request-0","p0","permit"],"phase":"terminal"},{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p0","later-cut"],"last":["request-0","p0","transform"],"phase":"resolving-cut"},{"capability":"unsupported","cut":"p1","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h1","intent":["request-0","unsupported","p0","same-cut"],"last":["request-0","p0","unsupported"],"phase":"terminal"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"resolving-cut"},{"capability":"supported","cut":"p1","decision":"deny","delivery":"withheld","gate":"deny","head":"h1","intent":["request-0","forbidden","p1","same-cut"],"last":["request-0","p1","deny"],"phase":"terminal"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"resolving-capability"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"resolving-cut"},{"capability":"unsupported","cut":"p1","decision":"unsupported","delivery":"withheld","gate":"permit","head":"h1","intent":["request-0","unsupported","p1","same-cut"],"last":["request-0","p1","unsupported"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"preparing-record"},{"capability":"supported","cut":"p0","decision":"none","delivery":"none","gate":"permit","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"transform","delivery":"delivered","gate":"unresolved","head":"h1","intent":["request-0","transform","p0","later-cut"],"last":["request-0","p0","transform"],"phase":"terminal"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"resolving-capability"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"gating"},{"capability":"unresolved","cut":"p1","decision":"none","delivery":"none","gate":"unresolved","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"resolving-capability"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"committing"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"none","gate":"permit","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"gating"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"none","delivery":"none","gate":"permit","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"gating"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"delivery-pending"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"none","gate":"permit","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"committing"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"none","gate":"permit","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"preparing-record"},{"capability":"supported","cut":"p0","decision":"permit","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"committing"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"delivery-pending"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"preparing-record"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","plain","p0","same-cut"],"last":["request-0","p0","permit"],"phase":"terminal"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"delivery-pending"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"committing"},{"capability":"supported","cut":"p1","decision":"permit","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","plain","p1","same-cut"],"last":["request-0","p1","permit"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"committing"},{"capability":"supported","cut":"p0","decision":"transform","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"delivery-pending"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"pending","gate":"permit","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"delivery-pending"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","transform","p0","same-cut"],"last":["request-0","p0","transform"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"declassify","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","declassify","p1","same-cut"],"last":["request-0","p1","declassify"],"phase":"terminal"},{"capability":"supported","cut":"p1","decision":"transform","delivery":"delivered","gate":"permit","head":"h1","intent":["request-0","transform","p1","same-cut"],"last":["request-0","p1","transform"],"phase":"terminal"}]} diff --git a/specs/formal/participant-semantics/crossing-models/rev2/manifest.json b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json new file mode 100644 index 000000000..e80d25b22 --- /dev/null +++ b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json @@ -0,0 +1 @@ +{"artifact_digests":{"abstract.aut":"sha256:5891bbc5b3da53c7345f383da7f935ee9f8f0e4dd56b50c6edc132bbbd33964b","abstract.json":"sha256:8a5804e83b674b2099206b113101e2a45e60d7f08996af099dfe685e494173e3","concrete.aut":"sha256:8d8ca9681c2893abf048a0988aa5efc76c22e1fe148c4c75be78780e9be09b39","concrete.json":"sha256:108384d53dadb8aff695d9591c6fa8908af753bee14d56ed37d4c5c382203691"},"catalog_digest":"sha256:0968aee4778afb3cd904eb4942e20b549d173321653c4bc356c13af5841bd7c5","catalog_revision":"rev8","complete_reachable_fixed_point":true,"domain_counts":{"audience":1,"controller":1,"decision":6,"delivery":4,"episode":1,"history_head":4,"input_class":5,"participant":1,"policy_cut":2,"replay":3,"request_id":1},"equivalence_result":"not-established","explicit_non_claims":["No equivalence or live-runtime result is established by construction."],"limitations":["One fresh operation and retries; no identity recycling."],"models":{"abstract":{"initial_state":{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["decided","delivery-pending","idle","offered","terminal"],"states":88,"transitions":107},"concrete":{"initial_state":{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["committing","delivery-pending","gating","idle","preparing-record","resolving-capability","resolving-cut","terminal","validating"],"states":178,"transitions":197}},"profile_digest":"sha256:4439d8ece4d8977f2d991b9ef6b5a73a98951ace513adf80ea4496923985dbb4","profile_file_digest":"sha256:47c02f085aa6952333f75512c9eb7ffc5f7b7982ba49ee0dba4c5a3c32857db4","profile_id":"participant-crossing-dpbb-finite-v1","profile_revision":"rev2","projection":"participant-crossing-projection@rev1","runtime_realization":"not-established","schema":"participant-crossing-model-bundle/v1","source_digests":{"implementations/formal/participant_crossing/__init__.py":"sha256:f51f0d2c6683d45c41da9712da916ccd8df86a96eff4e97d9274a1ee55a96fba","implementations/formal/participant_crossing/__main__.py":"sha256:f608aeb63a97fac9e45ef3855c5a8ddb0aaa9710168aac9fba57e868c600a802","implementations/formal/participant_crossing/abstract.py":"sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531","implementations/formal/participant_crossing/aut.py":"sha256:8ddf46d2cf08986aa99c2b3a39a6817850c321cb09bc9294472fd684fc0b00f8","implementations/formal/participant_crossing/concrete.py":"sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5","implementations/formal/participant_crossing/export.py":"sha256:922f5066a5b85ffe78abe7a79c215103b9ec05217d5ebd1021e9650713ef7948","implementations/formal/participant_crossing/graph.py":"sha256:18d6846bebb31bda0ecacd3e64a4c86c17309b9734d3ea9ed87c4fab7b07a37d","implementations/formal/participant_crossing/ingress.py":"sha256:9acf962a2c409d55dfd909f699a11e1a8ba995992fe7826db106b96edb0af95b","implementations/python/packages/raes_contracts/_behavioral_profile_loader.py":"sha256:e37cc424cc52cb0a210f63a126664bb82d6f3d3e2675b65501fcde75e31eb7dd","implementations/python/packages/raes_contracts/_canonical.py":"sha256:699b5b6801ec1b23c08676789114e77ccfcae3ed458f12a48670967b5fa2c13d","implementations/python/packages/raes_contracts/_participant_crossing_profile.py":"sha256:d4e3a5e771a466daaa253c9da699943cbb72d71b9365954f44472c49919630e3","implementations/python/packages/raes_contracts/behavioral_relation_profiles.py":"sha256:9ce0b3e28aa73a4cb85aaf9b8336e2020169bf5b387473f70da1922a4f5b1716","implementations/python/packages/raes_contracts/canonical.py":"sha256:eff8b51fee43ebb09628abf71612ed73eb403825c93219851965079837fed52a","implementations/python/packages/raes_contracts/contracts/participant_crossing.py":"sha256:c3ac84309e48d6944b9f036940954af5df2f2127c4f56b47f4d803c736bf9e3f","implementations/python/packages/raes_contracts/contracts/participant_crossing_validation.py":"sha256:a6bb4cddfcd06e5fa15ef605106c6baed12c2b8d4e997247b148bdad0a7ef50b","implementations/python/packages/raes_contracts/json_ingress.py":"sha256:b2ae13274cb0752f9f97828032a26283456efc2483110908dd09c52ca243faa5","implementations/python/packages/raes_runtime/control_plane_store.py":"sha256:f3cd56479ae50b5d5d0916234419a84ba3c50c48b75ca61dd01d9e098ed16b5d","implementations/python/packages/raes_runtime/participant_crossing_boundary.py":"sha256:553ea1ac962dbff89e4e2ac1355c70a59e344260d73f6c030afb9772cec45db7","implementations/python/packages/raes_runtime/participant_crossing_commit.py":"sha256:0a687c3e02c832a94fa25c88bc0e64c93098ad8f974011b5903132edaa76ba96","implementations/python/packages/raes_runtime/participant_crossing_egress.py":"sha256:87c8e0b11e5a78e5ff69a09801719ef554e6d7934bf44feccc8517a50aff064a","implementations/python/packages/raes_runtime/participant_crossing_mediation.py":"sha256:dd9e0e2b74176e73419007a37c60e66ea6c282dbb11c09e56fae7074bde4355f","implementations/python/packages/raes_runtime/participant_crossing_policy.py":"sha256:50344823aaaa545deca2848e1eeaff3e84d1143d9d3a679536e0848ee6229ee7","implementations/python/packages/raes_runtime/participant_crossing_records.py":"sha256:ceb2cde1e61965135e0c884209dd77fbf1c774de6bf0aea8aab1616e91a09432","implementations/python/packages/raes_runtime/participant_crossing_state_cut.py":"sha256:3bd347d26c08888ea61d8d19600c43f7f1cad01daedc37da34d413b8153b24c2","implementations/python/uv.lock":"sha256:089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd","specs/formal/participant-semantics/information-flow-control.md":"sha256:22e56877a1e439acdbe4e7c587e186f2420e06f366a4ab5875daa2bc5d63efb9","specs/formal/participant-semantics/participant-crossing-models.md":"sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29"},"source_revision":"sha256:d48852f9c71d17d0e2732b1e15d458542ccc4241bc64e3377a45580caaf5833c"} diff --git a/specs/formal/participant-semantics/participant-crossing-bisimulation.md b/specs/formal/participant-semantics/participant-crossing-bisimulation.md index 69e09b2ef..7a80b9c8d 100644 --- a/specs/formal/participant-semantics/participant-crossing-bisimulation.md +++ b/specs/formal/participant-semantics/participant-crossing-bisimulation.md @@ -5,13 +5,19 @@ Requirement: SEM-232. Decision: [ADR-100](../../../docs/decisions/adrs/adr-100-participant-crossing-bisimulation.md). -Profile: `participant-crossing-dpbb-finite-v1@rev1`. +Historical profile sketch: `participant-crossing-dpbb-finite-v1@rev1`. Relation catalog: `raes-behavioral-relations@rev8`, `divergence-preserving-branching-bisimulation`. -Status: normative design. No model, model-check, proof, runtime-realization, or -backend-conformance result is claimed by this specification. +Status: historical rev1 state/transition sketch. The relation clauses and +projection remain applicable. ADR-100's #971 amendment selects executable +profile/model rev2 as the downstream target. No equivalence, proof, +runtime-realization, or backend-conformance result is claimed here. + +The [executable rev2 refinement](participant-crossing-models.md) records #971's +approved single-operation interpretation and independently generated models. +The rev1 design below remains the historical theorem sketch. ## Theorem Target diff --git a/specs/formal/participant-semantics/participant-crossing-models.md b/specs/formal/participant-semantics/participant-crossing-models.md new file mode 100644 index 000000000..3ab8304ca --- /dev/null +++ b/specs/formal/participant-semantics/participant-crossing-models.md @@ -0,0 +1,132 @@ +# Executable Participant-Crossing Models + +Requirement: SEM-232. Construction package: #971. Classification: FM3. + +## Revision and scope + +`participant-crossing-dpbb-finite-v1@rev2` is the first executable refinement of +the [rev1 design](participant-crossing-bisimulation.md), selected by ADR-100’s +#971 amendment. Both model revisions +are `rev2`; projection `participant-crossing-projection@rev1` and taxonomy +`raes-behavioral-relations@rev8` retain their exact identities. Rev1 was design +authority, not a previously published executable profile. Its theorem sketch +is not an executed result and its candidate abstraction is not a generator. + +The user-approved scope is one fresh operation and its retries. Multiple fresh +operations are a separately revisioned scope in #1395. This authority introduces +no runtime changes, mandatory author annotations, or request-time proof work. + +## Complete environment + +The published profile declares every domain from the rev1 design, including +the singleton participant, audience, controller, episode and request identity; +cuts p0 and p1; all five input classes; all decision, replay and delivery +values; and history heads h0 through h3. A fresh request is admitted only while +no result has been recorded. It chooses one of the five input classes. The +original input is retained in the terminal state's intent. Identity recycling +and changed-input reuse are excluded environment actions, not unexamined input +samples. Every declared request/cut choice is explored to a reachable fixed +point. There is no depth or schedule bound. + +Policy advancement is enabled only at idle or terminal and changes p0 to p1 +once. At terminal the only request is a retry of the retained input. A retry +at the recorded cut repeats the outcome observations without another logical +commit. After policy advancement it emits request then replay rejection and +preserves the recorded result. These labels describe the formal outcome +protocol, not repeated backend execution. Mapping receipt replay and actual +delivery to that protocol requires #972 evidence. History advancement caused by +other operations is absent here and must not be equated with policy advancement. + +## Abstract rules + +State coordinates are phase, current cut, intent, decision, delivery, and last +result. Intent is absent or `(request-0, input-class, requested-cut, replay)`; +last is absent or `(request-0, recorded-cut, decision)`. Initial coordinates +are `(idle, p0, none, none, none, none)`. + +The independent abstract authority is `abstract.py`. Its total policy table +selects permit for plain, transform for transform, unsupported for unsupported, +deny for forbidden, and deny/declassify for declassify at p0/p1 respectively. + +1. A request enters offered, clears decision/delivery, and preserves last. +2. A stale retry emits `crossing.replay.reject` and returns to terminal, + restoring the recorded decision and its delivered/withheld outcome. +3. A fresh or same-cut offered request selects the policy or recorded result. + Deny/unsupported emit their decision label and enter terminal with delivery + withheld and last set. There is no extra silent completion transition. +4. Every deliverable result emits `crossing.decision.permit` and enters decided. + Plain permit sets delivery pending immediately. Transform/declassify first + set delivery none, then emit their corresponding change label and set it + pending. This prevents repeating a change. +5. Decided with delivery pending emits `crossing.delivery` to delivery-pending. + That phase emits `crossing.observation` to terminal, delivery delivered, + recording last if absent. The initial completion and all retries preserve + the original input for future retry selection. + +## Concrete rules + +The independent concrete authority is `concrete.py`, derived from API-423 +predecessor ordering and RUN-319 validation, policy/capability resolution, +deny-first gates, preparation and atomic commit. It imports no abstract +transition or policy function. State adds gate, capability and history head. +Initial gate/capability are unresolved and head is h0. + +1. Request stores intent, resets gate/capability/decision/delivery, and enters + validating. `internal.validate` enters resolving-cut. +2. A mismatched cut emits replay rejection and restores the recorded outcome. + Otherwise `internal.resolve-policy-cut` enters resolving-capability. +3. `internal.resolve-capability` sets unsupported only for the unsupported + input. Independently, forbidden and p0 declassification set gate deny; + the remaining cases set permit. This closed fixture assumes admitted + synthetic identity/authority coordinates, not live authentication. +4. Gating selects deny first, then unsupported capability, then the requested + change or plain permit. Its visible label matches that outcome class. + A replayed refusal completes immediately. Other results enter preparing-record. +5. Changes emit their visible label once using delivery none/pending. Then + `internal.prepare-record` enters committing without changing last or head. +6. A fresh result atomically sets last and changes h0 to h1 exactly once via + `internal.atomic-commit`. Refusals enter terminal; deliverable results remain + committing with last present. Same-cut retries already have last and skip + logical commit. Committing with last emits delivery, then observation from + delivery-pending completes the crossing. + +Head denotes one logical atomic result batch, not a count of API-423 records. +h2 and h3 remain in the declared domain but are unreachable: the environment +admits at most one fresh logical result. There is no head saturation or wrap. +The internal rank is validating=6, resolving-cut=5, resolving-capability=4, +gating=3, preparing-record=2, uncommitted committing=1, otherwise=0. Every hidden +edge strictly decreases it, including fresh refusal commits. Visible retry +cycles do not establish hidden divergence. + +## Observation and export + +The ten visible labels and five hidden classes are exactly those in the +published profile. Only the five named hidden classes become `internal`. +Native tau encodings and every undeclared label are rejected. Both exporters +retain semantic labels and ordinal-to-state maps in digest-bound sidecars. + +Terminal denotes completion of one crossing, not global LTS termination. +Success, refusal and stale retry have distinct visible completion sequences; +terminal still enables requests and possibly cut advance. No successful-stop +predicate is inferred from AUT or a sidecar. A missing outgoing edge is a +structural deadlock and is not treated as success. The baseline graphs have no +dead ends; faults introducing them remain observable in subsequent comparison. + +State numbers follow deterministic breadth-first discovery from ordinal zero; +successors sort by label and the synthetic dataclass state representation, +edges are unique and sorted by source, label, target. AUT is ASCII with LF and +a final newline. Counts describe exactly the emitted graph. JSON identity uses +the incumbent RFC 8785 canonicalizer; byte digests separately bind AUT and sources. + +## Assurance boundary + +Construction establishes no equivalence, runtime realization, backend +conformance, noninterference, opacity, timing, probability, concurrency, +controller-handoff, or multi-operation result. Resource exhaustion fails; +partial graphs are never published as complete. Live transformed-ingress +revalidation and every additional runtime gate remain explicit mapping +obligations, not silently projected internal transitions. + +Run export in a fresh interpreter from the source checkout. Copied inputs must +match the Python source identities captured from that executing checkout; +rebinding a profile to different source bytes cannot relabel the loaded code. From bd6f2756cbb150a03878552d883105f4b2601e98 Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sun, 27 Sep 2026 19:24:53 +0200 Subject: [PATCH 2/8] fix(formal): refresh crossing source inventory after synchronization --- docs/research/participant-bisimulation/model-construction.md | 4 +++- .../participant-semantics/crossing-models/rev2/manifest.json | 2 +- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/research/participant-bisimulation/model-construction.md b/docs/research/participant-bisimulation/model-construction.md index 692b17267..cfa4abe35 100644 --- a/docs/research/participant-bisimulation/model-construction.md +++ b/docs/research/participant-bisimulation/model-construction.md @@ -52,7 +52,9 @@ The concrete source inventory names API-423 occurrence/context validation and RUN-319 gate, mediation, record, commit, history-head, boundary, egress and store files. Their hashes detect changes requiring renewed mapping review. This model does not claim to include every live gate, transformed-ingress -revalidation, crash state or backend interaction. #972 must establish the +revalidation, crash state or backend interaction. The synchronized runtime's +mixed-effect serialization and stage-readback failure states are also outside +this single-operation model. #972 must establish the mapping for a selected runtime configuration. An exact retry returns the original runtime receipt without executing the action again; model outcome observations must not be interpreted as a second effect. Runtime history can diff --git a/specs/formal/participant-semantics/crossing-models/rev2/manifest.json b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json index e80d25b22..e8d53c282 100644 --- a/specs/formal/participant-semantics/crossing-models/rev2/manifest.json +++ b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json @@ -1 +1 @@ -{"artifact_digests":{"abstract.aut":"sha256:5891bbc5b3da53c7345f383da7f935ee9f8f0e4dd56b50c6edc132bbbd33964b","abstract.json":"sha256:8a5804e83b674b2099206b113101e2a45e60d7f08996af099dfe685e494173e3","concrete.aut":"sha256:8d8ca9681c2893abf048a0988aa5efc76c22e1fe148c4c75be78780e9be09b39","concrete.json":"sha256:108384d53dadb8aff695d9591c6fa8908af753bee14d56ed37d4c5c382203691"},"catalog_digest":"sha256:0968aee4778afb3cd904eb4942e20b549d173321653c4bc356c13af5841bd7c5","catalog_revision":"rev8","complete_reachable_fixed_point":true,"domain_counts":{"audience":1,"controller":1,"decision":6,"delivery":4,"episode":1,"history_head":4,"input_class":5,"participant":1,"policy_cut":2,"replay":3,"request_id":1},"equivalence_result":"not-established","explicit_non_claims":["No equivalence or live-runtime result is established by construction."],"limitations":["One fresh operation and retries; no identity recycling."],"models":{"abstract":{"initial_state":{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["decided","delivery-pending","idle","offered","terminal"],"states":88,"transitions":107},"concrete":{"initial_state":{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["committing","delivery-pending","gating","idle","preparing-record","resolving-capability","resolving-cut","terminal","validating"],"states":178,"transitions":197}},"profile_digest":"sha256:4439d8ece4d8977f2d991b9ef6b5a73a98951ace513adf80ea4496923985dbb4","profile_file_digest":"sha256:47c02f085aa6952333f75512c9eb7ffc5f7b7982ba49ee0dba4c5a3c32857db4","profile_id":"participant-crossing-dpbb-finite-v1","profile_revision":"rev2","projection":"participant-crossing-projection@rev1","runtime_realization":"not-established","schema":"participant-crossing-model-bundle/v1","source_digests":{"implementations/formal/participant_crossing/__init__.py":"sha256:f51f0d2c6683d45c41da9712da916ccd8df86a96eff4e97d9274a1ee55a96fba","implementations/formal/participant_crossing/__main__.py":"sha256:f608aeb63a97fac9e45ef3855c5a8ddb0aaa9710168aac9fba57e868c600a802","implementations/formal/participant_crossing/abstract.py":"sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531","implementations/formal/participant_crossing/aut.py":"sha256:8ddf46d2cf08986aa99c2b3a39a6817850c321cb09bc9294472fd684fc0b00f8","implementations/formal/participant_crossing/concrete.py":"sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5","implementations/formal/participant_crossing/export.py":"sha256:922f5066a5b85ffe78abe7a79c215103b9ec05217d5ebd1021e9650713ef7948","implementations/formal/participant_crossing/graph.py":"sha256:18d6846bebb31bda0ecacd3e64a4c86c17309b9734d3ea9ed87c4fab7b07a37d","implementations/formal/participant_crossing/ingress.py":"sha256:9acf962a2c409d55dfd909f699a11e1a8ba995992fe7826db106b96edb0af95b","implementations/python/packages/raes_contracts/_behavioral_profile_loader.py":"sha256:e37cc424cc52cb0a210f63a126664bb82d6f3d3e2675b65501fcde75e31eb7dd","implementations/python/packages/raes_contracts/_canonical.py":"sha256:699b5b6801ec1b23c08676789114e77ccfcae3ed458f12a48670967b5fa2c13d","implementations/python/packages/raes_contracts/_participant_crossing_profile.py":"sha256:d4e3a5e771a466daaa253c9da699943cbb72d71b9365954f44472c49919630e3","implementations/python/packages/raes_contracts/behavioral_relation_profiles.py":"sha256:9ce0b3e28aa73a4cb85aaf9b8336e2020169bf5b387473f70da1922a4f5b1716","implementations/python/packages/raes_contracts/canonical.py":"sha256:eff8b51fee43ebb09628abf71612ed73eb403825c93219851965079837fed52a","implementations/python/packages/raes_contracts/contracts/participant_crossing.py":"sha256:c3ac84309e48d6944b9f036940954af5df2f2127c4f56b47f4d803c736bf9e3f","implementations/python/packages/raes_contracts/contracts/participant_crossing_validation.py":"sha256:a6bb4cddfcd06e5fa15ef605106c6baed12c2b8d4e997247b148bdad0a7ef50b","implementations/python/packages/raes_contracts/json_ingress.py":"sha256:b2ae13274cb0752f9f97828032a26283456efc2483110908dd09c52ca243faa5","implementations/python/packages/raes_runtime/control_plane_store.py":"sha256:f3cd56479ae50b5d5d0916234419a84ba3c50c48b75ca61dd01d9e098ed16b5d","implementations/python/packages/raes_runtime/participant_crossing_boundary.py":"sha256:553ea1ac962dbff89e4e2ac1355c70a59e344260d73f6c030afb9772cec45db7","implementations/python/packages/raes_runtime/participant_crossing_commit.py":"sha256:0a687c3e02c832a94fa25c88bc0e64c93098ad8f974011b5903132edaa76ba96","implementations/python/packages/raes_runtime/participant_crossing_egress.py":"sha256:87c8e0b11e5a78e5ff69a09801719ef554e6d7934bf44feccc8517a50aff064a","implementations/python/packages/raes_runtime/participant_crossing_mediation.py":"sha256:dd9e0e2b74176e73419007a37c60e66ea6c282dbb11c09e56fae7074bde4355f","implementations/python/packages/raes_runtime/participant_crossing_policy.py":"sha256:50344823aaaa545deca2848e1eeaff3e84d1143d9d3a679536e0848ee6229ee7","implementations/python/packages/raes_runtime/participant_crossing_records.py":"sha256:ceb2cde1e61965135e0c884209dd77fbf1c774de6bf0aea8aab1616e91a09432","implementations/python/packages/raes_runtime/participant_crossing_state_cut.py":"sha256:3bd347d26c08888ea61d8d19600c43f7f1cad01daedc37da34d413b8153b24c2","implementations/python/uv.lock":"sha256:089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd","specs/formal/participant-semantics/information-flow-control.md":"sha256:22e56877a1e439acdbe4e7c587e186f2420e06f366a4ab5875daa2bc5d63efb9","specs/formal/participant-semantics/participant-crossing-models.md":"sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29"},"source_revision":"sha256:d48852f9c71d17d0e2732b1e15d458542ccc4241bc64e3377a45580caaf5833c"} +{"artifact_digests":{"abstract.aut":"sha256:5891bbc5b3da53c7345f383da7f935ee9f8f0e4dd56b50c6edc132bbbd33964b","abstract.json":"sha256:8a5804e83b674b2099206b113101e2a45e60d7f08996af099dfe685e494173e3","concrete.aut":"sha256:8d8ca9681c2893abf048a0988aa5efc76c22e1fe148c4c75be78780e9be09b39","concrete.json":"sha256:108384d53dadb8aff695d9591c6fa8908af753bee14d56ed37d4c5c382203691"},"catalog_digest":"sha256:0968aee4778afb3cd904eb4942e20b549d173321653c4bc356c13af5841bd7c5","catalog_revision":"rev8","complete_reachable_fixed_point":true,"domain_counts":{"audience":1,"controller":1,"decision":6,"delivery":4,"episode":1,"history_head":4,"input_class":5,"participant":1,"policy_cut":2,"replay":3,"request_id":1},"equivalence_result":"not-established","explicit_non_claims":["No equivalence or live-runtime result is established by construction."],"limitations":["One fresh operation and retries; no identity recycling."],"models":{"abstract":{"initial_state":{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["decided","delivery-pending","idle","offered","terminal"],"states":88,"transitions":107},"concrete":{"initial_state":{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["committing","delivery-pending","gating","idle","preparing-record","resolving-capability","resolving-cut","terminal","validating"],"states":178,"transitions":197}},"profile_digest":"sha256:4439d8ece4d8977f2d991b9ef6b5a73a98951ace513adf80ea4496923985dbb4","profile_file_digest":"sha256:47c02f085aa6952333f75512c9eb7ffc5f7b7982ba49ee0dba4c5a3c32857db4","profile_id":"participant-crossing-dpbb-finite-v1","profile_revision":"rev2","projection":"participant-crossing-projection@rev1","runtime_realization":"not-established","schema":"participant-crossing-model-bundle/v1","source_digests":{"implementations/formal/participant_crossing/__init__.py":"sha256:f51f0d2c6683d45c41da9712da916ccd8df86a96eff4e97d9274a1ee55a96fba","implementations/formal/participant_crossing/__main__.py":"sha256:f608aeb63a97fac9e45ef3855c5a8ddb0aaa9710168aac9fba57e868c600a802","implementations/formal/participant_crossing/abstract.py":"sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531","implementations/formal/participant_crossing/aut.py":"sha256:8ddf46d2cf08986aa99c2b3a39a6817850c321cb09bc9294472fd684fc0b00f8","implementations/formal/participant_crossing/concrete.py":"sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5","implementations/formal/participant_crossing/export.py":"sha256:922f5066a5b85ffe78abe7a79c215103b9ec05217d5ebd1021e9650713ef7948","implementations/formal/participant_crossing/graph.py":"sha256:18d6846bebb31bda0ecacd3e64a4c86c17309b9734d3ea9ed87c4fab7b07a37d","implementations/formal/participant_crossing/ingress.py":"sha256:9acf962a2c409d55dfd909f699a11e1a8ba995992fe7826db106b96edb0af95b","implementations/python/packages/raes_contracts/_behavioral_profile_loader.py":"sha256:e37cc424cc52cb0a210f63a126664bb82d6f3d3e2675b65501fcde75e31eb7dd","implementations/python/packages/raes_contracts/_canonical.py":"sha256:699b5b6801ec1b23c08676789114e77ccfcae3ed458f12a48670967b5fa2c13d","implementations/python/packages/raes_contracts/_participant_crossing_profile.py":"sha256:d4e3a5e771a466daaa253c9da699943cbb72d71b9365954f44472c49919630e3","implementations/python/packages/raes_contracts/behavioral_relation_profiles.py":"sha256:9ce0b3e28aa73a4cb85aaf9b8336e2020169bf5b387473f70da1922a4f5b1716","implementations/python/packages/raes_contracts/canonical.py":"sha256:eff8b51fee43ebb09628abf71612ed73eb403825c93219851965079837fed52a","implementations/python/packages/raes_contracts/contracts/participant_crossing.py":"sha256:c3ac84309e48d6944b9f036940954af5df2f2127c4f56b47f4d803c736bf9e3f","implementations/python/packages/raes_contracts/contracts/participant_crossing_validation.py":"sha256:a6bb4cddfcd06e5fa15ef605106c6baed12c2b8d4e997247b148bdad0a7ef50b","implementations/python/packages/raes_contracts/json_ingress.py":"sha256:b2ae13274cb0752f9f97828032a26283456efc2483110908dd09c52ca243faa5","implementations/python/packages/raes_runtime/control_plane_store.py":"sha256:2631ca837ee1fdd4ecede34c352ea4c0290c5f4f906c2ace1917f9b0de1ef6e2","implementations/python/packages/raes_runtime/participant_crossing_boundary.py":"sha256:88e1e16512251d48ad0f8f52a1bebaff7d90fe2be3b413221b460241344b6d56","implementations/python/packages/raes_runtime/participant_crossing_commit.py":"sha256:0a687c3e02c832a94fa25c88bc0e64c93098ad8f974011b5903132edaa76ba96","implementations/python/packages/raes_runtime/participant_crossing_egress.py":"sha256:87c8e0b11e5a78e5ff69a09801719ef554e6d7934bf44feccc8517a50aff064a","implementations/python/packages/raes_runtime/participant_crossing_mediation.py":"sha256:dd9e0e2b74176e73419007a37c60e66ea6c282dbb11c09e56fae7074bde4355f","implementations/python/packages/raes_runtime/participant_crossing_policy.py":"sha256:50344823aaaa545deca2848e1eeaff3e84d1143d9d3a679536e0848ee6229ee7","implementations/python/packages/raes_runtime/participant_crossing_records.py":"sha256:ceb2cde1e61965135e0c884209dd77fbf1c774de6bf0aea8aab1616e91a09432","implementations/python/packages/raes_runtime/participant_crossing_state_cut.py":"sha256:3bd347d26c08888ea61d8d19600c43f7f1cad01daedc37da34d413b8153b24c2","implementations/python/uv.lock":"sha256:089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd","specs/formal/participant-semantics/information-flow-control.md":"sha256:22e56877a1e439acdbe4e7c587e186f2420e06f366a4ab5875daa2bc5d63efb9","specs/formal/participant-semantics/participant-crossing-models.md":"sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29"},"source_revision":"sha256:16e7afa5c814c4d9557db1c9d86f5f1bac644f14f003f030f5c6eb4a2797be5d"} From 49b5567e6b9c340ca6402424af774686ce02220a Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sun, 27 Sep 2026 19:26:58 +0200 Subject: [PATCH 3/8] fix(docs): refresh historical ADR index digest --- tools/policy/historical_identity_records.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/policy/historical_identity_records.json b/tools/policy/historical_identity_records.json index aefadf385..3f645798c 100644 --- a/tools/policy/historical_identity_records.json +++ b/tools/policy/historical_identity_records.json @@ -495,7 +495,7 @@ "record_class": "historical-index", "rationale": "Indexes immutable pre-cutover ADR titles, paths, pins, and amendment summaries without making them current identity surfaces.", "occurrences": 4, - "content_sha256": "dddd15454fde8c67c1755e6b74e441bd748fb6088c8951b979b9688633a90a50" + "content_sha256": "d00fd5d91e9a86cde9bedfa30f71fb7af4697d557388c202c97254ae0f9d111c" }, { "path": "docs/decisions/cage-2-replication-design.md", From fc384eae0938f000482861bd787b35a608d6efda Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sun, 27 Sep 2026 19:35:26 +0200 Subject: [PATCH 4/8] fix(evidence): replay retained research controls for crossing models --- .../analysis-v56.json | 156 ++++ .../bundles/retest-v56.json | 122 +++ .../execution-snapshot-v56.json | 652 ++++++++++++++++ .../formal-semantic-validation/index.md | 5 + .../specification-coverage/analysis-v55.json | 105 +++ ...-specification-coverage-issue-971-v55.json | 10 + .../execution-snapshot-v55.json | 700 ++++++++++++++++++ docs/research/specification-coverage/index.md | 7 +- .../tests/test_formal_semantic_validation.py | 5 +- .../tests/test_specification_coverage.py | 2 +- tools/check_specification_coverage.py | 6 +- tools/formal_semantic_validation/_baseline.py | 5 +- tools/formal_semantic_validation/_loading.py | 15 +- .../_release_revisions.py | 4 +- tools/formal_semantic_validation/_releases.py | 6 +- tools/formal_semantic_validation/_retest.py | 2 +- 16 files changed, 1785 insertions(+), 17 deletions(-) create mode 100644 docs/research/formal-semantic-validation/analysis-v56.json create mode 100644 docs/research/formal-semantic-validation/bundles/retest-v56.json create mode 100644 docs/research/formal-semantic-validation/execution-snapshot-v56.json create mode 100644 docs/research/specification-coverage/analysis-v55.json create mode 100644 docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v55.json create mode 100644 docs/research/specification-coverage/execution-snapshot-v55.json diff --git a/docs/research/formal-semantic-validation/analysis-v56.json b/docs/research/formal-semantic-validation/analysis-v56.json new file mode 100644 index 000000000..199d956e4 --- /dev/null +++ b/docs/research/formal-semantic-validation/analysis-v56.json @@ -0,0 +1,156 @@ +{ + "analysis_id": "issue-971-analysis-v56", + "claim": { + "allowed_evidence": [ + "production parser and semantic-validator results", + "canonical compiled digests", + "participant contract regression tests", + "pinned protocol, corpus, and execution snapshot" + ], + "claim_id": "asr-530-formal-semantic-validation-retest", + "disallowed_evidence": [ + "schema success as semantic proof", + "workflow reachability as network or exploit reachability", + "FM labels as gate outcomes", + "attribution as counterfactual proof", + "formal prose or maintainer confidence alone" + ], + "evidence_artifacts": [ + "docs/research/formal-semantic-validation/protocol-v2.json", + "docs/research/formal-semantic-validation/corpus/manifest-v4.json", + "docs/research/formal-semantic-validation/execution-snapshot-v56.json", + "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json" + ], + "falsification_protocol": "Replay every retained and new case through its production entrypoint, require complete digest and evidence joins, execute participant fixtures, and derive status from the recorded outcomes.", + "objective_fail_criteria": "A supported negative passes, a positive fails, an observation drifts, a required participant case is missing, or weaker evidence is promoted to solver, exploit-path, runtime-stability, or counterfactual assurance.", + "objective_pass_criteria": "Every claim class has positive and negative cases, all supported cases reproduce the frozen outcome, every participant obligation has passing positive and negative fixtures, and unsupported classes remain untested.", + "statement": "At the recorded source-state digest, the retained RAES controls have the bounded statuses recorded here; historical releases are integrity evidence, not current replay evidence.", + "threats_to_validity": [ + "The issue-specific corpus is intentionally small and does not enumerate every validator invariant.", + "The participant fixtures exercise reference production contracts and tests, not every independent backend realization.", + "The replay gate runs on one Python reference configuration and one pinned RAES revision.", + "Unsupported solver-level classes have protocol cases but no executable observations." + ] + }, + "claim_results": [ + { + "case_count": 2, + "claim_class_id": "schema-validity", + "evidence_status": "demonstrated", + "limitations": [ + "Bounded to the named source/model structural controls." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 4, + "claim_class_id": "semantic-consistency", + "evidence_status": "partial", + "limitations": [ + "Partial coverage of named static semantics and participant obligations, not universal consistency." + ], + "matching_case_count": 4, + "participant_obligation_count": 7, + "replayable_case_count": 4, + "unsupported_case_count": 0 + }, + { + "case_count": 2, + "claim_class_id": "graph-reachability", + "evidence_status": "partial", + "limitations": [ + "Partial workflow control-flow reachability only; not network, service, or exploit reachability." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 4, + "claim_class_id": "constraint-satisfiability", + "evidence_status": "demonstrated", + "limitations": [ + "Demonstrated only for raes-finite-domain-satisfiability-v1 and its pinned solver configuration." + ], + "matching_case_count": 4, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 2 + }, + { + "case_count": 4, + "claim_class_id": "exploit-path-validity", + "evidence_status": "demonstrated", + "limitations": [ + "Demonstrated only for the admitted snapshot, typed graph, query, semantics, and bounded search profile." + ], + "matching_case_count": 4, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 2 + }, + { + "case_count": 2, + "claim_class_id": "determinism-stability", + "evidence_status": "partial", + "limitations": [ + "Partial parse-to-compile repeatability only; runtime and backend determinism are untested." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 2, + "claim_class_id": "counterfactual-necessity", + "evidence_status": "untested", + "limitations": [ + "Untested because no governed intervention or ablation entrypoint ran." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 0, + "unsupported_case_count": 2 + } + ], + "corpus_revision": "4.0.0", + "evidence_status": "partial", + "execution_id": "issue-971-execution-v56", + "generated_at": "2026-09-27", + "limitations": [ + "Satisfiability is limited to raes-finite-domain-satisfiability-v1 and its exact translation, theory, and Z3 configuration.", + "The subset-minimal unsatisfiable core is not a universal proof certificate.", + "Exploit-path results are limited to the admitted snapshot, normalized graph, query, transition semantics, and bounded search profile.", + "A valid path is not backend execution and an invalid path is not real-world non-exploitability.", + "The production exploit-path JSON loader permits duplicate keys; the research loader rejects them without claiming stronger production behavior.", + "Participant replay inherits the host environment and is not described as hermetic.", + "Counterfactual necessity remains untested.", + "Scoped observation demand is not a claim class in this preregistration and is not promoted to demonstrated by this retest.", + "EXP-732 provenance joins are verified by their dedicated regression suite; this retained corpus makes no universal run, apparatus, source, or augmentation assurance claim.", + "This retained corpus does not establish native backend attestation fidelity; materialization contract checks remain separate operational provenance, not experimental observations.", + "Capture admission and evidence-proof authority are verified by issue-1237 regression tests, not promoted to a new claim class by this retained corpus.", + "Evidence-requirement refinement lineage is outside this retained formal claim set; this retest refreshes integrated source provenance without promoting that feature to a formal claim.", + "Authoring-adapter transport behavior is outside this retained formal claim set.", + "Operational recovery observation and startup reconciliation are verified by their API-404 regression suite, not promoted to a new formal claim class by this retained corpus.", + "Single-owner store admission, immutable target/run scope, and provider shutdown ordering are verified by their API-404 CP-5 regression suite, not promoted to a formal claim by this retained corpus.", + "Mixed and staged trial admission is verified by its SEM-234/SCE-002/API-407 regression suite, not promoted to a new formal claim class by this retained corpus.", + "Offline control-plane maintenance, readiness, and bounded audit behavior are verified by issue #1186 runtime tests, not promoted to a formal claim by this retained corpus.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 profile declarations and capability admission are covered by dedicated runtime tests; the retained formal corpus does not execute control-plane profile composition.", + "Issue #1016 mixed-runtime coordination is covered by dedicated runtime tests; the retained formal corpus does not establish backend-native mixed realization, multi-controller coordination, IFC, or equivalence.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", + "Issue #1389 temporal-subject admission is verified by dedicated compiler tests and adds no new formal-semantic claim to this retained corpus.", + "Issue #971 model construction is verified by its own tests; this retained corpus establishes no participant-crossing equivalence or runtime-realization claim." + ], + "plain_language_outcome": "The retained formal cases replay with unchanged outcomes against the source containing the crossing profile and opacity admission guards.", + "protocol_revision": "2.0.0" +} diff --git a/docs/research/formal-semantic-validation/bundles/retest-v56.json b/docs/research/formal-semantic-validation/bundles/retest-v56.json new file mode 100644 index 000000000..ef64104b6 --- /dev/null +++ b/docs/research/formal-semantic-validation/bundles/retest-v56.json @@ -0,0 +1,122 @@ +{ + "analysis_path": "docs/research/formal-semantic-validation/analysis-v56.json", + "analysis_sha256": "015ff5b9e94a04655798e23a84a249a5a6c7ef10d110c1b13d8bd800e8243ff7", + "artifacts": [ + { + "artifact_id": "finite-domain-satisfiable-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "sha256": "0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" + }, + { + "artifact_id": "finite-domain-satisfiable-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add" + }, + { + "artifact_id": "finite-domain-unsatisfiable-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "sha256": "cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" + }, + { + "artifact_id": "finite-domain-unsatisfiable-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d" + }, + { + "artifact_id": "typed-exploit-path-valid-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "sha256": "0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" + }, + { + "artifact_id": "typed-exploit-path-valid-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c" + }, + { + "artifact_id": "typed-exploit-path-invalid-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "sha256": "0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" + }, + { + "artifact_id": "typed-exploit-path-invalid-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533" + }, + { + "artifact_id": "schema-valid-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml", + "sha256": "41a9adffdf9f5f2ccc2f887dcf7b15fba3b47c83a1af15f33db872c4a2449d67" + }, + { + "artifact_id": "schema-unknown-field-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml", + "sha256": "51cf62319a86c95a2517995939d1f370573051835e4b55bb6d5beaf049640481" + }, + { + "artifact_id": "semantic-resolved-objective-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml", + "sha256": "75834bdc883e2003e1c473870bdf75700978955bb83095c6bd718ba6bd3908a6" + }, + { + "artifact_id": "semantic-dangling-assertion-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml", + "sha256": "1d25bee5f556054e5f0a518df025e4c62e080e1964035e3c1a12e074d88d3a5d" + }, + { + "artifact_id": "semantic-ambiguous-reference-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml", + "sha256": "653cbd2fd62e220d49fb86f80133884207df5ae6752846345ae3085b93f6e4ed" + }, + { + "artifact_id": "semantic-feature-cycle-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml", + "sha256": "e1f66d95a9ad039687aec8cccbc8843b514072ff08e006c1b4ca6aa5cd8d4ed1" + }, + { + "artifact_id": "workflow-reachable-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml", + "sha256": "54c40ceb98ad47247447d737973b2c55e8fb2045e209c7545c4fb20cf42dc3dc" + }, + { + "artifact_id": "workflow-unreachable-step-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml", + "sha256": "ef22ef2e260f1a7fd92d286f9b571716436b192ddfd54aea7bdfcfdda4ca52a2" + }, + { + "artifact_id": "compile-repeatability-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", + "sha256": "0bc40900d598c1af7a405d798ca19710405e53ced262d8733081abf12edf89fe" + }, + { + "artifact_id": "compile-non-vacuity-control-comparison-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml", + "sha256": "d85338f89f20a45515b12da8640173c1a52e47eb17ca0f4f6b4f8f3306e863a1" + } + ], + "bundle_id": "raes-formal-semantic-validation", + "corpus_path": "docs/research/formal-semantic-validation/corpus/manifest-v4.json", + "corpus_sha256": "c57207af72406aa4f70882b9bbeb7cedcc79cf3854c878a95e3eb1fa59ea7a72", + "protocol_path": "docs/research/formal-semantic-validation/protocol-v2.json", + "protocol_sha256": "abf94093e344bf495dfb04e8b0c5985c0beaab8ebb17a75e15c8674fa81b1a7c", + "revision": "56.0.0", + "snapshot_path": "docs/research/formal-semantic-validation/execution-snapshot-v56.json", + "snapshot_sha256": "2e7343c23a224cc1e7892afcda0793991a02aa07eed7b2a447af4ba12c941550" +} diff --git a/docs/research/formal-semantic-validation/execution-snapshot-v56.json b/docs/research/formal-semantic-validation/execution-snapshot-v56.json new file mode 100644 index 000000000..7cc123be6 --- /dev/null +++ b/docs/research/formal-semantic-validation/execution-snapshot-v56.json @@ -0,0 +1,652 @@ +{ + "baseline": { + "execution_id": "issue-1389-execution-v54", + "release_path": "docs/research/formal-semantic-validation/bundles/retest-v54.json", + "release_revision": "55.0.0", + "release_sha256": "89591fe7e90a57a5d6047eb442171a6c1b1fdac7e5cf13ef458a374dd0a54398" + }, + "captured_at": "2026-09-27T17:33:58.330055+00:00", + "commands": [ + { + "argv": [ + "implementations/python/.venv/bin/python", + "tools/check_formal_semantic_validation.py" + ], + "command_id": "bundle-replay", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/pytest", + "-q", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record", + "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", + "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" + ], + "command_id": "participant-fixtures", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "satisfiability", + "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "--profile", + "raes-finite-domain-satisfiability-v1" + ], + "command_id": "finite-domain-satisfiable-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "satisfiability", + "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "--profile", + "raes-finite-domain-satisfiability-v1" + ], + "command_id": "finite-domain-unsatisfiable-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "exploit-path", + "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "--profile", + "raes-exploit-path-analysis-v1" + ], + "command_id": "typed-exploit-path-valid-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "exploit-path", + "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "--profile", + "raes-exploit-path-analysis-v1" + ], + "command_id": "typed-exploit-path-invalid-v2", + "network": "disabled" + } + ], + "configuration_id": "raes-python-reference-offline-v41", + "corpus_revision": "4.0.0", + "deviations": [], + "execution_id": "issue-971-execution-v56", + "execution_status": "complete", + "observations": [ + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "schema-valid-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "A passing minimal source does not establish semantic correctness." + ], + "replayable": true, + "result_digest": "f7d364ef384df8a1526b489501835b635021c860793b5764f91d956710d2250c", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "schema-unknown-field", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLParseError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The observation covers one unknown-field defect only." + ], + "replayable": true, + "result_digest": "f55d834b458f8e069e1c69061b4cc0a6d61e0e052bf90c670f2e6a5ad8b5bd98", + "source_digest": null + }, + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "semantic-resolved-objective", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "This is a positive control for one objective-reference slice." + ], + "replayable": true, + "result_digest": "652288785dc09095955ed3649f6407d616fb7c4d4f4188df4ed513ccb7537e0b", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-dangling-assertion", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "A single dangling reference does not prove complete semantic coverage." + ], + "replayable": true, + "result_digest": "0207cf616b56708ca9b8c4499d3301abe22dbe52162cf8d58d3bec429d9db024", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-ambiguous-reference", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "One namespace collision does not enumerate every ambiguity surface." + ], + "replayable": true, + "result_digest": "9da4a87797d228e0012ab6b30459f4892e41aa6f224a9840be035fee4a2eea73", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-feature-cycle", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "One static dependency cycle does not establish general constraint satisfiability." + ], + "replayable": true, + "result_digest": "d15dbcd99fb4f20b965d7031b07dd6534576302270399c3fa656d29e7de02b83", + "source_digest": null + }, + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "workflow-reachable-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The graph is workflow control flow only." + ], + "replayable": true, + "result_digest": "b1b49649b54bd59d4ef357b39cf9158da90f4eae560f8dd756acf97bd0827a06", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "workflow-unreachable-step", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The result does not establish network, service, participant, or exploit reachability." + ], + "replayable": true, + "result_digest": "bb931d19346ef9193408ae6c85deb4079704378fc5f00dc5f47a2817cff21943", + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "whole-scenario-satisfiable-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "No governed whole-scenario constraint theory or solver exists." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "whole-scenario-unsatisfiable-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Local checks cannot produce a whole-scenario unsat certificate." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "valid-exploit-path-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The issue-168 baseline had no canonical typed attack graph or path-query entrypoint." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "invalid-exploit-path-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Vulnerability and topology declarations are not an invalid-path proof." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "stable", + "analysis_profile": null, + "case_id": "compile-repeatability-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The witness ends at compiled output." + ], + "replayable": true, + "result_digest": "11264a648a949917c0e84a2a1e5d116139a35e6cb941844735a422df95141d6c", + "source_digest": null + }, + { + "actual_outcome": "distinguishable", + "analysis_profile": null, + "case_id": "compile-non-vacuity-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", + "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Distinct digests are a non-vacuity control, not semantic non-equivalence proof." + ], + "replayable": true, + "result_digest": "72c1ee8c7bbc1f970216fa232b3d4ae917bcb003bd823439bbac8a5db94214e2", + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "necessity-witness-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "No governed intervention or ablation protocol exists." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "non-necessity-control-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Attribution and negative fixtures do not demonstrate non-necessity." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "satisfiable", + "analysis_profile": "raes-finite-domain-satisfiability-v1", + "case_id": "finite-domain-satisfiable-v2", + "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "scenario-satisfiability-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "evidence_artifact_sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add", + "evidence_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", + "evidence_profile": "scenario-satisfiability-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "specs/formal/scenario-satisfiability/README.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Demonstrates only the pinned finite-domain theory, translation, solver profile, and source." + ], + "replayable": true, + "result_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", + "source_digest": "sha256:0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" + }, + { + "actual_outcome": "unsatisfiable", + "analysis_profile": "raes-finite-domain-satisfiability-v1", + "case_id": "finite-domain-unsatisfiable-v2", + "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "scenario-satisfiability-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "evidence_artifact_sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d", + "evidence_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", + "evidence_profile": "scenario-satisfiability-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "specs/formal/scenario-satisfiability/README.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The subset-minimal core is evidence for the pinned translation and solver, not a proof certificate for arbitrary SDL." + ], + "replayable": true, + "result_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", + "source_digest": "sha256:cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" + }, + { + "actual_outcome": "valid-path", + "analysis_profile": "raes-exploit-path-analysis-v1", + "case_id": "typed-exploit-path-valid-v2", + "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "exploit-path-analysis-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "evidence_artifact_sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c", + "evidence_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", + "evidence_profile": "exploit-path-analysis-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "specs/formal/exploit-path-analysis/README.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The witness is bounded to the admitted snapshot, normalized graph, query, semantics, and search profile; it does not establish backend execution." + ], + "replayable": true, + "result_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", + "source_digest": "sha256:0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" + }, + { + "actual_outcome": "invalid-path", + "analysis_profile": "raes-exploit-path-analysis-v1", + "case_id": "typed-exploit-path-invalid-v2", + "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "exploit-path-analysis-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "evidence_artifact_sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533", + "evidence_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", + "evidence_profile": "exploit-path-analysis-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "specs/formal/exploit-path-analysis/README.md" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Structured rejection proves only that this bounded graph/query cannot reach its goal; it does not establish real-world non-exploitability." + ], + "replayable": true, + "result_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", + "source_digest": "sha256:0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" + } + ], + "participant_observations": [ + { + "evidence_refs": [ + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Covers the reference SDL/contract path, not every backend projection." + ], + "negative_outcome": "passed", + "obligation_id": "hidden-vs-visible-projection", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Covers declared applicability and one unresolved-precondition failure." + ], + "negative_outcome": "passed", + "obligation_id": "fail-closed-action-applicability", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Contract evidence does not prove every backend's live concurrency fidelity." + ], + "negative_outcome": "passed", + "obligation_id": "shared-state-effects", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Rejecting timestamp-only causality does not supply counterfactual proof." + ], + "negative_outcome": "passed", + "obligation_id": "ordering-before-causality", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Attribution labels disclose basis; they do not demonstrate necessity." + ], + "negative_outcome": "passed", + "obligation_id": "evidence-labeled-attribution", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "The fixtures establish layer separation, not outcome validity in every realization." + ], + "negative_outcome": "passed", + "obligation_id": "participant-local-outcome-separation", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", + "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" + ], + "execution_id": "issue-971-execution-v56", + "limitations": [ + "Reference conformance evidence remains bounded to declared realization profiles." + ], + "negative_outcome": "passed", + "obligation_id": "realization-profile-honesty", + "positive_outcome": "passed" + } + ], + "protocol_revision": "2.0.0", + "raes_revision": "49b5567e6b9c340ca6402424af774686ce02220a", + "source_state": { + "base_revision": "49b5567e6b9c340ca6402424af774686ce02220a", + "checkout_state": "modified", + "implementation_digest": "be811200bbac80134856404f1d88b4868f8c0d82b0212f5bdbd784a5fd5be285", + "profile": "python-reference-source/v2" + }, + "versions": { + "python": "3.14.4", + "raes": "5.0.0", + "z3_engine": "4.16.0", + "z3_solver": "4.16.0.0" + } +} diff --git a/docs/research/formal-semantic-validation/index.md b/docs/research/formal-semantic-validation/index.md index 74cfd2465..26a32b866 100644 --- a/docs/research/formal-semantic-validation/index.md +++ b/docs/research/formal-semantic-validation/index.md @@ -506,3 +506,8 @@ Release 55.0.0 is recorded in [`analysis-v54.json`](analysis-v54.json). It replays the retained formal cases after issue #1389 admitted the exact participant inject delivery address as a temporal subject. Outcomes and bounded claim limits remain unchanged. + +Release 56.0.0 replays the retained cases against issue #971’s crossing profile +and opacity admission guards in [execution-snapshot-v56.json](execution-snapshot-v56.json) +and [analysis-v56.json](analysis-v56.json). Outcomes and claim limits are +unchanged; the crossing models remain construction evidence only. diff --git a/docs/research/specification-coverage/analysis-v55.json b/docs/research/specification-coverage/analysis-v55.json new file mode 100644 index 000000000..70e4aef0d --- /dev/null +++ b/docs/research/specification-coverage/analysis-v55.json @@ -0,0 +1,105 @@ +{ + "analysis_id": "raes-standardized-specification-coverage-issue-971-v55", + "backend_leakage": [], + "claim": { + "allowed_evidence": [ + "pinned source metadata and bounded paraphrases", + "production parser, semantic, instantiation, admission, compiler, contract, and profile results", + "exact artifact digests and typed pointers", + "documented missing-concept and backend-specific dispositions" + ], + "claim_id": "raes-standardized-configurable-specification-coverage", + "disallowed_evidence": [ + "field-count or schema breadth alone", + "the existing scenario stress corpus as the representative request corpus", + "free-form metadata as typed coverage", + "backend-private interpretation", + "post-hoc removal or repair of falsifying concepts" + ], + "evidence_artifacts": [ + "docs/research/specification-coverage/protocol-v1.json", + "docs/research/specification-coverage/execution-snapshot-v55.json", + "docs/research/specification-coverage/analysis-v55.json" + ], + "falsification_protocol": "docs/research/specification-coverage/protocol-v1.json", + "objective_fail_criteria": "A load-bearing concept is missing or lossy, an applicable stage fails, or backend vocabulary is required in core SDL while the result claims success.", + "objective_pass_criteria": "Every load-bearing concept passes at every owning stage, backend-specific mechanics stay outside core SDL, and no requested concept is silently lost.", + "statement": "RAES provides a standardized configurable portable specification surface for the preregistered representative cyber-agent evaluation environment requirements without backend vocabulary in core SDL.", + "threats_to_validity": [ + "The representative corpus contains four source strata and sixteen atomic concepts rather than every cyber-range requirement.", + "The reference processor and repository fixtures are not independent backend implementations.", + "No live range, simulator federation, or participant execution was part of this offline specification-coverage test." + ] + }, + "classification_counts": { + "deliberately-backend-specific": 1, + "directly-expressible": 10, + "missing": 3, + "profile-or-manifest-constraint": 2 + }, + "evidence_status": "partial", + "execution_status": "complete", + "generated_at": "2026-09-27", + "limitations": [ + "This result demonstrates bounded specification coverage, not universal cyber-range coverage, usability, adoption, backend substitution, or behavioral equivalence.", + "The three missing concepts are evidence, not implementation tasks within this snapshot.", + "The retained protocol does not test recursive realization or plan-level profile semantics; this release only re-establishes its original bounded coverage result against the current implementation.", + "The retained protocol does not test evidence-requirement refinement lineage; the dedicated EXP-731 regression suite covers that production boundary.", + "Authoring-adapter transport behavior is outside this retained protocol.", + "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", + "Operational recovery observation and startup reconciliation are covered by their API-404 regression suite, not a new claim in this preregistered matrix.", + "Store ownership, immutable runtime scope, and provider shutdown ordering are covered by the API-404 CP-5 regression suite, not by this retained specification-coverage protocol.", + "Mixed/staged trial compilation and admission are covered by issue #1015 regression tests, not by this retained specification-coverage corpus; no live mixed-runtime result is claimed.", + "Issue #1186 control-plane recovery operations are covered by their runtime regression suite, not by this retained specification-coverage corpus.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", + "Participant-local outcome state is verified by the ACT-618 tests; this retained corpus makes no additional outcome-state claim.", + "Backend operation supervision contracts are covered by issue #1360 contract tests; this retained offline corpus establishes no live backend supervision or recovery guarantee.", + "This capture replays the merged issue #1360 and #1357 source; the protocol makes no live backend execution or supervision claim.", + "This capture replays the merged issue #1360 and #1358 source; the protocol makes no live backend execution or supervision claim.", + "Issue #1389 participant inject delivery temporal-subject admission is covered by dedicated compiler tests; this retained matrix makes no new timing or execution claim.", + "Issue #971 adds offline crossing model construction; this retained protocol establishes no crossing equivalence or runtime-realization claim." + ], + "load_bearing_results": { + "failed": 0, + "missing": 0, + "passed": 10, + "total": 10 + }, + "plain_language_outcome": "The retained specification matrix replays with unchanged classifications against the source containing the crossing profile and opacity admission guards.", + "protocol_revision": "1.0.0", + "request_results": [ + { + "concept_count": 6, + "failed_stage_count": 0, + "missing_count": 0, + "request_id": "survey-representative-range", + "status": "demonstrated" + }, + { + "concept_count": 5, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "cyborg-participant-evaluation", + "status": "partial" + }, + { + "concept_count": 3, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "vsdl-configurable-infrastructure", + "status": "partial" + }, + { + "concept_count": 2, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "cyber-dem-federation", + "status": "partial" + } + ], + "snapshot_id": "raes-standardized-specification-coverage-issue-971-v55", + "snapshot_sha256": "973db4507f6bc2ae0c77345f2c85393c42c9411f0e4891f031108ee898774f76" +} diff --git a/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v55.json b/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v55.json new file mode 100644 index 000000000..1b7dd8b79 --- /dev/null +++ b/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v55.json @@ -0,0 +1,10 @@ +{ + "analysis_path": "docs/research/specification-coverage/analysis-v55.json", + "analysis_sha256": "8e11f6e6a2de00ccd58ca5e56bc2b0125f01033537cb11b9c2b0a56c3a51b56b", + "bundle_id": "raes-standardized-specification-coverage", + "protocol_path": "docs/research/specification-coverage/protocol-v1.json", + "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", + "revision": "55.0.0", + "snapshot_path": "docs/research/specification-coverage/execution-snapshot-v55.json", + "snapshot_sha256": "0816f47c70700e3527ca5ea3559c4e40afba5a1e2a415495aafd5036de29fb8d" +} diff --git a/docs/research/specification-coverage/execution-snapshot-v55.json b/docs/research/specification-coverage/execution-snapshot-v55.json new file mode 100644 index 000000000..18f6383a1 --- /dev/null +++ b/docs/research/specification-coverage/execution-snapshot-v55.json @@ -0,0 +1,700 @@ +{ + "artifacts": [ + { + "artifact_id": "enterprise-participant-sdl", + "kind": "sdl", + "path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032", + "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" + }, + { + "artifact_id": "port-range-sdl", + "kind": "sdl", + "path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f", + "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" + }, + { + "artifact_id": "experiment-task-contract", + "kind": "experiment-task", + "path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc", + "validator": "raes_contracts.contracts.ExperimentTaskModel" + }, + { + "artifact_id": "apparatus-context-contract", + "kind": "experiment-apparatus-context", + "path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299", + "validator": "raes_contracts.contracts.ExperimentApparatusContextModel" + }, + { + "artifact_id": "backend-profile", + "kind": "backend-profile", + "path": "contracts/profiles/backend/orchestration-capable.json", + "sha256": "f70b8505a5c0055416db86c533e2e5bf08b11e5a514f076223b6d6c36215a092", + "validator": "raes_contracts.backend_profiles.BackendProfileModel" + }, + { + "artifact_id": "known-limitations", + "kind": "documentation", + "path": "docs/explain/sdl/limitations.md", + "sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4", + "validator": "documentation evidence only" + } + ], + "baseline": { + "release_revision": "1.1.0", + "release_sha256": "4020a1d56c7fe2831cec59ea64a12bbda9d38ccd94f93b916dd90f1a28f17fcb" + }, + "captured_at": "2026-09-27", + "concept_results": [ + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "range-topology", + "rationale": "SDL nodes and infrastructure own host, network, link, and dependency meaning; the compiler emits canonical node deployment addresses.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed VM declaration.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Links and dependencies resolved.", + "outcome": "passed", + "pointer": "/infrastructure/shipping-portal", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Published instantiated shape admitted.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical deployment address retained.", + "outcome": "passed", + "pointer": "/node_deployments/provision.node.shipping-portal", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/nodes/shipping-portal" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "exercise-roles", + "rationale": "SDL entity roles own exercise responsibility without becoming control-plane identity or authorization.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed red role.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant/role", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Entity references validated.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Role retained after instantiation.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant/role", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Role retained in entity specification.", + "outcome": "passed", + "pointer": "/entity_specs/enterprise-participant/role", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/entities/enterprise-participant/role" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "evaluation-objectives", + "rationale": "SDL objectives own organization ownership, participant assignment, targets, windows, and assertion-based success; measures remain experiment contracts.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed objective declaration.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Owner, participant assignment, targets, assertions, and workflow refs resolved.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff/success", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Objective retained in admitted artifact.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical objective address retained.", + "outcome": "passed", + "pointer": "/objectives/evaluation.objective.demonstrate-handoff", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/objectives/demonstrate-handoff" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "control-workflows", + "rationale": "SDL workflows own the portable control graph and compile to canonical orchestration state contracts.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed control graph.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Step graph and objective refs validated.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery/steps", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Workflow retained after instantiation.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical control graph retained.", + "outcome": "passed", + "pointer": "/workflows/orchestration.workflow.yard-recovery", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/workflows/yard-recovery" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "authored-evidence-expectations", + "rationale": "SDL evidence requirements own portable capture intent and remain distinct from evidence records and measures.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed capture obligation.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Source refs and bindings validated.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Evidence intent retained in admitted artifact.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + } + ], + "typed_pointer": "/evidence_requirements/objective-truth-evidence" + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [], + "classification": "profile-or-manifest-constraint", + "completeness_disposition": "implemented", + "concept_id": "apparatus-selection-constraints", + "rationale": "The experiment task contract binds processor/backend identities, manifest refs, and capabilities outside SDL.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed ExperimentTaskModel validated.", + "outcome": "passed", + "pointer": "/apparatus_constraints/allowed_backend_refs/0", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/apparatus_constraints/allowed_backend_refs/0" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-agent", + "rationale": "SDL agents own participant entity, knowledge, actions, observation boundaries, and operating scope.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed participant declaration.", + "outcome": "passed", + "pointer": "/agents/participant-agent", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Participant refs and scope validated.", + "outcome": "passed", + "pointer": "/agents/participant-agent/observation_boundaries", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Participant retained in admitted artifact.", + "outcome": "passed", + "pointer": "/agents/participant-agent", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Compiled participant scope retained.", + "outcome": "passed", + "pointer": "/agent_specs/participant-agent", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/agents/participant-agent" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-action-contract", + "rationale": "The action contract declares portable preconditions, effects, observations, evidence, and failure classes without a runner command.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed action contract.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Action refs and evidence bindings validated.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login/effects", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Action retained in admitted artifact.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical action address retained.", + "outcome": "passed", + "pointer": "/action_contracts/participant.action-contract.probe-customer-portal-login", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/action_contracts/probe-customer-portal-login" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-observation-boundary", + "rationale": "The observation boundary separately declares visible, hidden, and evidence-only information with transition rules.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed observation boundary.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Information refs and transitions validated.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view/view_rules", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Boundary retained in admitted artifact.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical boundary address retained.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant.observation-boundary.participant-view", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/observation_boundaries/participant-view" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "evaluation-measure", + "rationale": "ExperimentTaskModel owns metric construct, unit, direction, aggregation, and evidence requirements outside SDL objectives.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed task contract validated.", + "outcome": "passed", + "pointer": "/evaluation_protocol/metric_definitions/foothold-achieved", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/evaluation_protocol/metric_definitions/foothold-achieved" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "participant-tool-affordance", + "rationale": "This preregistered matrix has no tested carrier for participant tool affordances. The retained missing classification records missing coverage evidence, not the absence of current participant-behavior capabilities.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "The preregistered carrier slot was not run; metadata does not substitute for a typed coverage test.", + "outcome": "not_run", + "pointer": null, + "stage_id": "authored", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "resource-constrained-topology", + "rationale": "SDL node resources and infrastructure dependencies express portable resource intent without provider resource identifiers.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed CPU and memory declaration.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal/resources", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Resource-bearing topology validated.", + "outcome": "passed", + "pointer": "/infrastructure/shipping-portal", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Constraints retained in admitted artifact.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal/resources", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Deployment specification retains resource intent.", + "outcome": "passed", + "pointer": "/node_deployments/provision.node.shipping-portal", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/nodes/shipping-portal/resources" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "formal-constraint-satisfiability", + "rationale": "This coverage matrix did not exercise a solver-backed carrier. The separate formal-semantic-validation release demonstrates its bounded finite-domain profile; that result is not silently imported into this protocol's missing carrier slot.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "No coverage-carrier execution was performed here; independent solver evidence does not change this preregistered denominator.", + "outcome": "not_run", + "pointer": null, + "stage_id": "semantic", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [ + { + "allowed": true, + "artifact_path": "source:vsdl-paper", + "pointer": "source sections 4-5", + "reason": "Legitimate VSDL realization vocabulary, not RAES core SDL structure.", + "term": "OpenStack/Terraform/Packer" + } + ], + "classification": "deliberately-backend-specific", + "completeness_disposition": "external", + "concept_id": "provider-specific-provisioning", + "rationale": "Provider image selection and provisioning engines are realization mechanics and therefore remain outside core SDL.", + "stage_results": [ + { + "artifact_path": "contracts/profiles/backend/orchestration-capable.json", + "diagnostic_codes": [], + "note": "The portable boundary requires backend contracts; it does not standardize a provider engine.", + "outcome": "not_applicable", + "pointer": "/required_contracts", + "stage_id": "realization-disclosure", + "validation_strength": "profile" + } + ], + "typed_pointer": null + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [], + "classification": "profile-or-manifest-constraint", + "completeness_disposition": "implemented", + "concept_id": "apparatus-clock-context", + "rationale": "ExperimentApparatusContextModel records clock authority, time domain, and synchronization as apparatus facts outside scenario meaning.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed apparatus context contract validated.", + "outcome": "passed", + "pointer": "/clocks/0", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/clocks/0" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "federated-object-event-exchange", + "rationale": "The federated cyber object/event exchange carrier was not exercised by this preregistered matrix. Runtime event internals are not treated as equivalent evidence.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "The missing coverage-carrier test is recorded explicitly, without inferring an ecosystem-wide capability absence.", + "outcome": "not_run", + "pointer": null, + "stage_id": "contract", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + } + ], + "deviations": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "baseline_sha256": "54ba1a60220e27a55da9cd2a407d7d3ab836fa54460d0b0c6cad87c2e744ddbb", + "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", + "retest_sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "baseline_sha256": "a27c7a64e0c5c618fadaccafdf1a4e71600170a8b77b983190822b5141f00dec", + "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", + "retest_sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f" + }, + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "baseline_sha256": "21952a752f4e8581a9fc3b872e4bc308150548170d38bcfc83dbbe35ff5e0b9f", + "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", + "retest_sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc" + }, + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "baseline_sha256": "9536d897a09cbc6920e667e4f8f9371e51307aa0b3b5ff3c7de682dd783420ab", + "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", + "retest_sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299" + }, + { + "artifact_path": "docs/explain/sdl/limitations.md", + "baseline_sha256": "129cf17810aad4c51988bc872e28fe43ae95019a80053c42d800ff7e2b9cc93e", + "rationale": "Correct historical mandatory-profile guidance after issue #1207; retain the preregistered missing-concept classifications and coverage limits.", + "retest_sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4" + } + ], + "execution_status": "complete", + "implementation_surfaces": [ + { + "content_sha256": "2818046a74bf8be2ede16398454d52da070fff8e9b230527d2e566959fd37655", + "path": "implementations/python/packages/raes_contracts", + "surface_id": "contract-models" + }, + { + "content_sha256": "27cf5d5bac07ef4b79d922e7c924832c89f13f12ab7e3a441b1a97557dba2b14", + "path": "implementations/python/packages/raes_processor", + "surface_id": "processor-pipeline" + }, + { + "content_sha256": "9ecd780448b054693503bab246120a1a2bb49a43016d0b9c27c5284ba609833f", + "path": "implementations/python/packages/raes", + "surface_id": "sdl-pipeline" + } + ], + "limitations": [ + "The execution validates the pinned reference implementation and published contracts, not an independent backend.", + "Repository-owned examples are exact execution artifacts but are not themselves the literature-derived request corpus; the protocol's requests and concepts are.", + "No live range, participant, simulator federation, or provider provisioning engine was executed.", + "Missing concepts remain frozen in this snapshot and require separately scoped product work before a later rerun.", + "This capture replays the retained protocol after EXP-732 run, apparatus, measurement-channel, and augmentation-producer provenance validation; it adds no independent backend or universal provenance assurance claim.", + "Materialization attestation is covered by its dedicated regression suite, not a new claim in this preregistered matrix.", + "This capture refreshes the corrected runtime limitations prose for issue #959; the protocol, coverage classifications and implementation source are unchanged.", + "This capture replays open-by-default augmentation scope integrated with the EXP-731 evidence refinements after composition type refinement; it does not evaluate native backend scope enforcement or broaden the preregistered coverage claims.", + "This capture replays the retained protocol after merging ACT-612 participant relationships with open-by-default augmentation scope; it adds no claim of realized participant relationships or native backend scope enforcement.", + "This capture replays issue #1299 partial listener descriptions on the integrated source state; endpoint completeness and backend admission remain outside this protocol's claims.", + "This capture also binds authoring-adapter semantic conformance to the integrated source; adapter transport behavior remains outside this protocol's claims.", + "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", + "This capture binds issue #1297 service-manager identity, native-name, and explicitly selected systemd-state contract changes to the integrated source. It exercises no live service manager and adds no backend-execution claim.", + "This capture replays the retained specification-coverage protocol after API-404 startup reconciliation added an operational recovery-observation contract. It does not evaluate crash recovery, classify provider effects, or broaden EXP-715 experiment-observation claims.", + "This capture binds API-404 single-owner store admission and immutable target/run scope to the integrated source. The retained offline protocol does not exercise process leases, SQLite lifecycle ordering, or crash recovery.", + "This capture binds issue #1015 deterministic mixed and staged trial admission to the integrated source. The retained offline language corpus does not execute mixed runtimes, phase transitions, backend handoff, or scheduler-driven realization.", + "This replay binds issue #1186 offline control-plane maintenance, readiness, and bounded audit code to the integrated source. The retained language corpus does not execute store recovery, HTTP health behavior, or audit redaction.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", + "Issue #1016 mixed-runtime coordination is covered by its dedicated runtime suite. The retained language corpus does not execute mixed providers or establish backend-native realization, multi-controller coordination, IFC, or equivalence.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution." + ], + "protocol_revision": "1.0.0", + "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", + "raes_revision": "49b5567e6b9c340ca6402424af774686ce02220a", + "snapshot_id": "raes-standardized-specification-coverage-issue-971-v55", + "snapshot_revision": "55.0.0", + "source_state": { + "base_revision": "49b5567e6b9c340ca6402424af774686ce02220a", + "checkout_state": "modified", + "implementation_digest": "be811200bbac80134856404f1d88b4868f8c0d82b0212f5bdbd784a5fd5be285", + "profile": "python-reference-source/v2" + } +} diff --git a/docs/research/specification-coverage/index.md b/docs/research/specification-coverage/index.md index af9bd738b..5524ed6f4 100644 --- a/docs/research/specification-coverage/index.md +++ b/docs/research/specification-coverage/index.md @@ -292,7 +292,7 @@ the port scenario. Historical captures and archived example bytes are retained. The matrix classifications and untested concepts are unchanged; no execution authority, successful action, or live backend fidelity is inferred. -Current validation requires release 54.0.0 and rejects duplicate or unsupported +Current validation requires release 55.0.0 and rejects duplicate or unsupported future revisions. It executes current artifacts, requires exact source and package hashes, and checks all passing stage pointers. `source_state` discloses the base Git commit, modified checkout state, and exact implementation digest; @@ -443,3 +443,8 @@ and claim limits remain unchanged; participant delivery timing is verified by its dedicated compiler tests in [`execution-snapshot-v54.json`](execution-snapshot-v54.json) and [`analysis-v54.json`](analysis-v54.json). + +Release 55.0.0 replays the retained matrix against issue #971’s crossing profile +and opacity admission guards in [execution-snapshot-v55.json](execution-snapshot-v55.json) +and [analysis-v55.json](analysis-v55.json). Classifications and claim limits +are unchanged; this is no participant-crossing equivalence result. diff --git a/implementations/python/tests/test_formal_semantic_validation.py b/implementations/python/tests/test_formal_semantic_validation.py index 812bf74be..9866d6dad 100644 --- a/implementations/python/tests/test_formal_semantic_validation.py +++ b/implementations/python/tests/test_formal_semantic_validation.py @@ -134,6 +134,7 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: "53.0.0", "54.0.0", "55.0.0", + "56.0.0", ] assert all(validate_release_bundle(REPO_ROOT, release) == [] for release in releases) @@ -142,10 +143,10 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: def test_current_retest_bundle_is_coherent_and_clean() -> None: release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, REPO_ROOT) - assert release.manifest["revision"] == "55.0.0" + assert release.manifest["revision"] == "56.0.0" assert protocol["revision"] == "2.0.0" assert corpus["revision"] == "4.0.0" - assert snapshot["baseline"]["release_revision"] == "54.0.0" + assert snapshot["baseline"]["release_revision"] == "55.0.0" assert snapshot["deviations"] == [] assert validate_retest_bundle(REPO_ROOT, release, protocol, corpus, snapshot, analysis) == [] diff --git a/implementations/python/tests/test_specification_coverage.py b/implementations/python/tests/test_specification_coverage.py index cb3d4c9fc..85fb6425e 100644 --- a/implementations/python/tests/test_specification_coverage.py +++ b/implementations/python/tests/test_specification_coverage.py @@ -53,7 +53,7 @@ def test_immutable_bundle_index_preserves_concurrent_captures() -> None: bundles = copy_bundle(load_bundles, REPO_ROOT) assert {manifest["revision"] for manifest, *_rest in bundles} >= {"1.0.0", "1.1.0", "19.0.0"} manifest, *_rest = copy_bundle(load_bundle, REPO_ROOT) - assert manifest["revision"] == "54.0.0" + assert manifest["revision"] == "55.0.0" def test_historical_failures_name_the_revision_specific_documents() -> None: diff --git a/tools/check_specification_coverage.py b/tools/check_specification_coverage.py index 39cdc899c..f9370fe6a 100644 --- a/tools/check_specification_coverage.py +++ b/tools/check_specification_coverage.py @@ -157,12 +157,12 @@ def _load_bundle_index(repo_root: Path) -> list[tuple[str, dict[str, object]]]: "51.0.0", "52.0.0", "53.0.0", - } | {"54.0.0"} + } | {"54.0.0", "55.0.0"} if ( - dict(records)[current_path].get("revision") != "54.0.0" + dict(records)[current_path].get("revision") != "55.0.0" or {record.get("revision") for _, record in records} != supported_revisions ): - raise ValueError("coverage evidence requires the explicit current 54.0.0 release and supported history") + raise ValueError("coverage evidence requires the explicit current 55.0.0 release and supported history") return records diff --git a/tools/formal_semantic_validation/_baseline.py b/tools/formal_semantic_validation/_baseline.py index a7b4b7840..c811eec11 100644 --- a/tools/formal_semantic_validation/_baseline.py +++ b/tools/formal_semantic_validation/_baseline.py @@ -6,7 +6,9 @@ from pathlib import Path from tools.evidence_bundle_index import load_index_records -from tools.formal_semantic_validation._release_revisions import _HISTORICAL_RETEST_REVISIONS +from tools.formal_semantic_validation._release_revisions import ( + _HISTORICAL_RETEST_REVISIONS, +) from tools.formal_semantic_validation._shape import ( _closed_object, _failure, @@ -190,6 +192,7 @@ def _selected_baseline_manifest( "52.0.0", "53.0.0", "54.0.0", + "55.0.0", }: expected_corpus_path = "docs/research/formal-semantic-validation/corpus/manifest-v4.json" elif baseline_revision in _V3_CORPUS_REVISIONS: diff --git a/tools/formal_semantic_validation/_loading.py b/tools/formal_semantic_validation/_loading.py index c7b8ba558..e0746c97a 100644 --- a/tools/formal_semantic_validation/_loading.py +++ b/tools/formal_semantic_validation/_loading.py @@ -5,7 +5,9 @@ from pathlib import Path from tools.evidence_bundle_index import load_index_records, revision_key -from tools.formal_semantic_validation._release_revisions import _SUPPORTED_RETEST_REVISIONS +from tools.formal_semantic_validation._release_revisions import ( + _SUPPORTED_RETEST_REVISIONS, +) from tools.formal_semantic_validation._types import ( _MAX_FILE_BYTES, MANIFEST_PATH, @@ -28,7 +30,12 @@ def load_release_bundles(repo_root: Path = REPO_ROOT) -> list[EvidenceRelease]: max_bytes=_MAX_FILE_BYTES, ) current_release_path(records) - supported_revisions = _SUPPORTED_RETEST_REVISIONS | {"1.0.0", "1.1.0", "1.2.0", "2.0.0"} + supported_revisions = _SUPPORTED_RETEST_REVISIONS | { + "1.0.0", + "1.1.0", + "1.2.0", + "2.0.0", + } if {record.get("revision") for _, record in records} != supported_revisions: raise ValueError("formal evidence requires every supported historical and current release") releases: list[EvidenceRelease] = [] @@ -75,6 +82,6 @@ def load_retest_bundle( if not releases: raise ValueError("the formal semantic-validation index selects no v2 retest release") release = max(releases, key=lambda item: revision_key(item.manifest.get("revision"))) - if release.manifest.get("revision") != "55.0.0" or release.protocol.get("revision") != "2.0.0": - raise ValueError("the current formal evidence release must be the explicit 55.0.0 retest") + if release.manifest.get("revision") != "56.0.0" or release.protocol.get("revision") != "2.0.0": + raise ValueError("the current formal evidence release must be the explicit 56.0.0 retest") return release, release.protocol, release.corpus, release.snapshot, release.analysis diff --git a/tools/formal_semantic_validation/_release_revisions.py b/tools/formal_semantic_validation/_release_revisions.py index b818c373b..b1a838b0d 100644 --- a/tools/formal_semantic_validation/_release_revisions.py +++ b/tools/formal_semantic_validation/_release_revisions.py @@ -53,7 +53,7 @@ "51.0.0", "52.0.0", } -) | {"53.0.0", "54.0.0"} +) | {"53.0.0", "54.0.0", "55.0.0"} -_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"55.0.0"} +_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"56.0.0"} _SOURCE_BOUND_RETEST_REVISIONS = _SUPPORTED_RETEST_REVISIONS - {"3.0.0"} diff --git a/tools/formal_semantic_validation/_releases.py b/tools/formal_semantic_validation/_releases.py index aa4a05987..5e9f92e86 100644 --- a/tools/formal_semantic_validation/_releases.py +++ b/tools/formal_semantic_validation/_releases.py @@ -159,7 +159,7 @@ def validate_release_bundle(repo_root: Path, release: EvidenceRelease) -> list[P release.corpus, release.snapshot, release.analysis, - replay_current=manifest.get("revision") == "55.0.0", + replay_current=manifest.get("revision") == "56.0.0", ) ) else: @@ -272,6 +272,7 @@ def _expected_corpus_revision(release_revision: object) -> str: "53.0.0", "54.0.0", "55.0.0", + "56.0.0", }: expected_corpus_revision = "4.0.0" return expected_corpus_revision @@ -299,7 +300,7 @@ def validate_retest_bundle( return [ _failure( "formal-validation-current-replay-required", - "only releases 3.0.0 through 54.0.0 can use integrated historical validation", + "only releases 3.0.0 through 55.0.0 can use integrated historical validation", snapshot_path, ) ] @@ -427,6 +428,7 @@ def _current_retest_source_failures( "53.0.0": "52.0.0", "54.0.0": "53.0.0", "55.0.0": "54.0.0", + "56.0.0": "55.0.0", }[release_revision] if not isinstance(baseline, Mapping) or baseline.get("release_revision") != expected_baseline: failures.append( diff --git a/tools/formal_semantic_validation/_retest.py b/tools/formal_semantic_validation/_retest.py index cbe06846f..6e6c95161 100644 --- a/tools/formal_semantic_validation/_retest.py +++ b/tools/formal_semantic_validation/_retest.py @@ -37,7 +37,7 @@ ) from tools.policy.common import PolicyFailure -_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 56)) +_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 57)) @dataclasses.dataclass(frozen=True) From 406033379df730d522c333b5db8e1f39f185f044 Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sun, 27 Sep 2026 19:40:50 +0200 Subject: [PATCH 5/8] test(evidence): align current capture revision assertions --- .../python/tests/test_issue_989_versioned_evidence.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/implementations/python/tests/test_issue_989_versioned_evidence.py b/implementations/python/tests/test_issue_989_versioned_evidence.py index 707f08176..42f4f2753 100644 --- a/implementations/python/tests/test_issue_989_versioned_evidence.py +++ b/implementations/python/tests/test_issue_989_versioned_evidence.py @@ -230,7 +230,7 @@ def test_latest_current_release_is_versioned_and_strict(monkeypatch): from tools.formal_semantic_validation._releases import validate_retest_bundle release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, ROOT) - assert release.manifest["revision"] == "55.0.0" + assert release.manifest["revision"] == "56.0.0" original = _retest.replay_case def changed_result(root, case): @@ -283,7 +283,7 @@ def test_specification_current_capture_does_not_accept_old_artifact_digest(artif from tools.check_specification_coverage import load_bundle, validate_bundle manifest, protocol, snapshot, analysis = copy_bundle(load_bundle, ROOT) - assert manifest["revision"] == "54.0.0" + assert manifest["revision"] == "55.0.0" snapshot = deepcopy(snapshot) artifact = next(a for a in snapshot["artifacts"] if a["artifact_id"] == artifact_id) artifact["sha256"] = old_digest @@ -507,6 +507,7 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "53.0.0", "54.0.0", "55.0.0", + "56.0.0", ] if family == "formal" else [ @@ -565,6 +566,7 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "52.0.0", "53.0.0", "54.0.0", + "55.0.0", ] ) revisions.pop(-1 if removed == "current" else 0) From 8a8cc46859a161f7c93aa07c61b5338c23973619 Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sun, 27 Sep 2026 23:03:28 +0200 Subject: [PATCH 6/8] fix(formal): address profile typing and assertion clarity --- .../analysis-v57.json | 156 ++++ .../bundles/retest-v57.json | 122 +++ .../execution-snapshot-v57.json | 652 ++++++++++++++++ .../formal-semantic-validation/index.md | 4 + .../specification-coverage/analysis-v56.json | 105 +++ ...-specification-coverage-issue-971-v56.json | 10 + .../execution-snapshot-v56.json | 700 ++++++++++++++++++ docs/research/specification-coverage/index.md | 6 +- .../_participant_crossing_profile.py | 11 +- .../tests/test_formal_semantic_validation.py | 5 +- .../tests/test_issue_971_crossing_export.py | 4 +- .../tests/test_issue_971_crossing_models.py | 9 +- .../tests/test_issue_971_crossing_profile.py | 18 +- .../test_issue_989_versioned_evidence.py | 6 +- .../tests/test_specification_coverage.py | 2 +- .../crossing-models/rev2/manifest.json | 2 +- tools/check_specification_coverage.py | 6 +- tools/formal_semantic_validation/_baseline.py | 1 + tools/formal_semantic_validation/_loading.py | 4 +- .../_release_revisions.py | 4 +- tools/formal_semantic_validation/_releases.py | 6 +- tools/formal_semantic_validation/_retest.py | 2 +- 22 files changed, 1801 insertions(+), 34 deletions(-) create mode 100644 docs/research/formal-semantic-validation/analysis-v57.json create mode 100644 docs/research/formal-semantic-validation/bundles/retest-v57.json create mode 100644 docs/research/formal-semantic-validation/execution-snapshot-v57.json create mode 100644 docs/research/specification-coverage/analysis-v56.json create mode 100644 docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v56.json create mode 100644 docs/research/specification-coverage/execution-snapshot-v56.json diff --git a/docs/research/formal-semantic-validation/analysis-v57.json b/docs/research/formal-semantic-validation/analysis-v57.json new file mode 100644 index 000000000..970013b5b --- /dev/null +++ b/docs/research/formal-semantic-validation/analysis-v57.json @@ -0,0 +1,156 @@ +{ + "analysis_id": "issue-971-analysis-v57", + "claim": { + "allowed_evidence": [ + "production parser and semantic-validator results", + "canonical compiled digests", + "participant contract regression tests", + "pinned protocol, corpus, and execution snapshot" + ], + "claim_id": "asr-530-formal-semantic-validation-retest", + "disallowed_evidence": [ + "schema success as semantic proof", + "workflow reachability as network or exploit reachability", + "FM labels as gate outcomes", + "attribution as counterfactual proof", + "formal prose or maintainer confidence alone" + ], + "evidence_artifacts": [ + "docs/research/formal-semantic-validation/protocol-v2.json", + "docs/research/formal-semantic-validation/corpus/manifest-v4.json", + "docs/research/formal-semantic-validation/execution-snapshot-v57.json", + "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json" + ], + "falsification_protocol": "Replay every retained and new case through its production entrypoint, require complete digest and evidence joins, execute participant fixtures, and derive status from the recorded outcomes.", + "objective_fail_criteria": "A supported negative passes, a positive fails, an observation drifts, a required participant case is missing, or weaker evidence is promoted to solver, exploit-path, runtime-stability, or counterfactual assurance.", + "objective_pass_criteria": "Every claim class has positive and negative cases, all supported cases reproduce the frozen outcome, every participant obligation has passing positive and negative fixtures, and unsupported classes remain untested.", + "statement": "At the recorded source-state digest, the retained RAES controls have the bounded statuses recorded here; historical releases are integrity evidence, not current replay evidence.", + "threats_to_validity": [ + "The issue-specific corpus is intentionally small and does not enumerate every validator invariant.", + "The participant fixtures exercise reference production contracts and tests, not every independent backend realization.", + "The replay gate runs on one Python reference configuration and one pinned RAES revision.", + "Unsupported solver-level classes have protocol cases but no executable observations." + ] + }, + "claim_results": [ + { + "case_count": 2, + "claim_class_id": "schema-validity", + "evidence_status": "demonstrated", + "limitations": [ + "Bounded to the named source/model structural controls." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 4, + "claim_class_id": "semantic-consistency", + "evidence_status": "partial", + "limitations": [ + "Partial coverage of named static semantics and participant obligations, not universal consistency." + ], + "matching_case_count": 4, + "participant_obligation_count": 7, + "replayable_case_count": 4, + "unsupported_case_count": 0 + }, + { + "case_count": 2, + "claim_class_id": "graph-reachability", + "evidence_status": "partial", + "limitations": [ + "Partial workflow control-flow reachability only; not network, service, or exploit reachability." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 4, + "claim_class_id": "constraint-satisfiability", + "evidence_status": "demonstrated", + "limitations": [ + "Demonstrated only for raes-finite-domain-satisfiability-v1 and its pinned solver configuration." + ], + "matching_case_count": 4, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 2 + }, + { + "case_count": 4, + "claim_class_id": "exploit-path-validity", + "evidence_status": "demonstrated", + "limitations": [ + "Demonstrated only for the admitted snapshot, typed graph, query, semantics, and bounded search profile." + ], + "matching_case_count": 4, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 2 + }, + { + "case_count": 2, + "claim_class_id": "determinism-stability", + "evidence_status": "partial", + "limitations": [ + "Partial parse-to-compile repeatability only; runtime and backend determinism are untested." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 2, + "claim_class_id": "counterfactual-necessity", + "evidence_status": "untested", + "limitations": [ + "Untested because no governed intervention or ablation entrypoint ran." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 0, + "unsupported_case_count": 2 + } + ], + "corpus_revision": "4.0.0", + "evidence_status": "partial", + "execution_id": "issue-971-execution-v57", + "generated_at": "2026-09-27", + "limitations": [ + "Satisfiability is limited to raes-finite-domain-satisfiability-v1 and its exact translation, theory, and Z3 configuration.", + "The subset-minimal unsatisfiable core is not a universal proof certificate.", + "Exploit-path results are limited to the admitted snapshot, normalized graph, query, transition semantics, and bounded search profile.", + "A valid path is not backend execution and an invalid path is not real-world non-exploitability.", + "The production exploit-path JSON loader permits duplicate keys; the research loader rejects them without claiming stronger production behavior.", + "Participant replay inherits the host environment and is not described as hermetic.", + "Counterfactual necessity remains untested.", + "Scoped observation demand is not a claim class in this preregistration and is not promoted to demonstrated by this retest.", + "EXP-732 provenance joins are verified by their dedicated regression suite; this retained corpus makes no universal run, apparatus, source, or augmentation assurance claim.", + "This retained corpus does not establish native backend attestation fidelity; materialization contract checks remain separate operational provenance, not experimental observations.", + "Capture admission and evidence-proof authority are verified by issue-1237 regression tests, not promoted to a new claim class by this retained corpus.", + "Evidence-requirement refinement lineage is outside this retained formal claim set; this retest refreshes integrated source provenance without promoting that feature to a formal claim.", + "Authoring-adapter transport behavior is outside this retained formal claim set.", + "Operational recovery observation and startup reconciliation are verified by their API-404 regression suite, not promoted to a new formal claim class by this retained corpus.", + "Single-owner store admission, immutable target/run scope, and provider shutdown ordering are verified by their API-404 CP-5 regression suite, not promoted to a formal claim by this retained corpus.", + "Mixed and staged trial admission is verified by its SEM-234/SCE-002/API-407 regression suite, not promoted to a new formal claim class by this retained corpus.", + "Offline control-plane maintenance, readiness, and bounded audit behavior are verified by issue #1186 runtime tests, not promoted to a formal claim by this retained corpus.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 profile declarations and capability admission are covered by dedicated runtime tests; the retained formal corpus does not execute control-plane profile composition.", + "Issue #1016 mixed-runtime coordination is covered by dedicated runtime tests; the retained formal corpus does not establish backend-native mixed realization, multi-controller coordination, IFC, or equivalence.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", + "Issue #1389 temporal-subject admission is verified by dedicated compiler tests and adds no new formal-semantic claim to this retained corpus.", + "Issue #971 model construction is verified by its own tests; this retained corpus establishes no participant-crossing equivalence or runtime-realization claim." + ], + "plain_language_outcome": "The retained formal cases replay unchanged outcomes after adding type annotations to the crossing profile.", + "protocol_revision": "2.0.0" +} diff --git a/docs/research/formal-semantic-validation/bundles/retest-v57.json b/docs/research/formal-semantic-validation/bundles/retest-v57.json new file mode 100644 index 000000000..c1b9ca5d3 --- /dev/null +++ b/docs/research/formal-semantic-validation/bundles/retest-v57.json @@ -0,0 +1,122 @@ +{ + "analysis_path": "docs/research/formal-semantic-validation/analysis-v57.json", + "analysis_sha256": "6eb5bb63b610146cf9519c077df7cc8ebaea566ffe6cefa4173129fdb77de9eb", + "artifacts": [ + { + "artifact_id": "finite-domain-satisfiable-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "sha256": "0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" + }, + { + "artifact_id": "finite-domain-satisfiable-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add" + }, + { + "artifact_id": "finite-domain-unsatisfiable-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "sha256": "cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" + }, + { + "artifact_id": "finite-domain-unsatisfiable-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d" + }, + { + "artifact_id": "typed-exploit-path-valid-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "sha256": "0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" + }, + { + "artifact_id": "typed-exploit-path-valid-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c" + }, + { + "artifact_id": "typed-exploit-path-invalid-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "sha256": "0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" + }, + { + "artifact_id": "typed-exploit-path-invalid-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533" + }, + { + "artifact_id": "schema-valid-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml", + "sha256": "41a9adffdf9f5f2ccc2f887dcf7b15fba3b47c83a1af15f33db872c4a2449d67" + }, + { + "artifact_id": "schema-unknown-field-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml", + "sha256": "51cf62319a86c95a2517995939d1f370573051835e4b55bb6d5beaf049640481" + }, + { + "artifact_id": "semantic-resolved-objective-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml", + "sha256": "75834bdc883e2003e1c473870bdf75700978955bb83095c6bd718ba6bd3908a6" + }, + { + "artifact_id": "semantic-dangling-assertion-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml", + "sha256": "1d25bee5f556054e5f0a518df025e4c62e080e1964035e3c1a12e074d88d3a5d" + }, + { + "artifact_id": "semantic-ambiguous-reference-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml", + "sha256": "653cbd2fd62e220d49fb86f80133884207df5ae6752846345ae3085b93f6e4ed" + }, + { + "artifact_id": "semantic-feature-cycle-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml", + "sha256": "e1f66d95a9ad039687aec8cccbc8843b514072ff08e006c1b4ca6aa5cd8d4ed1" + }, + { + "artifact_id": "workflow-reachable-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml", + "sha256": "54c40ceb98ad47247447d737973b2c55e8fb2045e209c7545c4fb20cf42dc3dc" + }, + { + "artifact_id": "workflow-unreachable-step-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml", + "sha256": "ef22ef2e260f1a7fd92d286f9b571716436b192ddfd54aea7bdfcfdda4ca52a2" + }, + { + "artifact_id": "compile-repeatability-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", + "sha256": "0bc40900d598c1af7a405d798ca19710405e53ced262d8733081abf12edf89fe" + }, + { + "artifact_id": "compile-non-vacuity-control-comparison-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml", + "sha256": "d85338f89f20a45515b12da8640173c1a52e47eb17ca0f4f6b4f8f3306e863a1" + } + ], + "bundle_id": "raes-formal-semantic-validation", + "corpus_path": "docs/research/formal-semantic-validation/corpus/manifest-v4.json", + "corpus_sha256": "c57207af72406aa4f70882b9bbeb7cedcc79cf3854c878a95e3eb1fa59ea7a72", + "protocol_path": "docs/research/formal-semantic-validation/protocol-v2.json", + "protocol_sha256": "abf94093e344bf495dfb04e8b0c5985c0beaab8ebb17a75e15c8674fa81b1a7c", + "revision": "57.0.0", + "snapshot_path": "docs/research/formal-semantic-validation/execution-snapshot-v57.json", + "snapshot_sha256": "297d94a9a40639f0e217dd416bcdd7e2b47e105fa753cc5ddb636375e9ce9c89" +} diff --git a/docs/research/formal-semantic-validation/execution-snapshot-v57.json b/docs/research/formal-semantic-validation/execution-snapshot-v57.json new file mode 100644 index 000000000..a2516ffbe --- /dev/null +++ b/docs/research/formal-semantic-validation/execution-snapshot-v57.json @@ -0,0 +1,652 @@ +{ + "baseline": { + "execution_id": "issue-971-execution-v56", + "release_path": "docs/research/formal-semantic-validation/bundles/retest-v56.json", + "release_revision": "56.0.0", + "release_sha256": "a34056af25ca084bcba2bb9ee4d488cb50cace324736c94de30ae40fd05c3b46" + }, + "captured_at": "2026-09-27T21:02:10.732663+00:00", + "commands": [ + { + "argv": [ + "implementations/python/.venv/bin/python", + "tools/check_formal_semantic_validation.py" + ], + "command_id": "bundle-replay", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/pytest", + "-q", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record", + "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", + "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" + ], + "command_id": "participant-fixtures", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "satisfiability", + "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "--profile", + "raes-finite-domain-satisfiability-v1" + ], + "command_id": "finite-domain-satisfiable-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "satisfiability", + "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "--profile", + "raes-finite-domain-satisfiability-v1" + ], + "command_id": "finite-domain-unsatisfiable-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "exploit-path", + "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "--profile", + "raes-exploit-path-analysis-v1" + ], + "command_id": "typed-exploit-path-valid-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "exploit-path", + "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "--profile", + "raes-exploit-path-analysis-v1" + ], + "command_id": "typed-exploit-path-invalid-v2", + "network": "disabled" + } + ], + "configuration_id": "raes-python-reference-offline-v41", + "corpus_revision": "4.0.0", + "deviations": [], + "execution_id": "issue-971-execution-v57", + "execution_status": "complete", + "observations": [ + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "schema-valid-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "A passing minimal source does not establish semantic correctness." + ], + "replayable": true, + "result_digest": "f7d364ef384df8a1526b489501835b635021c860793b5764f91d956710d2250c", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "schema-unknown-field", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLParseError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The observation covers one unknown-field defect only." + ], + "replayable": true, + "result_digest": "f55d834b458f8e069e1c69061b4cc0a6d61e0e052bf90c670f2e6a5ad8b5bd98", + "source_digest": null + }, + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "semantic-resolved-objective", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "This is a positive control for one objective-reference slice." + ], + "replayable": true, + "result_digest": "652288785dc09095955ed3649f6407d616fb7c4d4f4188df4ed513ccb7537e0b", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-dangling-assertion", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "A single dangling reference does not prove complete semantic coverage." + ], + "replayable": true, + "result_digest": "0207cf616b56708ca9b8c4499d3301abe22dbe52162cf8d58d3bec429d9db024", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-ambiguous-reference", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "One namespace collision does not enumerate every ambiguity surface." + ], + "replayable": true, + "result_digest": "9da4a87797d228e0012ab6b30459f4892e41aa6f224a9840be035fee4a2eea73", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-feature-cycle", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "One static dependency cycle does not establish general constraint satisfiability." + ], + "replayable": true, + "result_digest": "d15dbcd99fb4f20b965d7031b07dd6534576302270399c3fa656d29e7de02b83", + "source_digest": null + }, + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "workflow-reachable-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The graph is workflow control flow only." + ], + "replayable": true, + "result_digest": "b1b49649b54bd59d4ef357b39cf9158da90f4eae560f8dd756acf97bd0827a06", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "workflow-unreachable-step", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The result does not establish network, service, participant, or exploit reachability." + ], + "replayable": true, + "result_digest": "bb931d19346ef9193408ae6c85deb4079704378fc5f00dc5f47a2817cff21943", + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "whole-scenario-satisfiable-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "No governed whole-scenario constraint theory or solver exists." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "whole-scenario-unsatisfiable-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Local checks cannot produce a whole-scenario unsat certificate." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "valid-exploit-path-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The issue-168 baseline had no canonical typed attack graph or path-query entrypoint." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "invalid-exploit-path-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Vulnerability and topology declarations are not an invalid-path proof." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "stable", + "analysis_profile": null, + "case_id": "compile-repeatability-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The witness ends at compiled output." + ], + "replayable": true, + "result_digest": "11264a648a949917c0e84a2a1e5d116139a35e6cb941844735a422df95141d6c", + "source_digest": null + }, + { + "actual_outcome": "distinguishable", + "analysis_profile": null, + "case_id": "compile-non-vacuity-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", + "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Distinct digests are a non-vacuity control, not semantic non-equivalence proof." + ], + "replayable": true, + "result_digest": "72c1ee8c7bbc1f970216fa232b3d4ae917bcb003bd823439bbac8a5db94214e2", + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "necessity-witness-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "No governed intervention or ablation protocol exists." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "non-necessity-control-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Attribution and negative fixtures do not demonstrate non-necessity." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "satisfiable", + "analysis_profile": "raes-finite-domain-satisfiability-v1", + "case_id": "finite-domain-satisfiable-v2", + "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "scenario-satisfiability-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "evidence_artifact_sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add", + "evidence_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", + "evidence_profile": "scenario-satisfiability-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "specs/formal/scenario-satisfiability/README.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Demonstrates only the pinned finite-domain theory, translation, solver profile, and source." + ], + "replayable": true, + "result_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", + "source_digest": "sha256:0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" + }, + { + "actual_outcome": "unsatisfiable", + "analysis_profile": "raes-finite-domain-satisfiability-v1", + "case_id": "finite-domain-unsatisfiable-v2", + "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "scenario-satisfiability-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "evidence_artifact_sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d", + "evidence_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", + "evidence_profile": "scenario-satisfiability-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "specs/formal/scenario-satisfiability/README.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The subset-minimal core is evidence for the pinned translation and solver, not a proof certificate for arbitrary SDL." + ], + "replayable": true, + "result_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", + "source_digest": "sha256:cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" + }, + { + "actual_outcome": "valid-path", + "analysis_profile": "raes-exploit-path-analysis-v1", + "case_id": "typed-exploit-path-valid-v2", + "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "exploit-path-analysis-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "evidence_artifact_sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c", + "evidence_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", + "evidence_profile": "exploit-path-analysis-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "specs/formal/exploit-path-analysis/README.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The witness is bounded to the admitted snapshot, normalized graph, query, semantics, and search profile; it does not establish backend execution." + ], + "replayable": true, + "result_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", + "source_digest": "sha256:0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" + }, + { + "actual_outcome": "invalid-path", + "analysis_profile": "raes-exploit-path-analysis-v1", + "case_id": "typed-exploit-path-invalid-v2", + "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "exploit-path-analysis-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "evidence_artifact_sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533", + "evidence_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", + "evidence_profile": "exploit-path-analysis-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "specs/formal/exploit-path-analysis/README.md" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Structured rejection proves only that this bounded graph/query cannot reach its goal; it does not establish real-world non-exploitability." + ], + "replayable": true, + "result_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", + "source_digest": "sha256:0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" + } + ], + "participant_observations": [ + { + "evidence_refs": [ + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Covers the reference SDL/contract path, not every backend projection." + ], + "negative_outcome": "passed", + "obligation_id": "hidden-vs-visible-projection", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Covers declared applicability and one unresolved-precondition failure." + ], + "negative_outcome": "passed", + "obligation_id": "fail-closed-action-applicability", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Contract evidence does not prove every backend's live concurrency fidelity." + ], + "negative_outcome": "passed", + "obligation_id": "shared-state-effects", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Rejecting timestamp-only causality does not supply counterfactual proof." + ], + "negative_outcome": "passed", + "obligation_id": "ordering-before-causality", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Attribution labels disclose basis; they do not demonstrate necessity." + ], + "negative_outcome": "passed", + "obligation_id": "evidence-labeled-attribution", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "The fixtures establish layer separation, not outcome validity in every realization." + ], + "negative_outcome": "passed", + "obligation_id": "participant-local-outcome-separation", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", + "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" + ], + "execution_id": "issue-971-execution-v57", + "limitations": [ + "Reference conformance evidence remains bounded to declared realization profiles." + ], + "negative_outcome": "passed", + "obligation_id": "realization-profile-honesty", + "positive_outcome": "passed" + } + ], + "protocol_revision": "2.0.0", + "raes_revision": "406033379df730d522c333b5db8e1f39f185f044", + "source_state": { + "base_revision": "406033379df730d522c333b5db8e1f39f185f044", + "checkout_state": "modified", + "implementation_digest": "0bca9c465e832c6ce5cf7c835df43995c6555456610052219a98a0e3ddc31d8f", + "profile": "python-reference-source/v2" + }, + "versions": { + "python": "3.14.4", + "raes": "5.0.0", + "z3_engine": "4.16.0", + "z3_solver": "4.16.0.0" + } +} diff --git a/docs/research/formal-semantic-validation/index.md b/docs/research/formal-semantic-validation/index.md index 26a32b866..77304b19f 100644 --- a/docs/research/formal-semantic-validation/index.md +++ b/docs/research/formal-semantic-validation/index.md @@ -511,3 +511,7 @@ Release 56.0.0 replays the retained cases against issue #971’s crossing profil and opacity admission guards in [execution-snapshot-v56.json](execution-snapshot-v56.json) and [analysis-v56.json](analysis-v56.json). Outcomes and claim limits are unchanged; the crossing models remain construction evidence only. + +Release 57.0.0 replays the same cases after the #971 profile type annotations +in [execution-snapshot-v57.json](execution-snapshot-v57.json) and +[analysis-v57.json](analysis-v57.json), preserving all outcomes and claim limits. diff --git a/docs/research/specification-coverage/analysis-v56.json b/docs/research/specification-coverage/analysis-v56.json new file mode 100644 index 000000000..5cf6f2c79 --- /dev/null +++ b/docs/research/specification-coverage/analysis-v56.json @@ -0,0 +1,105 @@ +{ + "analysis_id": "raes-standardized-specification-coverage-issue-971-v56", + "backend_leakage": [], + "claim": { + "allowed_evidence": [ + "pinned source metadata and bounded paraphrases", + "production parser, semantic, instantiation, admission, compiler, contract, and profile results", + "exact artifact digests and typed pointers", + "documented missing-concept and backend-specific dispositions" + ], + "claim_id": "raes-standardized-configurable-specification-coverage", + "disallowed_evidence": [ + "field-count or schema breadth alone", + "the existing scenario stress corpus as the representative request corpus", + "free-form metadata as typed coverage", + "backend-private interpretation", + "post-hoc removal or repair of falsifying concepts" + ], + "evidence_artifacts": [ + "docs/research/specification-coverage/protocol-v1.json", + "docs/research/specification-coverage/execution-snapshot-v56.json", + "docs/research/specification-coverage/analysis-v56.json" + ], + "falsification_protocol": "docs/research/specification-coverage/protocol-v1.json", + "objective_fail_criteria": "A load-bearing concept is missing or lossy, an applicable stage fails, or backend vocabulary is required in core SDL while the result claims success.", + "objective_pass_criteria": "Every load-bearing concept passes at every owning stage, backend-specific mechanics stay outside core SDL, and no requested concept is silently lost.", + "statement": "RAES provides a standardized configurable portable specification surface for the preregistered representative cyber-agent evaluation environment requirements without backend vocabulary in core SDL.", + "threats_to_validity": [ + "The representative corpus contains four source strata and sixteen atomic concepts rather than every cyber-range requirement.", + "The reference processor and repository fixtures are not independent backend implementations.", + "No live range, simulator federation, or participant execution was part of this offline specification-coverage test." + ] + }, + "classification_counts": { + "deliberately-backend-specific": 1, + "directly-expressible": 10, + "missing": 3, + "profile-or-manifest-constraint": 2 + }, + "evidence_status": "partial", + "execution_status": "complete", + "generated_at": "2026-09-27", + "limitations": [ + "This result demonstrates bounded specification coverage, not universal cyber-range coverage, usability, adoption, backend substitution, or behavioral equivalence.", + "The three missing concepts are evidence, not implementation tasks within this snapshot.", + "The retained protocol does not test recursive realization or plan-level profile semantics; this release only re-establishes its original bounded coverage result against the current implementation.", + "The retained protocol does not test evidence-requirement refinement lineage; the dedicated EXP-731 regression suite covers that production boundary.", + "Authoring-adapter transport behavior is outside this retained protocol.", + "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", + "Operational recovery observation and startup reconciliation are covered by their API-404 regression suite, not a new claim in this preregistered matrix.", + "Store ownership, immutable runtime scope, and provider shutdown ordering are covered by the API-404 CP-5 regression suite, not by this retained specification-coverage protocol.", + "Mixed/staged trial compilation and admission are covered by issue #1015 regression tests, not by this retained specification-coverage corpus; no live mixed-runtime result is claimed.", + "Issue #1186 control-plane recovery operations are covered by their runtime regression suite, not by this retained specification-coverage corpus.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", + "Participant-local outcome state is verified by the ACT-618 tests; this retained corpus makes no additional outcome-state claim.", + "Backend operation supervision contracts are covered by issue #1360 contract tests; this retained offline corpus establishes no live backend supervision or recovery guarantee.", + "This capture replays the merged issue #1360 and #1357 source; the protocol makes no live backend execution or supervision claim.", + "This capture replays the merged issue #1360 and #1358 source; the protocol makes no live backend execution or supervision claim.", + "Issue #1389 participant inject delivery temporal-subject admission is covered by dedicated compiler tests; this retained matrix makes no new timing or execution claim.", + "Issue #971 adds offline crossing model construction; this retained protocol establishes no crossing equivalence or runtime-realization claim." + ], + "load_bearing_results": { + "failed": 0, + "missing": 0, + "passed": 10, + "total": 10 + }, + "plain_language_outcome": "The retained matrix replays unchanged classifications after adding type annotations to the crossing profile.", + "protocol_revision": "1.0.0", + "request_results": [ + { + "concept_count": 6, + "failed_stage_count": 0, + "missing_count": 0, + "request_id": "survey-representative-range", + "status": "demonstrated" + }, + { + "concept_count": 5, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "cyborg-participant-evaluation", + "status": "partial" + }, + { + "concept_count": 3, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "vsdl-configurable-infrastructure", + "status": "partial" + }, + { + "concept_count": 2, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "cyber-dem-federation", + "status": "partial" + } + ], + "snapshot_id": "raes-standardized-specification-coverage-issue-971-v56", + "snapshot_sha256": "1374220797ea167547909575816297e08178bf1e64829761b5836acb92bfc22a" +} diff --git a/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v56.json b/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v56.json new file mode 100644 index 000000000..f78b7adf2 --- /dev/null +++ b/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v56.json @@ -0,0 +1,10 @@ +{ + "analysis_path": "docs/research/specification-coverage/analysis-v56.json", + "analysis_sha256": "55157d601a226aa2f38dc7c7eaec600be05c8faaebb06de4bc4fdd9c24ef56f5", + "bundle_id": "raes-standardized-specification-coverage", + "protocol_path": "docs/research/specification-coverage/protocol-v1.json", + "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", + "revision": "56.0.0", + "snapshot_path": "docs/research/specification-coverage/execution-snapshot-v56.json", + "snapshot_sha256": "a1df69ccfc5b4073c910a26db23d50b31c15371e8a9642245b410813beb1b8f4" +} diff --git a/docs/research/specification-coverage/execution-snapshot-v56.json b/docs/research/specification-coverage/execution-snapshot-v56.json new file mode 100644 index 000000000..fd9fa51e5 --- /dev/null +++ b/docs/research/specification-coverage/execution-snapshot-v56.json @@ -0,0 +1,700 @@ +{ + "artifacts": [ + { + "artifact_id": "enterprise-participant-sdl", + "kind": "sdl", + "path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032", + "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" + }, + { + "artifact_id": "port-range-sdl", + "kind": "sdl", + "path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f", + "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" + }, + { + "artifact_id": "experiment-task-contract", + "kind": "experiment-task", + "path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc", + "validator": "raes_contracts.contracts.ExperimentTaskModel" + }, + { + "artifact_id": "apparatus-context-contract", + "kind": "experiment-apparatus-context", + "path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299", + "validator": "raes_contracts.contracts.ExperimentApparatusContextModel" + }, + { + "artifact_id": "backend-profile", + "kind": "backend-profile", + "path": "contracts/profiles/backend/orchestration-capable.json", + "sha256": "f70b8505a5c0055416db86c533e2e5bf08b11e5a514f076223b6d6c36215a092", + "validator": "raes_contracts.backend_profiles.BackendProfileModel" + }, + { + "artifact_id": "known-limitations", + "kind": "documentation", + "path": "docs/explain/sdl/limitations.md", + "sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4", + "validator": "documentation evidence only" + } + ], + "baseline": { + "release_revision": "1.1.0", + "release_sha256": "4020a1d56c7fe2831cec59ea64a12bbda9d38ccd94f93b916dd90f1a28f17fcb" + }, + "captured_at": "2026-09-27", + "concept_results": [ + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "range-topology", + "rationale": "SDL nodes and infrastructure own host, network, link, and dependency meaning; the compiler emits canonical node deployment addresses.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed VM declaration.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Links and dependencies resolved.", + "outcome": "passed", + "pointer": "/infrastructure/shipping-portal", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Published instantiated shape admitted.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical deployment address retained.", + "outcome": "passed", + "pointer": "/node_deployments/provision.node.shipping-portal", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/nodes/shipping-portal" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "exercise-roles", + "rationale": "SDL entity roles own exercise responsibility without becoming control-plane identity or authorization.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed red role.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant/role", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Entity references validated.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Role retained after instantiation.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant/role", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Role retained in entity specification.", + "outcome": "passed", + "pointer": "/entity_specs/enterprise-participant/role", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/entities/enterprise-participant/role" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "evaluation-objectives", + "rationale": "SDL objectives own organization ownership, participant assignment, targets, windows, and assertion-based success; measures remain experiment contracts.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed objective declaration.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Owner, participant assignment, targets, assertions, and workflow refs resolved.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff/success", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Objective retained in admitted artifact.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical objective address retained.", + "outcome": "passed", + "pointer": "/objectives/evaluation.objective.demonstrate-handoff", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/objectives/demonstrate-handoff" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "control-workflows", + "rationale": "SDL workflows own the portable control graph and compile to canonical orchestration state contracts.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed control graph.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Step graph and objective refs validated.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery/steps", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Workflow retained after instantiation.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical control graph retained.", + "outcome": "passed", + "pointer": "/workflows/orchestration.workflow.yard-recovery", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/workflows/yard-recovery" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "authored-evidence-expectations", + "rationale": "SDL evidence requirements own portable capture intent and remain distinct from evidence records and measures.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed capture obligation.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Source refs and bindings validated.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Evidence intent retained in admitted artifact.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + } + ], + "typed_pointer": "/evidence_requirements/objective-truth-evidence" + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [], + "classification": "profile-or-manifest-constraint", + "completeness_disposition": "implemented", + "concept_id": "apparatus-selection-constraints", + "rationale": "The experiment task contract binds processor/backend identities, manifest refs, and capabilities outside SDL.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed ExperimentTaskModel validated.", + "outcome": "passed", + "pointer": "/apparatus_constraints/allowed_backend_refs/0", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/apparatus_constraints/allowed_backend_refs/0" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-agent", + "rationale": "SDL agents own participant entity, knowledge, actions, observation boundaries, and operating scope.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed participant declaration.", + "outcome": "passed", + "pointer": "/agents/participant-agent", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Participant refs and scope validated.", + "outcome": "passed", + "pointer": "/agents/participant-agent/observation_boundaries", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Participant retained in admitted artifact.", + "outcome": "passed", + "pointer": "/agents/participant-agent", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Compiled participant scope retained.", + "outcome": "passed", + "pointer": "/agent_specs/participant-agent", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/agents/participant-agent" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-action-contract", + "rationale": "The action contract declares portable preconditions, effects, observations, evidence, and failure classes without a runner command.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed action contract.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Action refs and evidence bindings validated.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login/effects", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Action retained in admitted artifact.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical action address retained.", + "outcome": "passed", + "pointer": "/action_contracts/participant.action-contract.probe-customer-portal-login", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/action_contracts/probe-customer-portal-login" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-observation-boundary", + "rationale": "The observation boundary separately declares visible, hidden, and evidence-only information with transition rules.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed observation boundary.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Information refs and transitions validated.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view/view_rules", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Boundary retained in admitted artifact.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical boundary address retained.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant.observation-boundary.participant-view", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/observation_boundaries/participant-view" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "evaluation-measure", + "rationale": "ExperimentTaskModel owns metric construct, unit, direction, aggregation, and evidence requirements outside SDL objectives.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed task contract validated.", + "outcome": "passed", + "pointer": "/evaluation_protocol/metric_definitions/foothold-achieved", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/evaluation_protocol/metric_definitions/foothold-achieved" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "participant-tool-affordance", + "rationale": "This preregistered matrix has no tested carrier for participant tool affordances. The retained missing classification records missing coverage evidence, not the absence of current participant-behavior capabilities.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "The preregistered carrier slot was not run; metadata does not substitute for a typed coverage test.", + "outcome": "not_run", + "pointer": null, + "stage_id": "authored", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "resource-constrained-topology", + "rationale": "SDL node resources and infrastructure dependencies express portable resource intent without provider resource identifiers.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed CPU and memory declaration.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal/resources", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Resource-bearing topology validated.", + "outcome": "passed", + "pointer": "/infrastructure/shipping-portal", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Constraints retained in admitted artifact.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal/resources", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Deployment specification retains resource intent.", + "outcome": "passed", + "pointer": "/node_deployments/provision.node.shipping-portal", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/nodes/shipping-portal/resources" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "formal-constraint-satisfiability", + "rationale": "This coverage matrix did not exercise a solver-backed carrier. The separate formal-semantic-validation release demonstrates its bounded finite-domain profile; that result is not silently imported into this protocol's missing carrier slot.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "No coverage-carrier execution was performed here; independent solver evidence does not change this preregistered denominator.", + "outcome": "not_run", + "pointer": null, + "stage_id": "semantic", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [ + { + "allowed": true, + "artifact_path": "source:vsdl-paper", + "pointer": "source sections 4-5", + "reason": "Legitimate VSDL realization vocabulary, not RAES core SDL structure.", + "term": "OpenStack/Terraform/Packer" + } + ], + "classification": "deliberately-backend-specific", + "completeness_disposition": "external", + "concept_id": "provider-specific-provisioning", + "rationale": "Provider image selection and provisioning engines are realization mechanics and therefore remain outside core SDL.", + "stage_results": [ + { + "artifact_path": "contracts/profiles/backend/orchestration-capable.json", + "diagnostic_codes": [], + "note": "The portable boundary requires backend contracts; it does not standardize a provider engine.", + "outcome": "not_applicable", + "pointer": "/required_contracts", + "stage_id": "realization-disclosure", + "validation_strength": "profile" + } + ], + "typed_pointer": null + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [], + "classification": "profile-or-manifest-constraint", + "completeness_disposition": "implemented", + "concept_id": "apparatus-clock-context", + "rationale": "ExperimentApparatusContextModel records clock authority, time domain, and synchronization as apparatus facts outside scenario meaning.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed apparatus context contract validated.", + "outcome": "passed", + "pointer": "/clocks/0", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/clocks/0" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "federated-object-event-exchange", + "rationale": "The federated cyber object/event exchange carrier was not exercised by this preregistered matrix. Runtime event internals are not treated as equivalent evidence.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "The missing coverage-carrier test is recorded explicitly, without inferring an ecosystem-wide capability absence.", + "outcome": "not_run", + "pointer": null, + "stage_id": "contract", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + } + ], + "deviations": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "baseline_sha256": "54ba1a60220e27a55da9cd2a407d7d3ab836fa54460d0b0c6cad87c2e744ddbb", + "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", + "retest_sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "baseline_sha256": "a27c7a64e0c5c618fadaccafdf1a4e71600170a8b77b983190822b5141f00dec", + "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", + "retest_sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f" + }, + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "baseline_sha256": "21952a752f4e8581a9fc3b872e4bc308150548170d38bcfc83dbbe35ff5e0b9f", + "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", + "retest_sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc" + }, + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "baseline_sha256": "9536d897a09cbc6920e667e4f8f9371e51307aa0b3b5ff3c7de682dd783420ab", + "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", + "retest_sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299" + }, + { + "artifact_path": "docs/explain/sdl/limitations.md", + "baseline_sha256": "129cf17810aad4c51988bc872e28fe43ae95019a80053c42d800ff7e2b9cc93e", + "rationale": "Correct historical mandatory-profile guidance after issue #1207; retain the preregistered missing-concept classifications and coverage limits.", + "retest_sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4" + } + ], + "execution_status": "complete", + "implementation_surfaces": [ + { + "content_sha256": "eecc20e815a93387560fabc5a1fe20b3ffa471d9fc73c44ecc4f62df871d687c", + "path": "implementations/python/packages/raes_contracts", + "surface_id": "contract-models" + }, + { + "content_sha256": "27cf5d5bac07ef4b79d922e7c924832c89f13f12ab7e3a441b1a97557dba2b14", + "path": "implementations/python/packages/raes_processor", + "surface_id": "processor-pipeline" + }, + { + "content_sha256": "9ecd780448b054693503bab246120a1a2bb49a43016d0b9c27c5284ba609833f", + "path": "implementations/python/packages/raes", + "surface_id": "sdl-pipeline" + } + ], + "limitations": [ + "The execution validates the pinned reference implementation and published contracts, not an independent backend.", + "Repository-owned examples are exact execution artifacts but are not themselves the literature-derived request corpus; the protocol's requests and concepts are.", + "No live range, participant, simulator federation, or provider provisioning engine was executed.", + "Missing concepts remain frozen in this snapshot and require separately scoped product work before a later rerun.", + "This capture replays the retained protocol after EXP-732 run, apparatus, measurement-channel, and augmentation-producer provenance validation; it adds no independent backend or universal provenance assurance claim.", + "Materialization attestation is covered by its dedicated regression suite, not a new claim in this preregistered matrix.", + "This capture refreshes the corrected runtime limitations prose for issue #959; the protocol, coverage classifications and implementation source are unchanged.", + "This capture replays open-by-default augmentation scope integrated with the EXP-731 evidence refinements after composition type refinement; it does not evaluate native backend scope enforcement or broaden the preregistered coverage claims.", + "This capture replays the retained protocol after merging ACT-612 participant relationships with open-by-default augmentation scope; it adds no claim of realized participant relationships or native backend scope enforcement.", + "This capture replays issue #1299 partial listener descriptions on the integrated source state; endpoint completeness and backend admission remain outside this protocol's claims.", + "This capture also binds authoring-adapter semantic conformance to the integrated source; adapter transport behavior remains outside this protocol's claims.", + "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", + "This capture binds issue #1297 service-manager identity, native-name, and explicitly selected systemd-state contract changes to the integrated source. It exercises no live service manager and adds no backend-execution claim.", + "This capture replays the retained specification-coverage protocol after API-404 startup reconciliation added an operational recovery-observation contract. It does not evaluate crash recovery, classify provider effects, or broaden EXP-715 experiment-observation claims.", + "This capture binds API-404 single-owner store admission and immutable target/run scope to the integrated source. The retained offline protocol does not exercise process leases, SQLite lifecycle ordering, or crash recovery.", + "This capture binds issue #1015 deterministic mixed and staged trial admission to the integrated source. The retained offline language corpus does not execute mixed runtimes, phase transitions, backend handoff, or scheduler-driven realization.", + "This replay binds issue #1186 offline control-plane maintenance, readiness, and bounded audit code to the integrated source. The retained language corpus does not execute store recovery, HTTP health behavior, or audit redaction.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", + "Issue #1016 mixed-runtime coordination is covered by its dedicated runtime suite. The retained language corpus does not execute mixed providers or establish backend-native realization, multi-controller coordination, IFC, or equivalence.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution." + ], + "protocol_revision": "1.0.0", + "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", + "raes_revision": "406033379df730d522c333b5db8e1f39f185f044", + "snapshot_id": "raes-standardized-specification-coverage-issue-971-v56", + "snapshot_revision": "56.0.0", + "source_state": { + "base_revision": "406033379df730d522c333b5db8e1f39f185f044", + "checkout_state": "modified", + "implementation_digest": "0bca9c465e832c6ce5cf7c835df43995c6555456610052219a98a0e3ddc31d8f", + "profile": "python-reference-source/v2" + } +} diff --git a/docs/research/specification-coverage/index.md b/docs/research/specification-coverage/index.md index 5524ed6f4..847ec3852 100644 --- a/docs/research/specification-coverage/index.md +++ b/docs/research/specification-coverage/index.md @@ -292,7 +292,7 @@ the port scenario. Historical captures and archived example bytes are retained. The matrix classifications and untested concepts are unchanged; no execution authority, successful action, or live backend fidelity is inferred. -Current validation requires release 55.0.0 and rejects duplicate or unsupported +Current validation requires release 56.0.0 and rejects duplicate or unsupported future revisions. It executes current artifacts, requires exact source and package hashes, and checks all passing stage pointers. `source_state` discloses the base Git commit, modified checkout state, and exact implementation digest; @@ -448,3 +448,7 @@ Release 55.0.0 replays the retained matrix against issue #971’s crossing profi and opacity admission guards in [execution-snapshot-v55.json](execution-snapshot-v55.json) and [analysis-v55.json](analysis-v55.json). Classifications and claim limits are unchanged; this is no participant-crossing equivalence result. + +Release 56.0.0 replays the same matrix after the #971 profile type annotations +in [execution-snapshot-v56.json](execution-snapshot-v56.json) and +[analysis-v56.json](analysis-v56.json), preserving all classifications. diff --git a/implementations/python/packages/raes_contracts/_participant_crossing_profile.py b/implementations/python/packages/raes_contracts/_participant_crossing_profile.py index 9ea9b89ae..221baeef9 100644 --- a/implementations/python/packages/raes_contracts/_participant_crossing_profile.py +++ b/implementations/python/packages/raes_contracts/_participant_crossing_profile.py @@ -1,11 +1,14 @@ """Closed single-operation SEM-232 profile vocabulary and parameters.""" -from typing import Literal +from typing import TYPE_CHECKING, Any, Literal, Self from pydantic import Field, StrictInt, model_validator from .contracts.base import ContractModel, PrefixedDigestString +if TYPE_CHECKING: + from .behavioral_relation_profiles import BehavioralRelationProfileModel + INPUT_CLASSES = ("plain", "transform", "declassify", "unsupported", "forbidden") VISIBLE = ( "crossing.request", @@ -104,13 +107,13 @@ class ParticipantCrossingParametersModel(ContractModel): completion: Literal["per-crossing-visible-outcome"] @model_validator(mode="after") - def _independent_sources(self): + def _independent_sources(self) -> Self: if self.left.source_digest == self.right.source_digest: raise ValueError("crossing transition authorities must have independent source identities") return self -def validate_crossing_profile_join(profile) -> None: +def validate_crossing_profile_join(profile: "BehavioralRelationProfileModel") -> None: expected = { "profile_id": "participant-crossing-dpbb-finite-v1", "profile_revision": "rev2", @@ -125,7 +128,7 @@ def validate_crossing_profile_join(profile) -> None: raise ValueError("crossing profile identity, projection or carrier does not match its parameters") -def crossing_profile_schema_join() -> dict: +def crossing_profile_schema_join() -> dict[str, Any]: """Publish the relation/variant join in the existing profile schema.""" return { "if": { diff --git a/implementations/python/tests/test_formal_semantic_validation.py b/implementations/python/tests/test_formal_semantic_validation.py index 9866d6dad..2be76cffa 100644 --- a/implementations/python/tests/test_formal_semantic_validation.py +++ b/implementations/python/tests/test_formal_semantic_validation.py @@ -135,6 +135,7 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: "54.0.0", "55.0.0", "56.0.0", + "57.0.0", ] assert all(validate_release_bundle(REPO_ROOT, release) == [] for release in releases) @@ -143,10 +144,10 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: def test_current_retest_bundle_is_coherent_and_clean() -> None: release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, REPO_ROOT) - assert release.manifest["revision"] == "56.0.0" + assert release.manifest["revision"] == "57.0.0" assert protocol["revision"] == "2.0.0" assert corpus["revision"] == "4.0.0" - assert snapshot["baseline"]["release_revision"] == "55.0.0" + assert snapshot["baseline"]["release_revision"] == "56.0.0" assert snapshot["deviations"] == [] assert validate_retest_bundle(REPO_ROOT, release, protocol, corpus, snapshot, analysis) == [] diff --git a/implementations/python/tests/test_issue_971_crossing_export.py b/implementations/python/tests/test_issue_971_crossing_export.py index 05516e5f0..2b13928e4 100644 --- a/implementations/python/tests/test_issue_971_crossing_export.py +++ b/implementations/python/tests/test_issue_971_crossing_export.py @@ -34,7 +34,9 @@ def test_export_readback_and_counts(tmp_path): for name, module in (("abstract", abstract), ("concrete", concrete)): initial, states, edges = export.parse_aut(bundle[f"{name}.aut"]) graph = module.build() - assert initial == 0 and states == len(graph.states) and len(edges) == len(graph.edges) + assert initial == 0 + assert states == len(graph.states) + assert len(edges) == len(graph.edges) assert manifest["models"][name]["states"] == states assert manifest["models"][name]["transitions"] == len(edges) assert manifest["models"][name]["initial_states"] == 1 diff --git a/implementations/python/tests/test_issue_971_crossing_models.py b/implementations/python/tests/test_issue_971_crossing_models.py index 1c19c8e77..9062645d2 100644 --- a/implementations/python/tests/test_issue_971_crossing_models.py +++ b/implementations/python/tests/test_issue_971_crossing_models.py @@ -85,10 +85,13 @@ def test_atomic_refusal_and_hidden_progress(): assert concrete.internal_rank(before) > concrete.internal_rank(after) if before.head != after.head: assert label == "internal.atomic-commit" - assert before.head == "h0" and after.head == "h1" - assert before.last is None and after.last is not None + assert before.head == "h0" + assert after.head == "h1" + assert before.last is None + assert after.last is not None if before.phase == "preparing-record" and before.intent[3] == "fresh": - assert before.head == "h0" and before.last is None + assert before.head == "h0" + assert before.last is None @pytest.mark.parametrize("module", [abstract, concrete]) diff --git a/implementations/python/tests/test_issue_971_crossing_profile.py b/implementations/python/tests/test_issue_971_crossing_profile.py index 68e428259..da50934e2 100644 --- a/implementations/python/tests/test_issue_971_crossing_profile.py +++ b/implementations/python/tests/test_issue_971_crossing_profile.py @@ -139,10 +139,9 @@ def test_binary_binding_checks_both_carriers(): binding = crossing_binding(profile) catalog = load_behavioral_relation_catalog_revision("rev8") validate_behavioral_claim_binding(binding, catalog=catalog, profile=profile) + wrong_binding = binding.model_copy(update={"right_carrier_ref": "wrong"}) with pytest.raises(ValueError, match="right carrier"): - validate_behavioral_claim_binding( - binding.model_copy(update={"right_carrier_ref": "wrong"}), catalog=catalog, profile=profile - ) + validate_behavioral_claim_binding(wrong_binding, catalog=catalog, profile=profile) def test_opacity_consumers_reject_binary_profile_before_accessing_parameters(): @@ -163,10 +162,11 @@ def test_opacity_consumers_reject_binary_profile_before_accessing_parameters(): request.catalog_digest = canonical_json_digest(catalog.model_dump(mode="json")) with pytest.raises(ParticipantOpacityOperationalError, match="opacity parameter profile"): _model_check_admission.validate_admission(request, profile, catalog) + binding, support = _binding(), _support() with pytest.raises(ValueError, match="profile"): validate_participant_opacity_runtime_enforcement( - _binding(), - support=_support(), + binding, + support=support, participant_address="participant-0", audience_scope_ref="audience-0", profile=profile, @@ -194,9 +194,9 @@ def test_opacity_rejects_crossing_profile_with_matching_claim_and_coordinates(co assumptions=None, declared_counts=None, ) - with pytest.raises(ParticipantOpacityOperationalError, match="opacity parameter profile"): - if consumer == "analysis": + if consumer == "analysis": + with pytest.raises(ParticipantOpacityOperationalError, match="opacity parameter profile"): _service._validate_profile_admission(request, profile) - _service._validate_profile_domains(request, profile) - else: + else: + with pytest.raises(ParticipantOpacityOperationalError, match="opacity parameter profile"): _model_check_admission.validate_admission(request, profile, catalog) diff --git a/implementations/python/tests/test_issue_989_versioned_evidence.py b/implementations/python/tests/test_issue_989_versioned_evidence.py index 42f4f2753..2eebf3e75 100644 --- a/implementations/python/tests/test_issue_989_versioned_evidence.py +++ b/implementations/python/tests/test_issue_989_versioned_evidence.py @@ -230,7 +230,7 @@ def test_latest_current_release_is_versioned_and_strict(monkeypatch): from tools.formal_semantic_validation._releases import validate_retest_bundle release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, ROOT) - assert release.manifest["revision"] == "56.0.0" + assert release.manifest["revision"] == "57.0.0" original = _retest.replay_case def changed_result(root, case): @@ -283,7 +283,7 @@ def test_specification_current_capture_does_not_accept_old_artifact_digest(artif from tools.check_specification_coverage import load_bundle, validate_bundle manifest, protocol, snapshot, analysis = copy_bundle(load_bundle, ROOT) - assert manifest["revision"] == "55.0.0" + assert manifest["revision"] == "56.0.0" snapshot = deepcopy(snapshot) artifact = next(a for a in snapshot["artifacts"] if a["artifact_id"] == artifact_id) artifact["sha256"] = old_digest @@ -508,6 +508,7 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "54.0.0", "55.0.0", "56.0.0", + "57.0.0", ] if family == "formal" else [ @@ -567,6 +568,7 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "53.0.0", "54.0.0", "55.0.0", + "56.0.0", ] ) revisions.pop(-1 if removed == "current" else 0) diff --git a/implementations/python/tests/test_specification_coverage.py b/implementations/python/tests/test_specification_coverage.py index 85fb6425e..63823b7eb 100644 --- a/implementations/python/tests/test_specification_coverage.py +++ b/implementations/python/tests/test_specification_coverage.py @@ -53,7 +53,7 @@ def test_immutable_bundle_index_preserves_concurrent_captures() -> None: bundles = copy_bundle(load_bundles, REPO_ROOT) assert {manifest["revision"] for manifest, *_rest in bundles} >= {"1.0.0", "1.1.0", "19.0.0"} manifest, *_rest = copy_bundle(load_bundle, REPO_ROOT) - assert manifest["revision"] == "55.0.0" + assert manifest["revision"] == "56.0.0" def test_historical_failures_name_the_revision_specific_documents() -> None: diff --git a/specs/formal/participant-semantics/crossing-models/rev2/manifest.json b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json index e8d53c282..164f424f9 100644 --- a/specs/formal/participant-semantics/crossing-models/rev2/manifest.json +++ b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json @@ -1 +1 @@ -{"artifact_digests":{"abstract.aut":"sha256:5891bbc5b3da53c7345f383da7f935ee9f8f0e4dd56b50c6edc132bbbd33964b","abstract.json":"sha256:8a5804e83b674b2099206b113101e2a45e60d7f08996af099dfe685e494173e3","concrete.aut":"sha256:8d8ca9681c2893abf048a0988aa5efc76c22e1fe148c4c75be78780e9be09b39","concrete.json":"sha256:108384d53dadb8aff695d9591c6fa8908af753bee14d56ed37d4c5c382203691"},"catalog_digest":"sha256:0968aee4778afb3cd904eb4942e20b549d173321653c4bc356c13af5841bd7c5","catalog_revision":"rev8","complete_reachable_fixed_point":true,"domain_counts":{"audience":1,"controller":1,"decision":6,"delivery":4,"episode":1,"history_head":4,"input_class":5,"participant":1,"policy_cut":2,"replay":3,"request_id":1},"equivalence_result":"not-established","explicit_non_claims":["No equivalence or live-runtime result is established by construction."],"limitations":["One fresh operation and retries; no identity recycling."],"models":{"abstract":{"initial_state":{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["decided","delivery-pending","idle","offered","terminal"],"states":88,"transitions":107},"concrete":{"initial_state":{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["committing","delivery-pending","gating","idle","preparing-record","resolving-capability","resolving-cut","terminal","validating"],"states":178,"transitions":197}},"profile_digest":"sha256:4439d8ece4d8977f2d991b9ef6b5a73a98951ace513adf80ea4496923985dbb4","profile_file_digest":"sha256:47c02f085aa6952333f75512c9eb7ffc5f7b7982ba49ee0dba4c5a3c32857db4","profile_id":"participant-crossing-dpbb-finite-v1","profile_revision":"rev2","projection":"participant-crossing-projection@rev1","runtime_realization":"not-established","schema":"participant-crossing-model-bundle/v1","source_digests":{"implementations/formal/participant_crossing/__init__.py":"sha256:f51f0d2c6683d45c41da9712da916ccd8df86a96eff4e97d9274a1ee55a96fba","implementations/formal/participant_crossing/__main__.py":"sha256:f608aeb63a97fac9e45ef3855c5a8ddb0aaa9710168aac9fba57e868c600a802","implementations/formal/participant_crossing/abstract.py":"sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531","implementations/formal/participant_crossing/aut.py":"sha256:8ddf46d2cf08986aa99c2b3a39a6817850c321cb09bc9294472fd684fc0b00f8","implementations/formal/participant_crossing/concrete.py":"sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5","implementations/formal/participant_crossing/export.py":"sha256:922f5066a5b85ffe78abe7a79c215103b9ec05217d5ebd1021e9650713ef7948","implementations/formal/participant_crossing/graph.py":"sha256:18d6846bebb31bda0ecacd3e64a4c86c17309b9734d3ea9ed87c4fab7b07a37d","implementations/formal/participant_crossing/ingress.py":"sha256:9acf962a2c409d55dfd909f699a11e1a8ba995992fe7826db106b96edb0af95b","implementations/python/packages/raes_contracts/_behavioral_profile_loader.py":"sha256:e37cc424cc52cb0a210f63a126664bb82d6f3d3e2675b65501fcde75e31eb7dd","implementations/python/packages/raes_contracts/_canonical.py":"sha256:699b5b6801ec1b23c08676789114e77ccfcae3ed458f12a48670967b5fa2c13d","implementations/python/packages/raes_contracts/_participant_crossing_profile.py":"sha256:d4e3a5e771a466daaa253c9da699943cbb72d71b9365954f44472c49919630e3","implementations/python/packages/raes_contracts/behavioral_relation_profiles.py":"sha256:9ce0b3e28aa73a4cb85aaf9b8336e2020169bf5b387473f70da1922a4f5b1716","implementations/python/packages/raes_contracts/canonical.py":"sha256:eff8b51fee43ebb09628abf71612ed73eb403825c93219851965079837fed52a","implementations/python/packages/raes_contracts/contracts/participant_crossing.py":"sha256:c3ac84309e48d6944b9f036940954af5df2f2127c4f56b47f4d803c736bf9e3f","implementations/python/packages/raes_contracts/contracts/participant_crossing_validation.py":"sha256:a6bb4cddfcd06e5fa15ef605106c6baed12c2b8d4e997247b148bdad0a7ef50b","implementations/python/packages/raes_contracts/json_ingress.py":"sha256:b2ae13274cb0752f9f97828032a26283456efc2483110908dd09c52ca243faa5","implementations/python/packages/raes_runtime/control_plane_store.py":"sha256:2631ca837ee1fdd4ecede34c352ea4c0290c5f4f906c2ace1917f9b0de1ef6e2","implementations/python/packages/raes_runtime/participant_crossing_boundary.py":"sha256:88e1e16512251d48ad0f8f52a1bebaff7d90fe2be3b413221b460241344b6d56","implementations/python/packages/raes_runtime/participant_crossing_commit.py":"sha256:0a687c3e02c832a94fa25c88bc0e64c93098ad8f974011b5903132edaa76ba96","implementations/python/packages/raes_runtime/participant_crossing_egress.py":"sha256:87c8e0b11e5a78e5ff69a09801719ef554e6d7934bf44feccc8517a50aff064a","implementations/python/packages/raes_runtime/participant_crossing_mediation.py":"sha256:dd9e0e2b74176e73419007a37c60e66ea6c282dbb11c09e56fae7074bde4355f","implementations/python/packages/raes_runtime/participant_crossing_policy.py":"sha256:50344823aaaa545deca2848e1eeaff3e84d1143d9d3a679536e0848ee6229ee7","implementations/python/packages/raes_runtime/participant_crossing_records.py":"sha256:ceb2cde1e61965135e0c884209dd77fbf1c774de6bf0aea8aab1616e91a09432","implementations/python/packages/raes_runtime/participant_crossing_state_cut.py":"sha256:3bd347d26c08888ea61d8d19600c43f7f1cad01daedc37da34d413b8153b24c2","implementations/python/uv.lock":"sha256:089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd","specs/formal/participant-semantics/information-flow-control.md":"sha256:22e56877a1e439acdbe4e7c587e186f2420e06f366a4ab5875daa2bc5d63efb9","specs/formal/participant-semantics/participant-crossing-models.md":"sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29"},"source_revision":"sha256:16e7afa5c814c4d9557db1c9d86f5f1bac644f14f003f030f5c6eb4a2797be5d"} +{"artifact_digests":{"abstract.aut":"sha256:5891bbc5b3da53c7345f383da7f935ee9f8f0e4dd56b50c6edc132bbbd33964b","abstract.json":"sha256:8a5804e83b674b2099206b113101e2a45e60d7f08996af099dfe685e494173e3","concrete.aut":"sha256:8d8ca9681c2893abf048a0988aa5efc76c22e1fe148c4c75be78780e9be09b39","concrete.json":"sha256:108384d53dadb8aff695d9591c6fa8908af753bee14d56ed37d4c5c382203691"},"catalog_digest":"sha256:0968aee4778afb3cd904eb4942e20b549d173321653c4bc356c13af5841bd7c5","catalog_revision":"rev8","complete_reachable_fixed_point":true,"domain_counts":{"audience":1,"controller":1,"decision":6,"delivery":4,"episode":1,"history_head":4,"input_class":5,"participant":1,"policy_cut":2,"replay":3,"request_id":1},"equivalence_result":"not-established","explicit_non_claims":["No equivalence or live-runtime result is established by construction."],"limitations":["One fresh operation and retries; no identity recycling."],"models":{"abstract":{"initial_state":{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["decided","delivery-pending","idle","offered","terminal"],"states":88,"transitions":107},"concrete":{"initial_state":{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["committing","delivery-pending","gating","idle","preparing-record","resolving-capability","resolving-cut","terminal","validating"],"states":178,"transitions":197}},"profile_digest":"sha256:4439d8ece4d8977f2d991b9ef6b5a73a98951ace513adf80ea4496923985dbb4","profile_file_digest":"sha256:47c02f085aa6952333f75512c9eb7ffc5f7b7982ba49ee0dba4c5a3c32857db4","profile_id":"participant-crossing-dpbb-finite-v1","profile_revision":"rev2","projection":"participant-crossing-projection@rev1","runtime_realization":"not-established","schema":"participant-crossing-model-bundle/v1","source_digests":{"implementations/formal/participant_crossing/__init__.py":"sha256:f51f0d2c6683d45c41da9712da916ccd8df86a96eff4e97d9274a1ee55a96fba","implementations/formal/participant_crossing/__main__.py":"sha256:f608aeb63a97fac9e45ef3855c5a8ddb0aaa9710168aac9fba57e868c600a802","implementations/formal/participant_crossing/abstract.py":"sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531","implementations/formal/participant_crossing/aut.py":"sha256:8ddf46d2cf08986aa99c2b3a39a6817850c321cb09bc9294472fd684fc0b00f8","implementations/formal/participant_crossing/concrete.py":"sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5","implementations/formal/participant_crossing/export.py":"sha256:922f5066a5b85ffe78abe7a79c215103b9ec05217d5ebd1021e9650713ef7948","implementations/formal/participant_crossing/graph.py":"sha256:18d6846bebb31bda0ecacd3e64a4c86c17309b9734d3ea9ed87c4fab7b07a37d","implementations/formal/participant_crossing/ingress.py":"sha256:9acf962a2c409d55dfd909f699a11e1a8ba995992fe7826db106b96edb0af95b","implementations/python/packages/raes_contracts/_behavioral_profile_loader.py":"sha256:e37cc424cc52cb0a210f63a126664bb82d6f3d3e2675b65501fcde75e31eb7dd","implementations/python/packages/raes_contracts/_canonical.py":"sha256:699b5b6801ec1b23c08676789114e77ccfcae3ed458f12a48670967b5fa2c13d","implementations/python/packages/raes_contracts/_participant_crossing_profile.py":"sha256:59d4da70d8de477947888e39f70b43176499297e2b6ad3629ea31d92d2ea1afd","implementations/python/packages/raes_contracts/behavioral_relation_profiles.py":"sha256:9ce0b3e28aa73a4cb85aaf9b8336e2020169bf5b387473f70da1922a4f5b1716","implementations/python/packages/raes_contracts/canonical.py":"sha256:eff8b51fee43ebb09628abf71612ed73eb403825c93219851965079837fed52a","implementations/python/packages/raes_contracts/contracts/participant_crossing.py":"sha256:c3ac84309e48d6944b9f036940954af5df2f2127c4f56b47f4d803c736bf9e3f","implementations/python/packages/raes_contracts/contracts/participant_crossing_validation.py":"sha256:a6bb4cddfcd06e5fa15ef605106c6baed12c2b8d4e997247b148bdad0a7ef50b","implementations/python/packages/raes_contracts/json_ingress.py":"sha256:b2ae13274cb0752f9f97828032a26283456efc2483110908dd09c52ca243faa5","implementations/python/packages/raes_runtime/control_plane_store.py":"sha256:2631ca837ee1fdd4ecede34c352ea4c0290c5f4f906c2ace1917f9b0de1ef6e2","implementations/python/packages/raes_runtime/participant_crossing_boundary.py":"sha256:88e1e16512251d48ad0f8f52a1bebaff7d90fe2be3b413221b460241344b6d56","implementations/python/packages/raes_runtime/participant_crossing_commit.py":"sha256:0a687c3e02c832a94fa25c88bc0e64c93098ad8f974011b5903132edaa76ba96","implementations/python/packages/raes_runtime/participant_crossing_egress.py":"sha256:87c8e0b11e5a78e5ff69a09801719ef554e6d7934bf44feccc8517a50aff064a","implementations/python/packages/raes_runtime/participant_crossing_mediation.py":"sha256:dd9e0e2b74176e73419007a37c60e66ea6c282dbb11c09e56fae7074bde4355f","implementations/python/packages/raes_runtime/participant_crossing_policy.py":"sha256:50344823aaaa545deca2848e1eeaff3e84d1143d9d3a679536e0848ee6229ee7","implementations/python/packages/raes_runtime/participant_crossing_records.py":"sha256:ceb2cde1e61965135e0c884209dd77fbf1c774de6bf0aea8aab1616e91a09432","implementations/python/packages/raes_runtime/participant_crossing_state_cut.py":"sha256:3bd347d26c08888ea61d8d19600c43f7f1cad01daedc37da34d413b8153b24c2","implementations/python/uv.lock":"sha256:089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd","specs/formal/participant-semantics/information-flow-control.md":"sha256:22e56877a1e439acdbe4e7c587e186f2420e06f366a4ab5875daa2bc5d63efb9","specs/formal/participant-semantics/participant-crossing-models.md":"sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29"},"source_revision":"sha256:6db9703d26c75a27d42190989c87a74ec454fdcb5809b231c84205d8804eaf2b"} diff --git a/tools/check_specification_coverage.py b/tools/check_specification_coverage.py index f9370fe6a..568669120 100644 --- a/tools/check_specification_coverage.py +++ b/tools/check_specification_coverage.py @@ -157,12 +157,12 @@ def _load_bundle_index(repo_root: Path) -> list[tuple[str, dict[str, object]]]: "51.0.0", "52.0.0", "53.0.0", - } | {"54.0.0", "55.0.0"} + } | {"54.0.0", "55.0.0", "56.0.0"} if ( - dict(records)[current_path].get("revision") != "55.0.0" + dict(records)[current_path].get("revision") != "56.0.0" or {record.get("revision") for _, record in records} != supported_revisions ): - raise ValueError("coverage evidence requires the explicit current 55.0.0 release and supported history") + raise ValueError("coverage evidence requires the explicit current 56.0.0 release and supported history") return records diff --git a/tools/formal_semantic_validation/_baseline.py b/tools/formal_semantic_validation/_baseline.py index c811eec11..dbdedc7be 100644 --- a/tools/formal_semantic_validation/_baseline.py +++ b/tools/formal_semantic_validation/_baseline.py @@ -193,6 +193,7 @@ def _selected_baseline_manifest( "53.0.0", "54.0.0", "55.0.0", + "56.0.0", }: expected_corpus_path = "docs/research/formal-semantic-validation/corpus/manifest-v4.json" elif baseline_revision in _V3_CORPUS_REVISIONS: diff --git a/tools/formal_semantic_validation/_loading.py b/tools/formal_semantic_validation/_loading.py index e0746c97a..c3de60f90 100644 --- a/tools/formal_semantic_validation/_loading.py +++ b/tools/formal_semantic_validation/_loading.py @@ -82,6 +82,6 @@ def load_retest_bundle( if not releases: raise ValueError("the formal semantic-validation index selects no v2 retest release") release = max(releases, key=lambda item: revision_key(item.manifest.get("revision"))) - if release.manifest.get("revision") != "56.0.0" or release.protocol.get("revision") != "2.0.0": - raise ValueError("the current formal evidence release must be the explicit 56.0.0 retest") + if release.manifest.get("revision") != "57.0.0" or release.protocol.get("revision") != "2.0.0": + raise ValueError("the current formal evidence release must be the explicit 57.0.0 retest") return release, release.protocol, release.corpus, release.snapshot, release.analysis diff --git a/tools/formal_semantic_validation/_release_revisions.py b/tools/formal_semantic_validation/_release_revisions.py index b1a838b0d..0c2d151ea 100644 --- a/tools/formal_semantic_validation/_release_revisions.py +++ b/tools/formal_semantic_validation/_release_revisions.py @@ -53,7 +53,7 @@ "51.0.0", "52.0.0", } -) | {"53.0.0", "54.0.0", "55.0.0"} +) | {"53.0.0", "54.0.0", "55.0.0", "56.0.0"} -_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"56.0.0"} +_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"57.0.0"} _SOURCE_BOUND_RETEST_REVISIONS = _SUPPORTED_RETEST_REVISIONS - {"3.0.0"} diff --git a/tools/formal_semantic_validation/_releases.py b/tools/formal_semantic_validation/_releases.py index 5e9f92e86..673aa2f5d 100644 --- a/tools/formal_semantic_validation/_releases.py +++ b/tools/formal_semantic_validation/_releases.py @@ -159,7 +159,7 @@ def validate_release_bundle(repo_root: Path, release: EvidenceRelease) -> list[P release.corpus, release.snapshot, release.analysis, - replay_current=manifest.get("revision") == "56.0.0", + replay_current=manifest.get("revision") == "57.0.0", ) ) else: @@ -273,6 +273,7 @@ def _expected_corpus_revision(release_revision: object) -> str: "54.0.0", "55.0.0", "56.0.0", + "57.0.0", }: expected_corpus_revision = "4.0.0" return expected_corpus_revision @@ -300,7 +301,7 @@ def validate_retest_bundle( return [ _failure( "formal-validation-current-replay-required", - "only releases 3.0.0 through 55.0.0 can use integrated historical validation", + "only releases 3.0.0 through 56.0.0 can use integrated historical validation", snapshot_path, ) ] @@ -429,6 +430,7 @@ def _current_retest_source_failures( "54.0.0": "53.0.0", "55.0.0": "54.0.0", "56.0.0": "55.0.0", + "57.0.0": "56.0.0", }[release_revision] if not isinstance(baseline, Mapping) or baseline.get("release_revision") != expected_baseline: failures.append( diff --git a/tools/formal_semantic_validation/_retest.py b/tools/formal_semantic_validation/_retest.py index 6e6c95161..ec1da39d7 100644 --- a/tools/formal_semantic_validation/_retest.py +++ b/tools/formal_semantic_validation/_retest.py @@ -37,7 +37,7 @@ ) from tools.policy.common import PolicyFailure -_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 57)) +_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 58)) @dataclasses.dataclass(frozen=True) From efffbe550747d94ea71fb9521802e3e7f9ee55b8 Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Wed, 30 Sep 2026 06:30:08 +0200 Subject: [PATCH 7/8] fix(deps): update PyJWT and refresh source-bound evidence --- .../analysis-v64.json | 156 ++++ .../bundles/retest-v64.json | 122 +++ .../execution-snapshot-v64.json | 652 ++++++++++++++++ .../formal-semantic-validation/index.md | 5 + .../specification-coverage/analysis-v63.json | 105 +++ ...-specification-coverage-issue-971-v63.json | 10 + .../execution-snapshot-v63.json | 700 ++++++++++++++++++ docs/research/specification-coverage/index.md | 7 +- .../tests/test_formal_semantic_validation.py | 5 +- .../test_issue_989_versioned_evidence.py | 6 +- .../tests/test_specification_coverage.py | 2 +- implementations/python/uv.lock | 6 +- .../crossing-models/rev2/manifest.json | 2 +- tools/check_specification_coverage.py | 6 +- tools/formal_semantic_validation/_baseline.py | 1 + tools/formal_semantic_validation/_loading.py | 4 +- .../_release_revisions.py | 5 +- tools/formal_semantic_validation/_releases.py | 5 +- tools/formal_semantic_validation/_retest.py | 2 +- 19 files changed, 1781 insertions(+), 20 deletions(-) create mode 100644 docs/research/formal-semantic-validation/analysis-v64.json create mode 100644 docs/research/formal-semantic-validation/bundles/retest-v64.json create mode 100644 docs/research/formal-semantic-validation/execution-snapshot-v64.json create mode 100644 docs/research/specification-coverage/analysis-v63.json create mode 100644 docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v63.json create mode 100644 docs/research/specification-coverage/execution-snapshot-v63.json diff --git a/docs/research/formal-semantic-validation/analysis-v64.json b/docs/research/formal-semantic-validation/analysis-v64.json new file mode 100644 index 000000000..d5ac5acdc --- /dev/null +++ b/docs/research/formal-semantic-validation/analysis-v64.json @@ -0,0 +1,156 @@ +{ + "analysis_id": "issue-971-dependency-analysis-v64", + "claim": { + "allowed_evidence": [ + "production parser and semantic-validator results", + "canonical compiled digests", + "participant contract regression tests", + "pinned protocol, corpus, and execution snapshot" + ], + "claim_id": "asr-530-formal-semantic-validation-retest", + "disallowed_evidence": [ + "schema success as semantic proof", + "workflow reachability as network or exploit reachability", + "FM labels as gate outcomes", + "attribution as counterfactual proof", + "formal prose or maintainer confidence alone" + ], + "evidence_artifacts": [ + "docs/research/formal-semantic-validation/protocol-v2.json", + "docs/research/formal-semantic-validation/corpus/manifest-v4.json", + "docs/research/formal-semantic-validation/execution-snapshot-v64.json", + "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json" + ], + "falsification_protocol": "Replay every retained and new case through its production entrypoint, require complete digest and evidence joins, execute participant fixtures, and derive status from the recorded outcomes.", + "objective_fail_criteria": "A supported negative passes, a positive fails, an observation drifts, a required participant case is missing, or weaker evidence is promoted to solver, exploit-path, runtime-stability, or counterfactual assurance.", + "objective_pass_criteria": "Every claim class has positive and negative cases, all supported cases reproduce the frozen outcome, every participant obligation has passing positive and negative fixtures, and unsupported classes remain untested.", + "statement": "At the recorded source-state digest, the retained RAES controls have the bounded statuses recorded here; historical releases are integrity evidence, not current replay evidence.", + "threats_to_validity": [ + "The issue-specific corpus is intentionally small and does not enumerate every validator invariant.", + "The participant fixtures exercise reference production contracts and tests, not every independent backend realization.", + "The replay gate runs on one Python reference configuration and one pinned RAES revision.", + "Unsupported solver-level classes have protocol cases but no executable observations." + ] + }, + "claim_results": [ + { + "case_count": 2, + "claim_class_id": "schema-validity", + "evidence_status": "demonstrated", + "limitations": [ + "Bounded to the named source/model structural controls." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 4, + "claim_class_id": "semantic-consistency", + "evidence_status": "partial", + "limitations": [ + "Partial coverage of named static semantics and participant obligations, not universal consistency." + ], + "matching_case_count": 4, + "participant_obligation_count": 7, + "replayable_case_count": 4, + "unsupported_case_count": 0 + }, + { + "case_count": 2, + "claim_class_id": "graph-reachability", + "evidence_status": "partial", + "limitations": [ + "Partial workflow control-flow reachability only; not network, service, or exploit reachability." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 4, + "claim_class_id": "constraint-satisfiability", + "evidence_status": "demonstrated", + "limitations": [ + "Demonstrated only for raes-finite-domain-satisfiability-v1 and its pinned solver configuration." + ], + "matching_case_count": 4, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 2 + }, + { + "case_count": 4, + "claim_class_id": "exploit-path-validity", + "evidence_status": "demonstrated", + "limitations": [ + "Demonstrated only for the admitted snapshot, typed graph, query, semantics, and bounded search profile." + ], + "matching_case_count": 4, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 2 + }, + { + "case_count": 2, + "claim_class_id": "determinism-stability", + "evidence_status": "partial", + "limitations": [ + "Partial parse-to-compile repeatability only; runtime and backend determinism are untested." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 2, + "unsupported_case_count": 0 + }, + { + "case_count": 2, + "claim_class_id": "counterfactual-necessity", + "evidence_status": "untested", + "limitations": [ + "Untested because no governed intervention or ablation entrypoint ran." + ], + "matching_case_count": 2, + "participant_obligation_count": 0, + "replayable_case_count": 0, + "unsupported_case_count": 2 + } + ], + "corpus_revision": "4.0.0", + "evidence_status": "partial", + "execution_id": "issue-971-dependency-execution-v64", + "generated_at": "2026-09-30", + "limitations": [ + "Satisfiability is limited to raes-finite-domain-satisfiability-v1 and its exact translation, theory, and Z3 configuration.", + "The subset-minimal unsatisfiable core is not a universal proof certificate.", + "Exploit-path results are limited to the admitted snapshot, normalized graph, query, transition semantics, and bounded search profile.", + "A valid path is not backend execution and an invalid path is not real-world non-exploitability.", + "The production exploit-path JSON loader permits duplicate keys; the research loader rejects them without claiming stronger production behavior.", + "Participant replay inherits the host environment and is not described as hermetic.", + "Counterfactual necessity remains untested.", + "Scoped observation demand is not a claim class in this preregistration and is not promoted to demonstrated by this retest.", + "EXP-732 provenance joins are verified by their dedicated regression suite; this retained corpus makes no universal run, apparatus, source, or augmentation assurance claim.", + "This retained corpus does not establish native backend attestation fidelity; materialization contract checks remain separate operational provenance, not experimental observations.", + "Capture admission and evidence-proof authority are verified by issue-1237 regression tests, not promoted to a new claim class by this retained corpus.", + "Evidence-requirement refinement lineage is outside this retained formal claim set; this retest refreshes integrated source provenance without promoting that feature to a formal claim.", + "Authoring-adapter transport behavior is outside this retained formal claim set.", + "Operational recovery observation and startup reconciliation are verified by their API-404 regression suite, not promoted to a new formal claim class by this retained corpus.", + "Single-owner store admission, immutable target/run scope, and provider shutdown ordering are verified by their API-404 CP-5 regression suite, not promoted to a formal claim by this retained corpus.", + "Mixed and staged trial admission is verified by its SEM-234/SCE-002/API-407 regression suite, not promoted to a new formal claim class by this retained corpus.", + "Offline control-plane maintenance, readiness, and bounded audit behavior are verified by issue #1186 runtime tests, not promoted to a formal claim by this retained corpus.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 profile declarations and capability admission are covered by dedicated runtime tests; the retained formal corpus does not execute control-plane profile composition.", + "Issue #1016 mixed-runtime coordination is covered by dedicated runtime tests; the retained formal corpus does not establish backend-native mixed realization, multi-controller coordination, IFC, or equivalence.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", + "Issue #1389 temporal-subject admission is verified by dedicated compiler tests and adds no new formal-semantic claim to this retained corpus.", + "Issue #971 model construction is verified by its own tests; this retained corpus establishes no participant-crossing equivalence or runtime-realization claim." + ], + "plain_language_outcome": "The retained cases replay after upgrading the locked PyJWT dependency to 2.14.0; outcomes and bounded claim limits are unchanged.", + "protocol_revision": "2.0.0" +} diff --git a/docs/research/formal-semantic-validation/bundles/retest-v64.json b/docs/research/formal-semantic-validation/bundles/retest-v64.json new file mode 100644 index 000000000..e3f0038d5 --- /dev/null +++ b/docs/research/formal-semantic-validation/bundles/retest-v64.json @@ -0,0 +1,122 @@ +{ + "analysis_path": "docs/research/formal-semantic-validation/analysis-v64.json", + "analysis_sha256": "9bab1375614530a6021434c557b033691a2feff57a5ffbc6fed6ebbbcbe9638a", + "artifacts": [ + { + "artifact_id": "finite-domain-satisfiable-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "sha256": "0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" + }, + { + "artifact_id": "finite-domain-satisfiable-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add" + }, + { + "artifact_id": "finite-domain-unsatisfiable-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "sha256": "cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" + }, + { + "artifact_id": "finite-domain-unsatisfiable-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d" + }, + { + "artifact_id": "typed-exploit-path-valid-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "sha256": "0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" + }, + { + "artifact_id": "typed-exploit-path-valid-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c" + }, + { + "artifact_id": "typed-exploit-path-invalid-v2-input", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "sha256": "0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" + }, + { + "artifact_id": "typed-exploit-path-invalid-v2-evidence", + "kind": "production-evidence", + "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533" + }, + { + "artifact_id": "schema-valid-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml", + "sha256": "41a9adffdf9f5f2ccc2f887dcf7b15fba3b47c83a1af15f33db872c4a2449d67" + }, + { + "artifact_id": "schema-unknown-field-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml", + "sha256": "51cf62319a86c95a2517995939d1f370573051835e4b55bb6d5beaf049640481" + }, + { + "artifact_id": "semantic-resolved-objective-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml", + "sha256": "75834bdc883e2003e1c473870bdf75700978955bb83095c6bd718ba6bd3908a6" + }, + { + "artifact_id": "semantic-dangling-assertion-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml", + "sha256": "1d25bee5f556054e5f0a518df025e4c62e080e1964035e3c1a12e074d88d3a5d" + }, + { + "artifact_id": "semantic-ambiguous-reference-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml", + "sha256": "653cbd2fd62e220d49fb86f80133884207df5ae6752846345ae3085b93f6e4ed" + }, + { + "artifact_id": "semantic-feature-cycle-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml", + "sha256": "e1f66d95a9ad039687aec8cccbc8843b514072ff08e006c1b4ca6aa5cd8d4ed1" + }, + { + "artifact_id": "workflow-reachable-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml", + "sha256": "54c40ceb98ad47247447d737973b2c55e8fb2045e209c7545c4fb20cf42dc3dc" + }, + { + "artifact_id": "workflow-unreachable-step-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml", + "sha256": "ef22ef2e260f1a7fd92d286f9b571716436b192ddfd54aea7bdfcfdda4ca52a2" + }, + { + "artifact_id": "compile-repeatability-control-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", + "sha256": "0bc40900d598c1af7a405d798ca19710405e53ced262d8733081abf12edf89fe" + }, + { + "artifact_id": "compile-non-vacuity-control-comparison-fixture", + "kind": "corpus-input", + "path": "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml", + "sha256": "d85338f89f20a45515b12da8640173c1a52e47eb17ca0f4f6b4f8f3306e863a1" + } + ], + "bundle_id": "raes-formal-semantic-validation", + "corpus_path": "docs/research/formal-semantic-validation/corpus/manifest-v4.json", + "corpus_sha256": "c57207af72406aa4f70882b9bbeb7cedcc79cf3854c878a95e3eb1fa59ea7a72", + "protocol_path": "docs/research/formal-semantic-validation/protocol-v2.json", + "protocol_sha256": "abf94093e344bf495dfb04e8b0c5985c0beaab8ebb17a75e15c8674fa81b1a7c", + "revision": "64.0.0", + "snapshot_path": "docs/research/formal-semantic-validation/execution-snapshot-v64.json", + "snapshot_sha256": "b6b53fa25e1be2fb06e34645a22c0e23546011c126bce474e36e73e39974fdf0" +} diff --git a/docs/research/formal-semantic-validation/execution-snapshot-v64.json b/docs/research/formal-semantic-validation/execution-snapshot-v64.json new file mode 100644 index 000000000..31e46d7b8 --- /dev/null +++ b/docs/research/formal-semantic-validation/execution-snapshot-v64.json @@ -0,0 +1,652 @@ +{ + "baseline": { + "execution_id": "issue-971-merged-execution-v63", + "release_path": "docs/research/formal-semantic-validation/bundles/retest-v63.json", + "release_revision": "63.0.0", + "release_sha256": "82f0fcb448e2d402b1356b6ceebc012be80737ea315e460fb4fe4727a16cc9af" + }, + "captured_at": "2026-09-30T04:28:43.287163+00:00", + "commands": [ + { + "argv": [ + "implementations/python/.venv/bin/python", + "tools/check_formal_semantic_validation.py" + ], + "command_id": "bundle-replay", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/pytest", + "-q", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record", + "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", + "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" + ], + "command_id": "participant-fixtures", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "satisfiability", + "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "--profile", + "raes-finite-domain-satisfiability-v1" + ], + "command_id": "finite-domain-satisfiable-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "satisfiability", + "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "--profile", + "raes-finite-domain-satisfiability-v1" + ], + "command_id": "finite-domain-unsatisfiable-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "exploit-path", + "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "--profile", + "raes-exploit-path-analysis-v1" + ], + "command_id": "typed-exploit-path-valid-v2", + "network": "disabled" + }, + { + "argv": [ + "implementations/python/.venv/bin/raes", + "processor", + "exploit-path", + "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "--profile", + "raes-exploit-path-analysis-v1" + ], + "command_id": "typed-exploit-path-invalid-v2", + "network": "disabled" + } + ], + "configuration_id": "raes-python-reference-offline-v41", + "corpus_revision": "4.0.0", + "deviations": [], + "execution_id": "issue-971-dependency-execution-v64", + "execution_status": "complete", + "observations": [ + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "schema-valid-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "A passing minimal source does not establish semantic correctness." + ], + "replayable": true, + "result_digest": "f7d364ef384df8a1526b489501835b635021c860793b5764f91d956710d2250c", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "schema-unknown-field", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLParseError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The observation covers one unknown-field defect only." + ], + "replayable": true, + "result_digest": "f55d834b458f8e069e1c69061b4cc0a6d61e0e052bf90c670f2e6a5ad8b5bd98", + "source_digest": null + }, + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "semantic-resolved-objective", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "This is a positive control for one objective-reference slice." + ], + "replayable": true, + "result_digest": "652288785dc09095955ed3649f6407d616fb7c4d4f4188df4ed513ccb7537e0b", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-dangling-assertion", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "A single dangling reference does not prove complete semantic coverage." + ], + "replayable": true, + "result_digest": "0207cf616b56708ca9b8c4499d3301abe22dbe52162cf8d58d3bec429d9db024", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-ambiguous-reference", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "One namespace collision does not enumerate every ambiguity surface." + ], + "replayable": true, + "result_digest": "9da4a87797d228e0012ab6b30459f4892e41aa6f224a9840be035fee4a2eea73", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "semantic-feature-cycle", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "One static dependency cycle does not establish general constraint satisfiability." + ], + "replayable": true, + "result_digest": "d15dbcd99fb4f20b965d7031b07dd6534576302270399c3fa656d29e7de02b83", + "source_digest": null + }, + { + "actual_outcome": "accepted", + "analysis_profile": null, + "case_id": "workflow-reachable-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The graph is workflow control flow only." + ], + "replayable": true, + "result_digest": "b1b49649b54bd59d4ef357b39cf9158da90f4eae560f8dd756acf97bd0827a06", + "source_digest": null + }, + { + "actual_outcome": "rejected", + "analysis_profile": null, + "case_id": "workflow-unreachable-step", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "SDLValidationError", + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The result does not establish network, service, participant, or exploit reachability." + ], + "replayable": true, + "result_digest": "bb931d19346ef9193408ae6c85deb4079704378fc5f00dc5f47a2817cff21943", + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "whole-scenario-satisfiable-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "No governed whole-scenario constraint theory or solver exists." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "whole-scenario-unsatisfiable-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Local checks cannot produce a whole-scenario unsat certificate." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "valid-exploit-path-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The issue-168 baseline had no canonical typed attack graph or path-query entrypoint." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "invalid-exploit-path-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Vulnerability and topology declarations are not an invalid-path proof." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "stable", + "analysis_profile": null, + "case_id": "compile-repeatability-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The witness ends at compiled output." + ], + "replayable": true, + "result_digest": "11264a648a949917c0e84a2a1e5d116139a35e6cb941844735a422df95141d6c", + "source_digest": null + }, + { + "actual_outcome": "distinguishable", + "analysis_profile": null, + "case_id": "compile-non-vacuity-control", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", + "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Distinct digests are a non-vacuity control, not semantic non-equivalence proof." + ], + "replayable": true, + "result_digest": "72c1ee8c7bbc1f970216fa232b3d4ae917bcb003bd823439bbac8a5db94214e2", + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "necessity-witness-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "No governed intervention or ablation protocol exists." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "unsupported", + "analysis_profile": null, + "case_id": "non-necessity-control-request", + "configuration_digest": null, + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": null, + "evidence_artifact_path": null, + "evidence_artifact_sha256": null, + "evidence_digest": null, + "evidence_profile": null, + "evidence_refs": [ + "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Attribution and negative fixtures do not demonstrate non-necessity." + ], + "replayable": false, + "result_digest": null, + "source_digest": null + }, + { + "actual_outcome": "satisfiable", + "analysis_profile": "raes-finite-domain-satisfiability-v1", + "case_id": "finite-domain-satisfiable-v2", + "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "scenario-satisfiability-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "evidence_artifact_sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add", + "evidence_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", + "evidence_profile": "scenario-satisfiability-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", + "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", + "specs/formal/scenario-satisfiability/README.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Demonstrates only the pinned finite-domain theory, translation, solver profile, and source." + ], + "replayable": true, + "result_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", + "source_digest": "sha256:0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" + }, + { + "actual_outcome": "unsatisfiable", + "analysis_profile": "raes-finite-domain-satisfiability-v1", + "case_id": "finite-domain-unsatisfiable-v2", + "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "scenario-satisfiability-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "evidence_artifact_sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d", + "evidence_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", + "evidence_profile": "scenario-satisfiability-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", + "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", + "specs/formal/scenario-satisfiability/README.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The subset-minimal core is evidence for the pinned translation and solver, not a proof certificate for arbitrary SDL." + ], + "replayable": true, + "result_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", + "source_digest": "sha256:cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" + }, + { + "actual_outcome": "valid-path", + "analysis_profile": "raes-exploit-path-analysis-v1", + "case_id": "typed-exploit-path-valid-v2", + "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "exploit-path-analysis-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "evidence_artifact_sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c", + "evidence_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", + "evidence_profile": "exploit-path-analysis-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", + "specs/formal/exploit-path-analysis/README.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The witness is bounded to the admitted snapshot, normalized graph, query, semantics, and search profile; it does not establish backend execution." + ], + "replayable": true, + "result_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", + "source_digest": "sha256:0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" + }, + { + "actual_outcome": "invalid-path", + "analysis_profile": "raes-exploit-path-analysis-v1", + "case_id": "typed-exploit-path-invalid-v2", + "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", + "configuration_id": "raes-python-reference-offline-v41", + "diagnostic_kind": "exploit-path-analysis-evidence/v1", + "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "evidence_artifact_sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533", + "evidence_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", + "evidence_profile": "exploit-path-analysis-evidence/v1", + "evidence_refs": [ + "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", + "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", + "specs/formal/exploit-path-analysis/README.md" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Structured rejection proves only that this bounded graph/query cannot reach its goal; it does not establish real-world non-exploitability." + ], + "replayable": true, + "result_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", + "source_digest": "sha256:0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" + } + ], + "participant_observations": [ + { + "evidence_refs": [ + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", + "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Covers the reference SDL/contract path, not every backend projection." + ], + "negative_outcome": "passed", + "obligation_id": "hidden-vs-visible-projection", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", + "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Covers declared applicability and one unresolved-precondition failure." + ], + "negative_outcome": "passed", + "obligation_id": "fail-closed-action-applicability", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", + "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Contract evidence does not prove every backend's live concurrency fidelity." + ], + "negative_outcome": "passed", + "obligation_id": "shared-state-effects", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", + "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Rejecting timestamp-only causality does not supply counterfactual proof." + ], + "negative_outcome": "passed", + "obligation_id": "ordering-before-causality", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", + "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Attribution labels disclose basis; they do not demonstrate necessity." + ], + "negative_outcome": "passed", + "obligation_id": "evidence-labeled-attribution", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", + "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "The fixtures establish layer separation, not outcome validity in every realization." + ], + "negative_outcome": "passed", + "obligation_id": "participant-local-outcome-separation", + "positive_outcome": "passed" + }, + { + "evidence_refs": [ + "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", + "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" + ], + "execution_id": "issue-971-dependency-execution-v64", + "limitations": [ + "Reference conformance evidence remains bounded to declared realization profiles." + ], + "negative_outcome": "passed", + "obligation_id": "realization-profile-honesty", + "positive_outcome": "passed" + } + ], + "protocol_revision": "2.0.0", + "raes_revision": "ebec7a35bb9836748ee67badd5553a7d3fec1b72", + "source_state": { + "base_revision": "ebec7a35bb9836748ee67badd5553a7d3fec1b72", + "checkout_state": "modified", + "implementation_digest": "c11d338c6c52b3dd50b785e02af57d97d6cf8f1cbef544f98fd0403fda1d9fd2", + "profile": "python-reference-source/v2" + }, + "versions": { + "python": "3.14.4", + "raes": "5.0.0", + "z3_engine": "4.16.0", + "z3_solver": "4.16.0.0" + } +} diff --git a/docs/research/formal-semantic-validation/index.md b/docs/research/formal-semantic-validation/index.md index c75ad132f..0a5e435ea 100644 --- a/docs/research/formal-semantic-validation/index.md +++ b/docs/research/formal-semantic-validation/index.md @@ -547,3 +547,8 @@ models and API-424 control contracts in [analysis-v63.json](analysis-v63.json). Outcomes and bounded claim limits remain unchanged. This is construction evidence, with no participant-crossing equivalence or runtime-realization claim. + +Release 64.0.0 repeats the retained cases after the locked PyJWT dependency +upgrade to 2.14.0 in [execution-snapshot-v64.json](execution-snapshot-v64.json) +and [analysis-v64.json](analysis-v64.json). Outcomes and claim limits remain +unchanged. diff --git a/docs/research/specification-coverage/analysis-v63.json b/docs/research/specification-coverage/analysis-v63.json new file mode 100644 index 000000000..8deb588f1 --- /dev/null +++ b/docs/research/specification-coverage/analysis-v63.json @@ -0,0 +1,105 @@ +{ + "analysis_id": "raes-standardized-specification-coverage-issue-971-v63", + "backend_leakage": [], + "claim": { + "allowed_evidence": [ + "pinned source metadata and bounded paraphrases", + "production parser, semantic, instantiation, admission, compiler, contract, and profile results", + "exact artifact digests and typed pointers", + "documented missing-concept and backend-specific dispositions" + ], + "claim_id": "raes-standardized-configurable-specification-coverage", + "disallowed_evidence": [ + "field-count or schema breadth alone", + "the existing scenario stress corpus as the representative request corpus", + "free-form metadata as typed coverage", + "backend-private interpretation", + "post-hoc removal or repair of falsifying concepts" + ], + "evidence_artifacts": [ + "docs/research/specification-coverage/protocol-v1.json", + "docs/research/specification-coverage/execution-snapshot-v63.json", + "docs/research/specification-coverage/analysis-v63.json" + ], + "falsification_protocol": "docs/research/specification-coverage/protocol-v1.json", + "objective_fail_criteria": "A load-bearing concept is missing or lossy, an applicable stage fails, or backend vocabulary is required in core SDL while the result claims success.", + "objective_pass_criteria": "Every load-bearing concept passes at every owning stage, backend-specific mechanics stay outside core SDL, and no requested concept is silently lost.", + "statement": "RAES provides a standardized configurable portable specification surface for the preregistered representative cyber-agent evaluation environment requirements without backend vocabulary in core SDL.", + "threats_to_validity": [ + "The representative corpus contains four source strata and sixteen atomic concepts rather than every cyber-range requirement.", + "The reference processor and repository fixtures are not independent backend implementations.", + "No live range, simulator federation, or participant execution was part of this offline specification-coverage test." + ] + }, + "classification_counts": { + "deliberately-backend-specific": 1, + "directly-expressible": 10, + "missing": 3, + "profile-or-manifest-constraint": 2 + }, + "evidence_status": "partial", + "execution_status": "complete", + "generated_at": "2026-09-30", + "limitations": [ + "This result demonstrates bounded specification coverage, not universal cyber-range coverage, usability, adoption, backend substitution, or behavioral equivalence.", + "The three missing concepts are evidence, not implementation tasks within this snapshot.", + "The retained protocol does not test recursive realization or plan-level profile semantics; this release only re-establishes its original bounded coverage result against the current implementation.", + "The retained protocol does not test evidence-requirement refinement lineage; the dedicated EXP-731 regression suite covers that production boundary.", + "Authoring-adapter transport behavior is outside this retained protocol.", + "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", + "Operational recovery observation and startup reconciliation are covered by their API-404 regression suite, not a new claim in this preregistered matrix.", + "Store ownership, immutable runtime scope, and provider shutdown ordering are covered by the API-404 CP-5 regression suite, not by this retained specification-coverage protocol.", + "Mixed/staged trial compilation and admission are covered by issue #1015 regression tests, not by this retained specification-coverage corpus; no live mixed-runtime result is claimed.", + "Issue #1186 control-plane recovery operations are covered by their runtime regression suite, not by this retained specification-coverage corpus.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", + "Participant-local outcome state is verified by the ACT-618 tests; this retained corpus makes no additional outcome-state claim.", + "Backend operation supervision contracts are covered by issue #1360 contract tests; this retained offline corpus establishes no live backend supervision or recovery guarantee.", + "This capture replays the merged issue #1360 and #1357 source; the protocol makes no live backend execution or supervision claim.", + "This capture replays the merged issue #1360 and #1358 source; the protocol makes no live backend execution or supervision claim.", + "Issue #1389 participant inject delivery temporal-subject admission is covered by dedicated compiler tests; this retained matrix makes no new timing or execution claim.", + "Issue #971 adds offline crossing model construction; this retained protocol establishes no crossing equivalence or runtime-realization claim." + ], + "load_bearing_results": { + "failed": 0, + "missing": 0, + "passed": 10, + "total": 10 + }, + "plain_language_outcome": "The retained cases replay after upgrading the locked PyJWT dependency to 2.14.0; outcomes and bounded claim limits are unchanged.", + "protocol_revision": "1.0.0", + "request_results": [ + { + "concept_count": 6, + "failed_stage_count": 0, + "missing_count": 0, + "request_id": "survey-representative-range", + "status": "demonstrated" + }, + { + "concept_count": 5, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "cyborg-participant-evaluation", + "status": "partial" + }, + { + "concept_count": 3, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "vsdl-configurable-infrastructure", + "status": "partial" + }, + { + "concept_count": 2, + "failed_stage_count": 1, + "missing_count": 1, + "request_id": "cyber-dem-federation", + "status": "partial" + } + ], + "snapshot_id": "raes-standardized-specification-coverage-issue-971-v63", + "snapshot_sha256": "7bcd2526101247117b1d0252d4b25b6f62c4191a5636881523d06a3c85f2597f" +} diff --git a/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v63.json b/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v63.json new file mode 100644 index 000000000..29f4893d0 --- /dev/null +++ b/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-971-v63.json @@ -0,0 +1,10 @@ +{ + "analysis_path": "docs/research/specification-coverage/analysis-v63.json", + "analysis_sha256": "74f597b1c4b6f71a3b902a99f6af15517ce3d4c389df5e325eff09c0e0171e25", + "bundle_id": "raes-standardized-specification-coverage", + "protocol_path": "docs/research/specification-coverage/protocol-v1.json", + "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", + "revision": "63.0.0", + "snapshot_path": "docs/research/specification-coverage/execution-snapshot-v63.json", + "snapshot_sha256": "582c7dfeafb3eca7fb4af4f9b4f4859b9d3a3b7d185f93a731fef672c79d9e0c" +} diff --git a/docs/research/specification-coverage/execution-snapshot-v63.json b/docs/research/specification-coverage/execution-snapshot-v63.json new file mode 100644 index 000000000..5bb61b052 --- /dev/null +++ b/docs/research/specification-coverage/execution-snapshot-v63.json @@ -0,0 +1,700 @@ +{ + "artifacts": [ + { + "artifact_id": "enterprise-participant-sdl", + "kind": "sdl", + "path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032", + "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" + }, + { + "artifact_id": "port-range-sdl", + "kind": "sdl", + "path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f", + "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" + }, + { + "artifact_id": "experiment-task-contract", + "kind": "experiment-task", + "path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc", + "validator": "raes_contracts.contracts.ExperimentTaskModel" + }, + { + "artifact_id": "apparatus-context-contract", + "kind": "experiment-apparatus-context", + "path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299", + "validator": "raes_contracts.contracts.ExperimentApparatusContextModel" + }, + { + "artifact_id": "backend-profile", + "kind": "backend-profile", + "path": "contracts/profiles/backend/orchestration-capable.json", + "sha256": "f70b8505a5c0055416db86c533e2e5bf08b11e5a514f076223b6d6c36215a092", + "validator": "raes_contracts.backend_profiles.BackendProfileModel" + }, + { + "artifact_id": "known-limitations", + "kind": "documentation", + "path": "docs/explain/sdl/limitations.md", + "sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4", + "validator": "documentation evidence only" + } + ], + "baseline": { + "release_revision": "1.1.0", + "release_sha256": "4020a1d56c7fe2831cec59ea64a12bbda9d38ccd94f93b916dd90f1a28f17fcb" + }, + "captured_at": "2026-09-30", + "concept_results": [ + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "range-topology", + "rationale": "SDL nodes and infrastructure own host, network, link, and dependency meaning; the compiler emits canonical node deployment addresses.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed VM declaration.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Links and dependencies resolved.", + "outcome": "passed", + "pointer": "/infrastructure/shipping-portal", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Published instantiated shape admitted.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical deployment address retained.", + "outcome": "passed", + "pointer": "/node_deployments/provision.node.shipping-portal", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/nodes/shipping-portal" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "exercise-roles", + "rationale": "SDL entity roles own exercise responsibility without becoming control-plane identity or authorization.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed red role.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant/role", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Entity references validated.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Role retained after instantiation.", + "outcome": "passed", + "pointer": "/entities/enterprise-participant/role", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Role retained in entity specification.", + "outcome": "passed", + "pointer": "/entity_specs/enterprise-participant/role", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/entities/enterprise-participant/role" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "evaluation-objectives", + "rationale": "SDL objectives own organization ownership, participant assignment, targets, windows, and assertion-based success; measures remain experiment contracts.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed objective declaration.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Owner, participant assignment, targets, assertions, and workflow refs resolved.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff/success", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Objective retained in admitted artifact.", + "outcome": "passed", + "pointer": "/objectives/demonstrate-handoff", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical objective address retained.", + "outcome": "passed", + "pointer": "/objectives/evaluation.objective.demonstrate-handoff", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/objectives/demonstrate-handoff" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "control-workflows", + "rationale": "SDL workflows own the portable control graph and compile to canonical orchestration state contracts.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed control graph.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Step graph and objective refs validated.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery/steps", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Workflow retained after instantiation.", + "outcome": "passed", + "pointer": "/workflows/yard-recovery", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical control graph retained.", + "outcome": "passed", + "pointer": "/workflows/orchestration.workflow.yard-recovery", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/workflows/yard-recovery" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "authored-evidence-expectations", + "rationale": "SDL evidence requirements own portable capture intent and remain distinct from evidence records and measures.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed capture obligation.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Source refs and bindings validated.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Evidence intent retained in admitted artifact.", + "outcome": "passed", + "pointer": "/evidence_requirements/objective-truth-evidence", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + } + ], + "typed_pointer": "/evidence_requirements/objective-truth-evidence" + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [], + "classification": "profile-or-manifest-constraint", + "completeness_disposition": "implemented", + "concept_id": "apparatus-selection-constraints", + "rationale": "The experiment task contract binds processor/backend identities, manifest refs, and capabilities outside SDL.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed ExperimentTaskModel validated.", + "outcome": "passed", + "pointer": "/apparatus_constraints/allowed_backend_refs/0", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/apparatus_constraints/allowed_backend_refs/0" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-agent", + "rationale": "SDL agents own participant entity, knowledge, actions, observation boundaries, and operating scope.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed participant declaration.", + "outcome": "passed", + "pointer": "/agents/participant-agent", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Participant refs and scope validated.", + "outcome": "passed", + "pointer": "/agents/participant-agent/observation_boundaries", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Participant retained in admitted artifact.", + "outcome": "passed", + "pointer": "/agents/participant-agent", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Compiled participant scope retained.", + "outcome": "passed", + "pointer": "/agent_specs/participant-agent", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/agents/participant-agent" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-action-contract", + "rationale": "The action contract declares portable preconditions, effects, observations, evidence, and failure classes without a runner command.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed action contract.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Action refs and evidence bindings validated.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login/effects", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Action retained in admitted artifact.", + "outcome": "passed", + "pointer": "/action_contracts/probe-customer-portal-login", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical action address retained.", + "outcome": "passed", + "pointer": "/action_contracts/participant.action-contract.probe-customer-portal-login", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/action_contracts/probe-customer-portal-login" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "participant-observation-boundary", + "rationale": "The observation boundary separately declares visible, hidden, and evidence-only information with transition rules.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed observation boundary.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Information refs and transitions validated.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view/view_rules", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Boundary retained in admitted artifact.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant-view", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "diagnostic_codes": [], + "note": "Canonical boundary address retained.", + "outcome": "passed", + "pointer": "/observation_boundaries/participant.observation-boundary.participant-view", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/observation_boundaries/participant-view" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "evaluation-measure", + "rationale": "ExperimentTaskModel owns metric construct, unit, direction, aggregation, and evidence requirements outside SDL objectives.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed task contract validated.", + "outcome": "passed", + "pointer": "/evaluation_protocol/metric_definitions/foothold-achieved", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/evaluation_protocol/metric_definitions/foothold-achieved" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "participant-tool-affordance", + "rationale": "This preregistered matrix has no tested carrier for participant tool affordances. The retained missing classification records missing coverage evidence, not the absence of current participant-behavior capabilities.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "The preregistered carrier slot was not run; metadata does not substitute for a typed coverage test.", + "outcome": "not_run", + "pointer": null, + "stage_id": "authored", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "directly-expressible", + "completeness_disposition": "implemented", + "concept_id": "resource-constrained-topology", + "rationale": "SDL node resources and infrastructure dependencies express portable resource intent without provider resource identifiers.", + "stage_results": [ + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Typed CPU and memory declaration.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal/resources", + "stage_id": "authored", + "validation_strength": "structural" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Resource-bearing topology validated.", + "outcome": "passed", + "pointer": "/infrastructure/shipping-portal", + "stage_id": "semantic", + "validation_strength": "semantic" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Constraints retained in admitted artifact.", + "outcome": "passed", + "pointer": "/nodes/shipping-portal/resources", + "stage_id": "instantiated", + "validation_strength": "phase-admitted" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "diagnostic_codes": [], + "note": "Deployment specification retains resource intent.", + "outcome": "passed", + "pointer": "/node_deployments/provision.node.shipping-portal", + "stage_id": "compiled", + "validation_strength": "compiled" + } + ], + "typed_pointer": "/nodes/shipping-portal/resources" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "formal-constraint-satisfiability", + "rationale": "This coverage matrix did not exercise a solver-backed carrier. The separate formal-semantic-validation release demonstrates its bounded finite-domain profile; that result is not silently imported into this protocol's missing carrier slot.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "No coverage-carrier execution was performed here; independent solver evidence does not change this preregistered denominator.", + "outcome": "not_run", + "pointer": null, + "stage_id": "semantic", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [ + { + "allowed": true, + "artifact_path": "source:vsdl-paper", + "pointer": "source sections 4-5", + "reason": "Legitimate VSDL realization vocabulary, not RAES core SDL structure.", + "term": "OpenStack/Terraform/Packer" + } + ], + "classification": "deliberately-backend-specific", + "completeness_disposition": "external", + "concept_id": "provider-specific-provisioning", + "rationale": "Provider image selection and provisioning engines are realization mechanics and therefore remain outside core SDL.", + "stage_results": [ + { + "artifact_path": "contracts/profiles/backend/orchestration-capable.json", + "diagnostic_codes": [], + "note": "The portable boundary requires backend contracts; it does not standardize a provider engine.", + "outcome": "not_applicable", + "pointer": "/required_contracts", + "stage_id": "realization-disclosure", + "validation_strength": "profile" + } + ], + "typed_pointer": null + }, + { + "backend_support": "profile-bound", + "backend_vocabulary_occurrences": [], + "classification": "profile-or-manifest-constraint", + "completeness_disposition": "implemented", + "concept_id": "apparatus-clock-context", + "rationale": "ExperimentApparatusContextModel records clock authority, time domain, and synchronization as apparatus facts outside scenario meaning.", + "stage_results": [ + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "diagnostic_codes": [], + "note": "Closed apparatus context contract validated.", + "outcome": "passed", + "pointer": "/clocks/0", + "stage_id": "contract", + "validation_strength": "contract" + } + ], + "typed_pointer": "/clocks/0" + }, + { + "backend_support": "not-evaluated", + "backend_vocabulary_occurrences": [], + "classification": "missing", + "completeness_disposition": "documented-gap", + "concept_id": "federated-object-event-exchange", + "rationale": "The federated cyber object/event exchange carrier was not exercised by this preregistered matrix. Runtime event internals are not treated as equivalent evidence.", + "stage_results": [ + { + "artifact_path": "docs/explain/sdl/limitations.md", + "diagnostic_codes": [], + "note": "The missing coverage-carrier test is recorded explicitly, without inferring an ecosystem-wide capability absence.", + "outcome": "not_run", + "pointer": null, + "stage_id": "contract", + "validation_strength": "not-applicable" + } + ], + "typed_pointer": null + } + ], + "deviations": [ + { + "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", + "baseline_sha256": "54ba1a60220e27a55da9cd2a407d7d3ab836fa54460d0b0c6cad87c2e744ddbb", + "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", + "retest_sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032" + }, + { + "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", + "baseline_sha256": "a27c7a64e0c5c618fadaccafdf1a4e71600170a8b77b983190822b5141f00dec", + "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", + "retest_sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f" + }, + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", + "baseline_sha256": "21952a752f4e8581a9fc3b872e4bc308150548170d38bcfc83dbbe35ff5e0b9f", + "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", + "retest_sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc" + }, + { + "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", + "baseline_sha256": "9536d897a09cbc6920e667e4f8f9371e51307aa0b3b5ff3c7de682dd783420ab", + "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", + "retest_sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299" + }, + { + "artifact_path": "docs/explain/sdl/limitations.md", + "baseline_sha256": "129cf17810aad4c51988bc872e28fe43ae95019a80053c42d800ff7e2b9cc93e", + "rationale": "Correct historical mandatory-profile guidance after issue #1207; retain the preregistered missing-concept classifications and coverage limits.", + "retest_sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4" + } + ], + "execution_status": "complete", + "implementation_surfaces": [ + { + "content_sha256": "d6a39a62f389a683207a7378378e9c0df3a87e88c44f677617be7af905141d79", + "path": "implementations/python/packages/raes_contracts", + "surface_id": "contract-models" + }, + { + "content_sha256": "27cf5d5bac07ef4b79d922e7c924832c89f13f12ab7e3a441b1a97557dba2b14", + "path": "implementations/python/packages/raes_processor", + "surface_id": "processor-pipeline" + }, + { + "content_sha256": "7de8bf15504fd996b11c7b9f15d0743b452d1c438b37174124097ff2f2a11028", + "path": "implementations/python/packages/raes", + "surface_id": "sdl-pipeline" + } + ], + "limitations": [ + "The execution validates the pinned reference implementation and published contracts, not an independent backend.", + "Repository-owned examples are exact execution artifacts but are not themselves the literature-derived request corpus; the protocol's requests and concepts are.", + "No live range, participant, simulator federation, or provider provisioning engine was executed.", + "Missing concepts remain frozen in this snapshot and require separately scoped product work before a later rerun.", + "This capture replays the retained protocol after EXP-732 run, apparatus, measurement-channel, and augmentation-producer provenance validation; it adds no independent backend or universal provenance assurance claim.", + "Materialization attestation is covered by its dedicated regression suite, not a new claim in this preregistered matrix.", + "This capture refreshes the corrected runtime limitations prose for issue #959; the protocol, coverage classifications and implementation source are unchanged.", + "This capture replays open-by-default augmentation scope integrated with the EXP-731 evidence refinements after composition type refinement; it does not evaluate native backend scope enforcement or broaden the preregistered coverage claims.", + "This capture replays the retained protocol after merging ACT-612 participant relationships with open-by-default augmentation scope; it adds no claim of realized participant relationships or native backend scope enforcement.", + "This capture replays issue #1299 partial listener descriptions on the integrated source state; endpoint completeness and backend admission remain outside this protocol's claims.", + "This capture also binds authoring-adapter semantic conformance to the integrated source; adapter transport behavior remains outside this protocol's claims.", + "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", + "This capture binds issue #1297 service-manager identity, native-name, and explicitly selected systemd-state contract changes to the integrated source. It exercises no live service manager and adds no backend-execution claim.", + "This capture replays the retained specification-coverage protocol after API-404 startup reconciliation added an operational recovery-observation contract. It does not evaluate crash recovery, classify provider effects, or broaden EXP-715 experiment-observation claims.", + "This capture binds API-404 single-owner store admission and immutable target/run scope to the integrated source. The retained offline protocol does not exercise process leases, SQLite lifecycle ordering, or crash recovery.", + "This capture binds issue #1015 deterministic mixed and staged trial admission to the integrated source. The retained offline language corpus does not execute mixed runtimes, phase transitions, backend handoff, or scheduler-driven realization.", + "This replay binds issue #1186 offline control-plane maintenance, readiness, and bounded audit code to the integrated source. The retained language corpus does not execute store recovery, HTTP health behavior, or audit redaction.", + "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", + "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", + "Issue #1016 mixed-runtime coordination is covered by its dedicated runtime suite. The retained language corpus does not execute mixed providers or establish backend-native realization, multi-controller coordination, IFC, or equivalence.", + "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", + "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution." + ], + "protocol_revision": "1.0.0", + "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", + "raes_revision": "ebec7a35bb9836748ee67badd5553a7d3fec1b72", + "snapshot_id": "raes-standardized-specification-coverage-issue-971-v63", + "snapshot_revision": "63.0.0", + "source_state": { + "base_revision": "ebec7a35bb9836748ee67badd5553a7d3fec1b72", + "checkout_state": "modified", + "implementation_digest": "c11d338c6c52b3dd50b785e02af57d97d6cf8f1cbef544f98fd0403fda1d9fd2", + "profile": "python-reference-source/v2" + } +} diff --git a/docs/research/specification-coverage/index.md b/docs/research/specification-coverage/index.md index 5cf371e29..8ef608cfa 100644 --- a/docs/research/specification-coverage/index.md +++ b/docs/research/specification-coverage/index.md @@ -292,7 +292,7 @@ the port scenario. Historical captures and archived example bytes are retained. The matrix classifications and untested concepts are unchanged; no execution authority, successful action, or live backend fidelity is inferred. -Current validation requires release 62.0.0 and rejects duplicate or unsupported +Current validation requires release 63.0.0 and rejects duplicate or unsupported future revisions. It executes current artifacts, requires exact source and package hashes, and checks all passing stage pointers. `source_state` discloses the base Git commit, modified checkout state, and exact implementation digest; @@ -489,3 +489,8 @@ crossing models and API-424 control contracts in [analysis-v62.json](analysis-v62.json). Classifications and claim limits remain unchanged; this is no participant-crossing equivalence or runtime-realization result. + +Release 63.0.0 repeats the retained matrix after the locked PyJWT dependency +upgrade to 2.14.0 in [execution-snapshot-v63.json](execution-snapshot-v63.json) +and [analysis-v63.json](analysis-v63.json). Classifications and claim limits +remain unchanged. diff --git a/implementations/python/tests/test_formal_semantic_validation.py b/implementations/python/tests/test_formal_semantic_validation.py index 7f5707719..87cb25654 100644 --- a/implementations/python/tests/test_formal_semantic_validation.py +++ b/implementations/python/tests/test_formal_semantic_validation.py @@ -142,6 +142,7 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: "61.0.0", "62.0.0", "63.0.0", + "64.0.0", ] assert all(validate_release_bundle(REPO_ROOT, release) == [] for release in releases) @@ -150,10 +151,10 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: def test_current_retest_bundle_is_coherent_and_clean() -> None: release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, REPO_ROOT) - assert release.manifest["revision"] == "63.0.0" + assert release.manifest["revision"] == "64.0.0" assert protocol["revision"] == "2.0.0" assert corpus["revision"] == "4.0.0" - assert snapshot["baseline"]["release_revision"] == "62.0.0" + assert snapshot["baseline"]["release_revision"] == "63.0.0" assert snapshot["deviations"] == [] assert validate_retest_bundle(REPO_ROOT, release, protocol, corpus, snapshot, analysis) == [] diff --git a/implementations/python/tests/test_issue_989_versioned_evidence.py b/implementations/python/tests/test_issue_989_versioned_evidence.py index 008084153..9691f32c6 100644 --- a/implementations/python/tests/test_issue_989_versioned_evidence.py +++ b/implementations/python/tests/test_issue_989_versioned_evidence.py @@ -230,7 +230,7 @@ def test_latest_current_release_is_versioned_and_strict(monkeypatch): from tools.formal_semantic_validation._releases import validate_retest_bundle release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, ROOT) - assert release.manifest["revision"] == "63.0.0" + assert release.manifest["revision"] == "64.0.0" original = _retest.replay_case def changed_result(root, case): @@ -283,7 +283,7 @@ def test_specification_current_capture_does_not_accept_old_artifact_digest(artif from tools.check_specification_coverage import load_bundle, validate_bundle manifest, protocol, snapshot, analysis = copy_bundle(load_bundle, ROOT) - assert manifest["revision"] == "62.0.0" + assert manifest["revision"] == "63.0.0" snapshot = deepcopy(snapshot) artifact = next(a for a in snapshot["artifacts"] if a["artifact_id"] == artifact_id) artifact["sha256"] = old_digest @@ -515,6 +515,7 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "61.0.0", "62.0.0", "63.0.0", + "64.0.0", ] if family == "formal" else [ @@ -581,6 +582,7 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "60.0.0", "61.0.0", "62.0.0", + "63.0.0", ] ) revisions.pop(-1 if removed == "current" else 0) diff --git a/implementations/python/tests/test_specification_coverage.py b/implementations/python/tests/test_specification_coverage.py index 4b7f11819..5818ff970 100644 --- a/implementations/python/tests/test_specification_coverage.py +++ b/implementations/python/tests/test_specification_coverage.py @@ -53,7 +53,7 @@ def test_immutable_bundle_index_preserves_concurrent_captures() -> None: bundles = copy_bundle(load_bundles, REPO_ROOT) assert {manifest["revision"] for manifest, *_rest in bundles} >= {"1.0.0", "1.1.0", "19.0.0"} manifest, *_rest = copy_bundle(load_bundle, REPO_ROOT) - assert manifest["revision"] == "62.0.0" + assert manifest["revision"] == "63.0.0" def test_historical_failures_name_the_revision_specific_documents() -> None: diff --git a/implementations/python/uv.lock b/implementations/python/uv.lock index 4898369a6..acefa855b 100644 --- a/implementations/python/uv.lock +++ b/implementations/python/uv.lock @@ -1065,11 +1065,11 @@ wheels = [ [[package]] name = "pyjwt" -version = "2.13.0" +version = "2.14.0" source = { registry = "https://pypi.org/simple" } -sdist = { url = "https://files.pythonhosted.org/packages/3b/81/58d0ac84e1ef3a3843791d6954d94c0b33d526c75eeb1efbce9d0a4c4077/pyjwt-2.13.0.tar.gz", hash = "sha256:41571c89ca91598c79e8ef18a2d07367d4810fbbd6f637794879baf1b7703423", size = 107515, upload-time = "2026-05-21T19:54:36.618Z" } +sdist = { url = "https://files.pythonhosted.org/packages/af/c3/8a3b59c25070cc61dc517fbdfa5dc0904670c96f605cc69759dc09166b99/pyjwt-2.14.0.tar.gz", hash = "sha256:77283c83fb56ecf566a886c757a714bc83668e38156de2cce8263302f42e0b86", size = 113177, upload-time = "2026-09-11T13:11:54.638Z" } wheels = [ - { url = "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", hash = "sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", size = 31274, upload-time = "2026-05-21T19:54:35.362Z" }, + { url = "https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl", hash = "sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc", size = 32896, upload-time = "2026-09-11T13:11:53.409Z" }, ] [package.optional-dependencies] diff --git a/specs/formal/participant-semantics/crossing-models/rev2/manifest.json b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json index 164f424f9..6fc5eaa2d 100644 --- a/specs/formal/participant-semantics/crossing-models/rev2/manifest.json +++ b/specs/formal/participant-semantics/crossing-models/rev2/manifest.json @@ -1 +1 @@ -{"artifact_digests":{"abstract.aut":"sha256:5891bbc5b3da53c7345f383da7f935ee9f8f0e4dd56b50c6edc132bbbd33964b","abstract.json":"sha256:8a5804e83b674b2099206b113101e2a45e60d7f08996af099dfe685e494173e3","concrete.aut":"sha256:8d8ca9681c2893abf048a0988aa5efc76c22e1fe148c4c75be78780e9be09b39","concrete.json":"sha256:108384d53dadb8aff695d9591c6fa8908af753bee14d56ed37d4c5c382203691"},"catalog_digest":"sha256:0968aee4778afb3cd904eb4942e20b549d173321653c4bc356c13af5841bd7c5","catalog_revision":"rev8","complete_reachable_fixed_point":true,"domain_counts":{"audience":1,"controller":1,"decision":6,"delivery":4,"episode":1,"history_head":4,"input_class":5,"participant":1,"policy_cut":2,"replay":3,"request_id":1},"equivalence_result":"not-established","explicit_non_claims":["No equivalence or live-runtime result is established by construction."],"limitations":["One fresh operation and retries; no identity recycling."],"models":{"abstract":{"initial_state":{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["decided","delivery-pending","idle","offered","terminal"],"states":88,"transitions":107},"concrete":{"initial_state":{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["committing","delivery-pending","gating","idle","preparing-record","resolving-capability","resolving-cut","terminal","validating"],"states":178,"transitions":197}},"profile_digest":"sha256:4439d8ece4d8977f2d991b9ef6b5a73a98951ace513adf80ea4496923985dbb4","profile_file_digest":"sha256:47c02f085aa6952333f75512c9eb7ffc5f7b7982ba49ee0dba4c5a3c32857db4","profile_id":"participant-crossing-dpbb-finite-v1","profile_revision":"rev2","projection":"participant-crossing-projection@rev1","runtime_realization":"not-established","schema":"participant-crossing-model-bundle/v1","source_digests":{"implementations/formal/participant_crossing/__init__.py":"sha256:f51f0d2c6683d45c41da9712da916ccd8df86a96eff4e97d9274a1ee55a96fba","implementations/formal/participant_crossing/__main__.py":"sha256:f608aeb63a97fac9e45ef3855c5a8ddb0aaa9710168aac9fba57e868c600a802","implementations/formal/participant_crossing/abstract.py":"sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531","implementations/formal/participant_crossing/aut.py":"sha256:8ddf46d2cf08986aa99c2b3a39a6817850c321cb09bc9294472fd684fc0b00f8","implementations/formal/participant_crossing/concrete.py":"sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5","implementations/formal/participant_crossing/export.py":"sha256:922f5066a5b85ffe78abe7a79c215103b9ec05217d5ebd1021e9650713ef7948","implementations/formal/participant_crossing/graph.py":"sha256:18d6846bebb31bda0ecacd3e64a4c86c17309b9734d3ea9ed87c4fab7b07a37d","implementations/formal/participant_crossing/ingress.py":"sha256:9acf962a2c409d55dfd909f699a11e1a8ba995992fe7826db106b96edb0af95b","implementations/python/packages/raes_contracts/_behavioral_profile_loader.py":"sha256:e37cc424cc52cb0a210f63a126664bb82d6f3d3e2675b65501fcde75e31eb7dd","implementations/python/packages/raes_contracts/_canonical.py":"sha256:699b5b6801ec1b23c08676789114e77ccfcae3ed458f12a48670967b5fa2c13d","implementations/python/packages/raes_contracts/_participant_crossing_profile.py":"sha256:59d4da70d8de477947888e39f70b43176499297e2b6ad3629ea31d92d2ea1afd","implementations/python/packages/raes_contracts/behavioral_relation_profiles.py":"sha256:9ce0b3e28aa73a4cb85aaf9b8336e2020169bf5b387473f70da1922a4f5b1716","implementations/python/packages/raes_contracts/canonical.py":"sha256:eff8b51fee43ebb09628abf71612ed73eb403825c93219851965079837fed52a","implementations/python/packages/raes_contracts/contracts/participant_crossing.py":"sha256:c3ac84309e48d6944b9f036940954af5df2f2127c4f56b47f4d803c736bf9e3f","implementations/python/packages/raes_contracts/contracts/participant_crossing_validation.py":"sha256:a6bb4cddfcd06e5fa15ef605106c6baed12c2b8d4e997247b148bdad0a7ef50b","implementations/python/packages/raes_contracts/json_ingress.py":"sha256:b2ae13274cb0752f9f97828032a26283456efc2483110908dd09c52ca243faa5","implementations/python/packages/raes_runtime/control_plane_store.py":"sha256:2631ca837ee1fdd4ecede34c352ea4c0290c5f4f906c2ace1917f9b0de1ef6e2","implementations/python/packages/raes_runtime/participant_crossing_boundary.py":"sha256:88e1e16512251d48ad0f8f52a1bebaff7d90fe2be3b413221b460241344b6d56","implementations/python/packages/raes_runtime/participant_crossing_commit.py":"sha256:0a687c3e02c832a94fa25c88bc0e64c93098ad8f974011b5903132edaa76ba96","implementations/python/packages/raes_runtime/participant_crossing_egress.py":"sha256:87c8e0b11e5a78e5ff69a09801719ef554e6d7934bf44feccc8517a50aff064a","implementations/python/packages/raes_runtime/participant_crossing_mediation.py":"sha256:dd9e0e2b74176e73419007a37c60e66ea6c282dbb11c09e56fae7074bde4355f","implementations/python/packages/raes_runtime/participant_crossing_policy.py":"sha256:50344823aaaa545deca2848e1eeaff3e84d1143d9d3a679536e0848ee6229ee7","implementations/python/packages/raes_runtime/participant_crossing_records.py":"sha256:ceb2cde1e61965135e0c884209dd77fbf1c774de6bf0aea8aab1616e91a09432","implementations/python/packages/raes_runtime/participant_crossing_state_cut.py":"sha256:3bd347d26c08888ea61d8d19600c43f7f1cad01daedc37da34d413b8153b24c2","implementations/python/uv.lock":"sha256:089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd","specs/formal/participant-semantics/information-flow-control.md":"sha256:22e56877a1e439acdbe4e7c587e186f2420e06f366a4ab5875daa2bc5d63efb9","specs/formal/participant-semantics/participant-crossing-models.md":"sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29"},"source_revision":"sha256:6db9703d26c75a27d42190989c87a74ec454fdcb5809b231c84205d8804eaf2b"} +{"artifact_digests":{"abstract.aut":"sha256:5891bbc5b3da53c7345f383da7f935ee9f8f0e4dd56b50c6edc132bbbd33964b","abstract.json":"sha256:8a5804e83b674b2099206b113101e2a45e60d7f08996af099dfe685e494173e3","concrete.aut":"sha256:8d8ca9681c2893abf048a0988aa5efc76c22e1fe148c4c75be78780e9be09b39","concrete.json":"sha256:108384d53dadb8aff695d9591c6fa8908af753bee14d56ed37d4c5c382203691"},"catalog_digest":"sha256:0968aee4778afb3cd904eb4942e20b549d173321653c4bc356c13af5841bd7c5","catalog_revision":"rev8","complete_reachable_fixed_point":true,"domain_counts":{"audience":1,"controller":1,"decision":6,"delivery":4,"episode":1,"history_head":4,"input_class":5,"participant":1,"policy_cut":2,"replay":3,"request_id":1},"equivalence_result":"not-established","explicit_non_claims":["No equivalence or live-runtime result is established by construction."],"limitations":["One fresh operation and retries; no identity recycling."],"models":{"abstract":{"initial_state":{"cut":"p0","decision":"none","delivery":"none","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["decided","delivery-pending","idle","offered","terminal"],"states":88,"transitions":107},"concrete":{"initial_state":{"capability":"unresolved","cut":"p0","decision":"none","delivery":"none","gate":"unresolved","head":"h0","intent":null,"last":null,"phase":"idle"},"initial_states":1,"reachable_phases":["committing","delivery-pending","gating","idle","preparing-record","resolving-capability","resolving-cut","terminal","validating"],"states":178,"transitions":197}},"profile_digest":"sha256:4439d8ece4d8977f2d991b9ef6b5a73a98951ace513adf80ea4496923985dbb4","profile_file_digest":"sha256:47c02f085aa6952333f75512c9eb7ffc5f7b7982ba49ee0dba4c5a3c32857db4","profile_id":"participant-crossing-dpbb-finite-v1","profile_revision":"rev2","projection":"participant-crossing-projection@rev1","runtime_realization":"not-established","schema":"participant-crossing-model-bundle/v1","source_digests":{"implementations/formal/participant_crossing/__init__.py":"sha256:f51f0d2c6683d45c41da9712da916ccd8df86a96eff4e97d9274a1ee55a96fba","implementations/formal/participant_crossing/__main__.py":"sha256:f608aeb63a97fac9e45ef3855c5a8ddb0aaa9710168aac9fba57e868c600a802","implementations/formal/participant_crossing/abstract.py":"sha256:efbd1672a1687a21930625a1a16177b450d037f5bddf2047cb17832bf9d26531","implementations/formal/participant_crossing/aut.py":"sha256:8ddf46d2cf08986aa99c2b3a39a6817850c321cb09bc9294472fd684fc0b00f8","implementations/formal/participant_crossing/concrete.py":"sha256:9d2e3c716e76b20b956d0a5d5d49a3533022663a04b6ad5baa318f2e3bd5b3b5","implementations/formal/participant_crossing/export.py":"sha256:922f5066a5b85ffe78abe7a79c215103b9ec05217d5ebd1021e9650713ef7948","implementations/formal/participant_crossing/graph.py":"sha256:18d6846bebb31bda0ecacd3e64a4c86c17309b9734d3ea9ed87c4fab7b07a37d","implementations/formal/participant_crossing/ingress.py":"sha256:9acf962a2c409d55dfd909f699a11e1a8ba995992fe7826db106b96edb0af95b","implementations/python/packages/raes_contracts/_behavioral_profile_loader.py":"sha256:e37cc424cc52cb0a210f63a126664bb82d6f3d3e2675b65501fcde75e31eb7dd","implementations/python/packages/raes_contracts/_canonical.py":"sha256:699b5b6801ec1b23c08676789114e77ccfcae3ed458f12a48670967b5fa2c13d","implementations/python/packages/raes_contracts/_participant_crossing_profile.py":"sha256:59d4da70d8de477947888e39f70b43176499297e2b6ad3629ea31d92d2ea1afd","implementations/python/packages/raes_contracts/behavioral_relation_profiles.py":"sha256:9ce0b3e28aa73a4cb85aaf9b8336e2020169bf5b387473f70da1922a4f5b1716","implementations/python/packages/raes_contracts/canonical.py":"sha256:eff8b51fee43ebb09628abf71612ed73eb403825c93219851965079837fed52a","implementations/python/packages/raes_contracts/contracts/participant_crossing.py":"sha256:c3ac84309e48d6944b9f036940954af5df2f2127c4f56b47f4d803c736bf9e3f","implementations/python/packages/raes_contracts/contracts/participant_crossing_validation.py":"sha256:a6bb4cddfcd06e5fa15ef605106c6baed12c2b8d4e997247b148bdad0a7ef50b","implementations/python/packages/raes_contracts/json_ingress.py":"sha256:b2ae13274cb0752f9f97828032a26283456efc2483110908dd09c52ca243faa5","implementations/python/packages/raes_runtime/control_plane_store.py":"sha256:2631ca837ee1fdd4ecede34c352ea4c0290c5f4f906c2ace1917f9b0de1ef6e2","implementations/python/packages/raes_runtime/participant_crossing_boundary.py":"sha256:88e1e16512251d48ad0f8f52a1bebaff7d90fe2be3b413221b460241344b6d56","implementations/python/packages/raes_runtime/participant_crossing_commit.py":"sha256:0a687c3e02c832a94fa25c88bc0e64c93098ad8f974011b5903132edaa76ba96","implementations/python/packages/raes_runtime/participant_crossing_egress.py":"sha256:87c8e0b11e5a78e5ff69a09801719ef554e6d7934bf44feccc8517a50aff064a","implementations/python/packages/raes_runtime/participant_crossing_mediation.py":"sha256:dd9e0e2b74176e73419007a37c60e66ea6c282dbb11c09e56fae7074bde4355f","implementations/python/packages/raes_runtime/participant_crossing_policy.py":"sha256:50344823aaaa545deca2848e1eeaff3e84d1143d9d3a679536e0848ee6229ee7","implementations/python/packages/raes_runtime/participant_crossing_records.py":"sha256:ceb2cde1e61965135e0c884209dd77fbf1c774de6bf0aea8aab1616e91a09432","implementations/python/packages/raes_runtime/participant_crossing_state_cut.py":"sha256:3bd347d26c08888ea61d8d19600c43f7f1cad01daedc37da34d413b8153b24c2","implementations/python/uv.lock":"sha256:5e3a68a2c3a0077b99c153157e68c671317e4da63329b04af1d0a0480f05b4db","specs/formal/participant-semantics/information-flow-control.md":"sha256:22e56877a1e439acdbe4e7c587e186f2420e06f366a4ab5875daa2bc5d63efb9","specs/formal/participant-semantics/participant-crossing-models.md":"sha256:b1a7884b356d0938f7c5534070161f96cd0a69ce74e0b24ec9da950e17ce8e29"},"source_revision":"sha256:b7a8e45daec8847e70bd187130ed0af26d7990cbe8ae1e33d94cebeeddcd1ef7"} diff --git a/tools/check_specification_coverage.py b/tools/check_specification_coverage.py index a0dc567fc..508fc9a29 100644 --- a/tools/check_specification_coverage.py +++ b/tools/check_specification_coverage.py @@ -157,12 +157,12 @@ def _load_bundle_index(repo_root: Path) -> list[tuple[str, dict[str, object]]]: "51.0.0", "52.0.0", "53.0.0", - } | {"54.0.0", "55.0.0", "56.0.0", "57.0.0", "58.0.0", "59.0.0", "60.0.0", "61.0.0", "62.0.0"} + } | {"54.0.0", "55.0.0", "56.0.0", "57.0.0", "58.0.0", "59.0.0", "60.0.0", "61.0.0", "62.0.0", "63.0.0"} if ( - dict(records)[current_path].get("revision") != "62.0.0" + dict(records)[current_path].get("revision") != "63.0.0" or {record.get("revision") for _, record in records} != supported_revisions ): - raise ValueError("coverage evidence requires the explicit current 62.0.0 release and supported history") + raise ValueError("coverage evidence requires the explicit current 63.0.0 release and supported history") return records diff --git a/tools/formal_semantic_validation/_baseline.py b/tools/formal_semantic_validation/_baseline.py index 5093ab24f..003b71396 100644 --- a/tools/formal_semantic_validation/_baseline.py +++ b/tools/formal_semantic_validation/_baseline.py @@ -199,6 +199,7 @@ def _selected_baseline_manifest( "61.0.0", "62.0.0", "63.0.0", + "64.0.0", }: expected_corpus_path = "docs/research/formal-semantic-validation/corpus/manifest-v4.json" elif baseline_revision in _V3_CORPUS_REVISIONS: diff --git a/tools/formal_semantic_validation/_loading.py b/tools/formal_semantic_validation/_loading.py index a834e9c02..d453e3ea8 100644 --- a/tools/formal_semantic_validation/_loading.py +++ b/tools/formal_semantic_validation/_loading.py @@ -75,6 +75,6 @@ def load_retest_bundle( if not releases: raise ValueError("the formal semantic-validation index selects no v2 retest release") release = max(releases, key=lambda item: revision_key(item.manifest.get("revision"))) - if release.manifest.get("revision") != "63.0.0" or release.protocol.get("revision") != "2.0.0": - raise ValueError("the current formal evidence release must be the explicit 63.0.0 retest") + if release.manifest.get("revision") != "64.0.0" or release.protocol.get("revision") != "2.0.0": + raise ValueError("the current formal evidence release must be the explicit 64.0.0 retest") return release, release.protocol, release.corpus, release.snapshot, release.analysis diff --git a/tools/formal_semantic_validation/_release_revisions.py b/tools/formal_semantic_validation/_release_revisions.py index e2ebe4feb..11e14cc95 100644 --- a/tools/formal_semantic_validation/_release_revisions.py +++ b/tools/formal_semantic_validation/_release_revisions.py @@ -53,9 +53,9 @@ "51.0.0", "52.0.0", } -) | {"53.0.0", "54.0.0", "55.0.0", "56.0.0", "57.0.0", "58.0.0", "59.0.0", "60.0.0", "61.0.0", "62.0.0"} +) | {"53.0.0", "54.0.0", "55.0.0", "56.0.0", "57.0.0", "58.0.0", "59.0.0", "60.0.0", "61.0.0", "62.0.0", "63.0.0"} -_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"63.0.0"} +_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"64.0.0"} _SOURCE_BOUND_RETEST_REVISIONS = _SUPPORTED_RETEST_REVISIONS - {"3.0.0"} _RETEST_BASELINE_REVISIONS = { @@ -121,4 +121,5 @@ "61.0.0": "55.0.0", "62.0.0": "61.0.0", "63.0.0": "62.0.0", + "64.0.0": "63.0.0", } diff --git a/tools/formal_semantic_validation/_releases.py b/tools/formal_semantic_validation/_releases.py index f6879bef2..52add38a5 100644 --- a/tools/formal_semantic_validation/_releases.py +++ b/tools/formal_semantic_validation/_releases.py @@ -160,7 +160,7 @@ def validate_release_bundle(repo_root: Path, release: EvidenceRelease) -> list[P release.corpus, release.snapshot, release.analysis, - replay_current=manifest.get("revision") == "63.0.0", + replay_current=manifest.get("revision") == "64.0.0", ) ) else: @@ -281,6 +281,7 @@ def _expected_corpus_revision(release_revision: object) -> str: "61.0.0", "62.0.0", "63.0.0", + "64.0.0", }: expected_corpus_revision = "4.0.0" return expected_corpus_revision @@ -308,7 +309,7 @@ def validate_retest_bundle( return [ _failure( "formal-validation-current-replay-required", - "only releases 3.0.0 through 62.0.0 can use integrated historical validation", + "only releases 3.0.0 through 63.0.0 can use integrated historical validation", snapshot_path, ) ] diff --git a/tools/formal_semantic_validation/_retest.py b/tools/formal_semantic_validation/_retest.py index fec7207b5..21d5bb392 100644 --- a/tools/formal_semantic_validation/_retest.py +++ b/tools/formal_semantic_validation/_retest.py @@ -37,7 +37,7 @@ ) from tools.policy.common import PolicyFailure -_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 64)) +_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 65)) @dataclasses.dataclass(frozen=True) From d07ab6614a47facaf529481b6aedf37cd613d1fc Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Wed, 30 Sep 2026 06:31:37 +0200 Subject: [PATCH 8/8] fix(build): refresh dependency projections for PyJWT update --- .../tooling/python/smoke/linux-arm64-cp314.txt | 2 +- .../linux-arm64-cp314.wheelhouse-manifest.json | 14 +++++++------- .../tooling/python/smoke/linux-x86_64-cp311.txt | 2 +- .../linux-x86_64-cp311.wheelhouse-manifest.json | 14 +++++++------- .../tooling/python/smoke/linux-x86_64-cp312.txt | 2 +- .../linux-x86_64-cp312.wheelhouse-manifest.json | 14 +++++++------- .../tooling/python/smoke/linux-x86_64-cp313.txt | 2 +- .../linux-x86_64-cp313.wheelhouse-manifest.json | 14 +++++++------- .../tooling/python/smoke/linux-x86_64-cp314.txt | 2 +- .../linux-x86_64-cp314.wheelhouse-manifest.json | 14 +++++++------- .../tooling/python/smoke/macos-arm64-cp314.txt | 2 +- .../macos-arm64-cp314.wheelhouse-manifest.json | 14 +++++++------- 12 files changed, 48 insertions(+), 48 deletions(-) diff --git a/implementations/tooling/python/smoke/linux-arm64-cp314.txt b/implementations/tooling/python/smoke/linux-arm64-cp314.txt index f70edd674..6645b844f 100644 --- a/implementations/tooling/python/smoke/linux-arm64-cp314.txt +++ b/implementations/tooling/python/smoke/linux-arm64-cp314.txt @@ -45,7 +45,7 @@ pydantic==2.12.5 --hash=sha256:e561593fccf61e8a20fc46dfc2dfe075b8be7d0188df33f22 pydantic-core==2.41.5 --hash=sha256:25e1c2af0fce638d5f1988b686f3b3ea8cd7de5f244ca147c777769e798a9cd1 pydantic-settings==2.14.2 --hash=sha256:a20c97b37910b6550d5ea50fbcc2d4187defe58cd57070b73863d069419c9440 pygments==2.20.0 --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 -pyjwt==2.13.0 --hash=sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728 +pyjwt==2.14.0 --hash=sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc pytest==9.1.0 --hash=sha256:8ebb0e7888bdf2bdfc602ec51f8f62d50200af37356c74e503c79a94f5c81f32 pytest-cov==7.1.0 --hash=sha256:a0461110b7865f9a271aa1b51e516c9a95de9d696734a2f71e3e78f46e1d4678 pytest-mock==3.15.1 --hash=sha256:0a25e2eb88fe5168d535041d09a4529a188176ae608a6d249ee65abc0949630d diff --git a/implementations/tooling/python/smoke/linux-arm64-cp314.wheelhouse-manifest.json b/implementations/tooling/python/smoke/linux-arm64-cp314.wheelhouse-manifest.json index cba1adeee..cd7244fee 100644 --- a/implementations/tooling/python/smoke/linux-arm64-cp314.wheelhouse-manifest.json +++ b/implementations/tooling/python/smoke/linux-arm64-cp314.wheelhouse-manifest.json @@ -377,12 +377,12 @@ "version": "2.20.0" }, { - "filename": "pyjwt-2.13.0-py3-none-any.whl", + "filename": "pyjwt-2.14.0-py3-none-any.whl", "name": "pyjwt", - "sha256": "66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", - "size": 31274, - "url": "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", - "version": "2.13.0" + "sha256": "ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc", + "size": 32896, + "url": "https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl", + "version": "2.14.0" }, { "filename": "pytest-9.1.0-py3-none-any.whl", @@ -730,8 +730,8 @@ } ], "lock_path": "implementations/python/uv.lock", - "lock_sha256": "089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd", + "lock_sha256": "5e3a68a2c3a0077b99c153157e68c671317e4da63329b04af1d0a0480f05b4db", "python_closure_profile_id": "public-linux-arm64-cp314-all-extras", - "requirements_sha256": "80683a45b71cd5a285abcd6115fd60b3f2bab31b61e664363346f255862c8047", + "requirements_sha256": "7f08c5e719ebff1b39db3b101c749e3efa0887e0b6a1baf5b66a44c206abd963", "schema_version": "raes-python-wheelhouse-manifest/v1" } diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp311.txt b/implementations/tooling/python/smoke/linux-x86_64-cp311.txt index 8feda8e8d..525a51e18 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp311.txt +++ b/implementations/tooling/python/smoke/linux-x86_64-cp311.txt @@ -45,7 +45,7 @@ pydantic==2.12.5 --hash=sha256:e561593fccf61e8a20fc46dfc2dfe075b8be7d0188df33f22 pydantic-core==2.41.5 --hash=sha256:f31d95a179f8d64d90f6831d71fa93290893a33148d890ba15de25642c5d075b pydantic-settings==2.14.2 --hash=sha256:a20c97b37910b6550d5ea50fbcc2d4187defe58cd57070b73863d069419c9440 pygments==2.20.0 --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 -pyjwt==2.13.0 --hash=sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728 +pyjwt==2.14.0 --hash=sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc pytest==9.1.0 --hash=sha256:8ebb0e7888bdf2bdfc602ec51f8f62d50200af37356c74e503c79a94f5c81f32 pytest-cov==7.1.0 --hash=sha256:a0461110b7865f9a271aa1b51e516c9a95de9d696734a2f71e3e78f46e1d4678 pytest-mock==3.15.1 --hash=sha256:0a25e2eb88fe5168d535041d09a4529a188176ae608a6d249ee65abc0949630d diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp311.wheelhouse-manifest.json b/implementations/tooling/python/smoke/linux-x86_64-cp311.wheelhouse-manifest.json index 251924e9b..5ac3e5d17 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp311.wheelhouse-manifest.json +++ b/implementations/tooling/python/smoke/linux-x86_64-cp311.wheelhouse-manifest.json @@ -377,12 +377,12 @@ "version": "2.20.0" }, { - "filename": "pyjwt-2.13.0-py3-none-any.whl", + "filename": "pyjwt-2.14.0-py3-none-any.whl", "name": "pyjwt", - "sha256": "66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", - "size": 31274, - "url": "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", - "version": "2.13.0" + "sha256": "ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc", + "size": 32896, + "url": "https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl", + "version": "2.14.0" }, { "filename": "pytest-9.1.0-py3-none-any.whl", @@ -730,8 +730,8 @@ } ], "lock_path": "implementations/python/uv.lock", - "lock_sha256": "089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd", + "lock_sha256": "5e3a68a2c3a0077b99c153157e68c671317e4da63329b04af1d0a0480f05b4db", "python_closure_profile_id": "public-linux-x86_64-cp311-all-extras", - "requirements_sha256": "d3afe72bb25fb802dec0858de0af71c7129fbabb081ea334f18a4ce5c73b60ad", + "requirements_sha256": "2248bb47ada5496ba1c3cd9ab8cd695c4cc608f1130dcb490f80a4563c55033c", "schema_version": "raes-python-wheelhouse-manifest/v1" } diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp312.txt b/implementations/tooling/python/smoke/linux-x86_64-cp312.txt index 9955645fd..ab8e022c2 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp312.txt +++ b/implementations/tooling/python/smoke/linux-x86_64-cp312.txt @@ -45,7 +45,7 @@ pydantic==2.12.5 --hash=sha256:e561593fccf61e8a20fc46dfc2dfe075b8be7d0188df33f22 pydantic-core==2.41.5 --hash=sha256:eceb81a8d74f9267ef4081e246ffd6d129da5d87e37a77c9bde550cb04870c1c pydantic-settings==2.14.2 --hash=sha256:a20c97b37910b6550d5ea50fbcc2d4187defe58cd57070b73863d069419c9440 pygments==2.20.0 --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 -pyjwt==2.13.0 --hash=sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728 +pyjwt==2.14.0 --hash=sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc pytest==9.1.0 --hash=sha256:8ebb0e7888bdf2bdfc602ec51f8f62d50200af37356c74e503c79a94f5c81f32 pytest-cov==7.1.0 --hash=sha256:a0461110b7865f9a271aa1b51e516c9a95de9d696734a2f71e3e78f46e1d4678 pytest-mock==3.15.1 --hash=sha256:0a25e2eb88fe5168d535041d09a4529a188176ae608a6d249ee65abc0949630d diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp312.wheelhouse-manifest.json b/implementations/tooling/python/smoke/linux-x86_64-cp312.wheelhouse-manifest.json index 7d482401d..235f2baa3 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp312.wheelhouse-manifest.json +++ b/implementations/tooling/python/smoke/linux-x86_64-cp312.wheelhouse-manifest.json @@ -377,12 +377,12 @@ "version": "2.20.0" }, { - "filename": "pyjwt-2.13.0-py3-none-any.whl", + "filename": "pyjwt-2.14.0-py3-none-any.whl", "name": "pyjwt", - "sha256": "66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", - "size": 31274, - "url": "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", - "version": "2.13.0" + "sha256": "ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc", + "size": 32896, + "url": "https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl", + "version": "2.14.0" }, { "filename": "pytest-9.1.0-py3-none-any.whl", @@ -730,8 +730,8 @@ } ], "lock_path": "implementations/python/uv.lock", - "lock_sha256": "089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd", + "lock_sha256": "5e3a68a2c3a0077b99c153157e68c671317e4da63329b04af1d0a0480f05b4db", "python_closure_profile_id": "public-linux-x86_64-cp312-all-extras", - "requirements_sha256": "7390076b9b60eacaa7453e4a8259a8478760a1008140fb1100900f145146d987", + "requirements_sha256": "c8e7ee3c169df9b68463d3194990d23e4421568806f3778e7fe71e5d1931c6bd", "schema_version": "raes-python-wheelhouse-manifest/v1" } diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp313.txt b/implementations/tooling/python/smoke/linux-x86_64-cp313.txt index 15616a7cb..8aa858ad5 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp313.txt +++ b/implementations/tooling/python/smoke/linux-x86_64-cp313.txt @@ -45,7 +45,7 @@ pydantic==2.12.5 --hash=sha256:e561593fccf61e8a20fc46dfc2dfe075b8be7d0188df33f22 pydantic-core==2.41.5 --hash=sha256:406bf18d345822d6c21366031003612b9c77b3e29ffdb0f612367352aab7d586 pydantic-settings==2.14.2 --hash=sha256:a20c97b37910b6550d5ea50fbcc2d4187defe58cd57070b73863d069419c9440 pygments==2.20.0 --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 -pyjwt==2.13.0 --hash=sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728 +pyjwt==2.14.0 --hash=sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc pytest==9.1.0 --hash=sha256:8ebb0e7888bdf2bdfc602ec51f8f62d50200af37356c74e503c79a94f5c81f32 pytest-cov==7.1.0 --hash=sha256:a0461110b7865f9a271aa1b51e516c9a95de9d696734a2f71e3e78f46e1d4678 pytest-mock==3.15.1 --hash=sha256:0a25e2eb88fe5168d535041d09a4529a188176ae608a6d249ee65abc0949630d diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp313.wheelhouse-manifest.json b/implementations/tooling/python/smoke/linux-x86_64-cp313.wheelhouse-manifest.json index d2c314ee6..a337f76a6 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp313.wheelhouse-manifest.json +++ b/implementations/tooling/python/smoke/linux-x86_64-cp313.wheelhouse-manifest.json @@ -377,12 +377,12 @@ "version": "2.20.0" }, { - "filename": "pyjwt-2.13.0-py3-none-any.whl", + "filename": "pyjwt-2.14.0-py3-none-any.whl", "name": "pyjwt", - "sha256": "66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", - "size": 31274, - "url": "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", - "version": "2.13.0" + "sha256": "ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc", + "size": 32896, + "url": "https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl", + "version": "2.14.0" }, { "filename": "pytest-9.1.0-py3-none-any.whl", @@ -730,8 +730,8 @@ } ], "lock_path": "implementations/python/uv.lock", - "lock_sha256": "089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd", + "lock_sha256": "5e3a68a2c3a0077b99c153157e68c671317e4da63329b04af1d0a0480f05b4db", "python_closure_profile_id": "public-linux-x86_64-cp313-all-extras", - "requirements_sha256": "972e2c097f06d633c5b37ca38f2649180708f8c1e2378ff4c32b45c44a519796", + "requirements_sha256": "aae28599ecbf6de78ed62968e4b08cd1a3e15e29b75d67d8b2f95b8d1b16cb7b", "schema_version": "raes-python-wheelhouse-manifest/v1" } diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp314.txt b/implementations/tooling/python/smoke/linux-x86_64-cp314.txt index 12d3765c7..d68b1bd0c 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp314.txt +++ b/implementations/tooling/python/smoke/linux-x86_64-cp314.txt @@ -45,7 +45,7 @@ pydantic==2.12.5 --hash=sha256:e561593fccf61e8a20fc46dfc2dfe075b8be7d0188df33f22 pydantic-core==2.41.5 --hash=sha256:22f0fb8c1c583a3b6f24df2470833b40207e907b90c928cc8d3594b76f874375 pydantic-settings==2.14.2 --hash=sha256:a20c97b37910b6550d5ea50fbcc2d4187defe58cd57070b73863d069419c9440 pygments==2.20.0 --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 -pyjwt==2.13.0 --hash=sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728 +pyjwt==2.14.0 --hash=sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc pytest==9.1.0 --hash=sha256:8ebb0e7888bdf2bdfc602ec51f8f62d50200af37356c74e503c79a94f5c81f32 pytest-cov==7.1.0 --hash=sha256:a0461110b7865f9a271aa1b51e516c9a95de9d696734a2f71e3e78f46e1d4678 pytest-mock==3.15.1 --hash=sha256:0a25e2eb88fe5168d535041d09a4529a188176ae608a6d249ee65abc0949630d diff --git a/implementations/tooling/python/smoke/linux-x86_64-cp314.wheelhouse-manifest.json b/implementations/tooling/python/smoke/linux-x86_64-cp314.wheelhouse-manifest.json index d74ba0e60..2d7b9d14d 100644 --- a/implementations/tooling/python/smoke/linux-x86_64-cp314.wheelhouse-manifest.json +++ b/implementations/tooling/python/smoke/linux-x86_64-cp314.wheelhouse-manifest.json @@ -377,12 +377,12 @@ "version": "2.20.0" }, { - "filename": "pyjwt-2.13.0-py3-none-any.whl", + "filename": "pyjwt-2.14.0-py3-none-any.whl", "name": "pyjwt", - "sha256": "66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", - "size": 31274, - "url": "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", - "version": "2.13.0" + "sha256": "ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc", + "size": 32896, + "url": "https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl", + "version": "2.14.0" }, { "filename": "pytest-9.1.0-py3-none-any.whl", @@ -730,8 +730,8 @@ } ], "lock_path": "implementations/python/uv.lock", - "lock_sha256": "089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd", + "lock_sha256": "5e3a68a2c3a0077b99c153157e68c671317e4da63329b04af1d0a0480f05b4db", "python_closure_profile_id": "public-linux-x86_64-cp314-all-extras", - "requirements_sha256": "114cfc5b65e331634aa5e5a12cc0a9c230c26decb3e4eba5263c2653848f3e30", + "requirements_sha256": "5951e3a45476f79bab8eee967b4d96f79bc946d46b3c5c39a38e5f02db192dfd", "schema_version": "raes-python-wheelhouse-manifest/v1" } diff --git a/implementations/tooling/python/smoke/macos-arm64-cp314.txt b/implementations/tooling/python/smoke/macos-arm64-cp314.txt index cefcca5b6..a69dd82cc 100644 --- a/implementations/tooling/python/smoke/macos-arm64-cp314.txt +++ b/implementations/tooling/python/smoke/macos-arm64-cp314.txt @@ -45,7 +45,7 @@ pydantic==2.12.5 --hash=sha256:e561593fccf61e8a20fc46dfc2dfe075b8be7d0188df33f22 pydantic-core==2.41.5 --hash=sha256:1d1d9764366c73f996edd17abb6d9d7649a7eb690006ab6adbda117717099b14 pydantic-settings==2.14.2 --hash=sha256:a20c97b37910b6550d5ea50fbcc2d4187defe58cd57070b73863d069419c9440 pygments==2.20.0 --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 -pyjwt==2.13.0 --hash=sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728 +pyjwt==2.14.0 --hash=sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc pytest==9.1.0 --hash=sha256:8ebb0e7888bdf2bdfc602ec51f8f62d50200af37356c74e503c79a94f5c81f32 pytest-cov==7.1.0 --hash=sha256:a0461110b7865f9a271aa1b51e516c9a95de9d696734a2f71e3e78f46e1d4678 pytest-mock==3.15.1 --hash=sha256:0a25e2eb88fe5168d535041d09a4529a188176ae608a6d249ee65abc0949630d diff --git a/implementations/tooling/python/smoke/macos-arm64-cp314.wheelhouse-manifest.json b/implementations/tooling/python/smoke/macos-arm64-cp314.wheelhouse-manifest.json index 863588c3f..4e5d667ae 100644 --- a/implementations/tooling/python/smoke/macos-arm64-cp314.wheelhouse-manifest.json +++ b/implementations/tooling/python/smoke/macos-arm64-cp314.wheelhouse-manifest.json @@ -377,12 +377,12 @@ "version": "2.20.0" }, { - "filename": "pyjwt-2.13.0-py3-none-any.whl", + "filename": "pyjwt-2.14.0-py3-none-any.whl", "name": "pyjwt", - "sha256": "66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", - "size": 31274, - "url": "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", - "version": "2.13.0" + "sha256": "ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc", + "size": 32896, + "url": "https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl", + "version": "2.14.0" }, { "filename": "pytest-9.1.0-py3-none-any.whl", @@ -730,8 +730,8 @@ } ], "lock_path": "implementations/python/uv.lock", - "lock_sha256": "089c252ebfadd73c474b8e7606b67b0e10abfd02be113b90c1bd6fc91da720dd", + "lock_sha256": "5e3a68a2c3a0077b99c153157e68c671317e4da63329b04af1d0a0480f05b4db", "python_closure_profile_id": "public-macos-arm64-cp314-all-extras", - "requirements_sha256": "3a56212b27baace71c892671e3b0c94c2cbab8953b45f14b673ffea4c8f7bec3", + "requirements_sha256": "194417debbb0eb330933da49d4b5a5f1ee8981af428b2f72eb8959e01fbeaf5b", "schema_version": "raes-python-wheelhouse-manifest/v1" }