Part of #241. Tracks the design-review findings that cannot be expressed as JSON-Schema if/then and so land outside sourceos-spec schemas. The schema-expressible ones were fixed inline (#240 SEAM-015 teeth; #246 ledger hash-chain + biometric boundary; #245 SEAM-014/017 manifest teeth + license).
Cross-document invariants → ontogenesis SHACL (T7-8)
Runtime / conformance → workstation-contracts (T7-19)
Spec text / architecture (source-os docs, ADR)
Base-model license (OQ3/finding #11) is now contract-checkable via ModelManifest.license/ModelAdapterManifest.license (#245) — closed at the contract layer; base-model selection still owed under MIT/Apache-only.
Part of #241. Tracks the design-review findings that cannot be expressed as JSON-Schema
if/thenand so land outside sourceos-spec schemas. The schema-expressible ones were fixed inline (#240 SEAM-015 teeth; #246 ledger hash-chain + biometric boundary; #245 SEAM-014/017 manifest teeth + license).Cross-document invariants → ontogenesis SHACL (T7-8)
ModelAdapterManifest.baseModelDigest == ModelManifest.modelDigestwhenbaseModelManifestRefis set.SourceOSModelCarryRef.modelRefresolves to aModelManifest.modelDigest.AdapterPromotionDecision.baseModelDigest/candidateAdapterDigestresolve to real manifests.ledgerPrevHash= hash of entry N-1) — schema only requires the field exists, not that the chain is unbroken.sensitiveCategoriescompleteness (that the T0 classifier actually ran over the input) — schema can't attest a runtime check happened.Runtime / conformance → workstation-contracts (T7-19)
inferenced) counter proving every completion emitted a receipt. Never-fired = suspect.confidenceMethodcalibration, not trust the scalar.visiondmust not return raw embeddings overvision.sockto a networked client — the schema boundary is the decision, the socket is the leak.Spec text / architecture (source-os docs, ADR)
input_retained:falsemeans users can audit what trained the model but not what left the device (hashes only). State the limitation.Base-model license (OQ3/finding #11) is now contract-checkable via
ModelManifest.license/ModelAdapterManifest.license(#245) — closed at the contract layer; base-model selection still owed under MIT/Apache-only.