diff --git a/AFI_Full_Architecture.md b/AFI_Full_Architecture.md index 16f60d3..8f0e81a 100644 --- a/AFI_Full_Architecture.md +++ b/AFI_Full_Architecture.md @@ -77,7 +77,7 @@ flowchart TD ``` **Normative authority.** -- **afi-governance** holds the accepted decisions — object identity, lifecycle, persistence, scoring pins, math authority, districts, and economic law. Sixteen decision records sit on the current default branch. +- **afi-governance** holds the accepted decisions — object identity, lifecycle, persistence, scoring pins, math authority, districts, and economic law. Seventeen decision records sit on the current default branch. - **afi-config** holds the canonical schemas, registries, conventions, and known-answer tests (KATs) that a decision delegates to it. - **afi-math** holds canonical deterministic kernels (the 86-billion emissions schedule, decay/Greeks surfaces) with golden vectors. @@ -107,8 +107,8 @@ AFI is organized by responsibility, not by repository alone. The planes below de `afi-governance/decisions/` carries the accepted decisions. The load-bearing ones today: - **object-identity-v0.1** — canonical Signal (USS v1.1), a thin Scored Signal projection, the strategy triple, `signalId` as the join key. -- **factory-configurable-pipelines-v1** — the analyst-configurable pipeline model: the five-category namespace, the composition and executor boundary, delegation of the V1 contract family to afi-config, and the scored-evidence v2 composition reference. -- **provider-byok-foundations-v0.1** — the provider-neutral adapter socket and the secure bring-your-own-key (BYOK) credential boundary: the five categories as open capability lanes, one resolved result per category, the three non-secret objects (Provider, CredentialRef, ProviderInstance), trusted registered adapters, the credential-never-in-artifact and least-privilege runtime-resolution invariants, canonical category-output validation before scoring, and an Evidence V2 freeze with provider-invocation provenance reserved to a later evidence decision (see [`specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md`](specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md)). +- **factory-configurable-pipelines-v1** — the analyst-configurable pipeline model: the five-category namespace, the composition and executor boundary, delegation of the contract family to afi-config, and the composition reference carried on canonical scored evidence. +- **provider-byok-foundations-v0.1** — the provider-neutral adapter socket and the secure bring-your-own-key (BYOK) credential boundary: the five categories as open capability lanes, one resolved result per category, the three non-secret objects (Provider, CredentialRef, ProviderInstance), trusted registered adapters, the credential-never-in-artifact and least-privilege runtime-resolution invariants, canonical category-output validation before scoring, and the provider-invocation provenance reservation that `evidence-v3-provider-provenance-v0.1` fills (see [`specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md`](specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md)). - **lifecycle-v0.1** — the settlement lifecycle up to the off-chain finality writer; it explicitly reserves on-chain settlement, epochs, rewards, claims, and mint to a future chain-governance track. - **persistence-v0.1** and **persistence-impl-v0.1** — the canonical evidence store and its staged implementation. - **uwr-profile-pin-v0.1** and **uwr-runtime-consumption-v0.1** — the pinned (testnet-provisional) UWR profile and the rules for consuming it at runtime. @@ -117,6 +117,7 @@ AFI is organized by responsibility, not by repository alone. The planes below de - **district-surface-consolidation-v0.1** — the clean-cut District surface record (DSC-GOV): one live `GraphExecutor` as the sole signal-evaluation executor, the District-1 implementation record pointing at the live pipeline, the District-2 provenance law homed in `afi-reactor/src/evidence/provenance/`, exactly one provider framework (`afi-reactor/src/providers/`), and the five-category terminology rule. - **district-one-signal-evaluation-capability-v0.1** — the District One capability record (D1CAP-GOV): District 1 is the **active Signal Evaluation capability and authority domain** (implementation-independent — a conforming future implementation may replace the current one through accepted authority without retiring the district), with its durable responsibility boundary, its exclusions, the descriptive current-implementation mapping, and the ruling that Mission A's clean cut was an implementation retirement only — the district endures. - **five-lane-provider-runtime-v0.1** — the Five-Lane Provider Runtime Activation record (FLPR-GOV): the PBF-GOV provider framework is the **sole live enrichment-execution seam** for all five categories; every enabled lane node carries exactly one explicit `providerInstanceRef` (fail-closed, no silent fallback, no env-var vendor selection); the sentiment/aiMl/candlestick-pattern/SEC-EDGAR adapters and the bounded additive `candlestick` block on `afi.enrichment.pattern.v1`; the byte-level scoring-invariance obligations; and the forward-only removal of every classic direct-call category path. +- **evidence-v3-provider-provenance-v0.1** — the Evidence V3 and provider-invocation provenance record (EV3-GOV): `afi.scored-signal-evidence.v3` as the **sole current canonical scored-signal evidence contract** (the prior record shape carried forward plus exactly three required additions — `providerInvocations`, `recordHash`, `replayHash`); exactly five closed, credential-safe, deterministically ordered per-lane provider invocation proofs (`afi.provider-invocation-proof.v1`, carried, never consumed) with the nested Tiny Brains aiMl invocation proof (`afi.aiml-invocation-proof.v1`); the registered `afi.d2.*` hash-domain assignments with an explicit canonical/replay projection separation; the all-five evaluation-completeness law (every category lane fail-fast — a failed lane yields no scored evaluation and no evidence record); capture in the one live graph pass with a fail-closed sole evidence builder in District 2 that never invokes a provider; V3-only hash-verified admission at the sole canonical writer; and the forward-only replacement of the prior evidence surfaces. The lifecycle state machine is governed as `INGESTED → VALIDATED → SCORED → CERTIFIED → QUALIFIED → CHALLENGE_OPEN → [CONTESTED →] FINALIZED → EPOCH_ELIGIBLE`. **The implemented lifecycle currently reaches `SCORED`.** @@ -125,7 +126,7 @@ The lifecycle state machine is governed as `INGESTED → VALIDATED → SCORED `afi-config` is the canonical home for the schemas and registries the runtime consumes: - the **USS v1.1** signal schema (`schemas/usignal/`); -- the **scored-signal-evidence v2** schema (`afi.scored-signal-evidence.v2`) and its published valid/invalid vectors; +- the **scored-signal-evidence v3** schema (`afi.scored-signal-evidence.v3`) with its per-lane provider invocation proof contracts (`afi.provider-invocation-proof.v1`, `afi.aiml-invocation-proof.v1`) and its published valid/invalid vectors; - the pipeline-composition, analysis-plugin, analyst-strategy, and provider-binding registries; - the **provider / BYOK contract family** — the non-secret `afi.provider.v1`, `afi.credential-ref.v1` (an opaque pointer that never holds a secret), and `afi.provider-instance.v1` (tenant-scoped) schemas, the `registries/providers/` reference records, and the canonical per-category output contracts `afi.enrichment.{technical,pattern,sentiment,news,aiml}.v1` — all five categories have governed contracts (PBF-GOV foundations; the full contract family completed with the enrichment-contract mission); - the **CPJ v0.1** community-provider-journal schema (`schemas/cpj/v0_1`) and the active oracle provider bindings that consume it; @@ -165,10 +166,11 @@ Factory is **not** the API Atlas, **not** the Gateway, **not** the Reactor runti - **Two live ingress paths reach the executor.** Most submissions arrive routed from the Gateway (`POST /api/v1/signals` → the Reactor webhook). The Reactor also exposes **`POST /api/ingest/cpj`**, a direct community-provider-journal ingest (`afi.cpj.v0.1`, for Telegram/Discord oracle providers) that bypasses the Gateway under an optional shared secret, validates CPJ v0.1, and deduplicates by ingest hash (`409` on a duplicate). Both paths **resolve the provider → strategy binding** against the boot-validated provider-binding registry — an unbound provider is rejected with an honest `403`, never a silent default composition — then map to USS v1.1 and run the identical scoring path. - **The direct CPJ route is an internal trusted service boundary, not a public API (Reference/Reserved).** Its authentication is optional (a single shared secret) and provider identity is self-asserted, so any future public or partner CPJ access is designated to be mediated by a separate authenticated **Institute oracle-ingress reference service** — designated, **not implemented or deployed** — or another conforming external trust boundary; the route is neither renamed, moved, nor exposed. Provider binding, CPJ validation, and provenance stay mandatory regardless of exposure (ingest dedupe is opt-in, `AFI_INGEST_DEDUPE=1`) (INST-GOV; see [`specs/AFI_RESEARCH_INSTITUTE_REFERENCE_SERVICES.v0.1.md`](specs/AFI_RESEARCH_INSTITUTE_REFERENCE_SERVICES.v0.1.md)). - The **graph is manifest-driven**, not a hardcoded DAG. The executor runs topological waves (Kahn's algorithm) with bounded concurrency, deterministic ready-sets, per-node timeout and retry, conditional edges, and joins keyed by node id. Graph validation enforces unique ids, acyclicity, reachability, exactly one non-bypassable scorer sink, and declared joins. -- The **five analysis categories** are vendor-neutral, provider-instance-backed lane plugins bound at build time, alongside the five-category join plugin and the scorer. Any registered strategy (for example the "Froggy trend-pullback" scorer) is an ordinary registry entry, not a special path. The `aiMl` lane joins the sibling lanes' outputs and invokes the self-hosted `afi-tiny-brains` service through its governed adapter, naming the ProviderInstance-selected orchestration profile (the governed `model` field) and carrying the technical lane's real close-price series; Tiny Brains runs that profile's approved internal experts (Chronos-Bolt forecaster + deterministic trend baseline behind `froggy-reference-v1`) through a deterministic resolver into exactly one result. Its result is read-only context and **does not affect UWR scoring** (a failed lane, unknown profile, unready model, or invalid expert output settles under the declared failure policy as a recorded degradation — nothing is fabricated). +- The **five analysis categories** are vendor-neutral, provider-instance-backed lane plugins bound at build time, alongside the five-category join plugin and the scorer. Any registered strategy (for example the "Froggy trend-pullback" scorer) is an ordinary registry entry, not a special path. The `aiMl` lane joins the sibling lanes' outputs and invokes the self-hosted `afi-tiny-brains` service through its governed adapter, naming the ProviderInstance-selected orchestration profile (the governed `model` field) and carrying the technical lane's real close-price series; Tiny Brains runs that profile's approved internal experts (Chronos-Bolt forecaster + deterministic trend baseline behind `froggy-reference-v1`) through a deterministic resolver into exactly one result. Its result is read-only context and **does not affect UWR scoring** (a failed lane, unknown profile, unready model, or invalid expert output fails the run under the all-five evaluation-completeness law — no scored evaluation, no scored signal, no evidence record; bounded operational diagnostics only, nothing fabricated). - The **bounded provider-adapter runtime** inside the Reactor, below the category node (not a second executor), is the **sole live enrichment-execution seam** (FLPR-GOV). Boot loads the governed `registries/{providers,provider-instances,credential-refs}` records fail-closed; every lane node carries a non-secret `providerInstanceRef`; the runtime resolves the tenant-scoped provider instance, resolves **only** the authorized credential through an injected least-privilege `SecretResolver` (the adapter receives a bounded credential bundle, never a resolver), invokes the trusted statically registered adapter, and validates the canonical `afi.enrichment..v1` output before it reaches the scorer — one resolved result per category, fail-closed at every boundary, no silent provider fallback. Eight adapters are registered: keyless local technical, first-party candlestick pattern (local kernels), Tiny-Brains pattern (self-hosted STUMPY/ruptures/find_peaks), keyless CFTC-COT sentiment (public domain), credentialed Coinalyze sentiment (BYOK header), credentialed NewsData news (BYOK header), keyless SEC-EDGAR news, and first-party Tiny-Brains aiMl (internal orchestration selected per instance via the governed `model` field, validated against the provider record's `supportedModels`). The committed reference profile selects an all-five keyless/self-hosted instance set; selecting a different supported provider is a registry/record change, never category-node code. Credentials are resolved only at invocation and appear in no artifact, log, hash, or evidence; the current resolver backend is the env-backed development backend, and deployment-specific secret backends are pending a later staging wave (PBF-GOV + FLPR-GOV; see [`specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md`](specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md)). - The scorer node wraps afi-core's analyst, resolves the UWR configuration fail-closed, and emits scores and their resolved source verbatim. -- The Reactor **constructs Evidence V2** (`afi.scored-signal-evidence.v2`) with `lifecycleState = SCORED`, `finalized = false`, the registry-backed UWR-profile stamp, and a required all-or-nothing composition reference. Scores are read verbatim from afi-core and never recomputed. +- **A scored evaluation requires all five lanes to succeed** (EV3-GOV): every category lane node in the registered manifest is fail-fast, so a failed lane yields no scored evaluation, no scored signal, and no evidence record — bounded operational diagnostics only. **Provider invocation provenance is captured inside the same single graph pass** at the provider-runtime seam, where the identity chain is already resolved, and travels with execution state to District 2 — evidence describes the invocation that occurred and never re-calls a provider. Each lane's proof binds non-secret facts only: the Provider identity (id, record version, record fingerprint, execution class, deterministic/probabilistic posture), the ProviderInstance identity (id, record version, configuration fingerprint, and the governed `model` where the instance declares one), the adapter identity (id, version, transport kind), the credential binding — an explicit keyless posture or an opaque CredentialRef (id, record version, kind, governed status; never a secret, secret-derived hash, header, token, or credentialed URL) — and the normalized invocation-input, provider-result, and category-result hashes. The `aiMl` proof additionally nests the Tiny Brains invocation proof: orchestration profile, resolver, and per-expert identities and versions, per-expert output hashes, model artifact fingerprints, and the service's verified input/output hashes — hashes and identifiers only, no raw payloads, prompts, paths, or weights. +- The Reactor **constructs Evidence V3** (`afi.scored-signal-evidence.v3`) — the sole current canonical scored-signal evidence contract — with `lifecycleState = SCORED`, `finalized = false`, the registry-backed UWR-profile stamp, a required all-or-nothing composition reference, exactly **five** provider invocation proofs (one per category, unique, deterministically ordered, carried, never consumed), and record-level `recordHash` / `replayHash` commitments. District 2's sole evidence builder validates the five bound proofs and cross-checks every identity and hash against the boot-verified registries and the results the analyst path actually consumed, fail-closed on any mismatch. The canonical record separates immutable invocation facts and the deterministic replay projection from operational diagnostics: wall-clock timings, attempt counts, and transport noise stay in runtime logs and never enter the record or any hashed preimage; `replayHash` commits to the replay projection, so two evaluations of the same canonical inputs through the same composition produce identical `replayHash` values. Scores are read verbatim from afi-core and never recomputed. - The **submitter rejects any non-`SCORED` record**, proves the wrapper, schema, sub-artifact schemas, and identifier continuity before submitting, and surfaces every failure as a typed non-2xx. The Reactor **never touches MongoDB directly**; it consumes afi-infra's store as a typed dependency, and persistence is a required step of the run. ### 6. Core and mathematical computation plane **(Implemented)** @@ -189,7 +191,7 @@ UWR (the Universal Weighting Rule) is the governed scoring mechanism. There is n `afi-infra` owns the **sole canonical write path**. -- The store's `submit` is the only first-write path: it requires the record schema to be `afi.scored-signal-evidence.v2`, validates the governed schema and identifier continuity, then inserts into a collection with a **unique `signalId` index**. The default database is `afi_scored_signal_evidence` and the current collection is `scored_signal_evidence` (with a history collection), overridable by environment. +- The store's `submit` is the only first-write path: it requires the record schema to be `afi.scored-signal-evidence.v3` (the only admissible evidence contract), validates the governed schema and identifier continuity, verifies the record's `recordHash` and `replayHash` by recomputation (an invalid or mis-hashed record is rejected, never persisted), then inserts into a collection with a **unique `signalId` index**. The default database is `afi_scored_signal_evidence` and the current collection is `scored_signal_evidence` (with a history collection), overridable by environment. - Persistence is **append-once and idempotent**: an identical re-submission returns an idempotent-duplicate outcome; a differing submission for the same `signalId` is a conflict (`409`). A governed correction must go through `supersede()`, which archives the existing version and installs the new one inside a single transaction with version pinning and refuses to alter a finalized record. - The Gateway routes and never writes here; the Reactor submits and never writes here; afi-infra is the writer. @@ -243,7 +245,7 @@ flowchart TD D --> E["GraphExecutor
manifest-driven topological waves"] E --> F["five analysis categories
technical • pattern • sentiment • news • aiMl"] F --> G["deterministic join → scorer sink
afi-core UWR scoring"] - G --> H["Evidence V2 construction
afi.scored-signal-evidence.v2 • composition ref • SCORED"] + G --> H["Evidence V3 construction
afi.scored-signal-evidence.v3 • five invocation proofs • composition ref • SCORED"] H --> I["afi-infra store.submit
unique signalId • append-once • transactional"] I --> J(["Canonical record persisted
lifecycleState = SCORED"]) style RG stroke-dasharray: 5 5 @@ -255,7 +257,7 @@ The dotted entry lanes are the **designated** ways to reach the two implemented ```text ingest → USS v1.1 validation → scoring (governed UWR engine, pinned profile) - → Evidence V2 construction (composition reference) + → Evidence V3 construction (composition reference • five provider invocation proofs • recordHash/replayHash) → canonical store (unique signalId, append-once, transactional supersession) → lifecycleState = SCORED ``` @@ -294,7 +296,7 @@ flowchart LR Exactly **two** Districts are formally registered (`authority-districts-v0.1`, Part D, as amended by `district-surface-consolidation-v0.1` (DSC-GOV) and `district-one-signal-evaluation-capability-v0.1` (D1CAP-GOV)). Both are **active capability domains**, and both remain **non-production** (nothing is deployed). No other District is created or implied. Districts represent durable capability and authority boundaries: implementations may be replaced through accepted authority without retiring the district they implement. - **District 1 — Signal Evaluation** — the **active** Signal Evaluation capability and authority domain (D1CAP-GOV). It owns evaluation from canonical signal input through the scorer/UWR seam: evaluation-time validation, execution of the five enrichment categories, explicit provider-instance resolution for provider-backed categories, category-result validation against the governed `afi.enrichment.*.v1` contracts, deterministic fan-out and join (exactly one validated result per category), analyst invocation under accepted authority, canonical scorer/UWR invocation (invoked, never re-implemented), and creation of the scored evaluation result handed to District 2. Its current implementation is the live flow described in "The current end-to-end flow" below: the two ingress paths → the one manifest-driven `GraphExecutor` (`afi-reactor/src/pipeline/`) → category nodes → enrichment join → analyst/scorer/UWR → the District-2 handoff. The district is not any directory, class, manifest, analyst, or provider — the mapping is descriptive, and a conforming future implementation may replace it through accepted authority. The five-lane provider runtime is **active** for all five categories (FLPR-GOV; see the category table below). Git history preserves the earlier proof-of-concept implementation record; that record's retirement under DSC-GOV was an implementation retirement only — the district is active. -- **District 2 — Canonical Data & Provenance Boundary.** Active. Its M1 schema family is implemented in `afi-config/schemas/provenance/v1` with validation tests, authorized for **M1 only** ("no runtime wiring") by the D-17 instrument homed in afi-docs. Its live provenance law — CanonicalHash v1 (`afi.hash.v1`), the ScoredSignal v1 projection builders, and the D2 schema validators — is implemented in `afi-reactor/src/evidence/provenance/` and runs as a required step of every scoring run; the prospective, bounded, non-production ratification of `district-2-m2-ratification-v0.1` is recorded at that location by DSC-GOV D-DSC-3 (no canonical-object declaration is made). **It receives the scored evaluation result from District 1 at the scorer/UWR seam** and owns evidence construction, validation, and the canonical handoff to persistence from there. +- **District 2 — Canonical Data & Provenance Boundary.** Active. Its M1 schema family is implemented in `afi-config/schemas/provenance/v1` with validation tests, authorized for **M1 only** ("no runtime wiring") by the D-17 instrument homed in afi-docs. Its live provenance law — CanonicalHash v1 (`afi.hash.v1`), the ScoredSignal v1 projection builders, and the D2 schema validators — is implemented in `afi-reactor/src/evidence/provenance/` and runs as a required step of every scoring run; the prospective, bounded, non-production ratification of `district-2-m2-ratification-v0.1` is recorded at that location by DSC-GOV D-DSC-3 (no canonical-object declaration is made). **It receives the scored evaluation result and the five bound provider invocation proofs from District 1 at the scorer/UWR seam** and owns evidence construction, validation, and the canonical handoff to persistence from there: its sole evidence builder validates the five proofs (exactly five, unique by category, deterministically ordered), cross-checks every identity and hash fail-closed, and constructs the one canonical Evidence V3 artifact (`afi.scored-signal-evidence.v3`) that afi-infra persists as sole writer. **District 2 never invokes a provider** — evidence describes the invocation that occurred (EV3-GOV). **Five-category state (District 1, current truth):** @@ -306,7 +308,7 @@ Exactly **two** Districts are formally registered (`authority-districts-v0.1`, P | `news` | `afi.enrichment.news.v1` | `afi-instance-reference-news-sec-edgar` (public filings) | `afi-instance-byok-news-newsdata` (BYOK header) | no (evidence/lenses only) | | `aiMl` | `afi.enrichment.aiml.v1` | `afi-instance-reference-aiml-tiny-brains` (self-hosted service; `model: froggy-reference-v1` selects the internal orchestration profile) | — | no (read-only context; evidence/lenses only) | -All five categories execute live through the provider runtime: the registered `froggy-trend-pullback v1.2.0` manifest binds an explicit `providerInstanceRef` on every lane node (the committed all-five keyless/self-hosted reference profile), and provider selection is a registry/record change under FLPR-GOV D-FLPR-4 — never category-node code, never an environment switch, never a silent fallback. +All five categories execute live through the provider runtime: the registered `froggy-trend-pullback v1.3.0` manifest binds an explicit `providerInstanceRef` on every lane node (the committed all-five keyless/self-hosted reference profile) and declares every category lane fail-fast — a scored evaluation requires all five lanes to succeed, and a failed lane yields no scored evaluation, no scored signal, and no evidence record (EV3-GOV D-EV3-5). Provider selection is a registry/record change under FLPR-GOV D-FLPR-4 — never category-node code, never an environment switch, never a silent fallback. **District map authority.** No canonical API Atlas exists and none is started (ATLAS-GOV reserved). District authority and the accepted decision chain — the Part D prose registry as amended — remain the current District map; a future Atlas will describe real District capabilities and interfaces, not define or execute them. No machine-readable District registry exists; creating one belongs to ATLAS-GOV. @@ -325,7 +327,7 @@ All five categories execute live through the provider runtime: the registered `f |---|---| | **Developer** | `afi-reactor` (runtime) and `afi-core` (scoring library), then the contracts in `afi-config`. | | **Analyst / strategy author** | the UWR profile registry and KATs in `afi-config`; author pipelines and configs with `afi-factory`. | -| **Validator** | the `scored-signal-evidence` v2 schema and vectors in `afi-config`; store semantics in `afi-infra`. | +| **Validator** | the `scored-signal-evidence` v3 schema and vectors in `afi-config`; store semantics in `afi-infra`. | | **Operator** | `afi-gateway` (submission boundary) and `afi-infra` (canonical store). | | **Researcher** | `afi-docs`, `afi-econ`, `afi-benchkit`, and the frozen record in `afi-artifacts`. | diff --git a/ARCHITECTURE_STATUS.md b/ARCHITECTURE_STATUS.md index 74824d0..319c34f 100644 --- a/ARCHITECTURE_STATUS.md +++ b/ARCHITECTURE_STATUS.md @@ -1,6 +1,6 @@ # AFI Protocol — Architecture Status -**Last updated:** 2026-07-18 +**Last updated:** 2026-07-19 **Purpose:** Orchestration-focused status snapshot of how AFI scoring is implemented today. The organization-wide current-state map is [AFI_Full_Architecture.md](AFI_Full_Architecture.md). --- @@ -27,11 +27,20 @@ instantiation, manifest validation, and canonical (timestamp-free) hashing. Nothing the Factory emits is canonical until validated against the delegated `afi-config` contracts. -- **Evidence**: the Reactor constructs `afi.scored-signal-evidence.v2` records - carrying a thin `afi.composition-ref.v1` composition reference (pipeline - identity, analyst-config hash, scorer and plugin-set references, hash-addressed - execution summaries); `afi-infra` validates and persists them at the sole - canonical persistence interface. +- **Evidence**: the Reactor constructs `afi.scored-signal-evidence.v3` records — + the sole current canonical evidence contract — carrying a thin + `afi.composition-ref.v1` composition reference (pipeline identity, + analyst-config hash, scorer and plugin-set references, hash-addressed + execution summaries), exactly five credential-safe per-lane provider + invocation proofs (`afi.provider-invocation-proof.v1`, unique by category, + deterministically ordered; the `aiMl` proof nests the Tiny Brains invocation + proof `afi.aiml-invocation-proof.v1`), and record-level + `recordHash`/`replayHash` commitments; `afi-infra` validates, hash-verifies, + and persists them at the sole canonical persistence interface. +- **Evaluation completeness**: a scored evaluation requires all five category + lanes to succeed (EV3-GOV) — every lane node in the registered manifest is + fail-fast, and a failed lane yields no scored evaluation, no scored signal, + and no evidence record (bounded operational diagnostics only). Implementation lives under: @@ -53,7 +62,7 @@ Implementation lives under: | Graph orchestration | `afi-reactor/src/pipeline/` | | Pipeline authoring (templates, validation, hashing) | `afi-factory` | | Validators, scoring, decay | `afi-core` | -| Schemas & registries (USS, `afi.pipeline.v1` family, evidence v2) | `afi-config/schemas/`, `afi-config/registries/` | +| Schemas & registries (USS, `afi.pipeline.v1` family, evidence v3) | `afi-config/schemas/`, `afi-config/registries/` | | Canonical evidence store | `afi-infra` | | On-chain mint | `afi-token` | | Off-chain mint coordination | `afi-mint` | @@ -75,7 +84,7 @@ Implementation lives under: | Registered strategy | An analyst-strategy registry entry binding a pipeline, scorer, UWR profile, and decay configuration (`afi-config/registries/analyst-strategies/`) | | Analysis category | One of the five canonical categories: `technical`, `pattern`, `sentiment`, `news`, `aiMl` | | Scorer terminal | The exactly-one scoring node terminating a valid pipeline; performs the sole `VALIDATED → SCORED` transition | -| Composition reference | The thin `afi.composition-ref.v1` object carried on `afi.scored-signal-evidence.v2`, binding evidence to the executed composition by canonical hashes | +| Composition reference | The thin `afi.composition-ref.v1` object carried on `afi.scored-signal-evidence.v3`, binding evidence to the executed composition by canonical hashes | | District 1 — Signal Evaluation | The **active** Signal Evaluation capability and authority domain (`district-one-signal-evaluation-capability-v0.1`, D1CAP-GOV): canonical input → five-category enrichment → deterministic join → analyst/scorer/UWR seam → District-2 handoff. Its current implementation is the live GraphExecutor pipeline (`afi-reactor/src/pipeline/`); implementations may be replaced through accepted authority without retiring the district | | District 2 — Evidence & Provenance | The active canonical data & provenance boundary: receives the scored evaluation result from District 1 and owns evidence construction, validation, and the canonical persistence handoff. Live law in `afi-reactor/src/evidence/provenance/` | | Pipehead | The bounded stage discipline of the Pipehead Addendum (one node → one validated category result → merge → one scorer seam), implemented today by the live pipeline nodes. District 1's former non-production Pipehead POC implementation was retired and deleted by Mission A (DSC-GOV) — an implementation retirement only, not a District retirement (D1CAP-GOV); git history preserves the former implementation | diff --git a/scripts/check_stale_refs.py b/scripts/check_stale_refs.py index cfa7965..40824ad 100755 --- a/scripts/check_stale_refs.py +++ b/scripts/check_stale_refs.py @@ -36,7 +36,7 @@ ), "reactor_scored_signals_v1": ( "Reactor-owned Mongo collection behind the removed writer; superseded by the " - "canonical afi.scored-signal-evidence.v2 evidence store (MongoDB " + "canonical afi.scored-signal-evidence.v3 evidence store (MongoDB " "'scored_signal_evidence') owned by afi-infra." ), } diff --git a/specs/AFI_ANALYST_SHOP_MVP.md b/specs/AFI_ANALYST_SHOP_MVP.md index 37e9a98..690cca8 100644 --- a/specs/AFI_ANALYST_SHOP_MVP.md +++ b/specs/AFI_ANALYST_SHOP_MVP.md @@ -42,7 +42,7 @@ flowchart TB ID[Provider onboarding\nproviderId + beneficiary] ING[Ingest\nTelegram / TV / API → USS/CPJ] RX[afi-reactor\nenrich → UWR score → qualify\n→ submit evidence] - TSSD[(afi-infra canonical store\nafi.scored-signal-evidence.v1)] + TSSD[(afi-infra canonical store\nafi.scored-signal-evidence.v3)] MINT[afi-mint → Base Sepolia] end subgraph optional["Optional — Storefront & visibility"] @@ -79,7 +79,7 @@ flowchart TB | A1 | Register as provider | `providerId`, API key, beneficiary address form | No | | A2 | Choose ingest source | Template: TradingView webhook URL, Telegram bot token, or REST | No | | A3 | Send test signal | USS/CPJ validation errors surfaced clearly | No | -| A4 | Confirm scored | Canonical scored-signal evidence record (`afi.scored-signal-evidence.v1`) persisted by afi-infra, lifecycleState=SCORED | No | +| A4 | Confirm scored | Canonical scored-signal evidence record (`afi.scored-signal-evidence.v3`) persisted by afi-infra, lifecycleState=SCORED | No | | A5 | Confirm mint (testnet) | `MintCoordinated` on Base Sepolia + stage=MINTED in TSSD record | No | **Done = shop is operational.** Analyst can mint-attributed signals on testnet. diff --git a/specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md b/specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md index e76e48f..db25b86 100644 --- a/specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md +++ b/specs/AFI_PROVIDER_BYOK_FOUNDATIONS.v0.1.md @@ -1,6 +1,6 @@ # AFI Provider Adapter and BYOK Foundations v0.1 -**Status:** v0.1 foundation record of the provider-neutral adapter socket and secure bring-your-own-key (BYOK) credential boundary. Governed by `afi-governance/decisions/provider-byok-foundations-v0.1.md` (PBF-GOV). Documents the Wave-1 foundation delivered across `afi-config`, `afi-factory`, and `afi-reactor` on the existing configurable executor and Evidence V2. The activation of this foundation as the sole live enrichment-execution seam for all five categories is recorded by `afi-governance/decisions/five-lane-provider-runtime-v0.1.md` (FLPR-GOV) and reflected in `AFI_Full_Architecture.md`; this record intentionally describes the v0.1 foundation itself. +**Status:** v0.1 foundation record of the provider-neutral adapter socket and secure bring-your-own-key (BYOK) credential boundary. Governed by `afi-governance/decisions/provider-byok-foundations-v0.1.md` (PBF-GOV). Documents the Wave-1 foundation delivered across `afi-config`, `afi-factory`, and `afi-reactor` on the existing configurable executor and the canonical evidence contract. The activation of this foundation as the sole live enrichment-execution seam for all five categories is recorded by `afi-governance/decisions/five-lane-provider-runtime-v0.1.md` (FLPR-GOV) and reflected in `AFI_Full_Architecture.md`; this record intentionally describes the v0.1 foundation itself. This foundation establishes the provider **socket** and the credential **boundary**. It does not complete all commercial provider integrations, and it deploys nothing. @@ -44,9 +44,9 @@ Every boundary fails closed. The **SecretResolver** resolves only the exact auth Secret resolution occurs only at runtime, at the adapter edge. Factory cannot resolve secrets. Adapters receive only scoped credentials. Logs, errors, traces, canonical hashes, and Evidence exclude credentials (structural closure plus a redaction boundary). Deployment-specific secret backends (for example GCP Secret Manager) are pending a later staging wave; this foundation provisions none. -## 6. Evidence V2 freeze +## 6. Evidence and invocation provenance -Evidence V2 (`afi.scored-signal-evidence.v2`) is unchanged: schema, semantics, canonical Mongo record shape, store version pin, and lifecycle status are all identical. The versioned pipeline composition may commit to a non-secret ProviderInstance reference through its existing artifact hash, but no provider credential, provider-invocation object, or new collection is persisted. Detailed provider/model **invocation provenance** is deferred to a later governed evidence decision that will determine Evidence V3 after real adapters reveal the true provenance fields. Evidence V2 does not contain provider-invocation provenance. +The canonical scored-signal evidence contract is **`afi.scored-signal-evidence.v3`** (EV3-GOV, `afi-governance/decisions/evidence-v3-provider-provenance-v0.1.md` — the governed evidence decision this foundation reserved invocation provenance to). Every V3 record carries exactly five closed, credential-safe per-lane provider invocation proofs cryptographically bound to the scored result, plus record-level `recordHash`/`replayHash` commitments. Each proof records non-secret identity facts only — Provider, ProviderInstance, adapter, and the credential binding (explicit keyless posture or an opaque CredentialRef) — with normalized invocation input/output hashes; no provider credential, raw provider payload, or secret enters evidence. The versioned pipeline composition commits to a non-secret ProviderInstance reference through its existing artifact hash. This v0.1 foundation record establishes the socket and boundary those proofs describe. ## 7. Scoring, UWR, Tiny Brains diff --git a/specs/AFI_RESEARCH_INSTITUTE_REFERENCE_SERVICES.v0.1.md b/specs/AFI_RESEARCH_INSTITUTE_REFERENCE_SERVICES.v0.1.md index 02af2f7..b108c28 100644 --- a/specs/AFI_RESEARCH_INSTITUTE_REFERENCE_SERVICES.v0.1.md +++ b/specs/AFI_RESEARCH_INSTITUTE_REFERENCE_SERVICES.v0.1.md @@ -231,7 +231,7 @@ content is not automatically written on-chain and is not automatically published The Institute is an operator, researcher, publisher, and service provider — not a protocol authority. Governance, config, and math retain their authority; the Gateway -remains routes-not-writes; the Reactor constructs Evidence V2 and does not become a +remains routes-not-writes; the Reactor constructs Evidence V3 and does not become a general external trust gateway; `afi-infra` remains the sole canonical writer; `afi-factory` authors pipeline artifacts and is not the ingress operator. The Institute being the MIT copyright holder of record across the organization's licenses is an diff --git a/specs/AFI_REWARDS_VAULT_AND_CLAIMS.md b/specs/AFI_REWARDS_VAULT_AND_CLAIMS.md index 8e13a3f..4371b00 100644 --- a/specs/AFI_REWARDS_VAULT_AND_CLAIMS.md +++ b/specs/AFI_REWARDS_VAULT_AND_CLAIMS.md @@ -40,7 +40,7 @@ The word "vault" is overloaded in the AFI codebase and recon. This spec is bound | Object | Custodies | Layer / role | Defined by | Reward authority? | |--------|-----------|--------------|------------|-------------------| | **RewardsVault** | **Reward tokens** (the per-epoch reward budget) | Layer 4 — this document | this spec | Pays **only** against committed `claimRoot`; **never mints**, **never decides** | -| **Canonical evidence store** (`afi.scored-signal-evidence.v2`, carrying a composition reference per afi-governance `decisions/factory-configurable-pipelines-v1.md`; `VaultedSignalRecord`) | **Data** (scored-signal evidence and lifecycle records) | Layer 1 support; off-chain (MongoDB) | doctrine §7; `afi-infra/src/evidence/*`, `afi-infra/src/tssd/*` | **None.** Holds zero tokens. Unchanged by Settlement v1. | +| **Canonical evidence store** (`afi.scored-signal-evidence.v3`, carrying a composition reference per afi-governance `decisions/factory-configurable-pipelines-v1.md` and per-lane provider invocation proofs per `decisions/evidence-v3-provider-provenance-v0.1.md`; `VaultedSignalRecord`) | **Data** (scored-signal evidence and lifecycle records) | Layer 1 support; off-chain (MongoDB) | doctrine §7; `afi-infra/src/evidence/*`, `afi-infra/src/tssd/*` | **None.** Holds zero tokens. Unchanged by Settlement v1. | | **xERC20 bridge lockbox** (`XERC20Lockbox`) | **Canonical AFI for bridging** (mint/burn xAFI, rate-limited) | Token posture (doctrine §10) | doctrine §10; `afi-xerc20/.../XERC20Lockbox.sol` | **None for rewards.** Bridge custody only. | **Naming MUST rules:**