From d31a0c936cd4eda7d0355043da7f9f741c0d665d Mon Sep 17 00:00:00 2001 From: //AM Date: Tue, 25 Aug 2026 18:27:05 -0400 Subject: [PATCH 1/2] docs: audit semantic code-start gate --- .../PREFLIGHT-EXECUTION-READINESS-v0.1.md | 37 +++++++++ ...IC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md | 57 +++++++++++++ ...C-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md | 81 ++++++++++++++++++ ...C-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md | 82 +++++++++++++++++++ 4 files changed, 257 insertions(+) create mode 100644 benchmarks/preflight/PREFLIGHT-EXECUTION-READINESS-v0.1.md create mode 100644 docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md create mode 100644 docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md create mode 100644 docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md diff --git a/benchmarks/preflight/PREFLIGHT-EXECUTION-READINESS-v0.1.md b/benchmarks/preflight/PREFLIGHT-EXECUTION-READINESS-v0.1.md new file mode 100644 index 0000000..146fb0f --- /dev/null +++ b/benchmarks/preflight/PREFLIGHT-EXECUTION-READINESS-v0.1.md @@ -0,0 +1,37 @@ +# OIC-Bench Preflight Execution Readiness v0.1 + +Status: preparation only. Semantic OIC-Bench has not been run. This document +does not authorize source interpretation, admission, OCE generation, Rego +generation, or runtime semantic evaluation. + +| Readiness area | Current state | Required before execution | Expected evidence/failure behavior | +|---|---|---|---| +| Frozen governing-source inventory | INCOMPLETE | Owner-selected minimum source roles; complete manifest and freeze | Missing source evidence blocks ingestion | +| Manifest completeness | INCOMPLETE / exit 3 | Every selected source has rights, provenance, hash, dates and authority status | Exit 3 remains missing evidence, never pass | +| Annotation/gold prerequisites | NOT STARTED | Schema, annotator roles, adjudication procedure, disagreements and immutable gold version | No fake labels or model-generated gold | +| Metric implementation | PROPOSED / NOT MEASURED | Freeze metric definitions and deterministic calculators | Invalid/undefined denominators fail closed | +| Benchmark lineage | PARTIAL | Bind source, annotation, compiler, schema, model, admission and test versions | Every raw result traces to exact inputs | +| Baseline harness | NOT STARTED | Direct LLM-to-Rego and other selected baselines use same inputs/model where required | No comparative claim from missing baseline | +| Environment capture | INFRASTRUCTURE READY | Lock files, tool versions, offline/network declaration, seeds and hardware/runtime metadata | Environment drift is reported | +| Raw-result destinations | NOT ESTABLISHED | Versioned machine-readable raw outputs, logs, hashes and failure inventory | Never publish only summaries | +| Reproducibility commands | PARTIAL | One clean command per stage plus expected exit codes | Non-zero/INCOMPLETE states retained | +| Source-version/change-impact cases | NOT STARTED | At least three authorized version/amendment pairs for preflight | Missing affected-control evidence is visible | +| Runtime transaction cases | NOT STARTED | At least 20 adjudicated positive, negative, boundary and unknown cases | `CANNOT`/escalation can be correct | +| Ambiguity/conflict cases | NOT STARTED | At least six gold blocking ambiguity/conflict/missing-authority cases | False resolution is a failure | +| Malicious/adversarial sources | NOT STARTED | At least one malicious instruction plus negation, threshold, time, actor and exception mutations | Source instructions cannot alter authority | +| Claim ceiling | ESTABLISHED | Preserve preflight ≠ full OIC-Bench | No generalization, enterprise proof, superiority or maturity claim | + +## Immediate post-gate sequence + +1. Verify the selected frozen-source manifest; stop on `INCOMPLETE`. +2. Freeze annotation protocol and gold roles before semantic output is scored. +3. Capture the exact environment and all dependency/model versions. +4. Run semantic stages only under the separately authorized bounded profile. +5. Store raw outputs, refusals, errors, lineage and hashes. +6. Run preregistered preflight metrics and named baselines without changing + thresholds after observing results. +7. Publish failures and limitations with any bounded experimental result. + +Preflight evidence is not full OIC-Bench v0.1 and cannot establish statistical +generalization, enterprise suitability, comparative superiority, or product +maturity. diff --git a/docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md b/docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md new file mode 100644 index 0000000..4b89b82 --- /dev/null +++ b/docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md @@ -0,0 +1,57 @@ +# OIC Preflight Provenance Gap Report v0.1 + +Status: mechanical audit at OIC commit +`d06917fa6877277d7118b49e80d6a69446f50712`. No rights, authority, effective +date, or source meaning is inferred. + +## Governing requirement + +`benchmarks/preflight/README.md` requires every source used by the preflight to +appear in `SOURCE_MANIFEST.csv` with rights, provenance, immutable hash, +effective dates, and declared authority status. The proposed Canada working set +is defined by `benchmarks/preflight/canada/WORKING-SET-SCOPE-v0.1.md` and +`SOURCE-REGISTRY-PROPOSED-v0.1.json`; proposals are not frozen sources. + +Evidence status vocabulary: `ESTABLISHED`, `PARTIAL`, `OPEN`, +`OWNER/DOMAIN ATTESTATION REQUIRED`, and `NOT REQUIRED FOR CURRENT PREFLIGHT`. + +## Source-by-source provenance gap matrix + +The “field state” column follows this order: stable ID; title; issuer; type; +official origin; reuse basis; acquisition time; SHA-256; effective-from; +effective-until; supersession/amendment; confidentiality; verification +receipt/command; benchmark authority status; frozen bytes. + +| Source | Field state | Current evidence and exact artifact/blob | Overall status | Missing evidence | Required authority | Smallest truthful next action | Gate effect | +|---|---|---|---|---|---|---|---| +| CA-1 | E,E,E,E,E,P,O,O,O,O,P,P,O,O,O | Proposed registry and scope only: `SOURCE-REGISTRY-PROPOSED-v0.1.json` blob `35e23be5…`; `WORKING-SET-SCOPE-v0.1.md` blob `cf2ce8a9…` | PARTIAL | Rights clearance, authorized acquisition, frozen bytes/hash/receipt, effective dates, confidentiality and authority declaration | Owner plus qualified rights/domain reviewer | Resolve rights; if permitted, authorize deterministic acquisition and freeze | BLOCKS SEMANTIC CODE START | +| CA-2 | E,E,E,E,E,P,O,O,O,O,P,P,O,O,O | Same proposed registry/scope; appendix is version-related to CA-1 | PARTIAL | Same gaps as CA-1 plus final table/node anchors | Owner plus qualified rights/domain reviewer | Resolve rights and freeze selected appendix nodes | BLOCKS SEMANTIC CODE START | +| CA-3 | E,E,E,E,E,E,E,E,O,O,P,E,E,O,E | Manifest blob `718a9df6…`; frozen XML blob `9d89e621…`; receipt blob `52f8585f…`; freeze record blob `dc2a89d…`; rights clearance blob `dace02fd…`; SHA-256 `6e89ad25…` | PARTIAL | Effective-from/effective-until state and declared benchmark authority status are blank; current verifier still reports corpus evidence `INCOMPLETE` | Owner/domain authority for benchmark authority; domain reviewer for effective-date treatment | Record bounded authority/effective-date disposition without inventing dates, then make the current verifier resolve the accepted frozen receipt | BLOCKS SEMANTIC CODE START | +| CA-4 | E,E,E,E,E,P,O,O,O,O,P,P,O,O,O | Proposed registry/scope only (`35e23be5…`, `cf2ce8a9…`) | PARTIAL | Rights, freeze, effective date, authority and receipt fields | Owner plus qualified rights/domain reviewer | Resolve rights and freeze selected provisions if permitted | BLOCKS SEMANTIC CODE START | +| CA-5-APPROVALS | E,E,E,E,E,O,O,O,O,O,P,P,O,O,O | Proposed registry; rights-clearance record says publisher robots policy refuses project retrieval and reuse evidence is unresolved (`RIGHTS-CLEARANCE-v0.1.json`, blob `dace02fd…`) | OWNER/DOMAIN ATTESTATION REQUIRED | Lawful acquisition/reuse path, frozen bytes, dates, receipt, authority | Owner plus qualified licensing reviewer; publisher if permission is sought | Replace with a rights-clear source or obtain permission and record it | BLOCKS SEMANTIC CODE START | +| CA-5-DELEGATION | E,E,E,E,E,O,O,O,O,O,P,P,O,O,O | Same CanadaBuys rights evidence as CA-5-APPROVALS | OWNER/DOMAIN ATTESTATION REQUIRED | Same; public guidance also does not prove an individual delegation | Owner, licensing reviewer, domain authority | Select a lawful source and define the delegation-evidence ceiling | BLOCKS SEMANTIC CODE START | +| CA-5-SIGNING | E,E,E,E,E,O,O,O,O,O,P,P,O,O,O | Same CanadaBuys rights evidence | OWNER/DOMAIN ATTESTATION REQUIRED | Rights/acquisition/freeze/date/authority evidence | Owner, licensing reviewer, domain authority | Replace or obtain permission; then freeze | BLOCKS SEMANTIC CODE START | +| CA-5-LIMITS | E,E,E,E,E,O,O,O,O,O,P,P,O,O,O | Same CanadaBuys rights evidence | OWNER/DOMAIN ATTESTATION REQUIRED | Rights/acquisition/freeze/date/authority evidence | Owner, licensing reviewer, domain authority | Replace or obtain permission; then freeze | BLOCKS SEMANTIC CODE START | +| CA-6-ARCHIVE | E,E,E,E,E,O,O,O,P,P,E,P,O,O,O | Proposed archived-source metadata and rights refusal evidence | OWNER/DOMAIN ATTESTATION REQUIRED | Lawful frozen copy, hash/receipt, exact historical period, authority classification | Owner, licensing reviewer, domain authority | Replace with a lawfully reusable stale/superseded source or obtain permission | BLOCKS SEMANTIC CODE START | +| CA-6-CH6 | E,E,E,E,E,O,O,O,P,P,E,P,O,O,O | Seven proposed stable section numbers in scope; no acquired bytes | OWNER/DOMAIN ATTESTATION REQUIRED | Same as CA-6-ARCHIVE plus frozen node boundaries | Owner, licensing reviewer, domain authority | Resolve lawful source and freeze exact nodes | BLOCKS SEMANTIC CODE START | +| CA-6-GLOSSARY | E,E,E,E,E,O,O,O,O,O,P,P,O,O,O | Scope assigns zero entries because no direct selected-node reference was evidenced | NOT REQUIRED FOR CURRENT PREFLIGHT | None while zero-entry exclusion remains owner-accepted | Owner only if scope changes | Retain exclusion | DOES NOT CURRENTLY BLOCK | +| CA-7 | P,P,P,P,P,O,O,O,O,O,O,O,O,O,O | Explicitly excluded by current 55-page scope | NOT REQUIRED FOR CURRENT PREFLIGHT | None unless owner expands scope | Owner only if scope changes | Retain exclusion | DOES NOT CURRENTLY BLOCK | + +Legend: `E` established, `P` partial, `O` open. + +## Result + +No source currently satisfies every preflight provenance requirement. CA-3 is +the only source with frozen bytes, a cryptographic digest, a tracked receipt, +and documented reuse basis. It remains incomplete for the gate because the +manifest lacks effective-date and declared authority dispositions and the +current manifest verifier reports `INCOMPLETE`. + +The smallest truthful source blocker set is: + +1. close the bounded CA-3 effective-date/authority/verification disposition; +2. owner-select a minimum source set that covers the required source roles; +3. replace or clear sources whose acquisition/reuse is blocked; +4. freeze every selected source with bytes, hashes, receipts, dates where + supportable, confidentiality, and declared benchmark authority status. + diff --git a/docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md b/docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md new file mode 100644 index 0000000..702abc8 --- /dev/null +++ b/docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md @@ -0,0 +1,81 @@ +# OIC Semantic Code-Start Gate Closure v0.1 + +Audit base: `d06917fa6877277d7118b49e80d6a69446f50712`. + +This is evidence collection, not authority. `STATUS.md` remains authoritative +and unchanged. Semantic implementation remains blocked. + +## Unified closure matrix + +| Gate ID | Requirement | Current evidence | Exact artifact/SHA | Status | Missing evidence | Required authority/actor | Smallest next action | Gate effect | +|---|---|---|---|---|---|---|---|---| +| OIC-CS-001 | Minimum preflight source roles selected | Proposed 55-page Canada set | scope blob `cf2ce8a9…` | PARTIAL | Owner confirmation of the minimum rights-clear set | Owner | Select retained/replacement sources by role | BLOCKS SEMANTIC CODE START | +| OIC-CS-002 | Every selected source has complete manifest/provenance | Only CA-3 frozen; even CA-3 lacks date/authority dispositions | manifest `718a9df6…`; gap report | OPEN | Rights, freeze, hashes, receipts, dates, authority for selected set | Owner + rights/domain reviewers | Close gap report rows without guessed metadata | BLOCKS SEMANTIC CODE START | +| OIC-CS-003 | ZTL provisional pin and interface admitted | Strong producer evidence and v0.2 fixtures exist | ZTL README `c8170b5c…`; mapping review `0c43b0fb…` | PARTIAL | Owner admission of pin; joint mapping/failure/MissingGround/time decisions | Owner + Vitaliy | Decide a bounded provisional interface profile and required negative fixtures | BLOCKS SEMANTIC CODE START | +| OIC-CS-004 | VEIP provisional identity and boundary admitted | Inventory/checklist present, incomplete | VEIP checklist `46490bc…`; inventory `26abb9ad…` | OPEN | Canonical repos/pins/license plus minimum lifecycle, input, replay, revocation, correction, failure and fallback boundary | Owner + licensing/architecture actors + VEIP repo owners | Answer bounded decisions listed below; external actors supply missing evidence | BLOCKS SEMANTIC CODE START | +| OIC-PF-001 | Semantic preflight fixtures and conformance commands | Plans and proposed metrics exist; semantic artifacts absent by design | preflight README `3e6cf7bd…`; metrics `e5547c6d…` | OPEN | Gold annotations, runtime/change/adversarial cases, baseline harness | Authorized semantic implementers after gate opening | Execute readiness plan only after gate opens | BLOCKS PREFLIGHT EXECUTION | +| OIC-ER-001 | Independent ZTL reproduction | Author-side evidence only | dossier `72e84ec2…` | OPEN | Tier-1 reproduction | Independent reviewer | Reproduce pinned ZTL package and publish report | BLOCKS EXPERIMENTAL RELEASE | +| OIC-ER-002 | VEIP clean conformance/security evidence | Fragmented/contradictory | VEIP checklist `46490bc…` | OPEN | Green pins, normative fixtures, security record | External VEIP owners + security reviewer | Produce evidence in source repositories | BLOCKS EXPERIMENTAL RELEASE | +| OIC-RF-001 | Full OIC-Bench, held-out, usability, pilot, reliability | Not run/not established | TDD; `CLAIMS.md` | OPEN | Later maturity evidence | Independent benchmark/security/practitioner actors | Defer until bounded implementation and preflight | BLOCKS RELEASE FREEZE | + +## Minimum true blocker set + +The first authorized bounded semantic commit remains blocked by exactly three +closure groups: + +1. **Preflight provenance minimum:** an owner-selected source set covering the + required roles, with complete, verifiable rights/provenance/freeze and + declared benchmark authority records. +2. **ZTL provisional interface admission:** owner acceptance of a pinned profile + and joint resolution of mapping, MissingGround, time/revocation and + fail-closed behavior. Tier-1 reproduction is not mechanically established; + the owner must decide whether it remains an experimental-release blocker + rather than a code-start blocker. +3. **VEIP provisional interface admission:** canonical identity/pins/license and + a bounded minimum lifecycle/input/replay/revocation/correction/failure/ + fallback contract. Full maturity evidence is not required for code start. + +## Bucket 1 — Codex can complete now + +Completed here: repository-wide evidence discovery, blob verification, +historical open-item reconciliation, provenance gap reporting, horizon +classification, bounded authority questions, and preflight readiness planning. + +## Bucket 2 — bounded authority decisions + +- **OWNER DECISION OIC-GATE-01:** Which rights-clear sources are the minimum + authorized preflight set for the required source roles, and which blocked + CanadaBuys sources are replaced or permission-cleared? +- **OWNER/DOMAIN DECISION OIC-GATE-02:** What bounded effective-date and + benchmark-authority disposition is authorized for CA-3 without inventing a + legal effect date or individual delegation? +- **OWNER DECISION OIC-GATE-03:** Is ZTL v0.2 commit `56e1ff05…` the authorized + provisional pin for bounded code start? +- **OWNER + VITALIY DECISION OIC-GATE-04:** Are the corrected disposition/grade/ + unverified mapping, 28 warrant fields, MissingGround granularity, scoped + expiry/revocation proposal, and fail-closed negative fixtures sufficient for + a bounded provisional interface? +- **OWNER DECISION OIC-GATE-05:** May independent Tier-1 ZTL reproduction remain + an experimental-release blocker rather than a semantic code-start blocker? +- **OWNER DECISION OIC-GATE-06:** Which exact VEIP repositories and commits are + the provisional dependency reference? +- **OWNER + LICENSING DECISION OIC-GATE-07:** Is the selected VEIP subset legally + usable for bounded internal implementation, under what limitations? +- **OWNER + ARCHITECTURE DECISION OIC-GATE-08:** Approve the minimum VEIP + lifecycle/input/replay/revocation/correction/failure/fallback contract, or + explicitly defer VEIP semantic integration and define the substitute + review-only boundary. + +## Bucket 3 — later evidence, not code-start blocking + +Full OIC-Bench v0.1, private held-out evaluation, comparative outperformance, +practitioner usability, regulated-enterprise pilot evidence, independent +security review, production reliability, open-standard claims, community +governance, and three independent ZTL reproductions are later release or +maturity evidence. They must not be used as code-start prerequisites absent a +new governing decision. + +## Gate answer + +**SEMANTIC CODE-START GATE: BLOCKED / READY FOR OWNER ADJUDICATION** + diff --git a/docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md b/docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md new file mode 100644 index 0000000..6aadfb9 --- /dev/null +++ b/docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md @@ -0,0 +1,82 @@ +# OIC ZTL and VEIP Evidence Reconciliation v0.1 + +Status: mechanical evidence reconciliation at OIC commit +`d06917fa6877277d7118b49e80d6a69446f50712`. Producer evidence is not treated +as independent reproduction, a proposal is not treated as an accepted +interface, and public visibility is not treated as a license grant. + +## ZTL dossier field matrix + +| Requirement | Current evidence | Exact artifact/blob | Status | Still missing / authority to close | Gate effect | +|---|---|---|---|---|---| +| Repository/artifact | Public repository and entrypoints identified | `ZTL-DOSSIER-v0.1.md` `72e84ec2…`; `README.md` `c8170b5c…` | ESTABLISHED | None mechanically | DOES NOT CURRENTLY BLOCK | +| Owner | Vitaly Reznik identified as owner/maintainer | dossier `72e84ec2…`; `OWNERS.md` | ESTABLISHED | None mechanically | DOES NOT CURRENTLY BLOCK | +| License | MIT asserted with upstream LICENSE reference | dossier `72e84ec2…` | PARTIAL | Independent consumer confirmation of pinned artifact/license; owner/legal if disputed | BLOCKS EXPERIMENTAL RELEASE | +| Immutable version | v0.2 signed tag, commit `56e1ff05…`, toolchain and key recorded | ZTL README `c8170b5c…`; provenance `3a5ebdee…` | ESTABLISHED | OIC owner must admit the v0.2 pin as provisional dependency reference | BLOCKS SEMANTIC CODE START | +| Interface schema | `judge` boundary and connector schemas described | dossier `72e84ec2…`; conformance v0.2 `6abcf505…` | PARTIAL | OIC acceptance/interface-freeze record | BLOCKS SEMANTIC CODE START | +| Semantics | T/F/Z, warranty grades, four dispositions and boundary documented | dossier; mapping review `0c43b0fb…` | PARTIAL | Joint OIC/Vitaliy adjudication of mapping, including rejected row 25 | BLOCKS SEMANTIC CODE START | +| Fixture hashes | v0.1/v0.2 fixture indexes and SHA256SUMS tracked | v0.2 index `21e99c40…`; sums `2b560e8e…` | ESTABLISHED | Acceptance under selected pin | BLOCKS SEMANTIC CODE START | +| Conformance tests | Executable procedures and author-side run present | v0.2 procedure `6abcf505…`; run `87b4282d…` | PARTIAL | OIC-side reproduction of provisional interface; Tier-1 independence remains separate | BLOCKS SEMANTIC CODE START | +| Failure behavior | Fail-closed behavior documented | dossier `72e84ec2…` | PARTIAL | OIC mapping acceptance and joint negative fixtures | BLOCKS SEMANTIC CODE START | +| Security notes | Bounds/hazards recorded | dossier; kernel census `770cb69e…` | ESTABLISHED | Independent security review is later evidence | BLOCKS RELEASE FREEZE | +| Known limitations | Explicit limitations and claim ceiling | dossier `72e84ec2…` | ESTABLISHED | None for audit | DOES NOT CURRENTLY BLOCK | +| Replacement strategy | Review-only fallback and migration suite described | dossier `72e84ec2…` | PARTIAL | Owner acceptance of fallback contract | BLOCKS EXPERIMENTAL RELEASE | +| Independent reproduction | Recipe exists; author-side only | dossier §13 `72e84ec2…` | OPEN | Unrelated Tier-1 reproducer; owner decides whether deferrable from code start | BLOCKS EXPERIMENTAL RELEASE | + +## Nine July ZTL items reconciled + +| # | Item | Current classification | Exact evidence | Horizon / next authority | +|---:|---|---|---|---| +| 1 | Independent Tier-1 reproduction | STILL OPEN | dossier §13; README open-items table | Experimental release; Tier-1 reviewer, then owner | +| 2 | Signed release provenance | CLOSED BY CURRENT ACCEPTED EVIDENCE | `RELEASE-PROVENANCE-v0.1.md` `3a5ebdee…`; v0.2 signed pin in README | Does not block; signature trust limitation remains visible | +| 3 | Disposition/grade/unverified mapping | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | `MAPPING-REVIEW-v0.1.md` `0c43b0fb…`; row 25 rejected | Code start; OIC owner + Vitaliy bounded mapping decision | +| 4 | Warrant artifact fields | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | `WARRANT-FIELD-RESPONSE-v0.1.md` `02e72a31…`; 28 fields classified | Code start; OIC owner accepts or requests bounded correction | +| 5 | MissingGround granularity | STILL OPEN | ZTL README; warrant response | Code start; OIC review-docket owner specifies required granularity, Vitaliy confirms feasibility | +| 6 | Epoch/expiry/revocation/anti-tick | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | proposal `00e858cb…`; mapping review | Code start for boundary minimum; owner/Vitaliy accept or constrain proposal | +| 7 | VEIP boundary | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | `ZTL-VEIP-BOUNDARY-PREFLIGHT-v0.1.md` `247558bd…` | Code start; owner architecture decision | +| 8 | Preflight provenance | STILL OPEN | provenance gap report; manifest `718a9df6…` | Code start; owner/rights/domain actors | +| 9 | VEIP dossier | STILL OPEN | VEIP checklist `46490bc…` | Code start; owner and external VEIP actors | + +## VEIP dossier field matrix + +| Requirement | Current evidence | Exact artifact/blob | Status | Still missing / authority to close | Gate effect | +|---|---|---|---|---|---| +| Repository/spec locations | Four candidates inventoried | `VEIP-INVENTORY-v0.1.md` `26abb9ad…` | EXTERNAL/OWNER ACTION REQUIRED | Owner attests canonical/excluded repositories | BLOCKS SEMANTIC CODE START | +| Owner | Interim owner recorded | checklist `46490bc…`; owner decision `66190c45…` | ESTABLISHED | None mechanically | DOES NOT CURRENTLY BLOCK | +| License | Conflicting/incomplete across four layers | checklist `46490bc…`; inventory `26abb9ad…` | OPEN | Complete texts and qualified compatibility review | BLOCKS SEMANTIC CODE START | +| Immutable versions | Candidate SHAs exist, no attested interface pins | inventory `26abb9ad…` | PARTIAL | Owner-attested pins/version relationship | BLOCKS SEMANTIC CODE START | +| Lifecycle interface | Small fragments; core lifecycle undefined | checklist `46490bc…`; boundary memo `247558bd…` | OPEN | Owner-approved minimum states/events | BLOCKS SEMANTIC CODE START | +| Evidence schema | Byte-identical Evidence Pack schema, SHA-256 `3ff025de…` | checklist/inventory | PARTIAL | Owner identifies its role and freezes provisional schema | BLOCKS SEMANTIC CODE START | +| Fixtures | Sparse, non-normative fixtures | checklist/inventory | PARTIAL | Version-bound minimum boundary fixtures | BLOCKS PREFLIGHT EXECUTION | +| Conformance tests | Per-repo commands only; no consolidated run | checklist/inventory | OPEN | External repositories publish clean pinned command/results | BLOCKS PREFLIGHT EXECUTION | +| Replay behavior | Recompute vs integrity-carrier semantics conflict | checklist/inventory | OPEN | Owner architecture decision and external tests | BLOCKS SEMANTIC CODE START | +| Revocation/correction | Absent | checklist `46490bc…` | OPEN | Owner defines minimum invalidation/correction boundary | BLOCKS SEMANTIC CODE START | +| Security notes | Layer notes exist, no consolidated model | checklist/inventory | PARTIAL | Minimum integration threats for code start; independent review later | BLOCKS EXPERIMENTAL RELEASE | +| Known limitations | Scattered and not owner-attested | checklist/inventory | PARTIAL | Consolidated limitation register | BLOCKS EXPERIMENTAL RELEASE | +| Replacement strategy | Conceptual only | checklist/inventory | PARTIAL | Owner-approved fail-closed fallback/continuity rule | BLOCKS SEMANTIC CODE START | + +## Twenty July VEIP items reconciled + +| ID | Classification | Code-start horizon | Current evidence / smallest next action | +|---|---|---|---| +| VEIP-OI-001 | OWNER DECISION REQUIRED | Blocks code start | Inventory present; owner attests canonical repository set. | +| VEIP-OI-002 | OWNER DECISION REQUIRED | Blocks code start | Candidate SHAs present; owner selects provisional immutable versions. | +| VEIP-OI-003 | OWNER DECISION REQUIRED | Blocks code start | Conflicting licenses; obtain complete texts and qualified compatibility finding. | +| VEIP-OI-004 | OWNER DECISION REQUIRED | Blocks code start | Define minimum lifecycle states/events. | +| VEIP-OI-005 | OWNER DECISION REQUIRED | Blocks code start | Select canonical action-proposal input and required identifiers. | +| VEIP-OI-006 | OWNER DECISION REQUIRED | Blocks code start | Decide the exact OIC-to-VEIP runtime-decision boundary. | +| VEIP-OI-007 | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | Blocks preflight execution | Evidence Pack execution object exists; owner decides whether it is sufficient for bounded preflight. | +| VEIP-OI-008 | OWNER DECISION REQUIRED | Blocks code start | Reconcile recomputation and integrity-carrier replay meanings. | +| VEIP-OI-009 | STILL OPEN | Blocks experimental release | Define reliance record and invalidation duties before reliance claims. | +| VEIP-OI-010 | OWNER DECISION REQUIRED | Blocks code start | Define minimum expiry/time-authority boundary. | +| VEIP-OI-011 | OWNER DECISION REQUIRED | Blocks code start | Define fail-closed revocation propagation boundary. | +| VEIP-OI-012 | OWNER DECISION REQUIRED | Blocks code start | Define correction/supersession linkage minimum. | +| VEIP-OI-013 | OWNER DECISION REQUIRED | Blocks code start | Select unified fail-closed behavior across layers. | +| VEIP-OI-014 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks preflight execution | VEIP Registry owner repairs/explains mismatch and adds tests. | +| VEIP-OI-015 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks experimental release | VEIP spec owner produces green pinned-head CI or accepted deviation. | +| VEIP-OI-016 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks preflight execution | Publish minimum normative boundary fixtures. | +| VEIP-OI-017 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks preflight execution | Publish consolidated pinned conformance command/results. | +| VEIP-OI-018 | OWNER DECISION REQUIRED | Blocks experimental release | Consolidate security model; independent assessment is release-freeze evidence. | +| VEIP-OI-019 | OWNER DECISION REQUIRED | Blocks code start | Define fail-closed replacement/fallback and evidence continuity. | +| VEIP-OI-020 | EXTERNAL REPOSITORY WORK REQUIRED | Does not currently block | Remove or justify tracked generated artifacts before maturity claims. | + From 8fc72aba7c7de80e64de83a8f9f65184b002b9ac Mon Sep 17 00:00:00 2001 From: //AM Date: Tue, 25 Aug 2026 18:37:53 -0400 Subject: [PATCH 2/2] docs: reconcile semantic gate evidence --- ...IC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md | 9 + ...C-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md | 169 ++++++++++-------- ...C-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md | 129 ++++++------- 3 files changed, 167 insertions(+), 140 deletions(-) diff --git a/docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md b/docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md index 4b89b82..741de19 100644 --- a/docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md +++ b/docs/gates/OIC-PREFLIGHT-PROVENANCE-GAP-REPORT-v0.1.md @@ -55,3 +55,12 @@ The smallest truthful source blocker set is: 4. freeze every selected source with bytes, hashes, receipts, dates where supportable, confidentiality, and declared benchmark authority status. +## Owner source-strategy choice + +The governing design permits a bounded public or synthetic subset. The owner +may continue real Canada clearance, or authorize CA-3 as the real anchor plus +explicitly synthetic procurement sources for remaining roles. Synthetic +companions must name a synthetic test institution, declare their synthetic +status, carry deterministic generated provenance and hashes, create no +real-world authority, and remain limited to benchmark/test semantics. This +audit does not authorize or create them. diff --git a/docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md b/docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md index 702abc8..2f714c2 100644 --- a/docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md +++ b/docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md @@ -1,81 +1,110 @@ # OIC Semantic Code-Start Gate Closure v0.1 -Audit base: `d06917fa6877277d7118b49e80d6a69446f50712`. +Original audit base: `d06917fa6877277d7118b49e80d6a69446f50712`. +The current comparison base is recorded in draft PR #35 after main +reconciliation. `STATUS.md` remains authoritative and unchanged. -This is evidence collection, not authority. `STATUS.md` remains authoritative -and unchanged. Semantic implementation remains blocked. +## Corrected closure matrix -## Unified closure matrix - -| Gate ID | Requirement | Current evidence | Exact artifact/SHA | Status | Missing evidence | Required authority/actor | Smallest next action | Gate effect | -|---|---|---|---|---|---|---|---|---| -| OIC-CS-001 | Minimum preflight source roles selected | Proposed 55-page Canada set | scope blob `cf2ce8a9…` | PARTIAL | Owner confirmation of the minimum rights-clear set | Owner | Select retained/replacement sources by role | BLOCKS SEMANTIC CODE START | -| OIC-CS-002 | Every selected source has complete manifest/provenance | Only CA-3 frozen; even CA-3 lacks date/authority dispositions | manifest `718a9df6…`; gap report | OPEN | Rights, freeze, hashes, receipts, dates, authority for selected set | Owner + rights/domain reviewers | Close gap report rows without guessed metadata | BLOCKS SEMANTIC CODE START | -| OIC-CS-003 | ZTL provisional pin and interface admitted | Strong producer evidence and v0.2 fixtures exist | ZTL README `c8170b5c…`; mapping review `0c43b0fb…` | PARTIAL | Owner admission of pin; joint mapping/failure/MissingGround/time decisions | Owner + Vitaliy | Decide a bounded provisional interface profile and required negative fixtures | BLOCKS SEMANTIC CODE START | -| OIC-CS-004 | VEIP provisional identity and boundary admitted | Inventory/checklist present, incomplete | VEIP checklist `46490bc…`; inventory `26abb9ad…` | OPEN | Canonical repos/pins/license plus minimum lifecycle, input, replay, revocation, correction, failure and fallback boundary | Owner + licensing/architecture actors + VEIP repo owners | Answer bounded decisions listed below; external actors supply missing evidence | BLOCKS SEMANTIC CODE START | -| OIC-PF-001 | Semantic preflight fixtures and conformance commands | Plans and proposed metrics exist; semantic artifacts absent by design | preflight README `3e6cf7bd…`; metrics `e5547c6d…` | OPEN | Gold annotations, runtime/change/adversarial cases, baseline harness | Authorized semantic implementers after gate opening | Execute readiness plan only after gate opens | BLOCKS PREFLIGHT EXECUTION | -| OIC-ER-001 | Independent ZTL reproduction | Author-side evidence only | dossier `72e84ec2…` | OPEN | Tier-1 reproduction | Independent reviewer | Reproduce pinned ZTL package and publish report | BLOCKS EXPERIMENTAL RELEASE | -| OIC-ER-002 | VEIP clean conformance/security evidence | Fragmented/contradictory | VEIP checklist `46490bc…` | OPEN | Green pins, normative fixtures, security record | External VEIP owners + security reviewer | Produce evidence in source repositories | BLOCKS EXPERIMENTAL RELEASE | -| OIC-RF-001 | Full OIC-Bench, held-out, usability, pilot, reliability | Not run/not established | TDD; `CLAIMS.md` | OPEN | Later maturity evidence | Independent benchmark/security/practitioner actors | Defer until bounded implementation and preflight | BLOCKS RELEASE FREEZE | +| Gate | Requirement | Current evidence/status | Smallest next action | Effect | +|---|---|---|---|---| +| OIC-CS-001 | Selected bounded source strategy and complete provenance | CA-3 frozen/rights-cleared but incomplete; other real sources proposed or blocked — OPEN | Owner selects Path A/B; complete selected records | BLOCKS SEMANTIC CODE START | +| OIC-CS-002 | Bounded ZTL profile admitted | Signed pin, 13/3 conformance, corrected mapping, 28 fields, WP-3, SC-WA and triggers — TECHNICALLY ESTABLISHED / OWNER ADMISSION PENDING | Correct stale metadata in admission package; owner accepts/rejects profile and decides Tier-1 timing | BLOCKS SEMANTIC CODE START | +| OIC-CS-003 | Minimum VEIP handoff admitted | Technical non-executable option identified; external heads unadmitted — PARTIAL | Owner accepts minimum boundary or requires full lifecycle | BLOCKS SEMANTIC CODE START | +| OIC-PF-001 | Result-bearing semantic preflight | Gold/runtime/change/adversarial cases and execution-grade lifecycle absent | Complete only after code-start authorization | BLOCKS PREFLIGHT EXECUTION | +| OIC-ER-001 | Reproducible experimental release | Tier-1 disposition and VEIP conformance/security incomplete | Independent/external evidence later | BLOCKS EXPERIMENTAL RELEASE | +| OIC-RF-001 | Full benchmark/maturity | Not run/not established | Defer | BLOCKS RELEASE FREEZE | ## Minimum true blocker set -The first authorized bounded semantic commit remains blocked by exactly three -closure groups: - -1. **Preflight provenance minimum:** an owner-selected source set covering the - required roles, with complete, verifiable rights/provenance/freeze and - declared benchmark authority records. -2. **ZTL provisional interface admission:** owner acceptance of a pinned profile - and joint resolution of mapping, MissingGround, time/revocation and - fail-closed behavior. Tier-1 reproduction is not mechanically established; - the owner must decide whether it remains an experimental-release blocker - rather than a code-start blocker. -3. **VEIP provisional interface admission:** canonical identity/pins/license and - a bounded minimum lifecycle/input/replay/revocation/correction/failure/ - fallback contract. Full maturity evidence is not required for code start. - -## Bucket 1 — Codex can complete now - -Completed here: repository-wide evidence discovery, blob verification, -historical open-item reconciliation, provenance gap reporting, horizon -classification, bounded authority questions, and preflight readiness planning. - -## Bucket 2 — bounded authority decisions - -- **OWNER DECISION OIC-GATE-01:** Which rights-clear sources are the minimum - authorized preflight set for the required source roles, and which blocked - CanadaBuys sources are replaced or permission-cleared? -- **OWNER/DOMAIN DECISION OIC-GATE-02:** What bounded effective-date and - benchmark-authority disposition is authorized for CA-3 without inventing a - legal effect date or individual delegation? -- **OWNER DECISION OIC-GATE-03:** Is ZTL v0.2 commit `56e1ff05…` the authorized - provisional pin for bounded code start? -- **OWNER + VITALIY DECISION OIC-GATE-04:** Are the corrected disposition/grade/ - unverified mapping, 28 warrant fields, MissingGround granularity, scoped - expiry/revocation proposal, and fail-closed negative fixtures sufficient for - a bounded provisional interface? -- **OWNER DECISION OIC-GATE-05:** May independent Tier-1 ZTL reproduction remain - an experimental-release blocker rather than a semantic code-start blocker? -- **OWNER DECISION OIC-GATE-06:** Which exact VEIP repositories and commits are - the provisional dependency reference? -- **OWNER + LICENSING DECISION OIC-GATE-07:** Is the selected VEIP subset legally - usable for bounded internal implementation, under what limitations? -- **OWNER + ARCHITECTURE DECISION OIC-GATE-08:** Approve the minimum VEIP - lifecycle/input/replay/revocation/correction/failure/fallback contract, or - explicitly defer VEIP semantic integration and define the substitute - review-only boundary. - -## Bucket 3 — later evidence, not code-start blocking - -Full OIC-Bench v0.1, private held-out evaluation, comparative outperformance, -practitioner usability, regulated-enterprise pilot evidence, independent -security review, production reliability, open-standard claims, community -governance, and three independent ZTL reproductions are later release or -maturity evidence. They must not be used as code-start prerequisites absent a -new governing decision. +1. **Source-set owner decision plus provenance completion.** +2. **ZTL profile owner admission**, not new ZTL semantic design; includes stale + metadata correction and independent-reproduction timing. +3. **Minimum VEIP boundary owner admission**, not completion of the full VEIP + lifecycle product. + +No additional code-start blocker is asserted without an exact governing +requirement. + +## Corpus alternatives + +**Path A — real Canada clearance:** finish rights, bytes, hashes, receipts, +dates, confidentiality and benchmark authority for the selected real set. + +**Path B — mixed public/synthetic code-start set:** subject to owner +authorization, retain CA-3 as the real anchor and create deterministic synthetic +companions for the remaining roles. Each must name a synthetic test institution, +declare synthetic status, carry generated provenance and fixed hashes, create no +real-world authority and support benchmark/test semantics only. + +Path B may accelerate code start. It does not establish real-world corpus +completeness, enterprise generalization, superiority or legal validity. Neither +path is executed here. + +## Horizon separation + +| Horizon | Required state | +|---|---| +| Code start | Selected source path provenance-complete for bounded scope; exact ZTL profile admitted; minimum fail-closed/non-executable VEIP handoff admitted | +| Result-bearing preflight execution | Authorized semantic implementation, gold/metric lineage, runtime cases and execution-grade VEIP lifecycle for the tested path | +| Experimental release | Frozen reproducible preflight, raw results, Tier-1 disposition, VEIP conformance/security and bounded claims | +| Release freeze | Full OIC-Bench/held-out, independent review, usability, security, reliability and maturity gates | + +## OWNER DECISIONS REQUIRED TO OPEN BOUNDED SEMANTIC CODE START + +### OIC-CS-OD-001 — Source strategy + +- **Question:** Continue real Canada clearance or authorize CA-3 plus bounded + synthetic companions? +- **Option A:** Continue Path A. +- **Option B:** Authorize Path B with its strict claim ceiling. +- **Recommended conservative default:** A unless speed justifies B's limits. +- **Evidence:** provenance report; governing design permits public or synthetic. +- **Authorizes:** provenance work for the chosen path. +- **Still prohibits:** semantic execution and real-world authority/result claims. + +### OIC-CS-OD-002 — ZTL profile admission + +- **Question:** Accept profile `ztl-v0.1` version `0.1.0`, signed tag + `veraxis-ztl-input-v0.2-signed`, commit `56e1ff05…`, fixture index + `ffadd653…` for bounded code start? +- **Option A:** Accept after correcting stale provenance metadata. +- **Option B:** Keep blocked and name precise additional evidence. +- **Recommended conservative default:** A only while provisional boundaries, + hazards and claim ceilings remain explicit. +- **Evidence:** merged PR #18/#16 and current accepted contracts/review. +- **Authorizes:** bounded semantic code targeting the admitted profile. +- **Still prohibits:** independence/maturity/authority claims and operational + authorization by ZTL. + +### OIC-CS-OD-003 — ZTL independent-reproduction timing + +- **Question:** Require Tier-1 before code start or defer it? +- **Option A:** Require before code start. +- **Option B:** Defer to experimental release/release freeze. +- **Recommended conservative default:** B, while all independence claims remain + prohibited. +- **Evidence:** dossier §13 and v0.2 producer conformance. +- **Authorizes:** timing only. +- **Still prohibits:** calling producer evidence independent. + +### OIC-CS-OD-004 — Minimum VEIP boundary + +- **Question:** Accept a non-executable review-only handoff for compiler code + start, or require the full lifecycle first? +- **Option A:** Accept: ActionProposal precedes OIC; OIC consumes exact context + and emits RuntimeDecision evidence; VEIP does not reinterpret ZTL; neither + creates the other's authority; missing integration is fail-closed. +- **Option B:** Require the full VEIP lifecycle first. +- **Recommended conservative default:** A for bounded compiler work only, with + result-bearing execution separately blocked. +- **Evidence:** current warrant contract and ZTL-VEIP preflight; external heads + remain unadmitted. +- **Authorizes:** bounded compiler contracts without a VEIP execution adapter. +- **Still prohibits:** execution, reliance, lifecycle adapters, operational + publication and VEIP maturity claims. ## Gate answer -**SEMANTIC CODE-START GATE: BLOCKED / READY FOR OWNER ADJUDICATION** +**SEMANTIC CODE-START GATE: BLOCKED — OWNER DECISIONS NOW ISOLATED** diff --git a/docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md b/docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md index 6aadfb9..f7ff30a 100644 --- a/docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md +++ b/docs/gates/OIC-ZTL-VEIP-EVIDENCE-RECONCILIATION-v0.1.md @@ -1,82 +1,71 @@ # OIC ZTL and VEIP Evidence Reconciliation v0.1 -Status: mechanical evidence reconciliation at OIC commit -`d06917fa6877277d7118b49e80d6a69446f50712`. Producer evidence is not treated -as independent reproduction, a proposal is not treated as an accepted -interface, and public visibility is not treated as a license grant. +Status: owner-review correction. Historical July TODO states are not carried +forward when merged successor evidence closes them. Technical evidence is not +owner admission. -## ZTL dossier field matrix +## ZTL live-status matrix -| Requirement | Current evidence | Exact artifact/blob | Status | Still missing / authority to close | Gate effect | -|---|---|---|---|---|---| -| Repository/artifact | Public repository and entrypoints identified | `ZTL-DOSSIER-v0.1.md` `72e84ec2…`; `README.md` `c8170b5c…` | ESTABLISHED | None mechanically | DOES NOT CURRENTLY BLOCK | -| Owner | Vitaly Reznik identified as owner/maintainer | dossier `72e84ec2…`; `OWNERS.md` | ESTABLISHED | None mechanically | DOES NOT CURRENTLY BLOCK | -| License | MIT asserted with upstream LICENSE reference | dossier `72e84ec2…` | PARTIAL | Independent consumer confirmation of pinned artifact/license; owner/legal if disputed | BLOCKS EXPERIMENTAL RELEASE | -| Immutable version | v0.2 signed tag, commit `56e1ff05…`, toolchain and key recorded | ZTL README `c8170b5c…`; provenance `3a5ebdee…` | ESTABLISHED | OIC owner must admit the v0.2 pin as provisional dependency reference | BLOCKS SEMANTIC CODE START | -| Interface schema | `judge` boundary and connector schemas described | dossier `72e84ec2…`; conformance v0.2 `6abcf505…` | PARTIAL | OIC acceptance/interface-freeze record | BLOCKS SEMANTIC CODE START | -| Semantics | T/F/Z, warranty grades, four dispositions and boundary documented | dossier; mapping review `0c43b0fb…` | PARTIAL | Joint OIC/Vitaliy adjudication of mapping, including rejected row 25 | BLOCKS SEMANTIC CODE START | -| Fixture hashes | v0.1/v0.2 fixture indexes and SHA256SUMS tracked | v0.2 index `21e99c40…`; sums `2b560e8e…` | ESTABLISHED | Acceptance under selected pin | BLOCKS SEMANTIC CODE START | -| Conformance tests | Executable procedures and author-side run present | v0.2 procedure `6abcf505…`; run `87b4282d…` | PARTIAL | OIC-side reproduction of provisional interface; Tier-1 independence remains separate | BLOCKS SEMANTIC CODE START | -| Failure behavior | Fail-closed behavior documented | dossier `72e84ec2…` | PARTIAL | OIC mapping acceptance and joint negative fixtures | BLOCKS SEMANTIC CODE START | -| Security notes | Bounds/hazards recorded | dossier; kernel census `770cb69e…` | ESTABLISHED | Independent security review is later evidence | BLOCKS RELEASE FREEZE | -| Known limitations | Explicit limitations and claim ceiling | dossier `72e84ec2…` | ESTABLISHED | None for audit | DOES NOT CURRENTLY BLOCK | -| Replacement strategy | Review-only fallback and migration suite described | dossier `72e84ec2…` | PARTIAL | Owner acceptance of fallback contract | BLOCKS EXPERIMENTAL RELEASE | -| Independent reproduction | Recipe exists; author-side only | dossier §13 `72e84ec2…` | OPEN | Unrelated Tier-1 reproducer; owner decides whether deferrable from code start | BLOCKS EXPERIMENTAL RELEASE | +PR #18 merged at approved head `2f79d4812dbba298a5986e4b40b55c0f296363e5`. +PR #16 merged at approved head `4277838743ec5169bf5045e3e8196330f5e2317f`. +The proposed profile pins signed tag `veraxis-ztl-input-v0.2-signed`, kernel +commit `56e1ff0510c62b04dbd85bbe08b7a6deacbf276b`, and fixture-index SHA-256 +`ffadd65352d69ffcf55787c6dc26339e51eaed76b4c2ae789f7c813625247145`. + +| Requirement | Evidence | Exact artifact/blob | Live status | Remaining action | +|---|---|---|---|---| +| Signed provenance/pin | Signed v0.2 tag and commit | release provenance `3a5ebdee…`; profile `2f8520b2…` | CLOSED BY MERGED ACCEPTED EVIDENCE | Owner admission only | +| Conformance | 13 reachable, 3 NOT_REACHABLE, 0 mismatches/hash problems | conformance `6abcf505…`; run `87b4282d…`; index `21e99c40…` | CLOSED BY MERGED ACCEPTED EVIDENCE | Owner admission only | +| Mapping review | Completed row review and successor cross-review | mapping review `0c43b0fb…`; JSON `a60b41ab…` | CLOSED BY MERGED ACCEPTED EVIDENCE | Owner admission only | +| Historical row 25 | Current `EARNED/hereditary/unverified=any` correction present | profile; mapping review §§1/A | CLOSED BY MERGED ACCEPTED EVIDENCE | None technical | +| Warrant fields | All 28 classified; none unsupported or requiring ZTL change | warrant response `02e72a31…`; mapping review §F | CLOSED BY MERGED ACCEPTED EVIDENCE | Owner admission only | +| WP-3 | Successor trigger binds row 28, observed `sound`, subscription and reasons; SC-RD-006 added | mapping review §A; mapping JSON | CLOSED BY MERGED ACCEPTED EVIDENCE | None technical | +| SC-WA-001/002 | Partition and digest projections accepted | mapping review §A; mapping JSON | CLOSED BY MERGED ACCEPTED EVIDENCE | None technical | +| Trigger set | Five triggers confirmed complete for present anti-tick model | mapping review §G; warrant contract `b9ae57b3…` | CLOSED BY MERGED ACCEPTED EVIDENCE | VEIP carrier deferred | +| Profile metadata | Notice still says PR #18 is draft/not on main | profile `2f8520b2…`, `evidence_dependency_notice` | CURRENTNESS METADATA CORRECTION REQUIRED | Correct in admission package; not a semantic defect | +| Profile admission | Status remains `PROPOSED - ... not admitted` | profile `2f8520b2…` | TECHNICALLY ESTABLISHED / OWNER ADMISSION PENDING | Owner accepts/rejects exact profile | +| Tier-1 reproduction | Producer/Tier-3 evidence only | dossier `72e84ec2…`; profile provenance | LATER INDEPENDENT-EVIDENCE GATE | Owner decides timing; Tier-1 reviewer acts | + +The stale `evidence_dependency_notice` is a **CURRENTNESS / PROVENANCE +METADATA DEFECT**, not a semantic mapping defect. Both referenced PRs are +merged. The profile is not edited here; its admission package should replace +the obsolete draft/merge-order statements while retaining `PROPOSED / NOT +ADMITTED` until the owner decides. ## Nine July ZTL items reconciled -| # | Item | Current classification | Exact evidence | Horizon / next authority | -|---:|---|---|---|---| -| 1 | Independent Tier-1 reproduction | STILL OPEN | dossier §13; README open-items table | Experimental release; Tier-1 reviewer, then owner | -| 2 | Signed release provenance | CLOSED BY CURRENT ACCEPTED EVIDENCE | `RELEASE-PROVENANCE-v0.1.md` `3a5ebdee…`; v0.2 signed pin in README | Does not block; signature trust limitation remains visible | -| 3 | Disposition/grade/unverified mapping | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | `MAPPING-REVIEW-v0.1.md` `0c43b0fb…`; row 25 rejected | Code start; OIC owner + Vitaliy bounded mapping decision | -| 4 | Warrant artifact fields | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | `WARRANT-FIELD-RESPONSE-v0.1.md` `02e72a31…`; 28 fields classified | Code start; OIC owner accepts or requests bounded correction | -| 5 | MissingGround granularity | STILL OPEN | ZTL README; warrant response | Code start; OIC review-docket owner specifies required granularity, Vitaliy confirms feasibility | -| 6 | Epoch/expiry/revocation/anti-tick | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | proposal `00e858cb…`; mapping review | Code start for boundary minimum; owner/Vitaliy accept or constrain proposal | -| 7 | VEIP boundary | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | `ZTL-VEIP-BOUNDARY-PREFLIGHT-v0.1.md` `247558bd…` | Code start; owner architecture decision | -| 8 | Preflight provenance | STILL OPEN | provenance gap report; manifest `718a9df6…` | Code start; owner/rights/domain actors | -| 9 | VEIP dossier | STILL OPEN | VEIP checklist `46490bc…` | Code start; owner and external VEIP actors | +| # | Item | Current disposition | Evidence/boundary | +|---:|---|---|---| +| 1 | Independent Tier-1 reproduction | LATER INDEPENDENT-EVIDENCE GATE | Dossier §13; owner decides code-start timing | +| 2 | Signed release provenance | CLOSED BY MERGED ACCEPTED EVIDENCE | Signed v0.2 record | +| 3 | Disposition/grade/unverified mapping | CLOSED BY MERGED ACCEPTED EVIDENCE | Completed mapping and successor review | +| 4 | Warrant fields | CLOSED BY MERGED ACCEPTED EVIDENCE | 28/28 classified and reconfirmed | +| 5 | MissingGround granularity | CLOSED BY MERGED ACCEPTED EVIDENCE | Contracts distinguish informational/load-bearing/blocking grounds and bind subscriptions to missing grounds | +| 6 | Epoch/expiry/revocation | CLOSED BY MERGED ACCEPTED EVIDENCE FOR CURRENT BOUNDED MODEL | Five-trigger set complete for present anti-tick model | +| 7 | VEIP boundary | EXTERNAL / VEIP DEPENDENCY | ZTL end bounded; carrier requires owner VEIP decision | +| 8 | Preflight provenance | STILL OPEN | Separate provenance gap report | +| 9 | VEIP dossier | EXTERNAL / VEIP DEPENDENCY | Minimum record requires owner decision; full lifecycle is later | + +## VEIP current evidence -## VEIP dossier field matrix +| Public repository | Verified `main` head | OIC status | +|---|---|---| +| `veip-spec` | `b7bae309cd39b6be2f1669aff75c4feb9cf18668` | NEWER EXTERNAL EVIDENCE EXISTS - NOT YET ADMITTED INTO OIC | +| `veip-sdk` | `40bcb5708c8e3aadcb0e31d3190824ddc33f8fce` | NEWER EXTERNAL EVIDENCE EXISTS - NOT YET ADMITTED INTO OIC | +| `veip-verifier-core` | `e8b985920b60ba74f2e0e014ee107a5c4937b1fc` | NEWER EXTERNAL EVIDENCE EXISTS - NOT YET ADMITTED INTO OIC | +| `veip-registry` | `a0b70452d14c0b29da500d53714ae215b09bc43e` | NEWER EXTERNAL EVIDENCE EXISTS - NOT YET ADMITTED INTO OIC | -| Requirement | Current evidence | Exact artifact/blob | Status | Still missing / authority to close | Gate effect | -|---|---|---|---|---|---| -| Repository/spec locations | Four candidates inventoried | `VEIP-INVENTORY-v0.1.md` `26abb9ad…` | EXTERNAL/OWNER ACTION REQUIRED | Owner attests canonical/excluded repositories | BLOCKS SEMANTIC CODE START | -| Owner | Interim owner recorded | checklist `46490bc…`; owner decision `66190c45…` | ESTABLISHED | None mechanically | DOES NOT CURRENTLY BLOCK | -| License | Conflicting/incomplete across four layers | checklist `46490bc…`; inventory `26abb9ad…` | OPEN | Complete texts and qualified compatibility review | BLOCKS SEMANTIC CODE START | -| Immutable versions | Candidate SHAs exist, no attested interface pins | inventory `26abb9ad…` | PARTIAL | Owner-attested pins/version relationship | BLOCKS SEMANTIC CODE START | -| Lifecycle interface | Small fragments; core lifecycle undefined | checklist `46490bc…`; boundary memo `247558bd…` | OPEN | Owner-approved minimum states/events | BLOCKS SEMANTIC CODE START | -| Evidence schema | Byte-identical Evidence Pack schema, SHA-256 `3ff025de…` | checklist/inventory | PARTIAL | Owner identifies its role and freezes provisional schema | BLOCKS SEMANTIC CODE START | -| Fixtures | Sparse, non-normative fixtures | checklist/inventory | PARTIAL | Version-bound minimum boundary fixtures | BLOCKS PREFLIGHT EXECUTION | -| Conformance tests | Per-repo commands only; no consolidated run | checklist/inventory | OPEN | External repositories publish clean pinned command/results | BLOCKS PREFLIGHT EXECUTION | -| Replay behavior | Recompute vs integrity-carrier semantics conflict | checklist/inventory | OPEN | Owner architecture decision and external tests | BLOCKS SEMANTIC CODE START | -| Revocation/correction | Absent | checklist `46490bc…` | OPEN | Owner defines minimum invalidation/correction boundary | BLOCKS SEMANTIC CODE START | -| Security notes | Layer notes exist, no consolidated model | checklist/inventory | PARTIAL | Minimum integration threats for code start; independent review later | BLOCKS EXPERIMENTAL RELEASE | -| Known limitations | Scattered and not owner-attested | checklist/inventory | PARTIAL | Consolidated limitation register | BLOCKS EXPERIMENTAL RELEASE | -| Replacement strategy | Conceptual only | checklist/inventory | PARTIAL | Owner-approved fail-closed fallback/continuity rule | BLOCKS SEMANTIC CODE START | +Newer private/reconstructed material is likewise not admitted without formal +binding into the OIC evidence chain. -## Twenty July VEIP items reconciled +| Horizon | Minimum evidence | State | +|---|---|---| +| Semantic code start | Owner-approved non-executable handoff: ActionProposal precedes OIC; OIC consumes exact context and emits RuntimeDecision evidence; neither side creates/reinterprets the other's authority; missing lifecycle integration is fail-closed | TECHNICAL OPTION / OWNER ADMISSION PENDING | +| Result-bearing preflight | Accepted execution carrier plus replay, expiry, revocation, correction and failure behavior for the tested path | OPEN | +| Experimental release/maturity | Canonical repos/pins/licenses, fixtures, conformance, security, reliance, replacement and independent review | OPEN / EXTERNAL WORK REQUIRED | -| ID | Classification | Code-start horizon | Current evidence / smallest next action | -|---|---|---|---| -| VEIP-OI-001 | OWNER DECISION REQUIRED | Blocks code start | Inventory present; owner attests canonical repository set. | -| VEIP-OI-002 | OWNER DECISION REQUIRED | Blocks code start | Candidate SHAs present; owner selects provisional immutable versions. | -| VEIP-OI-003 | OWNER DECISION REQUIRED | Blocks code start | Conflicting licenses; obtain complete texts and qualified compatibility finding. | -| VEIP-OI-004 | OWNER DECISION REQUIRED | Blocks code start | Define minimum lifecycle states/events. | -| VEIP-OI-005 | OWNER DECISION REQUIRED | Blocks code start | Select canonical action-proposal input and required identifiers. | -| VEIP-OI-006 | OWNER DECISION REQUIRED | Blocks code start | Decide the exact OIC-to-VEIP runtime-decision boundary. | -| VEIP-OI-007 | EVIDENCE NOW PRESENT BUT NOT ADJUDICATED | Blocks preflight execution | Evidence Pack execution object exists; owner decides whether it is sufficient for bounded preflight. | -| VEIP-OI-008 | OWNER DECISION REQUIRED | Blocks code start | Reconcile recomputation and integrity-carrier replay meanings. | -| VEIP-OI-009 | STILL OPEN | Blocks experimental release | Define reliance record and invalidation duties before reliance claims. | -| VEIP-OI-010 | OWNER DECISION REQUIRED | Blocks code start | Define minimum expiry/time-authority boundary. | -| VEIP-OI-011 | OWNER DECISION REQUIRED | Blocks code start | Define fail-closed revocation propagation boundary. | -| VEIP-OI-012 | OWNER DECISION REQUIRED | Blocks code start | Define correction/supersession linkage minimum. | -| VEIP-OI-013 | OWNER DECISION REQUIRED | Blocks code start | Select unified fail-closed behavior across layers. | -| VEIP-OI-014 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks preflight execution | VEIP Registry owner repairs/explains mismatch and adds tests. | -| VEIP-OI-015 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks experimental release | VEIP spec owner produces green pinned-head CI or accepted deviation. | -| VEIP-OI-016 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks preflight execution | Publish minimum normative boundary fixtures. | -| VEIP-OI-017 | EXTERNAL REPOSITORY WORK REQUIRED | Blocks preflight execution | Publish consolidated pinned conformance command/results. | -| VEIP-OI-018 | OWNER DECISION REQUIRED | Blocks experimental release | Consolidate security model; independent assessment is release-freeze evidence. | -| VEIP-OI-019 | OWNER DECISION REQUIRED | Blocks code start | Define fail-closed replacement/fallback and evidence continuity. | -| VEIP-OI-020 | EXTERNAL REPOSITORY WORK REQUIRED | Does not currently block | Remove or justify tracked generated artifacts before maturity claims. | +The twenty-item July inventory remains a gap register, but it is not one +code-start blocker. Items 001–006 and 013 reduce to the minimum handoff +admission question; 007–012 govern result-bearing execution; 014–019 govern +preflight/release evidence; 020 is hygiene. External heads alone close none.