Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,9 @@ PYTHON ?= python
verify:
$(PYTHON) -m oic.cli validate-schema
$(PYTHON) -m oic.cli verify-bootstrap
$(PYTHON) scripts/verify_code_start_gate.py
@set +e; $(PYTHON) -m oic.cli verify-manifest --all; code=$$?; set -e; \
test $$code -eq 3; echo "PASS manifest remains explicitly INCOMPLETE (exit 3)"

falsify:
$(PYTHON) scripts/falsify_infrastructure.py

22 changes: 12 additions & 10 deletions adr/ADR-013.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
**Status:** Proposed
**Work order:** OIC-WO-002
**Architecture authority:** GPT-5.6 Thinking. **Final design authority:** Arkadiy Miteiko / Veraxis.
**Scope:** architecture, proposed schemas, and conformance fixtures only. No ZTL call, no VEIP call, no admission, no envelope generation, no Rego, no runtime execution. The semantic implementation gate remains **BLOCKED**.
**Scope:** architecture, proposed schemas, and conformance fixtures only. No ZTL call, no VEIP call, no envelope generation, no Rego, no runtime execution. The exact ZTL profile is owner-admitted for bounded code start; the semantic code-start gate remains **NOT OPEN** pending separate exact-head review.

---

Expand Down Expand Up @@ -277,8 +277,9 @@ Schema but fails a semantic conformance rule is invalid.** The eight rules are d
machine-readably in the canonical mapping and are executable through a **test-only**
validator kept deliberately outside `src/oic`.

**W-17.** This contract's `MEASURED` labels reference evidence still in **draft** PR #18.
**PR #16 must not merge before PR #18.**
**W-17.** This contract's `MEASURED` labels reference checked-in evidence on `main`. Owner
decision OIC-OWNER-DECISION-003 admits the exact profile/tag/commit/fixture-index tuple for
bounded code start only. Tier-1 reproduction remains **NOT ESTABLISHED**.

**Pin correction.** The commit this profile previously pinned,
`e819dec7e89d2dc67d6371e1eedb8e7aae854602`, predated the declared `ztljudge.judge`
Expand All @@ -287,8 +288,8 @@ under that entrypoint could actually have been reproduced. The proposed profile
corrected to the signed `veraxis-ztl-input-v0.2-signed` pin,
`56e1ff0510c62b04dbd85bbe08b7a6deacbf276b`, and its conformance fixture set to
`interface-freeze-v0.2/` (13 reachable, 3 not-reachable, 16 total). This corrects the
**proposed** profile's evidence pin; it does not admit a v0.2 semantic profile —
`kernel_profile_id` remains `ztl-v0.1` and no profile version field exists to bump.
profile's evidence pin; it does not create a v0.2 semantic profile — `kernel_profile_id`
remains `ztl-v0.1` and version remains `0.1.0`.

On PR #18's eventual merge this work still rebases onto the resulting `main` and
re-verifies every `MEASURED` label against the checked-in (not draft-branch) evidence, in
Expand Down Expand Up @@ -495,9 +496,10 @@ Not decided here. The eventual handoff must bind **at least**:
- evaluation input hash;
- authority and admission versions.

**Final VEIP transition names and event schemas are deliberately not decided in this PR.**
Arkadiy Miteiko is interim VEIP contract owner (OIC-OWNER-DECISION-002 §5); the schema is
deferred to OIC-GC-004.
**Final VEIP transition names and event schemas remain deliberately undecided.** The
bounded, non-executable record in `docs/contracts/VEIP-CODE-START-BOUNDARY-v0.1.json`
expresses the minimum handoff only; it creates no lifecycle authority or runtime adapter.
Final transition names and executable event schemas remain deferred to OIC-GC-004.

### 4.4 The two directions that must not cross

Expand All @@ -522,8 +524,8 @@ emits a lifecycle event has crossed the other way.
## 6. Compatibility impact and migration

**Nothing in `schemas/draft/` is modified by this ADR.** The proposals live in
`schemas/proposed/` and are inert until an owner decision admits them. `STATUS.md` is
unchanged and the semantic gate remains BLOCKED.
`schemas/proposed/` and remain inert. The exact ZTL input profile is admitted only for
bounded code start; the semantic code-start gate remains **NOT OPEN**.

Three migrations are *proposed*, not applied:

Expand Down
8 changes: 8 additions & 0 deletions benchmarks/preflight/code-start-v0.1/PROVENANCE.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
{
"receipts": [
{"source_id": "CA-3", "sha256": "6e89ad25847944ca2bd72bcbf02ec3d2942a234d373b6c10db44307e0fbdf2c3", "provenance": "OIC-CA-FREEZE-CA-3-v0.1"},
{"source_id": "SYN-NS-GOV-1", "sha256": "b882459931ddf06fb647e6885c1ced368b4a5f45b6441df618484a30473a2a24", "provenance": "DETERMINISTIC_REPOSITORY_GENERATION"},
{"source_id": "SYN-NS-PROC-1", "sha256": "cfb578274460cc17492f4b25a4db6893ce87a527e1207fe6a52b6384125ec073", "provenance": "DETERMINISTIC_REPOSITORY_GENERATION"},
{"source_id": "SYN-NS-AMEND-2", "sha256": "8e197bc9e01554853163dfb5f84ad807893f678b26673737c8a72ddf0c8daf47", "provenance": "DETERMINISTIC_REPOSITORY_GENERATION"}
]
}
46 changes: 46 additions & 0 deletions benchmarks/preflight/code-start-v0.1/SOURCE-SET.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
{
"scope": "SEMANTIC_CODE_START_PREREQUISITES_ONLY",
"global_manifest_status": "INCOMPLETE",
"sources": [
{
"source_id": "CA-3",
"path": "benchmarks/corpus/canada/freeze-v0.1/sources/CA-3.xml",
"sha256": "6e89ad25847944ca2bd72bcbf02ec3d2942a234d373b6c10db44307e0fbdf2c3",
"origin_classification": "REAL_PUBLIC_CANADIAN_SOURCE_UNOFFICIAL_COPY",
"benchmark_authority": "BOUNDED_TEST_INPUT_ONLY",
"effective_state": "NOT_ESTABLISHED_NO_DATE_INVENTED",
"rights_basis": "Reproduction of Federal Law Order (SI/97-5), subject to due diligence and no representation as an official version",
"rights_limitations": "Unofficial copy; third-party material, insignia, personal-information, and broader corpus clearance remain source-specific and unchanged",
"receipt": "benchmarks/corpus/canada/freeze-v0.1/receipts/CA-3.receipt.json"
},
{
"source_id": "SYN-NS-GOV-1",
"path": "benchmarks/preflight/code-start-v0.1/sources/SYNTHETIC-NORTHSTAR-GOVERNANCE-v1.txt",
"sha256": "b882459931ddf06fb647e6885c1ced368b4a5f45b6441df618484a30473a2a24",
"origin_classification": "SYNTHETIC_FICTIONAL",
"benchmark_authority": "SYNTHETIC_BENCHMARK_ONLY",
"issuer": "Veraxis synthetic fixture generator",
"effective_state": "SYNTHETIC_CURRENT"
},
{
"source_id": "SYN-NS-PROC-1",
"path": "benchmarks/preflight/code-start-v0.1/sources/SYNTHETIC-NORTHSTAR-PROCEDURE-v1.txt",
"sha256": "cfb578274460cc17492f4b25a4db6893ce87a527e1207fe6a52b6384125ec073",
"origin_classification": "SYNTHETIC_FICTIONAL",
"benchmark_authority": "SYNTHETIC_BENCHMARK_ONLY",
"issuer": "Veraxis synthetic fixture generator",
"effective_state": "SYNTHETIC_SUPERSEDED",
"superseded_by": "SYN-NS-AMEND-2"
},
{
"source_id": "SYN-NS-AMEND-2",
"path": "benchmarks/preflight/code-start-v0.1/sources/SYNTHETIC-NORTHSTAR-AMENDMENT-v2.txt",
"sha256": "8e197bc9e01554853163dfb5f84ad807893f678b26673737c8a72ddf0c8daf47",
"origin_classification": "SYNTHETIC_FICTIONAL",
"benchmark_authority": "SYNTHETIC_BENCHMARK_ONLY",
"issuer": "Veraxis synthetic fixture generator",
"effective_state": "SYNTHETIC_CURRENT",
"supersedes": "SYN-NS-PROC-1"
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
SYNTHETIC — FICTIONAL TEST/BENCHMARK AUTHORITY ONLY
Document: Northstar Test Institution Operating Procedure Amendment
Version: 2.0.0
Created: 2026-08-27T00:00:00Z
Effective state: SYNTHETIC_CURRENT
Confidentiality: PUBLIC_SYNTHETIC

This amendment supersedes SYNTHETIC-NORTHSTAR-PROCEDURE-v1 in full.

Current procedure: TEST_PURCHASE_HIGH requires both Approver-A and Approver-B,
consistent with the Governance Charter. A stale procedure must be refused as
current evidence.

This document is fictional. It creates no legal, governmental, institutional,
Canadian, or other real-world authority. It is limited to deterministic tests
and benchmarks.
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
SYNTHETIC — FICTIONAL TEST/BENCHMARK AUTHORITY ONLY
Document: Northstar Test Institution Governance Charter
Version: 1.0.0
Created: 2026-08-27T00:00:00Z
Effective state: SYNTHETIC_CURRENT
Confidentiality: PUBLIC_SYNTHETIC

Definitions: Requester means a fictional test actor. Approver means a fictional
test actor listed in the matrix. Evidence means a deterministic record bound to
the proposed action.

Approval and delegation matrix:
- TEST_PURCHASE_LOW requires Approver-A.
- TEST_PURCHASE_HIGH requires Approver-A and Approver-B.
- Approver-A may delegate TEST_PURCHASE_LOW to Delegate-A. No other delegation
is recognized.

Evidence requirement: every proposal carries its source identifier, amount,
requester identifier, and approval records.

Exception: TEST_EMERGENCY may omit Approver-B only when an emergency record and
Approver-A approval are present.

Discretionary clause: Approver-A may refer any proposal for human review.
Referral establishes no approval.

This document is fictional. It creates no legal, governmental, institutional,
Canadian, or other real-world authority. It is limited to deterministic tests
and benchmarks.
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
SYNTHETIC — FICTIONAL STALE TEST/BENCHMARK SOURCE
Document: Northstar Test Institution Operating Procedure
Version: 1.0.0
Created: 2026-08-27T00:00:00Z
Effective state: SYNTHETIC_SUPERSEDED
Confidentiality: PUBLIC_SYNTHETIC

Procedure: TEST_PURCHASE_HIGH requires only Approver-A.

This deliberately conflicting procedure is superseded in full by
SYNTHETIC-NORTHSTAR-AMENDMENT-v2. It must never be treated as current.

This document is fictional. It creates no legal, governmental, institutional,
Canadian, or other real-world authority. It is limited to deterministic tests
and benchmarks.
13 changes: 13 additions & 0 deletions docs/contracts/VEIP-CODE-START-BOUNDARY-v0.1.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"status": "NON_EXECUTABLE_BOUNDARY_RECORD",
"version": "0.1.0",
"sequence": ["ActionProposal", "OIC exact proposal", "RuntimeDecision", "evidence handed downstream toward VEIP"],
"executable_runtime_integration": false,
"oic_has_veip_lifecycle_authority": false,
"veip_reinterprets_ztl": false,
"oic_self_authorizes_runtime_execution": false,
"missing_lifecycle_integration": "FAIL_CLOSED",
"runtime_adapter_authorized": false,
"lifecycle_execution_authorized": false,
"runtime_import_authorized": false
}
37 changes: 14 additions & 23 deletions docs/contracts/WARRANT-CONTRACT-v0.1.md
Original file line number Diff line number Diff line change
Expand Up @@ -550,15 +550,15 @@ the first VEIP artifact.

ZTL must not create a VEIP lifecycle record. VEIP must not reinterpret the ZTL formula.

## 13a. Evidence dependency on PR #18
## 13a. Admitted bounded ZTL evidence

**PR #16 must not merge before PR #18.**

Every `MEASURED` label in the canonical mapping, and every field in
[`kernel-profiles/ztl-v0.1.json`](kernel-profiles/ztl-v0.1.json), references evidence that
is still in **draft** PR #18 and is not yet on `main`. Merging this first would leave the
contract citing a branch that could still change or be abandoned — the mapping would claim
measurement it could not point at.
The evidence formerly carried through PR #18 is checked in on `main`. Owner decision
OIC-OWNER-DECISION-003 admits the exact `ztl-v0.1` profile version `0.1.0`, signed tag
`veraxis-ztl-input-v0.2-signed`, commit
`56e1ff0510c62b04dbd85bbe08b7a6deacbf276b`, and fixture-index SHA-256
`ffadd65352d69ffcf55787c6dc26339e51eaed76b4c2ae789f7c813625247145` for bounded
semantic code start only. Tier-1 reproduction remains **NOT ESTABLISHED** and is deferred
to the experimental-release boundary. No ZTL runtime import or execution is admitted.

### Pin correction

Expand All @@ -577,29 +577,20 @@ dependency pin.
`interface-freeze-v0.1` is **not edited**. It remains immutable historical evidence with a
documented lineage hole — the commit it cited predated `ztljudge.judge`, so no fixture
claiming reproduction against it under that entrypoint was actually recomputable at that
pin. This correction updates the **proposed** `ztl-v0.1` profile's evidence pin only.
`kernel_profile_id` remains `ztl-v0.1`; no admitted v0.2 semantic profile is created.
pin. This correction updated the `ztl-v0.1` profile's evidence pin only.
`kernel_profile_id` remains `ztl-v0.1`; no v0.2 semantic profile is created.

The new commit's fixture set additionally reproduces `EARNED` + non-empty `unverified` as a
**pinned, reachable** fixture (`earned-hereditary-nonempty-unverified.json`), rather than
leaving it as census-only corroboration. That question from the prior revision is therefore
resolved by the pin correction itself, not left open.

### Remaining merge-order steps

Because the current evidence is PR #18's **draft** head rather than its merged state, this
PR still must, once PR #18 merges:

1. rebase onto the merged `main`;
2. re-verify **every** `MEASURED` authority label against the checked-in evidence, in case
anything moved between the current evidence head and the merge;
3. re-point the census and fixture references at their merged paths if either changed.

## 14. Standing

Proposed under OIC-WO-002. Not admitted. No ZTL or VEIP code exists, is imported, or is
The contract remains proposed and unimplemented; only the exact ZTL input profile is
owner-admitted for bounded code start. No ZTL or VEIP code exists, is imported, or is
called. No policy document is parsed, no Institutional IR is constructed, no Open Control
Envelope is generated, no Rego is emitted, and OPA is not invoked.

`STATUS.md` is unchanged. `schemas/draft/` is unchanged. **No semantic implementation was
introduced. The semantic implementation gate remains BLOCKED.**
`schemas/draft/` is unchanged. **No semantic implementation was introduced. The semantic
code-start gate is READY FOR SEPARATE EXACT-HEAD REVIEW and NOT OPEN.**
3 changes: 2 additions & 1 deletion docs/contracts/ZTL-OCE-MAPPING-v0.1.md
Original file line number Diff line number Diff line change
Expand Up @@ -213,4 +213,5 @@ Proposed by the OIC side under OIC-WO-002. Requires:
- **Arkadiy Miteiko / Veraxis** — final design authority.

No ZTL call was made to produce this document; the measured rows cite fixtures published
by the ZTL side. No adapter exists. The semantic implementation gate remains **BLOCKED**.
by the ZTL side. No adapter exists. The semantic code-start gate remains **NOT OPEN**
pending separate exact-head review.
20 changes: 7 additions & 13 deletions docs/contracts/kernel-profiles/ztl-v0.1.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"$comment": "PROPOSED, NOT ADMITTED. A frozen description of one logic kernel's interface and vocabulary. Dispositions, grades, and digests are NOT portable between kernels, so every WarrantArtifact declares the kernel_profile_id it was produced under and OIC never compares artifacts across profiles. Nothing in this file imports, executes, or calls ZTL.",
"$comment": "OWNER-ADMITTED FOR BOUNDED SEMANTIC CODE START ONLY. A frozen description of one logic kernel's interface and vocabulary. Dispositions, grades, and digests are NOT portable between kernels, so every WarrantArtifact declares the kernel_profile_id it was produced under and OIC never compares artifacts across profiles. Nothing in this file imports, executes, or calls ZTL.",
"canonicalization_profile_id": "ztl-jcs-float-free-sha384-v0.1",
"commit": "56e1ff0510c62b04dbd85bbe08b7a6deacbf276b",
"conformance_fixture_set": {
Expand All @@ -13,7 +13,7 @@
"index_sha256": "ffadd65352d69ffcf55787c6dc26339e51eaed76b4c2ae789f7c813625247145",
"location": "adapters/ztl/fixtures/interface-freeze-v0.2/",
"not_reachable": 3,
"provenance": "Published by the ZTL side under ZTL-OIC-WO-002/OIC-WO-003, reproduced against the pinned v0.2 commit by its author (Tier 3). Independent Tier-1 reproduction remains OPEN.",
"provenance": "Published by the ZTL side under ZTL-OIC-WO-002/OIC-WO-003, reproduced against the pinned v0.2 commit by its author (Tier 3). Independent Tier-1 reproduction is NOT ESTABLISHED and is deferred to the experimental-release boundary.",
"reachable": 13,
"total": 16
},
Expand Down Expand Up @@ -81,16 +81,9 @@
],
"entrypoint": "ztljudge.judge",
"evidence_dependency_notice": {
"current_pin": "interface-freeze-v0.2, index_sha256 ffadd65352d69ffcf55787c6dc26339e51eaed76b4c2ae789f7c813625247145 (13 reachable, 3 not-reachable, 16 total), reproduced against the signed commit 56e1ff0510c62b04dbd85bbe08b7a6deacbf276b (veraxis-ztl-input-v0.2-signed). This is PR #18's current DRAFT evidence head, not its merged state.",
"merge_order": "PR #16 must not merge before PR #18.",
"on_pr18_merge": [
"PR #16 rebases onto the merged main.",
"Every MEASURED authority label in the canonical mapping is re-verified against the checked-in evidence, in case anything moved between the current evidence head and the merge.",
"conformance_fixture_set.location, counts and index_sha256 are re-pointed at the merged path if the evidence changed further before merge.",
"The census reference is re-pointed at its merged path."
],
"statement": "Every field in this profile references evidence that is still in DRAFT pull request #18 and is NOT yet on main.",
"status": "BLOCKING for merge order"
"current_pin": "interface-freeze-v0.2, index_sha256 ffadd65352d69ffcf55787c6dc26339e51eaed76b4c2ae789f7c813625247145 (13 reachable, 3 not-reachable, 16 total), reproduced against signed commit 56e1ff0510c62b04dbd85bbe08b7a6deacbf276b (veraxis-ztl-input-v0.2-signed). Evidence is checked in on main and owner-admitted for bounded code start.",
"statement": "The exact profile, tag, commit, and fixture index are admitted only for bounded semantic code start. No runtime import or execution is admitted.",
"status": "ADMITTED_BOUNDED_CODE_START"
},
"formula_digest_algorithm": "sha384",
"formula_hash_projection": {
Expand Down Expand Up @@ -218,7 +211,8 @@
"name": "veraxis-ztl-input-v0.2-signed",
"signs_commit": "56e1ff0510c62b04dbd85bbe08b7a6deacbf276b"
},
"status": "PROPOSED - frozen interface description, not admitted",
"status": "ADMITTED FOR BOUNDED SEMANTIC CODE START ONLY",
"tier_1_reproduction": "NOT ESTABLISHED — DEFERRED TO EXPERIMENTAL RELEASE",
"unsigned_tag": "veraxis-ztl-input-v0.1",
"unverified_ground_semantics": {
"EARNED": "informational - irrelevant to this conclusion because the result is hereditary",
Expand Down
10 changes: 10 additions & 0 deletions docs/decisions/OIC-OWNER-DECISION-003.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# OIC Owner Decision 003 — semantic code-start prerequisites

Status: **RECORDED FOR SEPARATE EXACT-HEAD REVIEW — GATE NOT OPEN**

- **OD-001:** bounded source set is CA-3 plus deterministic, explicitly synthetic fictional companions. Synthetic material has benchmark authority only. CA-3 remains an unofficial copy with its existing source-specific rights limitations; broader Canada clearance is unchanged.
- **OD-002:** admit only profile `ztl-v0.1` version `0.1.0`, tag `veraxis-ztl-input-v0.2-signed`, commit `56e1ff0510c62b04dbd85bbe08b7a6deacbf276b`, fixture-index SHA-256 `ffadd65352d69ffcf55787c6dc26339e51eaed76b4c2ae789f7c813625247145` for bounded semantic code start. No ZTL runtime is imported or executed.
- **OD-003:** Tier-1 independent reproduction is **NOT ESTABLISHED** and deferred to the experimental-release boundary. It is not a code-start blocker and is not represented as PASS.
- **OD-004:** the minimum boundary is `ActionProposal → OIC exact proposal → RuntimeDecision → evidence handed downstream toward VEIP`. The boundary record is non-executable. OIC has no VEIP lifecycle authority, VEIP does not reinterpret ZTL, and no runtime adapter, import, execution, or self-authorization is permitted.

Global repository completeness remains **INCOMPLETE**. These decisions close only bounded prerequisites and do not authorize semantic implementation.
20 changes: 20 additions & 0 deletions docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# OIC semantic code-start gate closure candidate

Global repository completeness: **INCOMPLETE**

Scoped prerequisite evidence:

| Decision | Evidence | Producer disposition |
|---|---|---|
| OD-001 | `benchmarks/preflight/code-start-v0.1/SOURCE-SET.json` plus immutable source bytes/digests | MATERIAL prerequisites represented |
| OD-002 | `docs/contracts/kernel-profiles/ztl-v0.1.json` exact profile/tag/commit/index | ADMITTED for bounded code start only |
| OD-003 | owner decision record | NOT ESTABLISHED; deferred to experimental release |
| OD-004 | `docs/contracts/VEIP-CODE-START-BOUNDARY-v0.1.json` | NON-EXECUTABLE boundary represented |

Negative controls are enforced by `scripts/verify_code_start_gate.py` and contract tests. This establishes neither semantic correctness nor legal, benchmark, runtime, lifecycle, or production claims.

SEMANTIC CODE-START GATE:
READY FOR SEPARATE EXACT-HEAD REVIEW
NOT OPEN

SEMANTIC IMPLEMENTATION HAS NOT STARTED.
Loading