Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 6 additions & 4 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# Agent operating boundary

This repository is a non-semantic infrastructure foundation. The semantic OIC
code-start gate remains **BLOCKED** by `STATUS.md`. No agent may implement or
claim document interpretation, candidate extraction, institutional admission,
This repository includes an owner-opened, bounded semantic candidate-extraction
slice defined by `docs/decisions/OIC-OWNER-DECISION-004.md`. No agent may claim
general document interpretation, institutional admission,
Open Control Envelope generation, Rego compilation, or runtime semantic
decisions under this work order.

Expand All @@ -22,7 +22,9 @@ bash scripts/generate_sbom.sh
bash scripts/wheel_smoke_test.sh
```

Implemented CLI commands are limited to `oic validate-schema`,
The only authorized semantic production path is
`src/oic/candidate_extraction.py`, limited to the three synthetic Northstar
sources. Implemented CLI commands are limited to `oic validate-schema`,
`oic verify-bootstrap`, `oic verify-manifest`, and `oic doctor`. They verify
infrastructure contracts only. Do not invent semantic commands, hosted APIs,
gateways, remote context services, or MCP servers.
Expand Down
39 changes: 22 additions & 17 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,14 +15,17 @@ Target capability:
> evidentiary standard required to authorize, explain, audit, or correct those
> actions.

**What exists today:** a tested, non-semantic Python infrastructure package for
**What exists today:** a tested Python infrastructure package plus one bounded,
deterministic candidate extractor for three synthetic Northstar sources. The
infrastructure supports
offline schema validation, historical bootstrap verification, current manifest
verification, environment and gate diagnostics, and reproducible CI and SBOM
checks. It is not a functioning institutional compiler.

**What is blocked:** semantic implementation remains blocked pending the corpus
provenance and ZTL/VEIP interface evidence listed in [`STATUS.md`](STATUS.md).
Nothing in this README opens that gate or promotes the repository's maturity.
**What is blocked:** every semantic capability beyond source → candidate
normative unit remains blocked. Institutional admission, IR/OCE generation,
runtime authorization, CA-3 extraction, and ZTL/VEIP runtime integration are
not authorized. See [`STATUS.md`](STATUS.md).

## Capability being developed

Expand Down Expand Up @@ -295,17 +298,17 @@ verification, operational, and independent-review evidence.

**STATUS: CURRENT**

Current capabilities include non-semantic schemas and contracts,
Current capabilities include schemas and contracts,
manifest/integrity verification, the falsification harness, supply-chain
controls, and the benchmark preflight specification.
controls, the benchmark preflight specification, and the bounded synthetic
candidate extractor.

Exit requires complete governing-source rights and provenance plus sufficient
ZTL and VEIP provisional-interface evidence to open the semantic code-start
gate.
The global corpus manifest remains incomplete and ZTL/VEIP runtime integration
remains unauthorized.

### Stage 1 - Source-to-control reference

**STATUS: NEXT - BLOCKED by the semantic code-start gate**
**STATUS: FIRST BOUNDED SLICE OWNER-OPENED; REMAINDER BLOCKED**

Target path:

Expand Down Expand Up @@ -372,19 +375,21 @@ conformance, and community governance.

## Current phase

This repository authorizes contract-first, non-semantic infrastructure work.
It currently implements four infrastructure CLI commands:
This repository authorizes contract-first infrastructure work and the exact
bounded extraction scope in `docs/decisions/OIC-OWNER-DECISION-004.md`. It
currently implements four infrastructure CLI commands:

- `oic validate-schema`
- `oic verify-bootstrap`
- `oic verify-manifest`
- `oic doctor`

It does not implement document interpretation, candidate extraction,
It implements deterministic candidate extraction only for three authorized
synthetic sources. It does not implement general document interpretation,
institutional admission, Institutional IR production, Open Control Envelope
generation, Rego compilation, or runtime semantic decisions.

Run the safe non-semantic checks after the hash-locked installation described
Run the checks after the hash-locked installation described
in [`docs/operations/CI.md`](docs/operations/CI.md):

```bash
Expand All @@ -398,9 +403,9 @@ must not be normalized into success.

## First executable objective

The first semantic objective remains blocked. When its prerequisites are
authorized, a bounded set of public or synthetic procurement governing sources
is intended to flow through:
The first semantic objective is owner-opened only through source-anchored
candidate normative units for the synthetic Northstar source set. Later stages
remain blocked:

```text
documents
Expand Down
13 changes: 12 additions & 1 deletion STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,17 @@ It does not authorize public quality, enterprise-readiness, legal-compliance, un
| Public Lab restrictions visible before upload | PASS as specification | `LIMITATIONS.md`, `docs/architecture/LAB_RESTRICTIONS.md` |
| Named owner for each implemented module | PASS for kickoff | `OWNERS.md` |

**Semantic implementation gate:** BLOCKED until the preflight corpus manifest and ZTL/VEIP provisional-interface records are completed.
SEMANTIC CODE-START GATE:
OWNER-OPENED AT
914830ceec70bde17004d2ccbbb13218ca44a89b

FIRST AUTHORIZED SEMANTIC SCOPE:
SOURCE → CANDIDATE NORMATIVE UNIT
SYNTHETIC NORTHSTAR SOURCES ONLY

Only the deterministic candidate-extraction slice is opened. Institutional
admission, IR/OCE generation, runtime authorization and integration, CA-3
semantic extraction, and all production or benchmark claims remain blocked or
not established. Global manifest completeness remains `INCOMPLETE`.

Infrastructure scaffolding and schema validation may proceed before that gate.
29 changes: 29 additions & 0 deletions benchmarks/preflight/semantic-001/EXPECTED-CANDIDATES.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
{
"classification": [
"OWNER-SPECIFIED PREIMPLEMENTATION EXPECTATION",
"NOT AN OBSERVED BENCHMARK RESULT",
"NOT INDEPENDENTLY ADJUDICATED"
],
"expected_total": 14,
"expected_by_source": {
"SYN-NS-GOV-1": 11,
"SYN-NS-PROC-1": 1,
"SYN-NS-AMEND-2": 2
},
"candidates": [
{"label":"G1","source_id":"SYN-NS-GOV-1","unit_type":"definition","actor":"Requester","action":"means","object":"a fictional test actor","conditions":[]},
{"label":"G2","source_id":"SYN-NS-GOV-1","unit_type":"definition","actor":"Approver","action":"means","object":"a fictional test actor listed in the matrix","conditions":[]},
{"label":"G3","source_id":"SYN-NS-GOV-1","unit_type":"definition","actor":"Evidence","action":"means","object":"a deterministic record bound to the proposed action","conditions":[]},
{"label":"G4","source_id":"SYN-NS-GOV-1","unit_type":"condition","actor":null,"action":"TEST_PURCHASE_LOW","object":"approval","conditions":["Approver-A"]},
{"label":"G5","source_id":"SYN-NS-GOV-1","unit_type":"condition","actor":null,"action":"TEST_PURCHASE_HIGH","object":"approval","conditions":["Approver-A","Approver-B"]},
{"label":"G6","source_id":"SYN-NS-GOV-1","unit_type":"delegation","actor":"Approver-A","action":"delegate","object":"TEST_PURCHASE_LOW to Delegate-A","conditions":[]},
{"label":"G7","source_id":"SYN-NS-GOV-1","unit_type":"prohibition","actor":null,"action":"recognize","object":"other delegation","conditions":[]},
{"label":"G8","source_id":"SYN-NS-GOV-1","unit_type":"evidence_duty","actor":null,"action":"proposal_carries_evidence","object":null,"conditions":[]},
{"label":"G9","source_id":"SYN-NS-GOV-1","unit_type":"exception","actor":null,"action":"TEST_EMERGENCY","object":"omit Approver-B","conditions":["emergency record present","Approver-A approval present"]},
{"label":"G10","source_id":"SYN-NS-GOV-1","unit_type":"discretion","actor":"Approver-A","action":"refer","object":"any proposal for human review","conditions":[]},
{"label":"G11","source_id":"SYN-NS-GOV-1","unit_type":"prohibition","actor":null,"action":"treat referral as approval","object":null,"conditions":[]},
{"label":"P1","source_id":"SYN-NS-PROC-1","unit_type":"condition","actor":null,"action":"TEST_PURCHASE_HIGH","object":"approval","conditions":["Approver-A"]},
{"label":"A1","source_id":"SYN-NS-AMEND-2","unit_type":"condition","actor":null,"action":"TEST_PURCHASE_HIGH","object":"approval","conditions":["Approver-A","Approver-B"]},
{"label":"A2","source_id":"SYN-NS-AMEND-2","unit_type":"prohibition","actor":null,"action":"use as current evidence","object":"SYNTHETIC-NORTHSTAR-PROCEDURE-v1","conditions":[]}
]
}
44 changes: 44 additions & 0 deletions docs/decisions/OIC-OWNER-DECISION-004.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
# OIC Owner Decision 004 — First bounded semantic implementation

- Decision date: 2026-08-28
- Authorized base: `914830ceec70bde17004d2ccbbb13218ca44a89b`
- Scope: `BOUNDED SEMANTIC CODE START`
- Gate disposition: `OPEN` for the scope below only
- Authorized production path: `src/oic/candidate_extraction.py`
- Authorized sources: `SYN-NS-GOV-1`, `SYN-NS-PROC-1`, `SYN-NS-AMEND-2`

## Exact owner authorization

> I authorize the OIC semantic code-start gate to OPEN on
> Institutional-Compiler main at exact commit
> 914830ceec70bde17004d2ccbbb13218ca44a89b.
>
> This authorization permits bounded semantic implementation under
> TDD-OIC-001 v1.1 and the admitted gate constraints.
>
> It does not authorize institutional admission, runtime authorization,
> OCE execution, Rego/OPA execution, ZTL runtime integration, VEIP runtime
> integration, production claims, or benchmark claims unless separately
> authorized.

## Authorization boundary

- First authorized semantic production path: `src/oic/candidate_extraction.py`
- Authorized source IDs: `SYN-NS-GOV-1`, `SYN-NS-PROC-1`, `SYN-NS-AMEND-2`
- CA-3 semantic extraction: `NOT AUTHORIZED`
- Institutional admission: `NOT AUTHORIZED`
- Institutional IR: `NOT AUTHORIZED`
- OCE generation or execution: `NOT AUTHORIZED`
- Rego/OPA: `NOT AUTHORIZED`
- ZTL runtime: `NOT AUTHORIZED`
- VEIP runtime: `NOT AUTHORIZED`
- Production claims: `NOT AUTHORIZED`
- Benchmark claims: `NOT AUTHORIZED`

Candidate output remains extracted, uncertain, unadmitted, and without machine
confidence. The stale procedure remains visible as superseded. Network/model/API
dependencies and licensing or corpus-rights changes are not authorized. Global
manifest completeness remains `INCOMPLETE`.

This decision does not permit the evaluator or implementation to extend its own
scope. Further semantic paths or sources require a separate owner decision.
21 changes: 21 additions & 0 deletions docs/gates/OIC-SEMANTIC-CODE-START-GATE-OPEN-v0.1.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
{
"gate_id": "OIC-SEMANTIC-CODE-START-GATE-OPEN-v0.1",
"state": "OPEN",
"owner_decision": "docs/decisions/OIC-OWNER-DECISION-004.md",
"authorization_base_sha": "914830ceec70bde17004d2ccbbb13218ca44a89b",
"authorized_semantic_paths": ["src/oic/candidate_extraction.py"],
"authorized_source_ids": ["SYN-NS-GOV-1", "SYN-NS-PROC-1", "SYN-NS-AMEND-2"],
"authorized_scope": "SOURCE_TO_CANDIDATE_NORMATIVE_UNIT",
"forbidden_capabilities": [
"INSTITUTIONAL_ADMISSION",
"INSTITUTIONAL_IR",
"OPEN_CONTROL_ENVELOPE",
"POLICY_TARGET_GENERATION",
"RUNTIME_AUTHORIZATION",
"ZTL_RUNTIME",
"VEIP_RUNTIME",
"CA_3_SEMANTIC_EXTRACTION",
"NETWORK_MODEL_API_DEPENDENCY"
],
"global_manifest_status": "INCOMPLETE"
}
5 changes: 3 additions & 2 deletions docs/operations/FOUNDATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -265,8 +265,9 @@ enforcement artifact (none exists to produce).

## 8. Current limitations

- **This is not a compiler.** No semantic implementation exists. See `LIMITATIONS.md`.
- **The semantic implementation gate is BLOCKED** and nothing here opens it.
- **This is not a compiler.** One bounded synthetic candidate extractor exists.
- **The semantic code-start gate is OWNER-OPENED** only for that extractor and
those three synthetic sources; institutional admission remains blocked.
- **Preflight corpus provenance is OPEN.** `SOURCE_MANIFEST.csv` has no rows.
- **ZTL and VEIP are PROVISIONAL / NOT CONFIGURED.** Their interfaces are unfrozen
(ADR-009, ADR-010) and no adapter, container, or call exists.
Expand Down
4 changes: 2 additions & 2 deletions scripts/falsify_infrastructure.py
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,8 @@
"tests/contract/test_semantic_conformance.py::test_reject_duplicated_reason_codes",
),
(
"semantic code-start remains blocked",
"tests/contract/test_claims_discipline.py::test_operator_guide_states_the_semantic_gate_is_blocked",
"semantic code-start scope expansion rejection",
"tests/contract/test_semantic_code_start_gate_closure.py::test_owner_gate_refuses_allowlist_self_extension",
),
)

Expand Down
34 changes: 27 additions & 7 deletions scripts/verify_code_start_gate.py
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
#!/usr/bin/env python3
"""Fail-closed verifier for the non-semantic code-start evidence package."""
"""Fail-closed verifier for the owner-opened bounded semantic code-start gate."""

from __future__ import annotations

Expand Down Expand Up @@ -38,6 +38,9 @@
"src/oic/schemas.py",
}
)
OWNER_OPEN_BASE = "914830ceec70bde17004d2ccbbb13218ca44a89b"
OWNER_AUTHORIZED_SEMANTIC_PATHS = frozenset({"src/oic/candidate_extraction.py"})
AUTHORIZED_SOURCE_IDS = frozenset({"SYN-NS-GOV-1", "SYN-NS-PROC-1", "SYN-NS-AMEND-2"})


class GateEvidenceError(ValueError):
Expand All @@ -50,7 +53,7 @@ def _require(condition: bool, message: str) -> None:


def discover_unadmitted_production_paths(root: Path) -> list[str]:
"""Compare tracked ``src/oic`` paths with the immutable pre-gate baseline."""
"""Compare tracked paths with the immutable baseline plus owner allowlist."""
git = shutil.which("git")
if git is None:
raise GateEvidenceError("cannot enumerate tracked src/oic production paths")
Expand All @@ -63,8 +66,9 @@ def discover_unadmitted_production_paths(root: Path) -> list[str]:
if result.returncode != 0:
raise GateEvidenceError("cannot enumerate tracked src/oic production paths")
current = {line for line in result.stdout.splitlines() if line}
added = sorted(current - ADMITTED_SRC_OIC_PATHS)
missing = sorted(ADMITTED_SRC_OIC_PATHS - current)
admitted = ADMITTED_SRC_OIC_PATHS | OWNER_AUTHORIZED_SEMANTIC_PATHS
added = sorted(current - admitted)
missing = sorted(admitted - current)
return added + [f"MISSING:{path}" for path in missing]


Expand All @@ -74,6 +78,7 @@ def validate_evidence(
profile: dict[str, Any],
veip: dict[str, Any],
gate_text: str,
gate_record: dict[str, Any],
source_bytes: dict[str, bytes],
active_text: str,
semantic_paths: list[str] | None = None,
Expand Down Expand Up @@ -168,10 +173,23 @@ def validate_evidence(
"GLOBAL REPOSITORY COMPLETENESS" in normalized_gate and "INCOMPLETE" in normalized_gate,
"global incompleteness not explicit",
)
_require("READY FOR SEPARATE EXACT-HEAD REVIEW" in normalized_gate, "gate language invalid")
_require(
"READY FOR SEPARATE EXACT-HEAD REVIEW\nNOT OPEN" in normalized_gate, "gate language invalid"
gate_record.get("gate_id") == "OIC-SEMANTIC-CODE-START-GATE-OPEN-v0.1",
"wrong owner gate identity",
)
_require(not semantic_paths, "semantic implementation appeared before gate opening")
_require(gate_record.get("state") == "OPEN", "owner gate is not OPEN")
_require(gate_record.get("authorization_base_sha") == OWNER_OPEN_BASE, "wrong owner base SHA")
_require(
set(gate_record.get("authorized_semantic_paths", [])) == OWNER_AUTHORIZED_SEMANTIC_PATHS,
"gate production allowlist mismatch",
)
_require(
set(gate_record.get("authorized_source_ids", [])) == AUTHORIZED_SOURCE_IDS,
"gate source allowlist mismatch",
)
_require(gate_record.get("global_manifest_status") == "INCOMPLETE", "gate escalates manifest")
_require(not semantic_paths, "production path exceeds owner authorization")


def load_and_validate(root: Path) -> None:
Expand All @@ -186,6 +204,7 @@ def load(path: str) -> dict[str, Any]:
gate_text = (root / "docs/gates/OIC-SEMANTIC-CODE-START-GATE-CLOSURE-v0.1.md").read_text(
encoding="utf-8"
)
gate_record = load("docs/gates/OIC-SEMANTIC-CODE-START-GATE-OPEN-v0.1.json")
active_text = "\n".join(
(root / path).read_text(encoding="utf-8")
for path in (
Expand All @@ -204,6 +223,7 @@ def load(path: str) -> dict[str, Any]:
profile,
veip,
gate_text,
gate_record,
source_bytes,
active_text,
semantic_paths=semantic_paths,
Expand All @@ -216,4 +236,4 @@ def load(path: str) -> dict[str, Any]:
except (GateEvidenceError, OSError, KeyError, json.JSONDecodeError) as exc:
print(f"FAIL semantic code-start gate evidence: {exc}")
sys.exit(1)
print("PASS semantic code-start prerequisite evidence; gate remains NOT OPEN")
print("PASS semantic code-start gate is owner-opened for the exact bounded path and sources")
Loading