Skip to content

Maintenance: pin Contract C authority root regression - #52

Merged
camerontjs-dot merged 1 commit into
mainfrom
maintenance/contract-c-authority-root-regression-20260909
Sep 10, 2026
Merged

camerontjs-dot merged 1 commit into
mainfrom
maintenance/contract-c-authority-root-regression-20260909

Conversation

@camerontjs-dot

@camerontjs-dot camerontjs-dot commented Sep 10, 2026

Copy link
Copy Markdown
Owner

Classification

Maintenance / regression-only hardening. No Decision policy semantics, Contract C/D contract behavior, Authorization, execution, release, or production default change.

Exact base

main@a4425f8eb47449ff6c683222921bbea9483742e2

Evidence basis

Draft research PR #51 mutation-audited ten load-bearing Decision Engine faults. Existing maintained integrations killed 9/10. The survivor removed exact Contract C authority-root verification from src/contractCIngress.js; all maintained CAL Decision integrations still passed, while a research wrong-authority control killed the mutant.

Smallest change

One maintained integration test only: tests/decisionEvaluateCli.integration.mjs.

The CLI helper permits an explicit Contract C authority root for negative controls. The new control deliberately supplies the exact released Contract D checkout as the Contract C authority root. That checkout is from the same apparatus repository and still contains compatible Contract C validation machinery, but it is not the exact released Contract C authority identity. Correct ingress rejects it with authority_identity_mismatch and emits no Decision bytes.

Verification

Exact candidate head: ff4783aa55e63f3ca098d2f54884b43b96fee31f.

  • CI & Repository Hygiene Verification run 34430551382: SUCCESS.
  • Contract-first Decision evaluate CLI conformance run 34430551350: SUCCESS.

The targeted conformance reran both maintained policies, the shared runtime/CLI integration, exact Contract D independent consumption, and tracked-mutation checks.

Disposition

SUPPORTED FOR REGRESSION-ONLY MAINTENANCE.

This promotes only the cheap falsifier demonstrated by PR #51. It does not promote any research policy or ingress architecture.

Non-claims

@camerontjs-dot
camerontjs-dot marked this pull request as ready for review September 10, 2026 02:45
@camerontjs-dot
camerontjs-dot merged commit 358c2bb into main Sep 10, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant