Research: pressure C2 authority boundary at Decision ingress - #76
Draft
camerontjs-dot wants to merge 4 commits into
Draft
camerontjs-dot wants to merge 4 commits into
camerontjs-dot wants to merge 4 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Classification
Draft Research / authority-boundary hardening. Keep Draft. Do not merge as production.
No maintained
src/**,scripts/**, ortests/**mutation occurred. No Contract C2/D mutation, CAL change, Decision policy expansion, Authorization, execution, tag, release, or production-default change is authorized.Terminal status
Research disposition:
SUPPORTED_WITH_BOUNDARY.Terminal record:
research/c2-authority-boundary-hardening-rc0/RESULT.mdDecisive frozen science head:
bee53b481dbeac6c225899a5e1c0c188504a0d67Decisive hosted evidence:
35185025913— SUCCESS;105085123610— SUCCESS;10481498841;sha256:801b0d61a788817b2e8231dd7f130549727c679985133f843aa63df80d829018.Exact stacked subject
This research is stacked on the C2 integration specimen because the completed CAL Pipeline run used that path:
b1bcc33e2b5ef0707b8cbf7dd8e821b2d34d1b55;7be709b2141c767c5da89b8b94cf90233c4238fe;b42c827acb0a9fe65353354d709add0e27bab307;2.0.0;contract-c-successor-candidate-a-rc2-research.The branch changes research apparatus/records only. Exact-head workflow scope checks verified maintained Decision bytes unchanged before the decisive run.
Observed result
The preregistered baseline passed both current Decision ingress and exact canonical C2
verify_candidate(...).Four validator-valid, freshly resealed substitutions were then tested:
For all four:
CLEAR;The rejection reasons were the intended authority discriminators: missing exact Contract-B evidence reference, wrong resolver authority, or unknown/ambiguous implementation-policy binding.
Collusion control
The same canonical verifier accepted mutated objects when its external evidence-index / resolver authority inputs were deliberately changed to collude with the mutation.
Therefore the result does not justify simply adding more caller-supplied verifier arguments to Decision ingress. The external authority inputs must themselves be independently bound or derived from authoritative artifacts.
Bounded inference
The current C2 Decision policy kernel was not falsified. The hardening gap is immediately before it.
Current C2 ingress establishes exact C2 bytes/authority and top-level Contract-B identity, but does not independently establish the full Contract-B participant-reference authority or immutable producer-policy resolver binding that canonical C2 is capable of checking.
This does not show that the completed pipeline's observed HOLD was wrong, that CAL semantics are wrong, or that any current source claim is false. It identifies a downstream authority aperture that becomes material if Decision Engine is expected to independently establish those references before issuing a Decision.
Next discriminator
Do not modify maintained C2 ingress from this result alone.
The next bounded experiment is to derive the strict verifier inputs from independent authority rather than caller declarations:
If an independently reconstructable authority source does not exist, that is a cross-component authority requirement rather than permission for Decision Engine to invent one.
Full preregistration and exact observations are preserved in the research directory. No promotion is authorized by this PR.