Research: qualify trusted authority-adapter seam RC2 - #78
Draft
camerontjs-dot wants to merge 14 commits into
Draft
camerontjs-dot wants to merge 14 commits into
camerontjs-dot wants to merge 14 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Classification
Draft Research only. Do not merge as a maintained runtime change, tag, release, or infer production readiness from this PR.
This successor is stacked on Draft Research PR #77 / terminal
97727a7d2f61c46b4e7ef3e11279fb0af7b915cd. It changes no maintainedsrc/**,scripts/**, ortests/**bytes.Question
Can materially different trusted authority domains converge on one unchanged post-admission Decision seam without making the projection kernel domain-aware or allowing callers to move the trust anchor?
Terminal disposition
SUPPORTED_TRUSTED_AUTHORITY_ADAPTER_SEAMDecisive execution:
360dc46d6b6e510d8ce36fa06f2fb0de5ff473723523269826310524062969410501967992sha256:745346b1dc7530d9f362b89daeea52edfbe6c20dfe44cdf59f6f2187d8c9116974dee690eab4841a5f363d6538dc6d5ecee93051d60b4eaa3bab60a64fa98f49e12d53020b3a6a046f4ee7688db0a5ea5c5e0a63e758b1c1e5711e7b227759e3Observed result
All four preregistered phases passed:
The deliberately weak controls remained unsafe as expected: direct caller control of the raw kernel policy registry changed a Decision under the same policy ID/version, and caller selection of the signature verification key accepted an attacker signature. This is causal evidence that adapter/policy implementation and trust-root selection must remain trusted machinery.
Supported boundary
The common seam begins after authority admission. This PR does not establish a universal raw-ingress schema or plugin system.
Preserved failure
The first hosted run
35232390053/ job105239555259is preserved asAPPARATUS_LEGACY_DIGEST_PREFIX_ASSERTION_DEFECT. The frozen manifest scientific runner printed PASS, but a wrapper compared prefixed and bare SHA representations and stopped before the new Phase C/D harness. The decisive successor changed only that mechanical representation check via a preserved-harness wrapper/workflow correction.Remaining boundaries
See
research/authority-adapter-seam-rc2/RESULT.mdfor the complete terminal record.