Skip to content

Commit 01660ac

Browse files
author
liushiao
committed
docs(LGT-021): declare context materialization seams
1 parent f784b8b commit 01660ac

5 files changed

Lines changed: 59 additions & 17 deletions

File tree

.legatura/contracts/context-kernel-interface.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,19 +9,19 @@
99
"claims": [
1010
{
1111
"id": "context-materialization-binds-exact-authorized-bytes",
12-
"statement": "Given one logical compiled Context Capsule, its frozen Git-visible path inventory, and one matching opaque Assurance Runtime Repository Source Product, Context Kernel emits a bounded canonical content-addressed manifest and process-local delivery whose ordered concrete regular-file entries exactly cover the authorized initial read scope; missing, extra, cross-repository, drifted, escaping, ambiguous, symlink, non-regular, unreadable, duplicate, malformed, forged, serialized, or over-limit source facts fail closed."
12+
"statement": "Given one closed create input whose canonical Worker Work Specification and compiler-owned Change and Context bindings agree, Project Model alone expands the logical compiled Context Capsule over its frozen Git-visible inventory into one exact canonical UTF-8-byte-sorted concrete read plan and materialization-plan digest, and Context Kernel binds that digest into immutable Session context, consumes one matching live Assurance Runtime Repository Source Product only through the process-local options seam, and preserves its exact body-free projection and digest formulas to emit a bounded canonical content-addressed manifest and distinct process-local controller and delivery products; missing, extra, cross-repository, drifted, escaping, ambiguous, symlink, non-regular, unreadable, duplicate, unsorted, malformed, forged, serialized, caller-classified, or over-limit source, scope, Change, Context, or Worker facts fail closed."
1313
},
1414
{
1515
"id": "context-expansion-is-recorded-before-content-disclosure",
16-
"statement": "Every Context Expansion resolution made with the exact live controller Session product appends one successor Session and settlement bound to the exact execution, request, prior Session, stable source product, and Project Model impact product, atomically consumes the prior controller product, and returns a successor controller product; a grant commits exact process-lifetime blob state and compare-and-swap lineage before minting any newly authorized delivery, while denial or compiler-derived redundancy discloses no new bytes and persistence failure, stale binding, replay, partial grant, or scope broadening leaves the prior Session and controller current."
16+
"statement": "Every resolution accepts only one canonical Worker Context Expansion Request plus a controller choice of grant or deny in its closed ordinary input and the exact live controller Session and full-proposal Repository Source Products through its process-local options seam. Context Kernel derives the canonical UTF-8-byte-sorted proposal as prior disclosed paths union the original requested paths and classifies the request by exact set relation: a fully contained request becomes redundant and supplies an empty disclosure delta to Project Model, a disjoint request supplies its exact requested paths, and mixed overlap fails closed. Project Model compiles one neutral Context Impact from that disclosure delta and the full proposal projection; Context Kernel requires the proposal repository identity, Git content, tracked-path facts, and every prior manifest entry to equal the prior materialization and its six-field source binding to equal the Context Impact repositorySourceBinding field-for-field. A grant reads and commits only newly disclosed bytes, adopts the exact full proposal as successor materialization, and compare-and-swaps lineage before consuming the prior controller or minting delivery; denial and redundancy only project the body-free full proposal, preserve the prior materialization exactly, and append successors without reading or disclosing new bytes or minting delivery, while failed blob or lineage persistence leaves the prior Session and controller current, mints no delivery, and permits at most unreachable content-addressed blob residue from a completed blob commit."
1717
},
1818
{
1919
"id": "context-expansion-resolutions-cannot-be-worker-self-granted",
20-
"statement": "A Worker-authored Context Expansion Request remains inert: resolution authority is possession of an opaque process-local controller Session product passed only through a process-local options seam, minted for the exact Context Kernel instance and current Session, and retained outside Worker input; no request, report, observation, Execution Record, digest, plain Session record, proxy, deserialized value, caller identity, or caller-supplied grant, successor, source, scope, materialization, or impact can mint, rehydrate, or substitute that product."
20+
"statement": "A Worker-authored Context Expansion Request and serializable grant or deny choice remain inert: Worker Interface validation proves only the request's canonical self-declared bindings, including priorRecordDigest, and does not prove Worker Record currency or settle that Record; resolution authority is possession of an opaque process-local controller Session product passed only through the options seam, minted for the exact Context Kernel instance and current Session, retained outside Worker input, and consumed only after a successful lineage compare-and-swap. Controller, delivery, Repository Source, and Project Model ownership products are distinct WeakMap-branded process-local values and never ordinary document fields; no request, report, observation, Execution Record, digest, plain Session record, proxy, clone, deserialized value, caller identity, delivery product, or caller-supplied successor, source, scope, materialization, disposition, or impact can mint, rehydrate, or substitute resolution authority."
2121
},
2222
{
2323
"id": "context-session-lineage-is-append-only-and-non-authoritative",
24-
"statement": "Context Session records preserve exact previous and next materialization and Context Impact digests plus granted, denied, or redundant settlement facts, while source bodies remain out of coordination records and no Context fact creates Evidence, Knowledge Closure, Outcome or Claim satisfaction, an Authority Decision, capability enforcement, semantic code impact, or Change acceptance."
24+
"statement": "A Context Session is one closed schema-versioned self-digested ordinary document whose deterministic lineageRef binds exact execution, Change, and immutable Context bindings: the initial Session has sequence zero, null priorSessionDigest, and expected-null compare-and-swap, while every successor preserves lineageRef, increments sequence by one, names the current Session digest as priorSessionDigest and compare-and-swap expectation, and becomes current only on that exact append. It otherwise contains only one body-free source binding and ordered path-length-content-digest materialization, an absent initial resolution or one exact request, controller-decision, granted, denied, or redundant disposition, full proposal-source, neutral Context Impact, and realized disclosure-delta binding, plus acceptanceAuthority false. Source bodies and every opaque product remain outside Session, Worker Execution, Change, Store, HTTP, CLI, and Profile records; no Context fact creates Evidence, Knowledge Closure, Outcome or Claim satisfaction, an Authority Decision, capability enforcement, semantic code impact, score, confidence, or Change acceptance."
2525
},
2626
{
2727
"id": "context-kernel-proof-rejects-source-scope-and-settlement-attacks",

.legatura/contracts/project-model-interface.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,9 +23,13 @@
2323
"id": "context-capsule-binds-validated-path-ownership",
2424
"statement": "Generated Context Capsule write scope is projected only from an opaque, exact-Model-and-path-facts-bound ownership product for the primary Module; absent, forged, stale, ambiguous, disposition-only, or over-limit input fails closed."
2525
},
26+
{
27+
"id": "context-materialization-plan-is-derived-from-frozen-sources",
28+
"statement": "Given only a frozen Project Model, one logical compiled Context Capsule, exact tracked-path facts, and the matching opaque path-ownership product, Project Model expands the Capsule read selectors into one bounded canonical document with kind context-materialization-plan whose exact concrete pathRefs are canonical UTF-8-byte sorted and bound by pathSetDigest, whose readScopeDigest and writeScopeDigest reproduce the Capsule bindings, and whose discriminated owner-or-disposition path facts, Contract-surface facts, and materializationPlanDigest are compiler-derived; Context Kernel consumes that document and never parses selectors or invents structural classifications."
29+
},
2630
{
2731
"id": "context-expansion-impact-is-derived-from-frozen-sources",
28-
"statement": "Given a frozen Project Model, its opaque exact path-ownership product, an exact prior-disclosed path list and digest, requested concrete paths, and a stable repository source binding, Project Model derives the exact newly disclosed path owners, Contract relations, Assurance crossings, disposition references, and Context Impact digest; Context Session objects and worker or caller supplied owner, Module, Contract, assurance, semantic-impact, or verification classifications cannot substitute those neutral inputs or facts."
32+
"statement": "Given a frozen Project Model, its opaque exact path-ownership product, exact priorDisclosedPaths and priorDisclosedPathsDigest, canonical requested disclosure-delta paths, and the exact self-consistent Repository Source projection v1 produced by Assurance Runtime, Project Model validates that the projection tracked-path-facts digest matches the ownership product and that its canonical UTF-8-byte-sorted manifest pathRefs exactly equal the canonical union of prior and requested paths, then emits one ordinary self-sealed document with kind context-expansion-impact and an exact body-free repositorySourceBinding containing repositoryIdentityDigest, gitContentDigest, trackedPathFactsDigest, pathSetDigest, manifestDigest, and productDigest. requestedPathRefs and newlyDisclosedPathRefs are identical, while pathFacts, Contract relations, Assurance crossings, and disposition references describe only that disclosure delta; a canonical empty delta is valid, any non-empty requested set must be disjoint from priorDisclosedPaths, and any already-disclosed requested path fails closed. Context Session objects and worker or caller supplied classifications cannot substitute those neutral inputs or facts."
2933
},
3034
{
3135
"id": "context-expansion-impact-proof-rejects-binding-and-classification-attacks",

.legatura/gates/path-ownership.json

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -97,6 +97,32 @@
9797
"The selector grammar is deliberately restricted to exact paths and literal recursive prefixes rather than general glob intersection."
9898
]
9999
},
100+
{
101+
"id": "context-materialization-plan-proof",
102+
"appliesTo": ["project-model"],
103+
"command": ["node", "--test", "test/project-model/context-materialization.test.mjs"],
104+
"timeoutMs": 120000,
105+
"claimRefs": ["context-materialization-plan-is-derived-from-frozen-sources"],
106+
"oracle": {
107+
"kind": "node-test-runner-exit",
108+
"description": "The fixed Project Model Context materialization-plan compilation and attack scenario must exist and exit zero."
109+
},
110+
"applicability": {
111+
"phase": "acceptance",
112+
"purpose": "context-materialization-plan-proof"
113+
},
114+
"discriminatoryPower": {
115+
"rejects": [
116+
"initial concrete read materialization derived by a consumer parsing Module selectors or supplying owner, disposition, or Contract-surface classifications",
117+
"a materialization plan with the wrong literal kind, non-canonical path order, mismatched read or write scope digest, mismatched path-set formula, forged structural facts, or a non-self-sealing materializationPlanDigest",
118+
"a forged, serialized, wrong-Model, stale-path-facts, duplicate, malformed, unowned, disposition-only, selector-broadened, or over-limit input"
119+
]
120+
},
121+
"residualUncertainty": [
122+
"The materialization plan proves canonical structural selection from tracked-path facts; Assurance Runtime separately proves the stability and exact bytes of the matching Repository Source Product.",
123+
"The proof does not enforce filesystem access, infer semantic code impact, or decide Evidence, authority, or acceptance."
124+
]
125+
},
100126
{
101127
"id": "context-expansion-impact-proof",
102128
"appliesTo": ["project-model"],

0 commit comments

Comments
 (0)