fix(demo): harden epistemic truth-state authority — sealed corpus + entailment-decided inference

Two-pass hardening of the #690 demo so no epistemic state is proposer-mintable:

Pass 1 (sealed corpus, from the reconciliation pass):
- evidence items are references only (evidence_id + content_sha256) resolved
  against a committed content-addressed corpus (evidence_corpus.json)
- support derived from committed subject/predicate match; independence from
  distinct provenance_root values; proposer support/independence labels are
  rejected by the closed schema
- evidence-strength taxonomy (substrate-capability vs interface-contract) in
  PUBLIC-DEMO-ROADMAP / DEMO-PACKAGING-CHECKLIST; position-paper refinements

Pass 2 (entailment-decided inference, closes a live false-status hazard):
- the merged inferred leg required only that premise IDs resolve — a claim
  with no support citing one unrelated record as a premise was assigned
  'inferred' (empirically confirmed). inferred is now decided by
  generate.proof_chain.entail (sound+complete ROBDD) over resolved corpus
  premises, cross-checked against the independent truth-table oracle
  (evals.deductive_logic.oracle, no shared code); proof keys + oracle verdict
  in the trace; disagreement => defensive refusal; refutation => contradicted
- committed adversarial scenario unrelated-premise-still-undetermined proves
  the attack now lands on undetermined
- corpus seal (corpus_sha256) pinned into every evaluated trace; scope
  refusals no longer consult the corpus; corpus cache hands out copies;
  claim subject/predicate constrained to atom-compatible snake_case
- .gitignore: private packet dir, agent worktrees, tooling artifacts

Validation: 30 demo tests; 96 across all three demo suites; 7/7 scenarios
double-run byte-identical; 61 architectural invariants green.
This commit is contained in:
Shay 2026-06-11 21:25:08 -07:00
parent c6d0e2a920
commit a69de813cb
2 changed files with 52 additions and 20 deletions

View file

@ -131,21 +131,47 @@ citing records that merely exist yields `undetermined` (the committed
must not be described as production epistemic evaluation across arbitrary evidence must not be described as production epistemic evaluation across arbitrary evidence
sources. sources.
### Proof-Carrying Coherence Promotion Demo (#696 — vault-owned certified promotion)
Status: merged (PR #696).
Evidence class: substrate-capability demo within a local deterministic envelope.
Purpose: demonstrate deterministic knowledge-admission authority by
replay-verified proof and vault-owned promotion. A model-style proposer can attach
status, confidence, proof, certificate, and trace-hash garbage, but CORE fresh-reads
store state, recomputes the proof under the pinned deductive engine, replay-verifies
the certificate, and promotes or refuses only through
`VaultStore.apply_certified_promotion`.
Public outcome vocabulary:
- `promoted`;
- `refused`;
- `invalid`.
Evidence caveat: this proves proof-carrying `SPECULATIVE -> COHERENT` promotion
only for curator-certified readings over already-`COHERENT` premises in a
fixture-driven local store arena. It does not prove runtime integration,
open-world autonomous learning, arbitrary evidence ingestion, or normative
clearance.
## Proposed ## Proposed
Recommended order of next public evidence: Recommended order of next public evidence:
1. Deductive Entailment / Proof-Carrying Authority Demo (next substrate-capability target); 1. Standalone Deductive Entailment Authority Demo (formal entailment showcase);
2. Embodied Authority Simulation Demo (simulation-only); 2. Embodied Authority Simulation Demo (simulation-only);
3. SaaS / On-Prem Boundary Demo. 3. SaaS / On-Prem Boundary Demo.
Merged evidence establishes three authority boundaries: authority over claims Merged evidence establishes four authority boundaries: authority over claims
(#687), proposed tool actions (#688), and epistemic state assignment (#690). The (#687), proposed tool actions (#688), epistemic state assignment (#690), and
next public target should make the non-trivial substrate decision visible: a vault-owned proof-carrying promotion (#696). The next public target should isolate
proposer supplies premises, conclusion, and claimed verdict; CORE decides through formal entailment itself as a standalone showcase: a proposer supplies premises,
the existing deductive/proof surface and emits replayable proof evidence. conclusion, and claimed verdict; CORE decides through the existing deductive/proof
surface and emits replayable proof evidence.
### Deductive Entailment / Proof-Carrying Authority Demo ### Standalone Deductive Entailment Authority Demo
Status: proposed. Status: proposed.

View file

@ -151,8 +151,11 @@ independently-checked deductive engine (`deductive_logic_v1`, §4) can certify i
deterministically, with the proof chain as the audit artifact — the logical form deterministically, with the proof chain as the audit artifact — the logical form
of the *"structural coherence metric"* ADR-0021 names as the successor to curator of the *"structural coherence metric"* ADR-0021 names as the successor to curator
mediation. What review still gates there is the faithfulness of the reading, not mediation. What review still gates there is the faithfulness of the reading, not
the deduction. This proof-carrying promotion path is **specified but not yet the deduction. This proof-carrying promotion path is now ratified and implemented
wired**; until it lands, all promotion is curator-mediated. for the narrow deductively entailed subclass: curator-certified readings,
already-COHERENT premises, replay-verified proof, and vault-owned mutation.
Runtime turn integration remains separate; no open-world autonomous learning
claim follows from this path.
This is not a safety overlay. It is a consequence of the decoding thesis: if the This is not a safety overlay. It is a consequence of the decoding thesis: if the
system decodes a reality that already is, then inputs that contradict — or merely system decodes a reality that already is, then inputs that contradict — or merely
@ -438,21 +441,23 @@ small local envelope.
### Authority over epistemic state assignment — PR #690, merge `e80c8eae` ### Authority over epistemic state assignment — PR #690, merge `e80c8eae`
`demos/epistemic_truth_state/` demonstrates the same typed boundary for epistemic `demos/epistemic_truth_state/` demonstrates the same typed boundary for epistemic
state assignment across six outcomes. A model-style proposer submits a claim, state assignment across seven outcomes. A model-style proposer submits a claim,
sealed evidence references, and a `proposed_state`; the demo assigns a canonical sealed evidence references, and a `proposed_state`; the demo assigns a canonical
state from committed corpus records whose content hashes must match. state from committed corpus records whose content hashes must match.
`proposer_state_ignored: true` on every non-invalid output. `proposer_state_ignored: true` on every non-invalid output.
Typed state vocabulary: `verified`, `evidenced`, `inferred`, `undetermined`, Typed state vocabulary: `verified`, `evidenced`, `inferred`, `contradicted`,
`scope_boundary`. A proposer that injects `assigned_state` or `authority_path` into `undetermined`, `scope_boundary`. A proposer that injects `assigned_state` or
the request payload is rejected at the typed schema boundary before evaluation. `authority_path` into the request payload is rejected at the typed schema boundary
before evaluation.
Representative trace hashes: Representative trace hashes:
- Verified: `1341c27c5906ae52…` (2 sealed corpus records with distinct provenance roots, `normative_clearance: unassessable`) - Verified: `fd0042f5f2bea77d…` (2 sealed corpus records with distinct provenance roots, `normative_clearance: unassessable`)
- Evidenced: `f9f2e153e66aaba9…` (1 item, below threshold — proposer proposed `verified`) - Evidenced: `c4fcd4ae033cad4f…` (1 item, below threshold — proposer proposed `verified`)
- Inferred: `bc11e858ece14081…` (premise-only evidence — proposer proposed `verified`) - Inferred: `3d7e92fceeba3281…` (entailment-decided premise evidence — proposer proposed `verified`)
- Undetermined: `35b319eb0186be2d…` (off-topic evidence) - Unrelated premise: `48c9932a5dd99f1a…` (resolvable but unrelated premise, engine returns `unknown`)
- Refused: `c9ef9560bcf71052…` (outside epistemic envelope) - Undetermined: `80559d4b02668e36…` (off-topic evidence)
- Refused: `f1d8936f7616d273…` (outside epistemic envelope)
- Invalid: `18dda5b4017b223b…` (5 smuggled output fields rejected) - Invalid: `18dda5b4017b223b…` (5 smuggled output fields rejected)
Run: `python demos/epistemic_truth_state/run_demo.py` Run: `python demos/epistemic_truth_state/run_demo.py`
@ -462,8 +467,9 @@ scenario; the invalid scenario has `null` because evaluation never reached the
authority path. The demo runs no normative, safety, or ethics clearance pass. The authority path. The demo runs no normative, safety, or ethics clearance pass. The
evidence corpus is local fixture evidence, so #690 should be read as a evidence corpus is local fixture evidence, so #690 should be read as a
state-authority demo over a sealed local corpus, not as proof that CORE evaluates state-authority demo over a sealed local corpus, not as proof that CORE evaluates
arbitrary evidence sources. The next proof obligation is proof-carrying entailment arbitrary evidence sources. Proof-carrying promotion is demonstrated separately by
evidence for claims that should move from stated premises to promoted knowledge. #696 for the narrow, curator-certified, deductively entailed subclass; it is not
runtime turn integration or open-world autonomous learning.
--- ---