Skip to content

scientific(validation): bind each recovery replication to its RNG state and execution receipt #634

Description

@seonghobae

Scientific / provenance finding

#627 binds scientific-recovery authority to a versioned design profile that includes a seed-manifest SHA-256, and #633 binds authority to the exact grouped truth/recovery payload that passed the numerical gate. The surviving boundary still could not show which planned RNG state/seed entry and execution artifact produced each outer replication.

That left a reproducibility gap. Two runs could have the same profile, same planned seed-manifest digest, same exact-head test receipt, and both satisfy the same RMSE/Monte-Carlo gate while the association between outer replication i, its planned RNG state, and the concrete execution artifact was absent from promoted authority. recovery_evidence_sha256 proved payload content, not execution lineage.

Morris, White, and Crowther (2019, DOI 10.1002/sim.8086, §4.1) treats simulation studies as empirical experiments and recommends storing the random-number-generator state at the beginning of each repetition so failed repetitions can be reproduced and unintended dependence can be detected. TEPP already treats each outer element as one independent simulation repetition; the provenance contract must preserve the same unit.

RED → causal repair lineage

Canonical owner vehicle remains Draft #488.

  • source-level compile RED ee3484344e5cb65b0ff6853ec384c7559be78c69 introduced a typed per-replication execution receipt and a seventh public promotion argument. The predecessor public API had neither symbol nor parameter, so the contract cannot compile against it. Repair followed immediately; no hosted failing RED receipt is claimed.
  • causal production repair 9c2d41e8775d62331c8b320e99fd1fada96591aa adds ScientificRecoveryReplicationReceiptV1, canonical per-replication represented-payload SHA-256, receipt validation, duplicate planned seed-state refusal, and ordered aggregate replication_provenance_sha256 while leaving RMSE/MCSE/profile/exact-head/ADR-0014 arithmetic and authority gates unchanged.
  • public export 096d67cc5adf300a49d9e4b69e83e99fa8088bb6 exposes the typed receipt and payload helper.
  • existing recovery public contracts migrated ordinary-forward at 299a74bd14bca5549618b171490aacca3cefc932, e1b13941912c59d28b159a49c5d85535744973b2, b7768d6aba7fd38375690b08654a4af9a8798a8f, 01a6466053e5101ff6227cb5fb2f91d45db58418, 7b97ded81e8441ddaf6d22e8dd66c84c7bfcee05, and 831918de3536d51d241712d0e7db23db891f3691.
  • refusal/coverage contract 7cc8a26c0de66438c80e418c3ac2dce1973e2f7c exercises receipt count, index/order, profile, seed-manifest, payload, duplicate seed-state, finite/cardinality and canonical-digest refusal paths plus positive deterministic/change-sensitive provenance behavior.
  • current CHANGELOG exact head 252b25298af4d574e363e342e056559772976402 records the owner boundary.

Current contract

ScientificRecoveryReplicationReceiptV1 binds:

  • zero-based replication index;
  • exact recovery-profile SHA-256;
  • exact profile seed-manifest SHA-256;
  • canonical SHA-256 of the planned seed/RNG-state entry for that repetition;
  • canonical SHA-256 of the immutable execution artifact for that repetition;
  • canonical SHA-256 of the exact represented truth/recovery payload for that repetition;
  • a derived domain-separated receipt identity over those fields.

Promotion requires receipt count to equal planned_replications, positional index i to correspond to outer repetition i, exact profile/manifest identities to match the promoted profile, payload digest to equal the owner-recomputed digest of truth[i]/recovered[i], and planned seed-state identities to be unique across independent repetitions. Successful authority retains an ordered aggregate replication_provenance_sha256 beside profile, exact-head receipt, and grouped recovery-payload identities.

Boundary / remaining gaps

This repair deliberately does not call the receipt a cryptographic execution attestation or seed-manifest membership proof. Seed-state and execution-artifact digests remain trusted-adapter inputs. Signed/verifiable exact-head CI attestation, immutable pre-execution profile registration/approval chronology, verifiable membership of each seed-state entry in the declared seed manifest, and proof that the named execution artifact was produced from that state remain subsequent hardening gaps.

Current gate

#488 exact head is 252b25298af4d574e363e342e056559772976402, Draft/open/mergeable on protected main@a243f18da4a4ca8a8d068c39922537f1f8ed6ad0, ordinary-forward ahead 929 / behind 0. Current Documentation/Rust/Security/Semgrep/CodeQL/Bias-SE workflows are non-terminal and no qualifying current-head APPROVED review exists. Keep Draft and do not transfer predecessor receipts.

Keep this issue open through exact-head Rust/rustdoc/owned line+branch coverage/security/CodeQL/proof-budget, qualifying independent review, normal #492 prerequisite/protected-main integration, and code-current #435 TRACEABILITY/product-gap authority.

Refs #488 #625 #626 #627 #630 #631 #633 #492.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions