Scientific / provenance finding
#627 binds scientific-recovery authority to a versioned design profile that includes a seed-manifest SHA-256, and #633 binds authority to the exact grouped truth/recovery payload that passed the numerical gate. The surviving boundary still could not show which planned RNG state/seed entry and execution artifact produced each outer replication.
That left a reproducibility gap. Two runs could have the same profile, same planned seed-manifest digest, same exact-head test receipt, and both satisfy the same RMSE/Monte-Carlo gate while the association between outer replication i, its planned RNG state, and the concrete execution artifact was absent from promoted authority. recovery_evidence_sha256 proved payload content, not execution lineage.
Morris, White, and Crowther (2019, DOI 10.1002/sim.8086, §4.1) treats simulation studies as empirical experiments and recommends storing the random-number-generator state at the beginning of each repetition so failed repetitions can be reproduced and unintended dependence can be detected. TEPP already treats each outer element as one independent simulation repetition; the provenance contract must preserve the same unit.
RED → causal repair lineage
Canonical owner vehicle remains Draft #488.
- source-level compile RED
ee3484344e5cb65b0ff6853ec384c7559be78c69 introduced a typed per-replication execution receipt and a seventh public promotion argument. The predecessor public API had neither symbol nor parameter, so the contract cannot compile against it. Repair followed immediately; no hosted failing RED receipt is claimed.
- causal production repair
9c2d41e8775d62331c8b320e99fd1fada96591aa adds ScientificRecoveryReplicationReceiptV1, canonical per-replication represented-payload SHA-256, receipt validation, duplicate planned seed-state refusal, and ordered aggregate replication_provenance_sha256 while leaving RMSE/MCSE/profile/exact-head/ADR-0014 arithmetic and authority gates unchanged.
- public export
096d67cc5adf300a49d9e4b69e83e99fa8088bb6 exposes the typed receipt and payload helper.
- existing recovery public contracts migrated ordinary-forward at
299a74bd14bca5549618b171490aacca3cefc932, e1b13941912c59d28b159a49c5d85535744973b2, b7768d6aba7fd38375690b08654a4af9a8798a8f, 01a6466053e5101ff6227cb5fb2f91d45db58418, 7b97ded81e8441ddaf6d22e8dd66c84c7bfcee05, and 831918de3536d51d241712d0e7db23db891f3691.
- refusal/coverage contract
7cc8a26c0de66438c80e418c3ac2dce1973e2f7c exercises receipt count, index/order, profile, seed-manifest, payload, duplicate seed-state, finite/cardinality and canonical-digest refusal paths plus positive deterministic/change-sensitive provenance behavior.
- current CHANGELOG exact head
252b25298af4d574e363e342e056559772976402 records the owner boundary.
Current contract
ScientificRecoveryReplicationReceiptV1 binds:
- zero-based replication index;
- exact recovery-profile SHA-256;
- exact profile seed-manifest SHA-256;
- canonical SHA-256 of the planned seed/RNG-state entry for that repetition;
- canonical SHA-256 of the immutable execution artifact for that repetition;
- canonical SHA-256 of the exact represented truth/recovery payload for that repetition;
- a derived domain-separated receipt identity over those fields.
Promotion requires receipt count to equal planned_replications, positional index i to correspond to outer repetition i, exact profile/manifest identities to match the promoted profile, payload digest to equal the owner-recomputed digest of truth[i]/recovered[i], and planned seed-state identities to be unique across independent repetitions. Successful authority retains an ordered aggregate replication_provenance_sha256 beside profile, exact-head receipt, and grouped recovery-payload identities.
Boundary / remaining gaps
This repair deliberately does not call the receipt a cryptographic execution attestation or seed-manifest membership proof. Seed-state and execution-artifact digests remain trusted-adapter inputs. Signed/verifiable exact-head CI attestation, immutable pre-execution profile registration/approval chronology, verifiable membership of each seed-state entry in the declared seed manifest, and proof that the named execution artifact was produced from that state remain subsequent hardening gaps.
Current gate
#488 exact head is 252b25298af4d574e363e342e056559772976402, Draft/open/mergeable on protected main@a243f18da4a4ca8a8d068c39922537f1f8ed6ad0, ordinary-forward ahead 929 / behind 0. Current Documentation/Rust/Security/Semgrep/CodeQL/Bias-SE workflows are non-terminal and no qualifying current-head APPROVED review exists. Keep Draft and do not transfer predecessor receipts.
Keep this issue open through exact-head Rust/rustdoc/owned line+branch coverage/security/CodeQL/proof-budget, qualifying independent review, normal #492 prerequisite/protected-main integration, and code-current #435 TRACEABILITY/product-gap authority.
Refs #488 #625 #626 #627 #630 #631 #633 #492.
Scientific / provenance finding
#627 binds scientific-recovery authority to a versioned design profile that includes a seed-manifest SHA-256, and #633 binds authority to the exact grouped truth/recovery payload that passed the numerical gate. The surviving boundary still could not show which planned RNG state/seed entry and execution artifact produced each outer replication.
That left a reproducibility gap. Two runs could have the same profile, same planned seed-manifest digest, same exact-head test receipt, and both satisfy the same RMSE/Monte-Carlo gate while the association between outer replication
i, its planned RNG state, and the concrete execution artifact was absent from promoted authority.recovery_evidence_sha256proved payload content, not execution lineage.Morris, White, and Crowther (2019, DOI
10.1002/sim.8086, §4.1) treats simulation studies as empirical experiments and recommends storing the random-number-generator state at the beginning of each repetition so failed repetitions can be reproduced and unintended dependence can be detected. TEPP already treats each outer element as one independent simulation repetition; the provenance contract must preserve the same unit.RED → causal repair lineage
Canonical owner vehicle remains Draft #488.
ee3484344e5cb65b0ff6853ec384c7559be78c69introduced a typed per-replication execution receipt and a seventh public promotion argument. The predecessor public API had neither symbol nor parameter, so the contract cannot compile against it. Repair followed immediately; no hosted failing RED receipt is claimed.9c2d41e8775d62331c8b320e99fd1fada96591aaaddsScientificRecoveryReplicationReceiptV1, canonical per-replication represented-payload SHA-256, receipt validation, duplicate planned seed-state refusal, and ordered aggregatereplication_provenance_sha256while leaving RMSE/MCSE/profile/exact-head/ADR-0014 arithmetic and authority gates unchanged.096d67cc5adf300a49d9e4b69e83e99fa8088bb6exposes the typed receipt and payload helper.299a74bd14bca5549618b171490aacca3cefc932,e1b13941912c59d28b159a49c5d85535744973b2,b7768d6aba7fd38375690b08654a4af9a8798a8f,01a6466053e5101ff6227cb5fb2f91d45db58418,7b97ded81e8441ddaf6d22e8dd66c84c7bfcee05, and831918de3536d51d241712d0e7db23db891f3691.7cc8a26c0de66438c80e418c3ac2dce1973e2f7cexercises receipt count, index/order, profile, seed-manifest, payload, duplicate seed-state, finite/cardinality and canonical-digest refusal paths plus positive deterministic/change-sensitive provenance behavior.252b25298af4d574e363e342e056559772976402records the owner boundary.Current contract
ScientificRecoveryReplicationReceiptV1binds:Promotion requires receipt count to equal
planned_replications, positional indexito correspond to outer repetitioni, exact profile/manifest identities to match the promoted profile, payload digest to equal the owner-recomputed digest oftruth[i]/recovered[i], and planned seed-state identities to be unique across independent repetitions. Successful authority retains an ordered aggregatereplication_provenance_sha256beside profile, exact-head receipt, and grouped recovery-payload identities.Boundary / remaining gaps
This repair deliberately does not call the receipt a cryptographic execution attestation or seed-manifest membership proof. Seed-state and execution-artifact digests remain trusted-adapter inputs. Signed/verifiable exact-head CI attestation, immutable pre-execution profile registration/approval chronology, verifiable membership of each seed-state entry in the declared seed manifest, and proof that the named execution artifact was produced from that state remain subsequent hardening gaps.
Current gate
#488 exact head is
252b25298af4d574e363e342e056559772976402, Draft/open/mergeable on protectedmain@a243f18da4a4ca8a8d068c39922537f1f8ed6ad0, ordinary-forward ahead 929 / behind 0. Current Documentation/Rust/Security/Semgrep/CodeQL/Bias-SE workflows are non-terminal and no qualifying current-headAPPROVEDreview exists. Keep Draft and do not transfer predecessor receipts.Keep this issue open through exact-head Rust/rustdoc/owned line+branch coverage/security/CodeQL/proof-budget, qualifying independent review, normal #492 prerequisite/protected-main integration, and code-current #435 TRACEABILITY/product-gap authority.
Refs #488 #625 #626 #627 #630 #631 #633 #492.