Skip to content

scientific(validation): do not mint full scientific authority from recovery metrics alone #629

Description

@seonghobae

Finding

ADR 0014 and ClaimAuthority::required_kinds() require ScientificallySupported authority to have both ExactHeadTests and ScientificRecovery evidence. Fresh review found that the specialized recovery path bypassed that authority gate: after profile/RMSE validation, private claim::promote_scientific_recovery directly constructed a PromotedClaim(ScientificallySupported, candidate) and the public profile wrapper returned it. No exact-head test evidence collection was presented to the canonical promote_claim gate.

A caller could therefore mint full ScientificallySupported authority from valid recovery metrics plus matching candidate/protected SHA without the exact-head evidence that generic claim promotion explicitly requires. This is an authority-composition defect, not a numerical-recovery defect.

RED → causal repair

Canonical owner vehicle remains Draft #488.

  • source-level compile RED 4c824ad01a9b95beb0ba67b9c547b5e811db64a5 adds a public contract requiring the recovery API to receive claim evidence, proving that recovery metrics with an empty evidence collection must return ClaimEvidenceMissing, passing ExactHeadTests may compose with computed recovery, and queued/predecessor/skipped/LLM/failing exact-head evidence stays fail closed. The predecessor five-argument profile API cannot compile this contract. No hosted failing RED receipt is claimed because workflows had not materialized before the immediate repair.
  • causal production repair 96ed85a6e33464a218f79032d0d337a0c4245324 adds claim_evidence: &[ClaimEvidence] to the public profile recovery boundary. The grouped/profile numerical gate runs first; only after it succeeds does the function append a passing ScientificRecovery evidence item. Final ScientificallySupported authority is then recomposed through PromotionRequest + canonical claim::promote_claim. The recovery path never invents ExactHeadTests=true.
  • existing claim/recovery public contracts were migrated ordinary-forward at 66c044dd958cd5426b7c5234fe8aa3009256c93d, 3bc5dbce33ae72870a37d408e858deea010faeef, 550e112e5dd6ea0b512b850a269742f286b0c542, f8ba145a0116a31c59d7bfae534fecb0965f6759, and 5343f009ac58747f84e696316f1612a835b2f9a4.
  • CHANGELOG/current exact head 33a40073a9677e993c7e60b4df84196497c532ea records the authority-composition contract.

The private numerical helper's historical PromotedClaim return is deliberately discarded by the public boundary; it is now only a recovery-criterion validation step. Public authority is emitted only after the generic ADR 0014 gate accepts the combined evidence. A later consolidation can rename/internalize that helper without changing the repaired public invariant; no duplicate public authority route remains.

Preserved scientific/profile contracts

No RMSE/MCSE arithmetic, practical target, grouped-replication semantics, planned denominator, DGP/seed/estimand/state-composition profile identity, failure policy, #624 exact comparison, or #628 canonical zero-multiplier rule changed. #627/#628 content-provenance work remains intact.

This repair intentionally uses the existing trusted-adapter ClaimEvidence model; it does not claim that a caller-created boolean is cryptographic CI proof. Durable evidence-receipt binding and pre-execution profile chronology remain separate buyer/integration hardening gaps.

Current gate

#488 current exact head is 33a40073a9677e993c7e60b4df84196497c532ea on protected base main@a243f18da4a4ca8a8d068c39922537f1f8ed6ad0. Current workflows are all non-terminal: Documentation Quality 35500067526, Security 35500067599, Semgrep 35500067598, Rust Foundation 35500067587, Bias-SE proof budget 35500067579, CodeQL PR 35500067496 are queued at the latest read. Predecessor receipts do not transfer and qualifying independent current-head APPROVED review is absent.

Keep open through exact-head Rust/coverage/security/CodeQL/proof-budget, qualifying independent review, normal #492 prerequisite/protected-main integration, and code-current TRACEABILITY/product-gap authority. Source repair alone is not completion.

Refs #488 #623 #624 #625 #626 #627 #628 #492 ADR 0014.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions