Finding
ADR 0014 and ClaimAuthority::required_kinds() require ScientificallySupported authority to have both ExactHeadTests and ScientificRecovery evidence. Fresh review found that the specialized recovery path bypassed that authority gate: after profile/RMSE validation, private claim::promote_scientific_recovery directly constructed a PromotedClaim(ScientificallySupported, candidate) and the public profile wrapper returned it. No exact-head test evidence collection was presented to the canonical promote_claim gate.
A caller could therefore mint full ScientificallySupported authority from valid recovery metrics plus matching candidate/protected SHA without the exact-head evidence that generic claim promotion explicitly requires. This is an authority-composition defect, not a numerical-recovery defect.
RED → causal repair
Canonical owner vehicle remains Draft #488.
- source-level compile RED
4c824ad01a9b95beb0ba67b9c547b5e811db64a5 adds a public contract requiring the recovery API to receive claim evidence, proving that recovery metrics with an empty evidence collection must return ClaimEvidenceMissing, passing ExactHeadTests may compose with computed recovery, and queued/predecessor/skipped/LLM/failing exact-head evidence stays fail closed. The predecessor five-argument profile API cannot compile this contract. No hosted failing RED receipt is claimed because workflows had not materialized before the immediate repair.
- causal production repair
96ed85a6e33464a218f79032d0d337a0c4245324 adds claim_evidence: &[ClaimEvidence] to the public profile recovery boundary. The grouped/profile numerical gate runs first; only after it succeeds does the function append a passing ScientificRecovery evidence item. Final ScientificallySupported authority is then recomposed through PromotionRequest + canonical claim::promote_claim. The recovery path never invents ExactHeadTests=true.
- existing claim/recovery public contracts were migrated ordinary-forward at
66c044dd958cd5426b7c5234fe8aa3009256c93d, 3bc5dbce33ae72870a37d408e858deea010faeef, 550e112e5dd6ea0b512b850a269742f286b0c542, f8ba145a0116a31c59d7bfae534fecb0965f6759, and 5343f009ac58747f84e696316f1612a835b2f9a4.
- CHANGELOG/current exact head
33a40073a9677e993c7e60b4df84196497c532ea records the authority-composition contract.
The private numerical helper's historical PromotedClaim return is deliberately discarded by the public boundary; it is now only a recovery-criterion validation step. Public authority is emitted only after the generic ADR 0014 gate accepts the combined evidence. A later consolidation can rename/internalize that helper without changing the repaired public invariant; no duplicate public authority route remains.
Preserved scientific/profile contracts
No RMSE/MCSE arithmetic, practical target, grouped-replication semantics, planned denominator, DGP/seed/estimand/state-composition profile identity, failure policy, #624 exact comparison, or #628 canonical zero-multiplier rule changed. #627/#628 content-provenance work remains intact.
This repair intentionally uses the existing trusted-adapter ClaimEvidence model; it does not claim that a caller-created boolean is cryptographic CI proof. Durable evidence-receipt binding and pre-execution profile chronology remain separate buyer/integration hardening gaps.
Current gate
#488 current exact head is 33a40073a9677e993c7e60b4df84196497c532ea on protected base main@a243f18da4a4ca8a8d068c39922537f1f8ed6ad0. Current workflows are all non-terminal: Documentation Quality 35500067526, Security 35500067599, Semgrep 35500067598, Rust Foundation 35500067587, Bias-SE proof budget 35500067579, CodeQL PR 35500067496 are queued at the latest read. Predecessor receipts do not transfer and qualifying independent current-head APPROVED review is absent.
Keep open through exact-head Rust/coverage/security/CodeQL/proof-budget, qualifying independent review, normal #492 prerequisite/protected-main integration, and code-current TRACEABILITY/product-gap authority. Source repair alone is not completion.
Refs #488 #623 #624 #625 #626 #627 #628 #492 ADR 0014.
Finding
ADR 0014 and
ClaimAuthority::required_kinds()requireScientificallySupportedauthority to have bothExactHeadTestsandScientificRecoveryevidence. Fresh review found that the specialized recovery path bypassed that authority gate: after profile/RMSE validation, privateclaim::promote_scientific_recoverydirectly constructed aPromotedClaim(ScientificallySupported, candidate)and the public profile wrapper returned it. No exact-head test evidence collection was presented to the canonicalpromote_claimgate.A caller could therefore mint full
ScientificallySupportedauthority from valid recovery metrics plus matching candidate/protected SHA without the exact-head evidence that generic claim promotion explicitly requires. This is an authority-composition defect, not a numerical-recovery defect.RED → causal repair
Canonical owner vehicle remains Draft #488.
4c824ad01a9b95beb0ba67b9c547b5e811db64a5adds a public contract requiring the recovery API to receive claim evidence, proving that recovery metrics with an empty evidence collection must returnClaimEvidenceMissing, passingExactHeadTestsmay compose with computed recovery, and queued/predecessor/skipped/LLM/failing exact-head evidence stays fail closed. The predecessor five-argument profile API cannot compile this contract. No hosted failing RED receipt is claimed because workflows had not materialized before the immediate repair.96ed85a6e33464a218f79032d0d337a0c4245324addsclaim_evidence: &[ClaimEvidence]to the public profile recovery boundary. The grouped/profile numerical gate runs first; only after it succeeds does the function append a passingScientificRecoveryevidence item. FinalScientificallySupportedauthority is then recomposed throughPromotionRequest+ canonicalclaim::promote_claim. The recovery path never inventsExactHeadTests=true.66c044dd958cd5426b7c5234fe8aa3009256c93d,3bc5dbce33ae72870a37d408e858deea010faeef,550e112e5dd6ea0b512b850a269742f286b0c542,f8ba145a0116a31c59d7bfae534fecb0965f6759, and5343f009ac58747f84e696316f1612a835b2f9a4.33a40073a9677e993c7e60b4df84196497c532earecords the authority-composition contract.The private numerical helper's historical
PromotedClaimreturn is deliberately discarded by the public boundary; it is now only a recovery-criterion validation step. Public authority is emitted only after the generic ADR 0014 gate accepts the combined evidence. A later consolidation can rename/internalize that helper without changing the repaired public invariant; no duplicate public authority route remains.Preserved scientific/profile contracts
No RMSE/MCSE arithmetic, practical target, grouped-replication semantics, planned denominator, DGP/seed/estimand/state-composition profile identity, failure policy, #624 exact comparison, or #628 canonical zero-multiplier rule changed. #627/#628 content-provenance work remains intact.
This repair intentionally uses the existing trusted-adapter
ClaimEvidencemodel; it does not claim that a caller-created boolean is cryptographic CI proof. Durable evidence-receipt binding and pre-execution profile chronology remain separate buyer/integration hardening gaps.Current gate
#488 current exact head is
33a40073a9677e993c7e60b4df84196497c532eaon protected basemain@a243f18da4a4ca8a8d068c39922537f1f8ed6ad0. Current workflows are all non-terminal: Documentation Quality35500067526, Security35500067599, Semgrep35500067598, Rust Foundation35500067587, Bias-SE proof budget35500067579, CodeQL PR35500067496are queued at the latest read. Predecessor receipts do not transfer and qualifying independent current-headAPPROVEDreview is absent.Keep open through exact-head Rust/coverage/security/CodeQL/proof-budget, qualifying independent review, normal #492 prerequisite/protected-main integration, and code-current TRACEABILITY/product-gap authority. Source repair alone is not completion.
Refs #488 #623 #624 #625 #626 #627 #628 #492 ADR 0014.