Finding
#629 correctly stopped the specialized scientific-recovery path from minting ScientificallySupported authority without ExactHeadTests, but the repaired public API still accepts claim_evidence: &[ClaimEvidence]. ClaimEvidence::new(ExactHeadTests, true) contains only a kind and boolean; it carries neither the tested commit identity nor an immutable CI/test receipt identity.
That means the specialized recovery path can be handed a passing exact-head boolean that was actually obtained on a predecessor commit, while PromotionRequest only compares candidate_head with protected_head. The generic gate therefore cannot prove that the exact-head test evidence itself belongs to the candidate. #629 explicitly left durable exact-head evidence-receipt identity as a remaining hardening gap.
This is an authority/evidence-provenance defect, not a recovery-metric defect. RMSE/MCSE arithmetic, grouped independent replications, planned denominator, profile provenance, failure policy, and practical targets must not change.
Required RED
On canonical Validation Evidence PR #488, add a public contract requiring scientific recovery to consume an exact-head test receipt that carries:
- the tested Git commit SHA;
- an immutable canonical SHA-256 receipt/artifact identity;
- an explicit terminal state (
passed, failed, queued, skipped).
The contract must prove that:
- a passed receipt bound to the candidate head may compose with computed recovery;
- a passed receipt bound to another head fails as predecessor evidence;
- failed, queued, and skipped receipts fail closed with the existing canonical errors;
- malformed/noncanonical receipt SHA-256 fails closed;
- the returned scientific promotion retains both the recovery-profile SHA-256 and the exact-head receipt SHA-256 so downstream code cannot silently discard which receipt supported authority.
The predecessor boolean-only recovery API should be unable to satisfy this contract.
Minimal causal repair
Keep the generic ADR 0014 ClaimEvidence model intact for now. Harden the specialized scientific-recovery boundary by introducing a versioned exact-head receipt value object in the Validation Evidence owner, validate its head/digest/status, convert only a matching passed receipt into the internal ExactHeadTests=true evidence item, compute ScientificRecovery=true internally, and then call canonical promote_claim.
Do not infer CI truth from the receipt digest: receipt contents remain trusted-adapter evidence. The repair must bind identity and prevent predecessor/queued/skipped/failing evidence from being relabeled as a detached passing boolean. A later generic claim-receipt migration may reuse this contract.
Keep open through RED → causal repair → exact-head Rust/coverage/security/CodeQL/proof-budget → qualifying independent review → normal prerequisite/protected-main integration and code-current TRACEABILITY/product-gap authority.
Refs #488 #629 #627 #628 #492 ADR 0014.
Finding
#629 correctly stopped the specialized scientific-recovery path from minting
ScientificallySupportedauthority withoutExactHeadTests, but the repaired public API still acceptsclaim_evidence: &[ClaimEvidence].ClaimEvidence::new(ExactHeadTests, true)contains only a kind and boolean; it carries neither the tested commit identity nor an immutable CI/test receipt identity.That means the specialized recovery path can be handed a passing exact-head boolean that was actually obtained on a predecessor commit, while
PromotionRequestonly comparescandidate_headwithprotected_head. The generic gate therefore cannot prove that the exact-head test evidence itself belongs to the candidate. #629 explicitly left durable exact-head evidence-receipt identity as a remaining hardening gap.This is an authority/evidence-provenance defect, not a recovery-metric defect. RMSE/MCSE arithmetic, grouped independent replications, planned denominator, profile provenance, failure policy, and practical targets must not change.
Required RED
On canonical Validation Evidence PR #488, add a public contract requiring scientific recovery to consume an exact-head test receipt that carries:
passed,failed,queued,skipped).The contract must prove that:
The predecessor boolean-only recovery API should be unable to satisfy this contract.
Minimal causal repair
Keep the generic ADR 0014
ClaimEvidencemodel intact for now. Harden the specialized scientific-recovery boundary by introducing a versioned exact-head receipt value object in the Validation Evidence owner, validate its head/digest/status, convert only a matching passed receipt into the internalExactHeadTests=trueevidence item, computeScientificRecovery=trueinternally, and then call canonicalpromote_claim.Do not infer CI truth from the receipt digest: receipt contents remain trusted-adapter evidence. The repair must bind identity and prevent predecessor/queued/skipped/failing evidence from being relabeled as a detached passing boolean. A later generic claim-receipt migration may reuse this contract.
Keep open through RED → causal repair → exact-head Rust/coverage/security/CodeQL/proof-budget → qualifying independent review → normal prerequisite/protected-main integration and code-current TRACEABILITY/product-gap authority.
Refs #488 #629 #627 #628 #492 ADR 0014.