Skip to content
Merged

Dev #593

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
93 commits
Select commit Hold shift + click to select a range
ef64f0b
Fix critical and high-severity security vulnerabilities
claude Apr 4, 2026
5ca2c2b
feat(runtime): add shared operational state snapshots
Brad-Edwards Jun 20, 2026
c19f282
fix(runtime): simplify shared-state validators
Brad-Edwards Jun 20, 2026
512906b
Add repository-owned reference processor assembly (RUN-313)
Brad-Edwards Jun 20, 2026
4d464c4
fix(runtime): clear shared-state sonar findings
Brad-Edwards Jun 20, 2026
2c24c0a
Make ReferenceProcessor.realize static (SonarCloud code smell)
Brad-Edwards Jun 20, 2026
29ca38c
Merge pull request #562 from Brad-Edwards/194-run-307-state-model
Brad-Edwards Jun 20, 2026
be21711
Merge branch 'dev' into 196-RUN-313-ref-processor
Brad-Edwards Jun 20, 2026
106122b
Merge pull request #563 from Brad-Edwards/196-RUN-313-ref-processor
Brad-Edwards Jun 20, 2026
059d002
Add participant concurrency runtime contracts
Brad-Edwards Jun 20, 2026
f6ec82b
Add reference emulation backend (RUN-314)
Brad-Edwards Jun 20, 2026
80223e0
Resolve SonarCloud new-code smells on reference backend
Brad-Edwards Jun 20, 2026
9b530af
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 20, 2026
5c35dfb
Exclude reference-backend stub-parallel components from CPD (RUN-314)
Brad-Edwards Jun 20, 2026
ba18151
docs: reconcile asset inventory methodology closeout
Brad-Edwards Jun 20, 2026
4cb1645
Trigger PR CI for RUN-308 Sonar fix
Brad-Edwards Jun 20, 2026
9827df8
Merge pull request #564 from Brad-Edwards/195-concurrent-participants
Brad-Edwards Jun 20, 2026
3aa1dda
Merge branch 'dev' into 197-RUN-314-emulation-backend
Brad-Edwards Jun 20, 2026
f29c437
Merge pull request #565 from Brad-Edwards/197-RUN-314-emulation-backend
Brad-Edwards Jun 20, 2026
a288ec3
Merge branch 'dev' into 353-inventory-methodology-closeout
Brad-Edwards Jun 20, 2026
4a1fddb
Merge pull request #566 from Brad-Edwards/353-inventory-methodology-c…
Brad-Edwards Jun 20, 2026
edff995
Register API-406 backend carrier contracts
Brad-Edwards Jun 20, 2026
59cfd43
Merge pull request #568 from Brad-Edwards/200-api-406-contracts
Brad-Edwards Jun 21, 2026
17238a0
Expose participant feature support declarations
Brad-Edwards Jun 21, 2026
b25e936
Merge pull request #570 from Brad-Edwards/201-participant-feature-sup…
Brad-Edwards Jun 21, 2026
91ab68d
Merge dev and port security hardening
Brad-Edwards Jun 21, 2026
f921483
Address Sonar findings for security hardening
Brad-Edwards Jun 21, 2026
d537f1b
Reduce request guard complexity
Brad-Edwards Jun 21, 2026
b799782
Split request guard helpers
Brad-Edwards Jun 21, 2026
d4164ee
Simplify request header guard return path
Brad-Edwards Jun 21, 2026
b91d519
Merge pull request #143 from Brad-Edwards/recovered/security-audit-fixes
Brad-Edwards Jun 21, 2026
0615d9d
Expose API-408 participant retrieval views
Brad-Edwards Jun 21, 2026
65f216c
Merge origin/dev into API-408 retrieval branch
Brad-Edwards Jun 21, 2026
7895081
Require API-411 outcome state relationships
Brad-Edwards Jun 21, 2026
06e9218
Merge pull request #571 from Brad-Edwards/202-api-408-retrieval
Brad-Edwards Jun 21, 2026
63f3ab0
Merge branch 'dev' into 203-participant-outcomes
Brad-Edwards Jun 21, 2026
11a3fa9
Merge pull request #572 from Brad-Edwards/203-participant-outcomes
Brad-Edwards Jun 21, 2026
e36859d
Harden OCI module bundle extraction to fail closed on Python 3.11
Brad-Edwards Jun 21, 2026
849737a
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 21, 2026
54ba60b
Merge pull request #573 from Brad-Edwards/13-oci-tar-extraction
Brad-Edwards Jun 21, 2026
63c90be
added: publish experiment evidence contracts
Brad-Edwards Jun 21, 2026
88e493a
Merge remote-tracking branch 'origin/dev' into 88-experiment-evidence…
Brad-Edwards Jun 21, 2026
8343d7d
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 21, 2026
72e7dfc
Merge pull request #574 from Brad-Edwards/88-experiment-evidence-meas…
Brad-Edwards Jun 21, 2026
a01c687
Enable Ground Control workflow routing
Brad-Edwards Jun 21, 2026
155b120
Add EXP-707 capture-spec negative conformance coverage and invalid fi…
Brad-Edwards Jun 21, 2026
095a3e1
Merge pull request #575 from Brad-Edwards/233-exp-707-evidence-capture
Brad-Edwards Jun 22, 2026
255d07c
Add experiment run provenance contract
Brad-Edwards Jun 22, 2026
ab1e8ca
Fix SonarCloud findings
Brad-Edwards Jun 22, 2026
4d07bcb
Merge remote-tracking branch 'origin/dev' into 89-experiment-provenance
Brad-Edwards Jun 22, 2026
f1e9b47
Add EXP-708 evidence-record negative conformance coverage and invalid…
Brad-Edwards Jun 22, 2026
a575e23
Merge pull request #576 from Brad-Edwards/89-experiment-provenance
Brad-Edwards Jun 22, 2026
ac4f1dd
Merge branch 'dev' into 234-exp-708-evidence-record
Brad-Edwards Jun 22, 2026
b6fd5b1
Merge pull request #577 from Brad-Edwards/234-exp-708-evidence-record
Brad-Edwards Jun 22, 2026
efd9c0d
Add EXP-709 derived-measure negative conformance coverage and invalid…
Brad-Edwards Jun 22, 2026
04e3584
Merge pull request #578 from Brad-Edwards/235-exp-709-derived-measure…
Brad-Edwards Jun 22, 2026
4fc79eb
Add EXP-720 run-provenance negative conformance coverage and invalid …
Brad-Edwards Jun 22, 2026
b81861c
Merge pull request #579 from Brad-Edwards/238-EXP-720-provenance
Brad-Edwards Jun 22, 2026
c440d66
Add EXP-722 realized-form-disclosure negative conformance coverage an…
Brad-Edwards Jun 22, 2026
c78a2f8
Merge pull request #580 from Brad-Edwards/239-EXP-722-realized-form
Brad-Edwards Jun 22, 2026
d5a9d15
Implement SEM-214 context view semantics
Brad-Edwards Jun 22, 2026
639fb03
Merge remote-tracking branch 'origin/dev' into 247-sem-214-context-views
Brad-Edwards Jun 22, 2026
0c1a3d9
Merge pull request #581 from Brad-Edwards/247-sem-214-context-views
Brad-Edwards Jun 22, 2026
f0b94c8
Document observability evidence plane separation
Brad-Edwards Jun 23, 2026
9fd2b73
Merge pull request #582 from Brad-Edwards/127-sem-224-observability
Brad-Edwards Jun 23, 2026
74e478a
Implement SEM-216 boundary semantics for state, evidence, evaluation,…
Brad-Edwards Jun 23, 2026
0d36855
Merge remote-tracking branch 'origin/dev' into 248-SEM-216-view-bound…
Brad-Edwards Jun 23, 2026
2c72e7f
Merge pull request #583 from Brad-Edwards/248-SEM-216-view-boundary-s…
Brad-Edwards Jun 23, 2026
0ae036f
Implement SEM-224 observability plane separation semantics
Brad-Edwards Jun 23, 2026
3b56aac
Define external knowledge binding effects
Brad-Edwards Jun 23, 2026
d5a6d2a
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 23, 2026
821a29b
Merge pull request #585 from Brad-Edwards/249-sem-external-bindings
Brad-Edwards Jun 23, 2026
ac38329
Merge branch 'dev' into 334-SEM-224-obs-plane-separation
Brad-Edwards Jun 23, 2026
eba8724
Merge pull request #584 from Brad-Edwards/334-SEM-224-obs-plane-separ…
Brad-Edwards Jun 23, 2026
ed43912
Add participant behavior model specification
Brad-Edwards Jun 23, 2026
1eddd40
Merge pull request #586 from Brad-Edwards/77-participant-behavior-model
Brad-Edwards Jun 24, 2026
3d3a116
Add SEM-225 augmentation disclosure semantics
Brad-Edwards Jun 24, 2026
64d875d
Refactor SEM-225 disclosure validation
Brad-Edwards Jun 24, 2026
ef4cd53
Merge branch 'dev' into 335-sem-225
Brad-Edwards Jun 24, 2026
71da8c6
Merge pull request #587 from Brad-Edwards/335-sem-225
Brad-Edwards Jun 24, 2026
cb3f673
Add participant behavior binding gate
Brad-Edwards Jun 24, 2026
87f2407
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 24, 2026
36499ed
Merge remote-tracking branch 'origin/dev' into 204-act-602-model
Brad-Edwards Jun 24, 2026
221f583
Merge pull request #588 from Brad-Edwards/204-act-602-model
Brad-Edwards Jun 24, 2026
04ffdd3
Add scenario-native observability coverage
Brad-Edwards Jun 24, 2026
00ba076
Merge remote-tracking branch 'origin/dev' into 336-dsl-123-observability
Brad-Edwards Jun 24, 2026
01f74b6
Document ACT-603 interaction guardrails
Brad-Edwards Jun 24, 2026
3e9f5db
Merge pull request #589 from Brad-Edwards/336-dsl-123-observability
Brad-Edwards Jun 24, 2026
64ebfce
Merge branch 'dev' into 205-abstract-interaction-model
Brad-Edwards Jun 24, 2026
0be0e79
Merge pull request #590 from Brad-Edwards/205-abstract-interaction-model
Brad-Edwards Jun 24, 2026
5f530a4
Note APTL as a worked ACES SDL example in the README
Brad-Edwards Jun 24, 2026
0649516
Merge pull request #592 from Brad-Edwards/readme-aptl-example
Brad-Edwards Jun 24, 2026
4ec4363
Merge branch 'main' into dev
Brad-Edwards Jun 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,32 @@ jobs:
- name: Run fuzz session
run: uv tool run --from 'nox[uv]==2026.4.10' nox -f noxfile.py -s fuzz

# Opt-in, non-blocking, runtime-gated container integration tests (RUN-314).
# Kept out of the hermetic `verify` graph; the `docker` marker tests self-skip
# when no runtime is present, and this whole job never fails the build.
integration-docker:
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
with:
python-version: "3.12"
- name: Install uv
uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8
- name: Probe for a container runtime
id: runtime
run: |
if command -v docker >/dev/null 2>&1 && docker info >/dev/null 2>&1; then
echo "available=true" >> "$GITHUB_OUTPUT"
else
echo "available=false" >> "$GITHUB_OUTPUT"
echo "No container runtime available; skipping docker integration session."
fi
- name: Run docker integration session
if: steps.runtime.outputs.available == 'true'
run: uv tool run --from 'nox[uv]==2026.4.10' nox -f noxfile.py -s integration_docker

sonar:
runs-on: ubuntu-latest
needs: [verify]
Expand Down
5 changes: 5 additions & 0 deletions .ground-control.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,11 @@ requirements:
- GOV-918
- RUN-311
- ADR-012
routing:
enabled: true
default_provider: claude
default_fallback: parent
stages: {}
sonarcloud:
project_key: Brad-Edwards_aces
organization: brad-edwards
Expand Down
5 changes: 5 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,11 @@ The repository is not a managed cyber range and does not include a production
backend. Backend contracts, stubs, conformance checks, and examples are present;
real deployment backends remain separate implementations.

A worked example of ACES SDL driving a concrete range is
[APTL (Advanced Purple Team Lab)](https://github.com/Brad-Edwards/aptl), a
separate project that specifies its scenarios as ACES SDL documents and
realizes the selected topology on a Docker Compose backend.

## Contents

- [What ACES SDL Describes](#what-aces-sdl-describes)
Expand Down
1 change: 1 addition & 0 deletions changelog.d/+readme-aptl-example.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Noted in the README that APTL (Advanced Purple Team Lab) is a worked example of a separate project specifying its scenarios as ACES SDL documents and realizing the selected topology on a concrete Docker Compose backend.
1 change: 1 addition & 0 deletions changelog.d/13.security.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Harden OCI module bundle extraction to fail closed on every supported Python runtime. The resolver now validates the entire tar archive before writing — rejecting path traversal, symlinks, hard links, and special files, and stripping setuid/setgid/sticky bits — instead of relying on `tarfile`'s `filter="data"`, which is unavailable on Python 3.11.0–3.11.3 (the PEP 706 backport landed in 3.11.4) and previously allowed an unsafe extraction path on those supported runtimes.
1 change: 1 addition & 0 deletions changelog.d/143.security.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Port runtime control-plane and SDL module-registry security hardening onto the current package layout.
3 changes: 3 additions & 0 deletions changelog.d/194.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
### Added
- Added first-class RUN-307 shared operational state records/history to runtime snapshots with revision-aware validation.
- Added semantic diagnostics for malformed shared-state records, access markers, and append-only history violations.
1 change: 1 addition & 0 deletions changelog.d/195.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Added RUN-308 participant-runtime contract surfaces for joint action records, time-management contexts, runtime snapshot concurrency validation, and coverage for the concurrency guardrails.
1 change: 1 addition & 0 deletions changelog.d/196.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add a repository-owned reference processor (`aces_processor.reference.run_reference_processor` / `ReferenceProcessor`) that realizes the normative processing model: it carries SDL authoring input through instantiation, compilation, and planning to a portable execution plan and exposes the published processor manifest. Per ADR-008 the processor stops at the execution plan; backend realization stays in the runtime. The backend-conformance live probe now consumes the reference processor instead of inlining the compile/plan chain, and new tests drive its plan through the reference runtime to prove every contract version the processor manifest declares is exercised end to end. (RUN-313)
1 change: 1 addition & 0 deletions changelog.d/197.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add a repository-owned reference emulation backend (`aces_reference_backend`) that implements the four backend protocol roles (Provisioner, Orchestrator, Evaluator, ParticipantRuntime) over a pluggable deployment driver. The default in-process driver is hermetic; an opt-in OCI driver realizes plans against a real container runtime (docker/podman) through fixed-argv subprocess calls with bounded timeouts and no secret/native-id leakage into any portable artifact. The backend publishes identity/capability through the standard `BackendManifest`, registers on the existing `BackendRegistry` descriptor seam as `reference-emulation`, and passes `run_target_conformance` at the `FULL_REMOTE_CONTROL_PLANE` profile. Provenance flows through the SEM-218 apply gate; only portable ACES facts reach snapshots, diagnostics, and conformance reports. A `docker`-marked, runtime-gated integration test and a non-blocking `integration_docker` nox session / CI job exercise real-container realization without touching the hermetic `verify` graph. (RUN-314, ADR-063)
5 changes: 5 additions & 0 deletions changelog.d/200.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
### Added

- Made the API-406 participant lifecycle-event, observation-envelope, and
shared-state record contracts required by the full remote control-plane
backend profile and registered their conformance model validators.
1 change: 1 addition & 0 deletions changelog.d/201.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Expose API-407 participant feature-support declarations through backend manifest capability helpers and preserve them in rendered backend-manifest v2 payloads.
1 change: 1 addition & 0 deletions changelog.d/202.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Expose API-408 participant status, history, and reference/provenance context retrieval views through the runtime control plane and HTTP API.
1 change: 1 addition & 0 deletions changelog.d/203.changed.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Require API-411 participant outcome reports to carry at least one explicit state relationship in the published contract model and generated schema.
1 change: 1 addition & 0 deletions changelog.d/204.changed.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Added a runtime-snapshot conformance gate requiring participant behavior history to be tied to a compiled participant behavior binding before history is accepted.
1 change: 1 addition & 0 deletions changelog.d/233.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add negative conformance coverage and an invalid fixture for the EXP-707 experiment-capture-spec-v1 contract: a dedicated rejection test exercising the capture-requirement key-equality, window-reference resolution, capture-window time-ordering, and under-specified-window invariants, plus a schema-and-model invalid fixture for a window that declares no start, end, or trigger.
1 change: 1 addition & 0 deletions changelog.d/234.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add negative conformance coverage and invalid fixtures for the EXP-708 experiment-evidence-record-v1 contract: a dedicated rejection test exercising the content-uri-requires-checksum, non-empty source-refs, RFC 3339 captured-at, and redaction-requires-loss-disclosure invariants, plus schema-and-model invalid fixtures for a content URI without a checksum, an empty source-refs list, and a malformed captured-at timestamp. The model and published schema shipped under #88; this change adds the conformance tests of record without changing them.
1 change: 1 addition & 0 deletions changelog.d/235.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add negative conformance coverage and invalid fixtures for the EXP-709 experiment-derived-measure-v1 contract: a dedicated rejection test exercising the reported-requires-value, non-reported-must-not-carry-value, and RFC 3339 generated-at invariants, plus schema-and-model invalid fixtures for a reported measure without a value, a withheld measure carrying a value, and a malformed generated-at timestamp. The model and published schema shipped under #88; this change adds the conformance tests of record without changing them.
1 change: 1 addition & 0 deletions changelog.d/238.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add negative conformance coverage and invalid fixtures for the EXP-720 experiment-run-v1 canonical run provenance contract: a dedicated rejection test exercising the run-traceability claim-grounding and duplicate-reference invariants, the realized-form-disclosure substantive and processor/backend authority invariants, and the required traceability capture-spec surface, plus schema-and-model invalid fixtures for a realized-form disclosure missing a realized target, a backend-realized disclosure carrying a processor realization authority, and a run whose traceability omits capture-spec references. The model and published schema shipped under #89; this change adds the conformance tests of record without changing them.
1 change: 1 addition & 0 deletions changelog.d/239.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add negative conformance coverage and an invalid fixture for the EXP-722 experiment-run-v1 realized-form disclosure contract: a dedicated rejection test exercising the realized-form substantive invariants (a disclosure must name a realized reference or value summary and use the matching processor/backend realization authority) and the run-level invariant that disclosure evidence refs must be listed in the run traceability evidence refs and must be duplicate-free, plus a schema-and-model invalid fixture for a processor-realized disclosure carrying a backend realization authority. The model and published schema shipped under #89; this change adds the conformance tests of record without changing them.
3 changes: 3 additions & 0 deletions changelog.d/247.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
### Added

- Published SEM-214 meaning and comparability semantics for API-408 participant context views.
3 changes: 3 additions & 0 deletions changelog.d/248.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
### Added

- Published SEM-216 boundary semantics distinguishing runtime-observable state, captured evidence, derived evaluations, analysis outputs, and audience-specific views over the existing contract families. Participant-visible context views drawing on archival `evidence_record` or `derived_measure` source layers must now declare a governed view rule and redaction policy and mediate the source through the transformation, and redacted or withheld evidence records must disclose redaction/loss at the schema boundary.
1 change: 1 addition & 0 deletions changelog.d/249.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Added SEM-217 external knowledge binding effect semantics, including a typed classifier for annotation, alignment, refinement, and constraint effects over existing concept-authority and semantic-profile artifacts.
3 changes: 3 additions & 0 deletions changelog.d/334.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
### Added

- Published SEM-224 observability plane separation semantics: a carrier-oriented plane classifier (`aces_sdl.observability_plane_semantics`) that assigns each claim-bearing observability/evidence artifact exactly one of the five named planes — scenario-native observability, authored evidence requirement, processor/backend operational observability, captured evidence, and derived analysis — by carrier role rather than by free-form strings such as `log`, `trace`, or `evidence`. The three claim-bearing experiment-core contracts (`experiment-capture-spec-v1`, `experiment-evidence-record-v1`, `experiment-derived-measure-v1`) now publish their plane as a portable `x-aces-plane` schema annotation sourced from that classifier.
2 changes: 2 additions & 0 deletions changelog.d/335.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
Added SEM-225 run-level augmentation disclosures to `experiment-run-v1`, with validation for processor/backend authority, environment-visible carriers, participant-visible markings, comparability observer effects, and run-traced evidence provenance.
Refactored the SEM-225 disclosure validator into focused helper checks so the published contract validation stays maintainable.
1 change: 1 addition & 0 deletions changelog.d/336.changed.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Documented and test-backed DSL-123 scenario-native observability reference coverage.
2 changes: 2 additions & 0 deletions changelog.d/353.changed.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
Document the ACES asset-inventory issue-template fragment and reconcile the
methodology closeout notes for ACES #353.
2 changes: 2 additions & 0 deletions changelog.d/77.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
Added the participant behavior model ADR and formal spec covering ACT-602,
ACT-603, ACT-606, ACT-607, and ACT-608.
2 changes: 2 additions & 0 deletions changelog.d/88.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
Add the experiment evidence and measure contract boundary for EXP-707, EXP-708, EXP-709, and EXP-715. The experiment-core schema family now publishes `experiment-capture-spec-v1`, `experiment-evidence-record-v1`, and `experiment-derived-measure-v1`, with valid/invalid fixtures, semantic invariant annotations, and conformance validators that keep declarative capture intent, raw evidence, and derived measures separate. Backend manifests now support an optional `capabilities.observation` block with governed capture-kind, channel-kind, and sealing-mode vocabularies, and conformance rejects observation claims that lack the published evidence contracts. ADR-064 and the formal experiment-core spec record the boundary; runtime capture, storage, APIs, schedulers, and statistical engines remain out of scope for this contract-only change.
Refactor the reported-value invariant helper and observation capability gap reporting so SonarCloud quality gates remain clean for the published contract surface.
1 change: 1 addition & 0 deletions changelog.d/89.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Extend `experiment-run-v1` as the canonical run provenance record for EXP-710, EXP-720, and EXP-722. Run records now include required traceability links from capture specs to raw evidence, derived measures, and claims, plus realized-form disclosures for processor/backend/operator choices that were not fully authored in the scenario or task. ADR-065 and the formal experiment-core spec document the boundary; generated schemas, fixtures, and contract tests enforce the new provenance surface. Reference de-duplication now also tolerates constrained experiment reference models that omit optional digest, path, or subject fields.
22 changes: 17 additions & 5 deletions contracts/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,11 +54,23 @@ It includes:
- live runtime/control-plane contracts
- experiment, evidence, and provenance artifact boundaries

The first published experiment-core contract family includes task, run,
apparatus-context, and study/collection schemas under
`contracts/schemas/experiment-core/`. These contracts are archival design
artifacts for scientific experiment records; they do not add runtime execution,
storage, or API behavior by themselves.
The control-plane `participant-context-view-v1` contract includes the SEM-214
meaning and comparability envelope for derived operational context views:
participant-local scope, audience scope, observation point, governed source
layers, transformation rule, evidence/provenance basis, semantic limitations,
and explicit comparability disclosure.

The published experiment-core contract family includes task, run,
apparatus-context, study/collection, capture specification, raw evidence record,
and derived measure schemas under `contracts/schemas/experiment-core/`. These
contracts are archival design artifacts for scientific experiment records; they
do not add runtime execution, capture, storage, scheduling, statistical engines,
or API behavior by themselves.

`experiment-run-v1` is the canonical run provenance record. It carries the
task/run/apparatus context, result and evidence pointers, traceability links to
capture specs, evidence records, derived measures, and claims, plus
realized-form disclosures for underspecified concerns resolved during a run.

Within experiment-core contracts, identifier-bearing collections that require
uniqueness are object maps keyed by that identifier. This keeps uniqueness
Expand Down
100 changes: 100 additions & 0 deletions contracts/concept-authority/controlled-vocabularies-v1.json
Original file line number Diff line number Diff line change
Expand Up @@ -609,6 +609,106 @@
}
}
},
"observation-capture-kinds": {
"title": "Observation Capture Kinds",
"description": "Backend-supported evidence capture categories for experiment observation capability declarations.",
"kind": "vocabulary",
"governed_scopes": [
"capabilities.observation.supported_capture_kinds"
],
"extension_policy": "governed-extension",
"extension_pattern": "^x-[a-z0-9]+(?:-[a-z0-9]+)*:[a-z0-9]+(?:-[a-z0-9]+)*$",
"terms": {
"artifact": {
"title": "Artifact",
"description": "Backend can collect named artifact references as experiment evidence."
},
"log": {
"title": "Log",
"description": "Backend can collect log records as experiment evidence."
},
"observation": {
"title": "Observation",
"description": "Backend can collect direct observed facts or annotations as experiment evidence."
},
"packet-capture": {
"title": "Packet Capture",
"description": "Backend can collect packet-capture outputs as experiment evidence."
},
"telemetry": {
"title": "Telemetry",
"description": "Backend can collect telemetry streams or snapshots as experiment evidence."
},
"trace": {
"title": "Trace",
"description": "Backend can collect execution traces as experiment evidence."
}
}
},
"observation-channel-kinds": {
"title": "Observation Channel Kinds",
"description": "Backend-supported source channel categories for experiment observation capability declarations.",
"kind": "vocabulary",
"governed_scopes": [
"capabilities.observation.supported_channel_kinds"
],
"extension_policy": "governed-extension",
"extension_pattern": "^x-[a-z0-9]+(?:-[a-z0-9]+)*:[a-z0-9]+(?:-[a-z0-9]+)*$",
"terms": {
"backend-log": {
"title": "Backend Log",
"description": "Backend can capture evidence from backend-owned logs."
},
"evaluation-history": {
"title": "Evaluation History",
"description": "Backend can capture evidence from evaluation history surfaces."
},
"file-artifact": {
"title": "File Artifact",
"description": "Backend can capture evidence from file-backed artifacts."
},
"packet-capture": {
"title": "Packet Capture",
"description": "Backend can capture evidence from packet-capture channels."
},
"participant-observation": {
"title": "Participant Observation",
"description": "Backend can capture evidence from participant observation surfaces."
},
"runtime-snapshot": {
"title": "Runtime Snapshot",
"description": "Backend can capture evidence from runtime snapshot surfaces."
},
"workflow-history": {
"title": "Workflow History",
"description": "Backend can capture evidence from workflow history surfaces."
}
}
},
"observation-sealing-modes": {
"title": "Observation Sealing Modes",
"description": "Backend-supported integrity sealing modes for experiment observation evidence.",
"kind": "vocabulary",
"governed_scopes": [
"capabilities.observation.supported_sealing_modes"
],
"extension_policy": "governed-extension",
"extension_pattern": "^x-[a-z0-9]+(?:-[a-z0-9]+)*:[a-z0-9]+(?:-[a-z0-9]+)*$",
"terms": {
"digest": {
"title": "Digest",
"description": "Backend can bind evidence to a checksum or digest."
},
"immutable-store": {
"title": "Immutable Store",
"description": "Backend can store evidence in an append-only or immutable store."
},
"signed-attestation": {
"title": "Signed Attestation",
"description": "Backend can attach a signed attestation to evidence collection."
}
}
},
"participant-runtime-feature-support-levels": {
"title": "Participant Runtime Feature Support Levels",
"description": "Closed ADR-054 guarantee-strength scale for per-feature participant runtime support declarations.",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@
"participant-lifecycle-event-v1",
"participant-observation-envelope-v1",
"participant-shared-state-record-v1",
"participant-joint-action-record-v1",
"participant-time-management-context-v1",
"participant-outcome-report-v1"
],
"compatibility": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@
"participant-lifecycle-event-v1",
"participant-observation-envelope-v1",
"participant-shared-state-record-v1",
"participant-joint-action-record-v1",
"participant-time-management-context-v1",
"participant-outcome-report-v1"
],
"compatibility": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@
"participant-lifecycle-event-v1",
"participant-observation-envelope-v1",
"participant-shared-state-record-v1",
"participant-joint-action-record-v1",
"participant-time-management-context-v1",
"participant-outcome-report-v1"
],
"compatibility": {
Expand Down
Loading
Loading