Skip to content
Open
Show file tree
Hide file tree
Changes from 72 commits
Commits
Show all changes
79 commits
Select commit Hold shift + click to select a range
8fdf06c
docs: define Lotus Family conformance v0.1
safal207 Jul 18, 2026
90b806b
feat: add Lotus Family conformance manifest
safal207 Jul 18, 2026
c838f83
feat: add Lotus Family reference auditor
safal207 Jul 18, 2026
99303c5
test: add Lotus Family auditor regressions
safal207 Jul 18, 2026
d59ab1a
ci: run Lotus Family conformance suite
safal207 Jul 18, 2026
e2d48b5
chore: mark Lotus Family conformance package
safal207 Jul 18, 2026
f4b1e14
chore: preserve Lotus Family conformance directory
safal207 Jul 18, 2026
7d44963
chore: remove redundant placeholder
safal207 Jul 18, 2026
958f5fc
chore: record Lotus Family version
safal207 Jul 18, 2026
4bb0401
chore: ignore local Lotus Family artifacts
safal207 Jul 18, 2026
31344af
docs: add Lotus Family authority notice
safal207 Jul 18, 2026
77bf754
docs: describe Lotus Family conformance implementation
safal207 Jul 18, 2026
a1ef856
docs: add Lotus Family audit decision codes
safal207 Jul 18, 2026
d28a565
docs: add Lotus Family auditor roadmap
safal207 Jul 18, 2026
1c43eec
docs: record Lotus Family implementation slice
safal207 Jul 18, 2026
22dee84
docs: state Lotus Family acceptance criteria
safal207 Jul 18, 2026
01a293f
fix: fail closed on Lotus manifest drift
safal207 Jul 18, 2026
b85f543
fix: bind CML audit to full pytest discovery
safal207 Jul 18, 2026
33cfcae
test: cover manifest and CI discovery drift
safal207 Jul 18, 2026
258ea44
fix: harden pytest CI discovery parsing
safal207 Jul 18, 2026
d85abbc
test: cover commented and ignored pytest commands
safal207 Jul 18, 2026
d0828c5
fix: make CI discovery fail closed
safal207 Jul 18, 2026
9e6aee5
test: cover fail-closed CI command parsing
safal207 Jul 18, 2026
24d7e12
fix: harden Lotus workflow command discovery
safal207 Jul 18, 2026
c990749
test: reject fake steps outside GitHub jobs
safal207 Jul 18, 2026
9aa8467
feat: add causal test graph and fail-closed routes
safal207 Jul 18, 2026
d5d7ea6
test: align legacy fixture with Mix discovery
safal207 Jul 18, 2026
810d2c8
feat: add causal spacetime trajectory model
safal207 Jul 18, 2026
c8cff73
fix: bind spacetime model to verified provenance
safal207 Jul 18, 2026
9df5942
fix: reject non-executing shells and cyclic jobs
safal207 Jul 18, 2026
d5baf08
fix: repair Lotus route node identifiers
safal207 Jul 18, 2026
70a2e51
fix: reject hidden CI command reachability bypasses
safal207 Jul 18, 2026
517adda
test: cover hidden CI reachability bypasses
safal207 Jul 18, 2026
5214f30
fix: preserve workflow boundaries and fail-fast reachability
safal207 Jul 18, 2026
6818768
fix: reject empty compact model collections
safal207 Jul 18, 2026
d99bf64
test: cover workflow and compact model boundaries
safal207 Jul 18, 2026
9b1c933
test: assert public audit-only authority mode
safal207 Jul 18, 2026
344559b
fix: preserve workflow step gating semantics
safal207 Jul 18, 2026
bb48880
test: cover workflow step gate boundaries
safal207 Jul 18, 2026
ac33e22
fix: reject non-gating workflow execution contexts
safal207 Jul 18, 2026
cd7d439
fix: bind pytest discovery to audited configuration
safal207 Jul 18, 2026
0fb9556
test: cover final review gating boundaries
safal207 Jul 18, 2026
e483db5
fix: activate final workflow gating policy
safal207 Jul 18, 2026
5297e8a
fix: activate pytest configuration evidence
safal207 Jul 18, 2026
7f68a04
fix(lotus): cover hidden and native pytest config
safal207 Jul 18, 2026
e1a428e
test(lotus): cover hidden and native pytest configs
safal207 Jul 18, 2026
a728904
fix(lotus): parse pyproject pytest config with tomllib
safal207 Jul 18, 2026
83bc8e6
test(lotus): cover TOML semantic pytest tables
safal207 Jul 18, 2026
2469d07
fix: fail closed on pytest conftest hooks
safal207 Jul 18, 2026
178e9c6
test: cover pytest conftest collection hooks
safal207 Jul 18, 2026
5c05834
fix: audit pytest config for explicit Python tests
safal207 Jul 18, 2026
1120326
test: block pytest config for explicit test targets
safal207 Jul 18, 2026
572c8e9
fix: fail closed on anchored pytest env mappings
safal207 Jul 18, 2026
30d7c49
test: cover anchored pytest env mappings
safal207 Jul 18, 2026
64c764e
fix: allow safe setup before Lotus test discovery
safal207 Jul 18, 2026
dde8a82
test: preserve Pythia discovery after setup steps
safal207 Jul 18, 2026
655a1cb
fix(lotus): fail close unknown test policy and wrapped false
safal207 Jul 18, 2026
67e45a6
fix(lotus): route public workflow policy through v3
safal207 Jul 18, 2026
f3280db
test(lotus): cover unknown test policy and wrapped false
safal207 Jul 18, 2026
63b72ad
fix: audit pytest configs along explicit target ancestors
safal207 Jul 18, 2026
7ec718e
fix: route auditor through explicit-target config hardening
safal207 Jul 18, 2026
3dc334f
test: cover pytest config at explicit target root
safal207 Jul 18, 2026
bfdf554
fix: block CI command-resolution mutation
safal207 Jul 18, 2026
efd7a9b
fix: compile command-resolution guard safely
safal207 Jul 18, 2026
b4b76b3
test: guard CI command resolution
safal207 Jul 18, 2026
2983267
fix: fail closed on dynamic CI runner state
safal207 Jul 18, 2026
e44d054
fix: route workflow discovery through policy v4
safal207 Jul 18, 2026
1a22e0e
test: cover dynamic CI state and test arguments
safal207 Jul 18, 2026
ce0eaa7
Close Lotus workflow gating bypasses
safal207 Aug 27, 2026
8bce1dd
Harden Lotus test discovery configuration
safal207 Aug 27, 2026
530a808
Harden Lotus workflow discovery proof
safal207 Aug 27, 2026
0862cf6
Close remaining Lotus discovery bypasses
safal207 Aug 27, 2026
3bb3fed
Bound Lotus CI prerequisite trust
safal207 Aug 27, 2026
c9d7bbb
fix: isolate Lotus Elixir contract execution
safal207 Aug 27, 2026
c7a76da
Pin explicit Lotus test source
safal207 Aug 27, 2026
b4eded4
Bind Lotus test execution evidence
safal207 Aug 28, 2026
8031324
Block pytest dependency shadows
safal207 Aug 28, 2026
0b21952
Block bundled py pytest shadows
safal207 Aug 28, 2026
30d9f01
Require automatic hosted workflow evidence
safal207 Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions .github/workflows/lotus-family-conformance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
name: Lotus Family conformance

on:
pull_request:
paths:
- "standards/lotus-family/**"
- ".github/workflows/lotus-family-conformance.yml"
push:
paths:
- "standards/lotus-family/**"
- ".github/workflows/lotus-family-conformance.yml"
workflow_dispatch:

permissions:
contents: read

jobs:
conformance:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false

- name: Set up Python
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: "3.12"

- name: Run Lotus Family conformance suite
run: |
python -m unittest discover \
-s standards/lotus-family/conformance \
-p 'test_*.py' \
-v
2 changes: 2 additions & 0 deletions standards/lotus-family/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
artifacts/
__pycache__/
7 changes: 7 additions & 0 deletions standards/lotus-family/ACCEPTANCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Acceptance criteria

- Removing a required English or Russian contract term produces `DRIFT`.
- A regression test that is not discovered by configured CI produces `DRIFT`.
- Missing snapshots, refs, or exact commit identities produce `UNKNOWN`, never `PASS`.
- Evidence records checked file paths and SHA-256 hashes.
- Audit results remain advisory and grant no execution or merge authority.
15 changes: 15 additions & 0 deletions standards/lotus-family/DECISION-CODES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Lotus Family audit result codes

| Outcome | Reason code | Meaning |
|---|---|---|
| `PASS` | `LOTUS_CONTRACT_CONFORMANT` | Every configured invariant passed for the supplied snapshot and caller-provided identity claims. |
| `DRIFT` | `LOTUS_CONTRACT_DRIFT` | A required contract, test, or executable CI discovery invariant is missing. |
| `UNKNOWN` | `SNAPSHOT_UNAVAILABLE` | The repository snapshot is unavailable. |
| `UNKNOWN` | `COMMIT_SHA_INVALID` | The supplied commit claim is not a lowercase 40-character SHA. |
| `UNKNOWN` | `REPOSITORY_REF_MISSING` | The repository ref claim was not supplied. |
| `UNKNOWN` | `REPOSITORY_NOT_CONFIGURED` | No manifest adapter exists for the repository ID. |
| `UNKNOWN` | `MANIFEST_INVALID` | The manifest cannot be parsed or violates the audit-only boundary. |

Consumers must branch on `outcome` and `reason_code`, not on human-readable detail.
A `PASS` does not verify remote provenance and grants no ownership, approval,
execution, delivery, deployment, or merge authority.
5 changes: 5 additions & 0 deletions standards/lotus-family/IMPLEMENTATION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Implementation slice v0.1

This first slice turns the Lotus Family strength map into executable checks.
It intentionally audits materialized exact snapshots and does not perform remote
repository access or consequential actions.
4 changes: 4 additions & 0 deletions standards/lotus-family/NOTICE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# Authority notice

Lotus Family audit output is advisory evidence only. It does not grant ownership,
approval, execution, delivery, deployment, or merge authority.
89 changes: 89 additions & 0 deletions standards/lotus-family/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
# Lotus Family Conformance v0.1

A bounded, machine-readable audit surface for checking the shared Lotus contract
across Pythia, CML, and LS.

## Outcomes

- `PASS` β€” every configured content and executable-CI invariant passed for the
supplied snapshot and the caller-provided repository, ref, and commit claims.
- `DRIFT` β€” the snapshot is available, but a required contract term, regression
test, or CI discovery rule is missing.
- `UNKNOWN` β€” the repository snapshot, ref claim, commit claim, or manifest could
not be evaluated safely. `UNKNOWN` is never promoted to `PASS`.

## Identity assurance

Version 0.1 does not fetch a remote repository and does not prove commit
reachability or a clean working tree. Repository, ref, and commit values are
caller-provided claims recorded in evidence. Results expose
`identity_assurance.mode = caller_claim_only` so consumers cannot mistake these
claims for verified provenance.

SHA-256 evidence binds each check to the exact bytes read and evaluated from the
supplied snapshot. It does **not** prove that those bytes came from the claimed
remote repository, ref, or commit. Independent trusted materialization and
provenance verification are required before evidence may be called fresh for an
exact head.

Until that verification exists, `PASS` means conformance of the supplied
snapshot contents, not cryptographic proof that the snapshot came from the
claimed remote commit.

## Causal spacetime testing model

The test model has two compatible layers:

- `causality/lotus-family-causality-v0.1.json` and
`causality/test-paths-v0.1.json` preserve the original causal routes;
- `causality/lotus-family-system-v0.1.json` and
`causality/system-routes-v0.1.json` add spatial, temporal, hierarchical, and
trajectory views.

The system graph separates bounded snapshot `PASS` from independently verified
exact-head freshness and merge eligibility. Centrality means review priority and
blast radius only; it never grants ownership, approval, execution, delivery, or
merge authority.

Every new blocker must add or reuse a graph node and include an executable route
when runtime behavior is involved. This prevents isolated regression tests from
hiding missing relationships between workflow structure, inherited execution
context, test selection, evidence, and verdicts.

## Boundary

The auditor is read-only and `audit_only`. Its result does not grant ownership,
approval, execution, delivery, deployment, or merge authority.

It does not fetch repositories, call GitHub, merge pull requests, or deploy
software. An integration materializes the repository snapshot it wants to audit.

## Snapshot layout

```text
snapshot-root/
safal207__pythiaLabs/
safal207__Causal-Memory-Layer/
safal207__LS/
```

Each directory must contain the files named by
[`manifest/lotus-family-v0.1.json`](manifest/lotus-family-v0.1.json).

## Run one audit

```bash
python standards/lotus-family/conformance/lotus_family_auditor.py \
--manifest standards/lotus-family/manifest/lotus-family-v0.1.json \
--snapshot-root /path/to/snapshots \
--repository-id pythia \
--repository-ref refs/heads/main \
--commit-sha 0123456789abcdef0123456789abcdef01234567 \
--output artifacts/lotus-family/pythia.json
```

Exit codes are `0` for `PASS`, `2` for `DRIFT`, and `3` for `UNKNOWN`.

The evidence artifact records the caller-provided repository identity claims,
check outcomes, checked file paths, SHA-256 hashes, identity-assurance limits,
and the audit-only authority boundary.
20 changes: 20 additions & 0 deletions standards/lotus-family/ROADMAP.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# Lotus Family auditor roadmap

## v0.1

- manifest for Pythia, CML, and LS;
- syntactically exact repository ref and commit SHA claims;
- explicit `caller_claim_only` identity assurance;
- `PASS / DRIFT / UNKNOWN` outcomes;
- bilingual contract, authority firewall, regression test, and executable CI discovery checks;
- causal graph, executable causal routes, and derived traceability;
- SHA-256 evidence from the same bytes used for evaluation;
- audit-only authority boundary.

## Follow-up

- materialize snapshots through a trusted integration;
- verify remote repository identity, commit reachability, and clean snapshot state;
- sign or attest evidence artifacts without granting execution authority;
- aggregate three repository results into one family report;
- generate selected regression fixtures from causal routes while keeping human review.
1 change: 1 addition & 0 deletions standards/lotus-family/VERSION
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
0.1
68 changes: 68 additions & 0 deletions standards/lotus-family/causality/SYSTEM-MODEL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
# Lotus causal spacetime system model

The system model extends the original causal test graph with four additional
views while keeping one audit-only source of truth.

## Five dimensions

- **Causal** β€” why a condition changes risk or outcome.
- **Spatial** β€” where evidence exists: repository, file, workflow, job,
dependency graph, step, inherited shell, working directory, test scope,
evidence bundle, review, or merge gate.
- **Temporal** β€” which state must precede another and when independently bound
exact-head evidence becomes stale.
- **Hierarchy** β€” how goals, invariants, controls, evidence, outcomes, gates, and
authority boundaries relate.
- **Trajectory** β€” how the system moves toward bounded snapshot `PASS`,
fail-closed `DRIFT`, stale evidence, or merge eligibility.

Machine-readable sources:

- `lotus-family-system-v0.1.json` β€” 49 nodes, 64 unique directed
relationships, centers, and four canonical trajectories;
- `system-routes-v0.1.json` β€” 36 connected routes, including runtime
regressions and governance-only merge trajectories.

## Centers without centralized authority

The model has separate semantic, snapshot-evidence, and governance centers:
the invariant set, same-byte hashes, independently verified exact head, and the
advisory authority boundary.

Same-byte hashing proves which supplied bytes were evaluated. It does not prove
remote provenance. `center.exact_head` participates only in governance
trajectories after `gate.provenance_verified`; runtime audit `PASS` routes retain
`limitation.identity_unverified`.

Centrality scores mean review priority and blast radius only. A highly connected
node deserves stronger tests and independent review; it does not gain ownership
or approval authority.

## Time and merge separation

`PASS` belongs to the bounded snapshot-audit trajectory. Merge eligibility is a
separate trajectory requiring independent provenance binding, fresh exact-head
evidence, green CI, green security, a fresh exact-head review, and no actionable
blockers. Even `state.merge_eligible` terminates at
`authority.advisory_only`.

A head change moves independently bound evidence to `time.evidence_stale`, which
leads to `state.merge_blocked` until checks and review are rerun on the new exact
head.

## Effective execution context

GitHub Actions `defaults.run` values are resolved through workflow, job, and step
scope. Step-level values override job defaults, and job defaults override
workflow defaults. Unknown shells and non-root or dynamic working directories
fail closed because raw command text alone cannot prove which tests execute.

## New blocker rule

Every newly discovered blocker must:

1. add or reuse a system node;
2. add a directed relationship if the causal, spatial, temporal, or hierarchical
link is new;
3. include an executable route when runtime behavior is involved;
4. preserve the boundary `PASS != APPROVED != MERGED`.
37 changes: 37 additions & 0 deletions standards/lotus-family/causality/TRACEABILITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# Lotus Family causal traceability

The causality graph is the primary behavioral model. This table is the human-readable coverage ledger. A route is valid only when each adjacent node pair is an edge in `lotus-family-causality-v0.1.json`, and the route executes to the declared outcome in `test_causality_model.py`.

## Policy

- New blockers add or reuse a causal node before a regression route is accepted.
- `PASS` routes must reach evidence produced from the same bytes that were evaluated.
- `DRIFT` routes model a broken invariant or a false-positive CI path.
- `UNKNOWN` routes model evidence that cannot be evaluated safely.
- All outcomes remain advisory and grant no merge or execution authority.

## Routes

| Route | Repository | Scenario | Expected | Causal path |
|---|---|---|---|---|
| `CML-PASS-001` | `cml` | `valid` | `PASS` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.direct_run β†’ control.test_env_clean β†’ control.shell_straight_line β†’ control.contract_test_selected β†’ evidence.same_bytes_hashed β†’ outcome.pass β†’ authority.advisory_only |
| `LS-PASS-001` | `ls` | `valid` | `PASS` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.direct_run β†’ control.test_env_clean β†’ control.shell_straight_line β†’ control.contract_test_selected β†’ evidence.same_bytes_hashed β†’ outcome.pass β†’ authority.advisory_only |
| `PYTHIA-PASS-001` | `pythia` | `valid` | `PASS` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.direct_run β†’ control.test_env_clean β†’ control.shell_straight_line β†’ control.contract_test_selected β†’ evidence.same_bytes_hashed β†’ outcome.pass β†’ authority.advisory_only |
| `CI-NONRUN-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.non_run_text β†’ risk.false_ci_pass β†’ outcome.drift |
| `CI-STEP-SKIP-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_skipped β†’ risk.false_ci_pass β†’ outcome.drift |
| `CI-JOB-SKIP-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_not_runnable β†’ risk.false_ci_pass β†’ outcome.drift |
| `CI-NO-RUNNER-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_not_runnable β†’ risk.false_ci_pass β†’ outcome.drift |
| `CI-QUOTED-ENV-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.direct_run β†’ control.test_env_override β†’ risk.false_ci_pass β†’ outcome.drift |
| `CI-SHELL-CONTROL-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.direct_run β†’ control.test_env_clean β†’ control.shell_control_flow β†’ risk.false_ci_pass β†’ outcome.drift |
| `CML-SUBSET-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.direct_run β†’ control.test_env_clean β†’ control.shell_straight_line β†’ control.contract_test_excluded β†’ risk.false_ci_pass β†’ outcome.drift |
| `PYTHIA-SUBSET-001` | `pythia` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_runnable β†’ control.step_enabled β†’ control.direct_run β†’ control.test_env_clean β†’ control.shell_straight_line β†’ control.contract_test_excluded β†’ risk.false_ci_pass β†’ outcome.drift |
| `CI-FAKE-STEPS-001` | `cml` | `workflow` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_present β†’ control.workflow_job_not_runnable β†’ risk.false_ci_pass β†’ outcome.drift |
| `IDENTITY-INVALID-001` | `cml` | `invalid_commit` | `UNKNOWN` | input.snapshot_present β†’ input.identity_claims_invalid β†’ outcome.unknown |
| `SNAPSHOT-MISSING-001` | `cml` | `missing_snapshot` | `UNKNOWN` | input.snapshot_missing β†’ outcome.unknown |
| `CONTRACT-DRIFT-001` | `cml` | `missing_term` | `DRIFT` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ control.manifest_valid β†’ control.contract_terms_missing β†’ outcome.drift |
| `IDENTITY-LIMIT-001` | `cml` | `valid` | `PASS` | input.snapshot_present β†’ input.identity_claims_well_formed β†’ limitation.identity_unverified β†’ risk.identity_overclaim β†’ authority.advisory_only |
| `MANIFEST-INVALID-001` | `cml` | `invalid_manifest` | `UNKNOWN` | control.manifest_invalid β†’ outcome.unknown |

## Coverage interpretation

Node coverage shows that a condition or decision is represented. Edge coverage shows that a causal relationship is exercised. Route coverage shows that an end-to-end behavioral path reaches the expected `PASS`, `DRIFT`, or `UNKNOWN` result. The matrix remains useful for review and audit, but it is derived from the causal routes rather than acting as the source of truth.
Loading
Loading