Skip to harness content
Open technical reference map

Assurance source reference

Production Assurance Gap Register

Complete canonical source reference from docs/PRODUCTION_ASSURANCE_GAP_REGISTER.md.

Canonical pathdocs/PRODUCTION_ASSURANCE_GAP_REGISTER.mdRevision69bab1cInspect source

Production Assurance Gap Register

Decision

The Layer 0, workload-taxonomy, thirteen-domain, domain-pack, skill-router, and goal-loop design is internally coherent and executable. Asynchronous workflow orchestration is correctly modeled as a cross-cutting concern; adding a fourteenth production domain would weaken the model.

This does not make Valdris a self-certifying production authority. The v0.9 release candidate implements the missing interfaces and adversarial validators, while a real target must still commission external keys, thresholds, semantic adapters, an executor, and a rollback-resistant head before an authoritative claim is available.

v0.9 mechanism closure and commissioning status

PriorityCapabilityImplemented mechanismRemaining commissioning condition
P1Control-specific semantic proofvaldris.semantic-proof-adapter.v1 binds control, command, schemas, tier, bounds, validator, and assertions; valdris.semantic-execution-receipt.v1 signs the exact input, result, validator, tier, assertions, environment, and successful execution window.Target owner supplies a control-specific adapter and commissions its trusted execution signer; generic or agent-invented command success is rejected.
P1Acceptance thresholdsvaldris.acceptance-policy.v1 binds owner, version, source, digest, and thresholds plus a signed approval.Protected owner approves the target policy; the executing agent cannot select or weaken it.
P1AI workload identityuash.ai-workload-identity.v1 binds model, provider, prompt, tools, corpus, memory, eval, smoke, and observability; runtime routing is cross-bound.Commission actual provider/model and runtime receipt issuers.
P1Authoritative approvalsuash.approval-receipt.v1 uses operator-pinned Ed25519 trust, expiry, scope, artifact digest, correlation, and provider receipt.Add protected authority keys and live approval-provider verification.
P1Effective-tier eval coverageuash.agent-eval-plan.v1 derives mandatory dimensions from AI0-AI3; implementation readiness prevents post-hoc weakening.Commission datasets, rubrics, and semantic thresholds for the target.
P1Immutable proof executionOptional OCI reference executor uses an immutable image, read-only source, isolated output, clean environment, no network, resource limits, and signed receipt.Commission Docker/Podman or equivalent external runner and its protected signing key.
P1Rollback-resistant headOptional GitHub adapter performs a provider-backed expected-sequence/head compare-and-swap and signs the provider receipt; it is the only currently executable authoritative head validator.Commission a protected GitHub branch, or first add and review an executable validator for an equivalent WORM/TPM provider; signed provider JSON alone is rejected.
P1Implementation readinessuash.implementation-readiness.v1 resolves contracts and failing baselines; uash.implementation-readiness-receipt.v1 externally signs their digests, eval plan, monotonic head, and first-implementation boundary.Commission a protected readiness/head signer and invoke it before the first implementation event.
P1AI change reviewuash.ai-change-review.v1 reconstructs the declared base/head Git diff, exact changed paths, and changed lockfiles, then requires dependency, error-path, test, security, and observability coverage.Independent review supplies target-specific conclusions and evidence.
P1Prototype promotionuash.promotion-receipt.v1 rejects reuse of prototype evidence as production proof and binds rollback.Required only when a prototype is promoted.
P1Requirement traceabilityuash.requirements-contract.v1 maps requirements to acceptance criteria, sealed red tests, eval suites, API/event schema identities, and goal stopping conditions before the readiness seal.Product owner commissions the requirement statements and acceptance ownership.
P1Observable trace and decisionsvaldris.trace-receipt.v2 binds the exact evaluated trajectory artifact, JSONL trace path/digest/event count, redaction policy, runtime session, and uash.decision-evidence.v1; trace lines and decisions reject private model reasoning.Runtime trace/decision producer and authoritative signer must be commissioned.
P1Runtime driver and implementation executionvaldris.runtime-driver.v1 binds an external Codex/Claude/Hermes/custom adapter, goal/stop policy, durable lease/CAS checkpoint, and valdris.implementation-execution-receipt.v1. runtime-driver-state.mjs supplies a provider-neutral state reference.Commission the chosen runtime adapter and protected execution signer; Valdris remains the control plane, not an IDE or generic scheduler.
P2Typed tools and durable memoryvaldris.tool-registry.v1 plus observed call receipts bind schemas, effects, risk, approvals, timeout/retry/idempotency, hooks, and scopes. valdris.memory-head-receipt.v1 advances provider/store heads across sessions and isolation scopes.Commission actual tool providers, approval issuers, and memory store/head signer.
P2Conditional model judgesuash.model-judge-calibration.v1 is mandatory only for model evaluators and binds independent judge/model/provider/prompt identities, human labels, agreement/error limits, critical slices, and expiry. Deterministic evaluators need no model judge.Commission judge datasets, human labels, thresholds, expiry, and independent provider identity.
P2AI economicsuash.ai-economics-ledger.v1 reconciles signed provider usage with input/output tokens, model/tool spend, retry waste, tool calls, trajectory attempts, latency, human review, budget, and tenant attribution where applicable.Commission pricing and provider billing receipt adapters.
P2MCP/A2A interoperabilityvaldris.interop-transcript.v1 requires initialization, version/schema negotiation, auth-root isolation, discovery, correlation, timeout, cancellation, unknown-tool rejection, and replay protection for each declared protocol. valdris.interop-execution-receipt.v1 separately attests the exact adapter, trusted runner, executor, auth root, timeout, transcript, and request/response/assertion sets, with commissioned executor and authority principals that cannot share actor or key identity.Commission a live conformance runner and an independent trusted execution-receipt signer for each enabled connector/protocol.
P2Dependency provenancevaldris.dependency-provenance.v1 is required for every added/updated dependency and binds registry/source, publisher, license, content/integrity/vulnerability/provider receipts, allowlist approval, and a confusable-name check.Commission registry transparency/vulnerability adapters and the approved dependency allowlist.
P2Runtime, agents, routingvaldris.runtime-session.v1 binds connector conformance, DAG/fan-in, capabilities/hooks, context v2, model minimum-capability/quality/fallback routing, AI identity, budgets, and all operating-contract bindings.Live provider/model routing telemetry and receipt issuers remain commissioned adapter work.
P2Production learninguash.harness-learning.v1 binds failure, RCA, cause cluster, regression, reviewed change, expiry, and rollback; auto-application is forbidden.Required when production evidence changes the harness.

Until those target-specific conditions are commissioned, final handoff must distinguish structural, semantic, and authoritative status and leave missing external proof open. The repository remains 0.9.0-rc.1; a real provider-backed authoritative run is required before tagging v0.9.0.

Clean-room residual risk

PriorityGapWhy it mattersRequired acceptance test
Accepted residualPre-existing public Git history retentionThe current canonical tree, release artifacts, and newly generated commissioned packs can pass clean-room gates while older public commit objects still retain content removed by a normal PR. Full-history secret scanning detects supported patterns but does not delete Git objects, downstream clones, forks, or caches.ADR-0001 records owner acceptance for this non-destructive merge. Any future rewrite remains a separate explicitly authorized operation followed by reachable-ref and published-artifact rescanning.

Remaining hardening backlog

PriorityGapIntended direction
P2Conditional pack featuresMake SaaS metering/billing and youth-AI controls conditional on actual product features rather than the broad pack alone.
P3Additional provider adaptersAdd optional provider-specific executors, WORM/TPM heads, and receipt importers without making any vendor universal.

Closed in the Layer 0 hardening

  • Layer 0 is a prerequisite foundation, not production domain 14.
  • Temporal, SQS, queues, schedulers, workers, retries, and durable workflows route as cross-cutting orchestration across business logic, data, platform, overload, observability, and recovery.
  • Controlled HIPAA, security, rollback, prompt-injection, and payment-policy documents retain tier/concern review without pretending runtime behavior changed.
  • Ordinary README/copy work remains lightweight and receives scoped write authority.
  • SDKs, CLI packages, static frontends, and React context providers no longer trigger full-stack or live-provider proof accidentally.
  • Hard production dependencies are enforced; conditional dependencies do not over-project unrelated domains.
  • RBAC, patient data, regulated decisions, realtime state, iOS distribution, and modern AI/provider terms route to the intended concerns and packs.
  • Effective assurance tier governs foundation, production, AI, domain, and goal evidence freshness/trust.
  • Catalog integrity is unconditional, including inactive domain packs and docs-only routes.
  • Skill phases, canonical primaries, supporting skills, immutable initial artifacts, and deterministic task/tier budgets are machine-enforced.

Closed in the v0.8 clean-room assurance merge

  • Restricted project material is excluded from the current canonical tree, release artifacts, and newly generated commissioned packs by project-neutrality and privacy gates; real operational run packets are not committed to those current surfaces. Pre-existing public commit objects remain governed by the accepted residual-risk decision above.
  • The only direct-copy surface is an allowlisted, hash-verified MIT public assurance kernel pinned to its upstream commit.
  • All source assurance concepts have an explicit Valdris mapping, and schema compatibility rejects unmapped controls, weakened status conversion, unknown tiers, unsafe paths, and any Layer 14 async mapping.
  • Async workflow assurance is expressed as five cross-cutting controls spanning the applicable existing domains.
  • Proof commands run portably with argv arrays, timeouts, output bounds, repetition, redaction, optional red-baseline evidence, and exact pre/post Git/worktree/validator bindings; Windows npm shims run without enabling shell execution. These snapshots reject net mutation and later post-proof changes, but do not close the transient mutate-and-restore blocker above. The v0.8 bridge likewise revalidates the commissioned runtime before every nested gate and after the gate sequence, but its validate-then-spawn pathname interval is not an immutable execution environment and remains covered by this same open P1 blocker.
  • Privacy recursively scans the canonical harness tree and generated .valdris-harness pack, evaluates every same-line candidate, and fails closed on binary content unless a shipped public asset matches an approved path and SHA-256. After next build, a separate release-artifact mode scans the otherwise ignored .next production text surfaces for high-confidence credentials and deployable local-user paths, permits only known binary asset extensions, and fails closed on unscannable executable/config content; its focused verifier proves generated caches, development output, source maps, traces, dependency traces, build-root metadata, and expected binary assets do not create false positives while binary code and an embedded server-bundle credential fail. Commissioned target binaries use project policy; generated graph/ and design/anchors.json receive a separate bounded evidence scan.
  • Typed RCA is required for bugs (including regressions), incidents, and self-heal corrective work, and binds one regression command and failure signature across distinct existing pre-fix/post-fix commits plus a real source change.
  • Independent review requires an Ed25519 signature from a committed project trust store; digest-bound run packets validate canonical intake, classification, route, goal, and route-applicable gate artifacts.
  • Context manifests now commission a provider-neutral repo-specific case set, answer key, baseline mode, metric direction, candidate threshold, and positive minimum delta. The eval gate requires paired uash.context-arm-result.v1 JSON documents bound to the exact manifest, derives aggregate score/case count/critical-regression count from ordered per-case evidence, requires identical evaluator/model/prompt/config identities, and fails closed when the comparison is absent, stale, or detached from its result bytes.
  • Bridge state transitions are serialized per canonical run ID and journal-first; lossy storage aliases are rejected and a data-directory lease prevents multi-process writers. A separate exclusive recovery mutex covers stale-main-lease revalidation, unlink, and replacement, closing the concurrent-reclaimer race; malformed or stale recovery mutexes require explicit operator cleanup instead of automatic theft. Atomic snapshot replacement, incomplete-tail recovery, first-event seal replay, and run-ID-bound HMAC bindings over the immutable commissioning record, derived snapshot, event journal, and artifact SHA-256 claims prevent concurrent event loss, forged replay, crash-gap baseline adoption, persistent post-claim artifact drift, and commissioned-to-local downgrade. Required artifact bytes are rechecked before and after finish-line gates. Three distinct credentials are mandatory at startup: the bridge-only integrity key authenticates state, the ordinary access token authorizes API reads/writes and the server-side UI proxy, and the human approval token additionally authorizes grant/deny events. Raw credentials are never persisted, agents never receive the integrity or human token, and there is no ambiguous unsigned mode.

Proof commands

npm run typecheck
npm run dependency:audit
npm run build
npm run knowledge:gate
npm run skills:gate
npm run catalog:gate
npm run provenance:gate
npm run neutrality:gate
npm run privacy:gate
npm run verify:release-privacy
npm run privacy:release
npm run schema:compat:gate
npm run code-intelligence:scan
npm run code-intelligence:gate
npm run verify:enterprise-ai
npm run verify:proof-security
npm run verify:run-packet-trust
npm run verify:v09-assurance
npm run verify:work-harness-import
npm run verify:commissioned-portability
npm run verify:harness

Passing these proves the checked structural contracts and v0.9 adversarial mechanisms. It does not commission a target, create real external receipts, authorize a v0.9.0 tag, or purge pre-existing public Git history.