configuration/grammar/data/template.verification.data.json

configuration/grammar/data/template.verification.data.json is a file in GovLab Context. 70 lines of code and 0 definitions.

{
    "copyright": "PAG (Pattern Abstract Grammar) © Bane's Lab, CC BY-SA 4.0. Used with the author's explicit permission; attribution must be preserved. See ../../../LICENSE.",
    "check": {
        "by": [
            "the template round-trip check, which fills the template and validates the result against the grammar",
            "the slot check, which requires every declared slot to appear in the body and every slot in the body to be declared"
        ],
        "population": "this template's body and slots, and every document created from it",
        "freshness": "a verdict stands until the template, its document type or the grammar changes",
        "refusal": "the gate fails on a dangling slot, an unregistered type, or a filled template that does not validate",
        "observation": "none: a template is static text, and nothing observes it while a run executes",
        "evidence": "fires-and-accepts: one suite plants a slot the body never carries and a template of an unregistered type, another plants a retired head in a real template, and every filled template validates clean",
        "authority": "the template's document type and the grammar, which every document created from the template conforms to"
    },
    "type": "VERIFICATION",
    "title": "Forensic Context Verification Meta-Template (calibrated, adversarially-tested claim adjudication)",
    "slots": [
        {
            "name": "convention.max_recursion_depth",
            "description": "the recursion bound governing escalation and repair cycles",
            "required": true,
            "kind": "string"
        },
        {
            "name": "self.definition",
            "description": "this agent's own definition, read for the recursive self-audit",
            "required": true,
            "kind": "string"
        },
        {
            "name": "target",
            "description": "the system or artifact whose context claims are being verified",
            "required": true,
            "kind": "string"
        },
        {
            "name": "context_claims",
            "description": "the set of context claims to classify against implementation evidence",
            "required": true,
            "kind": "string"
        },
        {
            "name": "task_name",
            "description": "kebab-case name for the output file",
            "required": true,
            "kind": "string"
        }
    ],
    "constraints": [
        "declaration_required",
        "gate_per_node",
        "contract_reads_prior_output",
        "population_declared",
        "refusal_before_write",
        "invariant_has_objector",
        "evidence_grounded",
        "trust_anchor_disclosed_not_verified",
        "op_sets_mutually_exclusive_investigate_action",
        "claims_kinded_by_ontological_dimension",
        "claims_worth_ranked_before_probe",
        "detectors_calibrated_false_positive_and_false_negative",
        "observations_gathered_never_inferred",
        "matches_adversarially_tested",
        "recursive_self_audit_run",
        "escalation_builds_a_tool_or_marks_unverified_never_infers",
        "exactly_one_typed_artifact",
        "unknown_is_not_pass"
    ],
    "body": "---\nname: {task_name}\ntype: VERIFICATION\nversion: 1.0.0\n---\n\nTHIS VERIFICATION PERFORMS a forensic adjudication that classifies every context claim verified, contradicted or unverified against observable implementation evidence, with detectors calibrated and adversarially tested before any claim is trusted.\n\n%% META %%:\n    priority: EVIDENCE > TRUST_ANCHOR > TASK\n    trust: implementation_observation = TRUSTED, prior_knowledge = UNTRUSTED, a_claim = UNTRUSTED_UNTIL_MAPPED\n    objective: {context_claims}\n    jurisdiction: {context_claims} about {target} | external: the runtime, filesystem, command execution and tool io the trust anchor discloses\n    recursion_limit: {convention.max_recursion_depth}\n\n# NODE 1 — ORIENT   [epistemic · ontology · set-theory · yields: set]\n@purpose: \"disclose the trust anchor, bind one op-set, and kind every claim by its ontological dimension before touching any claim\"\n@genesis: existence\nCONTRACT:\n  input:     {context_claims} about {target}\n  transform: EXTRACT_FACTS <the minimal assumptions and the cannot-verify-the-verifier boundary> FROM <this document> INTO anchor; DETERMINE <INVESTIGATE or ACTION> INTO op_set; FOR EACH claim IN {context_claims}: CLASSIFY claim BY <its ontological dimension and evidence shape>\n  constraints: the anchor is disclosed, never verified; INVESTIGATE allows gap discovery, testing and documentation and forbids mutation; ACTION allows a bounded fix and forbids discovery; the two are disjoint\n  output:    run_context\nDECLARE run_context: object\nSET run_context = {anchor: anchor, op_set: op_set, claims: <every claim with its kind, evidence shape and math type>}\nHANDOFF GATE (evidence-bearing):\n  rule_id: \"ORIENT\"   yields: boolean\n  [check] the trust anchor is disclosed with its assumptions and boundary (evidence: run_context.anchor)\n  [check] exactly one op-set is bound and its allowed and forbidden operations are disjoint (evidence: run_context.op_set)\n  [check] every claim carries a kind and an evidence shape (evidence: run_context.claims) over: {context_claims} measured: <kinded> / <claims>\n  result: pass → NODE 2 | unkinded claim → REPAIR (owner: NODE 1) | unknown → BLOCKED\n\n# NODE 2 — INTENT   [conative · teleology · optimization · yields: ranking]\n@purpose: \"rank claims by verification worth and choose the method per claim by utility minus cost before probing anything\"\n@genesis: difference\n@mandatory\nCONTRACT:\n  input:     run_context from NODE 1\n  transform: FOR EACH claim IN run_context.claims: CALCULATE_METRIC risk times uncertainty FROM claim INTO claim.worth; FOR EACH claim IN run_context.claims: RANK <its admissible methods> BY risk-weighted coverage minus cost\n  constraints: a method is admissible only when its capability is available; a high-worth claim with no admissible method is marked will-be-unverified, never inverted below a low-worth escalation\n  output:    methods\nDECLARE methods: array\nSET methods = <one chosen method per claim, the argmax admissible one>\nHANDOFF GATE (tel-priority injection-gate):\n  rule_id: \"INTENT\"   yields: boolean over ranking\n  [check] every claim carries a worth and a chosen method (evidence: methods) over: run_context.claims measured: <with method> / <claims>\n  [check] each chosen method is the argmax of risk-weighted coverage minus cost (evidence: the per-claim ranking)\n  [check] no high-worth claim is left unmapped while a low-worth claim escalates (evidence: the worth order against the escalations)\n  result: pass → NODE 3 | priority inversion → REPAIR (owner: NODE 2) | unknown → BLOCKED\n\n# NODE 3 — CALIBRATE   [epistemic · analysis · graph · yields: set + boolean]\n@purpose: \"probe the runtime, calibrate every detector the chosen methods use against both controls, and arm the defenses before trusting any tool\"\n@genesis: relation\nCONTRACT:\n  input:     methods from NODE 2\n  transform: EXECUTE_TOOL <capability probes> WITH timeout: <bound> INTO capability; FOR EACH detector IN <the detectors the methods need>: EXECUTE_TOOL detector WITH <a known-good and a known-bad fixture> INTO detector.reliability; <arm sanitize, safe arithmetic and recursion control to {convention.max_recursion_depth}>\n  constraints: a detector is untrusted until it passes both controls; probing is by capability, never by an operating-system string\n  output:    capability_plan\nDECLARE capability_plan: object\nSET capability_plan = {mode: <full, degraded or blocked>, detectors: <each with its reliability>, defenses: <armed>}\nHANDOFF GATE (evidence-bearing):\n  rule_id: \"CALIBRATE\"   yields: boolean\n  [check] capabilities probed and classified (evidence: capability_plan.mode)\n  [check] every needed detector ran both the false-positive and the false-negative control (evidence: detector.reliability) over: needed detectors measured: <calibrated> / <detectors>\n  [check] the defenses are armed (evidence: capability_plan.defenses)\n  refuse: a probe that would mutate the target before EXECUTE_TOOL\n  result: pass → NODE 4 | unreliable detector → REPAIR (owner: NODE 2) | unknown → BLOCKED\n\n# NODE 4 — GATHER   [epistemic · formalization · computation · yields: set]\n@purpose: \"resolve each claim to an observable evidence requirement, order by verdict genesis, gather observations from the implementation, and hold the op-set\"\n@genesis: transformation\nCONTRACT:\n  input:     capability_plan from NODE 3\n  transform: FOR EACH claim IN run_context.claims: EXTRACT_FACTS <the observation that would settle it> FROM claim INTO requirement; ORDER requirements BY genesis rank then dependency; FOR EACH requirement IN requirements: READ_RESOURCE <the implementation it names> INTO observation\n  constraints: a requirement names the settling observation, never a presumed verdict; an observation is gathered, never inferred; a string crosses a boundary only after sanitize; a mutation under INVESTIGATE or a discovery under ACTION is inadmissible\n  preserves: the distinction between observed, pending escalation and absent\n  output:    observations\nDECLARE observations: array\nSET observations = <one per direct requirement, each bound to real implementation, escalations flagged pending>\nHANDOFF GATE (evidence-bearing):\n  rule_id: \"GATHER\"   yields: boolean\n  [check] every claim resolves to an observable requirement naming the settling observation (evidence: requirements) over: run_context.claims measured: <mapped> / <claims>\n  [check] every direct requirement produced an observation from the implementation and none was inferred (evidence: observations)\n  [check] the op-set was honored, every boundary cross was sanitized and recursion stayed bounded (evidence: the admissibility record)\n  result: pass → NODE 5 | inadmissible act → REPAIR (owner: NODE 1) | unknown → BLOCKED\n\n# NODE 5 — ADJUDICATE   [evaluative · verification · logic + probability · yields: set + number]\n@purpose: \"judge each observation against evidence, behavioral contract and hostile inputs, judge this agent's own claims, and resolve escalations without inference\"\n@genesis: constraint\n@mandatory\nCONTRACT:\n  input:     observations from NODE 4\n  transform: FOR EACH observation IN observations: CLASSIFY observation BY <verified, contradicted or unverified>; EXECUTE_TOOL <the detectors> WITH <traversal, null-byte, homoglyph, comment and spoof inputs> INTO adversarial; ANALYZE_CONTENT {self.definition} AGAINST <its own must and always claims> INTO self_audit; FOR EACH escalation IN <pending escalations>: <build a bounded tool or mark the claim unverified>\n  constraints: a match is not evidence until the calibration and adversarial verdicts hold; an overclaim downgrades confidence below threshold; an escalation is never resolved by inference; a stale write is rewritten as complete state\n  output:    adjudication\nDECLARE adjudication: object\nSET adjudication = {verdicts: <one per claim>, adversarial: adversarial, self_audit: self_audit, confidence: <a number in zero to one>, refuter: <what would flip a verdict>}\nHANDOFF GATE (ver-stop gate):\n  rule_id: \"ADJUDICATE\"   yields: boolean\n  [check] every claim is classified with its evidence and a refuter is named (evidence: adjudication.verdicts) over: run_context.claims measured: <classified> / <claims>\n  [check] every detector survived the adversarial inputs with the expected outcome (evidence: adjudication.adversarial)\n  [check] the recursive self-audit ran and an overclaim downgraded confidence (evidence: adjudication.self_audit)\n  [check] no pending escalation remains unresolved by tool or by an unverified mark (evidence: the escalation record)\n  refuse: an adversarial input that would escape the intended root before EXECUTE_TOOL\n  standing: moved-set <the implementation files re-read since NODE 4>\n  result: pass → NODE 6 | untested match → REPAIR (owner: NODE 3) | unknown → BLOCKED\n\n# NODE 6 — TERMINATE   [evaluative · termination · set-theory · yields: artifact]\n@purpose: \"emit exactly one typed artifact, deduplicated, naming every limitation, and stop only on saturation and completion and verification\"\n@genesis: emergence\n@mandatory\nCONTRACT:\n  input:     adjudication from NODE 5\n  transform: COMPOSE_ARTIFACT artifact FROM {run_context, adjudication} USING <the investigation report, the action log, or the blocked report>; REDUCE artifact.findings TO <one per claim and verdict>; PERSIST_ARTIFACT artifact TO <{task_name} report>; REPORT_RESULT artifact TO <the parties whose next work it creates>\n  constraints: exactly one artifact, bound at orientation; a self-assessed done is not ter-stop\n  output:    artifact\n  freshness: fingerprint(adjudication) + fingerprint(this document)\nHANDOFF GATE (ter-stop gate):\n  rule_id: \"TERMINATE\"   yields: boolean\n  [check] exactly one typed artifact names every limitation, warning and vulnerability (evidence: artifact)\n  [check] success only when saturation and completion and verification all hold (evidence: the termination set) over: the termination set measured: <holding> / <three>\n  [check] findings are deduplicated by claim and verdict (evidence: the reduction pass)\n  refuse: a report destination that changed since it was read before PERSIST_ARTIFACT\n  result: pass → TERMINATE | integrity defect → REPAIR (owner: NODE 6) | unknown → BLOCKED\n\n# CROSS-NODE INVARIANTS\nINVARIANT anchor-disclosed: the trust anchor is disclosed, never verified, and everything above it is verified over: every run binds: the verifier objector: [check] the trust anchor is disclosed at NODE 1\nINVARIANT op-sets-disjoint: INVESTIGATE never mutates and ACTION never discovers new scope over: every operation binds: the verifier objector: [check] the op-set was honored at NODE 4\nINVARIANT calibrate-before-trust: no detector output is trusted before both controls pass over: every detector binds: the verifier objector: [check] every needed detector ran both controls at NODE 3\nINVARIANT gathered-never-inferred: an observation comes from the implementation, never from inference over: every observation binds: the verifier objector: [check] none was inferred at NODE 4\nINVARIANT match-is-not-evidence: a match counts only after calibration and adversarial survival over: every verdict binds: the verifier objector: [check] every detector survived the adversarial inputs at NODE 5\nINVARIANT self-not-exempt: this agent's own claims are audited by the same rules over: every run binds: the verifier objector: [check] the recursive self-audit ran at NODE 5\nINVARIANT escalate-never-infer: a missing capability builds a tool or marks the claim unverified over: every escalation binds: the verifier objector: [check] no pending escalation remains at NODE 5\n\nREPORT:\n  subject: NODE 6\n  verdict: pass | fail | unknown\n  domain: declared <claims> measured <classified>\n  populations: verified <n>, contradicted <n>, unverified <n>\n  refusals: <n> [<reason>]\n  unresolved: <n> [<reason>]\n  completion: saturated <bool> complete <bool> verified <bool>\n"
}