Authority claims and supersession
This is the sole aggregate projection of docs/authority-claims.json, a cross-domain index, not replacement policy. Existing source owners and precedence remain authoritative.
Fast checker: scripts/authority_claims/check.py.
Verification modes and limits
- Delegated: display structured owner data and bind its exact bytes. The fast checker does not run Cargo/package closure, public row classification, or catalog provenance/registry validators. Those existing owners run separately in CI and the full gate.
- Native: expected observations below are compared with compiled private constants or
oce_blocks::catalog()by test-only owner modules. Python never extracts Rust literals. A fast-check PASS alone does not mean native comparisons passed. - Corpus: count raw provenance records and check universal tier/dependency metadata. These are fixture inventory facts, not correctness or independence proofs.
- Review-only: links and limits are explicit; semantics and support promises are not automated. No arbitrary Markdown, historical archive, or Rust semantics parser is involved.
Checked source bindings
Delegated owner observations
Packages: 17 members; 12 publishable; 5 private. Publication state: deferred-no-crates-published.
Feature selections: 3; the shared normal closure is owner-verified, not inferred here.
| Package | Classification | Publishable |
|---|---|---|
oce-api | host-facade | true |
oce-bless | test-support | false |
oce-blocks | transitional-companion | true |
oce-conformance | verification-tooling | false |
oce-cxf | implementation-dependency | true |
oce-diag | implementation-dependency | true |
oce-docs | reserved-panic-only | false |
oce-expr | implementation-dependency | true |
oce-extension | experimental-reserved | false |
oce-flatten | implementation-dependency | true |
oce-graph | implementation-dependency | true |
oce-model | implementation-dependency | true |
oce-reference-wal-adapter | private-reference-adapter | false |
oce-semantics | implementation-dependency | true |
oce-store | conditional-adapter-port | true |
oce-store-mem | implementation-dependency | true |
oce-validate | implementation-dependency | true |
| Public baseline | Descriptor rows | SHA-256 (owner descriptor) |
|---|---|---|
| crates/oce-api/tests/public-api.txt | 2560 | db804469b3d16c4d7388a6540204c3304ecacdb5ba55172f07d7016e8a3fb948 |
| crates/oce-store/tests/public-api.txt | 1230 | 78cf5fdbcbd415a4ca3c521501c9c1a9ccca099551839c2fd360edc311fcbafe |
Exact row assignments remain in the public ledger; statuses below are displayed, not re-adjudicated.
| Group | Status |
|---|---|
deprecated-compatibility | deprecated |
domain-key-stable | stable-candidate |
facade-stable | stable-candidate |
schedule-leakage | implementation-leakage-to-remove |
storage-port-conditional | conditional |
CDL source revision: a131864e4c4df22ebcd52bb8da439de0087ac365; catalog fingerprint: 9edead4415592f28.
This is the existing pinned source identity, not a new numeric catalog revision.
| Delegated source | SHA-256 (exact input bytes) |
|---|---|
| catalog-registry | c52b1c5807e78aaf930f09402717ab7b5f1d98d173452d0cd22bbd6cb0b16336 |
| catalog-source | a8109009c6ffebba52522c2d6f96ac898c926b420a6baec369328c55b40d2702 |
| packages | 901e3ad38af0c0d223aeb0624b5bac55398cf4370155a0541301dbb2ebffb74d |
| public-surface | c60488c42c3704b0cb8f15973ff40eea735ba96e9a94410445afd8b646060baf |
Native expected observations
| Fact | Expected |
|---|---|
| catalog-entries | 136 |
| catalog-reserved | 3 |
| execution-abi | 2 |
| state-format | 2 |
Raw evidence inventories
Each declared root is enumerated recursively and completely, sorted by repository-relative
path. Only tracked regular .csv, *.prov.json, and the fixed Tier-A MANIFEST.txt are admitted; missing, unexpected,
untracked, ignored, or symlink members fail. All JSON records must be objects with the stated
tier and Boolean depends_on_oce_blocks. Other record fields and CSV contents are opaque,
not semantically validated. The inventory SHA-256 hashes sorted lines of
<file-sha256> <repository-relative-path>\n, including every member, not just records.
Thus added/removed/renamed or byte-changed evidence cannot leave the projection unchanged.
| Corpus | Provenance records | All members | Tier | depends_on_oce_blocks | Inventory SHA-256 |
|---|---|---|---|---|---|
| tier-a-records | 412 | 1059 | A | false | 09b7f14460296742cc57d0f801465326bf933738c5394a2274205151022fbdae |
| tier-two-records | 46 | 92 | 2 | true | 94a5b189d657aef6441437ad4ee241929a7b73ce40237e729795eb1f64f14149 |
Review-only claims
| Family | Existing evidence | Limit |
|---|---|---|
| deferred-capabilities | docs/public-surface-contract.md; docs/cdl-coverage.md | Baseline-row classification is delegated above; broader capability deferral remains human-reviewed. No arbitrary Markdown or Rust semantics are parsed. |
| evidence-quality | docs/verification-evidence.md; TESTING.md | Raw record counts and declared dependency metadata do not prove correctness, semantic independence, solver coverage, or semantic subcounts. Shared kernels and profile-specific interpretations require review. |
| host-tick | docs/execution-profile.md; crates/oce-api/src/tests/pre_execution_profile_tests.rs | HostTick v1 is a documented semantic contract, not a separately encoded runtime or wire profile identity. Behavioral tests remain the evidence; this checker does not interpret their semantics. |
| platforms | docs/architecture.md; .github/workflows/pr-gate.yml | CI runner labels are execution evidence, not a structured support-promise contract. No supported-target matrix is inferred. |
| true-hold-extension | crates/oce-blocks/src/logical_timing.rs; crates/oce-blocks/src/port_names.rs | TrueHoldWithReset remains a deliberate local two-input extension with supersession-ambiguous historical annotations. This index records the ambiguity, not a new semantic ruling or a broken compile dependency. |
Representative supersession map — non-exhaustive
This is not a global history audit. Historical locators are inert text: never opened,
linked, or checked for existence. No archive, _spec/, or _research/ is a prerequisite.
Formatting cannot promote a lower-precedence record to authority. A null authority records
an unresolved question, not permission to select a new owner.
| ID / subject | Historical locator (text only) | Status | Current authority | Superseded by | Reason / responsibility owner |
|---|---|---|---|---|---|
dated-stability / Dated stability snapshot | docs/stability-baseline-2026-08-26.json | historical | docs/stability-baseline.md | — | Dated observations are evidence, not current authority; moving refs do not invalidate a historical capture. / Repository maintainers |
local-execution-plan / Local execution specifications | _spec/03 and _spec/07 (historical source-comment shorthand) | superseded | docs/execution-profile.md | — | Tracked execution-profile documentation and behavior tests govern HostTick semantics; historical locators are not clone prerequisites. / Execution maintainers |
local-package-plan / Local package planning | _spec/open-control-engine-2026-08-25/CURRENT-BASELINE.md | superseded | docs/package-publication-policy.md | — | The tracked package policy and ledger govern present classification, not the local planning snapshot. / Package policy maintainers |
local-public-plan / Local public-surface planning | _spec/open-control-engine-2026-08-25/milestones/M00-authority-and-baseline/ | superseded | docs/public-surface-contract.md | — | Tracked public classification and blessed signatures outrank ignored planning inputs. / Public facade maintainers |
true-hold-annotation / TrueHoldWithReset source annotations | crates/oce-blocks/src/logical_timing.rs:440-448; crates/oce-blocks/src/port_names.rs:43-52 | ambiguous | Unresolved | — | The deliberate local two-input extension and historical specification comments need human adjudication; no authority replacement is selected here. / Block semantics maintainers |
Updating a legitimate claim
- Edit the true owner first, following its existing compatibility/review policy.
- If a compiled numeric fact legitimately changes, update its native
expectedobservation in the index. Never copy delegated counts, classifications, or matrices into the index. - Explicitly regenerate only this page with
python3 scripts/authority_claims/check.py --write. - Run the named owner verifier(s),
python3 scripts/authority_claims/check.py --check, and the repository gate described in CI and the gate. Gate execution never regenerates or blesses this artifact.
The tool uses Python 3 and Git, standard library only, no network. Local development admits only declared pending nonignored checker/index/projection files; corpus and existing owner inputs must be tracked. A clean exact-commit checkout verifies final clone availability. Schema, fixed source/verifier bindings, and explicit historical status mappings are closed; expanding them is a reviewed protocol change, not automatic discovery of new authority.