From 829d2b7e0b799345e3972acf441faac2d2ac8deb Mon Sep 17 00:00:00 2001 From: tegwick Date: Sat, 5 Sep 2026 22:21:55 +0200 Subject: [PATCH] Record counterparty model completion and validation Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b --- WORK-RECORDS.md | 4 +- .../evidence/2026-09-05-counterparty-model.md | 55 +++++++++++++++ ...6-09-05-counterparty-protected-hashes.json | 55 +++++++++++++++ .../2026-09-05-counterparty-validate.py | 68 +++++++++++++++++++ ledger/concept-ownership.json | 2 +- workplans/CFED-WP-0001-foundation.md | 12 +++- 6 files changed, 191 insertions(+), 5 deletions(-) create mode 100644 docs/evidence/2026-09-05-counterparty-model.md create mode 100644 docs/evidence/2026-09-05-counterparty-protected-hashes.json create mode 100644 docs/evidence/2026-09-05-counterparty-validate.py diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 162548f..574c202 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -14,11 +14,11 @@ | task | CFED-WP-0001-T03 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T04 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T05 | done | — | workplans/CFED-WP-0001-foundation.md | -| task | CFED-WP-0001-T06 | todo | — | workplans/CFED-WP-0001-foundation.md | +| task | CFED-WP-0001-T06 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T07 | wait | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T08 | wait | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T09 | wait | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T10 | wait | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T11 | done | — | workplans/CFED-WP-0001-foundation.md | -| task | CFED-WP-0001-T12 | wait | — | workplans/CFED-WP-0001-foundation.md | +| task | CFED-WP-0001-T12 | todo | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T13 | wait | — | workplans/CFED-WP-0001-foundation.md | diff --git a/docs/evidence/2026-09-05-counterparty-model.md b/docs/evidence/2026-09-05-counterparty-model.md new file mode 100644 index 0000000..42c3f8d --- /dev/null +++ b/docs/evidence/2026-09-05-counterparty-model.md @@ -0,0 +1,55 @@ +# Counterparty model — 2026-09-05 + +COMMERCE-WP-0002 implements CFED-WP-0001-T06 with draft +commerce-counterparty 0.1.0. It covers all 18 commerce-owned ledger concepts and +the Reputation/Customer Account convenience mappings. Registry Identifier and +Proxy Commercial Identifier specialize imported Identifier; Payment Instrument +Reference specializes imported Scoped Identifier. + +The model imports 25 concepts from four InfoTechCanon models, pinned to source +commit `361c944325934ccdb190470baf6f55440b6b486e` with per-file hashes. Reputation +Signal, Performance Evidence and Beneficial Ownership Exemption are assertions +using Evidence, not documents masquerading as assertions. Adjudication Outcome +is imported. The opinion/observed/committed/adjudicated gradient remains a named +commercial application of general evidence strength, distinct from identity and +governance assurance. + +P14 separates commercial records from login accounts; P15 distinguishes +commercial binding from internal pipeline classification. A saved payment +reference does not infer consent, a mandate or payment. Jurisdiction-specific +thresholds remain donor research examples; the general model records applicable +rule/version references instead of prescribing those thresholds universally. +These are semantic model constraints, not legal determinations. + +Kernel and current navigation now reflect registered identity, evidence and +counterparty drafts. Original glossary, conceptual model, research, terminology, +scenarios and finished workplans remain unchanged: 53 protected files match their +SHA-256 snapshot. Corpus disposition remains T07; interface cards T08; social +collective/Family placement T12/T13. No stable promotion, consumer adoption or +runtime implementation is claimed. + +Reproduce with Python 3 and PyYAML: + +```bash +python3 docs/evidence/2026-09-05-counterparty-validate.py --commerce-repo ../commerce-canon --info-tech-repo ../info-tech-canon +python3 tools/validate_ownership.py --source-repo ../commerce-canon +git -C ../commerce-canon diff --check +``` + +Checks cover exact ledger/definition coverage, upstream concept presence and +reviewed hashes, owned/imported disjointness, registry/frontmatter integrity, +relative links and source preservation. Manual boundary cases in model section 5 +cover missing evidence, false equivalence, pipeline/commitment conflation and +source/assertion separation. These document checks are not runtime conformance +certification. Final publication receipts follow below. + +Validation result: 18 owned concepts, two convenience mappings, 25 imports from +four models, 30 relative links, 53 unchanged protected files; registry/boundaries +pass. Federation ledger still verifies its donor blob with zero unowned or +multiply owned concepts. + +Implementation commit `55a0134`; published/reconciled CommerceCanon commit +`8a07292dd78d094151f165d3ac1dfc7512114308`. Repo-manager returned applied on +primary/railiance01 with matching expected/derived commits and no refusals or +retirements. Native workplan UUID `9c12f321-e413-5d96-971e-2359eaa9a411`; +read-back verifies all three tasks done. Progress logged for both workplans. diff --git a/docs/evidence/2026-09-05-counterparty-protected-hashes.json b/docs/evidence/2026-09-05-counterparty-protected-hashes.json new file mode 100644 index 0000000..5719685 --- /dev/null +++ b/docs/evidence/2026-09-05-counterparty-protected-hashes.json @@ -0,0 +1,55 @@ +{ + "canon/CanonicalGlossary.md": "d5ca4392d2f89ba3e9580960b98003bb94b290dca9931456bb30c5a5fec5c70f", + "canon/DesignPrinciples.md": "250a6e467aa3fc58aa702ec9ecde4598af57cd4f7f474a8715044ccaf208c97c", + "model/ConceptualModel.md": "54153df86bbaf57e8f7dbe3b626aedcb36f4f3881437331a01e5a11e64f162a2", + "research/CorpusIndex.md": "d110cd1f665392ad7c5069c4432375d888290fa2786b5e0bb89f75b0597784ad", + "research/README.md": "1ab93b1176acaa499bbad9fd82a2d631356f1d131e63423ff26a0372cbc7cbc2", + "research/ResearchSeed.md": "1e432ff04d17f8cc27e4723931ce67b09eab28ba41da1ea62d08c26b74c03e0f", + "research/commercial-identity/kyc-aml-commercial-identity-binding.md": "5d3f63465cd786e76bbd067894ad94ab8c424733800bcae44f50362668bf5071", + "research/commercial-identity/commercial-identity-nuance-settlement.md": "cabb54601ee7d005f33ce71252f9003137e0bb64cb297ac65c1e4e13cad4ace9", + "research/commercial-identity/payment-credential-pci-boundary.md": "bcacaee7090ca32060cbaca19327471b123bb7e3f7b1ddc1dd6afa53bf98e787", + "research/commercial-identity/beneficial-ownership-kyc-boi.md": "602aad0622915b5a87fc1faa85f1378ef81cf1d988c1d44420c5f51be165aa43", + "research/commercial-identity/duns-commercial-credit-identity.md": "b33b789b047ff8ea53c4518f7c3f4933921c4289afb21e2fb8121e971f1e1740", + "research/commercial-identity/commercial-trust-binding-theory.md": "fc7be6f0641bf7fe88aee918c060c1f31643ed582b181f775133762245477e2e", + "research/commercial-identity/reputation-assurance-gradient.md": "0c992d05657d71e0208ab15e16348b49e522b37ea8248a579e2afaaf0d0aeb4c", + "research/commercial-identity/commercial-identity-synthesis.md": "ac70ecdb2046820a740ea72cfecc64f0add9acc25697fc04261fd60fba8fd3c8", + "research/commercial-identity/legal-person-agency-contract.md": "c3110cc62b493138d359489d6fb99c8306edc0f117b5f8d9863cc1af97bf14d1", + "research/commercial-identity/lei-gleif-legal-entity-identifier.md": "ef2ba7156f6dffd799f84ef482d4848dc800dce8854acf06aa4a43da48596354", + "research/commercial-identity/registry-identifier-subtypes.md": "1a621787a86962c907e2eb943aef4002ff86c53e8e1877e3a5aed36a8470f4fb", + "research/commercial-identity/crm-pipeline-commitment-threshold.md": "459828097e09d3c1fc0ea3c9febaee13f2be96e68a0fdd14aec4983b63eec8e1", + "research/commercial-identity/eidas-eudi-legal-person-wallet.md": "be8b05990cd05f8d157c1cf56604649db5abcfbeb9f376f8e9db45c0d3e3466e", + "research/commercial-identity/salesforce-crm-commercial-record.md": "52bf8c8dbbd787f42d6f088ccd65cf21cf7f5360448b81d5f9c5fd96c55409a4", + "research/commercial-subscription/stripe-customer-billing.md": "bb5c8fe3cab7421e952b518421fe517e8e007d65f3f67536d5c65e7fe841331c", + "research/commercial-subscription/b2b-saas-subscriber-tenancy.md": "133bf4325a7cdd96af010bb682e7e1825a947418aa8c0ac9f1af10e44f9e8aa6", + "research/authorization-relationships/zanzibar-rebac.md": "1f736195ab4b2d7b0639198cee687b25d5a2a7576388c75c400cc02ab0189be7", + "research/authorization-relationships/cerbos-abac-derived-roles.md": "c35f15042d45a83b6825ed43accf0f4c1249d35fa0ea87910af1df17bc31ce13", + "research/authorization-relationships/openfga-modeling.md": "e2d03ddfa7bee192a1e6dba39931adc02a97b93d7a8e305c2479809d9569b442", + "research/authorization-relationships/cedar-principal-action-resource-context.md": "1932a8632dd36a245ec26dec06100887d1d27a7c00df8d5861a7cf78da0ad110", + "research/verifiable-claims/vc-data-model-2.md": "dae7bc679c6c4e9df4e18e109ac0d069bf8036c1d7606c3e1d189c37351d5ee5", + "research/verifiable-claims/openid4vc.md": "e6fcc06121460464cc945fca5b174175c794a63c3134650543029d0b28c23e15", + "research/verifiable-claims/did-core.md": "cbe5fd46e093c9b98339ca40cad143878b4796bc488b223b0a2662d539e65e3f", + "research/authentication-federation/oidc-core-subject-identifiers.md": "e1a0bf8a27540c7f417a3878d3e07060738c1c8521101d7e807082823e15ef8e", + "research/authentication-federation/nist-800-63-4.md": "8697b739399c59bce96683aabeedd22eaf847bd09245d00176e896df734c802f", + "research/authentication-federation/shared-signals-caep-risc.md": "7303fd449a83d3398d0baa686fc9ae9c69c3e6eb1897dc1c8987ee3ff390f499", + "research/authentication-federation/saml-nameid-federation.md": "394457cf75d2a993c0de62be6542f5948d96519315d60a4297cd6cffee8547f7", + "research/identity-provisioning/zitadel-organizations-projects.md": "f4b1b6f4cce3c114ae17bb8dcfb3e81a218cfe8aa3a02ed1f84c994fda3699ef", + "research/identity-provisioning/scim-rfc7643-rfc7644.md": "c5c03952ac2f8025ab44b9ac7877183fc97d82da97ee9ebd1da8481a63dd47d9", + "research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md": "c3f3323a3f25bd0bde0b4ba5010223ad45cc50bbf353b2662d4eead86b1d6e06", + "research/identity-provisioning/keycloak-organizations.md": "09c43cdc9ecf28437b3440ed180ec47892d38077d531b20a803ca6a97b68b606", + "research/identity-provisioning/ory-kratos-keto.md": "5cd12c38f8d3c18c600c3648bc8126e51c88a9fe4a3ea2932ff110942a9f1db1", + "research/social-community-graphs/foaf-agent-person-group-onlineaccount.md": "4131e7685da56ee240b302c513ef51aebd791a78e438042d356769dc86abb2d6", + "research/social-community-graphs/activitypub-actors-followers.md": "8b28bfc385d112bc7afc8115300eafac3c52015d66f2c6c801ed3eb900dd7310", + "research/social-community-graphs/schema-org-person-organization-membership.md": "bc274f7cf1ff237ed25fbc0a975ab04520f69936dc0262da0cd88b10e66fb755", + "research/social-community-graphs/webid-solid-profile.md": "abf0c62e23b030eb186a1eac992cc2b0c53e8ee46c4415d2c9a067a3ce9f297f", + "research/entity-resolution-privacy/synonymity-assertions.md": "6ba40ec3722185e8ca3fce6d2af95f504f4bd5e4bb602138460906d13c9378b1", + "research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md": "12585f844728d3d18ff582c386b6cdc2610c8ce0112d5e1ff62055d3d8663985", + "research/entity-resolution-privacy/gdpr-pseudonymization.md": "de2bfcf7f52b37d2040b31236ed4a70da10f12fed753ec2f7f0e28c3f2fd4c70", + "terminology/TerminologyInventory.md": "5d22816b0bfe8671dc57f1d2cd5bd13dd0b6d15a77fcab7e4157d1f05dcfa4e1", + "terminology/TerminologyConflictMap.md": "06c8134a399a7377e108a975c69f03cf0ad4aa57dc7c67dbf97eb6e48f2aee11", + "scenarios/ScenarioTests.md": "4006416670649528dbf0a9e064f4b2a4e2817c89370ce395e2882761ad2d473e", + "workplans/IDENTITY-WP-0003-corpus-backfill-model-refinement.md": "910c7a248d1bfa4ff14c0eb5f45b182c76663bc726f57b6a826bfcd08433cae9", + "workplans/COMMERCE-WP-0001-foundation-layout.md": "3cb722146156a65c8ac8abb4c1dbf563e5c52a33ba9c1e8185fa914dce1ba3b2", + "workplans/IDENTITY-WP-0002-research-proposal-follow-up.md": "ea8f18a0f67281f0ac68f69629fe0de9b79e296b955b2988f86da4fe0794c951", + "workplans/IDENTITY-WP-0001-statehub-bootstrap.md": "425db8bb33f4966a5f21d02480cc32553cf5603d9f903575c706a65e888ae8dc", + "workplans/IDENTITY-WP-0004-commerce-rename.md": "99da61b774663b83c14c78936a3572aec5db223abaa77f2ba172c644be731b93" +} diff --git a/docs/evidence/2026-09-05-counterparty-validate.py b/docs/evidence/2026-09-05-counterparty-validate.py new file mode 100644 index 0000000..0afe14e --- /dev/null +++ b/docs/evidence/2026-09-05-counterparty-validate.py @@ -0,0 +1,68 @@ +"""Reproduce T06 ledger/import/provenance checks; requires Python 3 and PyYAML.""" +import argparse +import hashlib +import json +from pathlib import Path +import re +import subprocess + +import yaml + +parser = argparse.ArgumentParser() +parser.add_argument('--commerce-repo', type=Path, required=True) +parser.add_argument('--info-tech-repo', type=Path, required=True) +args = parser.parse_args() +commerce = args.commerce_repo.resolve() +upstream = args.info_tech_repo.resolve() +evidence = Path(__file__).resolve().parent +project = evidence.parents[1] +ledger = json.loads((project / 'ledger/concept-ownership.json').read_text()) +model_path = commerce / 'infospace/models/counterparty/CommerceCanonCounterpartyModel.md' +model = model_path.read_text() +fm = yaml.safe_load(model.split('---')[1]) +assigned = [t for e in ledger['entries'] for t in e['targets'] if t['owner']['canon'] == 'commerce-canon'] +owned = {t['concept'] for t in assigned if t['kind'] == 'concept'} +assert set(fm['owned_concepts']) == owned +assert len(fm['owned_concepts']) == len(owned) == 18 +assert set(fm['convenience_terms']) == {t['concept'] for t in assigned if t['kind'] == 'convenience_term'} +assert set(re.findall(r'^### 2\.\d+ (.+)$', model, re.M)) == owned +registry = yaml.safe_load((commerce / 'canon.yaml').read_text()) +assert len(registry['models']) == 1 +entry = registry['models'][0] +assert commerce / entry['path'] == model_path +for key in ['id', 'version', 'status']: assert entry[key] == fm[key] +manifest = json.loads(model_path.with_name('imports.json').read_text()) +assert set(fm['imports']) == {row['model'] for row in manifest['imports']} +imports = set() +for row in manifest['imports']: + data = (upstream / row['path']).read_bytes() + historical = subprocess.check_output(['git', 'show', manifest['source_commit'] + ':' + row['path']], cwd=upstream) + assert hashlib.sha256(data).hexdigest() == row['sha256'], 'upstream changed: ' + row['path'] + assert data == historical, 'reviewed commit differs: ' + row['path'] + text = data.decode() + if text.startswith('---\n'): + upstream_fm = yaml.safe_load(text.split('---')[1]) + upstream_owned = set(upstream_fm['owned_concepts']) + else: + upstream_owned = set(re.findall(r'^## \d+\.\d+[a-z]? (.+)$', text, re.M)) + assert set(row['concepts']) <= upstream_owned, set(row['concepts']) - upstream_owned + imports.update(row['concepts']) +assert owned.isdisjoint(imports) +for concept in ['Evidence', 'Evidence Source', 'Adjudication Outcome', 'Evidence strength', 'Identifier', 'Scoped Identifier']: + assert concept in imports and concept not in owned +protected = json.loads((evidence / '2026-09-05-counterparty-protected-hashes.json').read_text()) +for path, digest in protected.items(): + assert hashlib.sha256((commerce / path).read_bytes()).hexdigest() == digest, path +links = 0 +for relative in ['README.md', 'docs/RepositoryLayout.md', 'infospace/kernel/CommerceCanonCore.md', + 'infospace/models/README.md', 'infospace/models/counterparty/CommerceCanonCounterpartyModel.md', + 'workplans/COMMERCE-WP-0002-counterparty-model.md']: + path = commerce / relative + for link in re.findall(r'\]\(([^)]+)\)', path.read_text()): + if '://' in link or link.startswith('#'): continue + assert (path.parent / link.split('#')[0]).exists(), (relative, link) + links += 1 +print(json.dumps({'owned_concepts': len(owned), 'convenience_terms': 2, + 'imported_models': len(manifest['imports']), 'imported_concepts': len(imports), + 'upstream_commit': manifest['source_commit'], 'protected_files_unchanged': len(protected), + 'links_checked': links, 'registry_and_boundaries': 'pass'}, indent=2)) diff --git a/ledger/concept-ownership.json b/ledger/concept-ownership.json index fb6da13..741c74d 100644 --- a/ledger/concept-ownership.json +++ b/ledger/concept-ownership.json @@ -30,7 +30,7 @@ }, "counterparty": { "canon": "commerce-canon", - "state": "planned; ledger locator, not an accepted model ID" + "state": "draft commerce-counterparty 0.1.0 registered; counterparty retained as ledger locator" } }, "entries": [ diff --git a/workplans/CFED-WP-0001-foundation.md b/workplans/CFED-WP-0001-foundation.md index 066e9f7..bb6f8fc 100644 --- a/workplans/CFED-WP-0001-foundation.md +++ b/workplans/CFED-WP-0001-foundation.md @@ -235,7 +235,7 @@ reciprocal-import cycle review. G4 passes; T06 is now todo. ```task id: CFED-WP-0001-T06 -status: todo +status: done priority: high state_hub_task_id: "6bdb96c9-0524-5d3c-89e0-7c91df7ee56c" ``` @@ -261,6 +261,14 @@ Model identifier subtypes as the worked example of the import pattern: Carry over design principles P14 ("Separate Commercial Records From Accounts") and P15 ("Model Commercial Binding Explicitly"), which are commerce-side. +**Result (2026-09-05):** Native [COMMERCE-WP-0002](../../commerce-canon/workplans/COMMERCE-WP-0002-counterparty-model.md) +registers draft commerce-counterparty 0.1.0: 18 owned concepts, two convenience +mappings and 25 explicit imports from four pinned upstream models. P14/P15 and +assertion/source corrections are implemented. [Evidence](../docs/evidence/2026-09-05-counterparty-model.md) +records exact ledger coverage and 53 unchanged protected files. T12 is next +to establish social-collective destinations before corpus distribution. + + ## Distribute the research corpus as provenance ```task @@ -354,7 +362,7 @@ delegation-boundary review prerequisite. ```task id: CFED-WP-0001-T12 -status: wait +status: todo priority: medium state_hub_task_id: "f82385e9-5735-5147-aab6-d86653f33e26" ```