diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index f561643..ad6bc88 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -17,8 +17,8 @@ | task | CFED-WP-0001-T06 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T07 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T08 | done | — | workplans/CFED-WP-0001-foundation.md | -| task | CFED-WP-0001-T09 | todo | — | workplans/CFED-WP-0001-foundation.md | -| task | CFED-WP-0001-T10 | wait | — | workplans/CFED-WP-0001-foundation.md | +| task | CFED-WP-0001-T09 | done | — | workplans/CFED-WP-0001-foundation.md | +| task | CFED-WP-0001-T10 | todo | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T11 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T12 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T13 | done | — | workplans/CFED-WP-0001-foundation.md | diff --git a/docs/evidence/2026-09-06-hub-coordinates.json b/docs/evidence/2026-09-06-hub-coordinates.json new file mode 100644 index 0000000..19cd7f3 --- /dev/null +++ b/docs/evidence/2026-09-06-hub-coordinates.json @@ -0,0 +1,33 @@ +{ + "repo_count": 133, + "fields_checked": [ + "slug", + "local_path", + "host_paths", + "remote_url", + "mcp_server_name", + "mcp_server_url" + ], + "obsolete_live_coordinates": [], + "git_repos_checked": 141, + "obsolete_git_remote_repos": [], + "nonadjacent_dispositions": { + "inter-hub": "State Hub archived; excluded from live source coverage", + "markitect-project": "State Hub archived; excluded from live source coverage", + "vergabe_teilnahme": "Resolved by local_path to scanned vergabe-teilnahme checkout" + }, + "agent_configuration_scan": { + "roots": [ + "~/.codex", + "~/.config", + "~/.claude" + ], + "filename_patterns": [ + "*config*", + "*mcp*", + "*settings*" + ], + "live_matches": 0, + "historical_tool_result_matches": 2 + } +} \ No newline at end of file diff --git a/docs/evidence/2026-09-06-reference-sweep.json b/docs/evidence/2026-09-06-reference-sweep.json new file mode 100644 index 0000000..1548d15 --- /dev/null +++ b/docs/evidence/2026-09-06-reference-sweep.json @@ -0,0 +1,9 @@ +{ + "gate": "G8-source-scan", + "result": "pass", + "repositories_scanned": 141, + "files_scanned": 22414, + "reviewed_exception_files": 164, + "matching_lines": 307, + "errors": [] +} diff --git a/docs/evidence/2026-09-06-reference-sweep.md b/docs/evidence/2026-09-06-reference-sweep.md new file mode 100644 index 0000000..4467f9f --- /dev/null +++ b/docs/evidence/2026-09-06-reference-sweep.md @@ -0,0 +1,104 @@ +# G8 — Fleet source-reference sweep, 2026-09-06 + +CFED-WP-0001-T09 updates current source references across eight owning +repositories and the project ledger's validation command. Identity, actor, +access and shared-evidence references point to InfoTechCanon; repository and +commercial references point to CommerceCanon. No runtime contract, capability +identifier, maturity vector or concept assignment changes. + +## Source coverage and preserved references + +The [scan result](2026-09-06-reference-sweep.json) covers 141 adjacent Git +repositories and more than 22,000 files: tracked files (including ignored tracked +files), nonignored untracked files, hidden source/configuration files, and +symlink target paths (including dangling pointers). It +finds zero unreviewed legacy references. The +[exception ledger](../../ledger/reference-sweep.json) reviews 164 files / 307 +matching lines and fingerprints each exact reference line. Historical research, +accepted ADR context, authored accounts, completed workplans, migration scope +and stable test/scenario identifiers remain deliberate provenance. Changing or +adding a matching line requires a fresh review; exceptions are not directory-wide +suppression rules. G8's own evidence files are excluded as scan metadata. + +[State Hub coordinate evidence](2026-09-06-hub-coordinates.json) checks all 133 +registered repo records, their source coordinates and all 141 local Git remotes. +No obsolete live coordinate remains. The old State Hub lookup is a protected +alias resolving the same UUID `8c82baea-bb40-435d-ac42-ec7a7c20dbb8` and current +CommerceCanon paths/remote. Two records without adjacent checkouts, inter-hub +and markitect-project, are archived; vergabe_teilnahme resolves to the scanned +vergabe-teilnahme path. This source scan does not certify unregistered external +repositories or stale copies of historical checkouts on other hosts. + +Agent config/MCP/settings filename searches under ~/.codex, ~/.config and +~/.claude found no live match; two historical tool-result files were preserved. +Repository-owned MCP/config files are included in the source scan. Untracked ignored +third-party dependency trees and unrelated caches are not treated as source. + +## Published changes + +| Owner | Result | Published revision | +| --- | --- | --- | +| reuse-surface | Canonical source/roster, refreshed cache and composed index; live registration handover | `5501b8b` | +| repo-manager | CommerceCanon slug/Forge coordinate; existing repository UUID preserved | `6854ea10b278664baee7167efcceb2713bbab754` | +| binky-control | Current ecosystem and inventory references | `143b78e` | +| feature-control | Technical identity/evidence source references | `a555aaa` | +| kaizen-agentic | Identity/organization source references | `894d34c` | +| user-engine | Technical owner references in intent, mapping/card, docs and exporter docstring | `b9ae48b` | +| the-custodian | Current classification example and authoring override; obsolete human-review override retired | `4df570a` | +| commerce-canon | Current downstream owner links; original research proposal explicitly historical | `4a5b3d8fcbfd168ed1b3b326f3ecbedc6689b080` | + +Each owning repo has a synchronized native ADHOC-2026-09-06 record, except +reuse-surface, which uses existing REUSE-WP-0021. Consistency also assigned a +missing UUID to Kaizen's existing ADHOC-2026-08-21 record without changing its +body or task identities. The project ledger command now uses the renamed local +source path while retaining the original pinned Git blob. + +## Live federation proof + +[Registration evidence](2026-09-06-reuse-registration.json) records the enabled +CommerceCanon registration and the old source retained disabled with a replacement +note. Its history is preserved without keeping it in the active composition. +[Composed live proof](2026-09-06-reuse-composed.json) verifies exactly the two +expected capability IDs, owner/source repo, canonical URLs and cache paths: + +- capability.identity.subject-resolution — D3 / A0 / C1 / R0 +- capability.identity.vocabulary-canonicalize — D4 / A0 / C2 / R0 + +The fresh live response has no target warning. The local federation composer +refreshed just CommerceCanon, then its source slice replaced the old slice in +the generated index; all 60 unrelated local capability rows were preserved. +The two obsolete local cache files were backed up and removed. Capability +ownership metadata here is registry stewardship, not a competing concept owner. + +## Verification + +```bash +python3 tools/validate_fleet_references.py --workspace .. +PYTHONDONTWRITEBYTECODE=1 python3 tools/test_fleet_references.py +python3 tools/validate_ownership.py --source-repo ../commerce-canon +python3 tools/validate_corpus.py --commerce-repo ../commerce-canon --info-tech-repo ../info-tech-canon +python3 docs/evidence/2026-09-05-counterparty-validate.py --commerce-repo ../commerce-canon --info-tech-repo ../info-tech-canon +``` + +The three sweep regression tests verify tracked ignored/hidden coverage, +rejection of new live references, and exact exception fingerprints. Existing +reuse-surface federation tests: 15 passed. Existing User Engine identity-alignment +tests: 4 passed, run with PYTHONPATH=src. Changed YAML/fenced examples/Python parse; +new relative links resolve; Custodian's example/authoring override match +CommerceCanon source classification. Existing ownership, counterparty and corpus +preservation proofs remain passing. + +## Residuals and limits + +G8 source-reference acceptance passes. Whole-fleet State Hub consistency is not +claimed. REUSE-WP-0021-T01 is done; T02 remains waiting on supported restoration +of three archived blank bindings to their existing legacy identities. The +missing-identifier tool rejects blank scalars and would derive different UUIDs; +no manual substitution or identity migration was performed. REUSE-WP-0021 remains +active and is the live owner of this repair. + +Custodian's 13 historical consistency failures remain owned by CUST-IN-0017 +from the prior gate. Other touched native records synchronized successfully. +CFED-WP-0001-T10 retains the final project residual/adoption review. + +Acceptance decision: `48be4584-48df-4e81-8190-7a356e20f18b`. diff --git a/docs/evidence/2026-09-06-reuse-composed.json b/docs/evidence/2026-09-06-reuse-composed.json new file mode 100644 index 0000000..80c4a42 --- /dev/null +++ b/docs/evidence/2026-09-06-reuse-composed.json @@ -0,0 +1,59 @@ +{ + "capabilities": [ + { + "id": "capability.identity.subject-resolution", + "name": "Identity Subject Resolution", + "summary": "Resolve who or what is acting by mapping principals, accounts, actors, and identifiers to a stable subject model.", + "vector": "D3 / A0 / C1 / R0", + "domain": "helix_forge", + "status": "draft", + "owner": "commerce-canon", + "path": "registry/capabilities/capability.identity.subject-resolution.md", + "tags": [ + "identity", + "subject", + "architecture" + ], + "consumption_modes": [ + "informational" + ], + "source_repo": "commerce-canon", + "source_url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml", + "source_index": "/data/cache/commerce-canon.yaml" + }, + { + "id": "capability.identity.vocabulary-canonicalize", + "name": "Identity Vocabulary Canonicalization", + "summary": "Define an implementation-neutral vocabulary for identity-related concepts across overlapping domains.", + "vector": "D4 / A0 / C2 / R0", + "domain": "helix_forge", + "status": "draft", + "owner": "commerce-canon", + "path": "registry/capabilities/capability.identity.vocabulary-canonicalize.md", + "tags": [ + "identity", + "terminology", + "research" + ], + "consumption_modes": [ + "informational" + ], + "source_repo": "commerce-canon", + "source_url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml", + "source_index": "/data/cache/commerce-canon.yaml" + } + ], + "sources": [ + { + "repo": "commerce-canon", + "count": 2, + "url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml", + "cache": "/data/cache/commerce-canon.yaml" + } + ], + "composed_at": "2026-09-05T23:23:57+00:00", + "stale": false, + "target_warnings": [], + "total_capabilities": 65, + "other_warning_count": 0 +} \ No newline at end of file diff --git a/docs/evidence/2026-09-06-reuse-registration.json b/docs/evidence/2026-09-06-reuse-registration.json new file mode 100644 index 0000000..da5f13f --- /dev/null +++ b/docs/evidence/2026-09-06-reuse-registration.json @@ -0,0 +1,84 @@ +{ + "old_registration_before": { + "repo": "identity-canon", + "url": "https://forgejo.coulomb.social/coulomb/identity-canon/raw/branch/main/registry/indexes/capabilities.yaml", + "enabled": true, + "required": false, + "domain": "helix_forge", + "cache_ttl_seconds": 86400, + "auth_header": "Authorization", + "registered_at": "2026-06-15T23:35:02+00:00", + "updated_at": "2026-08-20T21:44:34+00:00" + }, + "retired_registration": { + "repo": "identity-canon", + "url": "https://forgejo.coulomb.social/coulomb/identity-canon/raw/branch/main/registry/indexes/capabilities.yaml", + "enabled": false, + "required": false, + "domain": "helix_forge", + "cache_ttl_seconds": 86400, + "auth_header": "Authorization", + "registered_at": "2026-06-15T23:35:02+00:00", + "updated_at": "2026-09-05T23:22:01+00:00", + "description": "Retired source registration after repository rename; replaced by commerce-canon under CFED-WP-0001-T09. Kept for history." + }, + "canonical_registration": { + "repo": "commerce-canon", + "url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml", + "enabled": true, + "required": false, + "domain": "helix_forge", + "cache_ttl_seconds": 86400, + "auth_header": "Authorization", + "description": "Canonical source after CFED-WP-0001-T03/T09; stable capability.identity identifiers retained.", + "registered_at": "2026-09-05T23:22:01+00:00", + "updated_at": "2026-09-05T23:22:01+00:00" + }, + "capability_ids": [ + "capability.identity.subject-resolution", + "capability.identity.vocabulary-canonicalize" + ], + "source_payload": { + "version": 1, + "updated": "2026-06-16", + "domain": "helix_forge", + "capabilities": [ + { + "id": "capability.identity.subject-resolution", + "name": "Identity Subject Resolution", + "summary": "Resolve who or what is acting by mapping principals, accounts, actors, and identifiers to a stable subject model.", + "vector": "D3 / A0 / C1 / R0", + "domain": "helix_forge", + "status": "draft", + "owner": "commerce-canon", + "path": "registry/capabilities/capability.identity.subject-resolution.md", + "tags": [ + "identity", + "subject", + "architecture" + ], + "consumption_modes": [ + "informational" + ] + }, + { + "id": "capability.identity.vocabulary-canonicalize", + "name": "Identity Vocabulary Canonicalization", + "summary": "Define an implementation-neutral vocabulary for identity-related concepts across overlapping domains.", + "vector": "D4 / A0 / C2 / R0", + "domain": "helix_forge", + "status": "draft", + "owner": "commerce-canon", + "path": "registry/capabilities/capability.identity.vocabulary-canonicalize.md", + "tags": [ + "identity", + "terminology", + "research" + ], + "consumption_modes": [ + "informational" + ] + } + ] + } +} \ No newline at end of file diff --git a/ledger/README.md b/ledger/README.md index 32dfd41..2b26560 100644 --- a/ledger/README.md +++ b/ledger/README.md @@ -34,7 +34,7 @@ Run from this repository: ```bash python3 tools/validate_ownership.py -python3 tools/validate_ownership.py --source-repo ../identity-canon +python3 tools/validate_ownership.py --source-repo ../commerce-canon python3 -m unittest discover -s tools -p 'test_*.py' ``` @@ -74,3 +74,7 @@ from the project root. Historical source assertions are not current definitions. [Reciprocal interface evidence](../docs/evidence/2026-09-06-interface-cards.md) records the three published canon cards and explicit upstream import review (G7). + +[Fleet reference review](reference-sweep.json) records exact historical-reference +exceptions; [G8 evidence](../docs/evidence/2026-09-06-reference-sweep.md) records +current source coordinates and service validation. diff --git a/ledger/reference-sweep.json b/ledger/reference-sweep.json new file mode 100644 index 0000000..47ee14e --- /dev/null +++ b/ledger/reference-sweep.json @@ -0,0 +1,1442 @@ +{ + "schema_version": 1, + "task": "CFED-WP-0001-T09", + "reviewed": "2026-09-06", + "scope": "Tracked and nonignored untracked source files in adjacent Git checkouts; separate service/cache/config evidence accompanies this ledger.", + "repositories": [ + ".nvm", + "activity-core", + "adaptive-pricing", + "agentic-resources", + "approval-engine", + "arc-nexus", + "artifact-store", + "audit-core", + "binect-chrome", + "binect-js", + "binky-control", + "can-you-assist", + "canned-prompts", + "citation-engine", + "citation-evidence", + "citation-work", + "clay-borg", + "commerce-canon", + "config-atlas", + "coordination-engine", + "core-hub", + "coulomb-loop", + "coulomb-social", + "direkt-vermittlung-de", + "disaster-control", + "doc-store-pg", + "domain-tree", + "email-connect", + "evidence-anchor", + "evidence-binder", + "evidence-source", + "executor-sandbox", + "feature-control", + "fin-hub", + "flex-auth", + "fluid-core", + "fluid-substack", + "fluid-telegram", + "fluid-x", + "freedom-intelligence", + "gate-house", + "glas-harness", + "ground-game", + "guide-board", + "hall-of-helix", + "helix-forge", + "hub-core", + "human-resources", + "ihp-railiance-probe", + "info-tech-canon", + "infospace-bench", + "issue-core", + "kaizen-agentic", + "key-cape", + "kings-guard", + "kontextual-engine", + "llm-connect", + "marki-docx", + "markitect-filter", + "markitect-main", + "markitect-quarkdown", + "markitect-tool", + "maturity-engine", + "net-kingdom", + "open-cmis-tck", + "open-reuse", + "ops-bridge", + "ops-hub", + "ops-mason", + "ops-warden", + "phase-memory", + "policy-nexus", + "polycode-sim", + "pqrst-practice", + "pr-hall-of-helix", + "prj-canon-federation", + "prj-forgejo-org-refactor", + "prj-state-hub-retirement", + "prj-unattended-progress-company", + "python-snake", + "qonto-assistant", + "rail-knative", + "rail-kubernetes", + "railiance-apps", + "railiance-bootstrap", + "railiance-cluster", + "railiance-enablement", + "railiance-fabric", + "railiance-forge", + "railiance-hosts", + "railiance-infra", + "railiance-master", + "railiance-platform", + "railiance-telemetry", + "ralph-workplan", + "rapp-core-hub", + "rapp-issue-core", + "rapp-openbao", + "rapp-policy-nexus", + "rapp-postgres", + "rapp-qonto", + "rapp-sbom-nexus", + "rapp-secrets-engine", + "rapp-tenant-engine", + "rapp-user-engine", + "reef-railiance", + "reef-storage", + "rein-aharness", + "rein-openweights", + "repo-manager", + "repo-scoping", + "repo-seed", + "resource-control", + "reuse-surface", + "risk-nexus", + "role-engine", + "sand-boxer", + "sbom-nexus", + "secrets-engine", + "shard-wiki", + "snuggles-inventor", + "soul-frame", + "state-hub", + "target-revenue", + "tegwick-control", + "tele-mcp", + "telegram-edge", + "tenant-engine", + "test-driver", + "testdrive-jsui", + "the-custodian", + "timeline-svg", + "tmux-amq", + "user-engine", + "vantage-point", + "vergabe-teilnahme", + "whitehat-security", + "whynot-control", + "whynot-design", + "wise-validator", + "zone-engine" + ], + "exceptions": [ + { + "file": "binky-control/history/260715-InitialExploration.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "53e34a9d8a7932c0e29470db2c856ecfd4087462fa37ee368c6ec96927cae034", + "ab2c365ecca4803fda228359f30e4f40e4a21052ffcd68c8bea1a702d750866e" + ] + }, + { + "file": "commerce-canon/.repo-classification.yaml", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "01b6f647f563930e1a803945222c895329749346dac160295eb1676ea7fcc3e1" + ] + }, + { + "file": "commerce-canon/INTENT.md", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "928a7676ae19dcea7b5ce87345bf1b25115bc0e0a1ca0001502c04f3d754b65c" + ] + }, + { + "file": "commerce-canon/README.md", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "9f1f656d9e0b86c1dda98e059862a0b55fdd15912f9d3f5b231ecda8d7072c2d" + ] + }, + { + "file": "commerce-canon/ResearchProposal.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "f2e88356d73c44676432eb33f18c9e592e82c815b3c18c5e4219be56cdc30d57", + "e0b41bcf9510a89a12f75e1bbdf14056f83c459492d335d486ef7a2409abdae2", + "203d61920b8697413faf8133272f08173f55d05c77526d99450d253580e147fb", + "25f0a5be773d0ccfaccf44be85feeea5fc3173d3e77c2ada24bb66da6bab8cc5", + "3f2588966eeab0899e393d1f40efd63172a92e218c2c3f41f80f319a90140f5e", + "b032a0b82b98a455fd08b6013fae1a66bffb2811dddcad5cce556ec6f9c6a885", + "7acbcaa1fa5832f8259b150885078597cf0a99d669c26be554026115310ef577" + ] + }, + { + "file": "commerce-canon/history/2026-09-05-commerce-rename-preparation.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "7fb36a505fb8ba00282c3cdcc1fcb3775af9ee7ebc6ae0b4d5d023611b6827ea" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/assimilation.yaml", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "589ca082fb3e56af6eceea64dbfc48f584039cc45c79f0b63d734bfdede9d1ac" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/CorpusIndex.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "ee6638f87c1eab4cec9bedf45c2ef4281374ad5cb780fb0137fc213e301ba220", + "7180c0d7b0a60bbc4e7cdb466bc806dba39af24670df7e9a6a8a6609b9746b02", + "8819d316e3003ecceedf7f6a5ed5803f96cac59196828e16d31e271396a57891" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/README.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "6363cb03b87084a55a94967dea20200a0c891abd1fccf588dc1dd0da7bebd7ef" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/ResearchSeed.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "69eb436b2cb2e492948358ee2817fa5431039049e02d0a8f28696caf965fe619", + "6d8609d16dbdf7d0eb312772ada5854e983f41d0c907f7005bb4d3725aa73754", + "dfd087a5074a320ccc5e7468d0ab32b6970368643e550cea2a9cd75c8fb91550", + "69f6f763e0afecaebfe299282f95a496e7b0e60672d0ab456f7d031817f7a859" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/beneficial-ownership-kyc-boi.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/commercial-identity-nuance-settlement.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "2b638371cfe9f97d6379a9c47715959094fa26c91b5330bb4882f87891bc581a" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/commercial-identity-synthesis.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "f6ffc6e77a820d360fdf9735b38397087825aba1cb912622ace1f647585570a2" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/commercial-trust-binding-theory.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0501cff37a4aeb53698cc66c0966465c2b64e1156bdfaa3b1768e86af0d7fd7d", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339", + "123ad1624cc2a53e6301b56416958651471eda616174889b9efcf6fccce5a8d0" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/crm-pipeline-commitment-threshold.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/duns-commercial-credit-identity.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/eidas-eudi-legal-person-wallet.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/kyc-aml-commercial-identity-binding.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/legal-person-agency-contract.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/lei-gleif-legal-entity-identifier.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/payment-credential-pci-boundary.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "2b0c760c01acba7174348fbe83808fbab852ca36061908860e2ee60dbd313f36", + "a526157f9f04ae35d554bd314993343a39dde918854f3919949f0d87e5d8acd9", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/registry-identifier-subtypes.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/reputation-assurance-gradient.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "2caae79a9f53570de6902b8221a208dceba85809743804ae95c451a5e4e55bc3" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/salesforce-crm-commercial-record.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-subscription/b2b-saas-subscriber-tenancy.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/commercial-subscription/stripe-customer-billing.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/identity-provisioning/keycloak-organizations.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/assimilation/canon-federation/source/research/identity-provisioning/zitadel-organizations-projects.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/infospace/kernel/CommerceCanonCore.md", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "69a939c3e0ef7c87e66620602d1a5fb6bfe2b3d68abf7763979203bc007e7454" + ] + }, + { + "file": "commerce-canon/model/ConceptualModel.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "80a31c9ac69fead1e86678db1a57472f1de1160761da8b68a40babd053186a39" + ] + }, + { + "file": "commerce-canon/research/CorpusIndex.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "ee6638f87c1eab4cec9bedf45c2ef4281374ad5cb780fb0137fc213e301ba220", + "7180c0d7b0a60bbc4e7cdb466bc806dba39af24670df7e9a6a8a6609b9746b02", + "8819d316e3003ecceedf7f6a5ed5803f96cac59196828e16d31e271396a57891" + ] + }, + { + "file": "commerce-canon/research/README.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "6363cb03b87084a55a94967dea20200a0c891abd1fccf588dc1dd0da7bebd7ef" + ] + }, + { + "file": "commerce-canon/research/ResearchSeed.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "69eb436b2cb2e492948358ee2817fa5431039049e02d0a8f28696caf965fe619", + "6d8609d16dbdf7d0eb312772ada5854e983f41d0c907f7005bb4d3725aa73754", + "dfd087a5074a320ccc5e7468d0ab32b6970368643e550cea2a9cd75c8fb91550", + "69f6f763e0afecaebfe299282f95a496e7b0e60672d0ab456f7d031817f7a859" + ] + }, + { + "file": "commerce-canon/research/authentication-federation/nist-800-63-4.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/authentication-federation/oidc-core-subject-identifiers.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "b1fdd89fbfac0d31c6591957807e2601096c578436a4b6c9259271c6b3aefe4b", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/authentication-federation/saml-nameid-federation.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/authentication-federation/shared-signals-caep-risc.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/authorization-relationships/cedar-principal-action-resource-context.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/authorization-relationships/cerbos-abac-derived-roles.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/authorization-relationships/openfga-modeling.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/authorization-relationships/zanzibar-rebac.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "c38af3d5826a37b01b97e39f0d4bdd17a909f06b49e6c3c8d75c0e145764765f", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/beneficial-ownership-kyc-boi.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/commercial-identity-nuance-settlement.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "2b638371cfe9f97d6379a9c47715959094fa26c91b5330bb4882f87891bc581a" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/commercial-identity-synthesis.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "f6ffc6e77a820d360fdf9735b38397087825aba1cb912622ace1f647585570a2" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/commercial-trust-binding-theory.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0501cff37a4aeb53698cc66c0966465c2b64e1156bdfaa3b1768e86af0d7fd7d", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339", + "123ad1624cc2a53e6301b56416958651471eda616174889b9efcf6fccce5a8d0" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/crm-pipeline-commitment-threshold.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/duns-commercial-credit-identity.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/eidas-eudi-legal-person-wallet.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/kyc-aml-commercial-identity-binding.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/legal-person-agency-contract.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/lei-gleif-legal-entity-identifier.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/payment-credential-pci-boundary.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "2b0c760c01acba7174348fbe83808fbab852ca36061908860e2ee60dbd313f36", + "a526157f9f04ae35d554bd314993343a39dde918854f3919949f0d87e5d8acd9", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/registry-identifier-subtypes.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/reputation-assurance-gradient.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "2caae79a9f53570de6902b8221a208dceba85809743804ae95c451a5e4e55bc3" + ] + }, + { + "file": "commerce-canon/research/commercial-identity/salesforce-crm-commercial-record.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-subscription/b2b-saas-subscriber-tenancy.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/commercial-subscription/stripe-customer-billing.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/entity-resolution-privacy/gdpr-pseudonymization.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/entity-resolution-privacy/synonymity-assertions.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "cf3b1dcb6bd58eee6228b58cd89c785c1e99e9e09c716910e44b250fadfa422c", + "f1dcb09461836a2b55c25e157fe8bb822decc828135fe72c77cb69ab43d9f366", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339", + "5a38d3d64f02dc2beae5a71d4c99bd5e86397a0cfb64ab3e741cdeda3a638379", + "01b5bd9597dc8419483984b6afd908696e176b4b428a7ed3c079ae2d590c2118" + ] + }, + { + "file": "commerce-canon/research/identity-provisioning/keycloak-organizations.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/identity-provisioning/ory-kratos-keto.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "8e003cace5b221325ecb0cf68a96779e9859bc455fca8bfba390cedf16afe041", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/identity-provisioning/scim-rfc7643-rfc7644.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/identity-provisioning/zitadel-organizations-projects.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/social-community-graphs/activitypub-actors-followers.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/social-community-graphs/foaf-agent-person-group-onlineaccount.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/social-community-graphs/schema-org-person-organization-membership.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/social-community-graphs/webid-solid-profile.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/verifiable-claims/did-core.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/verifiable-claims/openid4vc.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/research/verifiable-claims/vc-data-model-2.md", + "reason": "Original completed donor research/model input; current README directs consumers to published federation owners.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "commerce-canon/workplans/IDENTITY-WP-0001-statehub-bootstrap.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "9e509f2b2e889dc7316c33e94db6e304ff5606b874ab407477e3b044afb505a3", + "8e7185f0bac0945510063ab5d481e80aa8d4596334928d48b9c402ff5e8a32ad" + ] + }, + { + "file": "commerce-canon/workplans/IDENTITY-WP-0002-research-proposal-follow-up.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "9e509f2b2e889dc7316c33e94db6e304ff5606b874ab407477e3b044afb505a3" + ] + }, + { + "file": "commerce-canon/workplans/IDENTITY-WP-0003-corpus-backfill-model-refinement.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "9e509f2b2e889dc7316c33e94db6e304ff5606b874ab407477e3b044afb505a3" + ] + }, + { + "file": "commerce-canon/workplans/IDENTITY-WP-0004-commerce-rename.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "7624048163b9b549f5087c103d287aa3a43cf6453cc12667029af564e9085bcb", + "71d2abbcb343688d8012023c1d54e4404fb78db29e873e4d1a6feedd8d177b7c", + "6a08c234991cc0af7e82bca8e65b81e78af7f8085cf6695ec3ef49d6d29afd01", + "3b509fb7f96a4bd842c3821adf50f297c759498541437a0a3603380b4e993678", + "999b0e2374f52c0db3d368af036a617a836dcde362a238bb596b4236e6054aec" + ] + }, + { + "file": "feature-control/docs/canon-mapping.md", + "reason": "Stable local scenario/test identifier or reference to that test; not the repository source coordinate.", + "line_sha256": [ + "1a147ed48381699b65e69d8909fccc98257d277ecd69ff5f8ddf2f247d9de032" + ] + }, + { + "file": "feature-control/workplans/FEATURE-WP-0002-canon-prd-ucc-alignment.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "86bbf3acda0e54740445094ca675c32612aebc6da6d000ae2b0b3fb209fc6b0a", + "d37f525cfb6f1b8bcf25b996287fd40b6d6fba3ba24f9d55943a418a8175a5de" + ] + }, + { + "file": "hall-of-helix/entries/2026-08-23T20:55:00.000Z-codex-user-engine-boundary-answered.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "22b45e1278733fe3d488cbe34137c32d741be1b089384b76f5763fa422348b3a" + ] + }, + { + "file": "info-tech-canon/canon.yaml", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "55715e9e2b351d1fc1173fa08646a003db41cf57b77fd69b436e07ee4a43d8c5" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/assimilation.yaml", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "589ca082fb3e56af6eceea64dbfc48f584039cc45c79f0b63d734bfdede9d1ac" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/CorpusIndex.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "ee6638f87c1eab4cec9bedf45c2ef4281374ad5cb780fb0137fc213e301ba220", + "7180c0d7b0a60bbc4e7cdb466bc806dba39af24670df7e9a6a8a6609b9746b02", + "8819d316e3003ecceedf7f6a5ed5803f96cac59196828e16d31e271396a57891" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/README.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "6363cb03b87084a55a94967dea20200a0c891abd1fccf588dc1dd0da7bebd7ef" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/ResearchSeed.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "69eb436b2cb2e492948358ee2817fa5431039049e02d0a8f28696caf965fe619", + "6d8609d16dbdf7d0eb312772ada5854e983f41d0c907f7005bb4d3725aa73754", + "dfd087a5074a320ccc5e7468d0ab32b6970368643e550cea2a9cd75c8fb91550", + "69f6f763e0afecaebfe299282f95a496e7b0e60672d0ab456f7d031817f7a859" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authentication-federation/nist-800-63-4.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authentication-federation/oidc-core-subject-identifiers.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "b1fdd89fbfac0d31c6591957807e2601096c578436a4b6c9259271c6b3aefe4b", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authentication-federation/saml-nameid-federation.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authentication-federation/shared-signals-caep-risc.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authorization-relationships/cedar-principal-action-resource-context.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authorization-relationships/cerbos-abac-derived-roles.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authorization-relationships/openfga-modeling.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/authorization-relationships/zanzibar-rebac.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "c38af3d5826a37b01b97e39f0d4bdd17a909f06b49e6c3c8d75c0e145764765f", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/beneficial-ownership-kyc-boi.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/commercial-identity-nuance-settlement.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "2b638371cfe9f97d6379a9c47715959094fa26c91b5330bb4882f87891bc581a" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/commercial-identity-synthesis.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "f6ffc6e77a820d360fdf9735b38397087825aba1cb912622ace1f647585570a2" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/commercial-trust-binding-theory.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0501cff37a4aeb53698cc66c0966465c2b64e1156bdfaa3b1768e86af0d7fd7d", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339", + "123ad1624cc2a53e6301b56416958651471eda616174889b9efcf6fccce5a8d0" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/crm-pipeline-commitment-threshold.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/duns-commercial-credit-identity.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/eidas-eudi-legal-person-wallet.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/kyc-aml-commercial-identity-binding.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/legal-person-agency-contract.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/lei-gleif-legal-entity-identifier.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/payment-credential-pci-boundary.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "2b0c760c01acba7174348fbe83808fbab852ca36061908860e2ee60dbd313f36", + "a526157f9f04ae35d554bd314993343a39dde918854f3919949f0d87e5d8acd9", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/registry-identifier-subtypes.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/reputation-assurance-gradient.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "2caae79a9f53570de6902b8221a208dceba85809743804ae95c451a5e4e55bc3" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-identity/salesforce-crm-commercial-record.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-subscription/b2b-saas-subscriber-tenancy.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/commercial-subscription/stripe-customer-billing.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/entity-resolution-privacy/gdpr-pseudonymization.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/entity-resolution-privacy/synonymity-assertions.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "cf3b1dcb6bd58eee6228b58cd89c785c1e99e9e09c716910e44b250fadfa422c", + "f1dcb09461836a2b55c25e157fe8bb822decc828135fe72c77cb69ab43d9f366", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339", + "5a38d3d64f02dc2beae5a71d4c99bd5e86397a0cfb64ab3e741cdeda3a638379", + "01b5bd9597dc8419483984b6afd908696e176b4b428a7ed3c079ae2d590c2118" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/identity-provisioning/keycloak-organizations.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/identity-provisioning/ory-kratos-keto.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "8e003cace5b221325ecb0cf68a96779e9859bc455fca8bfba390cedf16afe041", + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/identity-provisioning/scim-rfc7643-rfc7644.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/identity-provisioning/zitadel-organizations-projects.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/social-community-graphs/activitypub-actors-followers.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/social-community-graphs/foaf-agent-person-group-onlineaccount.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/social-community-graphs/schema-org-person-organization-membership.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/social-community-graphs/webid-solid-profile.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/verifiable-claims/did-core.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/verifiable-claims/openid4vc.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/assimilation/canon-federation/source/research/verifiable-claims/vc-data-model-2.md", + "reason": "Frozen byte-identical donor research snapshot; governed by G6 corpus ledger.", + "line_sha256": [ + "0d6d32017243abf39118f238b874739991ad6ddf423c0d72ecad0ae139489339" + ] + }, + { + "file": "info-tech-canon/infospace/models/evidence/InfoTechCanonEvidenceModel.md", + "reason": "Explicit donor history, source provenance or completed research title; current owner references are canonical.", + "line_sha256": [ + "81427304e2a66f6f3d2210ee51e05da45d286bfb504b3b970def6c5e2f179bf6" + ] + }, + { + "file": "kaizen-agentic/history/2026-06-16-ecosystem-assessment.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "a50f5eafb06e3f79e1d86b55c0b9fa3676f02effe327af3e32291ebe1e173123", + "afca55028851c188534bc4a0d4f83ea30524292f37341f894e10aaa028962e6b", + "9dc51c5fd49ff072c70354e1246c3ae6a7dda9fe88296ad7b699695f8f89c195", + "7dc2438586b2870b1a6a9dc04611c3ebacf73aa8f71d4322caf710ac5832992a" + ] + }, + { + "file": "key-cape/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "4969860808fceb4c7cd0c29d9c9966ca2912fa333e2d91e86fc83acc3a06bbda" + ] + }, + { + "file": "policy-nexus/build/adr/custodian-canon-federation/v1/index.html", + "reason": "Published rendering of accepted-1 ADR historical context; accepted source remains unchanged.", + "line_sha256": [ + "beb46d781228fb57b618b4905bbdd98cebeaff0902b907c1d05713c8113444b1", + "be5a743b09c31ebe9a33ccc6835905e2f4bc5ab000f1048825141009bd506246", + "a2fe560dac9a4839db905abaaaf3d059e40df06f581360d83c3d943ff3513b84", + "36da703d64ee4d82e78b61e9078967048af148a42da862082052b25057c602a4", + "301b280d0a06a1468384fc5a5072c50e66827403fe96a2daa08ecc65c2709088", + "da53b13bcf334a48902f89097024c837ee3f6d7b0271415103edecd3b220e0aa", + "acc63368ae161af3c3d3735321b39029464700fc2991dbd3a884a3b50a0ca997", + "ac437309953b4bd95febdf8bf99ac7ba2ab0fb39c31e8c718c27b99556b21e1f", + "d0634bb507104f091806bbdcb3e887967144918289ba856b72e674f1f5bc7fbe", + "fa6e8fd5e3e3c6c10dde1a2ec3b196570c60f2000fde7b33cfb8a07bb8ef53fd", + "63f1908782b503c79840a4e41a1376af1f47db209397d1babfc68f950c57d6a8" + ] + }, + { + "file": "policy-nexus/build/adr/custodian-canon-federation/v1/revisions/accepted-1/index.html", + "reason": "Published rendering of accepted-1 ADR historical context; accepted source remains unchanged.", + "line_sha256": [ + "beb46d781228fb57b618b4905bbdd98cebeaff0902b907c1d05713c8113444b1", + "be5a743b09c31ebe9a33ccc6835905e2f4bc5ab000f1048825141009bd506246", + "a2fe560dac9a4839db905abaaaf3d059e40df06f581360d83c3d943ff3513b84", + "36da703d64ee4d82e78b61e9078967048af148a42da862082052b25057c602a4", + "301b280d0a06a1468384fc5a5072c50e66827403fe96a2daa08ecc65c2709088", + "da53b13bcf334a48902f89097024c837ee3f6d7b0271415103edecd3b220e0aa", + "acc63368ae161af3c3d3735321b39029464700fc2991dbd3a884a3b50a0ca997", + "ac437309953b4bd95febdf8bf99ac7ba2ab0fb39c31e8c718c27b99556b21e1f", + "d0634bb507104f091806bbdcb3e887967144918289ba856b72e674f1f5bc7fbe", + "fa6e8fd5e3e3c6c10dde1a2ec3b196570c60f2000fde7b33cfb8a07bb8ef53fd", + "63f1908782b503c79840a4e41a1376af1f47db209397d1babfc68f950c57d6a8" + ] + }, + { + "file": "prj-canon-federation/.repo-classification.yaml", + "reason": "Project migration goal/identity or pinned original source inventory; describes the source-to-destination rename.", + "line_sha256": [ + "bad06974377d86e534db5dedcf06ce72ef316dfe248a4696b5b79d92236ca86d" + ] + }, + { + "file": "prj-canon-federation/GOAL.md", + "reason": "Project migration goal/identity or pinned original source inventory; describes the source-to-destination rename.", + "line_sha256": [ + "f91e3f204762df89d044bc47daa71c55a9b5dd2c5e3aaff6f7276926323b7ba1", + "57368ed9e1071e142bac0d975f87f2fe1720086d89100d100f2d2ec60d4d444f", + "0f2e77c59da05163c0e1f2318cf51cb88a6e794726836618ac9da0fbfaeedd35", + "95b049612edab23b5fa7ec0802e4c0629f91e961725e44f509b3855ae1117404", + "19245146951e1c4e7dde00ab4a01f0255e1ee2def4e221ce75cbb6f55e35f4f5", + "fd9fe5f148a7ff1ae121fd96a3589f81e78c3f80e6e66945b4b093756a2007d4" + ] + }, + { + "file": "prj-canon-federation/README.md", + "reason": "Project migration goal/identity or pinned original source inventory; describes the source-to-destination rename.", + "line_sha256": [ + "bd14a94cce8f1976e542245f9ed5dc4ac5118d01c2c3eacf98d073a0351db851" + ] + }, + { + "file": "prj-canon-federation/SCOPE.md", + "reason": "Project migration goal/identity or pinned original source inventory; describes the source-to-destination rename.", + "line_sha256": [ + "c7c9d6463b3206ccb791b6769a8d018a0f9df2c5ad2db8738a5ad8395b96dec1", + "9428439c5750d368e0d69642c70a117a05362d95f091659bf4e67e2912ea7b75" + ] + }, + { + "file": "prj-canon-federation/docs/evidence/2026-09-05-commerce-metadata.patch", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "cfba33123d245cc674917e8348e4cf1d349265ed8de85e4d52da4100ea75f4d4", + "f26e434f96830d6b7b63c357e141ec90a69ec9962f68716b532737dd05478e07", + "67f7272e0d057d7903354eddb2028fd7ccd58cc8f1596ee360e35020630023f9", + "1352f35b7714bb0add1b6654865b5253433c4f2094b13c1667a8a223c6d97270", + "8f700ee78c8d8be8182ee8e34c82e59148f9ea1c3815b017561f2920523aa425", + "354fc1660600c5730bee0e1832801055d3e4be3386e2e957c8271b988d6d6648", + "7d8513b3710016cba978630eb2f6d9fcd5dff908d120ba3595d1f0acebcf8ec8", + "b0375e0ff152f56d56ea5adfd71fb8278dfb434e4e280fec02267a9480ce6bdd", + "8bf735ab66de524b532fb286e00596239ff91a6a42e5a7c514b5a8fe64c592d6", + "3557878b06009876538fb6ef0ab6314b55fd6bb6d328cccb26f83cff92d192a0", + "fcc5b1a7325b97b4b8855b058a3072fb470be250061aa3a7b6944a3dd43307db", + "81b3565a14a3bd512bfedfc95983f617e5d9da6eb282421a36b2c482dfd12cd2", + "62eb19241a47672ce4d152cd8863ce0282a09b73249fe55f000ed880205dddd5", + "ba6df5e4a2a16bbcc527767d51dd3d88bc8b8540471a7bd1dcdf3ebd1d88d21b", + "817dbee5a1fc97f05e96f3c59092daadaf5794e60e14d213787ab2e6f8fd8111" + ] + }, + { + "file": "prj-canon-federation/docs/evidence/2026-09-05-forge-identity.json", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "35fe3f6f411a0fabfb393dcf1942eea1dd0a0e20995f58ef1b449533ac72ed95", + "a522d07bd284932aabc4099a805ba2e21bf89fc4480f3ed2451595118f122f9f", + "21a5f747955b722ab5f28b0fce65d3e4e8b513ef29e2ecfa9394ea950ab7bad7", + "da22b029e7f0d27e04f652783edf0b76f9ba9db1262c2b23a02424eeb6010c69", + "1916d43b2a6c9e6e86cea9295bed77042e8f921e3737ce3be587b26c12604dcf" + ] + }, + { + "file": "prj-canon-federation/docs/evidence/2026-09-05-ownership-ledger.md", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "ee8cc8c48ba5431ee83e3e813ea25d3c4092cc22db532580e4c907c0871054c7" + ] + }, + { + "file": "prj-canon-federation/docs/evidence/2026-09-05-rename-completed.json", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "764c25a40de5eff93438cf14072357dd8ce743809cb323883c284e2c70922ac4", + "5edfa553ce3c59f721e13f6bf68990c18ff8abce3c990e108c519a36eaf3668e", + "5edfa553ce3c59f721e13f6bf68990c18ff8abce3c990e108c519a36eaf3668e", + "5edfa553ce3c59f721e13f6bf68990c18ff8abce3c990e108c519a36eaf3668e", + "5edfa553ce3c59f721e13f6bf68990c18ff8abce3c990e108c519a36eaf3668e" + ] + }, + { + "file": "prj-canon-federation/docs/evidence/2026-09-05-rename-preflight-verified.json", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "764c25a40de5eff93438cf14072357dd8ce743809cb323883c284e2c70922ac4", + "90b4b9a4bd1af86ec734e3ae9df4b99ad5419c42d510b10ed0ff6f6f53b7d204", + "5798027fb9813bcd7e05234c97997023318e810be7ddd543d175632890f4abd3", + "425d7760bf63db57ef90d3aba047801351d7619efed8c3e2187693f614e8669d", + "b1c4605ddd47ab6b023e5b85ca2d0d74438ade936f87bdaa46447e70bdab4615" + ] + }, + { + "file": "prj-canon-federation/docs/evidence/2026-09-05-rename-preflight.json", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "764c25a40de5eff93438cf14072357dd8ce743809cb323883c284e2c70922ac4", + "e37835834e7b74351e1cbe9a4a20a9144245c78c61b51eb74a45d99c06c8950f", + "25e98709a5d9a30a3d7b93d77f484447391f8416989a26624f747df1834660cc" + ] + }, + { + "file": "prj-canon-federation/docs/evidence/2026-09-05-rename-preparation.md", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "e37d6045007c61a2c5612758b7a90952d14284e23d246b77e8d4e29be02882ae", + "b6605ea978f3add569068a9d9e61f2d43133b5c964423afa6424ce44be658223", + "8da399142a3a991f4f74dc0a08c1a2719d00578294373993404bd9fcfd015f79" + ] + }, + { + "file": "prj-canon-federation/history/2026-08-16-genesis.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "200a730328014b30f157e5c58490cabd5e0a30613527b030b244c7452dfef6b7", + "5668a8b2cd2ac786a5097fd633fb70ca55ab6670c79d83bbf44f8787028e2173", + "f2f5f330deb510061dbd09971897af5228494cadada92bb4f227d9262e1f623c", + "64847bdb949ba3c4d867cb70e79b5bf9d2519d35277e3b8db810925b5dce88f0", + "7af7b4c59ba524cf58366abc3cc8bf5c2e62107390e8c2b2eebac0e7231ffd11", + "0ff8778b7beda23766f336de8bbca123f0c8beecaa2b0ca38c731e488724aec2" + ] + }, + { + "file": "prj-canon-federation/ledger/source-inventory.json", + "reason": "Project migration goal/identity or pinned original source inventory; describes the source-to-destination rename.", + "line_sha256": [ + "4e27b045ee77abad5cb711a008790dc524ede3d27501966e01fc85974a582a37" + ] + }, + { + "file": "prj-canon-federation/workplans/CFED-WP-0001-foundation.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "20ff83b24d2916dab3c6721d4695978213f947b41f5cbc60b67e11f33011b49f", + "d85fc9222136a7b2b8e227791e990926c1da2587cb42f3a061c9ef582bd3f34f", + "852ca4b80751bdb452786961a95f2615de849a6a5c4f254012c0b71eff0e5565", + "32c96b7c704d3aef82abe936a47e4ba99e3b5ba603a1cf3bb9cf229b16d149bc", + "c79938360d7756f8f4f7f30778dc23eae2f26bd0908275c05fc5554ab3eed06b", + "f426b872ff4e6a8a76887309c92c05c682d601d4201b52781c4c1e7ce315bc16", + "3738f0b333f66bf47998af9db36d7ed7fa28463b8c759a54cd263d78920114f6", + "d6703a933277a4b48761f635c3339131419eacb34fcdfb580dd98c9ddc95fecc", + "cff773ba3d01289aae13aa2401498c4abb2307302921231e73580fa5f37fe789", + "829df739c8307cdc48b8ecb2816c4279ba77e6c22513f960b42cfa0a56610a6b" + ] + }, + { + "file": "repo-manager/docs/evidence/RMGR-WP-0005-closed-provenance-2026-08-21.json", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "bf1a6378d79c98684076c55a8fb51d2466257f90a34729b31aa60b07d02e8027", + "bf1a6378d79c98684076c55a8fb51d2466257f90a34729b31aa60b07d02e8027", + "bf1a6378d79c98684076c55a8fb51d2466257f90a34729b31aa60b07d02e8027" + ] + }, + { + "file": "reuse-surface/history/2026-06-16-federation-deduplication-plan.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "04531d1b11aa811a8a9f9e9ea60390b0d512f42f31db83ced1e1bf6c7a443bb1", + "a9239e9a5f48bc4acd03a0133734efbdaed10eb6c5454f329d14444f42bcda03" + ] + }, + { + "file": "reuse-surface/history/2026-06-16-hub-registration-blocks.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "17805406296e90861b7052c5f7a2e828600abfb717aa0f093f78b1be3b79d243" + ] + }, + { + "file": "reuse-surface/history/2026-06-16-wp0014-remaining-work-by-repo.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "3542ad5976b7e738cf7497f766b4059fb02136d81dda0a1fcedc503e00eb02f4" + ] + }, + { + "file": "reuse-surface/history/2026-06-17-sibling-registry-established.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "48826202cee726d297ce27b454eeeaf741f0c13ae2bdfbd09bc7fd268aaa0a65" + ] + }, + { + "file": "reuse-surface/history/2026-07-06-t04-review-summary.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "071deade133c45d5fee5ea4eb931601b0193d5854510afbec32ba7a682f512dd", + "e9f1130f51e95291f2992f46e42e10f3d16fc3eb396f97e854ca184ee1b935ed" + ] + }, + { + "file": "reuse-surface/workplans/REUSE-WP-0002-mvp-registry-foundation.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "250ca305789976cd53d952bcb1512bcd887d1799dcc8ee9b6b68a5a7f5a22200" + ] + }, + { + "file": "reuse-surface/workplans/REUSE-WP-0003-intent-scope-gap-closure.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "573726a36e3675f15ee10bbc8cb25235d4e1aac6683637cafbd42a8cfbfd815e" + ] + }, + { + "file": "reuse-surface/workplans/REUSE-WP-0005-registry-federation.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "55c4e0bc628e52e077c091a587d5ef244d89632e5ef2c13d89e72b6231078588" + ] + }, + { + "file": "reuse-surface/workplans/REUSE-WP-0021-commerce-canon-source-rename.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "96ca749e88c23fc423a640588c63062669e3cd60a4ab67a1a9000d6d8f7357a1" + ] + }, + { + "file": "reuse-surface/workplans/archived/260616-REUSE-WP-0014-local-repo-registry-rollout.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "d6fde07d0912dfec9159458ad2fd2b3b44e8133fcc813a1fa62b3e4ccbd9e165" + ] + }, + { + "file": "reuse-surface/workplans/archived/260616-REUSE-WP-0015-federation-polish-and-planning-analytics.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "6585bd32e9e66e0c2c363d8227d2c5734a598493616ec87a1aa9497b7d026c7e" + ] + }, + { + "file": "state-hub/workplans/STATE-WP-0089-rename-redirect-recovery.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "6f9f1f1d8b7fa84aea56c4eac38eee18a8c5b01fd0e34be5eeeccda9177f7233" + ] + }, + { + "file": "target-revenue/history/260730-TRSL-OrgWideLicenseRollout.md", + "reason": "Dated historical or authored provenance record; not a live source coordinate.", + "line_sha256": [ + "5d0023e0e032681da40b234b37f0bfada2e08b2f01bf3057af6a52f16281a0fd" + ] + }, + { + "file": "the-custodian/canon/architecture/adr-006-canon-federation-concept-ownership.md", + "reason": "Accepted ADR context and rename decision; deliberately preserves original repository identity.", + "line_sha256": [ + "4fb0f1c590ae5da88d8046e964d7ffef75513e8d106b0925654a78862d7ef51e", + "96793f8db177ec60cf2f41e223ad586ff14295998093f41d004ce627c3da6a09", + "de64ceba1bbb5d5ae2e90d38d49f28a4af91d2e570c1a0ed5de831a07688af9f", + "5f3fc27be09135c1dd7b0d137b7c0e8b09b6f7a604bcb53780a42aa90c294824", + "75071c53e23ab77116f40c0939f549d4e68d3a0057d06eae9f6d8ebc540612e4", + "4763dfc7d1a9507ade09445b878865f8a3335fb0e6e9d2b83a2e9a1dd3a614f9", + "e7ed53ef2e16559d5b04c38554894f3c031e3362ae443c1af1fff491abf9c82d", + "d3f285a3d4f11822ee0599a225466473e7ba7c0d505842b8862a33bd4e266f61", + "64715b2121f54219277f7473af3fa277d61c84b485ec4cec35d6be28dbf41d74", + "7967efdb74b6db87a7edde4119d943130e4f124e3793b375d33eccbcd6a19da4", + "58f3f1e85365272556a6c6be817c5a9ca9814dd637a834579836fb12705393b1" + ] + }, + { + "file": "the-custodian/docs/evidence/workstream-terminology-baseline-20260708.json", + "reason": "Historical validation or migration evidence; pinned source names remain verifiable.", + "line_sha256": [ + "cb625955af68c3da06ff18c7c2b2614eee50cef0c3f5aa177b6bd4b74ec6e902" + ] + }, + { + "file": "user-engine/docs/canon-mapping.md", + "reason": "Stable local scenario/test identifier or reference to that test; not the repository source coordinate.", + "line_sha256": [ + "fc5c9037a2d1998bd905acf453560a978fd403cf4c430f59ec101c756b593d5c" + ] + }, + { + "file": "user-engine/docs/scenarios.md", + "reason": "Stable local scenario/test identifier or reference to that test; not the repository source coordinate.", + "line_sha256": [ + "75b7080b1d159c4e067e2bd18b05be895bc02fa33cf8d2de19bf59ef7c8af451" + ] + }, + { + "file": "user-engine/src/user_engine/testing/scenarios.py", + "reason": "Stable local scenario/test identifier or reference to that test; not the repository source coordinate.", + "line_sha256": [ + "d022ffe1b22207da4819813819104bd3958f967cae10062479f733c9dc81b53b" + ] + }, + { + "file": "user-engine/tests/test_integrated_scenarios.py", + "reason": "Stable local scenario/test identifier or reference to that test; not the repository source coordinate.", + "line_sha256": [ + "5588a05c4c30af54e85b11fb3f63fa26c50d583ecb964a51b7928560f683f493" + ] + }, + { + "file": "user-engine/workplans/USER-WP-0007-identity-domain-canon-alignment.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "dc25bba1fc9ed3f9131ae290a3ed298d87346360b9c6ed0f352021891692cc2d", + "a5dd8d948471979a72a0ee39103206c622f8eeb00a3ee57e8dc1bce4974015ac", + "108025480de709822b35ce087389d716690d2a71e125cf567bffeef26e3c2f42" + ] + }, + { + "file": "user-engine/workplans/USER-WP-0008-family-dataspace-onboarding.md", + "reason": "Completed workplan provenance or explicit old-to-new migration scope; matched lines are historical descriptions, not current source endpoints.", + "line_sha256": [ + "b33938436ad71ca41f89544722c7ddd9ded9c4d6416aa58275ca2b04fe0f57b5" + ] + } + ] +} diff --git a/tools/test_fleet_references.py b/tools/test_fleet_references.py new file mode 100644 index 0000000..fc17117 --- /dev/null +++ b/tools/test_fleet_references.py @@ -0,0 +1,50 @@ +from pathlib import Path +import hashlib +import json +import subprocess +import tempfile +import unittest + +from validate_fleet_references import scan, validate + + +class FleetReferenceTests(unittest.TestCase): + def setUp(self): + self.tmp = tempfile.TemporaryDirectory() + self.addCleanup(self.tmp.cleanup) + self.root = Path(self.tmp.name) + self.repo = self.root / 'example' + self.repo.mkdir() + subprocess.run(['git', 'init', '-q'], cwd=self.repo, check=True) + self.legacy = 'identity' + '-canon' + self.ledger = self.root / 'review.json' + self.ledger.write_text(json.dumps({'repositories': ['example'], 'exceptions': []})) + + def test_tracked_ignored_and_hidden_files_are_scanned(self): + (self.repo / '.gitignore').write_text('ignored.md\n') + (self.repo / 'ignored.md').write_text(self.legacy) + (self.repo / '.settings').write_text(self.legacy) + (self.repo / 'source-link').symlink_to('../' + self.legacy) + subprocess.run(['git', 'add', '-f', 'ignored.md'], cwd=self.repo, check=True) + _, _, found = scan(self.root) + self.assertEqual(set(found), {'example/ignored.md', 'example/.settings', 'example/source-link'}) + + def test_new_live_reference_is_rejected(self): + (self.repo / 'README.md').write_text('Source: ' + self.legacy) + result = validate(self.root, self.ledger) + self.assertEqual(result['result'], 'fail') + self.assertEqual(result['errors'][0]['reason'], 'unreviewed reference') + + def test_review_is_bound_to_exact_reference_content(self): + text = 'Historical source: ' + self.legacy + (self.repo / 'README.md').write_text(text) + data = {'repositories': ['example'], 'exceptions': [{'file': 'example/README.md', + 'reason': 'Historical source', 'line_sha256': [hashlib.sha256(text.encode()).hexdigest()]}]} + self.ledger.write_text(json.dumps(data)) + self.assertEqual(validate(self.root, self.ledger)['result'], 'pass') + (self.repo / 'README.md').write_text(text + '\nCurrent source: ' + self.legacy) + self.assertEqual(validate(self.root, self.ledger)['result'], 'fail') + + +if __name__ == '__main__': + unittest.main() diff --git a/tools/validate_fleet_references.py b/tools/validate_fleet_references.py new file mode 100644 index 0000000..d2f93de --- /dev/null +++ b/tools/validate_fleet_references.py @@ -0,0 +1,86 @@ +"""Validate reviewed legacy-reference exceptions across adjacent Git repositories. + +Scans tracked files plus nonignored untracked files, including hidden files and symlink target paths. +Matches are fingerprints, not embedded file content. Git internals and ignored untracked +dependency/cache trees are outside the source scan; live registry/cache +and service checks are separate evidence. +""" +from __future__ import annotations +import argparse +from collections import Counter +import hashlib +import json +import os +from pathlib import Path +import re +import subprocess + +PROJECT = Path(__file__).resolve().parents[1] +PATTERN = re.compile('identity' + r'[-_ ]?canon(?![a-z])', re.I) +AUDIT_FILES = { + 'ledger/reference-sweep.json', + 'docs/evidence/2026-09-06-reference-sweep.json', + 'docs/evidence/2026-09-06-reference-sweep.md', + 'docs/evidence/2026-09-06-reuse-registration.json', + 'docs/evidence/2026-09-06-reuse-composed.json', + 'docs/evidence/2026-09-06-hub-coordinates.json', +} + + +def scan(workspace): + repos = sorted(p for p in workspace.iterdir() if (p / '.git').exists()) + matches = {} + total_files = 0 + for repo in repos: + paths = subprocess.check_output(['git', 'ls-files', '-z', '--cached', '--others', '--exclude-standard'], cwd=repo) + for relative in sorted(set(p.decode() for p in paths.split(b'\0') if p)): + if repo.name == PROJECT.name and relative in AUDIT_FILES: + continue + path = repo / relative + if path.is_symlink(): + # Audit the routing pointer even if its destination is absent. + data = os.readlink(path).encode() + elif path.is_file(): + data = path.read_bytes() + else: + continue + total_files += 1 + if b'\0' in data: + continue + lines = data.decode('utf-8', errors='replace').splitlines() + found = [{'line': i, 'sha256': hashlib.sha256(line.encode()).hexdigest()} + for i, line in enumerate(lines, 1) if PATTERN.search(line)] + if found: + matches[f'{repo.name}/{relative}'] = found + return repos, total_files, matches + + +def validate(workspace, ledger_path): + ledger = json.loads(ledger_path.read_text()) + repos, file_count, found = scan(workspace) + accepted = {e['file']: e for e in ledger['exceptions']} + errors = [] + for name, rows in found.items(): + entry = accepted.get(name) + if not entry: + errors.append({'file': name, 'reason': 'unreviewed reference', 'lines': [r['line'] for r in rows]}) + elif Counter(r['sha256'] for r in rows) != Counter(entry['line_sha256']): + errors.append({'file': name, 'reason': 'reference content changed; review required'}) + for name in accepted.keys() - found.keys(): + errors.append({'file': name, 'reason': 'obsolete exception; remove or review'}) + missing = set(ledger['repositories']) - {p.name for p in repos} + errors.extend({'repo': r, 'reason': 'reviewed checkout missing'} for r in sorted(missing)) + return {'gate': 'G8-source-scan', 'result': 'pass' if not errors else 'fail', + 'repositories_scanned': len(repos), 'files_scanned': file_count, + 'reviewed_exception_files': len(accepted), 'matching_lines': sum(map(len, found.values())), + 'errors': errors} + + +if __name__ == '__main__': + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('--workspace', type=Path, default=PROJECT.parent) + parser.add_argument('--ledger', type=Path, default=PROJECT / 'ledger/reference-sweep.json') + args = parser.parse_args() + result = validate(args.workspace.resolve(), args.ledger) + print(json.dumps(result, indent=2)) + raise SystemExit(0 if result['result'] == 'pass' else 1) diff --git a/workplans/CFED-WP-0001-foundation.md b/workplans/CFED-WP-0001-foundation.md index 825911d..1eaa407 100644 --- a/workplans/CFED-WP-0001-foundation.md +++ b/workplans/CFED-WP-0001-foundation.md @@ -332,7 +332,7 @@ G7 passes; T09 is now todo. Whole-fleet consistency is not claimed by this gate. ```task id: CFED-WP-0001-T09 -status: todo +status: done priority: medium state_hub_task_id: "42ebf476-6a45-5e23-b507-eb90bc4f5c07" ``` @@ -344,6 +344,17 @@ registries, and `reuse-surface` entries. Deliberate historical provenance Gate **G8** is a clean sweep. +**Result (2026-09-06):** [G8 evidence](../docs/evidence/2026-09-06-reference-sweep.md) +records eight published owner updates, 141 scanned local Git repositories, +133 checked State Hub records and a verified live reuse-service handover. +The [exception ledger](../ledger/reference-sweep.json) fingerprints deliberate +provenance and stable test/scenario names; zero unreviewed references remain. +Two existing capability ids/vectors and repository identity are preserved. +REUSE-WP-0021-T01 is done; its T02 retains the unrelated archived-binding repair +as live waiting work. CUST-IN-0017 retains prior Custodian consistency debt. +G8 passes; T10 is now todo. Overall progress: 12/13 tasks complete. + + ## Land the evidence model in InfoTechCanon ```task @@ -443,7 +454,7 @@ T07 is now todo; destination concept areas are established for corpus routing. ```task id: CFED-WP-0001-T10 -status: wait +status: todo priority: low state_hub_task_id: "2faeb8fb-58cc-5ea8-b5a8-ea0ed9583b30" ```