Author SHA1 Message Date
temoin-agentandClaude Fable 5.1 f3d7383748 SPEC v1.2 : la mesure nomme ce qu'elle a examiné (relations.confirms)
gardes du contrat / conformite (pull_request) Successful in 28s
Le sens est la décision entière : c'est la MESURE qui déclare ce qu'elle
confirme, jamais l'assertion confirmée qui pointe en retour. Trois raisons
suffisantes chacune : l'assertion confirmée existe déjà et ne se réécrit
pas ; l'instrument sait ce qu'il a mesuré — le lien est inféré, jamais
saisi ; et l'auteur d'une confirmation est la machine, non l'agent dont
l'affirmation est confirmée. Le runner refuse confirms sur autre chose
qu'une mesure de provenance measured.

Mineur et ignorable : un consommateur qui ignore la clé la préserve.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 13:53:04 +02:00
oat_gitadmin 52706a26a7 Merge pull request 'SPEC v1.1 : une décroissance montrée nomme sa lecture' (#2) from contrat/lecture-de-decroissance into master
gardes du contrat / conformite (push) Successful in 18s
Reviewed-on: #2
Reviewed-by: oat_gitadmin <admin@openathle.com>
2026-09-19 09:00:39 +00:00
temoin-agentandClaude Opus 5 1954dcb704 SPEC v1.1 : une décroissance montrée nomme sa lecture
gardes du contrat / conformite (pull_request) Successful in 18s
Un auditeur qui voit une confiance décrue ne peut pas la reproduire s'il
ignore quelle fonction l'a produite, dans quelle version, à quelle date.
Deux lectures divergentes du même verbatim se valent alors, sans qu'on
puisse dire pourquoi : c'est l'opposabilité qui se fissure, non le fait.

Champ 15 confidence_reading (§4.1), OPTIONNEL — présent seulement quand
l'émetteur EXPOSE une valeur qu'il a dérivée ; ses quatre clés sont alors
requises (policy, version, value, as_of). Le verbatim reste intact au
champ 8. Règle de conformité au §9 : une valeur dérivée non déclarée
n'est pas conforme. Additif et ignorable — un consommateur v1.0 le
préserve et passe, comme §8 l'exige de tout champ inconnu.

Relevé par une lecture extérieure du 2026-09-19 : « c'est une ligne du
contrat, pas une ADR ». Elle avait raison sur les deux points.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 10:13:31 +02:00
8 changed files with 179 additions and 11 deletions
+47 -5
View File
@@ -1,4 +1,4 @@
# Assertion Envelope — Specification v1.0 # Assertion Envelope — Specification v1.2
**Status**: stable. Declared v1.0 upon the first real federated exchange **Status**: stable. Declared v1.0 upon the first real federated exchange
between two distinct jurisdictions — openathle → Prismagram, endorsed between two distinct jurisdictions — openathle → Prismagram, endorsed
@@ -84,12 +84,12 @@ fields (§7).
| 5 | `statement` | string | REQUIRED. What is asserted, in one sentence or few | | 5 | `statement` | string | REQUIRED. What is asserted, in one sentence or few |
| 6 | `evidence` | list of `{kind, ref}` | REQUIRED, MAY be empty. A conflict without evidence asks to be believed; evidence names where the fact lives | | 6 | `evidence` | list of `{kind, ref}` | REQUIRED, MAY be empty. A conflict without evidence asks to be believed; evidence names where the fact lives |
| 7 | `provenance` | string | REQUIRED. One of §6. Transported verbatim (§2.2) | | 7 | `provenance` | string | REQUIRED. One of §6. Transported verbatim (§2.2) |
| 8 | `confidence` | number | REQUIRED. `0.0`–`1.0`. Transported verbatim. Interpretation policies — decay, half-life, thresholds — are consumer-local readings and MUST NOT modify the transported value | | 8 | `confidence` | number | REQUIRED. `0.0`–`1.0`. Transported verbatim. Interpretation policies — decay, half-life, thresholds — are consumer-local readings and MUST NOT modify the transported value. A consumer that *exposes* such a reading declares it (field 15, §4.1) |
| 9 | `endorsement` | object or null | REQUIRED. `{by, at, rite}`; `rite` is one of `pr_approval`, `ui`, `batch`. `null` means: no human has endorsed this — which is a fact, not a defect | | 9 | `endorsement` | object or null | REQUIRED. `{by, at, rite}`; `rite` is one of `pr_approval`, `ui`, `batch`. `null` means: no human has endorsed this — which is a fact, not a defect |
| 10 | `jurisdiction` | string | REQUIRED. MUST equal the prefix of `id`. Lowercase ASCII, no separators | | 10 | `jurisdiction` | string | REQUIRED. MUST equal the prefix of `id`. Lowercase ASCII, no separators |
| 11 | `at` | string | REQUIRED. RFC 3339 timestamp of the asserted state | | 11 | `at` | string | REQUIRED. RFC 3339 timestamp of the asserted state |
| 12 | `lifecycle` | string | REQUIRED. One of `proposed`, `endorsed`, `superseded`, `rejected`, `under_revision` | | 12 | `lifecycle` | string | REQUIRED. One of `proposed`, `endorsed`, `superseded`, `rejected`, `under_revision` |
| 13 | `relations` | object | REQUIRED, MAY be empty. Keys among `amends`, `supersedes`, `depends_on`, `satellite_of`; values are lists of prefixed ids | | 13 | `relations` | object | REQUIRED, MAY be empty. Keys among `amends`, `supersedes`, `depends_on`, `satellite_of`, `confirms` (v1.2); values are lists of prefixed ids |
| 14 | `deadline` | string or null | REQUIRED. RFC 3339. When a falsifiable statement expires into a verdict | | 14 | `deadline` | string or null | REQUIRED. RFC 3339. When a falsifiable statement expires into a verdict |
| 15 | `falsification` | string or null | REQUIRED. What observation would make this assertion false. A hypothesis without one is not a hypothesis | | 15 | `falsification` | string or null | REQUIRED. What observation would make this assertion false. A hypothesis without one is not a hypothesis |
@@ -97,6 +97,37 @@ fields (§7).
assertion; `endorsement` records the proven event. The two are irreducible: assertion; `endorsement` records the proven event. The two are irreducible:
a declared status is not an approval (ADR-070 §3.2). a declared status is not an approval (ADR-070 §3.2).
### 4.1 Declared readings (v1.1)
| # | Field | Type | Rule |
|---|---|---|---|
| 15 | `confidence_reading` | object | OPTIONAL. Present only when the sender exposes a value it has itself derived from `confidence`. Keys: `policy` (string, the reading's name), `version` (string), `value` (number `0.0`–`1.0`), `as_of` (RFC 3339 timestamp). All four REQUIRED when the object is present |
A decayed confidence is a reading, not a fact. Two auditors applying two decay
functions to the same verbatim value, on two dates, would disagree without
either being wrong — and neither could say why. This field makes the reading
quotable: the verbatim value stays in field 8, the reading stands beside it,
named, versioned and dated.
It is OPTIONAL because a consumer that never exposes a derived value never owes
one; it is not optional for those who do (§9).
### 4.2 `confirms` — the measure names what it examined (v1.2)
A `measure` assertion MAY carry `relations.confirms`: the prefixed ids of the
assertions it examined. The direction is deliberate and it is the whole point:
**the measure declares what it confirms; the confirmed assertion is never
edited to point back.** Three reasons, each sufficient. The confirmed
assertion already exists and is append-only. The instrument already knows what
it measured — the link is inferred, never typed. And the author of a
confirmation is the machine that measured, not the agent whose claim is being
confirmed: a producer MUST NOT emit `confirms` on anything but a `measure` of
provenance `measured`.
A consumer MAY derive, from `confirms`, which assertions have been examined
and when — and MAY treat an assertion that no measure has ever confirmed
differently from one that has. That reading is consumer-local (§4.1).
## 5. Classes ## 5. Classes
`invariant`, `step_realized`, `transition`, `traversal`, `stressor`, `invariant`, `step_realized`, `transition`, `traversal`, `stressor`,
@@ -132,6 +163,13 @@ a standard field is a contract change under §8.
declared stable, nothing more. Consumers MUST treat `envelope: "0.1"` declared stable, nothing more. Consumers MUST treat `envelope: "0.1"`
messages as v1.0 messages; the schema accepts both values. This equivalence messages as v1.0 messages; the schema accepts both values. This equivalence
is specific to this pair and will not be repeated across future MAJORs. is specific to this pair and will not be repeated across future MAJORs.
- **v1.1 adds field 15 `confidence_reading`** (§4.1) and the consumer rule that
governs it (§9). Additive and ignorable: a v1.0 consumer that meets the field
preserves it and moves on, exactly as §8 requires of any unknown field. No
existing field, class, provenance or rule changed.
- **v1.2 adds the relation kind `confirms`** (§4.2), carried by measures only.
Additive and ignorable: a consumer that does not know the kind preserves it
as any unknown key of `relations` and moves on.
- At most **two published versions per year**. Deprecation is announced in - At most **two published versions per year**. Deprecation is announced in
this file at least one version before removal. this file at least one version before removal.
- Consumers MUST accept any message whose `envelope` shares their MAJOR and - Consumers MUST accept any message whose `envelope` shares their MAJOR and
@@ -155,7 +193,10 @@ MUST NOT emit an endorsement it did not witness as a dated event; MUST NOT
emit `measured` provenance for anything a machine did not measure. emit `measured` provenance for anything a machine did not measure.
**Consumer** — MUST NOT mutate `id`, `provenance` or `confidence` of a **Consumer** — MUST NOT mutate `id`, `provenance` or `confidence` of a
received assertion; MUST NOT reject messages carrying unknown classes or received assertion; MUST, when it presents or relays a confidence value it has
derived from the transported one, carry the verbatim value unchanged **and**
declare the applied reading in `confidence_reading` (§4.1) — an undeclared
derived value is not conformant, because nobody can reproduce it; MUST NOT reject messages carrying unknown classes or
unknown fields (preserve, expose, move on); MUST record received assertions unknown fields (preserve, expose, move on); MUST record received assertions
append-only; MAY annotate, reference and aggregate received assertions under append-only; MAY annotate, reference and aggregate received assertions under
its own identity, and MUST NOT present the result as the origin's. its own identity, and MUST NOT present the result as the origin's.
@@ -163,6 +204,7 @@ its own identity, and MUST NOT present the result as the origin's.
## 10. What this contract does not do ## 10. What this contract does not do
It does not say how assertions are stored, projected, displayed or decayed — It does not say how assertions are stored, projected, displayed or decayed —
those are jurisdiction-local. It does not transport source documents: sealing those are jurisdiction-local. It says only that a decay, once shown, names
itself (§4.1): the contract governs what is claimed, never how it is computed. It does not transport source documents: sealing
and encrypting source payloads is storage, not exchange. It does not decide and encrypting source payloads is storage, not exchange. It does not decide
who is right: it keeps both parties quotable, at their own risk. who is right: it keeps both parties quotable, at their own risk.
@@ -0,0 +1,20 @@
{
"reason": "confirms is the measure's word about what it examined; an agent claiming its own assertion is confirmed is self-attestation with a pointer (SPEC §4.2).",
"message": {
"envelope": "1.2",
"id": "temoin/EVI-999",
"class": "step_realized",
"subject": "x",
"statement": "y",
"evidence": [],
"provenance": "agent:claude-code",
"confidence": 0.4,
"endorsement": null,
"jurisdiction": "temoin",
"at": "2026-09-21T08:00:00Z",
"lifecycle": "proposed",
"relations": { "confirms": ["openathle/MES-INV-011-2"] },
"deadline": null,
"falsification": null
}
}
@@ -0,0 +1,21 @@
{
"reason": "A declared reading without its version is unreproducible: two auditors on two dates could not tell whether they read alike. All four keys are required when the object is present (SPEC §4.1).",
"message": {
"envelope": "1.1",
"id": "temoin/EVI-999",
"class": "measure",
"subject": "x",
"statement": "y",
"evidence": [],
"provenance": "measured",
"confidence": 1.0,
"endorsement": null,
"jurisdiction": "temoin",
"at": "2026-09-19T08:00:00Z",
"lifecycle": "proposed",
"relations": {},
"deadline": null,
"falsification": null,
"confidence_reading": { "policy": "half-life-by-class", "value": 0.87, "as_of": "2026-09-19T08:00:00Z" }
}
}
@@ -0,0 +1,23 @@
{
"envelope": "1.1",
"id": "temoin/EVI-129",
"class": "measure",
"subject": "INV-011",
"statement": "Detected mishoused on 8 September, reinforced on 10 — the loop closed.",
"evidence": [{ "kind": "coupe", "ref": "openathle/MES-INV-011-2" }],
"provenance": "measured",
"confidence": 1.0,
"endorsement": null,
"jurisdiction": "temoin",
"at": "2026-09-10T12:12:20.466Z",
"lifecycle": "proposed",
"relations": {},
"deadline": null,
"falsification": null,
"confidence_reading": {
"policy": "half-life-by-class",
"version": "1",
"value": 0.87,
"as_of": "2026-09-19T08:00:00Z"
}
}
@@ -0,0 +1,17 @@
{
"envelope": "1.2",
"id": "openathle/MES-INV-011-2",
"class": "measure",
"subject": "INV-011",
"statement": "INV-011 : vérifié à son étage (domaine) et au-dessus — défense en profondeur.",
"evidence": [{ "kind": "epreuve:domaine", "ref": "quarkus-backoffice/src/test/java/org/openathle/LicenceConfig/Domain/ValueObject/RegistryClubRefTest.java:1" }],
"provenance": "measured",
"confidence": 1.0,
"endorsement": null,
"jurisdiction": "openathle",
"at": "2026-09-10T12:12:20.466Z",
"lifecycle": "proposed",
"relations": { "confirms": ["openathle/INV-011"] },
"deadline": null,
"falsification": null
}
+5
View File
@@ -34,6 +34,11 @@ function crossFieldErrors(msg) {
if (prefix !== msg.jurisdiction) if (prefix !== msg.jurisdiction)
errs.push(`jurisdiction "${msg.jurisdiction}" must equal the prefix of id ("${prefix}")`); errs.push(`jurisdiction "${msg.jurisdiction}" must equal the prefix of id ("${prefix}")`);
} }
// §4.2 (v1.2) : la mesure nomme ce qu'elle a examiné — et elle seule.
if (Array.isArray(msg?.relations?.confirms) && msg.relations.confirms.length > 0) {
if (msg.class !== 'measure' || msg.provenance !== 'measured')
errs.push(`relations.confirms is carried by a measure of provenance measured only (got class "${msg.class}", provenance "${msg.provenance}")`);
}
return errs; return errs;
} }
+44 -4
View File
@@ -1,8 +1,8 @@
{ {
"$schema": "https://json-schema.org/draft/2020-12/schema", "$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://prismagram.com/published-language/envelope/1.0/assertion.schema.json", "$id": "https://prismagram.com/published-language/envelope/1.0/assertion.schema.json",
"title": "Assertion Envelope v0.1", "title": "Assertion Envelope v1.2",
"description": "Producer contract for envelope v0.1 messages (SPEC.md §4). One cross-field rule cannot be expressed here and is enforced by the conformance runner: `jurisdiction` MUST equal the prefix of `id`.", "description": "Producer contract for envelope v1.1 messages (SPEC.md §4). One cross-field rule cannot be expressed here and is enforced by the conformance runner: `jurisdiction` MUST equal the prefix of `id`.",
"type": "object", "type": "object",
"required": [ "required": [
"envelope", "envelope",
@@ -25,9 +25,11 @@
"envelope": { "envelope": {
"enum": [ "enum": [
"0.1", "0.1",
"1.0" "1.0",
"1.1",
"1.2"
], ],
"description": "Version of the contract. v1.0 is substantively identical to v0.1 (SPEC §8): both values validate. A message that does not declare its version is not versioned (A1 §3)." "description": "Version of the contract. v1.0 is substantively identical to v0.1 (SPEC §8): both values validate. v1.1 adds the optional declared reading (§4.1); v1.2 adds the relation kind `confirms` (§4.2). A message that does not declare its version is not versioned (A1 §3)."
}, },
"id": { "id": {
"type": "string", "type": "string",
@@ -153,6 +155,10 @@
}, },
"satellite_of": { "satellite_of": {
"$ref": "#/$defs/idList" "$ref": "#/$defs/idList"
},
"confirms": {
"$ref": "#/$defs/idList",
"description": "v1.2, §4.2. Carried by a `measure` of provenance `measured` only: the ids it examined. The measure points at what it confirms; the confirmed assertion is never edited to point back."
} }
}, },
"additionalProperties": false "additionalProperties": false
@@ -178,6 +184,40 @@
"minLength": 1 "minLength": 1
} }
] ]
},
"confidence_reading": {
"type": "object",
"description": "OPTIONAL (SPEC §4.1, v1.1). Present only when the sender exposes a value it derived from `confidence`. A derived value shown without this object is not conformant: nobody could reproduce it.",
"required": [
"policy",
"version",
"value",
"as_of"
],
"additionalProperties": false,
"properties": {
"policy": {
"type": "string",
"minLength": 1,
"description": "Name of the reading applied — not the value it produced."
},
"version": {
"type": "string",
"minLength": 1,
"description": "Version of that reading. Two auditors on two dates must be able to tell whether they read alike."
},
"value": {
"type": "number",
"minimum": 0,
"maximum": 1,
"description": "The derived value. The verbatim one stays in `confidence`, untouched."
},
"as_of": {
"type": "string",
"format": "date-time",
"description": "When the reading was taken. A decay without a date is not reproducible."
}
}
} }
}, },
"patternProperties": { "patternProperties": {
+2 -2
View File
@@ -1,9 +1,9 @@
{ {
"name": "published-language", "name": "published-language",
"version": "0.1.0", "version": "1.2.0",
"private": true, "private": true,
"type": "module", "type": "module",
"description": "Contrat d'échange inter-juridictions : grammaire source (grammar/) et enveloppe d'assertion (envelope/), sous un seul numéro de version (ADR-061/A1.2 §2.6, décision 6). Privé jusqu'à l'extraction publique décrite dans OPENING.md.", "description": "Contrat d'échange inter-juridictions : grammaire source (grammar/) et enveloppe d'assertion (envelope/), sous un seul numéro de version (ADR-061/A1.2 §2.6, décision 6). Public, développé ici par pull request endossée (temoin/DEC-014).",
"license": "Apache-2.0", "license": "Apache-2.0",
"scripts": { "scripts": {
"conformance": "node envelope/conformance/run.mjs", "conformance": "node envelope/conformance/run.mjs",