{
  "format": "hive.canon.reference-acceptance.v1",
  "status": "passed_bounded_reference",
  "owner": "Hive reference release owner",
  "production_acceptance": false,
  "surface_ids": [
    "evidence-contract",
    "counterparty-reconciliation",
    "decision-evidence",
    "action-boundary",
    "portable-trust"
  ],
  "scope": "Fixed synthetic evidence evaluation, package checks, explicit demonstration trust, local memory admission, and portable replay. This does not accept the complete target services or canonical adapters.",
  "reference_profile": "hive.reference.bundle.v1",
  "verification_report_profile": "hive.reference.verification.v2",
  "canonical_verifiers_exercised": false,
  "operations_inventory": "./operations.json",
  "tests": {
    "engine": {
      "passed": 191,
      "failed": 0
    },
    "independent_adversarial": {
      "passed": 111,
      "failed": 0
    },
    "browser": {
      "passed": true,
      "checks": 62,
      "failures": []
    }
  },
  "tested_files_sha256": {
    "canon-bindings.json": "f5f4900f5666d7ed2119aafd9bd9dcb7eab7c980ce0962b0708a0fc9939971d8",
    "operations.json": "a9bfbe4a95f59abcd22cac423d36d72675a11ee4b56ef42a1eb2fd4afbfeb18d",
    "operations.schema.json": "6c25794edb9b9dcbe210d0afec1ffe1df1518b7a48e6a6d853189a63bb5e0a54",
    "reference/README.txt": "0ecc861312d84b27593f7a2bf67803cd71dd4f76f03c5cab8c25c3adaceceeeb",
    "reference/encoding.mjs": "c33b7495cb378a331430028d3a6db0a965023853a6a397dcfce904c1b6092745",
    "reference/engine.mjs": "2fb20ae31b6598a4a54dd7d3a5a7fb8eddb200ed7066433fc8447645c2a4010d",
    "reference/fixture-expectations.json": "66733d74021fd713fa3545a9f2e8a1c6223a0b1c8a0d9078e2aaa55ad16949c9",
    "reference/fixtures/conflict.json": "839370c5f69ea9ffdd520a14b061198063144355e40d43c9bc71981cced4b611",
    "reference/fixtures/correction.json": "ca2b4a554aa731263240f39ca234202f6b69281643f6263bb324a84f0528d511",
    "reference/fixtures/denial.json": "5cc8a42f2868eb10606bed308382bfb6f6b7d2ec6371e006dedf3a8a01236801",
    "reference/fixtures/missing.json": "7d53f790dc60b2071b943f3cd91c7ecaba973e59d9d5ff42c0cd71270337dbc3",
    "reference/fixtures/normal.json": "cf293433f06f4b5905a786403cff7375dddb5cf0107941122c375a7abff85381",
    "reference/fixtures/retry.json": "0bfba5dbef9b25d8f1de20778beb96e62a97c8995cf061b723203669faab708d",
    "reference/fixtures/revoked.json": "150b927e5522355e96944f12bc5c7e1e320f7163fd39c8c73b6b7469614400f4",
    "reference/fixtures/stale-acceptance.json": "5c46bc139765142327359d552c97e7be947141a990abd9db195f346609e9adba",
    "reference/fixtures/tampered.json": "66a934de058869534102c92e218ced14d269571c1ade10af8a088c282222e8df",
    "reference/fixtures/trust.json": "94681314653bbd9c5e3c3766b60bb8aa53ebd8aca6394aeb7911089d3cd47667",
    "reference/fixtures/unknown-coverage.json": "ac1320971503d410046267772567fd999073c1db5aaf1a34e2716cfccbb734d7",
    "reference/fixtures/unsupported.json": "a802f5aec1584f216d85ba9f50017592900d560d32a8589c1a61bed996a52d1b",
    "reference/hive-canon-reference-offline.zip": "927698b8af792a748786adb504d1f1a10fb1aa12b23a150dde2aa8f728531cdb",
    "reference/hive-canon-reference-offline.zip.sha256": "9050ff0d7bdaaf65d68c51cf13f5fdd84e35e3c068afc4bdae992d87065533e5",
    "reference/offline-checker.mjs": "96b7d7a8f90075b5360da4e00b35ab06af6d6c4d1eeae328158e3392f8916617",
    "reference/offline_bundle/README.txt": "0ecc861312d84b27593f7a2bf67803cd71dd4f76f03c5cab8c25c3adaceceeeb",
    "reference/offline_bundle/artifact-manifest.json": "b77632ae832403d0d95b51ba96931b4ef98a4bcd6a6560e04661bbc424a0d09c",
    "reference/offline_bundle/conflict.json": "839370c5f69ea9ffdd520a14b061198063144355e40d43c9bc71981cced4b611",
    "reference/offline_bundle/conflict.snapshot.json": "3f5ba4aafc3b7d8e614a8b9449f716c294b2cc1cae5e1283c93a04e72e0c21ad",
    "reference/offline_bundle/correction.json": "ca2b4a554aa731263240f39ca234202f6b69281643f6263bb324a84f0528d511",
    "reference/offline_bundle/correction.snapshot.json": "c24b20d5fac98b4291382fb2ed3f6bec380dd8602335c5128b9303871da040b8",
    "reference/offline_bundle/denial.json": "5cc8a42f2868eb10606bed308382bfb6f6b7d2ec6371e006dedf3a8a01236801",
    "reference/offline_bundle/denial.snapshot.json": "3ca307c708f5380f0387294a4676f4c911d93b754014cd09d2e7e0debe8dd212",
    "reference/offline_bundle/encoding.mjs": "c33b7495cb378a331430028d3a6db0a965023853a6a397dcfce904c1b6092745",
    "reference/offline_bundle/engine.mjs": "2fb20ae31b6598a4a54dd7d3a5a7fb8eddb200ed7066433fc8447645c2a4010d",
    "reference/offline_bundle/fixture-expectations.json": "66733d74021fd713fa3545a9f2e8a1c6223a0b1c8a0d9078e2aaa55ad16949c9",
    "reference/offline_bundle/missing.json": "7d53f790dc60b2071b943f3cd91c7ecaba973e59d9d5ff42c0cd71270337dbc3",
    "reference/offline_bundle/missing.snapshot.json": "0e4b589cfcc41b61cc79a3d8fcef8164832857f187edbd1a987fecf59ebc2409",
    "reference/offline_bundle/normal.json": "cf293433f06f4b5905a786403cff7375dddb5cf0107941122c375a7abff85381",
    "reference/offline_bundle/normal.snapshot.json": "b8876c11f64a4d926d5016e318a1c4ac21147fe56b10995f31e7e02d5979dd8d",
    "reference/offline_bundle/offline-checker.mjs": "96b7d7a8f90075b5360da4e00b35ab06af6d6c4d1eeae328158e3392f8916617",
    "reference/offline_bundle/reference.schema.json": "dfd60e37915a81d6b2b99914c26f01d5c932808641a23ae680a2911e8b524d60",
    "reference/offline_bundle/retry.json": "0bfba5dbef9b25d8f1de20778beb96e62a97c8995cf061b723203669faab708d",
    "reference/offline_bundle/retry.snapshot.json": "17a765097757ee1cbb4021c275cc140239370cb64967b970973f7da3fe114497",
    "reference/offline_bundle/revoked.json": "150b927e5522355e96944f12bc5c7e1e320f7163fd39c8c73b6b7469614400f4",
    "reference/offline_bundle/revoked.snapshot.json": "55623acffe0c9385547a881ec926ea40fc615b924606b03e852fd7c3a8a3ac63",
    "reference/offline_bundle/stale-acceptance.json": "5c46bc139765142327359d552c97e7be947141a990abd9db195f346609e9adba",
    "reference/offline_bundle/stale-acceptance.snapshot.json": "e88ff0b758469004d2dac56254caa3d9a9957abb2b3b1aba2a6673291170bf24",
    "reference/offline_bundle/tampered.json": "66a934de058869534102c92e218ced14d269571c1ade10af8a088c282222e8df",
    "reference/offline_bundle/tampered.snapshot.json": "a28db6356d6b313634e4b85243c25a1b85dd10657b222f48428cea95aaaf74e4",
    "reference/offline_bundle/trust.json": "94681314653bbd9c5e3c3766b60bb8aa53ebd8aca6394aeb7911089d3cd47667",
    "reference/offline_bundle/unknown-coverage.json": "ac1320971503d410046267772567fd999073c1db5aaf1a34e2716cfccbb734d7",
    "reference/offline_bundle/unknown-coverage.snapshot.json": "acc7c6d49c31ac91924a52fc41dc36a34f13de231dfd2ddae62237b972a9a7ac",
    "reference/offline_bundle/unsupported.json": "a802f5aec1584f216d85ba9f50017592900d560d32a8589c1a61bed996a52d1b",
    "reference/offline_bundle/unsupported.snapshot.json": "55ba174cc1e464441b5a3f5b9ad800a20f83d45f899345a899ef3234131365a4",
    "reference/reference.schema.json": "dfd60e37915a81d6b2b99914c26f01d5c932808641a23ae680a2911e8b524d60",
    "reference/snapshots/conflict.snapshot.json": "3f5ba4aafc3b7d8e614a8b9449f716c294b2cc1cae5e1283c93a04e72e0c21ad",
    "reference/snapshots/correction.snapshot.json": "c24b20d5fac98b4291382fb2ed3f6bec380dd8602335c5128b9303871da040b8",
    "reference/snapshots/denial.snapshot.json": "3ca307c708f5380f0387294a4676f4c911d93b754014cd09d2e7e0debe8dd212",
    "reference/snapshots/missing.snapshot.json": "0e4b589cfcc41b61cc79a3d8fcef8164832857f187edbd1a987fecf59ebc2409",
    "reference/snapshots/normal.snapshot.json": "b8876c11f64a4d926d5016e318a1c4ac21147fe56b10995f31e7e02d5979dd8d",
    "reference/snapshots/retry.snapshot.json": "17a765097757ee1cbb4021c275cc140239370cb64967b970973f7da3fe114497",
    "reference/snapshots/revoked.snapshot.json": "55623acffe0c9385547a881ec926ea40fc615b924606b03e852fd7c3a8a3ac63",
    "reference/snapshots/stale-acceptance.snapshot.json": "e88ff0b758469004d2dac56254caa3d9a9957abb2b3b1aba2a6673291170bf24",
    "reference/snapshots/tampered.snapshot.json": "a28db6356d6b313634e4b85243c25a1b85dd10657b222f48428cea95aaaf74e4",
    "reference/snapshots/unknown-coverage.snapshot.json": "acc7c6d49c31ac91924a52fc41dc36a34f13de231dfd2ddae62237b972a9a7ac",
    "reference/snapshots/unsupported.snapshot.json": "55ba174cc1e464441b5a3f5b9ad800a20f83d45f899345a899ef3234131365a4",
    "reference/tests.mjs": "14a08162378552c1c9b9dad2ce384fdc3d7b1625e81a321db5d98ecad9fa9ade",
    "surface-map.schema.json": "7424cd1dbfda27cfc401ba322510f473657d912fa413cc6a43eb608175428a30",
    "surfaces.css": "04cacee538b4071c5cbbece54a5149eede42775ed68bb4f633982e7ee5e99f82",
    "surfaces.mjs": "43bbb0671de3343c79f83e12269b4a1402befd34699c207d90c5ef92ea31f64c"
  },
  "operation_evidence": {
    "format": "hive.canon.operation-test-results.v1",
    "scope": "Node local synthetic reference only; no browser, canonical adapter, AX target, integration, production, or independent-party acceptance.",
    "production_acceptance": false,
    "canonical_verifiers_exercised": false,
    "specified_targets_accepted": [],
    "target_gates_passed": [],
    "tester": {
      "identity": "Hive reference release builder",
      "relationship": "release_builder_not_independent",
      "independent": false
    },
    "review_trigger": "Any change to a required source, fixture, trust policy, operation selector, environment, or limitation requires a new run and review.",
    "tested_files_sha256": {
      "canon-bindings.json": "f5f4900f5666d7ed2119aafd9bd9dcb7eab7c980ce0962b0708a0fc9939971d8",
      "operations.json": "a9bfbe4a95f59abcd22cac423d36d72675a11ee4b56ef42a1eb2fd4afbfeb18d",
      "operations.schema.json": "6c25794edb9b9dcbe210d0afec1ffe1df1518b7a48e6a6d853189a63bb5e0a54",
      "reference/README.txt": "0ecc861312d84b27593f7a2bf67803cd71dd4f76f03c5cab8c25c3adaceceeeb",
      "reference/encoding.mjs": "c33b7495cb378a331430028d3a6db0a965023853a6a397dcfce904c1b6092745",
      "reference/engine.mjs": "2fb20ae31b6598a4a54dd7d3a5a7fb8eddb200ed7066433fc8447645c2a4010d",
      "reference/fixture-expectations.json": "66733d74021fd713fa3545a9f2e8a1c6223a0b1c8a0d9078e2aaa55ad16949c9",
      "reference/fixtures/conflict.json": "839370c5f69ea9ffdd520a14b061198063144355e40d43c9bc71981cced4b611",
      "reference/fixtures/correction.json": "ca2b4a554aa731263240f39ca234202f6b69281643f6263bb324a84f0528d511",
      "reference/fixtures/denial.json": "5cc8a42f2868eb10606bed308382bfb6f6b7d2ec6371e006dedf3a8a01236801",
      "reference/fixtures/missing.json": "7d53f790dc60b2071b943f3cd91c7ecaba973e59d9d5ff42c0cd71270337dbc3",
      "reference/fixtures/normal.json": "cf293433f06f4b5905a786403cff7375dddb5cf0107941122c375a7abff85381",
      "reference/fixtures/retry.json": "0bfba5dbef9b25d8f1de20778beb96e62a97c8995cf061b723203669faab708d",
      "reference/fixtures/revoked.json": "150b927e5522355e96944f12bc5c7e1e320f7163fd39c8c73b6b7469614400f4",
      "reference/fixtures/stale-acceptance.json": "5c46bc139765142327359d552c97e7be947141a990abd9db195f346609e9adba",
      "reference/fixtures/tampered.json": "66a934de058869534102c92e218ced14d269571c1ade10af8a088c282222e8df",
      "reference/fixtures/trust.json": "94681314653bbd9c5e3c3766b60bb8aa53ebd8aca6394aeb7911089d3cd47667",
      "reference/fixtures/unknown-coverage.json": "ac1320971503d410046267772567fd999073c1db5aaf1a34e2716cfccbb734d7",
      "reference/fixtures/unsupported.json": "a802f5aec1584f216d85ba9f50017592900d560d32a8589c1a61bed996a52d1b",
      "reference/hive-canon-reference-offline.zip": "927698b8af792a748786adb504d1f1a10fb1aa12b23a150dde2aa8f728531cdb",
      "reference/hive-canon-reference-offline.zip.sha256": "9050ff0d7bdaaf65d68c51cf13f5fdd84e35e3c068afc4bdae992d87065533e5",
      "reference/offline-checker.mjs": "96b7d7a8f90075b5360da4e00b35ab06af6d6c4d1eeae328158e3392f8916617",
      "reference/offline_bundle/README.txt": "0ecc861312d84b27593f7a2bf67803cd71dd4f76f03c5cab8c25c3adaceceeeb",
      "reference/offline_bundle/artifact-manifest.json": "b77632ae832403d0d95b51ba96931b4ef98a4bcd6a6560e04661bbc424a0d09c",
      "reference/offline_bundle/conflict.json": "839370c5f69ea9ffdd520a14b061198063144355e40d43c9bc71981cced4b611",
      "reference/offline_bundle/conflict.snapshot.json": "3f5ba4aafc3b7d8e614a8b9449f716c294b2cc1cae5e1283c93a04e72e0c21ad",
      "reference/offline_bundle/correction.json": "ca2b4a554aa731263240f39ca234202f6b69281643f6263bb324a84f0528d511",
      "reference/offline_bundle/correction.snapshot.json": "c24b20d5fac98b4291382fb2ed3f6bec380dd8602335c5128b9303871da040b8",
      "reference/offline_bundle/denial.json": "5cc8a42f2868eb10606bed308382bfb6f6b7d2ec6371e006dedf3a8a01236801",
      "reference/offline_bundle/denial.snapshot.json": "3ca307c708f5380f0387294a4676f4c911d93b754014cd09d2e7e0debe8dd212",
      "reference/offline_bundle/encoding.mjs": "c33b7495cb378a331430028d3a6db0a965023853a6a397dcfce904c1b6092745",
      "reference/offline_bundle/engine.mjs": "2fb20ae31b6598a4a54dd7d3a5a7fb8eddb200ed7066433fc8447645c2a4010d",
      "reference/offline_bundle/fixture-expectations.json": "66733d74021fd713fa3545a9f2e8a1c6223a0b1c8a0d9078e2aaa55ad16949c9",
      "reference/offline_bundle/missing.json": "7d53f790dc60b2071b943f3cd91c7ecaba973e59d9d5ff42c0cd71270337dbc3",
      "reference/offline_bundle/missing.snapshot.json": "0e4b589cfcc41b61cc79a3d8fcef8164832857f187edbd1a987fecf59ebc2409",
      "reference/offline_bundle/normal.json": "cf293433f06f4b5905a786403cff7375dddb5cf0107941122c375a7abff85381",
      "reference/offline_bundle/normal.snapshot.json": "b8876c11f64a4d926d5016e318a1c4ac21147fe56b10995f31e7e02d5979dd8d",
      "reference/offline_bundle/offline-checker.mjs": "96b7d7a8f90075b5360da4e00b35ab06af6d6c4d1eeae328158e3392f8916617",
      "reference/offline_bundle/reference.schema.json": "dfd60e37915a81d6b2b99914c26f01d5c932808641a23ae680a2911e8b524d60",
      "reference/offline_bundle/retry.json": "0bfba5dbef9b25d8f1de20778beb96e62a97c8995cf061b723203669faab708d",
      "reference/offline_bundle/retry.snapshot.json": "17a765097757ee1cbb4021c275cc140239370cb64967b970973f7da3fe114497",
      "reference/offline_bundle/revoked.json": "150b927e5522355e96944f12bc5c7e1e320f7163fd39c8c73b6b7469614400f4",
      "reference/offline_bundle/revoked.snapshot.json": "55623acffe0c9385547a881ec926ea40fc615b924606b03e852fd7c3a8a3ac63",
      "reference/offline_bundle/stale-acceptance.json": "5c46bc139765142327359d552c97e7be947141a990abd9db195f346609e9adba",
      "reference/offline_bundle/stale-acceptance.snapshot.json": "e88ff0b758469004d2dac56254caa3d9a9957abb2b3b1aba2a6673291170bf24",
      "reference/offline_bundle/tampered.json": "66a934de058869534102c92e218ced14d269571c1ade10af8a088c282222e8df",
      "reference/offline_bundle/tampered.snapshot.json": "a28db6356d6b313634e4b85243c25a1b85dd10657b222f48428cea95aaaf74e4",
      "reference/offline_bundle/trust.json": "94681314653bbd9c5e3c3766b60bb8aa53ebd8aca6394aeb7911089d3cd47667",
      "reference/offline_bundle/unknown-coverage.json": "ac1320971503d410046267772567fd999073c1db5aaf1a34e2716cfccbb734d7",
      "reference/offline_bundle/unknown-coverage.snapshot.json": "acc7c6d49c31ac91924a52fc41dc36a34f13de231dfd2ddae62237b972a9a7ac",
      "reference/offline_bundle/unsupported.json": "a802f5aec1584f216d85ba9f50017592900d560d32a8589c1a61bed996a52d1b",
      "reference/offline_bundle/unsupported.snapshot.json": "55ba174cc1e464441b5a3f5b9ad800a20f83d45f899345a899ef3234131365a4",
      "reference/reference.schema.json": "dfd60e37915a81d6b2b99914c26f01d5c932808641a23ae680a2911e8b524d60",
      "reference/snapshots/conflict.snapshot.json": "3f5ba4aafc3b7d8e614a8b9449f716c294b2cc1cae5e1283c93a04e72e0c21ad",
      "reference/snapshots/correction.snapshot.json": "c24b20d5fac98b4291382fb2ed3f6bec380dd8602335c5128b9303871da040b8",
      "reference/snapshots/denial.snapshot.json": "3ca307c708f5380f0387294a4676f4c911d93b754014cd09d2e7e0debe8dd212",
      "reference/snapshots/missing.snapshot.json": "0e4b589cfcc41b61cc79a3d8fcef8164832857f187edbd1a987fecf59ebc2409",
      "reference/snapshots/normal.snapshot.json": "b8876c11f64a4d926d5016e318a1c4ac21147fe56b10995f31e7e02d5979dd8d",
      "reference/snapshots/retry.snapshot.json": "17a765097757ee1cbb4021c275cc140239370cb64967b970973f7da3fe114497",
      "reference/snapshots/revoked.snapshot.json": "55623acffe0c9385547a881ec926ea40fc615b924606b03e852fd7c3a8a3ac63",
      "reference/snapshots/stale-acceptance.snapshot.json": "e88ff0b758469004d2dac56254caa3d9a9957abb2b3b1aba2a6673291170bf24",
      "reference/snapshots/tampered.snapshot.json": "a28db6356d6b313634e4b85243c25a1b85dd10657b222f48428cea95aaaf74e4",
      "reference/snapshots/unknown-coverage.snapshot.json": "acc7c6d49c31ac91924a52fc41dc36a34f13de231dfd2ddae62237b972a9a7ac",
      "reference/snapshots/unsupported.snapshot.json": "55ba174cc1e464441b5a3f5b9ad800a20f83d45f899345a899ef3234131365a4",
      "reference/tests.mjs": "14a08162378552c1c9b9dad2ce384fdc3d7b1625e81a321db5d98ecad9fa9ade",
      "surface-map.schema.json": "7424cd1dbfda27cfc401ba322510f473657d912fa413cc6a43eb608175428a30",
      "surfaces.css": "04cacee538b4071c5cbbece54a5149eede42775ed68bb4f633982e7ee5e99f82",
      "surfaces.mjs": "43bbb0671de3343c79f83e12269b4a1402befd34699c207d90c5ef92ea31f64c"
    },
    "run": {
      "started_at": "2026-09-12T17:35:10.941388+00:00",
      "finished_at": "2026-09-12T17:35:11.783511+00:00",
      "environment": {
        "profile": "node20-linux-local-synthetic-v1",
        "supported": true,
        "node": "v20.20.1",
        "platform": "linux",
        "arch": "x64",
        "webcrypto": true,
        "permission": true,
        "ed25519": true
      },
      "command": [
        "node",
        "--experimental-global-webcrypto",
        "--test",
        "--test-reporter=tap",
        "--test-name-pattern=^(?:a\\ different\\ caller\\ selected\\ public\\ key\\ cannot\\ verify\\ the\\ signature|artifact\\ boundary:\\ extra|artifact\\ boundary:\\ hash|artifact\\ boundary:\\ traversal|artifact\\ manifest\\ rejects\\ symlink\\ additions|clock\\ rollback\\ is\\ rejected|concurrent\\ token\\ uses\\ cannot\\ both\\ record\\ an\\ effect|correction\\ cycle\\ is\\ rejected|correction\\ fork\\ is\\ rejected|correction\\ keeps\\ history\\ and\\ changes\\ exact\\ acceptance\\ digest|crypto\\ unavailability\\ fails\\ closed|current\\ acceptance\\ does\\ not\\ override\\ conflict|denial\\ cannot\\ be\\ erased\\ by\\ a\\ retry|denial\\ correction\\ can\\ be\\ renewed\\ while\\ historical\\ denial\\ remains\\ counted|denial\\ is\\ not\\ a\\ missing\\ evidence\\ count\\ or\\ an\\ inferred\\ exception\\ denominator|empty\\ support\\ remains\\ unresolved\\ even\\ when\\ evidence\\ is\\ complete|explicit\\ acceptance\\ denial\\ blocks\\ complete\\ evidence|explicit\\ trust\\ policy:\\ no\\ selected\\ key|explicit\\ trust\\ policy:\\ revoked\\ key|fixture\\ conflict:\\ native\\ and\\ browser\\ crypto\\ parity,\\ snapshot,\\ gate|fixture\\ correction:\\ native\\ and\\ browser\\ crypto\\ parity,\\ snapshot,\\ gate|fixture\\ missing:\\ native\\ and\\ browser\\ crypto\\ parity,\\ snapshot,\\ gate|gate\\ binding:\\ action\\ digest|gate\\ binding:\\ case\\ ID|gate\\ binding:\\ rule\\ digest|gate\\ rejects\\ a\\ token\\ not\\ included\\ in\\ the\\ exact\\ package|gate\\ rejects\\ an\\ unsigned\\ bypass\\ request|gate\\ rejects\\ changed\\ action\\ payload|independent\\ register\\ with\\ an\\ unobserved\\ record\\ blocks\\ without\\ inventing\\ attempts|key\\ expiration\\ during\\ crypto\\ is\\ checked\\ at\\ effect\\ time|new\\ gate\\ resets\\ nonce\\ memory,\\ an\\ explicit\\ documented\\ boundary|nonce\\ is\\ consumed\\ once\\ and\\ receipt\\ follows\\ effect|offline\\ archive\\ manifest\\ and\\ expected\\ negative\\ fixture\\ outcomes|offline\\ command\\ needs\\ explicit\\ caller\\ selected\\ trust|offline\\ command\\ runs\\ with\\ restricted\\ filesystem\\ permission|offline\\ imports\\ have\\ no\\ networking,\\ process,\\ or\\ package\\ dependency|package\\ adversary:\\ changed\\ signature|package\\ adversary:\\ changed\\ token\\ signature\\ under\\ valid\\ envelope|package\\ adversary:\\ embedded\\ authorizing\\ key|package\\ adversary:\\ signed\\ false\\ snapshot|package\\ adversary:\\ wrong\\ algorithm|pure\\ evaluation\\ preserves\\ caller\\ objects\\ and\\ key\\ order\\ is\\ irrelevant|request\\ action\\ mutation\\ while\\ awaiting\\ does\\ not\\ change\\ the\\ effect|retry\\ does\\ not\\ inflate\\ eligible\\ population\\ or\\ logical\\ decision\\ counts|revision\\ alone\\ invalidates\\ acceptance|same\\ revision\\ with\\ different\\ claim\\ text\\ invalidates\\ acceptance|schema\\ projection\\ cannot\\ substitute\\ for\\ reference,\\ integrity,\\ or\\ replay\\ checks|selected\\ revoked\\ nonce\\ blocks\\ an\\ otherwise\\ verified\\ package|snapshot\\ and\\ returned\\ receipts\\ cannot\\ mutate\\ gate\\ state|stale\\ acceptance\\ retains\\ its\\ decision\\ but\\ never\\ authorizes|strict\\ rejection:\\ dangling\\ support|strict\\ rejection:\\ removed\\ required\\ kind|strict\\ rejection:\\ unsupported\\ rule|strict\\ text:\\ depth\\ bound|strict\\ text:\\ duplicate\\ keys|strict\\ text:\\ unsafe\\ integer|structural\\ links\\ do\\ not\\ judge\\ semantic\\ truth|superseded\\ support\\ does\\ not\\ remain\\ current|token\\ expiration\\ during\\ crypto\\ is\\ checked\\ at\\ effect\\ time|trust\\ change\\ during\\ verification\\ fails\\ closed|trust\\ report\\ distinguishes\\ valid\\ verification\\ at\\ different\\ selected\\ times|trust\\ report\\ never\\ represents\\ an\\ invalid\\ policy\\ time\\ as\\ evaluated|trust\\ report\\ retains\\ the\\ precise\\ selected\\ time\\ at\\ key\\ validity\\ boundaries|trust\\ updates\\ do\\ not\\ reset\\ used\\ nonces|two\\ current\\ identical\\ attestations\\ are\\ still\\ ambiguous|unknown\\ coverage\\ has\\ a\\ null\\ denominator\\ and\\ blocks|verification\\ combined\\ failure:\\ hash\\ failure\\ takes\\ precedence\\ over\\ an\\ unexamined\\ bad\\ signature|verification\\ combined\\ failure:\\ known\\ hash\\ failure\\ prevents\\ an\\ unusable\\ WebCrypto\\ call|verification\\ combined\\ failure:\\ native\\ crypto\\ failure\\ cannot\\ mask\\ a\\ known\\ hash\\ mismatch|verification\\ epistemic\\ status:\\ malformed\\ envelope\\ is\\ not\\ a\\ failed\\ crypto\\ check|verification\\ epistemic\\ status:\\ report\\ version\\ does\\ not\\ alter\\ signed\\ case\\ snapshots|verification\\ epistemic\\ status:\\ unknown\\ key\\ does\\ not\\ claim\\ signature\\ failure)$",
        "reference/tests.mjs"
      ],
      "working_directory": "isolated copy of hashed surfaces",
      "exit_code": 0,
      "stdout": "TAP version 13\n# Subtest: fixture normal: native and browser crypto parity, snapshot, gate\nok 1 - fixture normal: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 1.083855\n  ...\n# Subtest: fixture retry: native and browser crypto parity, snapshot, gate\nok 2 - fixture retry: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.151068\n  ...\n# Subtest: fixture missing: native and browser crypto parity, snapshot, gate\nok 3 - fixture missing: native and browser crypto parity, snapshot, gate\n  ---\n  duration_ms: 65.972899\n  ...\n# Subtest: fixture conflict: native and browser crypto parity, snapshot, gate\nok 4 - fixture conflict: native and browser crypto parity, snapshot, gate\n  ---\n  duration_ms: 36.611641\n  ...\n# Subtest: fixture correction: native and browser crypto parity, snapshot, gate\nok 5 - fixture correction: native and browser crypto parity, snapshot, gate\n  ---\n  duration_ms: 18.748944\n  ...\n# Subtest: fixture denial: native and browser crypto parity, snapshot, gate\nok 6 - fixture denial: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.132206\n  ...\n# Subtest: fixture unknown-coverage: native and browser crypto parity, snapshot, gate\nok 7 - fixture unknown-coverage: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.065043\n  ...\n# Subtest: fixture revoked: native and browser crypto parity, snapshot, gate\nok 8 - fixture revoked: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.070096\n  ...\n# Subtest: fixture stale-acceptance: native and browser crypto parity, snapshot, gate\nok 9 - fixture stale-acceptance: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.150169\n  ...\n# Subtest: fixture tampered: native and browser crypto parity, snapshot, gate\nok 10 - fixture tampered: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.140923\n  ...\n# Subtest: fixture unsupported: native and browser crypto parity, snapshot, gate\nok 11 - fixture unsupported: native and browser crypto parity, snapshot, gate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.103075\n  ...\n# Subtest: retry does not inflate eligible population or logical decision counts\nok 12 - retry does not inflate eligible population or logical decision counts\n  ---\n  duration_ms: 1.237663\n  ...\n# Subtest: denial is not a missing evidence count or an inferred exception denominator\nok 13 - denial is not a missing evidence count or an inferred exception denominator\n  ---\n  duration_ms: 4.695408\n  ...\n# Subtest: independent register with an unobserved record blocks without inventing attempts\nok 14 - independent register with an unobserved record blocks without inventing attempts\n  ---\n  duration_ms: 1.345139\n  ...\n# Subtest: unknown coverage has a null denominator and blocks\nok 15 - unknown coverage has a null denominator and blocks\n  ---\n  duration_ms: 1.146603\n  ...\n# Subtest: current acceptance does not override conflict\nok 16 - current acceptance does not override conflict\n  ---\n  duration_ms: 1.235985\n  ...\n# Subtest: correction keeps history and changes exact acceptance digest\nok 17 - correction keeps history and changes exact acceptance digest\n  ---\n  duration_ms: 1.550944\n  ...\n# Subtest: stale acceptance retains its decision but never authorizes\nok 18 - stale acceptance retains its decision but never authorizes\n  ---\n  duration_ms: 1.604279\n  ...\n# Subtest: same revision with different claim text invalidates acceptance\nok 19 - same revision with different claim text invalidates acceptance\n  ---\n  duration_ms: 0.909766\n  ...\n# Subtest: revision alone invalidates acceptance\nok 20 - revision alone invalidates acceptance\n  ---\n  duration_ms: 0.918072\n  ...\n# Subtest: structural links do not judge semantic truth\nok 21 - structural links do not judge semantic truth\n  ---\n  duration_ms: 1.103805\n  ...\n# Subtest: empty support remains unresolved even when evidence is complete\nok 22 - empty support remains unresolved even when evidence is complete\n  ---\n  duration_ms: 1.050163\n  ...\n# Subtest: superseded support does not remain current\nok 23 - superseded support does not remain current\n  ---\n  duration_ms: 1.709735\n  ...\n# Subtest: two current identical attestations are still ambiguous\nok 24 - two current identical attestations are still ambiguous\n  ---\n  duration_ms: 1.199944\n  ...\n# Subtest: explicit acceptance denial blocks complete evidence\nok 25 - explicit acceptance denial blocks complete evidence\n  ---\n  duration_ms: 0.88523\n  ...\n# Subtest: strict rejection: unknown root field\nok 26 - strict rejection: unknown root field # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.052133\n  ...\n# Subtest: strict rejection: unknown nested field\nok 27 - strict rejection: unknown nested field # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.038918\n  ...\n# Subtest: strict rejection: missing root field\nok 28 - strict rejection: missing root field # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.037514\n  ...\n# Subtest: strict rejection: wrong field type\nok 29 - strict rejection: wrong field type # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.035972\n  ...\n# Subtest: strict rejection: unsafe integer\nok 30 - strict rejection: unsafe integer # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.076698\n  ...\n# Subtest: strict rejection: fraction\nok 31 - strict rejection: fraction # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.03919\n  ...\n# Subtest: strict rejection: negative zero\nok 32 - strict rejection: negative zero # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.100521\n  ...\n# Subtest: strict rejection: nonfinite\nok 33 - strict rejection: nonfinite # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.088287\n  ...\n# Subtest: strict rejection: NaN\nok 34 - strict rejection: NaN # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.042087\n  ...\n# Subtest: strict rejection: bigint\nok 35 - strict rejection: bigint # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.039974\n  ...\n# Subtest: strict rejection: undefined\nok 36 - strict rejection: undefined # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.037652\n  ...\n# Subtest: strict rejection: cycle\nok 37 - strict rejection: cycle # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.03535\n  ...\n# Subtest: strict rejection: custom prototype\nok 38 - strict rejection: custom prototype # SKIP test name does not match pattern\n  ---\n  duration_ms: 2.376886\n  ...\n# Subtest: strict rejection: symbol field\nok 39 - strict rejection: symbol field # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.059165\n  ...\n# Subtest: strict rejection: nonenumerable field\nok 40 - strict rejection: nonenumerable field # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.036335\n  ...\n# Subtest: strict rejection: sparse array\nok 41 - strict rejection: sparse array # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033146\n  ...\n# Subtest: strict rejection: extended array\nok 42 - strict rejection: extended array # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.035124\n  ...\n# Subtest: strict rejection: unpaired surrogate\nok 43 - strict rejection: unpaired surrogate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.032325\n  ...\n# Subtest: strict rejection: bad ID\nok 44 - strict rejection: bad ID # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.096503\n  ...\n# Subtest: strict rejection: overlong ID\nok 45 - strict rejection: overlong ID # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.032767\n  ...\n# Subtest: strict rejection: duplicate records\nok 46 - strict rejection: duplicate records # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.030533\n  ...\n# Subtest: strict rejection: duplicate attempts\nok 47 - strict rejection: duplicate attempts # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.028843\n  ...\n# Subtest: strict rejection: duplicate evidence\nok 48 - strict rejection: duplicate evidence # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.029249\n  ...\n# Subtest: strict rejection: duplicate claims\nok 49 - strict rejection: duplicate claims # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033031\n  ...\n# Subtest: strict rejection: cross entity duplicate\nok 50 - strict rejection: cross entity duplicate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.032365\n  ...\n# Subtest: strict rejection: duplicate eligible IDs\nok 51 - strict rejection: duplicate eligible IDs # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031822\n  ...\n# Subtest: strict rejection: duplicate support IDs\nok 52 - strict rejection: duplicate support IDs # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.034254\n  ...\n# Subtest: strict rejection: outside eligible population\nok 53 - strict rejection: outside eligible population # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031195\n  ...\n# Subtest: strict rejection: unknown population denominator\nok 54 - strict rejection: unknown population denominator # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.032573\n  ...\n# Subtest: strict rejection: fabricated population source\nok 55 - strict rejection: fabricated population source # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033256\n  ...\n# Subtest: strict rejection: dangling attempt record\nok 56 - strict rejection: dangling attempt record # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031581\n  ...\n# Subtest: strict rejection: dangling evidence record\nok 57 - strict rejection: dangling evidence record # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.049503\n  ...\n# Subtest: strict rejection: dangling attempt\nok 58 - strict rejection: dangling attempt # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.034054\n  ...\n# Subtest: strict rejection: dangling support\nok 59 - strict rejection: dangling support\n  ---\n  duration_ms: 0.985948\n  ...\n# Subtest: strict rejection: dangling correction\nok 60 - strict rejection: dangling correction # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.045923\n  ...\n# Subtest: strict rejection: self correction\nok 61 - strict rejection: self correction # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033588\n  ...\n# Subtest: strict rejection: correction scope\nok 62 - strict rejection: correction scope # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.036058\n  ...\n# Subtest: strict rejection: attempt numbering gap\nok 63 - strict rejection: attempt numbering gap # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031945\n  ...\n# Subtest: strict rejection: retry without prior\nok 64 - strict rejection: retry without prior # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.029473\n  ...\n# Subtest: strict rejection: submission without evidence\nok 65 - strict rejection: submission without evidence # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.029352\n  ...\n# Subtest: strict rejection: denial with submitted value\nok 66 - strict rejection: denial with submitted value # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031326\n  ...\n# Subtest: strict rejection: attempt disposition mismatch\nok 67 - strict rejection: attempt disposition mismatch # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031671\n  ...\n# Subtest: strict rejection: unsupported action\nok 68 - strict rejection: unsupported action # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.032502\n  ...\n# Subtest: strict rejection: action record mismatch\nok 69 - strict rejection: action record mismatch # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.030256\n  ...\n# Subtest: strict rejection: zero units\nok 70 - strict rejection: zero units # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.029501\n  ...\n# Subtest: strict rejection: wrong evidence party\nok 71 - strict rejection: wrong evidence party # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.029075\n  ...\n# Subtest: strict rejection: empty acceptance digest\nok 72 - strict rejection: empty acceptance digest # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.028537\n  ...\n# Subtest: strict rejection: acceptance one party\nok 73 - strict rejection: acceptance one party # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.030654\n  ...\n# Subtest: strict rejection: unsupported schema\nok 74 - strict rejection: unsupported schema # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.029032\n  ...\n# Subtest: strict rejection: unsupported rule\nok 75 - strict rejection: unsupported rule\n  ---\n  duration_ms: 1.195274\n  ...\n# Subtest: strict rejection: removed required kind\nok 76 - strict rejection: removed required kind\n  ---\n  duration_ms: 0.598765\n  ...\n# Subtest: accessor input is rejected without invoking it\nok 77 - accessor input is rejected without invoking it # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.042338\n  ...\n# Subtest: correction fork is rejected\nok 78 - correction fork is rejected\n  ---\n  duration_ms: 0.836908\n  ...\n# Subtest: correction cycle is rejected\nok 79 - correction cycle is rejected\n  ---\n  duration_ms: 0.795318\n  ...\n# Subtest: denial cannot be erased by a retry\nok 80 - denial cannot be erased by a retry\n  ---\n  duration_ms: 1.454469\n  ...\n# Subtest: denial correction can be renewed while historical denial remains counted\nok 81 - denial correction can be renewed while historical denial remains counted\n  ---\n  duration_ms: 1.941864\n  ...\n# Subtest: strict text: duplicate keys\nok 82 - strict text: duplicate keys\n  ---\n  duration_ms: 0.395457\n  ...\n# Subtest: strict text: escaped duplicate keys\nok 83 - strict text: escaped duplicate keys # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.047443\n  ...\n# Subtest: strict text: decimal\nok 84 - strict text: decimal # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033149\n  ...\n# Subtest: strict text: exponent\nok 85 - strict text: exponent # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.032726\n  ...\n# Subtest: strict text: rounded decimal\nok 86 - strict text: rounded decimal # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.036519\n  ...\n# Subtest: strict text: unsafe integer\nok 87 - strict text: unsafe integer\n  ---\n  duration_ms: 0.113155\n  ...\n# Subtest: strict text: leading zero\nok 88 - strict text: leading zero # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.034875\n  ...\n# Subtest: strict text: negative zero\nok 89 - strict text: negative zero # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033125\n  ...\n# Subtest: strict text: trailing data\nok 90 - strict text: trailing data # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033018\n  ...\n# Subtest: strict text: prototype key\nok 91 - strict text: prototype key # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033237\n  ...\n# Subtest: strict text: constructor key\nok 92 - strict text: constructor key # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.030699\n  ...\n# Subtest: strict text: surrogate\nok 93 - strict text: surrogate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031465\n  ...\n# Subtest: strict text: unterminated string\nok 94 - strict text: unterminated string # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031204\n  ...\n# Subtest: strict text: trailing comma\nok 95 - strict text: trailing comma # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.035984\n  ...\n# Subtest: strict text: array trailing comma\nok 96 - strict text: array trailing comma # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.030238\n  ...\n# Subtest: strict text: byte bound\nok 97 - strict text: byte bound # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031246\n  ...\n# Subtest: strict text: depth bound\nok 98 - strict text: depth bound\n  ---\n  duration_ms: 0.112492\n  ...\n# Subtest: strict text: array bound\nok 99 - strict text: array bound # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.038763\n  ...\n# Subtest: canonical byte format and object ordering are explicit\nok 100 - canonical byte format and object ordering are explicit # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.056483\n  ...\n# Subtest: pure evaluation preserves caller objects and key order is irrelevant\nok 101 - pure evaluation preserves caller objects and key order is irrelevant\n  ---\n  duration_ms: 1.395149\n  ...\n# Subtest: portable SHA 256 matches native hashes at padding and bound edges\nok 102 - portable SHA 256 matches native hashes at padding and bound edges # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.046778\n  ...\n# Subtest: package adversary: embedded authorizing key\nok 103 - package adversary: embedded authorizing key\n  ---\n  duration_ms: 6.147255\n  ...\n# Subtest: package adversary: unknown key ID\nok 104 - package adversary: unknown key ID # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.057609\n  ...\n# Subtest: package adversary: wrong algorithm\nok 105 - package adversary: wrong algorithm\n  ---\n  duration_ms: 5.85318\n  ...\n# Subtest: package adversary: unknown token field\nok 106 - package adversary: unknown token field # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.05414\n  ...\n# Subtest: package adversary: token signer mismatch\nok 107 - package adversary: token signer mismatch # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.035622\n  ...\n# Subtest: package adversary: changed component\nok 108 - package adversary: changed component # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031308\n  ...\n# Subtest: package adversary: rehashed without signing\nok 109 - package adversary: rehashed without signing # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.040957\n  ...\n# Subtest: package adversary: changed signature\nok 110 - package adversary: changed signature\n  ---\n  duration_ms: 60.475483\n  ...\n# Subtest: package adversary: changed token signature under valid envelope\nok 111 - package adversary: changed token signature under valid envelope\n  ---\n  duration_ms: 17.624936\n  ...\n# Subtest: package adversary: signed false snapshot\nok 112 - package adversary: signed false snapshot\n  ---\n  duration_ms: 15.013232\n  ...\n# Subtest: package adversary: signed malformed case\nok 113 - package adversary: signed malformed case # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.10094\n  ...\n# Subtest: package adversary: bad token lifetime\nok 114 - package adversary: bad token lifetime # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.04096\n  ...\n# Subtest: package adversary: future case\nok 115 - package adversary: future case # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.034835\n  ...\n# Subtest: explicit trust policy: revoked key\nok 116 - explicit trust policy: revoked key\n  ---\n  duration_ms: 10.751069\n  ...\n# Subtest: explicit trust policy: expired key\nok 117 - explicit trust policy: expired key # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.097835\n  ...\n# Subtest: explicit trust policy: future key\nok 118 - explicit trust policy: future key # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.04009\n  ...\n# Subtest: explicit trust policy: no selected key\nok 119 - explicit trust policy: no selected key\n  ---\n  duration_ms: 3.991779\n  ...\n# Subtest: duplicate trust keys reject rather than selecting the first\nok 120 - duplicate trust keys reject rather than selecting the first # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.052406\n  ...\n# Subtest: a different caller selected public key cannot verify the signature\nok 121 - a different caller selected public key cannot verify the signature\n  ---\n  duration_ms: 4.651171\n  ...\n# Subtest: bundle input is copied before asynchronous verification\nok 122 - bundle input is copied before asynchronous verification # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.0804\n  ...\n# Subtest: gate binding: case ID\nok 123 - gate binding: case ID\n  ---\n  duration_ms: 8.949936\n  ...\n# Subtest: gate binding: revision\nok 124 - gate binding: revision # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.092329\n  ...\n# Subtest: gate binding: case digest\nok 125 - gate binding: case digest # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.037523\n  ...\n# Subtest: gate binding: rule digest\nok 126 - gate binding: rule digest\n  ---\n  duration_ms: 12.558844\n  ...\n# Subtest: gate binding: action digest\nok 127 - gate binding: action digest\n  ---\n  duration_ms: 8.370962\n  ...\n# Subtest: gate binding: future token\nok 128 - gate binding: future token # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.096596\n  ...\n# Subtest: gate binding: expired token\nok 129 - gate binding: expired token # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.038537\n  ...\n# Subtest: gate rejects an unsigned bypass request\nok 130 - gate rejects an unsigned bypass request\n  ---\n  duration_ms: 0.306307\n  ...\n# Subtest: gate rejects changed action payload\nok 131 - gate rejects changed action payload\n  ---\n  duration_ms: 4.625777\n  ...\n# Subtest: gate rejects a token not included in the exact package\nok 132 - gate rejects a token not included in the exact package\n  ---\n  duration_ms: 4.047579\n  ...\n# Subtest: nonce is consumed once and receipt follows effect\nok 133 - nonce is consumed once and receipt follows effect\n  ---\n  duration_ms: 7.444927\n  ...\n# Subtest: concurrent token uses cannot both record an effect\nok 134 - concurrent token uses cannot both record an effect\n  ---\n  duration_ms: 41.860802\n  ...\n# Subtest: snapshot and returned receipts cannot mutate gate state\nok 135 - snapshot and returned receipts cannot mutate gate state\n  ---\n  duration_ms: 5.011441\n  ...\n# Subtest: request action mutation while awaiting does not change the effect\nok 136 - request action mutation while awaiting does not change the effect\n  ---\n  duration_ms: 4.779933\n  ...\n# Subtest: selected revoked nonce blocks an otherwise verified package\nok 137 - selected revoked nonce blocks an otherwise verified package\n  ---\n  duration_ms: 3.831118\n  ...\n# Subtest: trust change during verification fails closed\nok 138 - trust change during verification fails closed\n  ---\n  duration_ms: 3.755902\n  ...\n# Subtest: trust updates do not reset used nonces\nok 139 - trust updates do not reset used nonces\n  ---\n  duration_ms: 7.748329\n  ...\n# Subtest: key expiration during crypto is checked at effect time\nok 140 - key expiration during crypto is checked at effect time\n  ---\n  duration_ms: 3.638774\n  ...\n# Subtest: token expiration during crypto is checked at effect time\nok 141 - token expiration during crypto is checked at effect time\n  ---\n  duration_ms: 4.506244\n  ...\n# Subtest: clock rollback is rejected\nok 142 - clock rollback is rejected\n  ---\n  duration_ms: 3.90502\n  ...\n# Subtest: new gate resets nonce memory, an explicit documented boundary\nok 143 - new gate resets nonce memory, an explicit documented boundary\n  ---\n  duration_ms: 15.700125\n  ...\n# Subtest: crypto unavailability fails closed\nok 144 - crypto unavailability fails closed\n  ---\n  duration_ms: 1.508788\n  ...\n# Subtest: offline archive manifest and expected negative fixture outcomes\nok 145 - offline archive manifest and expected negative fixture outcomes\n  ---\n  duration_ms: 38.242122\n  ...\n# Subtest: offline command needs explicit caller selected trust\nok 146 - offline command needs explicit caller selected trust\n  ---\n  duration_ms: 35.211104\n  ...\n# Subtest: offline command runs with restricted filesystem permission\nok 147 - offline command runs with restricted filesystem permission\n  ---\n  duration_ms: 126.617168\n  ...\n# Subtest: artifact boundary: traversal\nok 148 - artifact boundary: traversal\n  ---\n  duration_ms: 3.969003\n  ...\n# Subtest: artifact boundary: absolute\nok 149 - artifact boundary: absolute # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.073513\n  ...\n# Subtest: artifact boundary: backslash\nok 150 - artifact boundary: backslash # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.059788\n  ...\n# Subtest: artifact boundary: reserved basename\nok 151 - artifact boundary: reserved basename # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.040463\n  ...\n# Subtest: artifact boundary: duplicate\nok 152 - artifact boundary: duplicate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.038634\n  ...\n# Subtest: artifact boundary: casefold duplicate\nok 153 - artifact boundary: casefold duplicate # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.041586\n  ...\n# Subtest: artifact boundary: extra\nok 154 - artifact boundary: extra\n  ---\n  duration_ms: 3.463749\n  ...\n# Subtest: artifact boundary: hash\nok 155 - artifact boundary: hash\n  ---\n  duration_ms: 4.152918\n  ...\n# Subtest: artifact boundary: size\nok 156 - artifact boundary: size # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.054456\n  ...\n# Subtest: artifact boundary: self hash\nok 157 - artifact boundary: self hash # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.043678\n  ...\n# Subtest: artifact boundary: missing entry\nok 158 - artifact boundary: missing entry # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.494155\n  ...\n# Subtest: artifact boundary: unsafe excluded file\nok 159 - artifact boundary: unsafe excluded file # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.050168\n  ...\n# Subtest: artifact manifest rejects symlink additions\nok 160 - artifact manifest rejects symlink additions\n  ---\n  duration_ms: 4.826876\n  ...\n# Subtest: offline imports have no networking, process, or package dependency\nok 161 - offline imports have no networking, process, or package dependency\n  ---\n  duration_ms: 0.302624\n  ...\n# Subtest: schema structurally covers all supported fixtures, snapshots, and selected trust\nok 162 - schema structurally covers all supported fixtures, snapshots, and selected trust # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.049486\n  ...\n# Subtest: schema rejects unknown properties at every closed object\nok 163 - schema rejects unknown properties at every closed object # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.042529\n  ...\n# Subtest: schema projection cannot substitute for reference, integrity, or replay checks\nok 164 - schema projection cannot substitute for reference, integrity, or replay checks\n  ---\n  duration_ms: 5.49771\n  ...\n# Subtest: unknown trust fields fail shape and actual verifier\nok 165 - unknown trust fields fail shape and actual verifier # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.057473\n  ...\n# Subtest: expanded output cannot exceed canonical array bounds and still succeed\nok 166 - expanded output cannot exceed canonical array bounds and still succeed # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.038765\n  ...\n# Subtest: bounded local capacity rejects before recording an additional effect\nok 167 - bounded local capacity rejects before recording an additional effect # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.035008\n  ...\n# Subtest: trust report distinguishes valid verification at different selected times\nok 168 - trust report distinguishes valid verification at different selected times\n  ---\n  duration_ms: 14.049343\n  ...\n# Subtest: trust report retains the precise selected time at key validity boundaries\nok 169 - trust report retains the precise selected time at key validity boundaries\n  ---\n  duration_ms: 10.979949\n  ...\n# Subtest: trust report never represents an invalid policy time as evaluated\nok 170 - trust report never represents an invalid policy time as evaluated\n  ---\n  duration_ms: 1.69242\n  ...\n# Subtest: trust report preserves a validated policy time when the envelope or key is rejected\nok 171 - trust report preserves a validated policy time when the envelope or key is rejected # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.057806\n  ...\n# Subtest: trust report uses the captured time despite caller mutation during crypto\nok 172 - trust report uses the captured time despite caller mutation during crypto # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.055142\n  ...\n# Subtest: trust report and complete verification outputs match the structural schema\nok 173 - trust report and complete verification outputs match the structural schema # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.037317\n  ...\n# Subtest: verification epistemic status: unsupported bundle format\nok 174 - verification epistemic status: unsupported bundle format # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.036234\n  ...\n# Subtest: verification epistemic status: unsupported token format\nok 175 - verification epistemic status: unsupported token format # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.03518\n  ...\n# Subtest: verification epistemic status: unsupported signature algorithm\nok 176 - verification epistemic status: unsupported signature algorithm # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.034693\n  ...\n# Subtest: verification epistemic status: unsupported trust format\nok 177 - verification epistemic status: unsupported trust format # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.035895\n  ...\n# Subtest: verification epistemic status: unsupported key algorithm\nok 178 - verification epistemic status: unsupported key algorithm # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033679\n  ...\n# Subtest: verification epistemic status: unknown key does not claim signature failure\nok 179 - verification epistemic status: unknown key does not claim signature failure\n  ---\n  duration_ms: 2.89026\n  ...\n# Subtest: verification epistemic status: malformed envelope is not a failed crypto check\nok 180 - verification epistemic status: malformed envelope is not a failed crypto check\n  ---\n  duration_ms: 3.128111\n  ...\n# Subtest: verification epistemic status: a checked bad signature is explicitly invalid\nok 181 - verification epistemic status: a checked bad signature is explicitly invalid # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.054381\n  ...\n# Subtest: verification epistemic status: report version does not alter signed case snapshots\nok 182 - verification epistemic status: report version does not alter signed case snapshots\n  ---\n  duration_ms: 35.744796\n  ...\n# Subtest: verification epistemic status: missing runtime algorithm reports unavailable\nok 183 - verification epistemic status: missing runtime algorithm reports unavailable # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.110475\n  ...\n# Subtest: verification epistemic status: unusable crypto operation reports unavailable\nok 184 - verification epistemic status: unusable crypto operation reports unavailable # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.040297\n  ...\n# Subtest: verification combined failure: declared hash hash failure survives missing WebCrypto\nok 185 - verification combined failure: declared hash hash failure survives missing WebCrypto # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.03323\n  ...\n# Subtest: verification combined failure: case data hash failure survives missing WebCrypto\nok 186 - verification combined failure: case data hash failure survives missing WebCrypto # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031851\n  ...\n# Subtest: verification combined failure: snapshot hash failure survives missing WebCrypto\nok 187 - verification combined failure: snapshot hash failure survives missing WebCrypto # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.033576\n  ...\n# Subtest: verification combined failure: token hash failure survives missing WebCrypto\nok 188 - verification combined failure: token hash failure survives missing WebCrypto # SKIP test name does not match pattern\n  ---\n  duration_ms: 0.031703\n  ...\n# Subtest: verification combined failure: known hash failure prevents an unusable WebCrypto call\nok 189 - verification combined failure: known hash failure prevents an unusable WebCrypto call\n  ---\n  duration_ms: 2.623836\n  ...\n# Subtest: verification combined failure: native crypto failure cannot mask a known hash mismatch\nok 190 - verification combined failure: native crypto failure cannot mask a known hash mismatch\n  ---\n  duration_ms: 12.995264\n  ...\n# Subtest: verification combined failure: hash failure takes precedence over an unexamined bad signature\nok 191 - verification combined failure: hash failure takes precedence over an unexamined bad signature\n  ---\n  duration_ms: 2.472127\n  ...\n1..191\n# tests 191\n# suites 0\n# pass 72\n# fail 0\n# cancelled 0\n# skipped 119\n# todo 0\n# duration_ms 813.992872\n",
      "stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
      "stderr": "",
      "stderr_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "summary": {
        "tests": 191,
        "suites": 0,
        "pass": 72,
        "fail": 0,
        "cancelled": 0,
        "skipped": 119,
        "todo": 0
      }
    },
    "operation_results": [
      {
        "operation_id": "ec.inspect-requirements",
        "service_id": "evidence-contract",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-rule-1",
          "reference-encoding-v1"
        ],
        "scope": "requirements projection of one fixed local.release rule; no compiler or source access",
        "acceptance_scope": "Bounded analogue of required-evidence gaps only; not legal compliance or a passed EC production criterion.",
        "limitations": [
          "No authored applicability states, arbitrary obligation dependencies, ruleset retrieval, review workflow, or legal interpretation.",
          "requirements.status alone is not overall coverage, package integrity, or authorization."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 3,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "fixture missing: native and browser crypto parity, snapshot, gate",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "denial is not a missing evidence count or an inferred exception denominator",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "strict rejection: removed required kind",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "ec.evaluate-population",
        "service_id": "evidence-contract",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-rule-1"
        ],
        "scope": "coverage projection using supplied register fields, not independently verified population capture",
        "acceptance_scope": "Known/unknown register handling is bounded. AX-02 remains a target gap: the case requires at least one record and an empty known register cannot yield the architecture's valid empty-population result.",
        "limitations": [
          "independent.synthetic.input means a separate field, not an independent population authority.",
          "No source windows, exclusions, late cutoff, freeze/amendment workflow, or valid empty-scope reporting.",
          "Unknown applicability in EC-01 is a different target mechanism, not proved by unknown population handling."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 3,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "independent register with an unobserved record blocks without inventing attempts",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "unknown coverage has a null denominator and blocks",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "retry does not inflate eligible population or logical decision counts",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "cr.compare-logical-events",
        "service_id": "counterparty-reconciliation",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-rule-1"
        ],
        "scope": "one synthetic case comparison; not separate party record systems or durable ingress idempotency",
        "acceptance_scope": "Local deterministic analogues only. Intact conflicting synthetic packages do not demonstrate disagreement between independently authenticated parties.",
        "limitations": [
          "No independent per-party counts, tolerant matching, root-cause attribution, source authentication, or configurable precedence.",
          "No durable idempotency key, batch admission, source cursor, out-of-order ingestion, or multi-party matching service."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 5,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "retry does not inflate eligible population or logical decision counts",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "two current identical attestations are still ambiguous",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "current acceptance does not override conflict",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "fixture conflict: native and browser crypto parity, snapshot, gate",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "denial cannot be erased by a retry",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "cr.preserve-corrections",
        "service_id": "counterparty-reconciliation",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-rule-1"
        ],
        "scope": "validation and projection of supplied history, not an append-only storage or correction-authoring service",
        "acceptance_scope": "Bounded supplied-history analogue. Full SH-06 correction reason/author/authority and durable prior exports are not implemented.",
        "limitations": [
          "The reference evidence row has supersedes but no authenticated correction reason, author, or effective-time policy.",
          "No automatic new case creation, durable event log, late-data admission, or original-file retention service; those belong to cr.admit-observations."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 4,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "correction keeps history and changes exact acceptance digest",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "correction fork is rejected",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "correction cycle is rejected",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "denial correction can be renewed while historical denial remains counted",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "cr.bind-recorded-acceptance",
        "service_id": "counterparty-reconciliation",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-bundle-v1",
          "reference-encoding-v1"
        ],
        "scope": "binding only; authentication of the outer operator assertion requires separate verifyPackage checks",
        "acceptance_scope": "A current binding is not an accepted party decision. AX-04's non-independence boundary is applicable, but this reference has one joint assertion rather than even two synthetic party signatures.",
        "limitations": [
          "No separate party signature, actor identity, authority chain, tenant binding, decision scope, expiry, quorum, withdrawal, or escalation.",
          "A02 result-state boundary: no-check, unknown-key, or failed outer authentication must not display authenticated acceptance. This inventory does not certify the UI adapter repair or its tests.",
          "A valid outer package establishes only synthetic operator-recorded acceptance, never independent party consent."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 4,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "stale acceptance retains its decision but never authorizes",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "same revision with different claim text invalidates acceptance",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "revision alone invalidates acceptance",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "explicit acceptance denial blocks complete evidence",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "de.inspect-structural-support",
        "service_id": "decision-evidence",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-rule-1"
        ],
        "scope": "small structural reference projection only; no general typed transformation graph or semantic evaluator",
        "acceptance_scope": "Structural-only analogue. DE-02 general typed graph cycle handling and exact edge contracts remain target requirements.",
        "limitations": [
          "No per-node content commitments, closed transformation-edge vocabulary, source-region selectors, semantic entailment, causal assessment, or model identity.",
          "Correction-chain order rejection is not general graph-cycle detection; source permissions are not enforced by a synthetic evidence label."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 5,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "structural links do not judge semantic truth",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "empty support remains unresolved even when evidence is complete",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "superseded support does not remain current",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "strict rejection: dangling support",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "correction cycle is rejected",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "de.replay-fixed-rule",
        "service_id": "decision-evidence",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-rule-1",
          "reference-bundle-v1",
          "reference-encoding-v1",
          "reference-verification-v2"
        ],
        "scope": "whole-case fixed calculation replay; the native signature path shares the same evaluator",
        "acceptance_scope": "Reproduction of one supplied rule, not independent implementation, general pipeline reexecution, or proof that all affected results were found.",
        "limitations": [
          "No arbitrary executable rule runner, sandboxed transformations, incremental cache, affected-node set, or isolated counterfactual branch.",
          "An altered claim changes its digest/binding but need not change every calculated field. Semantic truth and correctness of local.release remain outside scope."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 5,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "pure evaluation preserves caller objects and key order is irrelevant",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "package adversary: signed false snapshot",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "same revision with different claim text invalidates acceptance",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "fixture correction: native and browser crypto parity, snapshot, gate",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "strict rejection: unsupported rule",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "ab.check-local-admission",
        "service_id": "action-boundary",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-case-v1",
          "reference-rule-1",
          "reference-bundle-v1",
          "reference-token-v1",
          "reference-trust-v1"
        ],
        "scope": "checks are inside execute, not a separate production authorization API; only local.record.release",
        "acceptance_scope": "AB-01 local payload analogue only. AX-08 changed destination remains target: the current action has no external destination field.",
        "limitations": [
          "No tenant, executor audience, remote destination/resource, real delegation chain, or production permission model.",
          "evaluateCase.gate.eligible alone authorizes nothing; even a ready pure evaluation requires successful package/trust/token and commit-time checks.",
          "No general bearer authorization is obtained from a canonical authorization.decision or imprimatur.clearance link."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 6,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "gate rejects an unsigned bypass request",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "gate rejects changed action payload",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "gate rejects a token not included in the exact package",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "gate binding: case ID",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "gate binding: rule digest",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "gate binding: action digest",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "ab.recheck-local-trust",
        "service_id": "action-boundary",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-token-v1",
          "reference-trust-v1",
          "reference-bundle-v1"
        ],
        "scope": "caller-owned clock and policy within one gate instance; no external trust authority",
        "acceptance_scope": "Local analogue of a commit-time trust fence, not current real authority revocation or a qualified external fence.",
        "limitations": [
          "Trust and time are caller-configured demonstration inputs; no authenticated clock, freshness contract, delivered revocation evidence, or real delegated authority.",
          "Policy updates within one process are not distributed policy-epoch synchronization or an operational revocation service."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 7,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "trust change during verification fails closed",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "trust updates do not reset used nonces",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "key expiration during crypto is checked at effect time",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "token expiration during crypto is checked at effect time",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "clock rollback is rejected",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "selected revoked nonce blocks an otherwise verified package",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "request action mutation while awaiting does not change the effect",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "ab.consume-local-effect",
        "service_id": "action-boundary",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-token-v1",
          "reference-receipt-v1",
          "reference-trust-v1"
        ],
        "scope": "one in-memory event store with effect-before-receipt ordering; no callbacks, external effects, or durable state",
        "acceptance_scope": "AB-02 is bounded to one live instance. AX-11 is explicitly unmet by this mechanism; its test demonstrates that a new instance loses replay memory.",
        "limitations": [
          "Nonce history and observations are volatile and not shared across instances or processes.",
          "Local receipts are unsigned; digest and order do not prove any external action happened.",
          "No external endpoint, durable reservation, recovery state, distributed transaction, or global exactly-once guarantee."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 4,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "nonce is consumed once and receipt follows effect",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "concurrent token uses cannot both record an effect",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "snapshot and returned receipts cannot mutate gate state",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "new gate resets nonce memory, an explicit documented boundary",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "pt.verify-reference-package",
        "service_id": "portable-trust",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-encoding-v1",
          "reference-bundle-v1",
          "reference-token-v1",
          "reference-trust-v1",
          "reference-verification-v2"
        ],
        "scope": "WebCrypto or native Node signature path for hive.reference.* only; Node path shares reference validation/evaluation",
        "acceptance_scope": "Reference parsing/integrity/replay and report-v2 state mechanics only. PT-03 has a bounded unsupported-algorithm analogue; no passing run or UI acceptance is claimed by this inventory.",
        "limitations": [
          "Ed25519 only; no generic canonical envelope routing, full typed constituent checks, multi-algorithm agility, or accredited validation.",
          "Inspected report-v2 code distinguishes unsupported, not_checked and unavailable from actual failed checks. Known hash mismatch remains invalid without an unperformed signature claim. This describes the A05 code repair and test definitions, not certification of its runtime or outward UI behavior.",
          "Structural JSON Schema is a projection, not authorization; object input cannot recover duplicate keys erased by a prior ordinary parser."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 15,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "strict text: duplicate keys",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "strict text: unsafe integer",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "strict text: depth bound",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "package adversary: changed signature",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "package adversary: changed token signature under valid envelope",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "package adversary: signed false snapshot",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "package adversary: wrong algorithm",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "crypto unavailability fails closed",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "schema projection cannot substitute for reference, integrity, or replay checks",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "verification epistemic status: unknown key does not claim signature failure",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "verification epistemic status: malformed envelope is not a failed crypto check",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "verification epistemic status: report version does not alter signed case snapshots",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "verification combined failure: known hash failure prevents an unusable WebCrypto call",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "verification combined failure: native crypto failure cannot mask a known hash mismatch",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "verification combined failure: hash failure takes precedence over an unexamined bad signature",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "pt.evaluate-demo-trust",
        "service_id": "portable-trust",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-trust-v1",
          "reference-bundle-v1",
          "reference-verification-v2"
        ],
        "scope": "policy evaluation of supplied demonstration facts, not real issuer enrollment or independently attested time",
        "acceptance_scope": "Bounded as-of reporting and caller choice. Current-trust freshness, real independent trust bootstrap, key epochs, and rotation remain target work.",
        "limitations": [
          "A separately downloaded copy of the same demo trust file is not independent authority or proof of external signer identity.",
          "No authenticated snapshot timestamp, current revocation distribution, accepted chronology, key-epoch migration, real purpose/tenant authority, or separate historical/current/integrity-only modes.",
          "No fingerprint alias/organization relationship assessment; multiple key IDs or keys alone cannot establish independence."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 7,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "package adversary: embedded authorizing key",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "explicit trust policy: no selected key",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "a different caller selected public key cannot verify the signature",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "explicit trust policy: revoked key",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "trust report distinguishes valid verification at different selected times",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "trust report retains the precise selected time at key validity boundaries",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "trust report never represents an invalid policy time as evaluated",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      },
      {
        "operation_id": "pt.check-retained-archive",
        "service_id": "portable-trust",
        "status": "passed_bounded_reference",
        "profile_refs": [
          "reference-artifacts-v1",
          "reference-bundle-v1",
          "reference-trust-v1",
          "reference-encoding-v1",
          "reference-verification-v2"
        ],
        "scope": "existing all-scenarios offline_bundle and explicitly supplied trust path; no network request or local gate effect",
        "acceptance_scope": "Existing local package/checker analogue only. CLI success means expected positive and negative fixture outcomes matched, not that every package passed.",
        "limitations": [
          "Node 20.20 or newer is required by the guide. Trusted checker acquisition, fresh extraction, runtime compatibility, and recipient challenge must be separately evidenced.",
          "The manifest cannot authenticate itself or its checker; a detached archive checksum provides byte identity, not authority. Hostile writable-directory replacement races remain outside scope.",
          "This operation covers the static all-scenarios package and checker, not an asserted test of the browser's separate selected-snapshot ZIP generator.",
          "No arbitrary package dependency closure, signed release admission, private-source disclosure enforcement, or independent evaluator implementation."
        ],
        "run_stdout_sha256": "c985090c75afd8e4dc2934cb61dde3eda8c81ad459493ac3db954ffa0a322949",
        "procedure": "Exact-name selection from ./reference/tests.mjs; shared run, not independent runs.",
        "expected": "All assertions in the exact cited test definition pass.",
        "actual": "All listed selectors executed and passed in the retained Node TAP run.",
        "passed": 8,
        "failed": 0,
        "skipped": 0,
        "results": [
          {
            "selector": "offline archive manifest and expected negative fixture outcomes",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "offline command needs explicit caller selected trust",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "offline command runs with restricted filesystem permission",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "artifact boundary: traversal",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "artifact boundary: extra",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "artifact boundary: hash",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "artifact manifest rejects symlink additions",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          },
          {
            "selector": "offline imports have no networking, process, or package dependency",
            "expected": "All assertions in the exact cited test definition pass.",
            "actual": "passed",
            "passed": 1,
            "failed": 0
          }
        ]
      }
    ]
  },
  "evidence_identity": {
    "engine_test_output_sha256": "3f9202acf029b91c62f6d0221566c37b622771253601dc5c53dc3bca0071164d",
    "independent_audit_output_sha256": "77c7e112ff9b79b7159320344e94f17eb8c5bb425fb0a605a0b38134c3e167ea",
    "browser_output_sha256": "3e37386f9f192aa3e2f3e5b6212045f9400c459eebb561a72ed834edd770c45b"
  },
  "approval": {
    "owner": "Hive reference release owner",
    "decision": "approve_bounded_reference_only",
    "observed_at": "2026-09-12T21:32:31.108565+00:00",
    "review_trigger": "Any change to a required source, fixture, trust policy, operation selector, environment, or limitation requires a new run and review."
  },
  "limits": [
    "Synthetic operator-recorded acceptance is not independent party consent.",
    "The local effect store is not durable and controls no external service.",
    "All 15 specified target operations remain unimplemented by this reference; no AX target gate is passed here.",
    "Runtime tests do not establish regulatory compliance, production capacity, availability, or cost.",
    "The reference is not a security certification or an independent issuer trust arrangement.",
    "Scoped TAP is unsigned release-builder evidence, not an authenticated independent attestation.",
    "76 operation-to-selector mappings share 72 actual test executions; overlapping selectors are not independent tests."
  ]
}
