Raw view — CANONICALIZATION-V2-ERRATUM-1@v1

sha256: 1327499b671202c1cf6860f72f78f0302321a839cd8b1488a594c92ea4195976

Published law page — ← laws index — raw .md

# CANONICALIZATION-V2-ERRATUM-1 — v1

Word Of Clout, LLC · additive at /laws/canonicalization-v2-erratum-1.md; no published law byte changes — a published law is immutable, and this erratum adds without altering. The v2 text at /laws/canonicalization-v2.md is untouched by this erratum.

## What this erratum corrects

CANONICALIZATION-LAW-1@v2, section "The limit, stated plainly" (the sentence: "the signature covers the fields named in step 1; the `derivation` block is deliberately excluded from signing (its content is bound instead through the signed `dependency_manifest_sha256`)"), reads as though the derivation block's *content* is bound by the signature. It is not. A digest binds exactly the bytes it is computed over — and `dependency_manifest_sha256` is computed over the `dependency_manifest` object alone. The v2 bytes stay as published; this erratum states the corrected limit.

## The Rule

### 1. A digest binds what it is computed over — no more

`dependency_manifest_sha256` is the SHA-256 of the canonical form of the `dependency_manifest` object. It therefore binds **exactly what that object enumerates** — every key and value of the manifest, no more. Any artifact, content, or file **not enumerated in the manifest** is **not bound** by the signature, whatever any sentence in any document says.

### 2. What a manifest may enumerate

A `dependency_manifest` may enumerate artifacts (name, sha256, bytes, citation), declared figures (counts, bounds, cutoffs), and inventories (per-file hashes and row counts for a set of published files). Whatever it enumerates is signed. Whatever it omits is unsigned — and no prose elsewhere in a record, page, or receipt can make an omitted artifact bound.

### 3. Content bindings require an inventory in the signed scope

A claim that a record binds a set of published files (an extract package, a runner, a ledger) requires an explicit inventory inside the canonical form — the manifest entries for those files: their paths, byte hashes, and (for line-oriented files) row counts, plus any expected outcome counts a verifier depends on. A signature over prose that *describes* a binding does not perform the binding.

## What this erratum never changes

No published record's signature, no published record's bytes, no published law byte, and no verdict. Records whose manifests enumerate less than a reader might assume remain exactly as published; this erratum changes what the *law claims*, to match what a hash can prove.