# Word Of Clout — ASTRA-R5 Public Artifact Set

## Reproduction and signature state — READ FIRST (PARITY-DISAGREEMENT-1 / FINDINGS-UNSIGNED-1, Tani 2026-09-15T02:51Z)

**The parity rule a reviewer applies (REPRO-PARITY-1):** regenerate through
`engagement-corpora/engagement-findings.mjs --eval-at <the shipped findings'
OWN eval_at>` and deep-compare BOTH `findings.json` AND `closure-receipts.json`
against the shipped bytes. The ONLY excluded leaves are the OBSERVED volatile
set (cited by strict zero-exclusion diff, 2026-09-15T02:52Z):

- `findings.json → ran_at.started_at`, `ran_at.finished_at` — the generation
  run's wall-clock window (when the run happened, never what it found);
- `closure-receipts.json → receipts[*].issued_at` — each receipt's wall-clock
  issue stamp (set at the run's finish);
- `signature` (top level of either bundle) — freeze-time signing, below.

Every other leaf — nested `ran_at`/`signature` keys included — must be
identical, or the package does not ship (package-check leg [13] enforces
exactly this rule; package-check leg [5] verifies any present signature).

**Signature state (FINDINGS-UNSIGNED-1, ruled by Tani 2026-09-15T02:51Z):**
the engagement artifacts `findings.json` and `closure-receipts.json` are
SIGNED AT FREEZE by `r5-freeze-phase2` with the root-held engagement key
(outside the tree; a separate class from int1 — separate key, separate
store), and the signatures are bound in the delivery manifest and checked
by the verifier. `"signature": null` is the PRE-SIGNING state —
complete-except-signing, awaiting the freeze — and a null signature in the
signed package is a defect. The engagement public key ships inside
`findings.json` (`trust.public_key`); no .pem file exists under public/
(KEY-IN-TREE-1).

**What this supersedes (opens the package, per the overnight order):** this
package supersedes `/verify/astra-r4/` — FROZEN HISTORY, byte-identical as
Astra fetched and cited it (delivery manifest file-sha256
`1ca88ceb6d1630f916f4228009e499fd6f6ab09353d453f5e1bfe129846d836e`,
frozen_at `2026-09-14T03:53:24.186Z`, commit `3522d9d3`, 20/20 sums,
delivery exit 0). The r4 bytes are never mutated; every r4 reproduction
keeps running against the r4 tree. This r5 tree carries the corrections.

**What changed from r4, by R5 item (Tani 2026-09-14T06:44Z ruling):**
- **R5-1 ADJUDICATION-2 (law v3→v4):** the identity-binding rule — a
  proposition whose subject is bound to another identity ticket is BLOCKED
  from independent adjudication, and the binding is disclosed per row
  (`binding_blocked_by_row`).
- **R5-2 OWNERSHIP-1:** closure receipts assign ownership after
  adjudication; a receipt can never route a WoC defect to the buyer or the
  board.
- **R5-7 EXTRACT-1:** ROW-034/ROW-048 — the suspect `MO` state values were
  OUR parser's, never the board's; both rows' address propositions are
  UNVERIFIABLE pending the parser fix, with the RAW source reading cited by
  line.
- **R5-8 MOCK-2:** the synthetic demonstration rebuilt as one labeled defect
  per row on an otherwise valid fixture baseline
  (`fixture-authorities.json`); the property stated exactly: *none of the
  labeled bad fields was VERIFIED* — never a mechanisms count.
- **R5-9 VERIFIER-R5:** the verifier reworked per the reviewer's R01–R07 —
  strict parser, default-mode RECORD-RELATIVE currentness with expiry
  enforcement (the explicit `--current`/`--mode current` flag names the
  checkpoint-bound contract and REQUIRES `--delivery-manifest` — DOC-MODE-1,
  Tani 2026-09-14T20:35Z), `--predicate`
  exact selector, temporal policy (future evidence rejected for as-of
  reliance), no-registry delivery refused, `--signature-only` conflicts with
  explicit modes. The R01–R07 vectors are in the 40-leg regression suite.
- **R5-6 SOURCE-REPRO-1:** `engagement-corpora/` ships the frozen extracts
  and the transformation machinery — a buyer re-derives any finding without
  accepting our extraction as authority.
- **R5-10 COVER-GEN-1:** `engagement-mock/REVIEW-COVER.md` is GENERATED
  from the artifacts by the package check — never hand-typed.

Contents: the corrected verifier machinery, the conformance fixture, the
trust stores, the canonicalization recipe v1.1, the frozen hash-chained
export, the LIVE successor record (mo-dental-013494@3), the complete
engagement package under `engagement-mock/` with its re-derivable corpora
under `engagement-corpora/`. Host operator steps live in the repo, not in
this package. **Signing state:** the package is complete EXCEPT
`delivery.manifest.json`, `SHA256SUMS`, and the record `.sig` — those are
created at the r5 freeze (int1 signing is the operator's act, not a package
act).

- **Requirements — standalone VERIFIER (`verifier.mjs`):** Node.js ≥ 20. No network. No dependencies — all verification is in-process pure Node (`node:crypto` hashing, no shell-outs).
- **Requirements — engagement package CHECK (`engagement-package-check.mjs`):** Node.js ≥ 20, plus the system binaries it shells out to, each declared with its purpose under TOOL-DEPENDENCY-1 (Tani 2026-09-16T06:32Z) and asserted by a preflight before any leg runs: `sha256sum` (required — legs [9]/[10] verify the signed and frozen package sums through the same binary a buyer runs) and `git` (optional, guarded — absent falls back to build-info, never a failure). No `jq`: the outside-reader probe is pure Node since TOOL-DEPENDENCY-1 — it asserts a reader reaches the documented values by ordinary JSON path traversal, not that the jq binary specifically works.
- **DEPENDENCY-TRUTH-1 — check against your machine before running anything:**
  - verifier (`verifier.mjs`): Node.js ≥ 20 — nothing else.
  - package check (`engagement-package-check.mjs`): Node.js ≥ 20 plus `sha256sum` — preflighted by name as the first line of output if absent.
- **Verdicts at delivery:** verifier suite 40/40 green (R01–R07 in the
  set); engagement package check PASS.

## Record history and currentness — the @2 consequence, STATED (Tani 2026-09-14T19:00Z)

The superseded production record `record-mo-dental-013494@2` (the r3
package) carries its dependency manifest stored under the pre-I16 recipe;
from R6-5 (VERIFIER-HARDEN-2, Astra R5 static review) dependency-manifest
consistency is BLOCKING in every mode labeled current. Therefore, with THIS
verifier:

- `@2` **refuses default-current: exit 1** (RECORD INTERNAL DIGEST MISMATCH) —
  the record's signed internal digest does not re-derive under the canonical
  recipe, and a current-reliance claim may not stand on it.
- `@2` **verifies only in explicit historical mode: exit 0, labeled
  HISTORICAL** — signed history stays inspectable; the labeled note names the
  manifest mismatch and states that no current-reliance claim is made.
- The current record `@3` (this package) re-derives and verifies in every
  mode.
- The r3 and r4 packages remain **byte-identical and served** as FROZEN
  HISTORY — every r3/r4 reproduction keeps running against their own trees.

That distinction is the product: **old evidence stays inspectable, never
currently reliable.** Nothing here was discovered by a reviewer — it is
the ruled, tested behavior (pinned in `scripts/astra-r5-verifier.r6.test.ts`).

## Exit-code contract (one table, every mode, no two failures render alike)

| exit | meaning |
|---|---|
| 0 | verified + recognized + eligible (and in current mode: in scope, deadlines live, checkpoint-bound) |
| 1 | signature fails (record OR delivery manifest; includes own-`__proto__` smuggle and internal digest mismatch in current mode) |
| 2 | usage (unknown flag, duplicate flag, conflicting modes, bad `--at`) |
| 3 | issuer/signer not in the trust store — or no `--well-known` supplied: a verifying signature alone is NOT authorization, for records AND delivery manifests |
| 4 | recognized but ineligible (revoked / not yet valid / clock before validity) |
| 5 | STALE — an in-scope proposition's `next_required_by` is past the evaluation time |
| 6 | SCOPE MISMATCH — record ≠ requested subject/proposition/predicate |
| 7 | DELIVERY/CHECKPOINT/TEMPORAL FAILURE — manifest signature/binding/coverage/chain broken; record not bound; or evidence issued after `--at` |

## Modes (VERIFIER-R5: one strict parser)

- **Default record verification (`--record` with NO mode flag) is RECORD-RELATIVE currentness**: expiry, temporal policy, and scope are enforced against the record itself, with NO checkpoint — success is labeled "current (default mode)" and never presented as checkpoint-bound.
- **`--mode current`** (or `--current`) is the STRICTER, CHECKPOINT-BOUND mode: it **REQUIRES `--delivery-manifest`** — the signed checkpoint that binds the record — and **exits 7 ("CURRENT MODE REQUIRES A TRUSTED CHECKPOINT")** without it. The checkpoint is evaluated BEFORE scope, so a scoped request in current mode without a manifest exits 7, not 6 — by design, not by defect.
- **One sentence, so no reviewer files what we already know:** currentness is the default NATURE of bare record verification (expiry enforced, record-relative, no checkpoint claimed), while the explicit `--current`/`--mode current` FLAG names the checkpoint-bound reliance contract, which cannot run without the signed delivery manifest.
- **`--mode historical`**: explicit, labeled HISTORICAL — integrity at the
  stated evaluation time only; no current-reliance claim. Historical
  success must be explicit; it is never a silent default.
- **`--signature-only`**: cryptographic-only check, labeled as NOT
  authorization; conflicts with any explicit mode (usage error).
- **Strict parser**: unknown flags, duplicate flags, and
  `--current`+`--mode` together are usage errors. `--predicate` is an exact
  scope selector (a mismatching predicate exits 6, never 0);
  `--proposition` selects by id/text; the two are mutually exclusive.
- **Temporal policy**: in current mode, evidence issued after the `--at`
  evaluation time is rejected (exit 7) — record `issued_at`, in-scope
  proposition `verified_at`, and checkpoint `frozen_at` must not postdate
  `--at`. Inability to discover a newer head offline never accepts a future
  one.

## Quick start — the first command a stranger runs

After the r5 freeze signs this package (record `.sig` + manifest), the
quick start is the live record end-to-end:

```
node verifier.mjs --record record-mo-dental-013494@3.json \
                  --sig record-mo-dental-013494@3.sig \
                  --well-known issuer-trust.json
# → CURRENT (default mode) — VERIFIED + RECOGNIZED + ELIGIBLE — exit 0
#    (record-relative currentness: no checkpoint supplied, none claimed)
```

Until the freeze, the same command runs against the r4 package bytes
(FROZEN history, unchanged) or the conformance fixture
(`fixture.json` — invented subject, invented values; never a customer).

## Commands

```
# default record verification — RECORD-RELATIVE currentness (deadlines
# enforced, scope enforced, NO checkpoint required):
node verifier.mjs --record record-mo-dental-013494@3.json \
                  --sig record-mo-dental-013494@3.sig --well-known issuer-trust.json

# checkpoint-bound current reliance (--mode current REQUIRES --delivery-manifest):
node verifier.mjs --mode current --record record-mo-dental-013494@3.json \
                  --sig record-mo-dental-013494@3.sig \
                  --subject 'Missouri dental practitioner — board license 013494' \
                  --delivery-manifest delivery.manifest.json \
                  --well-known issuer-trust.json
# wrong subject → 6 · deadline past at --at → 5 · future evidence at --at → 7
# --mode current WITHOUT --delivery-manifest → 7 (CURRENT MODE REQUIRES A
# TRUSTED CHECKPOINT — the checkpoint is evaluated before scope)

# the SCOPE-BIND-1 vector (Astra R5 static review R6-1), copy-pasteable —
# it runs in DEFAULT mode (no checkpoint needed) and MUST return 6:
node verifier.mjs --record record-mo-dental-013494@3.json \
                  --sig record-mo-dental-013494@3.sig \
                  --well-known issuer-trust.json \
                  --subject 'Missouri dental practitioner — board license 013494' \
                  --predicate practice_location
# → exit 6 — SCOPE MISMATCH (SCOPE-BIND-1):
#   "SCOPE MISMATCH (SCOPE-BIND-1) — the proposition(s) matching this request
#    describe npi:1467459891, which the record binds to the requested subject
#    only through candidate relation(s)
#    crosswalk:mo-dental-013494@3:npi-1467459891 (UNRATIFIED): an UNRATIFIED
#    candidate relation can never satisfy scope (CROSSWALK-BLIND-1 closed at
#    the consumer boundary)"

# historical integrity, explicit and labeled:
node verifier.mjs --mode historical --record record-mo-dental-013494@3.json \
                  --sig record-mo-dental-013494@3.sig --well-known issuer-trust.json

# delivery verification (the signed manifest binds every package file):
node verifier.mjs --delivery-manifest delivery.manifest.json --well-known issuer-trust.json
# no --well-known → exit 3 (a self-consistent or attacker-signed manifest is
# not authorization); --signature-only is the explicit cryptographic exception

# tamper with ANY bound file → exit 7, the file named
```

## Files

| file | what it is |
|---|---|
| `README.md` | this file (opens with what it supersedes and what changed) |
| `verifier.mjs` | the r5 standalone verifier (VERIFIER-R5 strict parser) |
| `fixture.json` / `fixture.sig` | synthetic conformance record (invented subject, invented values; never a customer), fixture-key signed |
| `issuer-trust.json` | trust stores as enforced live: PRODUCTION = int1 only; FIXTURE separate and labeled |
| `canonicalization.md` | recipe v1.1 (the I16-corrected dependency-manifest digest + the null-proto law) |
| `export.jsonl` | frozen hash-chained export (the r5 freeze appends the r5 line) |
| `record-mo-dental-013494@3.json` | the LIVE successor record (`.sig` created at the freeze) |
| `delivery.manifest.json` | the int1-SIGNED delivery manifest binding every package file — CREATED AT THE R5 FREEZE |
| `SHA256SUMS` | regenerated at the freeze (unsigned convenience metadata) |
| `engagement-mock/` | the complete engagement package: findings, closure receipts, the published comparison laws (v1→v6), the labor ledger, the follow-up cycle receipt, and the GENERATED REVIEW-COVER.md |
| `engagement-corpora/` | the frozen extracts (parsed board canonical, NPPES pool, raw DEN.TXT + fetch record) and the transformation machinery — a buyer re-derives any finding without accepting our extraction as authority |
| `engagement-corpora/engagement-findings.mjs` | the shipped adjudication generator (byte-identical to the repo copy; REPRO-PATH-1) — one package-relative command reproduces the package from manifest-listed inputs |
| `engagement-corpora/engagement-package-check.mjs` | the shipped package self-check + cover generator (byte-identical to the repo copy; REPRO-PATH-1) — the cover generator is listed in the package and named package-relative |
| `fixture-authorities.json` (in `engagement-mock/`) | the SYNTHETIC FIXTURE AUTHORITY corpus for MOCK-2 — never the pinned real corpora |

## Reproduce the engagement package (REPRO-PATH-1)

One package-relative command, fixed inputs, output OUTSIDE the frozen
delivery (the copy is not the frozen delivery) — the falsifier for the repro
path, as ruled:

```
cp -r . /tmp/r6-repro && cd /tmp/r6-repro
node engagement-corpora/engagement-findings.mjs --out engagement-mock/findings
```

**The parity rule for the reproduction (PARITY-DISAGREEMENT-1, Tani
2026-09-15T03:17Z):** a NAIVE deep-compare of the reproduced bundles against
the shipped bytes returns FALSE — regeneration is content-identical only
after excluding the OBSERVED volatile set: `findings.json → ran_at.started_at`,
`ran_at.finished_at`, and `signature`; `closure-receipts.json → signature` and
`receipts[*].issued_at` — the wall-clock of the reproducing run and the
signature that covers it. Every other leaf must be identical or the package
does not ship (package-check leg [13] prints this exclusion set verbatim in
its output). A reviewer running a bare deep-compare and getting FALSE should
read this line before filing it.

The shipped machinery resolves the corpora and the frozen inputs beside
itself; the clean copy alone — manifest-listed inputs only — reproduces any
selected finding and its absence lookup: no private files, no repo, no
network.

## The negative cases — TRUE labels

| # | true shape | result |
|---|---|---|
| NEG-6 | **Tampering** — an edited interior line breaks the whole-file digest and the `prev_sha256` chain | rejected |
| NEG-7 | **Key status** — revoked / future `valid_from` / clock before validity | exit 4 |
| NEG-8 | **Unknown-key recognition refusal** | exit 3 |
| NEG-9 | **Intact older-bundle replay at current mode** — deadlines past at the evaluation time. Bounded honestly: offline currentness is relative to the supplied authenticated checkpoint; this CLI cannot discover an unseen newer head | exit 5 |
| NEG-10 | **Deadline expiry at current mode** — evaluation time past an in-scope `next_required_by` (the license-expiry cap binds: it is inside the signed data) | exit 5 |
| NEG-11 | **Wrong-scope request** — an intact, valid receipt for subject A presented against a request for B | exit 6 |
| R01–R07 | **The independent reviewer's vectors** — default-after-expiry, ignored `--mode`/`--predicate`, no-registry delivery, future evidence at `--at`, conflicting signature-only, attacker-signed manifest | 5 · 6 · 3 · 7 · 2 · 3, all in the regression set |

All shapes run in the committed regression suite through this exact CLI
(`scripts/astra-r5-verifier.test.ts`, 40 legs).
