Skip to content

Extend proof-claim contract with CHRONOS carrier fields (additive superset) - #17

Merged
mdheller merged 2 commits into
mainfrom
feat/chronos-carrier-superset
Aug 2, 2026
Merged

mdheller merged 2 commits into
mainfrom
feat/chronos-carrier-superset

Conversation

@mdheller

@mdheller mdheller commented Aug 2, 2026

Copy link
Copy Markdown
Member

Summary

Closes/addresses #16. Extends holmes's existing TruthBounds/ReasoningTrace/ExplanationTrace proof-claim contract to be additionally expressible as a CHRONOS carrier (per sociosphere/docs/integration/neurosymbolic-chronos-alignment.md), per Michael's instruction to always take the superset and meld capabilities in rather than fork or replace.

This is purely additive. No existing field, JSON shape, contract invariant, or reasoning/inference logic is touched. Every artifact this repo already produces remains valid as-is; it can now also declare itself a CHRONOS carrier.

What changed

  • docs/PROOF_CLAIM_CONTRACT.md — new "CHRONOS carrier alignment" section: maps the doctrine's 10 required carrier fields onto Holmes's existing vocabulary (evidenceRefs, traceId, verificationStatus, admissionStatus, etc.) and the two genuinely-new fields.
  • examples/holmes-proof-claim-contract.json — both worked examples now carry:
    • reasoningTrace[].methodFamily = "LNN-style truth-bound propagation" (matches the doctrine's method-family row name exactly).
    • reasoningTrace[].nonAuthorityDeclaration — consistencyScope: "formula_local", doesNotAuthorize: [global_consistency, arbitrary_entailment_correctness, ...], and a human-readable statement — making the doctrine's forbidden-use rule ("never claim global consistency from a bounded local result") explicit as data.
    • a package-level chronosCarrier block filling the remaining carrier fields (sourceEvidenceRef, methodOutputType, groundingStatus, validationStatus, explanationTraceRef, owningAuthorityPlane, replayRef, governanceDecision), reusing existing values by reference rather than duplicating them.
  • tools/validate_holmes.py — enforces all of the above: methodFamily must be allow-listed, consistencyScope is rejected if "global", doesNotAuthorize must include the required forbidden claims, chronosCarrier must be complete and owningAuthorityPlane must always be SocioProphet/policy-fabric (Holmes never declares itself the owning authority plane).
  • fixtures/invalid/proof-claim-forbidden-global-consistency-claim.json — new negative fixture: a TruthBounds result whose nonAuthorityDeclaration.consistencyScope is "global", i.e. promoted as if it proved the whole system consistent. Validator rejects it.
  • repo.maturity.yaml / tools/validate_maturity.py — fixture-count references bumped 4 -> 5.

Verification against issue #16

Re-checked the issue's claims against current code rather than trusting them: docs/PROOF_CLAIM_CONTRACT.md, schemas/holmes-proof-claim-contract.schema.json, and examples/holmes-proof-claim-contract.json all matched the issue's description as of main. The actual repo validation pattern is a hand-written Python validator (tools/validate_holmes.py + tools/run_negative_fixtures.py), not deep JSON-Schema constraints (the .schema.json file only checks top-level required keys), so the new enforcement lives there, consistent with the existing pattern.

Test plan

  • python3 tools/validate_holmes.py — passes with new fields.
  • python3 tools/run_negative_fixtures.py — all 5 negative fixtures rejected, including the new forbidden-global-consistency case, with a clear, specific error message.
  • python3 tools/validate_maturity.py — passes.
  • go test ./... — no test files (pre-existing state), exits 0.
  • Confirmed the two pre-existing negative fixtures (proof-claim-wrong-owned-segment.json, proof-claim-missing-reasoning-field.json) still fail for their original reasons — no regression.
  • Note: make validate's final CLI smoke-test step (bin/holmes --version) crashes with a dyld: missing LC_UUID load command error in this environment. Verified this is pre-existing on unmodified origin/main (commit 4dfd418), caused by the net/http-based HellGraph wiring added in that commit, unrelated to and predating this change. Not touched here per the non-goal of not touching reasoning/CLI logic.

Not merging — leaving for review per instructions.

…ditive)

sociosphere/docs/integration/neurosymbolic-chronos-alignment.md defines a
CHRONOS carrier shape (source evidence ref, method family, method output
type, grounding status, validation status, explanation trace ref, owning
authority plane, non-authority declaration, replay ref, governance
decision) for any object crossing a governance boundary. Its method-family
table already has an "LNN-style truth-bound propagation" row that matches
Holmes's existing TruthBounds/ReasoningTrace mechanism almost exactly.

This is an additive superset extension of docs/PROOF_CLAIM_CONTRACT.md,
examples/holmes-proof-claim-contract.json, and tools/validate_holmes.py:
no existing field, behavior, or contract invariant is removed or changed.

- Each ReasoningTrace step now carries `methodFamily` (constant:
  "LNN-style truth-bound propagation", matching the doctrine's row name)
  and `nonAuthorityDeclaration` (consistencyScope, doesNotAuthorize,
  statement), making the doctrine's forbidden-use rule -- never claim
  global consistency from a bounded local result -- mechanically
  checkable rather than only prose in the contract doc.
- Each worked example now carries a package-level `chronosCarrier` block
  covering the remaining CHRONOS carrier fields, reusing Holmes's
  existing vocabulary where it already covers the same ground
  (validationStatus reuses proofCertificate/verificationPath outcomes,
  governanceDecision reuses policyReadyClaim.admissionStatus, etc.)
  rather than duplicating it.
- tools/validate_holmes.py enforces both: methodFamily must be an
  allow-listed value, nonAuthorityDeclaration.consistencyScope must be
  "formula_local" and is rejected if "global", and chronosCarrier must
  carry all required fields with owningAuthorityPlane always
  SocioProphet/policy-fabric (Holmes never declares itself the owning
  authority plane).
- New negative fixture
  fixtures/invalid/proof-claim-forbidden-global-consistency-claim.json
  demonstrates the forbidden use directly: a TruthBounds result
  promoted as if it proved global consistency. Validator rejects it.
- repo.maturity.yaml and tools/validate_maturity.py updated for the
  fixture count (4 -> 5).

Refs #16.
Copilot AI review requested due to automatic review settings August 2, 2026 08:35

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Extends Holmes’s proof-claim contract artifacts to optionally carry CHRONOS “carrier boundary” fields, updates the worked examples and documentation to describe the mapping, and strengthens validation/negative fixtures plus maturity evidence to cover the new alignment requirements.

Changes:

  • Adds methodFamily and nonAuthorityDeclaration to reasoningTrace[] in the proof-claim contract examples/docs and enforces them in tools/validate_holmes.py.
  • Introduces package-level chronosCarrier blocks on worked examples and adds a new negative fixture for forbidden "consistencyScope": "global".
  • Updates repo maturity evidence and validator thresholds to require 5 negative fixtures.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
tools/validate_maturity.py Bumps required negative fixture count from 4 → 5 and updates the cited evidence string.
tools/validate_holmes.py Adds CHRONOS-alignment validation for methodFamily, nonAuthorityDeclaration, and chronosCarrier.
repo.maturity.yaml Updates M3 evidence text to reflect the new CHRONOS-aligned fields and adds a nextAction about expanding allowed method families.
fixtures/invalid/proof-claim-forbidden-global-consistency-claim.json Adds a new negative fixture that exercises the forbidden global-consistency promotion.
examples/holmes-proof-claim-contract.json Updates both worked examples to include methodFamily, nonAuthorityDeclaration, and chronosCarrier.
docs/PROOF_CLAIM_CONTRACT.md Documents the CHRONOS carrier alignment mapping and the new fields.
Suppressed comments (1)

fixtures/invalid/proof-claim-forbidden-global-consistency-claim.json:56

  • Same as above for the vector worked example: include explanationTraceRef (null) so chronosCarrier stays structurally complete and the fixture remains targeted at the global-consistency promotion error.
        "chronosCarrier": {
          "sourceEvidenceRef": "vec://bad",
          "methodOutputType": "bounded-truth-interval",
          "groundingStatus": "ungrounded",
          "validationStatus": "rejected_before_policy",

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread tools/validate_holmes.py
Comment thread tools/validate_holmes.py
Comment on lines +284 to +305
if not str(carrier.get("sourceEvidenceRef", "")).strip():
return fail(f"{source}: workedExamples.{worked_example_key}.chronosCarrier.sourceEvidenceRef must be non-empty")

if carrier.get("groundingStatus") not in ALLOWED_GROUNDING_STATUSES:
return fail(
f"{source}: workedExamples.{worked_example_key}.chronosCarrier.groundingStatus must be one of "
f"{sorted(ALLOWED_GROUNDING_STATUSES)}; got {carrier.get('groundingStatus')!r}"
)

if carrier.get("owningAuthorityPlane") != REQUIRED_OWNING_AUTHORITY_PLANE:
return fail(
f"{source}: workedExamples.{worked_example_key}.chronosCarrier.owningAuthorityPlane must be "
f"{REQUIRED_OWNING_AUTHORITY_PLANE!r}; Holmes never declares itself the owning authority plane"
)

if not str(carrier.get("replayRef", "")).strip():
return fail(f"{source}: workedExamples.{worked_example_key}.chronosCarrier.replayRef must be non-empty")

if not str(carrier.get("governanceDecision", "")).strip():
return fail(f"{source}: workedExamples.{worked_example_key}.chronosCarrier.governanceDecision must be non-empty")

return None
Comment thread tools/validate_holmes.py Outdated
Comment on lines +254 to +256
does_not_authorize = set(declaration.get("doesNotAuthorize", []))
missing_claims = REQUIRED_FORBIDDEN_CLAIMS - does_not_authorize
if missing_claims:
Comment thread docs/PROOF_CLAIM_CONTRACT.md Outdated
Comment on lines +55 to +59
This section is an **additive superset**: it extends the existing
`TruthBounds`/`ReasoningTrace`/`ExplanationTrace` chain above with CHRONOS-carrier
fields, without removing or changing any existing field or behavior. Every artifact
this repo already produces remains valid; it is now also expressible as a CHRONOS
carrier.
- Require explanationTraceRef as a CHRONOS carrier key (null allowed
  when no explanation trace was produced), matching the documented
  contract and worked examples.
- validate_chronos_carrier now also rejects empty/invalid
  methodOutputType and validationStatus, and enforces
  explanationTraceRef is either null or a non-empty string.
- Fix doesNotAuthorize crash: an explicit null (or non-list, or
  non-string items) now fails validation with a clear message
  instead of raising TypeError from set(None).
- Soften PROOF_CLAIM_CONTRACT.md's backward-compatibility claim: the
  base proof-claim shape is unchanged, but the new CHRONOS-carrier
  fields are validator-enforced, so pre-alignment artifacts need
  updating rather than being automatically valid.
- Add missing explanationTraceRef: null to both chronosCarrier blocks
  in the forbidden-global-consistency-claim fixture so it fails for
  the intended forbidden-scope reason, not incidental missing-field
  reasons.
@mdheller
mdheller merged commit fa60e44 into main Aug 2, 2026
5 of 6 checks passed
@mdheller
mdheller deleted the feat/chronos-carrier-superset branch August 2, 2026 08:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants