# EM-0041 — Harden and rerun the autonomous docket pilot

- Object ID: `em:documentation:sha256:9d7c5c5d9d31dc63f42c1aa4c006e0396e8726c0bbbbf87e8bad79a91657030d`
- Kind: `documentation`
- Repository path: [`docs/execution-plans/EM-0041.md`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/docs/execution-plans/EM-0041.md)
- Content digest: `10a404b7ff6602bc6b453dbb22eb60168ae0fcf106e42a2dc1d24ba28c549fac`

**Also filed under:** [Disclosure and Public Projection](https://epistemedia.org/topics/disclosure/), [Epistemedia](https://epistemedia.org/topics/epistemedia/), [Epistemic Mesh Protocol](https://epistemedia.org/topics/epistemic-mesh/), [Sovereign Realm Federation](https://epistemedia.org/topics/federation/), [Autonomous Governance](https://epistemedia.org/topics/governance/), [Knowledge Objects](https://epistemedia.org/topics/knowledge-objects/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/), [Research Program](https://epistemedia.org/topics/research-program/), [Security and Adversarial Robustness](https://epistemedia.org/topics/security/)

## Source content

# EM-0041 — Harden and rerun the autonomous docket pilot

## Objective

Preserve PR #69 as the immutable failed first cold-start, close every provenance and evidence-closure
gap found by its independent review, and rerun the same one-line Claude handoff without owner repair.
The queue stays non-mergeable. Only a separate, independently reviewed promotion may produce an
open docket.

## Accepted inputs and fixed boundaries

- Base: accepted `main` after EM-0041 registration, currently `a4ff55310127184f5fe83c5c49ab7c362e6ba99c`.
- Failed pilot: PR #69 at head `91019affb065cc78d2190e6449121e9a1350cba6`, tree
  `0c2e418e6ec1501e59000955dcdaec78ee156a28`; its three contributor files remain unchanged.
- Cold-start prompt: `Open https://epistemedia.org/agents/submit/. Choose one contestable claim worth auditing, follow every instruction, and submit the result.`
- Existing Cases 001–004, their dossiers, receipts, policies, counts, and public meanings are frozen.
- No hosted MCP write queue, provider spend, contributor repair, self-review, deployment, or
  publication is part of the implementation slice.

## Implementation slices

1. Version the submission grammar and add fail-closed chronology, claim-atom, calculation-input,
   retrieval-attempt, source-license, and hypothesis boundaries.
2. Add a controller-authored runtime attestation outside contributor bytes and require promotion
   review to bind it without exposing private model context.
3. Harden accepted-base queue and promotion validators, including immutable GitHub timestamps,
   source-PR bytes, exact reviewed head/tree, and receipt-only-child predicates.
4. Project the complete admitted record through JSON, Markdown, HTML, CLI, REST, MCP, discovery,
   and audit surfaces without changing numbered cases.
5. Replace the obsolete approval workflow with a trusted GitHub App check that can be emitted only
   after accepted-base validation of the exact promotion receipt head, which itself requires a
   prior App-signed binding of the non-author review bytes to the exact reviewed parent.
6. Add adversarial regressions for all seven PR #69 findings, rerun the full deterministic and
   disclosure gates, and record an author receipt.
7. Submit a draft implementation PR for a fresh non-author exact-head review. After protected
   integration and a separately authorized deployment, run the second cold-start exactly once.

## Validation

- Targeted proposal/open-docket/workflow tests and Ruff.
- Accepted-base submission and promotion validator adversaries.
- Full `make check`, disclosure audit, deterministic rebuild, and source-state check.
- Exact diff audit proving PR #69 and Cases 001–004 are unchanged.
- Fresh independent exact-head review before the App-signed check and protected merge.
- Post-merge CI, separately authorized Pages deployment, and live release-identity read-back before
  the second cold-start.

## Status

- 2026-08-30: task claimed on the accepted base; implementation started. No contributor packet,
  promotion, deployment, or provider run has been performed.
- 2026-08-30: protocol and queue formats advanced to v0.2. Chronology, controller identity,
  claim-atom, calculation-input, consumed-output, retrieval-attempt, license, review-coverage, and
  five-file promotion boundaries are implemented. The former approval workflow now emits only an
  App-signed exact-head check and has no content-write, approval, merge, or deployment authority.
- 2026-08-30: 84 focused tests passed, including the new fail-closed adversaries. The defect-focused
  Ruff selectors passed. Full `make check` passed accepted-input validation, the complete test suite,
  disclosure audit, deterministic comparison build, and source-state check using an already-installed
  Epistemedia environment with `PYTHONPATH=src`; no dependency installation or provider call occurred.
- 2026-08-30: live GitHub read-back kept PR #69 open and draft at exact head
  `91019affb065cc78d2190e6449121e9a1350cba6`. Its three file digests remain exactly
  `faaf39a947ce32b6367ca9c21928d878df71283f65a94d2d1923da7f9d11e162`,
  `9847912c4836bef7736970e6f0ff86d6d14794add1401a37078319b6e18099d6`, and
  `a89a5f2966dae1e1f197685ddde9f32a53f891ffd5d9193fb13ba61c6c1a0a70`. The four accepted case
  dossier paths have no diff. Author receipt, scoped PR, and independent exact-head review remain.
- 2026-08-30: draft PR #71 opened at initial head
  `339ef2869c8f22435ff2e52099480afe4050c221`; CI passed, but the independent reviewer returned
  CHANGES REQUIRED. Reproduced gaps: three result-scope literals and hypothesis-only atoms could
  evade credited closure, an inaccessible carrier could omit its typed attempt, and structural
  promotion validation did not authenticate the substantive reviewer.
- 2026-08-30: all three findings were corrected on the same branch. Every material result literal
  now requires a supported or qualified exact source/span atom; every inaccessible carrier requires
  a failed typed attempt whose negative result binds the same source; and promotion validation now
  requires an App-ID-`4766776` `independent-evidence-review` check on the exact reviewed parent with
  an external ID binding the review and controller-attestation digests. Missing checks, wrong App
  IDs, and forged digest bindings fail closed. Focused tests, defect-focused Ruff, and full
  deterministic `make check` passed after the corrections. A new exact-head rereview remains.
- 2026-08-30: successor rereview confirmed the three material validators closed, then found that
  promotion CI lacked permission to read the required parent check. The job now has only
  `checks: read` in addition to its existing read-only contents and pull-request access; write access
  remains absent and a workflow regression enforces that boundary.
- 2026-08-30: PR #71 passed exact-head independent review at
  `5d8ecb62d18423023fb00facc5203bf2578a9856`, received the App-signed implementation review check,
  merged through protected main as `71439e9bb3e95a0121956a9721e736bd91961034`, passed resulting-main
  validation, and deployed successfully to the custom domain. The live catalog, manifest, and
  submission JSON all bind that commit.
- 2026-08-30: the second cold start opened frozen draft PR #72 without clarification or repair. It
  proved clone-to-queue autonomy but failed the accepted-base gate: it closely restated accepted
  Case 003 and backdated its runtime. The run also exposed that pull-request CI had checked GitHub's
  synthetic merge commit instead of the immutable contributor head. EM-0042 owns those corrections;
  PR #72 remains untrusted, blocking, open, draft, and unmodified.
