| Artifact | GAIX-FIP-001-THREAT-MODEL-AND-FAILURE-MODES |
|---|---|
| Accepted version | v0.1.2 |
| Text rendered on this page | v0.1.2 — accepted text, complete and verbatim (the title line and the document header table are included) |
| Status on this surface | ACCEPTED |
| Package hash | Not recorded. Generated at freeze (FREEZE MANIFEST — PENDING). |
Presentation changes on this page
- The text on this page is the accepted v0.1.2 source, rendered in source order. No wording is added, removed, reordered or reconciled. The title line and the document header table (Status, Baseline, Evidence state) are shown as written.
- The source's Markdown structure (headings, tables, lists, block quotes) is shown as the equivalent page structure, each heading with an in-page anchor. Status and class labels (for example
SPECIFIED / INSPECTION HYPOTHESIS,KNOWN OPEN DEFECT,IMPLEMENTED + TESTED — CONDITIONAL) are shown with matching visual treatment; the wording is unchanged. Evidence identifiers cited in the text (for example INV-06-B, KF-06, M1D T-05) are shown as text and are not linked. - Authorized public-presentation substitutions (local filesystem path wording; the named credential-incident wording): none was needed on this page. The accepted v0.1.2 text contains neither.
GAIX-FIP-001-THREAT-MODEL-AND-FAILURE-MODES-v0.1.2
| Status | ACCEPTED CONTROL BASELINE |
|---|---|
| Baseline | Accepted FIP-001 control artifacts v0.1.2 |
| Evidence state | Reconciled 2026-09-19 |
Reading rules.
T-nnIDs are threat-model IDs, not claims.- Every implementation state below is taken from the Claims/Non-Claims Register (claims use
FIP-C-; inspection hypotheses useFIP-H-; non-claims are an unnumbered controlled list) and the Known-Limitations Register (limitations useLIM-) or, where a register's wording is not specific enough, from the directly cited implementation evidence described next. - The registers remain the controlling claim ceiling. A directly cited evidence identifier supports only the exact proposition that evidence establishes. It creates no normative authority, no claim and no limitation. CONDITIONAL evidence is labelled CONDITIONAL wherever it is cited.
- Evidence identifiers:
GA-nn(governance conformance,105e7f0),KF-nn(federation conformance,b762610) andINV-nn(M1C invariant proofs,e44df17) are accepted baseline evidence.M1D T-nn(M1D composition proof,f8d6dda) is CONDITIONAL evidence and is never a threat-model ID. - This document adds no implementation status, no claim and no limitation. Any change follows those registers' change rules.
- Listing a failure mode here does not mean it is implemented, tested or closed.
1. Inspection objective
Intelligence is not authority.
The narrow inspection question is:
Can current standing and authority be made a precondition to a protected consequential transition under the conditions that exist at the relevant decision boundary?
The accepted implementation lets an inspector attack this at two implemented decision boundaries, on synthetic fixtures with a mock provider only:
- (a) R2's atomic authorization of a MergeProposal
INSPECTED → ACCEPTEDtransition (FIP-C-003). - (b) R3's Canon admission decision (FIP-C-007A; FIP-C-007B is CONDITIONAL, M1D T-07).
In this document, "protected consequential transition" means those two governance-boundary transitions only.
This model does not claim:
- Bind-time enforcement at model submission. It is specified in DM-001 §10 and not implemented (FIP-H-001).
- Merge application (FIP-H-006).
- Any external or real-world effect.
- Universal bind-time consequence enforcement.
2. Protected properties
| ID | Property | Register anchors |
|---|---|---|
| P-01 | Separation of intelligence/capability from authority | FIP-C-001A/B |
| P-02 | Current standing | FIP-C-002, C-003, C-007A |
| P-03 | Scoped authority | INV-06-A/B, GA-16, GA-18, FIP-C-007A |
| P-04 | Changed-condition revalidation | FIP-C-003, C-007A, C-007B (CONDITIONAL, M1D T-07) |
| P-05 | Non-collapse: Federation, Ingress, Proposal, Compatibility, Visibility, Possession and Gateway transport are not authority or admission | FIP-C-008..014, C-022 |
| P-06 | Refusal without unauthorized state mutation | FIP-C-007A, C-003 |
| P-07 | Evidence/provenance does not silently become authority | FIP-H-005, GAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "that provenance establishes authority", LIM-002 |
| P-08 | Historical evidence is separate from present authority | FIP-C-002, C-018, RAT-058: "Historical ACCEPTED evidence remains distinct from current merge-application authority." |
3. Threat / failure families
| ID | Threat | What an inspector attempts | Property |
|---|---|---|---|
| T-01 | Stale standing | Let a decision proceed after the actor's authority was revoked, the receiving domain went stale, a cited source's version drifted, or cited evidence expired | P-02, P-04 |
| T-02 | Authorization replay | Reuse a prior authorization, receipt or historical ACCEPTED to authorize a later or different consequential transition | P-02, P-08 |
| T-03 | Changed target | Change the object a transition acts on after approval | P-04 |
| T-04 | Changed destination | Change where an approved consequence lands (recipient, endpoint, provider destination) after approval | P-04 |
| T-05 | Changed scope | Exercise authority outside its registered scope (unregistered actor, wrong domain, revoked actor). The scope of an approved consequence is T-23. | P-03 |
| T-06A | Temporal drift before the decision | Let time pass between review/proposal and the decision so relied-upon standing lapses | P-02, P-04 |
| T-06B | Delayed execution | Let time pass between authorization/bind and a later consequential execution | P-02, P-04 |
| T-07 | Source-currentness loss | Cite a source that lost currentness (stale, withdrawn, revoked, unavailable, unknown) in a new admission that depends on it | P-02, P-08 |
| T-08 | Authority/domain identity collision | Present a source from one authority/namespace that shares an objectId and version with another authority's registered source | P-03 |
| T-09 | Route substitution | Substitute a different provider, model or route than the one authorized | P-01, P-04 |
| T-10 | Equivalent alternate route | Reach the same consequence by a materially equivalent path the tested route does not cover | P-01 |
| T-11A | Cache/mirror masking (Federation boundary) | Present a cached copy that hides loss of source standing | P-08 |
| T-11B | Cache/mirror masking (composed paths) | The same, through the composed Federation → Governance → Access → Gateway run | P-08 |
| T-12 | Provenance mistaken for authority | Supply provenance, possibly malformed, and have it consumed as authority for a protected transition | P-07 |
| T-13 | Receipt mistaken for renewed authority | Treat a Gateway invocation receipt or provider identity as authority for a protected transition | P-01, P-08 |
| T-14 | Federation mistaken for admission | Make a federated external object act as admitted Canon | P-05 |
| T-15 | Ingress mistaken for admission | Use a candidate offer/handoff to create standing or a proposal linkage | P-05 |
| T-16 | Proposal mistaken for admission | Reach ADMIT from a state that is not an explicit decision state | P-05 |
| T-17 | Compatibility mistaken for standing | Have structural compatibility or validation produce standing | P-05 |
| T-18 | Visibility mistaken for standing | Have a read, list or resolve change state or standing | P-05 |
| T-19 | Possession mistaken for authority | Hold a proposal, object or credential and thereby decide | P-05 |
| T-20 | Gateway transport mistaken for authority | Have a provider/gateway result carry or confer authority | P-01, P-05 |
| T-21 | Model correctness mistaken for authority | Argue that a correct or high-confidence model output is itself authority for the transition | P-01 |
| T-22 | Source-currentness uncertainty silently becoming permission | Have a source whose currentness is unknown or unresolved (e.g. the characterized SOURCE_CURRENTNESS_UNKNOWN and UNRESOLVED states) accepted as sufficient for a new admission because the currentness condition was lost in the handoff | P-02 |
| T-23 | Post-approval condition mutation | Mutate the approved payload, parameters or effective conditions after approval and before the transition | P-04 |
4. Coverage classification
Each threat has exactly one classification. ACCEPTED and CONDITIONAL entries inherit the cited claim's ceiling: synthetic fixtures, mock provider, INTERNAL reproduction at most. SPECIFIED / INSPECTION HYPOTHESIS covers both principle-only items and hypotheses.
| ID | Coverage | Register anchors | Ceiling / note |
|---|---|---|---|
| T-01 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-003; FIP-C-007A (GA-18..21) | Excludes source currentness (T-07) and cross-authority identity (T-08). R2 counts are agent-reported. |
| T-02 | SPECIFIED / INSPECTION HYPOTHESIS | FIP-C-002; FIP-H-006; LIM-016 | RAT-058: Historical ACCEPTED evidence remains distinct from current merge-application authority. No registered claim tests replay of a consequential transition, and merge application is not implemented. |
| T-03 | SPECIFIED / INSPECTION HYPOTHESIS | FIP-H-001; LIM-016 | Target-side effects not implemented. Pinned authorization inputs fall under T-01. |
| T-04 | SPECIFIED / INSPECTION HYPOTHESIS | FIP-H-001; LIM-016 | Destination is part of the DM-001 §10 binding, which is not implemented. |
| T-05 | IMPLEMENTED + TESTED — ACCEPTED | INV-06-A/B; GA-16; GA-18; FIP-C-007A | R3 admission decision boundary; fixtures only. |
| T-06A | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-003 (currency guard); FIP-C-007A (domain/evidence) | Decision boundary only. |
| T-06B | SPECIFIED / INSPECTION HYPOTHESIS | FIP-H-001; FIP-H-006; LIM-016 | No execution/bind path is implemented. |
| T-07 | KNOWN OPEN DEFECT | LIM-010 (CAND-01); FIP-H-002 | See §5. FIP-C-016A/B and FIP-C-018 are related and do not mitigate it. |
| T-08 | KNOWN OPEN DEFECT | LIM-011 (CAND-02); FIP-H-003; FIP-C-017A/B (limited; 017B CONDITIONAL, M1D T-09-A) | See §5. |
| T-09 | SPECIFIED / INSPECTION HYPOTHESIS | FIP-H-001; LIM-016; LIM-018 | The route is part of the DM-001 §10 binding. Mock-Gateway route-refusal behavior exists in unregistered evidence and is not claimed. |
| T-10 | OUT OF CURRENT FIP CLAIM SCOPE | GAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "universal route closure or non-bypassability"; §6 | Universal non-bypassability is a non-claim. |
| T-11A | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-016A; KF-06; KF-09 | Per-path Federation behavior. "Cache/mirror" here means only the tested modelled observation/mapping state: a stale, withdrawn or revoked source is reported as such and never as current (KF-06, KF-09). No real cache or mirror infrastructure layer was tested. |
| T-11B | IMPLEMENTED + TESTED — CONDITIONAL | FIP-C-016B; LIM-012; M1D T-03 (CONDITIONAL); M1D T-04 (CONDITIONAL); M1D T-05 (CONDITIONAL) | Rests on M1D. The CONDITIONAL evidence supports only this: at the Federation boundary a modelled stale, withdrawn or revoked source is never read as current and a locally current mapping cannot upgrade it (M1D T-03, T-04); and after admission a later change in the source leaves the Governance store, the decision and Canon Access unchanged while Federation reports the new state (M1D T-05). It does not establish composed-path non-masking. CAND-01 (§5) remains the composed currentness failure: a new admission can rely on a source that is already non-current. |
| T-12 | SPECIFIED / INSPECTION HYPOTHESIS | FIP-H-005; GAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "that provenance establishes authority"; LIM-002 | LIM-002 establishes a runtime provenance-validation defect (no runtime schema validates ProvenanceRecord; governance accepts a malformed record). It does not establish that provenance is actually consumed as consequential authority in any accepted path. That consumption is the hypothesis. |
| T-13 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-001B; INV-07-A/B/C; INV-08-A | Mock provider only. Established: a Gateway result confers no authority (INV-07); provider and model are recorded in the tested invocation evidence and an execution-receipt reference is present; and at the R3 admission decide() boundary a provider, model or MODEL_RETURN_PROPOSED presented as the decision actor is refused even when a well-formed execution-receipt reference is held (INV-08-A). Not established: receipt verification (LIM-017), any effect of a Gateway receipt on R2 authority (reuse of an R2 authorization receipt is T-02), or provider-identity guarantees beyond the tested evidence. |
| T-14 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-008 | Fixtures only. |
| T-15 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-009 | Fixtures only. |
| T-16 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-010 | Fixtures only. |
| T-17 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-011 | Fixtures only. |
| T-18 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-012 | Read paths only. |
| T-19 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-013 | Fixtures only. |
| T-20 | IMPLEMENTED + TESTED — ACCEPTED | FIP-C-014 | Mock provider only. |
| T-21 | SPECIFIED / INSPECTION HYPOTHESIS | FIP-C-001A (principle); LIM-018; LIM-030 | FIP-C-001B covers provider identity/receipt only, not "correctness." No live-provider evidence. |
| T-22 | KNOWN OPEN DEFECT | LIM-010 (CAND-01); FIP-H-002; the characterized SOURCE_CURRENTNESS_UNKNOWN and UNRESOLVED states (M1D T-08, f8d6dda, CONDITIONAL) | Limited to the CAND-01-supported behavior. It is not generalized to every malformed, unknown or unevaluable authority condition. Those are classified under their own rows (T-01, T-05, T-08, T-12) or are not claimed. |
| T-23 | SPECIFIED / INSPECTION HYPOTHESIS | FIP-H-001; LIM-016 | — |
Totals (25 rows):
- 12 IMPLEMENTED + TESTED — ACCEPTED.
- 1 IMPLEMENTED + TESTED — CONDITIONAL.
- 8 SPECIFIED / INSPECTION HYPOTHESIS.
- 3 KNOWN OPEN DEFECT.
- 1 OUT OF CURRENT FIP CLAIM SCOPE.
Scope note on uncertainty. Uncertainty about conditions other than source currentness is not asserted as a defect here and is not separately classified. Any finding would be dispositioned under §7 (as a broader manifestation of an included claim, or as an out-of-scope behavior).
5. CAND-01 / CAND-02 (published explicitly)
CAND-01 — source-currentness enforcement gap (LIM-010).
- Observed at the accepted baseline:
- A Federation-derived proposal could receive a new ADMIT whatever its source's currentness.
- In the M1D characterization (M1D T-08,
f8d6dda, CONDITIONAL), 10 non-current states were admitted and none refused:SYNC_STALE,SOURCE_UNAVAILABLE,SOURCE_VERSION_ADVANCED,WITHDRAWN,REVOKED,SOURCE_CURRENTNESS_UNKNOWN,RIGHTS_CHANGED,REVALIDATION_REQUIRED,MAPPING_INVALIDATED,UNRESOLVED. standingCurrentnessPrerequisiteswas stored and consumed by nothing.
- Contract basis:
- C3 v0.2 §3 (prerequisite standing/currentness assertions).
- C3 v0.2 §6 (source identity/version/currentness revalidation "as applicable").
- What it is not: it is not a rule that every non-current source is inadmissible. Historical or non-current material may be used where the contracts permit it without a currentness prerequisite. The defect is that the condition was silently lost in the handoff.
- Status: confirmed candidate defect (Richard's disposition, 2026-09-19 18:42Z), OPEN.
CAND-02 — authority/domain-qualified identity revalidation gap (LIM-011).
- Observed: Governance source revalidation keyed on
objectId+ version, soSYNTH-LAB-B/…/obj-001was satisfied by registry state forSYNTH-UNIVERSITY-A/…/obj-001(M1D T-09-C, CONDITIONAL). - Contract basis: C1 v0.2 §2 (qualified identity is authority/domain + namespace + object identity; "a bare local
idis insufficient"). - Status: confirmed candidate defect (same disposition), OPEN.
Pending remediation is not mitigation. A remediation exists for both (five local branches, unmerged), and it is PENDING REVIEW / UNACCEPTED (Manifest §6). It is not a fix, not a mitigation, and not to be cited as reducing either item's status. Inspectors work against the accepted baseline commits.
6. Route-closure discipline
- Blocking one tested route does not prove closure of every materially equivalent route. Universal non-bypassability is a non-claim (GAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "universal route closure or non-bypassability").
- Route closure is a property of a deployment environment (a declared route inventory, an executor/credential model and residual-path disclosure). This package makes no route-closure claim and declares no deployment route inventory.
- A refusal on route R is evidence about route R only.
- A demonstrated alternate route is an intended inspection outcome. It is recorded as
OUT OF CLAIM SCOPE, or as a valid failure if it lies inside a claim's stated fixtures and ceiling. - No claim is widened because a route was closed or found. New claims follow the register change rule.
7. Falsification criteria
7.1 Failure-type rubric
| Type | Definition | Challenge disposition (Package Architecture) |
|---|---|---|
| Implementation defect | A reproduced deviation from a claim, inside its stated fixtures, baseline commit and ceiling | REPRODUCED — VALID FAILURE, cause IMPLEMENTATION DEFECT |
| Specification ambiguity | Normative text admits two readings, or two accepted texts conflict | SPECIFICATION AMBIGUITY |
| Expected refusal | The system refuses where the claim says it must | REPRODUCED — EXPECTED BEHAVIOR |
| Unsupported route | A path the claim or test object does not cover | OUT OF CLAIM SCOPE (recorded as a route finding, §6) |
| Environmental difference | The result differs because of the environment (paths, unbuilt dist/, missing sibling repos, runtime version) | ENVIRONMENTAL DIFFERENCE |
| Out-of-scope behavior | Behavior beyond the ceiling: live providers, real institutions, bind-time, merge application, production | OUT OF CLAIM SCOPE |
Rules.
- Every challenge names the package version/hash and baseline commits.
- Reproducing a disclosed known defect (CAND-01, CAND-02, or the LIM-002 provenance-validation defect) confirms the disclosure. It is recorded as
REPRODUCED — EXPECTED BEHAVIORagainst the LIM entry and is not a new finding. - For a disclosed known defect,
EXPECTED BEHAVIORmeans expected relative to the published frozen baseline. It does not mean intended, acceptable or conforming behavior. - A broader manifestation, meaning a state, identity or path the disclosure does not describe, is a valid failure.
- Reporting that a SPECIFIED / INSPECTION HYPOTHESIS capability is absent is expected and
OUT OF CLAIM SCOPE. A specification ambiguity in its specified behavior is valid.
7.2 What would be a valid challenge, per included claim
| Claim | Valid challenge | Not a valid challenge |
|---|---|---|
| FIP-C-001B (INV-07-A/B/C; INV-08-A) | A Gateway result in the released fixtures that carries an authority-conferring flag and is accepted, or a provider, model or MODEL_RETURN_PROPOSED value accepted as the decision actor at the R3 admission decide() boundary, including when a well-formed execution-receipt reference is held | Live-provider behavior (LIM-018); receipt verification (LIM-017) |
| FIP-C-003 | INSPECTED → ACCEPTED authorization commits with a violated guard (version, fieldMatch or currency), or a refusal leaves partial mutation | Merge application; reading ACCEPTED as merge authority |
| FIP-C-007A (GA-18..21); FIP-C-007B (CONDITIONAL, M1D T-07) | ADMIT succeeds with a revoked actor, stale domain, drifted source version or expired evidence; or a refusal changes the store | Source-currentness or cross-authority-identity cases (known: CAND-01/02); only a broader manifestation is new |
| FIP-C-008 | A federated object acquires Canon posture or standing without an explicit governance decision | — |
| FIP-C-009 | A candidate offer creates standing or proposal linkage, or a forged pre-linked offer is accepted | — |
| FIP-C-010 | ADMIT succeeds from a non-decision state | — |
| FIP-C-011 | Structural compatibility or validation yields standing | — |
| FIP-C-012 | A read, list or resolve changes proposal state, posture or standing | Non-read operations |
| FIP-C-013 (possession); INV-06-A/B (unregistered, wrong-domain and revoked decision actors) | An unregistered, wrong-domain or revoked actor completes ADMIT | Real credential handling (out of scope) |
| FIP-C-014 | A Gateway result with an authority flag is accepted | Live-provider behavior |
| FIP-C-016A (KF-06, KF-09); FIP-C-016B (CONDITIONAL, M1D T-03, T-04) | A non-SYNC_CURRENT state resolves as CURRENT, or the modelled observation/mapping state masks a known loss of source standing (A: Federation boundary; B: as tested in M1D T-03 and T-04, CONDITIONAL) | Activation semantics (LIM-003); a real cache or mirror infrastructure layer (not tested); a new admission that relies on an already non-current source (known CAND-01) |
| FIP-C-017A (KF-03; GA-11, GA-12); FIP-C-017B (CONDITIONAL, M1D T-09-A) | A Federation result rewrites the source authority to a Canon authority, or a decision carries the external authority as standing authority | Cross-authority source-registry collision (known CAND-02) |
| FIP-C-018 (CONDITIONAL, M1D T-05) | A later withdrawal or revocation alters a recorded decision or the store snapshot | A new admission on an already non-current source (known CAND-01) |
| FIP-C-001A, C-002 (principles) | An internal contradiction or ambiguity in the approved texts | Any implementation behavior |
| FIP-H-005 (T-12) | A reproduced path, at the accepted baseline, in which provenance content (including malformed provenance) determines the outcome of a protected transition | The disclosed absence of runtime provenance validation itself (LIM-002), which is a known defect |
| FIP-H-001, H-002, H-003, H-006 | A specification ambiguity or internal inconsistency in the specified behavior | Absence of implementation (expected) |
8. Threat-model ceiling
This threat model does not establish:
- general alignment;
- universal safety;
- universal route closure;
- real-institution behavior (fixtures are synthetic);
- live-provider behavior where only mock-provider evidence exists;
- independent reproduction (all reproduction is INTERNAL at most);
- production deployment;
- bind-time or consequence enforcement at model submission.