Skip to content

Two vectors for checks no vector reached: clearance, and a stale grant - #1

Merged
doytsujin merged 1 commit into
mainfrom
vectors-clearance-and-stale-grant
Sep 28, 2026
Merged

doytsujin merged 1 commit into
mainfrom
vectors-clearance-and-stale-grant

Conversation

@doytsujin

Copy link
Copy Markdown
Collaborator

Every assertion had a mutant of its own and every mutant was caught, yet two checks each implementation makes were never exercised by any vector:

  • Clearance. Refusing a principal whose clearance is below the capability's sensitivity (CLASSIFICATION_EXCEEDS_CLEARANCE). Each refusal in the AD-004 vector is decided before clearance is reached.
  • A stale grant. Refusing a grant used after the data it was issued for has changed. Each revision change in the vectors is followed by a fresh request, never by use of the earlier grant.

An implementation without either check passed all fifteen vectors.

The change

  • ad-004-clearance-refusal-has-no-grant: grant the analyst detect_outliers (confidential, above their internal clearance), then request it. Expects REFUSED, CLASSIFICATION_EXCEEDS_CLEARANCE, AD-POL-006, no grant, nothing executed.
  • ad-003-stale-grant-executes-nothing: a granted request, then set_revision, then an MCP delegate under the earlier grant. Expects nothing executed and an error naming the revision.
  • Two mutants, clearance-ignored (M07) and stale-grants-accepted (M05), each removing one of the checks.

The fifteen original vector files are unchanged, so v0.1.0 as released is unaffected. This adds to the suite; it does not revise it.

Evidence

15 original vectors + the 2 new vectors
clearance-ignored not caught by any assertion caught by AD-004
stale-grants-accepted not caught by any assertion caught by AD-003
All 9 subjects (4 runtimes × 2 boundaries, toy) 15/15 15/15
Target detection 17/17 19/19

pytest: 407 passed. The run outputs in docs/runs/ are regenerated with the frameworks current today (versions in versions.txt). The counts are updated in the README, CLAIMS, RESULTS, PORTABILITY and the package README. RESULTS keeps its 2026-09-01 figures for everything not re-measured and dates the new ones. F-012 records the gap.

RELEASE.md still says 17/17, as history. A release that ships the new vectors would say 19/19.

Every assertion had a mutant of its own and every mutant was caught,
yet two checks each implementation makes were never exercised: refusing
a principal whose clearance is below the capability's sensitivity, and
refusing a grant used after the data it was issued for changed. An
implementation without either passed all fifteen vectors.

ad-004-clearance-refusal-has-no-grant entitles a principal to a
capability above their clearance and expects CLASSIFICATION_EXCEEDS_
CLEARANCE with no grant; ad-003-stale-grant-executes-nothing changes the
revision between a grant and its use across the MCP boundary and expects
nothing to run. Two mutants remove the checks (clearance-ignored,
stale-grants-accepted): against the fifteen original vectors neither is
caught; with the two new ones each is caught by its named assertion.
The fifteen original vectors are unchanged.

All nine subjects conform (17 vectors, 90 steps); 19/19 mutants caught
by their target. Run outputs regenerated with the frameworks current
today; counts in the README, claims, results, portability and findings
updated, and F-012 records the gap.
@doytsujin
doytsujin merged commit 6eeedad into main Sep 28, 2026
12 checks passed
@doytsujin
doytsujin deleted the vectors-clearance-and-stale-grant branch September 28, 2026 03:27
@doytsujin doytsujin mentioned this pull request Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant