# Independent implementation and buyer falsification handoff

The existing code and this corpus were authored by Finality. They establish no
external independence. An external team must receive the public specification
and canonical vectors, implement its verifier without primary implementation
code, and retain author/team, language, code-sharing declaration, source commit,
build identity and signed test results. A different language alone is insufficient.

Profile for this pack: Institutional outcome certificate v2. Input is one JSON
object with `certificate` and `options` (contract, evidence, independently trusted
issuer registry, trusted current head, and trusted evaluation time). Output is
one JSON object with boolean `valid`. Unexpected output, timeout, crash, or an
absent verdict fails the harness.

A FINAL verdict requires: exact version 2; positive integer sequence; tenant,
contract digest, trust-domain, policy/schema and reliance binding; Ed25519 issuer
signature and payload digest under a pretrusted active, time-valid issuer key;
recomputed full evidence commitment; unique evidence IDs; required authoritative
source observations satisfying every end-state predicate; freshness and clock
constraints; no contradiction; and exact current FINAL head identity, sequence,
tenant and payload digest. An embedded certificate key is not a trust root.
The authoritative source inputs and current head must be independently acquired;
this profile does not authenticate external source observations by itself.

Canonical object encoding: JSON objects sorted by key, arrays retain order, UTF-8,
SHA-256 payload commitments prefixed `sha256:`. Restrict this profile to finite
integer numbers, ASCII identifiers/keys, no undefined values or duplicate JSON
keys. This avoids making unsupported cross-language canonicalization claims.
Evidence roots sort `{id, content_digest: SHA256(canonical entire evidence object)}`
by ASCII evidence ID before hashing the canonical array. Sign the canonical
certificate excluding `payload_digest` and `signature`; Ed25519 signature uses
base64url. The verifier must reject rather than invent behavior outside its profile.

The corpus JSON includes 28 positive and negative cases with known expectations.
These are compatibility vectors. They are not blind buyer tests.

## Private buyer test

Buyer authors `cases.json`: `[{"id":"buyer-case","input":{...}}]`.
Buyer retains `PRIVATE-truth.json`: `{"buyer-case":false}` on its own machine.
Buyer selects/controls the real authoritative truth state independently.

Run `node challenge-runner.mjs adapter.mjs cases.json PRIVATE-truth.json`, or use
a command JSON file such as `["python3","buyer_verifier.py"]` instead of the
adapter filename. No shell is involved. Only each case's input is passed to the
adapter; the truth file remains in the buyer's runner. Keep the resulting local
report private until the buyer elects to share it. It contains oracle verdicts.
Run with a buyer-owned, network-isolated process sandbox when testing a remote or
untrusted implementation; this harness does not create isolation or attest that
an adapter was unable to access other local files.

The runner does not verify who authored a case, physical-world truth, or absence
of prior seller access. Its output therefore states `NOT_VERIFIED_BY_RUNNER`.
Buyer must sign a separate authorship/truth-custody declaration and executed
result before Finality may count it as buyer-authored or independently validated.

## Production evidence

Do not convert this synthetic corpus, SQLite fault lab or seller delivery
schedules into production-outcome counts. Record actual authorized workflow IDs,
contract revision, tenant binding, issuer/source trust roots, authoritative
observation digests, current-head transitions, contradictions, REOPEN events,
verifier verdicts, source/build identity and signed external operator receipts.
Count independently authored attacks only with independently attributable
execution receipts. Keep unavailable measurements `NOT_ESTABLISHED`, rather
than displaying zero as though measurement occurred.

For the DHL call: "We have an operating implementation and reproducible
seller-controlled assurance evidence. The next evaluation gives DHL control
of the workflow, authoritative truth and unseen adverse cases, so maturity is
measured by whether those tests can force an incorrect FINAL. Independent
validation and customer production evidence are not yet established."

## Institutional profile normalization (V126 clarification)

The contract digest preimage is the frozen contract, not always the raw input.
Before hashing, clone the contract and insert these defaults: version=1 if absent
or not a positive integer; required_source_count=authoritative_sources.length if
absent or not an integer; max_clock_skew_seconds=300 if absent/nonfinite, otherwise
max(0,value); source_freshness_seconds={} if absent/falsy. The supported public
ASCII/integer profile rejects other numeric types before this normalization.
Validate positive source count <= number of distinct sources, nonempty outcome
state, nonempty authorities, and nonnegative source freshness values. All other
fields retain their supplied values. The V122 positive contract omits the count:
its signed digest commits to the inserted required_source_count=2.

End-state predicates are exact canonical-value equality at dotted object paths.
Every present latest authoritative source must match; any mismatch blocks FINAL
including sources beyond the required threshold. Select newest observation time
per source; differing observations with the same source and timestamp conflict.
Every supplied evidence ID must be unique. For certificate commitment, use the
complete supplied evidence list; for outcome evaluation use the latest per source.
Contradiction operators at dotted paths: missing,eq,ne,lt,lte,gt,gte,in,not_in.
Missing tests absence; other operators require presence. Source future time is
permitted only within max_clock_skew_seconds. Freshness equality is admissible;
older than the permitted window blocks. Deadline is inclusive for observation and
verification time. Required certificate issued time <= trusted verification time,
and lies within active issuer key validity. Valid JSON and signatures alone do
not establish authority or a current FINAL head.

The strict ASCII/integer canonical wire profile is an interoperable research
subset. Older object-level production APIs accept a broader JSON domain; that is
not a claim of cross-language canonical equivalence beyond this subset. Unknown
policy semantics must reject. Never infer a digest preimage from vector IDs.

Key validity clarification: trusted verification time lies in the half-open interval
[not_before,not_after). Certificate issuance time lies in that same interval and
cannot be later than verification time. The deadline field is `deadline`; freshness
is unlimited for a source when that source has no configured freshness entry.
Same-source/equal-time conflict compares the entire canonical observation object.
Trusted roots and current heads must be acquired separately, not accepted from an
untrusted certificate envelope. Registries and time remain explicit external inputs.

Evidence identity sorting clarification: compare IDs by ASCII/code-unit lexical
order, not locale collation. V126 makes this explicit in the implementation.
Earlier reference releases may have used locale collation; retain those releases
for historical research, and do not assume every old non-ASCII commitment is
interoperable with this profile. Existing canonical V122 vectors are unchanged.
