> Historical source context. NO JUDGMENT WHATSOEVER. Judgment state: NONE.
> The source below is preserved from its publication context, not current policy or runtime status.
> Preservation is not endorsement or verification. It grants no authority to judge participants, content, or conduct.
> Current doctrine: https://concresca.com/freedom/ ; current operation: https://concresca.com/status/ .

# Adversarial Portability, Counterparty Challenge, and Redress Continuity

**DOC-055 · Concresca v0.21.0 lineage-recovery WIP**

**Machine-assisted contribution.** This document was generated from canonical Concresca registries with machine-assisted synthesis and code generation. The point-of-use disclosure is `/observation/machine-assistance-v021/`; the exact disclosure record is `/data/machine-assistance-disclosures/`. The disclosed model identity is **GPT-5.6 Pro**. A per-call identifier is not exposed to the artifact runtime. This disclosure does not make the document an external authority or independent source.

## Abstract

Portability is often treated as a data-conversion problem: serialize a record, move it to another system, and confirm that the receiving system can parse it. That test is necessary, but it is radically incomplete whenever the record carries authority, purpose, privacy, dissent, challenge, correction, appeal, retention, or restoration consequences. A record can arrive byte-for-byte intact while its meaning, permitted use, human-rights constraints, or review path is lost. It can also change bytes while preserving a declared semantic projection. These are different propositions and must be reported separately.

This release branch defines a local synthetic architecture for adversarial portability, counterparty challenge, correction dissemination, rollback limits, and purpose-limited disclosure. It contains 6 materially different operator contracts, 18 portability trial definitions, 15 challenge states, 10 correction-graph nodes, 8 rollback receipt templates, 12 disclosure demonstrations, 18 tamper detectors, and 16 paired human-legibility fixtures. Canonical definitions retain `actual_result: null`. Executed results are emitted only by identified deterministic runner reports.

The branch is deliberately classified **WIP**. The latest complete repository actually available for this continuation is v0.18.0. The sealed v0.19.0 and v0.20.0 repository packages, site packages, v0.20 bounded-input archive, and authorizing checksum record required by the v0.21 work contract are absent. This work therefore does not claim a continuous final release lineage. It implements and tests the v0.21 design on an explicitly identified lineage-recovery branch and emits WIP-named packages.

## 1. Answer first

A portable record is not rights-preserving merely because it can be parsed by another system. A rights-preserving transfer must preserve or explicitly bound at least the following:

1. record identity and source provenance;
2. authority issuer, scope, validity, revocation, and stay;
3. declared purpose and prohibited secondary purposes;
4. null, omission, ordering, Unicode, timestamp, and unknown-field semantics;
5. dissent, recusal, unresolved objection, and hard constitutional veto;
6. challenge and appeal state, including deadlines and pause conditions;
7. correction lineage and downstream notification obligations;
8. retention, deletion, tombstone, and legal-hold state;
9. disclosure audience and minimum necessary fields;
10. rollback reach, compensation, disclosure-only remedies, and irreversible effects.

The local v0.21 engine tests those propositions against synthetic fixtures. It does not test any real counterparty, person, institution, production system, legal regime, or independent certifier.

## 2. Evidence boundary and source-lineage status

The branch begins from the exact v0.18 repository archive whose SHA-256 is `7d1f837935c20aeba9e6241c0be87bfc5a9be574e7dd68bb9410a2928df3b1ef` and the exact v0.18 site archive whose SHA-256 is `92e9ed937fcbbb3a7fec328e30c870153347e9de37059eef4d10c35ecd633163`. Approved brand assets are protected by exact baseline hashes and are not redesigned or regenerated.

The missing lineage artifacts are:

- **sealed v0.19.0 repository ZIP** — `MISSING`
- **sealed v0.19.0 public-root ZIP** — `MISSING`
- **sealed v0.20.0 repository ZIP** — `MISSING`
- **sealed v0.20.0 public-root ZIP** — `MISSING`
- **v0.20.0 bounded reproduction-input ZIP** — `MISSING`
- **v0.20.0 final checksum record authorizing those archives** — `MISSING`


The consequence is narrow but mandatory: the branch cannot be called a final v0.21 release descended from an independently sealed v0.20 repository. Technical gates may pass, but package names must retain `-wip`. The release contract states: **Always emit repository and public-root ZIPs. When any mandatory gate or source-lineage requirement is unresolved, every release ZIP filename must include -wip.**

The work distinguishes four evidence layers:

- **Canonical definition:** a registry row defining expected behavior, with `actual_result: null`.
- **Local executed result:** an identified deterministic run over authenticated repository-owned inputs.
- **Environment comparison:** a comparison between identified local executions, with environment-specific variance preserved.
- **External or production observation:** an identified outside execution or event. No such result exists in this branch.

No fresh Eviulon or Evulgare capture is made. No selected-field baseline is represented as a fresh remote-body observation. No deployment, DNS change, IndexNow submission, search indexing, crawler visit, AI citation, legal recognition, production migration, participant study, or independent certification is claimed.

## 3. Six propositions that must not collapse

The registries and runner preserve six separate propositions:

### EXACT_BYTE_EQUALITY

The compared byte sequences match exactly. It does not imply semantic validity, authority continuity, policy legitimacy.

### NORMALIZED_SEMANTIC_EQUALITY

The declared semantic projection matches. It does not imply exact bytes, behavioral compatibility, legal validity.

### BEHAVIORAL_COMPATIBILITY

The synthetic engine accepts the same declared behavior. It does not imply production interoperability, institutional adoption.

### SCHEMA_COMPATIBILITY

Required fields and types can be represented without prohibited loss. It does not imply authority continuity, constitutional acceptability.

### AUTHORITY_CONTINUITY

Current authority evidence survives the transfer boundary. It does not imply technical availability, policy legitimacy.

### POLICY_LEGITIMACY

A competent authorized process accepted the policy basis. It does not imply local test pass. The current result remains null.

A report that says only “migration passed” is therefore inadequate. It must state which proposition passed, which did not pass, which was not evaluated, and which is non-comparable. Exact-byte equality cannot establish legal authority. Semantic equality cannot establish production behavior. Technical compatibility cannot establish constitutional acceptability. Local policy checks cannot create legitimacy for a real institution.

## 4. Typed actors and anti-circular authority

The architecture represents source operator, receiving operator, affected person, reviewer, challenger, correction recipient, disclosure recipient, and rollback authority as typed actors. Every operator contract binds these roles explicitly. The source and receiving actors must be distinct. A data subject cannot be substituted into an operator role. A receiving operator cannot certify its own authority merely because it possesses the payload. A rollback executor cannot call its work independently certified unless the required independent review actually exists.

The actor rules protect Human Standing by keeping people upstream of operator-owned scores and identifiers. A synthetic subject identifier is a fixture attribute, not ownership of the person. Cognitive liberty and private lawful conduct remain hard constraints: curiosity, desire, nonconformity, private thought, and lawful conduct cannot be converted into dangerousness or guilt by a portability operation.

## 5. Operator and counterparty contracts

{table(['ID', 'Profile', 'Authority boundary', 'Maximum retention', 'Explicit unknowns'], op_rows)}

These profiles are intentionally not cosmetic copies. They differ in purpose, retention, disclosure, succession, emergency sunset, public/private boundaries, and permitted transformations. OPR-004 is a non-operational research sandbox. OPR-003 is a temporary emergency continuity profile with a fourteen-day default retention period and hard post-event review. OPR-005 permits only non-personal public publication. OPR-006 models successor custody after operator loss while refusing to treat possession as legitimacy.

Every contract declares unknowns. Unknown real jurisdiction, absent external reviewer, unknown production key custody, unknown search indexing, and unknown successor legitimacy do not become affirmative compatibility merely because a local fixture is internally coherent.

## 6. Adversarial portability trials

{table(['ID', 'Trial', 'Route', 'Expected outcome', 'Rights preserved', 'Limitation'], trial_rows)}

The canonical table is definition-only. During a runner execution, each row produces an identified result with input hashes, state transitions, actual outcome, equality propositions, authority-continuity state, rights preserved, rights impaired or unestablished, challenge state, correction effect, rollback reach, downstream recipients, and limitations.

Several design rules follow from the trial set:

- A blocked hostile transfer can be a successful rights-preserving outcome even though operational compatibility fails.
- Unknown fields are preserved opaquely or the transfer is rejected; they are never silently discarded or interpreted as authority.
- Dissent cannot be replaced with an aggregate confidence value.
- A live appeal moves with the record and bounds receiving use.
- Shorter retention can be selected as a protective partial result, but the report must not call it full compatibility.
- A non-comparable authority conflict remains unresolved; a local runner cannot decide real jurisdictional supremacy.
- Successor custody preserves rights and duties but does not prove successor legitimacy.
- Public or independently copied material creates an irreversibility boundary that a local rollback cannot erase.

## 7. Challenge state machine

{table(['State', 'Live challenge', 'Confidence may override'], state_rows)}

A challenge may dispute provenance, authority, purpose, transformation, disclosure, or completeness. The architecture requires acknowledgement, evidence handling, bounded use where necessary, available or unavailable review, determination or unresolved state, appeal, correction, downstream notice, and expiry. Invalid transitions are explicit fixtures and are executed as negative controls by the runner.

The central invariant is that no confidence score can erase a live challenge, dissent, uncertainty, missing evidence, or missing authority. `REVIEW_UNAVAILABLE` is not a successful review. `UNRESOLVED` is not implied permission. `EXPIRED` does not erase history; a later action requires a new identified process.

The protocol also separates procedural completion from substantive correctness. A path may be structurally valid while the merits remain unknown. Conversely, an apparently persuasive determination is invalid if it skipped requested evidence or reset an appeal without preserving lineage.

## 8. Correction dissemination and redress continuity

{table(['ID', 'Scenario', 'Expected state', 'Correction ID'], correction_rows)}

The correction graph distinguishes origin, current holder, downstream recipient, redistributor, correction recipient, nonreachable recipient, independent derived record, public index, receipt store, and review archive. The runner demonstrates bounded graph traversal, idempotent delivery, conflicting corrections, superseding corrections, withdrawal, recipient nonresponse, and explicit nonreachability.

A correction is not the same as deletion, rollback, revocation, compensation, restored access, notification, downstream invalidation, or historical preservation. Each proposition has a distinct receipt and scope. Repeating the same correction does not create duplicate substantive effects. A superseding correction retains the superseded record. A withdrawal is recorded rather than erasing its history. A nonresponsive or unreachable recipient is never counted as corrected.

Every human-facing correction explanation must answer:

- What changed?
- Who changed it?
- Under what authority?
- Which recipients were notified?
- Which recipients confirmed?
- What remains wrong, unresolved, or unreachable?
- What can the affected person do next?

## 9. Rollback and irreversibility

{table(['ID', 'Receipt template', 'Effect class', 'Proof obligations', 'Actual event'], rollback_rows)}

The four effect classes are **REVERSIBLE**, **COMPENSABLE**, **DISCLOSE_ONLY**, and **IRREVERSIBLE**. Only a fully bounded reversible effect can support a complete-rollback claim, and only when every proof obligation passes. Public disclosure, human memory, independent downstream decisions, model-training influence, unknown copies, and some legal-retention states may prevent complete restoration.

This architecture prevents “rollback theater.” Restoring a local flag does not undo a human decision. Deleting one controlled copy does not erase redistribution. Publishing a correction does not recall all readers. Compensation may remedy some consequences without recreating the prior world. A truthful receipt states both what was repaired and what remains outside the restoration boundary.

All canonical rollback receipt `actual_event` fields remain null. The local engine evaluates template logic and synthetic effect classes; it does not claim that any real rollback occurred.

## 10. Privacy-preserving disclosure boundaries

{table(['ID', 'Demonstration', 'Purpose', 'Method', 'Expected outcome'], disclosure_rows)}

The demonstrations use deterministic field allowlists, role and purpose gates, retention reduction, cognitive-liberty exclusions, and one salted SHA-256 commitment example. The commitment example demonstrates only that a local engine can emit a digest instead of the underlying fixture value. It is **not** zero knowledge, unlinkability, differential privacy, secure multiparty computation, cryptographic erasure, or production security certification.

A request for a minimum-age proof is blocked because no qualifying cryptographic primitive is implemented. The architecture prefers an explicit failure over a false privacy claim. Social-score export and marketing audience expansion are blocked as prohibited purposes. Restricted evidence content can remain withheld while a digest, classification, provenance, and challenge route are disclosed.

A human explanation must state what was proven, what was withheld, why, by whom, under what authority, for how long, and how to challenge the disclosure.

## 11. Tamper and mutation program

{table(['ID', 'Mutation', 'Detector', 'Required failure reason'], tamper_rows)}

Each detector creates or evaluates a deliberate negative condition and must fail for the intended reason. The runner tests manifest mismatch, omitted indirect input, substituted runner, unsafe ZIP path, duplicate ZIP member, stale baseline lock, substituted environment identity, actor-role substitution, authority escalation, purpose expansion, dissent deletion, correction-recipient deletion, rollback overclaim, receipt replay, report truncation, structured-data contradiction, null-to-pass mutation, and semantic-digest manipulation.

The tamper program is not a list of expected results copied into a report. Each detector executes code and records whether the intended mutation was observed. A detector that is disabled, returns the wrong reason, or permits the mutation fails the technical gate.

## 12. Deterministic execution and non-circular authentication

The runtime manifest authenticates every declared runtime data and code input except itself. That exclusion is explicit and unavoidable: a file cannot contain its own final cryptographic digest without a circular rule. The runner records the manifest’s runtime SHA-256, and the package checksum authenticates the archive containing the manifest and inputs. Generated run reports are outputs and do not authenticate themselves.

Each execution records:

- run identifier and UTC timestamp;
- execution class and environment/operator contract;
- root path, platform, architecture, Python implementation and version;
- locale, preferred encoding, timezone, path separator, line separator, case sensitivity, and Unicode probe;
- runner and engine SHA-256;
- manifest SHA-256 and every input SHA-256;
- structural assertions and failures;
- portability, challenge, correction, rollback, disclosure, and tamper results;
- semantic evidence digest excluding declared environment variance;
- retained environment-specific fields;
- network and model access flags and observed call counts;
- evidence paths, uncertainty, and limitations.

The working-tree, fresh-repository-extraction, and bounded-input-extraction runs are separately identified. Matching semantic digests support only the declared local synthetic projection. Different roots, timestamps, execution classes, and environment fields remain visible rather than being normalized away to manufacture byte identity.

## 13. Human legibility and accessibility

The release includes {accessibility['fixture_count']} definition-only human-legibility fixtures arranged in positive/negative pairs across challenge, correction, rollback, unresolved authority, appeal timing, dissent, selective disclosure, and correction failure. Every `actual_result` remains null because no participant evaluation occurred.

Public pages use answer-first summaries, one H1, skip links, semantic landmarks, descriptive links, table headers, visible evidence labels, and non-modal layouts. The site avoids a popup or fixed control that obscures the research surface. Keyboard navigation remains available through the existing responsive menu, and no new interactive component requires pointer-only operation.

Legibility is a hard gate rather than a compensable score. A fluent sentence such as “the system handled the matter successfully” is materially incomplete when it hides a live challenge, unresolved authority, unreachable recipient, dissent, or irreversible effect.

## 14. Machine assistance at the point of use

The machine-assistance disclosure applies to the new registries, pages, DOC-055, runner, validator, release notes, and successor prompt. It records the model identity when known, branch and snapshot lineage, sanitized inputs, deterministic state, what the machine added, evidence used, uncertainty, limitations, and authoritative status.

Machine-generated explanation remains separate from authoritative source text. In this repository, the authoritative technical inputs are the exact canonical registries and code. The prose is an assisted interpretation of those inputs and must not silently outrank them. Because the artifact runtime does not expose a per-call identifier, that field remains null with status `NOT_EXPOSED_TO_ARTIFACT_RUNTIME` rather than being invented.

## 15. Human-rights implications

Portability is constitutionally consequential when transfer changes who can know, infer, retain, disclose, decide, coerce, or correct. The architecture therefore preserves:

- **Human Standing:** people remain rights-bearing subjects, not operator-owned scores.
- **Cognitive liberty:** private thought, lawful desire, curiosity, and nonconformity are not portable guilt signals.
- **Purpose limitation:** receipt does not authorize unrelated use.
- **Plurality and dissent:** minority reasoning and recusal survive transfer.
- **Meaningful challenge and appeal:** deadlines, stays, unavailable evidence, and unresolved review remain visible.
- **Least-irreversible action:** contested authority or incomplete evidence bounds use before irreversible harm.
- **Correction propagation:** downstream recipients are tracked, including nonresponse and nonreachability.
- **Restoration honesty:** reversible, compensable, disclose-only, and irreversible effects are not collapsed.

These are design commitments in a synthetic local framework. They are not findings about any real institution and are not legal advice.

## 16. Development failures and owning corrections

The most important failure is not a code defect: the required sealed v0.20 source lineage is absent. The correct response is not to relabel v0.18 as v0.20, copy a green status from a diagnostic record, or suppress ZIP delivery. The branch records the missing artifacts, continues substantive work, and emits `-wip.zip` packages.

The implementation also treats the following as owning-surface rules:

- canonical trial definitions retain null outcomes; run reports own executed results;
- registries own facts and counts; pages derive from registries;
- the runtime-input manifest owns the authenticated input inventory;
- the runner owns local executed evidence;
- the release validator owns current technical gates and WIP classification;
- public JSON and source endpoints reproduce exact canonical bytes;
- package policy owns internal/public separation;
- checksum records authenticate final emitted archives.

No generated page is manually patched to create an unsupported pass. When a derived surface is wrong, the current builder or registry is corrected and dependents are regenerated.

## 17. Material limitations and nonclaims

This branch does not establish:

1. a continuous sealed v0.19 → v0.20 → v0.21 release lineage;
2. external-machine, remote, third-party, or independent execution;
3. production migration, interoperability, rollback, disclosure, or correction;
4. legal authority, legal compliance, constitutional acceptance, or sovereign recognition;
5. human-participant legibility, accessibility, or usability outcomes;
6. cryptographic zero knowledge, unlinkability, differential privacy, multiparty computation, or erasure;
7. production privacy, security, safety, performance, or resilience;
8. search indexing, ranking, crawler visitation, or AI-system citation;
9. deployment, DNS mutation, hosting action, credential use, or external service change;
10. external Eviulon or Evulgare reobservation.

The local evidence supports a narrower statement: the identified repository-owned synthetic engine can reproduce the declared structural, portability, challenge, correction, rollback, disclosure, and tamper results over authenticated inputs in the tested local execution classes.

## 18. Public architecture

The v0.21 lineage-recovery layer publishes the following human-readable surfaces and exact JSON interfaces:

- `/observation/operator-contracts/` ↔ `/data/operator-contracts/`
- `/observation/adversarial-portability/` ↔ `/data/adversarial-portability/`
- `/observation/challenge-state-machine/` ↔ `/data/challenge-protocol/`
- `/observation/correction-dissemination/` ↔ `/data/correction-dissemination/`
- `/observation/rollback-irreversibility/` ↔ `/data/rollback-irreversibility/`
- `/observation/disclosure-boundaries/` ↔ `/data/disclosure-demonstrations/`
- `/observation/counterparty-tamper-lab/` ↔ `/data/counterparty-tamper/`
- `/observation/reproduction-limitations/` ↔ `/data/reproduction-limitations/`
- `/observation/machine-assistance-v021/` ↔ `/data/machine-assistance-disclosures/`
- `/data/v021-accessibility-fixtures/`
- `/data/v021-executions/`

DOC-055 is published at `/docs/55-adversarial-portability-challenge-redress-continuity/`, with its exact Markdown source at `/docs/55-adversarial-portability-challenge-redress-continuity/source/`.

## 19. Reproduction command

The repository execution command is:

```bash
python scripts/run-v021-adversarial-portability.py \
  --root . \
  --run-id <identified-run-id> \
  --execution-class <working_tree_local|fresh_repository_extraction|bounded_input_extraction> \
  --environment-contract OPR-004 \
  --output <identified-report-path>
```

The bounded input archive retains the same relative paths and contains the exact runtime manifest, runner, engine, and registries. Its extracted command runs without reference to the source worktree.

## 20. Conclusion

Rights-preserving portability is not a transport success state. It is a bounded proof problem across data fidelity, operational behavior, authority, purpose, privacy, dissent, challenge, correction, retention, rollback, and human legibility. The v0.21 local architecture makes those propositions explicit and adversarially tests them without claiming more than the evidence supports.

The most important release conclusion is also the simplest: **technical success does not repair missing provenance.** Even with passing local runs, the absent sealed v0.20 lineage requires WIP classification. The repository and deployable root are therefore delivered as versioned WIP ZIPs rather than withheld or falsely labeled final.

## Appendix A — Canonical owners

- `data/_source/operator-contracts.json`
- `data/_source/adversarial-portability.json`
- `data/_source/challenge-protocol.json`
- `data/_source/correction-dissemination.json`
- `data/_source/rollback-irreversibility.json`
- `data/_source/disclosure-demonstrations.json`
- `data/_source/counterparty-tamper.json`
- `data/_source/reproduction-limitations.json`
- `data/_source/v021-accessibility-fixtures.json`
- `data/_source/machine-assistance-disclosures.json`
- `data/_source/v021-lineage-lock.json`
- `data/_source/v021-release-contract.json`
- `data/_source/v021-runtime-inputs.json`
- `scripts/v021_engine.py`
- `scripts/run-v021-adversarial-portability.py`

## Appendix B — Machine-assistance record

The exact machine-assistance disclosure is reproduced below for audit convenience. The canonical JSON endpoint remains the owning machine-readable surface.

```json
{json.dumps(assistance['disclosures'][0], ensure_ascii=False, indent=2)}
```
