{
 "results": [
  {
   "_digests": {
    "assurance": "1d826f6d868fed31aac3216c7a936b7aa6ed46d24268e5e2048a3bcbea4b728b",
    "cleanroom": "4893bd49ed88200b82aaf1459fc88a125b06d7e8b1c61b75d11f9c866dabd189",
    "contract": "eab0641ecd82a2f6226efb69e19efde2aef3713369e05f07c5b8af9e003cd15d",
    "rig": "4eb70110342694a86abe94a89070cbd21b5f69af81141b5b7ff7cce65b59f811"
   },
   "claim": "Over the 12-dimension fault lattice, exactly one point (no faults) is ALLOW, and decide() and the clean-room verifier both return the model's first-failing-guard reason at every point.",
   "counterexamples": [],
   "counts": {
    "allow": 1,
    "cleanroom_mismatch": 0,
    "points": 435456,
    "runtime_mismatch": 0
   },
   "does_not_prove": "inputs outside the lattice; correctness of the guards' own predicates on other values",
   "exhaustive": true,
   "lattice_size": 435456,
   "method": "exhaustive_over_abstraction",
   "ok": true,
   "property": "DECIDE_CONFORMS_TO_ORDERED_GUARD_MODEL",
   "reasons": {
    "AUTHORITY_AMPLIFICATION": 1008,
    "AUTHORITY_CHAIN_MISMATCH": 1008,
    "AUTHORITY_REVOKED": 1008,
    "AUTHORITY_SUBJECT_MISMATCH": 1008,
    "AUTHORITY_UNAVAILABLE": 1008,
    "AUTHORITY_UNKNOWN_AGENT": 1008,
    "CONDITION_ARGV0_IN": 4,
    "ENVIRONMENT_DRIFT": 252,
    "EXPIRED": 36288,
    "IDENTITY_SUBSTITUTION": 1008,
    "MALFORMED_REQUEST": 14,
    "MODEL_SUBSTITUTION": 1512,
    "NOT_YET_VALID": 36288,
    "OK": 1,
    "POLICY_DRIFT": 84,
    "POLICY_UNAVAILABLE": 84,
    "POP_INVALID": 8,
    "POP_MALFORMED": 8,
    "POP_MISSING": 8,
    "POP_REPLAY": 8,
    "POP_REQUEST_MISMATCH": 8,
    "POP_STALE": 8,
    "QUORUM_MISSING": 1,
    "REQUEST_NOT_PINNED": 14,
    "RESOURCE_OUTSIDE_CONTRACT": 2,
    "STALE_EPOCH": 9072,
    "STATE_REVOKED": 108864,
    "TENANT_MISMATCH": 217728,
    "USES_EXHAUSTED": 18144
   },
   "seconds": 324.32
  },
  {
   "claim": "exhaustive over the lifecycle table the runtime enforces",
   "does_not_prove": "that every code path routes state changes through _transition() (see trace checks)",
   "edges": 22,
   "method": "explicit_state_model_check",
   "ok": true,
   "properties": [
    {
     "counterexample": null,
     "detail": "every state has a row and every target is a declared state",
     "ok": true,
     "property": "TABLE_CLOSED"
    },
    {
     "counterexample": null,
     "detail": "no transition leaves CONSUMED/EXPIRED/REVOKED/...",
     "ok": true,
     "property": "TERMINALS_ARE_SINKS"
    },
    {
     "counterexample": null,
     "detail": "the transition graph is acyclic",
     "ok": true,
     "property": "NO_CYCLES_EVERY_RUN_TERMINATES"
    },
    {
     "counterexample": null,
     "detail": "longest run from DRAFT has 5 transitions",
     "ok": true,
     "property": "BOUNDED_RUN_LENGTH"
    },
    {
     "counterexample": null,
     "detail": "every non-terminal state can reach a terminal one",
     "ok": true,
     "property": "NO_LIVE_DEADLOCK"
    },
    {
     "counterexample": null,
     "detail": "removing PROPOSED, VALIDATED or AUTHORIZED makes ACTIVE unreachable from DRAFT",
     "ok": true,
     "property": "ACTIVE_ONLY_VIA_VALIDATED_AND_AUTHORIZED"
    },
    {
     "counterexample": null,
     "detail": "no transition re-enters DRAFT",
     "ok": true,
     "property": "NO_REGRESSION_TO_DRAFT"
    },
    {
     "counterexample": null,
     "detail": "REVOKED is a legal next state from every live state",
     "ok": true,
     "property": "REVOCATION_NEVER_OPTIONAL"
    },
    {
     "counterexample": null,
     "detail": "predecessors of ACTIVE: ['AUTHORIZED']",
     "ok": true,
     "property": "ONLY_AUTHORIZED_ENTERS_ACTIVE"
    }
   ],
   "property": "LIFECYCLE_MODEL",
   "states": 12
  },
  {
   "method": "trace_property",
   "mismatches": [],
   "ok": true,
   "property": "Z3_ENCODING_FAITHFUL",
   "samples": 300
  },
  {
   "assumed_lemmas": [
    "L1a'': a non-empty string of only '/' ends in '/' (definition of str.rstrip; z3 regex reasoning times out on it; covered by the bounded check and encoding differential)"
   ],
   "bounded_exhaustive": {
    "accepted_pairs": 18912,
    "bounds": {
     "alphabet": "ab/*.",
     "max_res_len": 6,
     "max_scope_len": 5
    },
    "counterexamples": [],
    "method": "bounded_exhaustive",
    "ok": true,
    "property": "DELEGATION_SCOPE_ATTENUATION",
    "resources": 3923,
    "scopes": 3066,
    "seconds": 41.73
   },
   "cases": [
    {
     "case": "L1b",
     "result": "UNSAT",
     "seconds": 0.02
    },
    {
     "case": "L1a_prime",
     "result": "UNSAT",
     "seconds": 0.0
    },
    {
     "case": "PW",
     "result": "UNSAT",
     "seconds": 0.01
    },
    {
     "case": "parent_star",
     "result": "UNSAT",
     "seconds": 0.0
    },
    {
     "case": "child_star_parent_not",
     "result": "UNSAT",
     "seconds": 0.0
    },
    {
     "case": "parent_prefix_child_concrete",
     "result": "UNSAT",
     "seconds": 0.01
    },
    {
     "case": "parent_prefix_child_prefix",
     "result": "UNSAT",
     "seconds": 0.0
    },
    {
     "case": "parent_concrete_child_prefix",
     "result": "UNSAT",
     "seconds": 0.01
    },
    {
     "case": "parent_concrete_child_concrete:equal",
     "result": "UNSAT",
     "seconds": 0.0
    },
    {
     "case": "parent_concrete_child_concrete:parent_root",
     "result": "UNSAT",
     "seconds": 0.07
    },
    {
     "case": "parent_concrete_child_concrete:below:res_eq_child",
     "result": "UNSAT",
     "seconds": 0.0
    },
    {
     "case": "parent_concrete_child_concrete:below:res_below_child",
     "result": "UNSAT",
     "seconds": 0.0
    },
    {
     "case": "parent_concrete_child_concrete:below:child_not_root",
     "result": "UNSAT",
     "seconds": 0.0
    }
   ],
   "claim": "for all strings, under RIG's stored-scope normalization: a delegated child scope never covers a resource its parent does not; by induction over hops, the same holds for chains of any depth",
   "complete": true,
   "method": "smt_proof",
   "ok": true,
   "precondition": "scopes as RIG stores them: non-empty, no trailing '/' unless exactly '/', or '*'; resource contains no '*'",
   "property": "DELEGATION_SCOPE_ATTENUATION",
   "proved_cases": [
    "L1b",
    "L1a_prime",
    "PW",
    "parent_star",
    "child_star_parent_not",
    "parent_prefix_child_concrete",
    "parent_prefix_child_prefix",
    "parent_concrete_child_prefix",
    "parent_concrete_child_concrete:equal",
    "parent_concrete_child_concrete:parent_root",
    "parent_concrete_child_concrete:below:res_eq_child",
    "parent_concrete_child_concrete:below:res_below_child",
    "parent_concrete_child_concrete:below:child_not_root"
   ],
   "unnormalized": {
    "case": "UNNORMALIZED_PRECONDITION_DROPPED",
    "counterexample": {
     "child": "C///",
     "parent": "C//*",
     "resource": "C/KR"
    },
    "normalization_refuses_it": true,
    "still_a_counterexample": true
   }
  },
  {
   "allows": 43,
   "invokes": 292,
   "method": "trace_property",
   "ok": true,
   "property": "TEMPORAL_TRACE_PROPERTIES",
   "runs": [
    {
     "allows": 2,
     "invokes": 30,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000152000,
     "seed": 1,
     "steps": 80,
     "transitions": 67,
     "violations": []
    },
    {
     "allows": 1,
     "invokes": 33,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000334000,
     "seed": 2,
     "steps": 80,
     "transitions": 51,
     "violations": []
    },
    {
     "allows": 6,
     "invokes": 37,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000163000,
     "seed": 3,
     "steps": 80,
     "transitions": 65,
     "violations": []
    },
    {
     "allows": 6,
     "invokes": 38,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000081000,
     "seed": 4,
     "steps": 80,
     "transitions": 86,
     "violations": []
    },
    {
     "allows": 12,
     "invokes": 47,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000073000,
     "seed": 5,
     "steps": 80,
     "transitions": 53,
     "violations": []
    },
    {
     "allows": 7,
     "invokes": 36,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000142000,
     "seed": 6,
     "steps": 80,
     "transitions": 73,
     "violations": []
    },
    {
     "allows": 4,
     "invokes": 36,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000162000,
     "seed": 7,
     "steps": 80,
     "transitions": 74,
     "violations": []
    },
    {
     "allows": 5,
     "invokes": 35,
     "method": "trace_property",
     "ok": true,
     "property": "TEMPORAL_TRACE_PROPERTIES",
     "rig_revoked_at": 1790000161000,
     "seed": 8,
     "steps": 80,
     "transitions": 72,
     "violations": []
    }
   ]
  }
 ],
 "schema": "cain.assurance.v1",
 "seconds": 390.8
}
