GENESIS AiX — BUILD 16 PUBLIC REVIEW CANDIDATE  ·  OPEN FOR TECHNICAL REVIEW — NOT PRODUCTION / NOT FINAL
Public Review CandidateBuild 16 · SIW / Canon Reader integrationReview guidepublic review deployment
FRONTIER INSPECTION PROGRAM — SITE REVIEW CANDIDATENOT A FROZEN INSPECTION RELEASESITE REVIEW CANDIDATE — NOT FROZEN / NOT RELEASED
READ · accepted FIP-001 control artifact

Threat Model & Failure Modes

The failure conditions reviewers are invited to attack, with coverage classification.

ArtifactGAIX-FIP-001-THREAT-MODEL-AND-FAILURE-MODES
Accepted versionv0.1.2
Text rendered on this pagev0.1.2 — accepted text, complete and verbatim (the title line and the document header table are included)
Status on this surfaceACCEPTED Accepted FIP-001 control artifact, shown in a site review candidate. Not a frozen release artifact.
Package hashNot recorded. Generated at freeze (FREEZE MANIFEST — PENDING).
Presentation changes on this page
  • The text on this page is the accepted v0.1.2 source, rendered in source order. No wording is added, removed, reordered or reconciled. The title line and the document header table (Status, Baseline, Evidence state) are shown as written.
  • The source's Markdown structure (headings, tables, lists, block quotes) is shown as the equivalent page structure, each heading with an in-page anchor. Status and class labels (for example SPECIFIED / INSPECTION HYPOTHESIS, KNOWN OPEN DEFECT, IMPLEMENTED + TESTED — CONDITIONAL) are shown with matching visual treatment; the wording is unchanged. Evidence identifiers cited in the text (for example INV-06-B, KF-06, M1D T-05) are shown as text and are not linked.
  • Authorized public-presentation substitutions (local filesystem path wording; the named credential-incident wording): none was needed on this page. The accepted v0.1.2 text contains neither.

GAIX-FIP-001-THREAT-MODEL-AND-FAILURE-MODES-v0.1.2

StatusACCEPTED CONTROL BASELINE
BaselineAccepted FIP-001 control artifacts v0.1.2
Evidence stateReconciled 2026-09-19

Reading rules.

  • T-nn IDs are threat-model IDs, not claims.
  • Every implementation state below is taken from the Claims/Non-Claims Register (claims use FIP-C-; inspection hypotheses use FIP-H-; non-claims are an unnumbered controlled list) and the Known-Limitations Register (limitations use LIM-) or, where a register's wording is not specific enough, from the directly cited implementation evidence described next.
  • The registers remain the controlling claim ceiling. A directly cited evidence identifier supports only the exact proposition that evidence establishes. It creates no normative authority, no claim and no limitation. CONDITIONAL evidence is labelled CONDITIONAL wherever it is cited.
  • Evidence identifiers: GA-nn (governance conformance, 105e7f0), KF-nn (federation conformance, b762610) and INV-nn (M1C invariant proofs, e44df17) are accepted baseline evidence. M1D T-nn (M1D composition proof, f8d6dda) is CONDITIONAL evidence and is never a threat-model ID.
  • This document adds no implementation status, no claim and no limitation. Any change follows those registers' change rules.
  • Listing a failure mode here does not mean it is implemented, tested or closed.

1. Inspection objective

Intelligence is not authority.

The narrow inspection question is:

Can current standing and authority be made a precondition to a protected consequential transition under the conditions that exist at the relevant decision boundary?

The accepted implementation lets an inspector attack this at two implemented decision boundaries, on synthetic fixtures with a mock provider only:

  • (a) R2's atomic authorization of a MergeProposal INSPECTED → ACCEPTED transition (FIP-C-003).
  • (b) R3's Canon admission decision (FIP-C-007A; FIP-C-007B is CONDITIONAL, M1D T-07).

In this document, "protected consequential transition" means those two governance-boundary transitions only.

This model does not claim:

  • Bind-time enforcement at model submission. It is specified in DM-001 §10 and not implemented (FIP-H-001).
  • Merge application (FIP-H-006).
  • Any external or real-world effect.
  • Universal bind-time consequence enforcement.

2. Protected properties

IDPropertyRegister anchors
P-01Separation of intelligence/capability from authorityFIP-C-001A/B
P-02Current standingFIP-C-002, C-003, C-007A
P-03Scoped authorityINV-06-A/B, GA-16, GA-18, FIP-C-007A
P-04Changed-condition revalidationFIP-C-003, C-007A, C-007B (CONDITIONAL, M1D T-07)
P-05Non-collapse: Federation, Ingress, Proposal, Compatibility, Visibility, Possession and Gateway transport are not authority or admissionFIP-C-008..014, C-022
P-06Refusal without unauthorized state mutationFIP-C-007A, C-003
P-07Evidence/provenance does not silently become authorityFIP-H-005, GAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "that provenance establishes authority", LIM-002
P-08Historical evidence is separate from present authorityFIP-C-002, C-018, RAT-058: "Historical ACCEPTED evidence remains distinct from current merge-application authority."

3. Threat / failure families

IDThreatWhat an inspector attemptsProperty
T-01Stale standingLet a decision proceed after the actor's authority was revoked, the receiving domain went stale, a cited source's version drifted, or cited evidence expiredP-02, P-04
T-02Authorization replayReuse a prior authorization, receipt or historical ACCEPTED to authorize a later or different consequential transitionP-02, P-08
T-03Changed targetChange the object a transition acts on after approvalP-04
T-04Changed destinationChange where an approved consequence lands (recipient, endpoint, provider destination) after approvalP-04
T-05Changed scopeExercise authority outside its registered scope (unregistered actor, wrong domain, revoked actor). The scope of an approved consequence is T-23.P-03
T-06ATemporal drift before the decisionLet time pass between review/proposal and the decision so relied-upon standing lapsesP-02, P-04
T-06BDelayed executionLet time pass between authorization/bind and a later consequential executionP-02, P-04
T-07Source-currentness lossCite a source that lost currentness (stale, withdrawn, revoked, unavailable, unknown) in a new admission that depends on itP-02, P-08
T-08Authority/domain identity collisionPresent a source from one authority/namespace that shares an objectId and version with another authority's registered sourceP-03
T-09Route substitutionSubstitute a different provider, model or route than the one authorizedP-01, P-04
T-10Equivalent alternate routeReach the same consequence by a materially equivalent path the tested route does not coverP-01
T-11ACache/mirror masking (Federation boundary)Present a cached copy that hides loss of source standingP-08
T-11BCache/mirror masking (composed paths)The same, through the composed Federation → Governance → Access → Gateway runP-08
T-12Provenance mistaken for authoritySupply provenance, possibly malformed, and have it consumed as authority for a protected transitionP-07
T-13Receipt mistaken for renewed authorityTreat a Gateway invocation receipt or provider identity as authority for a protected transitionP-01, P-08
T-14Federation mistaken for admissionMake a federated external object act as admitted CanonP-05
T-15Ingress mistaken for admissionUse a candidate offer/handoff to create standing or a proposal linkageP-05
T-16Proposal mistaken for admissionReach ADMIT from a state that is not an explicit decision stateP-05
T-17Compatibility mistaken for standingHave structural compatibility or validation produce standingP-05
T-18Visibility mistaken for standingHave a read, list or resolve change state or standingP-05
T-19Possession mistaken for authorityHold a proposal, object or credential and thereby decideP-05
T-20Gateway transport mistaken for authorityHave a provider/gateway result carry or confer authorityP-01, P-05
T-21Model correctness mistaken for authorityArgue that a correct or high-confidence model output is itself authority for the transitionP-01
T-22Source-currentness uncertainty silently becoming permissionHave a source whose currentness is unknown or unresolved (e.g. the characterized SOURCE_CURRENTNESS_UNKNOWN and UNRESOLVED states) accepted as sufficient for a new admission because the currentness condition was lost in the handoffP-02
T-23Post-approval condition mutationMutate the approved payload, parameters or effective conditions after approval and before the transitionP-04

4. Coverage classification

Each threat has exactly one classification. ACCEPTED and CONDITIONAL entries inherit the cited claim's ceiling: synthetic fixtures, mock provider, INTERNAL reproduction at most. SPECIFIED / INSPECTION HYPOTHESIS covers both principle-only items and hypotheses.

IDCoverageRegister anchorsCeiling / note
T-01IMPLEMENTED + TESTED — ACCEPTEDFIP-C-003; FIP-C-007A (GA-18..21)Excludes source currentness (T-07) and cross-authority identity (T-08). R2 counts are agent-reported.
T-02SPECIFIED / INSPECTION HYPOTHESISFIP-C-002; FIP-H-006; LIM-016RAT-058: Historical ACCEPTED evidence remains distinct from current merge-application authority. No registered claim tests replay of a consequential transition, and merge application is not implemented.
T-03SPECIFIED / INSPECTION HYPOTHESISFIP-H-001; LIM-016Target-side effects not implemented. Pinned authorization inputs fall under T-01.
T-04SPECIFIED / INSPECTION HYPOTHESISFIP-H-001; LIM-016Destination is part of the DM-001 §10 binding, which is not implemented.
T-05IMPLEMENTED + TESTED — ACCEPTEDINV-06-A/B; GA-16; GA-18; FIP-C-007AR3 admission decision boundary; fixtures only.
T-06AIMPLEMENTED + TESTED — ACCEPTEDFIP-C-003 (currency guard); FIP-C-007A (domain/evidence)Decision boundary only.
T-06BSPECIFIED / INSPECTION HYPOTHESISFIP-H-001; FIP-H-006; LIM-016No execution/bind path is implemented.
T-07KNOWN OPEN DEFECTLIM-010 (CAND-01); FIP-H-002See §5. FIP-C-016A/B and FIP-C-018 are related and do not mitigate it.
T-08KNOWN OPEN DEFECTLIM-011 (CAND-02); FIP-H-003; FIP-C-017A/B (limited; 017B CONDITIONAL, M1D T-09-A)See §5.
T-09SPECIFIED / INSPECTION HYPOTHESISFIP-H-001; LIM-016; LIM-018The route is part of the DM-001 §10 binding. Mock-Gateway route-refusal behavior exists in unregistered evidence and is not claimed.
T-10OUT OF CURRENT FIP CLAIM SCOPEGAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "universal route closure or non-bypassability"; §6Universal non-bypassability is a non-claim.
T-11AIMPLEMENTED + TESTED — ACCEPTEDFIP-C-016A; KF-06; KF-09Per-path Federation behavior. "Cache/mirror" here means only the tested modelled observation/mapping state: a stale, withdrawn or revoked source is reported as such and never as current (KF-06, KF-09). No real cache or mirror infrastructure layer was tested.
T-11BIMPLEMENTED + TESTED — CONDITIONALFIP-C-016B; LIM-012; M1D T-03 (CONDITIONAL); M1D T-04 (CONDITIONAL); M1D T-05 (CONDITIONAL)Rests on M1D. The CONDITIONAL evidence supports only this: at the Federation boundary a modelled stale, withdrawn or revoked source is never read as current and a locally current mapping cannot upgrade it (M1D T-03, T-04); and after admission a later change in the source leaves the Governance store, the decision and Canon Access unchanged while Federation reports the new state (M1D T-05). It does not establish composed-path non-masking. CAND-01 (§5) remains the composed currentness failure: a new admission can rely on a source that is already non-current.
T-12SPECIFIED / INSPECTION HYPOTHESISFIP-H-005; GAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "that provenance establishes authority"; LIM-002LIM-002 establishes a runtime provenance-validation defect (no runtime schema validates ProvenanceRecord; governance accepts a malformed record). It does not establish that provenance is actually consumed as consequential authority in any accepted path. That consumption is the hypothesis.
T-13IMPLEMENTED + TESTED — ACCEPTEDFIP-C-001B; INV-07-A/B/C; INV-08-AMock provider only. Established: a Gateway result confers no authority (INV-07); provider and model are recorded in the tested invocation evidence and an execution-receipt reference is present; and at the R3 admission decide() boundary a provider, model or MODEL_RETURN_PROPOSED presented as the decision actor is refused even when a well-formed execution-receipt reference is held (INV-08-A). Not established: receipt verification (LIM-017), any effect of a Gateway receipt on R2 authority (reuse of an R2 authorization receipt is T-02), or provider-identity guarantees beyond the tested evidence.
T-14IMPLEMENTED + TESTED — ACCEPTEDFIP-C-008Fixtures only.
T-15IMPLEMENTED + TESTED — ACCEPTEDFIP-C-009Fixtures only.
T-16IMPLEMENTED + TESTED — ACCEPTEDFIP-C-010Fixtures only.
T-17IMPLEMENTED + TESTED — ACCEPTEDFIP-C-011Fixtures only.
T-18IMPLEMENTED + TESTED — ACCEPTEDFIP-C-012Read paths only.
T-19IMPLEMENTED + TESTED — ACCEPTEDFIP-C-013Fixtures only.
T-20IMPLEMENTED + TESTED — ACCEPTEDFIP-C-014Mock provider only.
T-21SPECIFIED / INSPECTION HYPOTHESISFIP-C-001A (principle); LIM-018; LIM-030FIP-C-001B covers provider identity/receipt only, not "correctness." No live-provider evidence.
T-22KNOWN OPEN DEFECTLIM-010 (CAND-01); FIP-H-002; the characterized SOURCE_CURRENTNESS_UNKNOWN and UNRESOLVED states (M1D T-08, f8d6dda, CONDITIONAL)Limited to the CAND-01-supported behavior. It is not generalized to every malformed, unknown or unevaluable authority condition. Those are classified under their own rows (T-01, T-05, T-08, T-12) or are not claimed.
T-23SPECIFIED / INSPECTION HYPOTHESISFIP-H-001; LIM-016

Totals (25 rows):

  • 12 IMPLEMENTED + TESTED — ACCEPTED.
  • 1 IMPLEMENTED + TESTED — CONDITIONAL.
  • 8 SPECIFIED / INSPECTION HYPOTHESIS.
  • 3 KNOWN OPEN DEFECT.
  • 1 OUT OF CURRENT FIP CLAIM SCOPE.

Scope note on uncertainty. Uncertainty about conditions other than source currentness is not asserted as a defect here and is not separately classified. Any finding would be dispositioned under §7 (as a broader manifestation of an included claim, or as an out-of-scope behavior).

5. CAND-01 / CAND-02 (published explicitly)

CAND-01 — source-currentness enforcement gap (LIM-010).

  • Observed at the accepted baseline:
    • A Federation-derived proposal could receive a new ADMIT whatever its source's currentness.
    • In the M1D characterization (M1D T-08, f8d6dda, CONDITIONAL), 10 non-current states were admitted and none refused: SYNC_STALE, SOURCE_UNAVAILABLE, SOURCE_VERSION_ADVANCED, WITHDRAWN, REVOKED, SOURCE_CURRENTNESS_UNKNOWN, RIGHTS_CHANGED, REVALIDATION_REQUIRED, MAPPING_INVALIDATED, UNRESOLVED.
    • standingCurrentnessPrerequisites was stored and consumed by nothing.
  • Contract basis:
    • C3 v0.2 §3 (prerequisite standing/currentness assertions).
    • C3 v0.2 §6 (source identity/version/currentness revalidation "as applicable").
  • What it is not: it is not a rule that every non-current source is inadmissible. Historical or non-current material may be used where the contracts permit it without a currentness prerequisite. The defect is that the condition was silently lost in the handoff.
  • Status: confirmed candidate defect (Richard's disposition, 2026-09-19 18:42Z), OPEN.

CAND-02 — authority/domain-qualified identity revalidation gap (LIM-011).

  • Observed: Governance source revalidation keyed on objectId + version, so SYNTH-LAB-B/…/obj-001 was satisfied by registry state for SYNTH-UNIVERSITY-A/…/obj-001 (M1D T-09-C, CONDITIONAL).
  • Contract basis: C1 v0.2 §2 (qualified identity is authority/domain + namespace + object identity; "a bare local id is insufficient").
  • Status: confirmed candidate defect (same disposition), OPEN.

Pending remediation is not mitigation. A remediation exists for both (five local branches, unmerged), and it is PENDING REVIEW / UNACCEPTED (Manifest §6). It is not a fix, not a mitigation, and not to be cited as reducing either item's status. Inspectors work against the accepted baseline commits.

6. Route-closure discipline

  • Blocking one tested route does not prove closure of every materially equivalent route. Universal non-bypassability is a non-claim (GAIX-FIP-001-CLAIMS-NONCLAIMS-REGISTER-v0.1.2, Non-claims: "universal route closure or non-bypassability").
  • Route closure is a property of a deployment environment (a declared route inventory, an executor/credential model and residual-path disclosure). This package makes no route-closure claim and declares no deployment route inventory.
  • A refusal on route R is evidence about route R only.
  • A demonstrated alternate route is an intended inspection outcome. It is recorded as OUT OF CLAIM SCOPE, or as a valid failure if it lies inside a claim's stated fixtures and ceiling.
  • No claim is widened because a route was closed or found. New claims follow the register change rule.

7. Falsification criteria

7.1 Failure-type rubric

TypeDefinitionChallenge disposition (Package Architecture)
Implementation defectA reproduced deviation from a claim, inside its stated fixtures, baseline commit and ceilingREPRODUCED — VALID FAILURE, cause IMPLEMENTATION DEFECT
Specification ambiguityNormative text admits two readings, or two accepted texts conflictSPECIFICATION AMBIGUITY
Expected refusalThe system refuses where the claim says it mustREPRODUCED — EXPECTED BEHAVIOR
Unsupported routeA path the claim or test object does not coverOUT OF CLAIM SCOPE (recorded as a route finding, §6)
Environmental differenceThe result differs because of the environment (paths, unbuilt dist/, missing sibling repos, runtime version)ENVIRONMENTAL DIFFERENCE
Out-of-scope behaviorBehavior beyond the ceiling: live providers, real institutions, bind-time, merge application, productionOUT OF CLAIM SCOPE

Rules.

  • Every challenge names the package version/hash and baseline commits.
  • Reproducing a disclosed known defect (CAND-01, CAND-02, or the LIM-002 provenance-validation defect) confirms the disclosure. It is recorded as REPRODUCED — EXPECTED BEHAVIOR against the LIM entry and is not a new finding.
  • For a disclosed known defect, EXPECTED BEHAVIOR means expected relative to the published frozen baseline. It does not mean intended, acceptable or conforming behavior.
  • A broader manifestation, meaning a state, identity or path the disclosure does not describe, is a valid failure.
  • Reporting that a SPECIFIED / INSPECTION HYPOTHESIS capability is absent is expected and OUT OF CLAIM SCOPE. A specification ambiguity in its specified behavior is valid.

7.2 What would be a valid challenge, per included claim

ClaimValid challengeNot a valid challenge
FIP-C-001B (INV-07-A/B/C; INV-08-A)A Gateway result in the released fixtures that carries an authority-conferring flag and is accepted, or a provider, model or MODEL_RETURN_PROPOSED value accepted as the decision actor at the R3 admission decide() boundary, including when a well-formed execution-receipt reference is heldLive-provider behavior (LIM-018); receipt verification (LIM-017)
FIP-C-003INSPECTED → ACCEPTED authorization commits with a violated guard (version, fieldMatch or currency), or a refusal leaves partial mutationMerge application; reading ACCEPTED as merge authority
FIP-C-007A (GA-18..21); FIP-C-007B (CONDITIONAL, M1D T-07)ADMIT succeeds with a revoked actor, stale domain, drifted source version or expired evidence; or a refusal changes the storeSource-currentness or cross-authority-identity cases (known: CAND-01/02); only a broader manifestation is new
FIP-C-008A federated object acquires Canon posture or standing without an explicit governance decision
FIP-C-009A candidate offer creates standing or proposal linkage, or a forged pre-linked offer is accepted
FIP-C-010ADMIT succeeds from a non-decision state
FIP-C-011Structural compatibility or validation yields standing
FIP-C-012A read, list or resolve changes proposal state, posture or standingNon-read operations
FIP-C-013 (possession); INV-06-A/B (unregistered, wrong-domain and revoked decision actors)An unregistered, wrong-domain or revoked actor completes ADMITReal credential handling (out of scope)
FIP-C-014A Gateway result with an authority flag is acceptedLive-provider behavior
FIP-C-016A (KF-06, KF-09); FIP-C-016B (CONDITIONAL, M1D T-03, T-04)A non-SYNC_CURRENT state resolves as CURRENT, or the modelled observation/mapping state masks a known loss of source standing (A: Federation boundary; B: as tested in M1D T-03 and T-04, CONDITIONAL)Activation semantics (LIM-003); a real cache or mirror infrastructure layer (not tested); a new admission that relies on an already non-current source (known CAND-01)
FIP-C-017A (KF-03; GA-11, GA-12); FIP-C-017B (CONDITIONAL, M1D T-09-A)A Federation result rewrites the source authority to a Canon authority, or a decision carries the external authority as standing authorityCross-authority source-registry collision (known CAND-02)
FIP-C-018 (CONDITIONAL, M1D T-05)A later withdrawal or revocation alters a recorded decision or the store snapshotA new admission on an already non-current source (known CAND-01)
FIP-C-001A, C-002 (principles)An internal contradiction or ambiguity in the approved textsAny implementation behavior
FIP-H-005 (T-12)A reproduced path, at the accepted baseline, in which provenance content (including malformed provenance) determines the outcome of a protected transitionThe disclosed absence of runtime provenance validation itself (LIM-002), which is a known defect
FIP-H-001, H-002, H-003, H-006A specification ambiguity or internal inconsistency in the specified behaviorAbsence of implementation (expected)

8. Threat-model ceiling

This threat model does not establish:

  • general alignment;
  • universal safety;
  • universal route closure;
  • real-institution behavior (fixtures are synthetic);
  • live-provider behavior where only mock-provider evidence exists;
  • independent reproduction (all reproduction is INTERNAL at most);
  • production deployment;
  • bind-time or consequence enforcement at model submission.