{
  "auditDate": "2026-08-13",
  "canonicalSpec": "docs/spec/SEMANTIC_OWNERSHIP_LEDGER_v0.1.md",
  "canonicalSpecSha256": "b9a7a8e55acba113d6af38a5dcfc6333575462f6fe6a2ee1224ed263cd9441d0",
  "closureContract": "docs/spec/SELFHOST_CLOSURE_LEVELS_v0.1.json",
  "closureContractIdentitySha256": "279ba0abaa32d5aa4cf303b825216608e60e07d5ffc17059f709d8ff7f004d3e",
  "commandBindings": [
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_agent_index.rs"
      ],
      "selector": "agent-index",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-AGENT-INDEX"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_agent_plan.rs"
      ],
      "selector": "agent-plan",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-AGENT-PLAN",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_ops.rs"
      ],
      "selector": "apply-patch",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-PATCH",
        "SD-OBLIGATION",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 18,
      "includesHidden": true,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_bench.rs"
      ],
      "selector": "bench/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-BENCH",
        "SD-EVIDENCE-VERIFY",
        "SD-SIGNING"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cli_schema.rs"
      ],
      "selector": "cli-schema",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-CLI-SCHEMA"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 2,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_commit.rs"
      ],
      "selector": "commit/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-COMMIT",
        "SD-STORE",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 7,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_debug.rs"
      ],
      "selector": "debug/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-DEBUG-TRACE",
        "SD-SOURCE-DECODE",
        "SD-PURE-EVAL",
        "SD-FRONTEND-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_core.rs"
      ],
      "selector": "eval",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SOURCE-DECODE",
        "SD-PURE-EVAL",
        "SD-FRONTEND-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_core.rs"
      ],
      "selector": "explain",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SOURCE-DECODE",
        "SD-PURE-EVAL",
        "SD-FRONTEND-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_source.rs"
      ],
      "selector": "fmt",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SOURCE-DECODE",
        "SD-PRINT-FORMAT",
        "SD-FRONTEND-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 5,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_gc.rs"
      ],
      "selector": "gc/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-ARTIFACT-GC",
        "SD-STORE",
        "SD-REFS",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_signing.rs"
      ],
      "selector": "keygen",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SIGNING"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/mcp"
      ],
      "selector": "mcp",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-WARM-MCP",
        "SD-CLI-SCHEMA"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_ops.rs"
      ],
      "selector": "optimize",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SOURCE-DECODE",
        "SD-OPTIMIZATION",
        "SD-WASM-TRANSLATION",
        "SD-FRONTEND-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/pkg_workspace_ops.rs"
      ],
      "selector": "pack",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-PACKAGE-EXEC",
        "SD-OBLIGATION"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_source.rs"
      ],
      "selector": "parse",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SOURCE-DECODE",
        "SD-FRONTEND-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 28,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_pkg.rs"
      ],
      "selector": "pkg/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-PACKAGE-WORKSPACE",
        "SD-PACKAGE-RESOLUTION",
        "SD-PACKAGE-EXEC",
        "SD-PACKAGE-DISTRIBUTION",
        "SD-PACKAGE-ABI-DEPLOY",
        "SD-OBLIGATION",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 3,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_policy.rs"
      ],
      "selector": "policy/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-POLICY-ALIAS",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 4,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_refs.rs"
      ],
      "selector": "refs/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-REFS",
        "SD-STORE",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_registry.rs"
      ],
      "selector": "registry/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-REGISTRY",
        "SD-EVIDENCE-VERIFY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_core.rs"
      ],
      "selector": "replay",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-REPLAY",
        "SD-EFFECT-DISPATCH",
        "SD-FRONTEND-CANON-IDENTITY",
        "SD-SOURCE-DECODE"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_core.rs"
      ],
      "selector": "run",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SOURCE-DECODE",
        "SD-PURE-EVAL",
        "SD-EFFECT-POLICY",
        "SD-EFFECT-DISPATCH",
        "SD-FRONTEND-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_selfhost_artifact.rs"
      ],
      "selector": "selfhost-artifact",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SELFHOST-ARTIFACT",
        "SD-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_selfhost.rs"
      ],
      "selector": "selfhost-dashboard",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-CLI-SCHEMA"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 4,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_ops.rs"
      ],
      "selector": "semantic-edit/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-PATCH",
        "SD-CANON-IDENTITY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 6,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/agent_session.rs"
      ],
      "selector": "session/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SESSION",
        "SD-PATCH",
        "SD-OBLIGATION"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_signing.rs"
      ],
      "selector": "sign",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-SIGNING",
        "SD-EVIDENCE-VERIFY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 4,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_store.rs"
      ],
      "selector": "store/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-STORE",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 2,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_sync.rs"
      ],
      "selector": "sync/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-REMOTE-SYNC",
        "SD-REGISTRY",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/pkg_task_runner.rs"
      ],
      "selector": "test",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-PACKAGE-EXEC",
        "SD-OBLIGATION",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_ops.rs"
      ],
      "selector": "transparency-verify",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-EVIDENCE-VERIFY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_ops.rs"
      ],
      "selector": "typecheck",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-TYPE-EFFECT"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 8,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_vcs.rs"
      ],
      "selector": "vcs/*",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-VCS",
        "SD-CANON-IDENTITY",
        "SD-EFFECT-POLICY"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/cmd_security_ops.rs"
      ],
      "selector": "verify",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-EVIDENCE-VERIFY",
        "SD-STORE"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    },
    {
      "expectedLeafCount": 1,
      "includesHidden": false,
      "routingImplementationPaths": [
        "crates/gc_cli_driver/src/lib.rs",
        "crates/gc_cli_driver/src/warm_worker_process.rs"
      ],
      "selector": "warm",
      "semanticDecisionIds": [
        "SD-ROUTE-SELECTION",
        "SD-WARM-MCP"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ]
    }
  ],
  "commandInventoryCount": 114,
  "commandSourcePaths": [
    "crates/gc_cli_driver/src/cli_args.rs",
    "crates/gc_cli_driver/src/cli_args/command_groups.rs",
    "crates/gc_cli_driver/src/cli_args/sync_registry_cmd.rs",
    "crates/gc_cli_driver/src/cli_args/pkg_cmd.rs",
    "crates/gc_cli_driver/src/cli_args/policy_gc_vcs_cmd.rs"
  ],
  "contentIdentitySha256": "e3302dc5e6d2c161bf7ab2c52846a09ba8f500ee38ae5aae3098116bec951344",
  "kind": "genesis/semantic-ownership-ledger-v0.1",
  "nonclaims": [
    "does-not-promote-any-semantic-decision",
    "does-not-change-production-authority-or-fallback-reachability",
    "does-not-establish-H2-H3-or-H4",
    "does-not-authorize-downstream-product-work"
  ],
  "schema": "docs/spec/SEMANTIC_OWNERSHIP_LEDGER_v0.1.schema.json",
  "schemaSha256": "c3bc52735a9d992a88857fc807de0dd9a605ab67d931ca24445596a0a57cfe74",
  "semanticDecisions": [
    {
      "applicability": "applicable",
      "commandSelectors": [
        "agent-index",
        "agent-plan",
        "apply-patch",
        "bench/*",
        "cli-schema",
        "commit/*",
        "debug/*",
        "eval",
        "explain",
        "fmt",
        "gc/*",
        "keygen",
        "mcp",
        "optimize",
        "pack",
        "parse",
        "pkg/*",
        "policy/*",
        "refs/*",
        "registry/*",
        "replay",
        "run",
        "selfhost-artifact",
        "selfhost-dashboard",
        "semantic-edit/*",
        "session/*",
        "sign",
        "store/*",
        "sync/*",
        "test",
        "transparency-verify",
        "typecheck",
        "vcs/*",
        "verify",
        "warm"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [],
      "id": "SD-ROUTE-SELECTION",
      "internalOnly": false,
      "limitations": [
        "H0 covers route selection only",
        "functional command decisions retain their own level"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "selfhost/toolchain.gc",
        "crates/gc_cli_driver/src/selfhost_frontend.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/selfhost_frontend.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/SELF_HOST_BOUNDARY.md",
        "docs/spec/SELFHOST_CLOSURE_LEVELS_v0.1.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ],
      "title": "CLI route and selfhost artifact selection",
      "verifierPaths": [
        "scripts/check_selfhost_boundary.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "cli-schema",
        "mcp",
        "selfhost-dashboard"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-CLI-SCHEMA",
      "internalOnly": false,
      "limitations": [
        "Rust currently defines and projects the production command schema"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/cli_schema.rs",
        "crates/gc_cli_driver/src/mcp"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/cli_schema.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/CLI_JSON_SCHEMAS_v0.1.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_spec_surface.rs",
        "crates/gc_wasi_cli/tests/cli_spec_surface.rs"
      ],
      "title": "CLI and MCP schema projection",
      "verifierPaths": [
        "scripts/check_cli_diagnostics_contract.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "debug/*",
        "eval",
        "explain",
        "fmt",
        "optimize",
        "parse",
        "replay",
        "run"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/selfhost_bridge.rs",
        "crates/gc_obligations/src/obligations/frontend_module_ops.rs"
      ],
      "id": "SD-SOURCE-DECODE",
      "internalOnly": false,
      "limitations": [
        "The exact production frontend profile is H2; bootstrap admission and non-frontend codecs are assessed separately"
      ],
      "migrationTasks": [
        "R4.2.a"
      ],
      "producingImplementationPaths": [
        "selfhost/parse.gc",
        "selfhost/parse_core_v1.gc",
        "crates/gc_coreform/src/parse.rs"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/cli_coreform_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/COREFORM_CANON_HASH.md",
        "docs/spec/SELF_HOST_BOUNDARY.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_obligations/src/tests/frontend_contracts.rs",
        "crates/gc_wasi_cli/tests/cli_coreform_frontend_profile.rs"
      ],
      "title": "Source parsing and CoreForm lowering",
      "verifierPaths": [
        "scripts/lib/selfhost_frontend_authority.py",
        "scripts/selfhost_frontend_authority_guard.sh",
        "scripts/check_selfhost_boundary.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "vcs/*",
        "semantic-edit/*",
        "selfhost-artifact"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [],
      "id": "SD-CANON-IDENTITY",
      "internalOnly": false,
      "limitations": [
        "Semantic-patch identities remain assigned to R4.2.c, package/lock/VCS object identities to R4.2.e, and self-host component/composition/compiled/bootstrap artifact identity and admission to R4.4.a; each remains host-authoritative until its assigned task closes"
      ],
      "migrationTasks": [
        "R4.2.c",
        "R4.2.e",
        "R4.4.a"
      ],
      "producingImplementationPaths": [
        "selfhost/canon.gc",
        "selfhost/hash.gc",
        "crates/gc_coreform/src/canon.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_coreform/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/COREFORM_CANON_HASH.md",
        "docs/spec/SELF_HOST_BOUNDARY.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_coreform/tests"
      ],
      "title": "Non-frontend canonical term and artifact identities",
      "verifierPaths": [
        "scripts/check_kernel_tcb_contract.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "fmt"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/selfhost_bridge.rs"
      ],
      "id": "SD-PRINT-FORMAT",
      "internalOnly": false,
      "limitations": [
        "H2 is scoped to canonical source printing in the exact production frontend profile; non-source artifact codecs remain separate decisions"
      ],
      "migrationTasks": [
        "R4.2.a"
      ],
      "producingImplementationPaths": [
        "selfhost/printer",
        "selfhost/printer/03_fmt_list_module.gc",
        "crates/gc_coreform/src/print.rs"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/cli_coreform_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/COREFORM_CANON_HASH.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_obligations/src/tests/frontend_contracts.rs",
        "crates/gc_wasi_cli/tests/cli_coreform_frontend_profile.rs"
      ],
      "title": "Canonical and structured source printing",
      "verifierPaths": [
        "scripts/lib/selfhost_frontend_authority.py",
        "scripts/selfhost_frontend_authority_guard.sh",
        "scripts/check_selfhost_boundary.sh"
      ]
    },
    {
      "applicability": "residual-stage0",
      "commandSelectors": [
        "eval",
        "explain",
        "run",
        "debug/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "declared-stage0-residual",
      "hostBindingPaths": [],
      "id": "SD-PURE-EVAL",
      "internalOnly": false,
      "limitations": [
        "S0-K is TCB-A and deliberately not promoted through H-level migration"
      ],
      "migrationTasks": [
        "R4.5.a"
      ],
      "producingImplementationPaths": [
        "crates/gc_kernel/src/eval_treewalk.rs",
        "crates/gc_kernel/src/value.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_kernel/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/SELF_HOST_BOUNDARY.md",
        "docs/spec/DETERMINISM.md"
      ],
      "stage0Domains": [
        "S0-K"
      ],
      "testPaths": [
        "crates/gc_kernel/src/tests.rs"
      ],
      "title": "Reference pure evaluation, values, resources, and seals",
      "verifierPaths": [
        "scripts/check_kernel_tcb_contract.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-COMPILED-EXECUTION",
      "internalOnly": true,
      "limitations": [
        "Rust compiled runtime is production authority"
      ],
      "migrationTasks": [
        "R3.1.f",
        "R4.5.c"
      ],
      "producingImplementationPaths": [
        "crates/gc_kernel/src/compiled.rs",
        "crates/gc_kernel/src/compiled_runtime"
      ],
      "productionAuthorityPaths": [
        "crates/gc_kernel/src/compiled_runtime"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/SELF_HOST_BOUNDARY.md"
      ],
      "stage0Domains": [
        "S0-X"
      ],
      "testPaths": [
        "crates/gc_kernel/src/compiled/tests.rs"
      ],
      "title": "Compiled artifact decoding and execution",
      "verifierPaths": [
        "scripts/check_kernel_tcb_contract.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "agent-plan",
        "run",
        "test",
        "apply-patch",
        "store/*",
        "refs/*",
        "commit/*",
        "pkg/*",
        "policy/*",
        "sync/*",
        "gc/*",
        "vcs/*"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-EFFECT-POLICY",
      "internalOnly": false,
      "limitations": [
        "H2 is scoped to genesis/selfhost-effect-policy-composition-v0.1; Rust retains TOML transport, secret/path resolution, bounded effect execution, cancellation, bridge validation/lifecycle, and replay mechanisms, while the compile-time parity-only compatibility parser remains independently invocable and H3/H4 are not claimed"
      ],
      "migrationTasks": [
        "R4.2.d"
      ],
      "producingImplementationPaths": [
        "selfhost/effect_policy_crypto_v1.gc",
        "selfhost/effect_policy_network_v1.gc",
        "selfhost/effect_policy_plugin_v1.gc",
        "selfhost/effect_policy_ffi_v1.gc",
        "selfhost/effect_policy_bridge_v1.gc",
        "selfhost/effect_policy_gpu_v1.gc",
        "selfhost/effect_policy_gfx_v1.gc",
        "selfhost/effect_policy_xr_v1.gc",
        "selfhost/effect_policy_resource_authority_v1.gc",
        "selfhost/effect_policy_authority_v1.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/effect_policy_authority_v1.gc",
        "selfhost/effect_policy_resource_authority_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CAPS_TOML.md",
        "docs/spec/HOST_ABI.md",
        "docs/spec/SELFHOST_EFFECT_POLICY_COMPOSITION_v0.1.md",
        "policies/selfhost_effect_policy_composition_v0.1.json"
      ],
      "stage0Domains": [
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_effects/src/policy_tests.rs",
        "crates/gc_effects/src/policy_authority.rs",
        "crates/gc_effects/src/policy_transport.rs"
      ],
      "title": "Capability and policy authorization decisions",
      "verifierPaths": [
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_selfhost_boundary.sh",
        "scripts/lib/selfhost_effect_policy_composition.py",
        "scripts/selfhost_effect_policy_composition_guard.sh"
      ]
    },
    {
      "applicability": "residual-stage0",
      "commandSelectors": [
        "run",
        "replay"
      ],
      "currentLevel": null,
      "fallbackReachability": "declared-stage0-residual",
      "hostBindingPaths": [
        "crates/gc_effects/src/runner_host_bridge.rs"
      ],
      "id": "SD-EFFECT-DISPATCH",
      "internalOnly": false,
      "limitations": [
        "Physical adapters remain explicit S0-H trust; policy semantics are tracked separately"
      ],
      "migrationTasks": [
        "R4.5.b"
      ],
      "producingImplementationPaths": [
        "crates/gc_effects/src/runner.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_effects/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/HOST_ABI.md",
        "docs/spec/SELF_HOST_BOUNDARY.md"
      ],
      "stage0Domains": [
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_effects/src/tests.rs"
      ],
      "title": "Physical host effect dispatch and containment",
      "verifierPaths": [
        "scripts/check_host_bridge_fault_injection.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "replay"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_effects/src",
        "crates/gc_obligations/src"
      ],
      "id": "SD-REPLAY",
      "internalOnly": false,
      "limitations": [
        "H2 is scoped to genesis/selfhost-replay-authority-v0.1; Rust retains structural log decoding, sealed effect-program stepping, canonical hash observation, response artifact loading/codec, and continuation application after acceptance, while the legacy semantic checker is compile-time parity-only and H3/H4 are not claimed"
      ],
      "migrationTasks": [
        "R4.2.d"
      ],
      "producingImplementationPaths": [
        "selfhost/effect_replay_authority_v1.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/effect_replay_authority_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/SEALS_DISPATCH_REPLAY.md",
        "docs/spec/GCLOG.md",
        "docs/spec/SELFHOST_REPLAY_AUTHORITY_v0.1.md",
        "policies/selfhost_replay_authority_v0.1.json"
      ],
      "stage0Domains": [
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_effects/src/tests.rs",
        "crates/gc_effects/src/replay_authority.rs"
      ],
      "title": "Strict deterministic effect-log replay",
      "verifierPaths": [
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_selfhost_boundary.sh",
        "scripts/lib/selfhost_replay_authority.py"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "debug/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-DEBUG-TRACE",
      "internalOnly": false,
      "limitations": [
        "Debug orchestration and trace interpretation remain Rust-authoritative"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/cmd_debug.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/cmd_debug.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md"
      ],
      "stage0Domains": [
        "S0-X"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_smoke.rs"
      ],
      "title": "Debugger trace, frame, timeline, and bisect decisions",
      "verifierPaths": [
        "crates/gc_cli/tests/cli_smoke.rs"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "typecheck"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/pkg_abi.rs",
        "crates/gc_obligations/src/obligations/typecheck_authority.rs",
        "crates/gc_obligations/src/obligations/typecheck_authority_decode.rs",
        "crates/gc_obligations/src/obligations/types_api.rs"
      ],
      "id": "SD-TYPE-EFFECT",
      "internalOnly": false,
      "limitations": [
        "H2 is scoped to genesis/typecheck-authority-v0.1; the compile-time parity-only Rust compatibility oracle remains independently invocable until its 2026-11-11 sunset review, and H3/H4 bootstrap or independent-reimplementation closure is not claimed"
      ],
      "migrationTasks": [
        "R4.2.b"
      ],
      "producingImplementationPaths": [
        "selfhost/typecheck_compat_v1.gc",
        "selfhost/typecheck_contract_profile_compose_v1.gc",
        "selfhost/typecheck_contract_profile_v1.gc",
        "selfhost/typecheck_core_v1.gc",
        "selfhost/typecheck_infer_app_v1.gc",
        "selfhost/typecheck_infer_apply_v1.gc",
        "selfhost/typecheck_infer_contract_v1.gc",
        "selfhost/typecheck_infer_core_v1.gc",
        "selfhost/typecheck_infer_effect_v1.gc",
        "selfhost/typecheck_infer_prim_v1.gc",
        "selfhost/typecheck_module_profile_descriptor_v1.gc",
        "selfhost/typecheck_module_profile_references_v1.gc",
        "selfhost/typecheck_module_profile_resolution_v1.gc",
        "selfhost/typecheck_package_context_v1.gc",
        "selfhost/typecheck_package_exports_v1.gc",
        "selfhost/typecheck_package_meta_v1.gc",
        "selfhost/typecheck_package_module_v1.gc",
        "selfhost/typecheck_package_report_v1.gc",
        "selfhost/typecheck_profile_negotiation_v1.gc",
        "selfhost/typecheck_typed_effects_v1.gc",
        "selfhost/typecheck_types_v1.gc",
        "selfhost/typecheck_unknown_signatures_v1.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/typecheck_package_report_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/SELFHOST_TYPECHECK_AUTHORITY_v0.1.md",
        "docs/spec/TYPES.md",
        "docs/spec/CONCURRENCY_v0.1.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_obligations/src/tests/typecheck_authority.rs",
        "crates/gc_types/src/lib_tests.rs"
      ],
      "title": "Type, effect, contract, and diagnostic checking",
      "verifierPaths": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/lib/selfhost_typecheck_authority.py",
        "scripts/selfhost_typecheck_authority_guard.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "optimize"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-OPTIMIZATION",
      "internalOnly": false,
      "limitations": [
        "Rust optimizer produces candidates; validation does not make it self-hosted"
      ],
      "migrationTasks": [
        "R4.2.f"
      ],
      "producingImplementationPaths": [
        "crates/gc_opt/src"
      ],
      "productionAuthorityPaths": [
        "crates/gc_opt/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/OPTIMIZER.md"
      ],
      "stage0Domains": [
        "S0-X"
      ],
      "testPaths": [
        "crates/gc_opt/src/lib_tests.rs"
      ],
      "title": "Rewrite selection and optimized CoreForm production",
      "verifierPaths": [
        "scripts/check_kernel_tcb_contract.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "optimize"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-WASM-TRANSLATION",
      "internalOnly": false,
      "limitations": [
        "Wasm production and validator orchestration remain Rust"
      ],
      "migrationTasks": [
        "R3.2.a",
        "R4.2.f"
      ],
      "producingImplementationPaths": [
        "crates/gc_opt/src/stage2_wasm",
        "crates/gc_wasm/src"
      ],
      "productionAuthorityPaths": [
        "crates/gc_opt/src/stage2_wasm"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/WASM.md"
      ],
      "stage0Domains": [
        "S0-X"
      ],
      "testPaths": [
        "crates/gc_wasm/src/tests.rs"
      ],
      "title": "CoreForm to Wasm lowering and translation validation",
      "verifierPaths": [
        "scripts/check_wasm_production_surface.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "apply-patch",
        "semantic-edit/*",
        "session/*"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_patches/src/patch_apply_report.rs",
        "crates/gc_patches/src/patch_apply_runtime.rs",
        "crates/gc_patches/src/patch_selfhost_authority.rs",
        "crates/gc_patches/src/patch_selfhost_toolchain.rs"
      ],
      "id": "SD-PATCH",
      "internalOnly": false,
      "limitations": [
        "H2 is scoped to genesis/selfhost-patch-authority-v0.1; the compile-time parity-only Rust compatibility oracle remains independently invocable until its 2026-11-11 sunset review, and H3/H4 bootstrap or independent-reimplementation closure is not claimed"
      ],
      "migrationTasks": [
        "R4.2.c"
      ],
      "producingImplementationPaths": [
        "selfhost/patch_schema_v1.gc",
        "selfhost/patch_authority_refactor_plan_v1.gc",
        "selfhost/patch_authority_diff_v1.gc",
        "selfhost/patch_authority_merge_v1.gc",
        "selfhost/patch_authority_apply_report_v1.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/patch_authority_refactor_plan_v1.gc",
        "selfhost/patch_authority_diff_v1.gc",
        "selfhost/patch_authority_merge_v1.gc",
        "selfhost/patch_authority_apply_report_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/PATCH_SCHEMA.md",
        "docs/spec/SELFHOST_PATCH_AUTHORITY_v0.1.md",
        "docs/spec/SELFHOST_REFACTOR_PIPELINE_v0.1.md",
        "docs/spec/SEMANTIC_REFACTOR_PLAN_v0.1.md",
        "docs/spec/SEMANTIC_PATCH_DIFF_v0.1.md",
        "docs/spec/SEMANTIC_PATCH_MERGE_v0.1.md",
        "docs/spec/SEMANTIC_PATCH_APPLY_REPORT_v0.1.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_patches/tests",
        "crates/gc_cli/tests/cli_semantic_edit.rs",
        "crates/gc_cli/tests/cli_typecheck_apply_patch_engine.rs"
      ],
      "title": "Semantic diff, patch, merge, and refactor decisions",
      "verifierPaths": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_refactor_guard.sh",
        "scripts/lib/selfhost_patch_authority.py",
        "scripts/selfhost_patch_authority_guard.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "apply-patch",
        "pack",
        "test",
        "pkg/*",
        "session/*"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_obligations/src/obligation_authority.rs",
        "crates/gc_obligations/src/obligation_authority_preflight.rs",
        "crates/gc_obligations/src/obligations/types_api.rs"
      ],
      "id": "SD-OBLIGATION",
      "internalOnly": false,
      "limitations": [
        "H2 is scoped to genesis/selfhost-obligation-authority-v0.1; Rust retains bounded execution, measurement, package-loading, rendering, replay, and strict contradiction mechanisms, while effect-policy authority and H3/H4 bootstrap closure are not claimed"
      ],
      "migrationTasks": [
        "R4.2.d"
      ],
      "producingImplementationPaths": [
        "selfhost/obligation_authority_core_v1.gc",
        "selfhost/obligation_authority_typecheck_v1.gc",
        "selfhost/obligation_authority_determinism_v1.gc",
        "selfhost/obligation_authority_lint_v1.gc",
        "selfhost/obligation_authority_ai_style_v1.gc",
        "selfhost/obligation_authority_preflight_v1.gc",
        "selfhost/obligation_authority_replay_v1.gc",
        "selfhost/obligation_authority_property_v1.gc",
        "selfhost/obligation_authority_stage_v1.gc",
        "selfhost/obligation_authority_coverage_v1.gc",
        "selfhost/obligation_authority_translation_v1.gc",
        "selfhost/obligation_authority_gfx_api_v1.gc",
        "selfhost/obligation_authority_gfx_runtime_v1.gc",
        "selfhost/obligation_authority_gfx_runtime_finalize_v1.gc",
        "selfhost/obligation_authority_v1.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/obligation_authority_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/ASSURANCE_ARTIFACTS_v0.1.md",
        "docs/spec/SELFHOST_OBLIGATION_AUTHORITY_v0.1.md",
        "policies/selfhost_obligation_authority_v0.1.json"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_obligations/src/obligation_authority_tests.rs",
        "crates/gc_cli/tests/cli_failures.rs",
        "crates/gc_cli/tests/cli_json_and_exit.rs"
      ],
      "title": "Obligation generation, evaluation, and promotion decisions",
      "verifierPaths": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/lib/selfhost_obligation_authority.py"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "session/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-SESSION",
      "internalOnly": false,
      "limitations": [
        "Session custody and stale-snapshot decisions remain Rust"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/agent_session.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/agent_session.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_agent_session.rs"
      ],
      "title": "Transactional snapshot, stage, test, apply, and abort decisions",
      "verifierPaths": [
        "crates/gc_cli/tests/cli_agent_session.rs"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "agent-index"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-AGENT-INDEX",
      "internalOnly": false,
      "limitations": [
        "Generated inputs are authoritative but Rust performs production lookup"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/cmd_agent_index.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/cmd_agent_index.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/AGENT_AUTHORING_BUNDLE_v0.1.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_agent_index.rs"
      ],
      "title": "Agent card, symbol, diagnostic, and source indexing",
      "verifierPaths": [
        "scripts/check_agent_authoring_bundle.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "agent-plan"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-AGENT-PLAN",
      "internalOnly": false,
      "limitations": [
        "Rust computes workflow selection and plan identity"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/cmd_agent_plan.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/cmd_agent_plan.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/AGENT_AUTHORING_BUNDLE_v0.1.md"
      ],
      "stage0Domains": [
        "S0-R",
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_agent_plan.rs"
      ],
      "title": "Structured intent workflow planning and policy prechecks",
      "verifierPaths": [
        "scripts/check_agent_reference_workflows.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "bench/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/host_bridge_runtime.rs"
      ],
      "id": "SD-BENCH",
      "internalOnly": false,
      "limitations": [
        "Downstream campaigns remain frozen; existing benchmark CLI semantics are Rust/Python authoritative"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/cmd_bench.rs",
        "scripts/lib"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/cmd_bench.rs",
        "scripts/lib"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/GENESISBENCH_PROTOCOL_v0.1.json"
      ],
      "stage0Domains": [
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_genesisbench_front_door.rs"
      ],
      "title": "Benchmark planning, execution, scoring, replay, custody, and registry decisions",
      "verifierPaths": [
        "scripts/check_agent_authoring_bundle.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "keygen",
        "sign",
        "bench/*"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/cmd_bench.rs",
        "crates/gc_cli_driver/src/cmd_security_signing.rs",
        "crates/gc_obligations/src/signing.rs",
        "crates/gc_obligations/src/signing_authority.rs",
        "crates/gc_obligations/src/signing_authority_decode.rs"
      ],
      "id": "SD-SIGNING",
      "internalOnly": false,
      "limitations": [
        "Operating-system entropy, Ed25519 and SHA mechanisms, codecs, bounded secret-file custody, content-addressed storage, and state-pointer writes remain host mechanisms; evidence verification is tracked separately by SD-EVIDENCE-VERIFY"
      ],
      "migrationTasks": [
        "R4.2.d"
      ],
      "producingImplementationPaths": [
        "selfhost/signing_authority_v1.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/signing_authority_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/ASSURANCE_ARTIFACTS_v0.1.md",
        "docs/spec/SELFHOST_SIGNING_AUTHORITY_v0.1.md",
        "docs/spec/SIGNING.md",
        "docs/spec/TRANSPARENCY_LOG.md"
      ],
      "stage0Domains": [
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_genesisbench_registry.rs",
        "crates/gc_cli/tests/cli_smoke.rs",
        "crates/gc_obligations/src/signing_authority_decode.rs"
      ],
      "title": "Key generation and artifact signing",
      "verifierPaths": [
        "scripts/lib/selfhost_signing_authority.py",
        "scripts/check_selfhost_boundary.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "verify",
        "transparency-verify",
        "registry/*",
        "bench/*",
        "sign"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/cmd_bench.rs",
        "crates/gc_cli_driver/src/cmd_security_ops.rs",
        "crates/gc_obligations/src/evidence_verify_authority.rs",
        "crates/gc_obligations/src/transparency.rs",
        "crates/gc_obligations/src/verify.rs"
      ],
      "id": "SD-EVIDENCE-VERIFY",
      "internalOnly": false,
      "limitations": [
        "Filesystem, content-addressed store access, hashing, Ed25519, and codecs remain bounded host mechanisms; package lock and resolution authority is tracked separately",
        "H2 is scoped to package/evidence/signature/transparency/GenesisBench verification; aggregate R4.2.d, H3/H4 bootstrap closure, release qualification, and publication readiness remain open",
        "The standalone evidence verifier remains an independent corroborator and cannot authorize or replace production GenesisCode verdicts"
      ],
      "migrationTasks": [
        "R4.2.d"
      ],
      "producingImplementationPaths": [
        "selfhost/evidence_verify_package_v1.gc",
        "selfhost/evidence_verify_authority_v1.gc",
        "selfhost/toolchain.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/evidence_verify_package_v1.gc",
        "selfhost/evidence_verify_authority_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/ASSURANCE_ARTIFACTS_v0.1.md",
        "docs/spec/SELFHOST_EVIDENCE_VERIFY_AUTHORITY_v0.1.md",
        "docs/spec/SIGNING.md",
        "docs/spec/TRANSPARENCY_LOG.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_genesisbench_registry.rs",
        "crates/gc_cli/tests/cli_smoke.rs",
        "crates/gc_cli/tests/release_evidence_regressions.rs",
        "crates/gc_obligations/src/evidence_verify_authority_tests.rs"
      ],
      "title": "Evidence, signature, transparency, package, and run verification",
      "verifierPaths": [
        "scripts/check_genesis_evidence_verifier.sh",
        "scripts/check_selfhost_boundary.sh",
        "scripts/lib/selfhost_evidence_verify_authority.py"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "store/*",
        "refs/*",
        "commit/*",
        "gc/*",
        "verify"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-STORE",
      "internalOnly": false,
      "limitations": [
        "Artifact-loaded GenesisCode exclusively decides core/store::{put,has,get,verify} payload and hash admission, canonical bytes, local integrity, local/remote source selection, CoreForm parsing, operation and cumulative cache budgets, canonical verification inventory selection/order, bounded observation admission, first-failure attribution, and content identity under genesis/selfhost-store-authority-v0.1",
        "Internal direct-store consumers and package/registry/VCS storage decisions remain host-authoritative, so SD-STORE remains H0"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "selfhost/toolchain.gc",
        "selfhost/store_authority_v1.gc",
        "selfhost/store_verify_authority_v1.gc",
        "crates/gc_cli_driver/src/cmd_store.rs"
      ],
      "productionAuthorityPaths": [
        "selfhost/store_authority_v1.gc",
        "selfhost/store_verify_authority_v1.gc",
        "crates/gc_effects/src/store_authority.rs",
        "crates/gc_effects/src/store_authority_read.rs",
        "crates/gc_effects/src/store_authority_verify.rs",
        "crates/gc_effects/src/policy_selfhost.rs",
        "crates/gc_effects/src/runner_cap_store.rs",
        "crates/gc_effects/src/runner_cap_store_read.rs",
        "crates/gc_effects/src/runner_cap_store_verify.rs",
        "crates/gc_effects/src/store.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/SELFHOST_STORE_AUTHORITY_v0.1.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_store.rs",
        "crates/gc_cli/tests/cli_store_verify_authority.rs",
        "crates/gc_effects/tests/store_caps.rs"
      ],
      "title": "Content-addressed object storage and integrity decisions",
      "verifierPaths": [
        "crates/gc_cli/tests/cli_store.rs",
        "crates/gc_cli/tests/cli_store_verify_authority.rs",
        "scripts/lib/selfhost_store_authority.py"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "refs/*",
        "gc/*"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-REFS",
      "internalOnly": false,
      "limitations": [
        "Artifact-loaded GenesisCode exclusively decides direct core/refs get/list lookup, prefix filtering/order, expected-old conflict, update/delete transition, and response facts under genesis/selfhost-refs-authority-v0.1",
        "Rust policy/evidence/signature admission and bulk sync/GPK reference updates remain host-authoritative, so SD-REFS remains H0"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "selfhost/toolchain.gc",
        "selfhost/refs_authority_v1.gc",
        "crates/gc_effects/src/refs_authority.rs",
        "crates/gc_cli_driver/src/cmd_refs.rs"
      ],
      "productionAuthorityPaths": [
        "selfhost/refs_authority_v1.gc",
        "crates/gc_effects/src/refs_authority.rs",
        "crates/gc_effects/src/runner_cap_refs.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/SELFHOST_REFS_AUTHORITY_v0.1.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_effects/src/refs_authority.rs",
        "crates/gc_cli/tests/cli_refs.rs"
      ],
      "title": "Reference read, list, update, and delete decisions",
      "verifierPaths": [
        "crates/gc_cli/tests/cli_refs.rs",
        "scripts/lib/selfhost_refs_authority.py"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "commit/*"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src"
      ],
      "id": "SD-COMMIT",
      "internalOnly": false,
      "limitations": [
        "Artifact-loaded GenesisCode exclusively constructs and validates canonical v1 commit objects for native commit new/show under genesis/selfhost-commit-authority-v0.1",
        "Ref resolution, patch/store/signing mechanisms, command orchestration, WASI commit CLI support, and internal package/registry/VCS commit construction and decoding remain host-authoritative, so SD-COMMIT remains H0"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "selfhost/toolchain.gc",
        "selfhost/commit_authority_v1.gc",
        "crates/gc_cli_driver/src/commit_authority.rs",
        "crates/gc_cli_driver/src/cmd_commit.rs"
      ],
      "productionAuthorityPaths": [
        "selfhost/commit_authority_v1.gc",
        "crates/gc_cli_driver/src/commit_authority.rs",
        "crates/gc_cli_driver/src/cmd_commit.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/SELFHOST_COMMIT_AUTHORITY_v0.1.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_commit.rs"
      ],
      "title": "Commit object construction and inspection",
      "verifierPaths": [
        "crates/gc_cli/tests/cli_commit.rs",
        "scripts/lib/selfhost_commit_authority.py"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "vcs/*"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-VCS",
      "internalOnly": false,
      "limitations": [
        "GenesisCode programs are routed but Rust VCS libraries retain production authority"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "selfhost/cli_coreform_vcs_pkg_v1.gc",
        "crates/gc_vcs/src"
      ],
      "productionAuthorityPaths": [
        "crates/gc_vcs/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/PATCH_SCHEMA.md"
      ],
      "stage0Domains": [
        "S0-R",
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_vcs_engine.rs"
      ],
      "title": "Semantic VCS hash, diff, apply, log, blame, why, merge, and conflict decisions",
      "verifierPaths": [
        "scripts/check_vcs_selfhost_contract.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "pkg/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-PACKAGE-WORKSPACE",
      "internalOnly": false,
      "limitations": [
        "Rust currently computes workspace and scaffold outputs"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/pkg_workspace_ops.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src/pkg_workspace_ops.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/GCPM_BUNDLE_v0.1.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_pkg_workspace.rs"
      ],
      "title": "Workspace, scaffold, manifest, migration, and environment decisions",
      "verifierPaths": [
        "scripts/check_gcpm_operation_contract_pack.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "pkg/*"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-PACKAGE-RESOLUTION",
      "internalOnly": false,
      "limitations": [
        "Artifact-loaded GenesisCode exclusively normalizes and serializes core/pkg-low::save-lock payloads and decides their canonical BLAKE3 lock identity under genesis/selfhost-pkg-lock-write-authority-v0.1",
        "Artifact-loaded GenesisCode exclusively validates and normalizes the typed public core/pkg-low::load-lock result under genesis/selfhost-pkg-lock-read-authority-v0.1",
        "Artifact-loaded GenesisCode exclusively constructs canonical package requirement environment fingerprints for lock, update, and install hydration under genesis/selfhost-pkg-resolution-identity-authority-v0.1",
        "Artifact-loaded GenesisCode exclusively normalizes and classifies effect-route selectors, checks declared strategy and tag-policy coherence, normalizes semver selection policy, and decides existing-lock update admission under genesis/selfhost-pkg-resolution-plan-authority-v0.1",
        "The generic Rust TOML syntax decoder, other internal typed lock consumers, semver grammar and comparison, ref observation, package graph resolution, registry behavior and transport, artifact and commit validation, workspace scaffolding, policy admission, sandboxing, bounded file transport, and atomic persistence remain production-required host mechanisms or host-authoritative, so SD-PACKAGE-RESOLUTION remains H0"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "selfhost/toolchain.gc",
        "selfhost/cli_pkg_runtime_v1.gc",
        "selfhost/pkg_lock_read_authority_v1.gc",
        "selfhost/pkg_lock_write_authority_v1.gc",
        "selfhost/pkg_resolution_identity_authority_v1.gc",
        "crates/gc_effects/src/pkg_lock_read_authority.rs",
        "crates/gc_effects/src/pkg_lock_write_authority.rs",
        "crates/gc_effects/src/pkg_resolution_identity_authority.rs",
        "crates/gc_effects/src/pkg_resolution_plan_authority.rs",
        "crates/gc_pkg/src"
      ],
      "productionAuthorityPaths": [
        "selfhost/pkg_lock_read_authority_v1.gc",
        "selfhost/pkg_lock_write_authority_v1.gc",
        "selfhost/pkg_resolution_identity_authority_v1.gc",
        "crates/gc_effects/src/pkg_lock_read_authority.rs",
        "crates/gc_effects/src/pkg_lock_write_authority.rs",
        "crates/gc_effects/src/pkg_resolution_identity_authority.rs",
        "crates/gc_effects/src/pkg_resolution_plan_authority.rs",
        "crates/gc_effects/src/runner_cap_pkg_low/dispatch_lock_io.rs",
        "crates/gc_effects/src/runner_cap_pkg_low/dispatch_lock_io/save_lock.rs",
        "crates/gc_pkg/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/GCPM_BUNDLE_v0.1.md",
        "docs/spec/SELFHOST_PKG_LOCK_READ_AUTHORITY_v0.1.md",
        "docs/spec/SELFHOST_PKG_LOCK_WRITE_AUTHORITY_v0.1.md",
        "docs/spec/SELFHOST_PKG_RESOLUTION_IDENTITY_AUTHORITY_v0.1.md",
        "docs/spec/SELFHOST_PKG_RESOLUTION_PLAN_AUTHORITY_v0.1.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_pkg_engine.rs",
        "crates/gc_cli/tests/cli_pkg_workspace.rs",
        "crates/gc_effects/src/pkg_lock_read_authority.rs",
        "crates/gc_effects/src/pkg_lock_write_authority.rs",
        "crates/gc_effects/src/pkg_resolution_identity_authority.rs",
        "crates/gc_effects/src/pkg_resolution_plan_authority.rs"
      ],
      "title": "Package graph, lock, update, install, and dependency resolution",
      "verifierPaths": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/lib/selfhost_pkg_lock_read_authority.py",
        "scripts/lib/selfhost_pkg_lock_write_authority.py",
        "scripts/lib/selfhost_pkg_resolution_identity_authority.py",
        "scripts/lib/selfhost_pkg_resolution_plan_authority.py"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "pkg/*",
        "test",
        "pack"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-PACKAGE-EXEC",
      "internalOnly": false,
      "limitations": [
        "Build and task orchestration remain Rust-authoritative"
      ],
      "migrationTasks": [
        "R4.2.e",
        "R4.2.f"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/pkg_task_runner.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/GCPM_BUNDLE_v0.1.md"
      ],
      "stage0Domains": [
        "S0-X"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_pkg_workspace.rs"
      ],
      "title": "Package build, run, test, optimize, and qualification decisions",
      "verifierPaths": [
        "scripts/check_gcpm_operation_contract_pack.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "pkg/*"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-PACKAGE-DISTRIBUTION",
      "internalOnly": false,
      "limitations": [
        "GenesisCode effect programs route operations; host performs acceptance and mutation"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "selfhost/cli_pkg_runtime_updates_v1.gc",
        "crates/gc_pkg/src"
      ],
      "productionAuthorityPaths": [
        "crates/gc_pkg/src",
        "crates/gc_registry/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/GCPM_BUNDLE_v0.1.md"
      ],
      "stage0Domains": [
        "S0-A",
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_pkg_workspace.rs"
      ],
      "title": "Snapshot, export, import, publish, and remote package decisions",
      "verifierPaths": [
        "scripts/check_gcpm_operation_contract_pack.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "pkg/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-PACKAGE-ABI-DEPLOY",
      "internalOnly": false,
      "limitations": [
        "Target and bridge planning remain Rust-authoritative"
      ],
      "migrationTasks": [
        "R4.2.e",
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/pkg_assurance_ops.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/GCPM_BUNDLE_v0.1.md",
        "docs/spec/HOST_ABI.md"
      ],
      "stage0Domains": [
        "S0-R",
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_pkg_workspace.rs"
      ],
      "title": "ABI, bridge, target, deploy-plan, and runtime-profile decisions",
      "verifierPaths": [
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "policy/*"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/cmd_policy.rs",
        "crates/gc_cli_driver/src/policy_config.rs"
      ],
      "id": "SD-POLICY-ALIAS",
      "internalOnly": false,
      "limitations": [
        "H2 is scoped to genesis/selfhost-policy-alias-authority-v0.1; Rust retains TOML and filesystem transport, while the compile-time parity-only compatibility oracle remains independently invocable until its 2026-11-11 sunset review; the other R4.2.d decisions and H3/H4 remain open"
      ],
      "migrationTasks": [
        "R4.2.d"
      ],
      "producingImplementationPaths": [
        "selfhost/policy_authority_v1.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/policy_authority_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CAPS_TOML.md",
        "docs/spec/SELFHOST_POLICY_ALIAS_AUTHORITY_v0.1.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_policy.rs",
        "crates/gc_cli_driver/src/tests_policy_config.rs"
      ],
      "title": "Local policy alias and default selection",
      "verifierPaths": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/lib/selfhost_policy_alias_authority.py",
        "scripts/selfhost_policy_alias_authority_guard.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "sync/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-REMOTE-SYNC",
      "internalOnly": false,
      "limitations": [
        "Remote synchronization remains host-authoritative"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/cmd_sync.rs",
        "crates/gc_registry/src"
      ],
      "productionAuthorityPaths": [
        "crates/gc_registry/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md"
      ],
      "stage0Domains": [
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_sync.rs"
      ],
      "title": "Remote object/ref synchronization decisions",
      "verifierPaths": [
        "scripts/check_remote_registry_runtime_parity.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "registry/*",
        "sync/*"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/cmd_registry.rs"
      ],
      "id": "SD-REGISTRY",
      "internalOnly": false,
      "limitations": [
        "Registry policy and serving remain Rust"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "crates/gc_registry/src",
        "crates/gc_cli_driver/src/cmd_registry.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_registry/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/GCPM_BUNDLE_v0.1.md"
      ],
      "stage0Domains": [
        "S0-H",
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_registry/src"
      ],
      "title": "Registry serving, admission, and retrieval decisions",
      "verifierPaths": [
        "scripts/check_remote_registry_runtime_parity.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "gc/*"
      ],
      "currentLevel": "H0",
      "fallbackReachability": "reachable-parity-harness",
      "hostBindingPaths": [
        "crates/gc_effects/src"
      ],
      "id": "SD-ARTIFACT-GC",
      "internalOnly": false,
      "limitations": [
        "GenesisCode reachability program is routed; host mutation remains authority"
      ],
      "migrationTasks": [
        "R4.2.e"
      ],
      "producingImplementationPaths": [
        "selfhost/cli_reachability_v1.gc",
        "crates/gc_cli_driver/src/cmd_gc.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_effects/src/runner_cap_gc_gpk_low.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md"
      ],
      "stage0Domains": [
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_gc.rs"
      ],
      "title": "Reachability, pin, purge, and artifact reclamation decisions",
      "verifierPaths": [
        "scripts/check_foundation_stdlib_conformance.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "selfhost-artifact"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [],
      "id": "SD-SELFHOST-ARTIFACT",
      "internalOnly": false,
      "limitations": [
        "Stage0 host code still assembles and admits the bootstrap artifact"
      ],
      "migrationTasks": [
        "R4.2.g",
        "R4.4.a"
      ],
      "producingImplementationPaths": [
        "selfhost/toolchain.gc",
        "crates/gc_cli_driver/src/cmd_selfhost_artifact.rs"
      ],
      "productionAuthorityPaths": [
        "crates/gc_prelude/src/selfhost_coreform_v1.rs"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/SELF_HOST_BOUNDARY.md"
      ],
      "stage0Domains": [
        "S0-P",
        "S0-A"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_selfhost_artifact.rs"
      ],
      "title": "Selfhost artifact assembly, identity, freshness, and admission",
      "verifierPaths": [
        "scripts/check_selfhost_artifact_fresh.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "warm",
        "mcp"
      ],
      "currentLevel": null,
      "fallbackReachability": "host-authoritative",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/warm_worker_process.rs"
      ],
      "id": "SD-WARM-MCP",
      "internalOnly": false,
      "limitations": [
        "Rust owns protocol dispatch, process lifecycle, and catalog projection"
      ],
      "migrationTasks": [
        "R4.2.g"
      ],
      "producingImplementationPaths": [
        "crates/gc_cli_driver/src/warm_worker_process.rs",
        "crates/gc_cli_driver/src/mcp"
      ],
      "productionAuthorityPaths": [
        "crates/gc_cli_driver/src"
      ],
      "rollbackPosture": "fail-closed; retain last independently reviewed authority and never silently cross implementation classes",
      "specAuthorityPaths": [
        "docs/spec/CLI.md",
        "docs/spec/WARM_PROTOCOL_v0.2.schema.json"
      ],
      "stage0Domains": [
        "S0-H"
      ],
      "testPaths": [
        "crates/gc_cli/tests/cli_mcp.rs"
      ],
      "title": "Warm daemon, worker, MCP catalog, and request orchestration",
      "verifierPaths": [
        "scripts/check_warm_protocol_contract.sh"
      ]
    },
    {
      "applicability": "applicable",
      "commandSelectors": [
        "debug/*",
        "eval",
        "explain",
        "fmt",
        "optimize",
        "parse",
        "replay",
        "run"
      ],
      "currentLevel": "H2",
      "fallbackReachability": "none-proven",
      "hostBindingPaths": [
        "crates/gc_cli_driver/src/selfhost_bridge.rs",
        "crates/gc_obligations/src/obligations/frontend_module_ops.rs"
      ],
      "id": "SD-FRONTEND-CANON-IDENTITY",
      "internalOnly": false,
      "limitations": [
        "H2 is limited to genesis/coreform-canon-hash-v0.2 source-to-CoreForm authority; Stage0 artifact admission and non-frontend term or artifact identities remain separate decisions"
      ],
      "migrationTasks": [
        "R4.2.a"
      ],
      "producingImplementationPaths": [
        "selfhost/canon.gc",
        "selfhost/cli_coreform_v1.gc",
        "selfhost/hash.gc",
        "selfhost/parse.gc",
        "selfhost/parse_core_v1.gc",
        "selfhost/printer/03_fmt_list_module.gc"
      ],
      "productionAuthorityPaths": [
        "selfhost/toolchain.gc",
        "selfhost/cli_coreform_v1.gc"
      ],
      "rollbackPosture": "fail-closed; retain the last independently reviewed GenesisCode artifact and never select a host frontend semantic producer",
      "specAuthorityPaths": [
        "docs/spec/COREFORM_CANON_HASH.md",
        "docs/spec/SELFHOST_FRONTEND_AUTHORITY_v0.1.md",
        "docs/spec/SELF_HOST_BOUNDARY.md"
      ],
      "stage0Domains": [
        "S0-R"
      ],
      "testPaths": [
        "crates/gc_obligations/src/tests/frontend_contracts.rs",
        "crates/gc_wasi_cli/tests/cli_coreform_frontend_profile.rs"
      ],
      "title": "Frontend canonical CoreForm bytes, module identity, and spans",
      "verifierPaths": [
        "scripts/lib/selfhost_frontend_authority.py",
        "scripts/selfhost_frontend_authority_guard.sh",
        "scripts/check_selfhost_boundary.sh"
      ]
    }
  ],
  "version": "0.1"
}
