Operate / Protocol and platform integrators
Interoperability
Exchange proof objects across systems without letting transport formats or foreign metadata replace the enclosing Receiz artifact.
Implementation rail · Receiz interoperability adapters and canonical verifier
Exact execution and operator checks
- 01
Operator check
Bind both systems
Record source and destination versions, carrier bytes, enclosing artifact digest, adapter version, schema mapping, and every external authority claim that must be rejected.
Substantive records: /reference/compatibility · /reference/schemas-test-vectors
Expected: The transport boundary cannot replace the proof boundary.
- 02
Exact mechanic
Inspect installed migration mechanics
pnpm exec receiz migrate v105-v106 --verify --root .- Mechanic
- receiz migrate v105-v106 --verify
- Authentication and account boundary
- Local repository and filesystem custody; no Receiz account is implied.
- Exact source
node_modules/@receiz/sdk/dist/cli.js· SHA-256 a0e99f2429ccaf2a2a4adc31bb19b9ecb7bffbcaba03a9439c99310b200e0232
Expected: The installed CLI verifies the migration inventory without inventing artifact truth.
- 03
Exact mechanic
Run test:interoperability-conformance
pnpm test:interoperability-conformance- Mechanic
- pnpm test:interoperability-conformance
- Authentication and account boundary
- Authorized local repository checkout; the command proves only the checked repository boundary.
- Exact source
package.json· SHA-256 132f99232dfaf26f7186b73752938d1377042808f42d60d374fe7b2e57c7646b
Expected: Carrier, wrapper, version, digest, and authority-boundary tests pass.
- 04
Operator check
Round-trip exact bytes
Export, import, and re-export the complete artifact across the destination; compare enclosing bytes or declared canonical digest and verify again.
Substantive records: /trust/conformance
Expected: The round trip preserves artifact identity and exact failure meanings.
Complete operating anatomy
Every boundary required to ship.
- Solved outcome
- Imported and exported artifacts preserve exact identity, carrier bytes, provenance, verification, and declared external boundaries.
- Prerequisites
- Hold source and destination systems, package and adapter versions, exact enclosing artifact bytes and digest, schema mapping, external wrapper, trusted roots, round-trip target, and rollback head.
- Exact primitive
- cross-system proof continuity
- Governing law
- Interoperability is governed by interoperability-conformance: A passing execution confirms the checked cross-system proof invariants for the exact repository state exercised. canonical-artifact-verifier: The verifier classifies the supplied artifact. Embedded subpayloads and remote responses remain subordinate. invariant-first: A weaker observation cannot rewrite an already verified stronger fact.
- Source-of-truth order
- Receiz law → sealed artifact truth → deterministic proof object state → verified durable local or register truth → authenticated snapshot → server distribution, synchronization, indexing, and publication → database, session, observability, and interface projections.
- Expected artifact, receipt, or state
- An interoperability receipt binding source system, target system, exact artifact digest, transformation boundary, and verification result.
- Inspection
- Inspect the enclosing artifact, transport wrapper, adapter version, digest continuity, and rejected external authority claims. Inspection exposes structure and receipt fields; inspection never establishes verification.
- Independent verification
- Independent verification for interoperability: pnpm test:interoperability-conformance. This establishes only the cross-system proof continuity boundary named by the bound sources; The implementation rail remains beneath proof authority: Receiz interoperability adapters and canonical verifier.
- Offline behavior
- Exported artifacts retain independent verification after origin-system loss; transport availability is not required once bytes are held.
- Identity and account boundary
- Public Record Moment, Seal File, Verify, Export, and public proof reading are account-free. Identity is optional and adds continuity, custody, recovery, and governed private controls after proof admission.
- Security boundary
- Treat foreign metadata, identities, signatures, and provider status as external inputs until bound beneath an accepted Receiz primitive.
- Conformance command
pnpm test:interoperability-conformance- Deployment checks
- Qualify import and export byte domains, schema versions, adapter pinning, digest continuity, unsupported cases, external-authority rejection, cross-platform round trip, local verification, and rollback.
- Production checklist
- Export; hash; import; reject unsupported wrapper; preserve enclosing artifact; re-export; compare bytes or canonical digest; verify; test legacy fixture; test external signature non-authority; rollback.
- Rollback and containment
- Containment for interoperability: Artifact continuity fails. Restore the complete artifact and correct the adapter. Authority is inverted. Verify the stronger Receiz artifact first, then project the wrapper beneath it. Interoperability is unproven. Pin compatible versions and recover the original artifact from custody. Preserve every stronger held artifact and admitted state while the named boundary is corrected.
Fail closed
Mutation and failure matrix
Adapter changes or strips enclosing artifact bytes.
- Effect
- Artifact continuity fails.
- Retry
- Do not admit the projected subpayload alone.
- Recovery
- Restore the complete artifact and correct the adapter.
External wrapper, metadata, or signature is promoted above Receiz proof.
- Effect
- Authority is inverted.
- Retry
- Reject the external authority claim.
- Recovery
- Verify the stronger Receiz artifact first, then project the wrapper beneath it.
Round-trip digest or verification status differs.
- Effect
- Interoperability is unproven.
- Retry
- Stop publication to the destination.
- Recovery
- Pin compatible versions and recover the original artifact from custody.
Exact authority
Claim-to-source bindings
A passing execution confirms the checked cross-system proof invariants for the exact repository state exercised.
scripts/test_interoperability_conformance.tsexecutable-conformance · SHA-256 c09d81f36305004f7ee02c40070b3c9cd64d8f5572ce12d211c022f3e75dbf4eThe verifier classifies the supplied artifact. Embedded subpayloads and remote responses remain subordinate.
packages/receiz-sdk/src/artifactVerification.tsimplementation-verifier · SHA-256 c10cdba92568fea273e1d9e7a3321083d52945378ab0cc83aee9720d44f0bba3A weaker observation cannot rewrite an already verified stronger fact.
docs/invariant-first-kernel.mdnormative-doctrine · SHA-256 0617593ee5e1a39d51ebd6ccd3d50453b2c717723edc4a1a5f3ed496872c347c
One complete system