Skip to content

C++ First Admission and Historical Trust

The C++ AdmissionService layers First Admission and Historical Trust above the six-stage Signed Document verifier (MWP-ADM-005). The language-independent flow is the local First Admission and Historical Trust runtime page, and the exact requirements are the local Admission clauses.

Public API Responsibility
AdmissionCurrentKeyResolver::resolve_current Return complete Organization-wide Registry evidence that the deployment asserts is current for this decision.
TrustedAdmissionContext::issue Issue the record ID, trusted acceptance instant, and accepting service only after authoritative absence.
AdmissionLog::lookup Return AdmissionLookup::found or AdmissionLookup::authoritative_absence. Cache miss, timeout, or unauthenticated absence fails closed under MWP-ADM-003.
AdmissionLog::append_or_return_existing Atomically append candidate bytes or return the concurrent authoritative winner through an authenticated service identity.
AuthenticatedAdmissionRecord Bind returned record bytes to the service identity authenticated by the adapter for MWP-ADM-009.
AdmissionService::prepare_first_admission Create and validate candidate evidence from an SDK-produced VerifiedSignedDocument; it does not append or imply admission.
AdmissionService::admit_first Verify current evidence, lookup, prepare after absence, append-or-return-existing, and validate the returned record under MWP-ADM-006.
AdmissionService::verify_historical_admission Rerun verification with historical Registry evidence and require an existing record without issuing context or appending under MWP-ADM-008.
PreparedFirstAdmission, AdmittedSignedDocument Preserve immutable verification and record evidence; record_bytes returns a view over the validated record bytes.

A caller-provided trust boolean is not an Admission lookup outcome and must never select the success path.

admit_first completes all six verification stages before log access. A found record is validated and returned without issuing trusted context or appending. After authoritative absence, the service issues context, prepares canonical candidate bytes, calls append_or_return_existing, and validates the record actually returned. A concurrent winner succeeds only when Schema, authentication, document binding, and trusted time satisfy MWP-ADM-009 and MWP-ADM-010.

verify_historical_admission uses KeyResolver, reruns all six stages, requires a found record, and never calls TrustedAdmissionContext::issue or AdmissionLog::append_or_return_existing. Matching record IDs recover the same authoritative record but do not prove Command freshness, signer authorization, state-machine acceptance, or portable log-proof verification under MWP-ADM-013 and MWP-ADM-014.

Six-stage faults remain SignedDocumentVerificationError. Admission-stage faults are AdmissionError with wire code AUTH_INVALID_SIGNATURE, stage admission, and a typed AdmissionReason, as required by MWP-ADM-012. Deployment adapters throw AdmissionAdapterError; generic success or availability is not authenticated evidence.