Go First Admission and Historical Trust
Go First Admission and Historical Trust
Section titled “Go First Admission and Historical Trust”The Go AdmissionService layers First Admission and Historical Trust above the
six-stage Signed Document verifier
(MWP-ADM-005).
The language-independent flow is the local
First Admission and Historical Trust runtime page,
and the exact requirements are the local
First-Admission and Historical-Trust clauses.
Public adapters and results
Section titled “Public adapters and results”| Public API | Responsibility |
|---|---|
AdmissionCurrentKeyResolver.ResolveCurrent |
Return complete Organization-wide Registry evidence that the deployment asserts is current for this decision. |
TrustedAdmissionContext.Issue |
Issue the trusted record ID, acceptance instant, and accepting service only after authoritative absence. |
AdmissionLog.Lookup |
Return a found authenticated record or AdmissionLookup{AuthoritativeAbsence: true}. Cache miss, timeout, unauthenticated absence, and indeterminate state fail closed under MWP-ADM-003. |
AdmissionLog.AppendOrReturnExisting |
Atomically append candidate bytes or return the concurrent authoritative winner through an authenticated service identity. |
AuthenticatedAdmissionRecord |
Bind RecordBytes to the service authenticated by the adapter so MWP-ADM-009 can validate the returned record. |
AdmissionService.PrepareFirstAdmission |
Create and validate candidate evidence from an SDK-produced VerifiedSignedDocument. It does not append or imply admission. |
AdmissionService.AdmitFirst |
Perform current verification, authoritative lookup, candidate creation, atomic append-or-return-existing, and returned-record validation under MWP-ADM-006. |
AdmissionService.VerifyHistoricalAdmission |
Rerun six-stage verification with historical Registry evidence and require an existing record without issuing context or appending, as required by MWP-ADM-008. |
AdmittedSignedDocument |
Return verified and parsed record evidence plus a defensive RecordBytes() copy. |
A caller-provided trust boolean is not an Admission lookup outcome and must never select the success path.
First-admission call order
Section titled “First-admission call order”AdmitFirst completes all six signed-document stages before consulting the log.
A found record is validated and returned without issuing trusted context or
appending. After authoritative absence, the service issues trusted context,
calls PrepareFirstAdmission, invokes AppendOrReturnExisting, snapshots the
returned value, and validates the record actually returned. A concurrent winner
is acceptable only when its Schema, authenticated service, document binding, and
trusted time pass
MWP-ADM-009
and
MWP-ADM-010.
Historical replay
Section titled “Historical replay”Historical replay reruns verification with retained Registry history, requires a
found record, and never calls TrustedAdmissionContext.Issue or
AdmissionLog.AppendOrReturnExisting. Matching record IDs demonstrate recovery
of the same authoritative record; they do not prove Command freshness, signer
authorization, state-machine acceptance, or portable log-proof verification.
Those remain separate under
MWP-ADM-013
and
MWP-ADM-014.
Error surface
Section titled “Error surface”AdmissionError.WireCode() returns AUTH_INVALID_SIGNATURE, while
ProtectedDiagnostic().Stage() returns admission. Stable protected reasons
distinguish missing, conflicting, malformed, unauthenticated, unavailable,
indeterminate, and self-anchoring evidence while preserving the non-oracular
wire result required by
MWP-ADM-012.
Deployment adapters should return NewAdmissionAdapterError with a supported
reason when they need the service to remap a trusted local failure. Arbitrary
errors are not proof of authoritative absence.