Skip to content

Go First Admission and Historical Trust

The Go AdmissionService layers First Admission and Historical Trust above the six-stage Signed Document verifier (MWP-ADM-005). The language-independent flow is the local First Admission and Historical Trust runtime page, and the exact requirements are the local First-Admission and Historical-Trust clauses.

Public API Responsibility
AdmissionCurrentKeyResolver.ResolveCurrent Return complete Organization-wide Registry evidence that the deployment asserts is current for this decision.
TrustedAdmissionContext.Issue Issue the trusted record ID, acceptance instant, and accepting service only after authoritative absence.
AdmissionLog.Lookup Return a found authenticated record or AdmissionLookup{AuthoritativeAbsence: true}. Cache miss, timeout, unauthenticated absence, and indeterminate state fail closed under MWP-ADM-003.
AdmissionLog.AppendOrReturnExisting Atomically append candidate bytes or return the concurrent authoritative winner through an authenticated service identity.
AuthenticatedAdmissionRecord Bind RecordBytes to the service authenticated by the adapter so MWP-ADM-009 can validate the returned record.
AdmissionService.PrepareFirstAdmission Create and validate candidate evidence from an SDK-produced VerifiedSignedDocument. It does not append or imply admission.
AdmissionService.AdmitFirst Perform current verification, authoritative lookup, candidate creation, atomic append-or-return-existing, and returned-record validation under MWP-ADM-006.
AdmissionService.VerifyHistoricalAdmission Rerun six-stage verification with historical Registry evidence and require an existing record without issuing context or appending, as required by MWP-ADM-008.
AdmittedSignedDocument Return verified and parsed record evidence plus a defensive RecordBytes() copy.

A caller-provided trust boolean is not an Admission lookup outcome and must never select the success path.

AdmitFirst completes all six signed-document stages before consulting the log. A found record is validated and returned without issuing trusted context or appending. After authoritative absence, the service issues trusted context, calls PrepareFirstAdmission, invokes AppendOrReturnExisting, snapshots the returned value, and validates the record actually returned. A concurrent winner is acceptable only when its Schema, authenticated service, document binding, and trusted time pass MWP-ADM-009 and MWP-ADM-010.

Historical replay reruns verification with retained Registry history, requires a found record, and never calls TrustedAdmissionContext.Issue or AdmissionLog.AppendOrReturnExisting. Matching record IDs demonstrate recovery of the same authoritative record; they do not prove Command freshness, signer authorization, state-machine acceptance, or portable log-proof verification. Those remain separate under MWP-ADM-013 and MWP-ADM-014.

AdmissionError.WireCode() returns AUTH_INVALID_SIGNATURE, while ProtectedDiagnostic().Stage() returns admission. Stable protected reasons distinguish missing, conflicting, malformed, unauthenticated, unavailable, indeterminate, and self-anchoring evidence while preserving the non-oracular wire result required by MWP-ADM-012.

Deployment adapters should return NewAdmissionAdapterError with a supported reason when they need the service to remap a trusted local failure. Arbitrary errors are not proof of authoritative absence.