Skip to content

Python First Admission and Historical Trust

Python First Admission and Historical Trust

Section titled “Python First Admission and Historical Trust”

The Python AdmissionService layers authenticated First Admission and Historical Trust above the six-stage Signed Document verifier (MWP-ADM-005). The controlling language-independent flow is the local First Admission and Historical Trust runtime page, and the exact requirements are the local First-Admission and Historical-Trust clauses.

Public API Responsibility
AdmissionCurrentKeyResolver.resolve_current Return complete Organization-wide Registry evidence that the deployment asserts is current for a new first-admission decision.
TrustedAdmissionContext.issue Issue the trusted record ID, trusted acceptance instant, and accepting service only after authoritative absence.
AdmissionLog.lookup Return AdmissionLookupStatus.FOUND with authenticated bytes or AdmissionLookupStatus.AUTHORITATIVE_ABSENCE. Transport failure, cache miss, indeterminate state, and unauthenticated absence fail closed under MWP-ADM-003.
AdmissionLog.append_or_return_existing Atomically append candidate bytes or return the concurrent authoritative winner.
AuthenticatedAdmissionRecord Bind returned record bytes to the accepting service identity authenticated by the adapter for MWP-ADM-009 validation.
AdmissionService.prepare_first_admission Create and validate candidate bytes from an already verified document and trusted context. It does not append or imply admission.
AdmissionService.admit_first Implement the current-evidence, authoritative-absence, atomic append, and returned-record flow in MWP-ADM-006.
AdmissionService.verify_historical_admission Rerun verification with historical Registry evidence and require a found record without issuing context or appending, as required by MWP-ADM-008.

The adapter result is typed evidence. A caller-provided trust boolean is not an authoritative lookup outcome and must never select the success path.

admit_first verifies before calling the log. When lookup returns AdmissionLookupStatus.AUTHORITATIVE_ABSENCE, it calls prepare_first_admission, invokes append_or_return_existing, then validates the record actually returned. A concurrent winner is acceptable only when its bytes, authenticated service, document binding, and trusted time all validate (MWP-ADM-009, MWP-ADM-010).

Historical replay uses retained Registry history, requires a found Admission record, and never calls TrustedAdmissionContext.issue or AdmissionLog.append_or_return_existing. Matching record IDs in the example demonstrate that replay recovered the first authoritative record; they do not by themselves prove Command freshness, signer authorization, state-machine acceptance, or portable log-proof verification. Command freshness and signer authorization remain separate requirements under MWP-ADM-013 and MWP-ADM-014.

Post-cryptographic Admission rejection remains protected stage admission and wire code AUTH_INVALID_SIGNATURE (MWP-ADM-012).