Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Distributed Cognitive Network

Volume VII — Cognitive ABI Specification 0.1

Part 4 — Canonical Lifecycle, State Machines, Security Properties, and Schema Roadmap


73. Purpose

This part closes Cognitive ABI 0.1 by defining the canonical lifecycle connecting the objects introduced in Parts 1–3, the minimum security properties an implementation must preserve, and the executable-schema roadmap required to turn the prose specification into a testable standard.


74. Canonical Cognitive Transaction

A cognitive transaction is the causally connected set of ABI interactions used to satisfy a goal or requirement. It is not necessarily a database transaction and may span local and remote components.

The baseline lifecycle is:

Observation / Goal
       ↓
Context Assembly
       ↓
Recognition
       ↓
CapabilityRequirement
       ↓
CapabilityResolution
       ↓
ExpertBinding
       ↓
ExecutionRequest
       ↓
ExecutionResult
       ↓
Validation / Evaluation
       ↓
PatchProposal (when state change is proposed)
       ↓
Authorization
       ↓
Commit
       ↓
KLineEpisode
       ↓
Learning / Compilation

Not every interaction requires every stage. Omitted stages MUST be justified by the semantics of the capability rather than silently bypassed.


75. Execution State Machine

Canonical execution states are:

created
  ↓
accepted
  ↓
running
  ├──→ waiting
  │      ↓
  │    running
  ↓
completed

Terminal alternatives are:

failed
cancelled
expired

An implementation MUST emit exactly one terminal state for an execution.


76. Patch State Machine

A PatchProposal follows:

created
  ↓
validated
  ↓
authorized
  ↓
committed

Alternative terminal states include:

rejected
conflicted
cancelled
expired

Execution completion MUST NOT be treated as patch commitment.


77. Evaluation State Machine

An evaluation follows:

requested
  ↓
accepted
  ↓
running
  ↓
completed

The completed result MUST identify its subject, protocol, environment or distribution commitments where applicable, evaluator, result, and evidence references.

An evaluation result is contextual evidence, not universal truth.


78. Compilation State Machine

Compilation follows:

candidate identified
       ↓
CompilationRequest
       ↓
compiling
       ↓
ArtifactCandidate
       ↓
evaluation
       ↓
eligible for publication/promotion

The ABI does not permit a compiler to mark its own output as trusted merely by completing compilation.


79. Causal Lineage

Every state transition SHOULD preserve sufficient causality to answer:

What caused this?
Which goal did it serve?
Which context was exposed?
Which capability was requested?
Which provider or artifact was bound?
What evidence was produced?
What evaluation was applied?
Which state change resulted?
What later cognition was learned from it?

Causal lineage is a first-class interoperability property.


80. Commitment Boundary

Private content and public or federated history are separated by commitments and references.

A component SHOULD expose the minimum information required for its role.

Example:

private prompt
    ↓ hash/commitment
ExecutionRequest
    ↓
remote execution
    ↓
private response
    ↓ hash/commitment
ExecutionResult
    ↓
Actum evidence reference

The ABI does not require raw private payloads to become globally visible.


81. Authority Non-Amplification

A component MUST NOT derive broader authority than it receives.

If authority permits:

send one email to recipient R

an adapter, K-line, expert, or artifact MUST NOT reinterpret that authority as:

send arbitrary email

Authority transformations MUST be monotonic toward equal or narrower scope unless a new authority grant is obtained.


82. Privacy Non-Degradation

A component MUST NOT silently weaken a mandatory privacy requirement during capability resolution, composition, adaptation, or fallback.

If a requirement specifies local_only, a resolver cannot satisfy it with a remote provider because the remote provider has higher quality.

Fallbacks that alter privacy class require explicit policy authorization.


83. Evidence Non-Degradation

Evidence requirements are also monotonic.

A provider requiring provider_authenticated + transcript_commitment cannot be replaced by an otherwise equivalent provider producing only a self-signed receipt unless local policy explicitly permits the weaker class.

The exact evidence mechanism remains late-bound.


84. Context Non-Expansion

Adapters and composed components MUST NOT receive more context merely because the Runtime Host possesses it.

Context assembly SHOULD implement least disclosure:

whole Mind state
      ≠
component context

A ContextSlice is a capability-specific view, not a serialization of the entire Mind.


85. Provider Substitution

Late binding permits provider substitution only while preserving the mandatory semantic contract.

Substitution MUST preserve or improve mandatory:

capability semantics
schema compatibility
authority constraints
privacy constraints
evidence constraints
jurisdiction constraints
side-effect class

Cost, latency, energy, and expected quality may then be optimized among admissible candidates.


86. Confused-Deputy Resistance

The Runtime Host MUST bind authority to the intended execution context rather than merely to component identity.

A component trusted for one capability MUST NOT reuse authority from that execution for another capability or goal.

Correlation identifiers are not authorization tokens.


87. Prompt and Data Injection Boundary

External content is data unless explicitly promoted through a trusted interpretation process.

Retrieved documents, web pages, emails, market descriptions, expert outputs, and K-lines obtained from federation MUST NOT automatically acquire runtime authority because they contain imperative language.

The ABI SHOULD preserve source provenance and trust classification for externally supplied content.


88. Artifact Supply-Chain Security

An artifact descriptor SHOULD bind:

artifact identity
content hash
template identity
compiler identity
build or compilation lineage
dependencies
evaluation references
runtime requirements
publisher

Artifact installation does not imply activation or authority.


89. K-Line Supply-Chain Security

Federated K-lines are executable cognitive supply-chain content.

A Runtime Host SHOULD require discovery, inspection, verification, trust evaluation, caching, and local activation before a remote K-line participates in System 1.

Remote publication MUST NOT directly modify local procedural cognition.


90. Market Isolation

Economic incentives MUST NOT override semantic admissibility.

Actum Compute may rank and price candidates, but the Runtime Host retains local authority to reject every market result.

A market cannot grant a provider trust merely by accepting payment or stake.


91. Evaluation Independence

Where policy requires independent evaluation, the evaluator MUST be logically distinct from the subject being evaluated according to the applicable trust policy.

The ABI MUST preserve evaluator identity or commitment sufficiently for this property to be checked.


92. Replay Resistance

Replay protection MAY occur at several layers:

ABI execution idempotency
provider request nonce
Actum nullifier
authority nonce
payment/settlement nullifier

Implementations MUST use the replay mechanism appropriate to the effect being protected.


93. Time and Freshness

Messages SHOULD carry timestamps and MAY carry deadlines, validity windows, freshness challenges, or monotonic counters.

Security-sensitive decisions MUST NOT rely on untrusted wall-clock timestamps alone when stronger freshness evidence is required.


94. Resource Exhaustion

Runtime Hosts SHOULD enforce limits on:

message size
context size
concurrent executions
recursive composition depth
K-line activation depth
stream duration
retry count
market discovery breadth
compiler workload

A Society of Experts must not become an unbounded fan-out mechanism.


95. Recursive Cognition Safety

Nested Agencies, K-lines, compilers, and remote Minds MAY recursively request capabilities.

The Runtime Host SHOULD preserve a causal depth counter or equivalent execution graph and MUST be able to terminate recursion according to local policy.


96. Determinism Declaration

Components SHOULD declare one of:

deterministic
seeded_nondeterministic
nondeterministic
external_state_dependent

This declaration informs replay, evaluation, caching, and evidence policy.


97. Cache Semantics

Cached cognition MUST remain bound to the conditions under which reuse is valid.

A cache entry SHOULD identify:

input commitment
context/environment signature
artifact/provider identity
validity window
evaluation status
authority assumptions
privacy class

Caching MUST NOT turn an expired or unauthorized execution into valid cognition.


98. Canonical Schema Set

Cognitive ABI 0.1 SHOULD be backed by machine-readable schemas for at least:

CommonEnvelope
ComponentDescriptor
CapabilityDescriptor
Observation
Goal
ContextSlice
CapabilityRequirement
CapabilityResolution
ExpertBinding
ExecutionRequest
ExecutionResult
PatchProposal
ValidationResult
EvaluationRequest
EvaluationResult
KLineEpisode
CompilationRequest
ArtifactCandidate
RuntimeEvent
ErrorEnvelope
VersionNegotiation
CancellationRequest

99. Schema Generation

The repository SHOULD establish one canonical schema source and generate language bindings where practical.

The target layout is:

schemas/
  cognitive-abi/
    v1/
      *.schema.json
bindings/
  rust/
  typescript/
  swift/

Generated bindings MUST NOT become a competing source of protocol truth.


100. Conformance Fixtures

The repository SHOULD add:

conformance/
  valid/
  invalid/
  traces/
  security/

Fixtures SHOULD test both schema validity and semantic invariants that cannot be expressed in JSON Schema alone.


101. Reference Adapter Requirements

Reference adapters for MCP, A2A, Agent Plugins, Actum Compute, and Actum SHOULD be deliberately thin.

They translate between the Cognitive ABI and external protocols. They MUST NOT relocate cognitive policy into the transport adapter.


102. Stable Waist Principle

The Cognitive ABI is intentionally narrower than the complete DCN architecture.

Above it, cognition may evolve through new K-lines, experts, compiler techniques, evaluation methods, and applications.

Below it, execution may evolve through new transports, model providers, hardware, confidential-compute systems, proof systems, and markets.

The ABI remains the stable semantic waist between these layers.


103. Volume VII Invariants

A conformant implementation preserves the following invariants:

  1. Capability is semantic and provider-independent.
  2. Binding is late and evidence-aware.
  3. Context is minimized.
  4. Authority is explicit and non-amplifying.
  5. Execution success is distinct from authorization and state commitment.
  6. Evidence is preserved without being confused with truth.
  7. Failure is explicit.
  8. Causality and lineage survive transport boundaries.
  9. Transport protocols do not become cognitive policy.
  10. Local activation sovereignty is preserved.
  11. Version and extension negotiation fail closed for mandatory semantics.
  12. Learning and compilation remain connected to the executions from which they derive.

104. Completion of Cognitive ABI 0.1

Parts 1–4 define the conceptual Cognitive ABI 0.1.

The next maturity step is not additional prose. It is to make the ABI executable through canonical JSON Schemas, generated Rust/TypeScript/Swift bindings, golden interaction traces, and a conformance test suite.

Once those artifacts exist, independent DCN Runtime, Kline, Actum Compute, evaluator, compiler, and expert implementations can be tested against the same semantic contract.