Runtime authority after uncertain consequences.
EvidenceBound Runtime Authority Benchmark on NVIDIA OpenShell tests whether recovery authority and trusted operation-lineage constraints remain enforceable at an independent pre-effect HTTP boundary immediately before a consequential side effect.
Independent runtime enforcement substrate
RAB-1 composes EvidenceBound authority semantics with stock NVIDIA OpenShell as an independent runtime enforcement substrate. The target is synthetic and non-idempotent: every accepted target contact creates a new consequence.
Same runtime. Same target. One authority layer changed.
Negative control: the same OpenShell runtime, network policy and target without EvidenceBound authority middleware. After an uncertain original consequence and retry, the control produced two target contacts and two consequences.
Controlled condition: the same OpenShell runtime and target with EvidenceBound authority middleware attached fail-closed.
12/12 hard gates
All precommitted hard gates passed in the frozen empirical result.
8/8 frozen scenarios
All frozen negative/control scenarios satisfied the precommitted verifier.
0 DENY → target contacts
No middleware-denied request ID appeared in target-contact evidence.
Recovery authority is not inferred from retry intent.
Uncertain outcome
Replay and replacement attempts after uncertain consequences are distinguished from fresh authority.
Revocation and lineage
Revoked, already-claimed, or wrong-lineage authority cannot create a replacement consequence.
Authorized recovery
After externally adjudicated NOT_COMMITTED and a fresh recovery grant, one replacement consequence is allowed.
Concurrent replay
Two concurrent attempts using the same operation authority produce one ALLOW and one target consequence.
Selective preservation
Blocking or revoking one lineage does not invalidate an unrelated valid authority.
Independent verifier
The verdict is computed from retained raw evidence by a verifier that does not import the runtime authority implementation.
Frozen identities and exact-tag regeneration.
| Anchor | Frozen value |
|---|---|
| OpenShell release | v0.1.2 |
| OpenShell source commit | 6648bd0c290efbc41ba131ee9831ee45cd431f94 |
| Execution tag | rab1-v1-full-pass-20260930 |
| Execution SHA | 5f4948894e0af6cb4a39f3823a400313c76d366b |
| Exact-tag regeneration | GitHub Actions run 36759924096 |
| Retained regeneration artifact | 73 retained files |
| Evidence manifest | 0 evidence hash failures |
| Core scenario records | Byte-identical to frozen primary |