{"apiVersion":"v1","matrix":{"$comment":"Layer 2 assistant conformance matrix — schema v2 (P1c, MSG-2065 note 2 / MSG-2071). REPO-ONLY until the P1c drill validates; /trust publication is gated on the drill. Values: covered | partial | not_covered | unknown. UNKNOWN means untested, not assumed. RULE (enforced by scripts/proofs/conformance_matrix_test.js): any cell valued covered or partial MUST carry a `proof` id referencing conformance/proofs/<id>.json whose result is pass and whose lastRun is < 30 days old — otherwise CI fails. A cell moves ONLY when its proof passes.","version":2,"updated":"2026-09-16","capabilities":{"commit_gate":"staged files evaluated by the governance server at commit time (pre-commit hook)","author_attribution":"author_type (human|agent|machine|unknown) attached to ownership signals / verdict envelopes","transcript_locality":"AI transcripts never leave the machine (serializer forbids transcript/trailer/message fields)","ownership_signals":"local git aggregates uploadable via `ovyero ownership scan` (counts + classification only)"},"assistants":{"claude-code":{"commit_gate":{"value":"covered","proof":"commit-gate-hook","note":"commits made by Claude Code run the installed pre-commit hook like any git commit"},"author_attribution":{"value":"covered","proof":"agent-trailer-claude","note":"Co-Authored-By: Claude … <noreply@anthropic.com> trailer → agent (weighted majority per path/author); human committer preserved"},"transcript_locality":{"value":"covered","proof":"no-transcript-egress"},"ownership_signals":{"value":"covered","proof":"ownership-scan-local"}},"openai-codex":{"commit_gate":{"value":"unknown","note":"untested: Codex CLI commits via git and should invoke pre-commit hooks — do not claim until a fixture proves it"},"author_attribution":{"value":"unknown","note":"no trailer pattern verified yet; if Codex stamps a Co-authored-by trailer it joins the fixture-proven agent table, never a guessed regex"},"transcript_locality":{"value":"unknown","note":"Codex is reported to keep transcripts local (advisor input 2026-09-16); OUR pipeline stores none regardless — the unknown is about the assistant's side until verified"},"ownership_signals":{"value":"covered","proof":"ownership-scan-local"}},"cursor":{"commit_gate":{"value":"covered","proof":"commit-gate-hook","note":"gate fires on git commit; apply-without-commit edits are ungoverned until committed"},"author_attribution":{"value":"partial","proof":"bot-and-unknown-attribution","note":"no trailer signal from Cursor; commits attributed to the human committer with author_type unknown (honest)"},"transcript_locality":{"value":"unknown","note":"Cursor's own cloud sync of chats is outside our control; OUR pipeline stores none — the unknown is about the assistant's side"},"ownership_signals":{"value":"covered","proof":"ownership-scan-local"}},"github-copilot":{"commit_gate":{"value":"covered","proof":"commit-gate-hook"},"author_attribution":{"value":"not_covered","note":"inline completions are indistinguishable from typing at commit time; no signal exists to attribute"},"transcript_locality":{"value":"unknown"},"ownership_signals":{"value":"covered","proof":"ownership-scan-local"}},"windsurf":{"commit_gate":{"value":"unknown","note":"untested: whether Windsurf's auto-commit flows invoke pre-commit hooks has not been verified — do not claim until the drill tests it"},"author_attribution":{"value":"unknown"},"transcript_locality":{"value":"unknown"},"ownership_signals":{"value":"covered","proof":"ownership-scan-local"}},"aider":{"commit_gate":{"value":"partial","proof":"commit-gate-hook","note":"aider auto-commits; hooks fire, but aider surfaces hook failures poorly — gate blocks work, UX of the block is degraded"},"author_attribution":{"value":"covered","proof":"agent-trailer-aider","note":"Co-authored-by: aider (…) trailer → agent; human committer preserved"},"transcript_locality":{"value":"covered","proof":"no-transcript-egress"},"ownership_signals":{"value":"covered","proof":"ownership-scan-local"}},"raw-git":{"commit_gate":{"value":"covered","proof":"commit-gate-hook"},"author_attribution":{"value":"partial","proof":"bot-and-unknown-attribution","note":"human by default; author_type 'unknown' is the honest envelope value unless an identities mapping asserts human"},"transcript_locality":{"value":"covered","proof":"no-transcript-egress","note":"no assistant involved"},"ownership_signals":{"value":"covered","proof":"ownership-scan-local"}},"ci-bots (Jenkins, Dependabot, GitHub Actions)":{"commit_gate":{"value":"not_covered","note":"non-interactive committers bypass local hooks entirely — see docs/LAYER2_CI_BOT_SPIKE.md"},"author_attribution":{"value":"partial","proof":"bot-and-unknown-attribution","note":"ATTRIBUTED (author_type machine + machine_kind via the classifier), NOT gated — the spike's P1c recommendation, shipped"},"transcript_locality":{"value":"covered","proof":"no-transcript-egress"},"ownership_signals":{"value":"partial","proof":"bot-and-unknown-attribution","note":"bot activity is recorded and surfaced as machineActivity but bots are never owners"}}}},"proofs":{"agent-trailer-aider":{"id":"agent-trailer-aider","claim":"A commit carrying a `Co-authored-by: aider (…)` trailer is classified author_type agent / agentKind aider with the human committer preserved as author.","command":"node scripts/proofs/commit_classifier_test.js","fixture":"message 'fix: tighten parser\\n\\nCo-authored-by: aider (gpt-4o) <aider@aider.chat>' by alice@acme.com","expected":"authorType=agent, agentKind=aider, author=alice@acme.com; body mentions and unknown trailers do NOT match","lastRun":"2026-09-16","result":"pass","evidence":"commit_classifier_test.js cases 'aider trailer -> agent/aider', 'human committer preserved', 'body mention alone is NOT a match'"},"agent-trailer-claude":{"id":"agent-trailer-claude","claim":"A commit carrying a `Co-Authored-By: Claude … <noreply@anthropic.com>` trailer is classified author_type agent / agentKind claude-code; per (path, author) the label applies by weighted majority of touched lines.","command":"node scripts/proofs/commit_classifier_test.js && node -e \"const {computeGitDoa}=require('./scripts/ownership-scan.js');const r=computeGitDoa(process.cwd(),{maxCommits:400});process.exit(r.some(x=>x.authorType==='agent')?0:1)\"","fixture":"this repository's own 2026-09-16 commits (live fixture) + the unit fixture in commit_classifier_test.js","expected":"classifier: authorType=agent, agentKind=claude-code; live scan of this repo yields agent rows (312/327 on 2026-09-16) with no trailer/message/content field on any row","lastRun":"2026-09-16","result":"pass","evidence":"commit_classifier_test.js 'Claude Code trailer -> agent/claude-code'; ownership-scan dry-run distribution {agent:312, unknown:15}"},"bot-and-unknown-attribution":{"id":"bot-and-unknown-attribution","claim":"Known bot identities (dependabot, renovate, github-actions, CI, *[bot]) are classified author_type machine with a machine_kind; bots take precedence over agent trailers; bots are never owners (excluded from DOA, surfaced as machineActivity); a bare human email classifies as unknown (humanity never asserted) unless an identities mapping asserts it.","command":"node scripts/proofs/commit_classifier_test.js && node scripts/proofs/ownership_resolver_test.js","fixture":"six bot fixtures + bot-precedence case in commit_classifier_test.js; AC-8 cases in ownership_resolver_test.js (5000 bot lines vs 120 human lines → human owns; bot-only → UNKNOWN 'bots are never owners')","expected":"machine/<kind> for every bot fixture; unknown for a bare email; human only via mapping; bots excluded from ownership","lastRun":"2026-09-16","result":"pass","evidence":"commit_classifier_test.js 21/21; ownership_resolver_test.js 30/30 (AC-8 block)"},"commit-gate-hook":{"id":"commit-gate-hook","claim":"A git commit with governed file types runs the Ovyero pre-commit gate and is blocked on findings / allowed on PASS.","command":"node scripts/proofs/v415_verifier_suite.js","fixture":"the repo's own commit history: ovyero_artifacts/OVYERO_VERDICTS.md records PASS/BLOCKED verdicts for every governed commit; 2026-09-16 shows three consecutive BLOCKED attempts on the forensics surface commit before a PASS","expected":"gate verdict recorded for each governed commit; BLOCKED prevents the commit","lastRun":"2026-09-16","result":"pass","evidence":"OVYERO_VERDICTS.md entries 2026-09-16 (67ffcc4 lineage); v415 119/119"},"no-transcript-egress":{"id":"no-transcript-egress","claim":"No transcript, trailer, message, code, diff, or content field can be stored server-side or leave the machine: the serializer allowlist drops them and the boot-guard refuses to allowlist any FORBIDDEN field.","command":"node scripts/proofs/forensic_serialize_test.js && node scripts/proofs/egress_identity_test.js","fixture":"FORBIDDEN_FIELDS = token, code, source, diff, content, transcript, secret, apiKey, key, password, trailer, message; records carrying those fields serialized through every allowlisted type","expected":"forbidden fields absent from every serialized record; CLI egress report byte-identical to the server route; module refuses to load if a forbidden field is ever allowlisted (caught its own author on 2026-09-16 with 'source')","lastRun":"2026-09-16","result":"pass","evidence":"forensic_serialize_test.js 14/14; egress_identity_test.js 9/9; Hivemind MSG-2063 live ingress attack (STOLEN_CODE/DIFF_BODY/AGENT_LEAK stripped); live_forensics_ac_suite.js 21/21"},"ownership-scan-local":{"id":"ownership-scan-local","claim":"`ovyero ownership scan` computes authorship aggregates locally from git metadata and uploads only {path, signalSource, owner, weight, lastTouchedAt, authorType} — no diffs, messages, or content.","command":"node scripts/ownership-scan.js scan --dry-run","fixture":"any git repository (this one on 2026-09-16: 1645 aggregates)","expected":"dry-run prints the exact rows that would upload; every row has only the six allowlisted fields; nothing uploaded in dry-run","lastRun":"2026-09-16","result":"pass","evidence":"dry-run output 2026-09-16; egress_identity_test.js 'ownership_signal drops commitMessage'; Hivemind MSG-2063 AC-6 client-side capture"}},"rule":"Any cell valued covered or partial must cite a proof that exists, passed, and ran within 30 days; scripts/proofs/conformance_matrix_test.js enforces this in CI."}