{
  "id": "C3-CAV-2026-0001",
  "schema_version": "control-verification-artifact-v0.1",
  "record_version": "0.1",
  "record_type": "control_verification_sample",
  "document_status": "SAMPLE_NOT_CERTIFICATION",
  "title": "C³ 制御検証記録サンプル — 承認条件",
  "source_record": {
    "repository": "c3infogm-rgb/c3-its-poc",
    "source_snapshot_commit": "c19227735b4c1a358f6758f6580d8e438eaa5e78",
    "source_path": "research/third_party_verification_record_v0_1/verification_record.json",
    "source_record_id": "C3-THIRD-PARTY-VERIFICATION-RECORD-SAMPLE-0001"
  },
  "control": {
    "control_id": "LG-PASS-APPROVED-NO-SIDE-EFFECT",
    "statement_ja": "PASS判定には承認が必要",
    "declared_property": "PASS requires approval_present=true.",
    "tested_target": "approval_present == true",
    "witness_ids": [
      "approval-empty"
    ]
  },
  "target": {
    "fixed_sha": "912ad7c5e10070fb514f18cfb4583e132d4f8a4a",
    "remediation_merged_main_sha": "c59f866bd107dcde061f257e4b99a125a8bf13c6",
    "fix_pr": 127
  },
  "verification": {
    "state": "NO_GAP_OBSERVED_FOR_DECLARED_WITNESS_SET",
    "customer_display": "検証済み",
    "same_witness_rerun": true,
    "before": {
      "observed_verdict": "PASS",
      "permit_token_issued": true,
      "predicate_status": "GAP_CONFIRMED"
    },
    "after": {
      "observed_verdict": "HOLD",
      "permit_token_issued": false,
      "predicate_status": "NO_GAP_OBSERVED_FOR_DECLARED_WITNESS_SET",
      "reason_code": "EAG_APPROVAL_MISSING"
    },
    "counterexample_candidate_count_after": 0,
    "negative_controls": {
      "count_pass": 3,
      "count_total": 3,
      "status": "PASS"
    }
  },
  "evidence_binding": {
    "artifact_digest": "sha256:c4fec26e648c23759dd8685fa4064b0a9800814b99f291ff297295d46cdb0ef7",
    "artifact_id": 9150047892,
    "bundle_id": "C3-BUNDLE-INTERNAL-APPROVAL-CLOSURE-001",
    "bundle_path": "research/structural_audit_bundle_schema_v0_1/examples/internal_approval_closure.json",
    "evidence_head": "6dc6b3736f6dc84f7f1590aaebfe3e016f9b6c1e",
    "evidence_pr": 118,
    "registry_record_id": "C3-POLICY-REAL-003",
    "workflow_run": 31618003025
  },
  "recalculation": {
    "principle": "Recompute the record from the registry-bound canonical bundle; do not trust the human-readable page by itself.",
    "bundle_validation_command": "PYTHONPATH=. python research/structural_audit_bundle_schema_v0_1/validate_bundle.py research/structural_audit_bundle_schema_v0_1/examples/internal_approval_closure.json",
    "record_validation_command": "PYTHONPATH=. python research/third_party_verification_record_v0_1/validate_verification_record.py"
  },
  "integrity": {
    "hash_scope": "raw_bytes_of_this_published_artifact",
    "hash_method": "sha256(raw_bytes)",
    "signature_status": "not_applied",
    "note_ja": "ブラウザ再確認は、この公開JSONの実バイト列をSHA-256で再計算し、ページ表示の期待値と照合する。制御条件そのものをブラウザで再実行するものではない。"
  },
  "claim_boundary": {
    "means": [
      "宣言した approval-empty 反例について、修正前は PASS / permit発行、修正後は HOLD / permit非発行へ変化した記録である。",
      "修正後の同じ反例について、NO_GAP_OBSERVED_FOR_DECLARED_WITNESS_SET が記録されている。",
      "公開JSONの実バイト列は、ブラウザでSHA-256を再計算して完全性を再確認できる。"
    ],
    "does_not_mean": [
      "リポジトリ全体またはシステム全体が安全であること。",
      "未検査の実行経路・制御条件・反例集合について同じ結果になること。",
      "形式検証、第三者認証、適合認証、法令準拠を取得したこと。",
      "将来のリリースでも同じ結果になること。",
      "ブラウザのハッシュ一致だけで制御条件の正しさが証明されたこと。"
    ]
  }
}
