<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.2.3) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

<!ENTITY RFC9943 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9943.xml">
<!ENTITY RFC9942 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9942.xml">
<!ENTITY RFC9052 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9052.xml">
<!ENTITY RFC8392 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8392.xml">
<!ENTITY RFC9597 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9597.xml">
<!ENTITY RFC8785 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8785.xml">
<!ENTITY RFC9162 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9162.xml">
<!ENTITY RFC2119 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY RFC8174 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
]>


<rfc ipr="trust200902" docName="draft-nestorov-scitt-p10-underdetermination-00" category="info" submissionType="IETF">
  <front>
    <title abbrev="P10 Underdetermination Profile">P10 Underdetermination Profile: Witness-Carrying Underdetermination Receipts for SCITT</title>

    <author fullname="Ivan Nestorov">
      <organization>VolMax Studio Lab d.o.o.</organization>
      <address>
        <email>volmax.core@gmail.com</email>
        <uri>https://orcid.org/0009-0006-7940-9539</uri>
      </address>
    </author>

    <date year="2026" month="September" day="28"/>

    <area>Security</area>
    
    <keyword>SCITT</keyword> <keyword>in-toto</keyword> <keyword>underdetermination</keyword> <keyword>receipt</keyword> <keyword>Lean</keyword>

    <abstract>


<?line 133?>

<t>P10 defines a third-party-verifiable binding for NotDemonstrated(reason=underdetermined). A conforming receipt carries two canonical witness worlds that are compatible with the same closed evidence set and produce different values for the same frozen claim. The witness result is checked against committed profile semantics and bound into a SCITT Transparent Statement containing an in-toto Statement v1 predicate. The result establishes underdetermination only relative to the declared profile and does not identify the actual world or establish either claim value as true.</t>



    </abstract>

    <note title="About This Document" removeInRFC="true">
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-nestorov-scitt-p10-underdetermination/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        scitt Working Group mailing list (<eref target="mailto:scitt@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/scitt/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/scitt/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/VolMax-Studio/p10-underdetermination-profile"/>.</t>
    </note>


  </front>

  <middle>


<?line 137?>

<section anchor="introduction"><name>Introduction</name>

<ul empty="true"><li>
  <t>The proposed P10 Underdetermination Profile defines a third-party-verifiable binding for <spanx style="verb">NotDemonstrated(reason=underdetermined)</spanx>. Issuance is permitted only when:
(1) the world class, admissible-evidence-bundle space and item-admission rules, frozen bundle constructor, compatibility relation, claim interpretation, evidence scope and coverage rules, canonicalization, world codec, committed log identity, leaf encoding, lifecycle/admitter authorization, and verifier were committed in a profile and an identified <spanx style="verb">InstanceCommitment</spanx> before the first evidence admission for that instance;
(2) within the committed transparency log <spanx style="verb">L</spanx>, exactly one profile and claim are bound to the <spanx style="verb">(issuer_id, request_id)</spanx> subject, and an <spanx style="verb">EvidenceClosure</spanx> plus checkpoint-bounded <spanx style="verb">CoverageProof</spanx> binds every valid, registered, in-scope admission made by a frozen authorized admitter through <spanx style="verb">S_R</spanx>;
(3) the receipt carries two semantically distinct worlds from that frozen world class, represented in the profile's frozen canonical serialization;
(4) the frozen verifier establishes that both witnesses are compatible with that same closed evidence set and assign different values to the same frozen claim; and
(5) the instance commitment, profile, claim, closed evidence set, witnesses, proof, verifier and mandatory limitations are SHA-256-bound in a SCITT Transparent Statement whose payload is an in-toto Statement v1 containing the P10 predicate, with complete VDS-prefix replay and registration/coverage verification satisfying <xref target="full-prefix-replay"/> through <xref target="evidence-closure-and-checkpoint-bounded-coverage"/>.
The result establishes underdetermination only relative to the declared profile and does not identify the actual world or establish either claim value as true.</t>
</li></ul>

<t><strong>Nature of the contribution:</strong> profile-and-binding contribution. It is not a new mathematical theorem.</t>

<section anchor="scope-and-relationship-to-scitt"><name>Scope and Relationship to SCITT</name>

<t>The profile defines a third-party-verifiable underdetermination binding for SCITT (<xref target="RFC9943"/>) using an in-toto Statement v1 (<xref target="IN-TOTO-STATEMENT"/>) predicate; the envelope structure is specified in <xref target="statement-and-predicate-structure"/>.</t>

</section>
<section anchor="non-claims"><name>Non-Claims</name>

<t><list style="symbols">
  <t>That “two compatible models ⇒ underdetermination” is novel.</t>
  <t>That the receipt identifies the actual world or establishes either claim value as true.</t>
  <t>That <spanx style="verb">Compatibleπ</spanx>, <spanx style="verb">Evalπ</spanx>, or <spanx style="verb">Eπ</spanx> faithfully represents reality (<xref target="security-considerations"/>).</t>
  <t>That <spanx style="verb">FormallyUnderdeterminationCapable</spanx> means the profile is operationally adequate or unbiased toward abstention (AP1).</t>
  <t>That registration order represents issuance, creation, or first-observation order (<xref target="full-prefix-replay"/>, <xref target="evidence-admission"/>).</t>
  <t>That the issuer did not open a semantically equivalent request under another <spanx style="verb">request_id</spanx> (<xref target="instance-commitment-and-subject"/>).</t>
  <t>That the issuer did not create sibling instances for the same <spanx style="verb">claim_digest</spanx> under different <spanx style="verb">request_id</spanx> values, bind them to different profiles or world classes, or select the presented instance after observing evidence or outcomes (<xref target="security-considerations"/>).</t>
  <t>That no parallel commitment or admission for the same <spanx style="verb">request_id</spanx> exists in another transparency log; the claim is relative only to committed L (<xref target="instance-commitment-and-subject"/> through <xref target="evidence-closure-and-checkpoint-bounded-coverage"/>).</t>
  <t>That no unregistered or evidence-scope-excluded external evidence exists, or that no entry exists after <spanx style="verb">S_R</spanx>; coverage applies only to frozen admitters and the identified subject through <spanx style="verb">S_R</spanx> (<xref target="evidence-closure-and-checkpoint-bounded-coverage"/>).</t>
  <t>That profile failure says anything about claim falsifiability (<xref target="issuance-conditions"/>).</t>
  <t>That P10 is first to use Lean certificates, abstention, or a per-call card (<xref target="KOOMULLIL"/>, <xref target="relationship-to-prior-work"/>).</t>
  <t>That P10 originated independent determinability or the rule against selecting one of several evidence-compatible candidates (<xref target="WADKINS-00"/>, <xref target="relationship-to-prior-work"/>).</t>
  <t>That decision-time or pre-evidence binding is novel as a general idea (<xref target="WADKINS-00"/>, <xref target="CLAIMRECEIPT"/>, <xref target="relationship-to-prior-work"/>).</t>
  <t>That an <spanx style="verb">indeterminate</spanx> receipt or reason-coded indeterminate state is novel (<xref target="KRAUSZ-02"/>, <xref target="relationship-to-prior-work"/>).</t>
  <t>That binding a claim, ruleset, or evidence set into a signed receipt is novel (<xref target="KRAUSZ-02"/>, <xref target="relationship-to-prior-work"/>).</t>
  <t>That content-addressed evidence or local receipt recomputation is novel (<xref target="KRAUSZ-02"/>, <xref target="relationship-to-prior-work"/>).</t>
  <t>That SCITT transport for a verification receipt is novel (<xref target="KRAUSZ-02"/> and existing SCITT profiles, <xref target="relationship-to-prior-work"/>).</t>
  <t>That the general need for evidence-coverage or omission controls is novel (<xref target="WADKINS-00"/>, <xref target="CLAIMRECEIPT"/>, and <xref target="KRAUSZ-02"/>, <xref target="relationship-to-prior-work"/>).</t>
  <t>That any downstream action was governed by the receipt's verdict. P10 establishes only that the certificate verifies under the uniquely committed profile and its transitively bound verifier artifacts.</t>
  <t>Anything about market or commercial priority.</t>
</list></t>

</section>
</section>
<section anchor="conventions-and-terminology"><name>Conventions and Terminology</name>

<t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>

<?line -18?>

<t>The following notation and symbols are defined in the referenced sections:</t>

<t><list style="symbols">
  <t><spanx style="verb">Wπ</spanx>, <spanx style="verb">Compatibleπ</spanx>, and <spanx style="verb">Evalπ</spanx> are defined in <xref target="definitions"/>.</t>
  <t><spanx style="verb">Eπ</spanx> and <spanx style="verb">VerifierManifestV0</spanx> are defined in <xref target="issuance-conditions"/>.</t>
  <t><spanx style="verb">InstanceCommitment</spanx> is defined in <xref target="instance-commitment-and-subject"/>.</t>
  <t><spanx style="verb">L</spanx> is defined in <xref target="full-prefix-replay"/>; <spanx style="verb">S_R</spanx> denotes the verified checkpoint obtained from the SCITT Receipt, as shown in <xref target="statement-and-predicate-structure"/>.</t>
  <t><spanx style="verb">SubjectView</spanx>, <spanx style="verb">RelevantAdmissionπ</spanx>, <spanx style="verb">EvidenceClosure</spanx>, and <spanx style="verb">CoverageProof</spanx> are defined in <xref target="evidence-closure-and-checkpoint-bounded-coverage"/>.</t>
</list></t>

</section>
<section anchor="formal-core"><name>Formal Core</name>

<section anchor="definitions"><name>Definitions</name>

<figure><sourcecode type="text"><![CDATA[
NonemptyCompatibleπ(e) :=
  ∃ w ∈ Wπ, Compatibleπ(e, w)

Determinateπ(e, c) :=
  NonemptyCompatibleπ(e) ∧
  ∀ w₀ w₁ ∈ Wπ,
    Compatibleπ(e, w₀) ∧ Compatibleπ(e, w₁)
    → Evalπ(c, w₀) = Evalπ(c, w₁)

Underdeterminedπ(e, c) :=
  ∃ w₀ w₁ ∈ Wπ,
    Compatibleπ(e, w₀) ∧ Compatibleπ(e, w₁) ∧
    Evalπ(c, w₀) ≠ Evalπ(c, w₁)

ProfileAdmissible(π, c) :=
  ∃ eᵈ ∈ Eπ, Determinateπ(eᵈ, c)

FormallyUnderdeterminationCapable(π, c) :=
  ∃ eᵘ eᵈ ∈ Eπ,
    Underdeterminedπ(eᵘ, c) ∧ Determinateπ(eᵈ, c)
]]></sourcecode></figure>

<t>Notes:</t>

<t><list style="symbols">
  <t><spanx style="verb">Evalπ(c, w₀) ≠ Evalπ(c, w₁)</spanx> entails the semantic distinctness of w₀ and w₁. Canonical serialization (<xref target="canonical-encoding"/>) prevents the same world from appearing twice.</t>
  <t><spanx style="verb">FormallyUnderdeterminationCapable(π, c) → ProfileAdmissible(π, c)</spanx>. Both tests remain in preflight for clearer diagnostics.</t>
  <t><spanx style="verb">FormallyUnderdeterminationCapable</spanx> is a formal property of the frozen profile. It says nothing about operational adequacy (<xref target="security-considerations"/>, AP1).</t>
</list></t>

</section>
<section anchor="issuance-conditions"><name>Issuance Conditions</name>

<t>In the formal core, <spanx style="verb">e</spanx> denotes a canonically closed evidence bundle. An individual admission object is denoted by <spanx style="verb">a</spanx>; the frozen <spanx style="verb">Bundleπ</spanx> function derives <spanx style="verb">e</spanx> from ordered valid admissions, and the closure proof establishes <spanx style="verb">e ∈ Eπ</spanx>.</t>

<figure><sourcecode type="text"><![CDATA[
InstanceCommittedBeforeEvidence(ι, π, c)
ProfileRegisteredBeforeEvidence(π, ι)
  -- via replay transcript
ActiveProfileBindingV0(ι, R)
  -- exact profile/verifier resolution below
CoverageClosedThroughCheckpoint(ι, e, S_R)
FormallyUnderdeterminationCapable(π, c)
  -- preflight
e ∈ Eπ
w₀, w₁ ∈ Wπ  (canonical form)
Compatibleπ(e, w₀)
Compatibleπ(e, w₁)
Evalπ(c, w₀) ≠ Evalπ(c, w₁)
]]></sourcecode></figure>

<t>The prerequisites in this summary are detailed in <xref target="instance-commitment-and-subject"/> for instance commitment, <xref target="full-prefix-replay"/> for profile registration and replay, <xref target="evidence-closure-and-checkpoint-bounded-coverage"/> for coverage closure, and <xref target="canonical-encoding"/> for canonical world encoding.</t>

<t><strong>Frozen and digested before evidence admission:</strong></t>

<t><list style="symbols">
  <t><spanx style="verb">Wπ</spanx>, <spanx style="verb">Compatibleπ</spanx>, <spanx style="verb">Evalπ</spanx>, and claim semantics</t>
  <t><spanx style="verb">Eπ</spanx> (the space of permitted closed evidence bundles), <spanx style="verb">AdmissibleItemπ</spanx>, <spanx style="verb">Bundleπ</spanx>, and admission rules</t>
  <t>evidence scope, coverage rules, and the rule for forming the closed evidence set</t>
  <t><spanx style="verb">LogIdentityV0</spanx>, <spanx style="verb">LeafEncodeV0</spanx>, checkpoint key/VDS algorithm, and lifecycle/admitter authorization</t>
  <t>evidence canonicalization and the canonical world codec (<xref target="canonical-encoding"/>)</t>
  <t><spanx style="verb">eᵈ</spanx> and <spanx style="verb">eᵘ</spanx>, with membership proofs for <spanx style="verb">Eπ</spanx> and proofs of <spanx style="verb">Determinateπ(eᵈ, c)</spanx> and <spanx style="verb">Underdeterminedπ(eᵘ, c)</spanx></t>
  <t><spanx style="verb">VerifierManifestV0</spanx> and its digest, including the exact checker and Lean toolchain artifacts defined below</t>
</list></t>

<figure><sourcecode type="text"><![CDATA[
VerifierManifestV0 binds:
  lean_toolchain_identifier
  lean_toolchain_artifact_digest
  checker_source_tree_digest
  dependency_lock_digest
  build_manifest_digest
  checker_olean_digest_set
  axiom_policy_digest
  acceptance_command_digest

profile.verifier_manifest_ref resolves VerifierManifestV0
profile.verifier_manifest_digest :=
  digest(canonical VerifierManifestV0)

profile_digest binds profile.verifier_manifest_ref and
  profile.verifier_manifest_digest

CertificateTargetV0(π, e, c, w₀, w₁) :=
  e ∈ Eπ                                      ∧
  w₀ ∈ Wπ                                     ∧
  w₁ ∈ Wπ                                     ∧
  Compatibleπ(e, w₀)                          ∧
  Compatibleπ(e, w₁)                          ∧
  Evalπ(c, w₀) ≠ Evalπ(c, w₁)

ActiveProfileBindingV0(ι, R) holds only if:
  FullPrefixReplay finds exactly one valid InstanceCommitment for the
    committed instance tuple                                      ∧
  digest(
    resolve(R.profile_commitment_ref)
      .canonical_profile_bytes)
    = InstanceCommitment.profile_digest                           ∧
  digest(
    resolve(profile.verifier_manifest_ref)
      .canonical_manifest_bytes)
    = profile.verifier_manifest_digest                            ∧
  R.verifier_digest = profile.verifier_manifest_digest            ∧
  R.claim_digest = InstanceCommitment.claim_digest                ∧
  every checker source, dependency lock, build manifest, `.olean`
    artifact, axiom policy, acceptance command, and Lean toolchain
    artifact used during verification matches VerifierManifestV0 ∧
  Wπ, Eπ, Compatibleπ, Evalπ, the codecs, and the checker are
    obtained exclusively from that resolved profile               ∧
  certificate.type = CertificateTargetV0(π, e, c, w₀, w₁)         ∧
  the submitted certificate type-checks under exactly those
    resolved profile, verifier, and toolchain artifacts.
]]></sourcecode></figure>

<t>The resolved checker <bcp14>MUST</bcp14> construct <spanx style="verb">CertificateTargetV0</spanx> exclusively from the committed profile, closed evidence set, committed claim, and canonical receipt witnesses. The certificate <bcp14>MUST NOT</bcp14> supply or select its own target proposition.</t>

<t>Every artifact digest above binds both the exact bytes and its frozen artifact identifier or path and format. An unavailable required profile, manifest, checker, build, dependency, <spanx style="verb">.olean</spanx>, axiom-policy, acceptance-command, or toolchain artifact yields <spanx style="verb">HALT</spanx>, with no epistemic verdict. A digest mismatch, substitution, or certificate checked under any other profile, checker, build, axiom policy, or toolchain yields <spanx style="verb">REJECT</spanx>.</t>

<t><strong>Preflight rule:</strong></t>

<figure><sourcecode type="text"><![CDATA[
¬ProfileAdmissible(π, c) →
  preflight HALT, no verdict
¬FormallyUnderdeterminationCapable(π, c) →
  profile MUST NOT issue an underdetermination receipt
]]></sourcecode></figure>

<t>For infinite <spanx style="verb">Wπ</spanx>, <spanx style="verb">Underdeterminedπ</spanx> is still checked with a concrete witness pair and decidable <spanx style="verb">Compatibleπ</spanx> and <spanx style="verb">Evalπ</spanx>. <spanx style="verb">Determinateπ(eᵈ, c)</spanx> is a universal claim: the verifier accepts a Lean proof term, but generation of such a proof is not guaranteed. If no proof term is available, preflight <bcp14>MUST</bcp14> return <spanx style="verb">HALT</spanx>, not an epistemic verdict.</t>

<t><spanx style="verb">UnfalsifiableAsStated</spanx> is not derived from profile failure. It requires a separate semantic obligation over the claim wording, relativized to the declared world class and evidence language. That obligation is outside this profile.</t>

</section>
</section>
<section anchor="instance-commitment-and-subject"><name>Instance Commitment and Subject</name>

<t>The identified adjudication instance is a subject derived from the issuer/request pair, not a freely chosen <spanx style="verb">instance_id</spanx>:</t>

<figure><sourcecode type="text"><![CDATA[
instance_subject := SubjectDeriveV0(issuer_id, request_id)
]]></sourcecode></figure>

<t><spanx style="verb">SubjectDeriveV0</spanx> uses frozen, domain-separated canonical encoding and returns a text string (<spanx style="verb">tstr</spanx>) for CWT <spanx style="verb">sub</spanx> (<xref target="RFC8392"/>). Its digest is bound by the commitment. Before the first evidence admission, the following <bcp14>MUST</bcp14> be registered:</t>

<figure><sourcecode type="text"><![CDATA[
InstanceCommitment(ι) binds:
  request_id
  issuer_id
  instance_subject
  instance_owner_iss
  log_identity_digest
  leaf_encoding_profile_digest
  claim_digest
  profile_digest
  evidence_scope_digest
  admission_rule_digest
  coverage_rule_digest
  authorized_admitter_set_digest
  subject_derivation_digest
]]></sourcecode></figure>

<t><list style="symbols">
  <t><spanx style="verb">instance_owner_iss = issuer_id</spanx> in the same frozen canonical representation, and the commitment <bcp14>MUST</bcp14> carry a valid owner signature with that protected <spanx style="verb">iss</spanx>.</t>
  <t>Uniqueness is checked <strong>within committed L</strong> by <spanx style="verb">(instance_owner_iss, request_id, instance_subject)</spanx>, where <spanx style="verb">instance_subject</spanx> <bcp14>MUST</bcp14> be the result of <spanx style="verb">SubjectDeriveV0(issuer_id, request_id)</spanx>.</t>
  <t>Full replay <bcp14>MUST</bcp14> find exactly one valid <spanx style="verb">InstanceCommitment</spanx> for that tuple, containing exactly one <spanx style="verb">profile_digest</spanx> and <spanx style="verb">claim_digest</spanx>. Zero commitments yields <spanx style="verb">HALT</spanx>; two or more, or conflicting digests, yield <spanx style="verb">REJECT</spanx>.</t>
  <t><spanx style="verb">authorized_admitter_set_digest</spanx> binds the exact frozen set of permitted CWT <spanx style="verb">iss</spanx> values.</t>
  <t>All lifecycle statements — profile, commitment, admission, closure, and final P10 adjudication Signed Statement — carry the same <strong>protected CWT <spanx style="verb">sub</spanx></strong> (<xref target="RFC9597"/>), equal to <spanx style="verb">instance_subject</spanx>.</t>
  <t>The profile-selection commitment, <spanx style="verb">InstanceCommitment</spanx>, <spanx style="verb">EvidenceClosure</spanx>, and final P10 Signed Statement are valid only with an <spanx style="verb">instance_owner_iss</spanx> signature. Evidence admissions use the separate frozen admitter set. A matching-<spanx style="verb">sub</spanx> lifecycle entry from another <spanx style="verb">iss</spanx> is not valid and is excluded from counts.</t>
  <t>A semantically equivalent natural-language request opened under another <spanx style="verb">request_id</spanx> remains outside the proven completeness scope.</t>
</list></t>

</section>
<section anchor="full-prefix-replay"><name>Full-Prefix Replay and Registration Order</name>

<t><strong>Registration order</strong> and checkpoint-bounded coverage are proven by replaying the append-only log, not by timestamps or selected inclusion proofs alone.</t>

<figure><sourcecode type="text"><![CDATA[
LogIdentityV0(L) := CanonicalDigest(
  ts_iss,
  checkpoint_verification_key_fingerprint,
  vds_algorithm,
  leaf_encoding_profile_digest)

LeafEncodeV0(x) :=
  frozen mapping from the exact registered Signed Statement
  bytes and their format/media-type identifier to
  RFC9162 leaf input
]]></sourcecode></figure>

<t>“The same L” means the same <spanx style="verb">LogIdentityV0</spanx>: the same TS <spanx style="verb">iss</spanx>, checkpoint verification key, VDS algorithm, and leaf-encoding profile. The commitment's <spanx style="verb">log_identity_digest</spanx> <bcp14>MUST</bcp14> match the L identified by the outer receipt; a mismatch yields <spanx style="verb">REJECT</spanx>.</t>

<figure><sourcecode type="text"><![CDATA[
FullPrefixReplay(L, S_R) :=
  fetch every leaf's exact registered bytes and protected header
    at indices [0, size(S_R))                                ∧
  decode protected sub for SubjectView candidates            ∧
  fetch payload bytes for every SubjectView candidate needed
    to classify lifecycle/admission validity                  ∧
  reconstruct the RFC9162_SHA256 VDS root using LeafEncodeV0 ∧
  reconstructed_root = root(S_R)                            ∧
  verify signed_checkpoint(S_R)
]]></sourcecode></figure>

<t>The verifier <bcp14>MUST</bcp14> have authorized read access to the leaf bytes and protected headers of the entire Statement Sequence through <spanx style="verb">S_R</spanx>, as well as all payload bytes of subject-view candidates needed for classification under the frozen rules. Payloads for unrelated subjects are not required. Trust in the commitment-bound checkpoint key, VDS algorithm, and <spanx style="verb">LeafEncodeV0</spanx> is an explicit premise. If the complete prefix or a required subject payload is unavailable, the result is <spanx style="verb">HALT</spanx>, with no epistemic verdict.</t>

<t>Replay verifies that the profile and unique commitment were registered before the first relevant admission, that exactly one valid owner-signed closure precedes the final receipt, and that all those entries are in committed L. An entry or proof from another log identity yields <spanx style="verb">REJECT</spanx>; a separate parallel log is outside the claim and <bcp14>MUST</bcp14> be disclosed by the limitation. P10 v0 uses <spanx style="verb">RFC9162_SHA256</spanx> (VDS alg <spanx style="verb">1</spanx>, <xref target="RFC9942"/>; tree structure, <xref target="RFC9162"/>). Inclusion and consistency proofs may accompany the transcript, but do not by themselves prove the absence of other entries.</t>

<t>An RFC 9943 Registration Policy can change, and its rejection of new entries is only defense in depth; it is not a soundness premise of P10 coverage.</t>

</section>
<section anchor="evidence-admission"><name>Evidence Admission</name>

<figure><sourcecode type="text"><![CDATA[
AuthorizedAdmitters(ι) := exact CWT iss set committed by
  authorized_admitter_set_digest

AuthorizedLifecycleIssuer(ι) := instance_owner_iss = issuer_id

EvidenceAdmission(a) :=
  registration in L of an authenticated statement binding the
  canonical form of a and proof AdmissibleItemπ(a) under the
  frozen admission rules:
  a SCITT Signed Statement whose payload is an in-toto Statement v1
  containing the P10 evidence-admission predicate, with
    protected sub = instance_subject                         ∧
    protected iss ∈ AuthorizedAdmitters(ι)                  ∧
    a valid signature for that iss                          ∧
    accessible payload bytes satisfying the frozen rules.
]]></sourcecode></figure>

<t>A matching <spanx style="verb">sub</spanx> from an unauthorized <spanx style="verb">iss</spanx> is not an admission. If the closure nevertheless cites it, the result is <spanx style="verb">REJECT</spanx>.</t>

<t>For a non-admission lifecycle predicate, a matching-<spanx style="verb">sub</spanx> entry is valid only if it has a valid <spanx style="verb">AuthorizedLifecycleIssuer(ι)</spanx> signature and the expected predicate type. An unauthorized lifecycle entry is excluded from uniqueness counts; if a valid object cites it as a commitment, profile, or closure, the result is <spanx style="verb">REJECT</spanx>.</t>

<t><strong>Definition-level limitation:</strong> admission is a protocol registration event. Registration order proves that the profile was locked before protocol registration of the evidence; it does not prove when the evidence was created or issued, or that the profile author had not previously seen public data.</t>

</section>
<section anchor="evidence-closure-and-checkpoint-bounded-coverage"><name>Evidence Closure and Checkpoint-Bounded Coverage</name>

<figure><sourcecode type="text"><![CDATA[
SubjectView(L, S_R, instance_subject) :=
  every replayed statement at leaf_index < size(S_R)
  whose protected CWT sub = instance_subject

ClosureTranscriptViewπ(L, S_R, ι) :=
  the subsequence of SubjectView containing only:
    valid owner-signed lifecycle entries for ι, or
    RelevantAdmissionπ entries for ι

RelevantAdmissionπ(x, ι) :=
  x ∈ SubjectView(L, S_R, instance_subject)                 ∧
  x is a valid EvidenceAdmission predicate                  ∧
  x.protected_iss ∈ AuthorizedAdmitters(ι)                  ∧
  signature_valid(x)                                       ∧
  payload_accessible(x)                                    ∧
  AdmissibleItemπ(x.payload)

EvidenceClosure(ι) binds:
  instance_subject
  terminal = true
  ordered_admission_refs
  closed_evidence_set_digest
  checkpoint_preclosure_transcript_digest

CoverageProofπ(ι, S_R) verifies:
  FullPrefixReplay(L, S_R)                                  ∧
  exactly one valid InstanceCommitment for the instance tuple ∧
  exactly one valid owner-signed EvidenceClosure
    for instance_subject                                    ∧
  ordered_admission_refs are in strictly ascending leaf order ∧
  ordered_admission_refs contain no duplicates              ∧
  each ref identifies a RelevantAdmissionπ                  ∧
  every RelevantAdmissionπ before the closure appears exactly once ∧
  no RelevantAdmissionπ occurs after closure and before size(S_R) ∧
  e = Bundleπ(ordered_admission_refs) ∈ Eπ                  ∧
  receipt.evidence_digest = digest(e)
]]></sourcecode></figure>

<t><list style="symbols">
  <t>No closure, replay, or required payload bytes → <spanx style="verb">HALT</spanx>, with no epistemic verdict. A conflicting commitment/closure, or an omitted, duplicated, misordered, unauthorized, or post-closure relevant admission → <spanx style="verb">REJECT</spanx>.</t>
  <t><spanx style="verb">checkpoint_preclosure_transcript_digest</spanx> <bcp14>MUST</bcp14> describe the uninterrupted <spanx style="verb">ClosureTranscriptViewπ</spanx> subsequence immediately before the closure leaf. Entries for other subjects and unauthorized matching-<spanx style="verb">sub</spanx> entries do not invalidate closure. If a valid owner-signed lifecycle entry or <spanx style="verb">RelevantAdmissionπ</spanx> lands between transcript preparation and closure registration, that closure candidate is invalid (fail-closed). The issuer <bcp14>MUST</bcp14> replay the subject view, rebuild the references, and register a new closure; the invalid attempt is not counted as a valid closure.</t>
  <t>The leaf index assigned by committed L is the authoritative total registration order, including entries received in the same batch. <spanx style="verb">Bundleπ</spanx> uses that strictly increasing order; the TS cannot present a different order for the same checkpoint without violating VDS integrity.</t>
  <t>The receipt is computed over closed <spanx style="verb">e</spanx>, not an arbitrarily selected admission. The claim holds only through signed checkpoint <spanx style="verb">S_R</spanx>; a later entry does not retroactively change the historical claim and supports no claim of future absence.</t>
  <t>To avoid a post-registration hash cycle, the issuer-signed P10 payload binds <spanx style="verb">evidence_closure_ref</spanx>, <spanx style="verb">evidence_admission_refs</spanx>, and <spanx style="verb">preclosure_transcript_digest</spanx>. The outer SCITT Receipt (<xref target="RFC9942"/>) supplies <spanx style="verb">S_R</spanx>; <spanx style="verb">S_R</spanx>, the final replay transcript, and the coverage-verification result are not fields in the issuer-signed payload. Full-prefix replay occurs after receipt acquisition.</t>
</list></t>

</section>
<section anchor="canonical-encoding"><name>Canonical Encoding</name>

<t><list style="symbols">
  <t>P10 v0 uses UTF-8 JSON Canonicalization Scheme (JCS, <xref target="RFC8785"/>) for claims, structured evidence objects, worlds, and the P10 predicate. The codec digest is part of the profile (<xref target="introduction"/>, item (1)) and receipt.</t>
  <t>Integers outside the safely interoperable JCS/JSON range, rational numbers, and exact decimal values are encoded as canonical strings under the frozen exact-number schema; they are not emitted as JSON numbers.</t>
  <t>A <strong>unique normal form</strong> applies: <spanx style="verb">decode ∘ encode = id</spanx> on <spanx style="verb">Wπ</spanx>, with exactly one JCS form per decoded world. <spanx style="verb">Compatibleπ</spanx> and <spanx style="verb">Evalπ</spanx> operate on decoded semantic objects; the verifier rejects noncanonical witnesses.</t>
  <t>A structured P10 <spanx style="verb">*_digest</spanx> uses SHA-256 over the corresponding JCS bytes. Binary artifacts are digested over raw bytes together with the frozen format/media-type identifier, not over a JCS reinterpretation. Noncryptographic or merely immutable identifiers are insufficient.</t>
</list></t>

</section>
<section anchor="statement-and-predicate-structure"><name>Statement and Predicate Structure</name>

<t><strong>Inside the issuer-signed P10 payload:</strong></t>

<figure><sourcecode type="text"><![CDATA[
instance_commitment_ref       -- before the first admission
profile_commitment_ref
  -- profile registration in L + checkpoint S₁
evidence_admission_refs
  -- all instance admissions covered by the closure
evidence_closure_ref
preclosure_transcript_digest  -- independent of S_R
instance_subject              -- protected CWT sub
log_identity_digest           -- committed L
claim_digest
evidence_digest               -- over the JCS form of the closed set
codec_digest
witness_0_digest, witness_1_digest   -- canonical form
capability_proof_digest       -- eᵈ, eᵘ, and proofs
proof_digest                  -- Lean object + axiom audit
verifier_digest
  -- equals profile.verifier_manifest_digest
limitations_digest
  -- includes verbatim AP1 and coverage/instance text
limitations                   -- mandatory must-understand P10 field
outcome = NotDemonstrated(reason=underdetermined)
]]></sourcecode></figure>

<t>In the issuer-signed field list above, <spanx style="verb">instance_commitment_ref</spanx> is specified in <xref target="instance-commitment-and-subject"/>; <spanx style="verb">evidence_closure_ref</spanx> and <spanx style="verb">preclosure_transcript_digest</spanx> in <xref target="evidence-closure-and-checkpoint-bounded-coverage"/>; <spanx style="verb">log_identity_digest</spanx> in <xref target="full-prefix-replay"/>; <spanx style="verb">codec_digest</spanx> in <xref target="canonical-encoding"/>; and the proofs bound by <spanx style="verb">capability_proof_digest</spanx> in <xref target="issuance-conditions"/>.</t>

<t><strong>Outside the issuer-signed payload, obtained only after registration:</strong></t>

<figure><sourcecode type="text"><![CDATA[
receipt_checkpoint_ref
  -- SCITT Receipt in COSE unprotected label 394
S_R
  -- verified checkpoint from the receipt
order_and_coverage_transcript_digest
  -- FullPrefixReplay through S_R
coverage_verification_result
  -- ACCEPT / REJECT / HALT + diagnostics
]]></sourcecode></figure>

<t>These post-registration values are P10 verifier output over the Transparent Statement. They may be serialized in a separate verification report, but are not part of the issuer-signed P10 predicate and do not enter its digest. The standard SCITT Receipt (<xref target="RFC9942"/>) remains in COSE unprotected-header label <spanx style="verb">394</spanx>, avoiding a hash cycle.</t>

<t>Before accepting the epistemic outcome, the verifier <bcp14>MUST</bcp14> establish <spanx style="verb">ActiveProfileBindingV0</spanx>. Registration order proves when the committed object entered <spanx style="verb">L</spanx>; it is not by itself evidence that the object was used. P10 establishes verifier-time use by independently resolving the unique instance-bound profile and its <spanx style="verb">VerifierManifestV0</spanx>, matching every required artifact, constructing <spanx style="verb">CertificateTargetV0</spanx> from the committed inputs, and type-checking the submitted certificate against that target under exactly that resolved combination.</t>

<t><strong>The only v0 envelope:</strong> a SCITT Signed Statement (<xref target="RFC9943"/>) (<spanx style="verb">COSE_Sign1</spanx>, <xref target="RFC9052"/>) whose payload is an in-toto Statement v1 (<xref target="IN-TOTO-STATEMENT"/>) with the P10 predicate. After registration and attachment of a SCITT Receipt (<xref target="RFC9942"/>), it becomes a Transparent Statement. Profile commitment, instance commitment, evidence admissions, evidence closure, and final P10 adjudication statement use the same pattern, the same L, and the same protected CWT <spanx style="verb">sub</spanx>. A bare in-toto predicate, standalone signed in-toto envelope, or SCITT Statement without the required Receipt is insufficient. No new wire format is introduced.</t>

</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<t>Lean (<xref target="LEAN4"/>) checks only the result of executing frozen, executable relations and functions over canonical objects. It checks nothing about the real world.</t>

<t>Each item in the following list is one row of the semantic-bridges table.</t>

<t><list style="symbols">
  <t><strong>Bridge:</strong> <spanx style="verb">Compatibleπ</spanx>
  <list style="symbols">
      <t><strong>What Lean checks:</strong> The frozen relation returns <spanx style="verb">true</spanx> for (e, w₀) and (e, w₁)</t>
      <t><strong>What remains an oracle / limitation:</strong> Whether the relation faithfully represents real-world compatibility</t>
    </list></t>
  <t><strong>Bridge:</strong> <spanx style="verb">Evalπ</spanx>
  <list style="symbols">
      <t><strong>What Lean checks:</strong> The frozen function returns different values on w₀ and w₁</t>
      <t><strong>What remains an oracle / limitation:</strong> Whether <spanx style="verb">Evalπ</spanx> faithfully translates the natural-language claim; this is P10 <spanx style="verb">R_sem</spanx> unless the claim is already formal</t>
    </list></t>
  <t><strong>Bridge:</strong> <spanx style="verb">Eπ</spanx> and admission
  <list style="symbols">
      <t><strong>What Lean checks:</strong> <spanx style="verb">e ∈ Eπ</spanx> under the frozen rules</t>
      <t><strong>What remains an oracle / limitation:</strong> Whether <spanx style="verb">Eπ</spanx> realistically covers obtainable evidence</t>
    </list></t>
  <t><strong>Bridge:</strong> Profile adequacy (AP1)
  <list style="symbols">
      <t><strong>What Lean checks:</strong> <spanx style="verb">FormallyUnderdeterminationCapable(π, c)</spanx></t>
      <t><strong>What remains an oracle / limitation:</strong> Whether the determining evidence fixture is practically obtainable and representative (limitation below)</t>
    </list></t>
  <t><strong>Bridge:</strong> Canonicalization / codec
  <list style="symbols">
      <t><strong>What Lean checks:</strong> SHA-256 digest and JCS canonical form match</t>
      <t><strong>What remains an oracle / limitation:</strong> Whether canonicalization loses claim-relevant information</t>
    </list></t>
  <t><strong>Bridge:</strong> Replay/order
  <list style="symbols">
      <t><strong>What Lean checks:</strong> The complete VDS prefix of committed L reconstructs <spanx style="verb">S_R</spanx> and registration order (<xref target="full-prefix-replay"/>)</t>
      <t><strong>What remains an oracle / limitation:</strong> Authorized access to all leaf/protected-header data and required subject payloads; registration order is not issuance order; other logs are outside the claim</t>
    </list></t>
  <t><strong>Bridge:</strong> Within-batch order
  <list style="symbols">
      <t><strong>What Lean checks:</strong> Committed leaf indices define one total registration order</t>
      <t><strong>What remains an oracle / limitation:</strong> The TS chooses within-batch leaf order; an order-sensitive <spanx style="verb">Bundleπ</spanx> therefore treats that TS choice as an explicit trust assumption</t>
    </list></t>
  <t><strong>Bridge:</strong> Pre-evidence commitment
  <list style="symbols">
      <t><strong>What Lean checks:</strong> Profile and instance were registered before protocol admission (<xref target="instance-commitment-and-subject"/> through <xref target="evidence-admission"/>)</t>
      <t><strong>What remains an oracle / limitation:</strong> Does not prove author ignorance of public data or absence of other instances</t>
    </list></t>
  <t><strong>Bridge:</strong> Active profile/verifier
  <list style="symbols">
      <t><strong>What Lean checks:</strong> <spanx style="verb">ActiveProfileBindingV0</spanx> resolves the unique instance-bound profile and verifies the certificate using only the checker, build, axiom policy, codecs, dependencies, <spanx style="verb">.olean</spanx> files, and Lean toolchain transitively bound by that profile</t>
      <t><strong>What remains an oracle / limitation:</strong> Establishes verifier-time recomputation under the committed adjudication profile; it does not establish that a downstream action was governed by the verdict</t>
    </list></t>
  <t><strong>Bridge:</strong> Coverage
  <list style="symbols">
      <t><strong>What Lean checks:</strong> <spanx style="verb">EvidenceClosure</spanx> and <spanx style="verb">CoverageProof</spanx> close all valid, registered, in-scope admissions by authorized admitters through <spanx style="verb">S_R</spanx> (<xref target="evidence-closure-and-checkpoint-bounded-coverage"/>)</t>
      <t><strong>What remains an oracle / limitation:</strong> Does not prove absence of unregistered/out-of-scope evidence, another <spanx style="verb">request_id</spanx>, or future entries</t>
    </list></t>
  <t><strong>Bridge:</strong> Cryptography
  <list style="symbols">
      <t><strong>What Lean checks:</strong> Digests and signatures match</t>
      <t><strong>What remains an oracle / limitation:</strong> Digest collision resistance, signature unforgeability, and log non-equivocation/integrity</t>
    </list></t>
  <t><strong>Bridge:</strong> Verifier
  <list style="symbols">
      <t><strong>What Lean checks:</strong> Kernel type-check plus <spanx style="verb">#print axioms</spanx> audit; the permitted axiom set is explicit in the profile</t>
      <t><strong>What remains an oracle / limitation:</strong> Trust in the Lean kernel and declared axioms; <spanx style="verb">sorryAx</spanx>, <spanx style="verb">Lean.ofReduceBool</spanx>, and <spanx style="verb">native_decide</spanx> are forbidden</t>
    </list></t>
</list></t>

<t><strong>AP1 limitation (verbatim, mandatory in the receipt):</strong></t>

<ul empty="true"><li>
  <t><spanx style="verb">FormallyUnderdeterminationCapable</spanx> does not establish that the determining evidence fixture is practically obtainable, representative, or likely to occur under the deployed acquisition process. A formally valid profile may remain operationally abstention-biased.</t>
</li></ul>

<t><strong>Coverage/instance limitation (verbatim, mandatory in the receipt):</strong></t>

<ul empty="true"><li>
  <t>This receipt establishes completeness only within the committed transparency log <spanx style="verb">L</spanx>, for valid, registered, in-scope admissions made by the frozen authorized admitters for the identified <spanx style="verb">(issuer, request)</spanx> subject through the signed checkpoint <spanx style="verb">S_R</spanx>. It does not establish that no commitment or admission for the same <spanx style="verb">request_id</spanx> exists in another transparency log, that no unregistered or out-of-scope evidence exists, that no semantically equivalent request was opened under a different <spanx style="verb">request_id</spanx>, or that no later statement was registered after <spanx style="verb">S_R</spanx>. Verification requires complete VDS-prefix replay of committed <spanx style="verb">L</spanx> and access to all subject payload bytes needed by the frozen admission rules. This receipt establishes uniqueness only for the identified instance tuple within committed <spanx style="verb">L</spanx> through <spanx style="verb">S_R</spanx>. It does not establish that the issuer did not create other instances for the same <spanx style="verb">claim_digest</spanx> under different <spanx style="verb">request_id</spanx> values, bind those instances to different profiles or world classes, or select the presented instance after observing evidence or outcomes.</t>
</li></ul>

<t>Where sibling <spanx style="verb">InstanceCommitment</spanx> payloads are accessible, a verifier <bcp14>SHOULD</bcp14> report the number visible through <spanx style="verb">S_R</spanx> for the same <spanx style="verb">(instance_owner_iss, claim_digest)</spanx>. Version 0.1.1 assigns no acceptance or rejection semantics to that count. This recommendation does not expand the payload-availability requirement of <spanx style="verb">FullPrefixReplay</spanx>; mandatory sibling counting requires a future profile with an additional availability or indexing rule.</t>

<t>Introducing a <spanx style="verb">Reachableπ(e)</spanx> predicate does not solve AP1. Lean would check frozen <spanx style="verb">Reachableπ(eᵈ)</spanx>, but not whether that relation faithfully represents physical or practical availability. It would merely move the oracle boundary.</t>

<t>Every row of this table is included in the receipt's <spanx style="verb">limitations</spanx> field. The P10 predicate specification marks <spanx style="verb">limitations</spanx> as a mandatory <strong>must-understand</strong> field: a P10 verifier <bcp14>MUST</bcp14> reject a predicate without it, even though generic in-toto v1 rules (<xref target="IN-TOTO-V1"/>) otherwise require unknown fields to be ignored.</t>

</section>
<section anchor="privacy-considerations"><name>Privacy Considerations</name>

<t>A P10 receipt contains or references claim, profile, evidence-admission, evidence-closure, witness, certificate, and verifier identifiers or digests. Cryptographic digests provide integrity binding but do not provide confidentiality, particularly for low-entropy or guessable inputs. Registration with a transparency service can create persistent and linkable metadata across receipts or instances. This profile does not define confidentiality, anonymization, unlinkability, access control, or retention policy.</t>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>
<t>This document has no IANA actions.</t>

</section>


  </middle>

  <back>


<references title='References' anchor="sec-combined-references">

    <references title='Normative References' anchor="sec-normative-references">

&RFC9943;
&RFC9942;
&RFC9052;
&RFC8392;
&RFC9597;
&RFC8785;
&RFC9162;
<reference anchor="IN-TOTO-STATEMENT" target="https://raw.githubusercontent.com/in-toto/attestation/06eafe3635bf8a425ad52cc82c6c90861e94a471/spec/v1/statement.md">
  <front>
    <title>in-toto Attestation Framework: Statement layer specification, v1</title>
    <author >
      <organization>in-toto Project</organization>
    </author>
    <date year="2024" month="May" day="06"/>
  </front>
  <seriesInfo name="Commit" value="06eafe3635bf8a425ad52cc82c6c90861e94a471"/>
</reference>
<reference anchor="IN-TOTO-V1" target="https://raw.githubusercontent.com/in-toto/attestation/06eafe3635bf8a425ad52cc82c6c90861e94a471/spec/v1/README.md">
  <front>
    <title>Specification for in-toto attestation layers, Version v1.1</title>
    <author >
      <organization>in-toto Project</organization>
    </author>
    <date year="2024" month="May" day="06"/>
  </front>
  <seriesInfo name="Commit" value="06eafe3635bf8a425ad52cc82c6c90861e94a471"/>
</reference>
&RFC2119;
&RFC8174;


    </references>

    <references title='Informative References' anchor="sec-informative-references">

<reference anchor="P10-V011" target="https://doi.org/10.5281/zenodo.22994744">
  <front>
    <title>P10 Underdetermination Profile, version 0.1.1</title>
    <author initials="I." surname="Nestorov" fullname="Ivan Nestorov">
      <organization></organization>
    </author>
    <date year="2026" month="September" day="27"/>
  </front>
  <seriesInfo name="DOI" value="10.5281/zenodo.22994744"/>
</reference>
<reference anchor="WADKINS-00" target="https://www.ietf.org/archive/id/draft-wadkins-agentproto-action-determinability-00.txt">
  <front>
    <title>Independent Determinability of Agent Actions</title>
    <author initials="D." surname="Wadkins" fullname="Douglas Wadkins">
      <organization>Strakewright</organization>
    </author>
    <date year="2026" month="September" day="10"/>
  </front>
  <seriesInfo name="Internet-Draft" value="draft-wadkins-agentproto-action-determinability-00"/>
</reference>
<reference anchor="KRAUSZ-02" target="https://www.ietf.org/archive/id/draft-krausz-verification-state-02.txt">
  <front>
    <title>The verification.* Constraint Family: Pre-Action Fail-Closed Gates for AI Agent Decisions</title>
    <author initials="J." surname="Krausz" fullname="Joe Krausz">
      <organization>TK Collective LLC</organization>
    </author>
    <date year="2026" month="September" day="22"/>
  </front>
  <seriesInfo name="Internet-Draft" value="draft-krausz-verification-state-02"/>
</reference>
<reference anchor="MIH-AAC-02" target="https://www.ietf.org/archive/id/draft-mih-scitt-agent-action-capsule-02.txt">
  <front>
    <title>An Agent Action Capsule Profile for SCITT</title>
    <author initials="S." surname="Mih" fullname="Steven Mih">
      <organization>Action State Group, Inc.</organization>
    </author>
    <date year="2026" month="July" day="06"/>
  </front>
  <seriesInfo name="Internet-Draft" value="draft-mih-scitt-agent-action-capsule-02"/>
</reference>
<reference anchor="PRAMANA" target="https://arxiv.org/abs/2605.20312v1">
  <front>
    <title>Pramana: A Protocol-Layer Treatment of Claim Verification in Autonomous Agent Networks</title>
    <author initials="R. K." surname="Kadaboina" fullname="Ravi Kiran Kadaboina">
      <organization></organization>
    </author>
    <date year="2026" month="May" day="19"/>
  </front>
  <seriesInfo name="arXiv" value="2605.20312"/>
</reference>
<reference anchor="CLAIMRECEIPT" target="https://arxiv.org/abs/2609.01992v1">
  <front>
    <title>ClaimReceipt: Verifying Evidence Sufficiency and Coverage in Agent Evaluations</title>
    <author initials="P." surname="Zhu" fullname="Peiying Zhu">
      <organization></organization>
    </author>
    <author initials="S." surname="Chang" fullname="Sidi Chang">
      <organization></organization>
    </author>
    <date year="2026" month="September" day="02"/>
  </front>
  <seriesInfo name="arXiv" value="2609.01992"/>
</reference>
<reference anchor="KOOMULLIL" target="https://arxiv.org/abs/2605.16407v1">
  <front>
    <title>Proof-Carrying Certificates for LLM Pipelines: A Trust-Boundary Architecture</title>
    <author initials="G." surname="Koomullil" fullname="George Koomullil">
      <organization></organization>
    </author>
    <date year="2026" month="May" day="13"/>
  </front>
  <seriesInfo name="arXiv" value="2605.16407"/>
</reference>
<reference anchor="LEAN4" target="https://doi.org/10.1007/978-3-030-79876-5_37">
  <front>
    <title>The Lean 4 Theorem Prover and Programming Language</title>
    <author initials="L." surname="de Moura" fullname="Leonardo de Moura">
      <organization></organization>
    </author>
    <author initials="S." surname="Ullrich" fullname="Sebastian Ullrich">
      <organization></organization>
    </author>
    <date year="2021"/>
  </front>
  <seriesInfo name="Lecture Notes in Computer Science" value="12699, pp. 625–635"/>
  <seriesInfo name="DOI" value="10.1007/978-3-030-79876-5_37"/>
</reference>


    </references>

</references>


<?line 604?>

<section numbered="true" anchor="conformance-tests"><name>Conformance Tests</name>

<section anchor="mutation-tests-must-yield-reject-or-the-stated-outcome"><name>Mutation Tests (MUST yield REJECT or the stated outcome)</name>

<t><list style="symbols">
  <t><strong>#:</strong> M1  <vspace blankLines='1'/>
<strong>Mutation:</strong> Change <spanx style="verb">W</spanx>, <spanx style="verb">Compatible</spanx>, <spanx style="verb">Eval</spanx>, <spanx style="verb">Eπ</spanx>, <spanx style="verb">AdmissibleItemπ</spanx>, <spanx style="verb">Bundleπ</spanx>, evidence scope, admission/coverage rules, codec, or canonicalization after instance commitment  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M2  <vspace blankLines='1'/>
<strong>Mutation:</strong> <spanx style="verb">Compatible := fun _ _ =&gt; true</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> Fails <spanx style="verb">FormallyUnderdeterminationCapable</spanx>: constant <spanx style="verb">Evalπ</spanx> gives no <spanx style="verb">eᵘ</spanx>; nonconstant <spanx style="verb">Evalπ</spanx> gives no <spanx style="verb">eᵈ</spanx>. Empty <spanx style="verb">Wπ</spanx> makes <spanx style="verb">Determinateπ</spanx> false via <spanx style="verb">NonemptyCompatibleπ</spanx>. No case yields an underdetermination receipt.</t>
  <t><strong>#:</strong> M3  <vspace blankLines='1'/>
<strong>Mutation:</strong> Witness outside frozen <spanx style="verb">Wπ</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M4  <vspace blankLines='1'/>
<strong>Mutation:</strong> Two witnesses with the same claim value  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M5  <vspace blankLines='1'/>
<strong>Mutation:</strong> Receipt without an earlier profile-registration entry  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M6  <vspace blankLines='1'/>
<strong>Mutation:</strong> Change <spanx style="verb">limitations</spanx> or witness bytes without changing the digest  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M7  <vspace blankLines='1'/>
<strong>Mutation:</strong> Profile/instance and admission are in different logs, or replay shows admission before commitment  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M8  <vspace blankLines='1'/>
<strong>Mutation:</strong> Same world in two serializations; noncanonical witness  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M9  <vspace blankLines='1'/>
<strong>Mutation:</strong> Profile without a determinability witness  <vspace blankLines='1'/>
<strong>Expected:</strong> Preflight HALT, no adjudication verdict. <strong>Not</strong> <spanx style="verb">UnfalsifiableAsStated</spanx>.</t>
  <t><strong>#:</strong> M10  <vspace blankLines='1'/>
<strong>Mutation:</strong> <spanx style="verb">eᵈ</spanx> or <spanx style="verb">eᵘ</spanx> added or replaced after admission  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M11  <vspace blankLines='1'/>
<strong>Mutation:</strong> Bare in-toto predicate, standalone signed in-toto envelope, or SCITT Statement without the required Receipt  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M12  <vspace blankLines='1'/>
<strong>Mutation:</strong> Receipt derived from self-reported timestamps instead of <xref target="full-prefix-replay"/>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M13  <vspace blankLines='1'/>
<strong>Mutation:</strong> Claim <spanx style="verb">c</spanx> was not bound by <spanx style="verb">InstanceCommitment</spanx> before first admission, or was replaced afterward  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M14  <vspace blankLines='1'/>
<strong>Mutation:</strong> No pre-evidence <spanx style="verb">InstanceCommitment</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> Preflight HALT, no adjudication verdict</t>
  <t><strong>#:</strong> M15  <vspace blankLines='1'/>
<strong>Mutation:</strong> Within committed L, another <spanx style="verb">profile_digest</spanx> or <spanx style="verb">claim_digest</spanx> exists under <spanx style="verb">(instance_owner_iss, request_id, instance_subject)</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M16  <vspace blankLines='1'/>
<strong>Mutation:</strong> Missing closure/proof, receipt not after closure or not over exactly the closed set, or relevant admission after closure and before <spanx style="verb">S_R</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> Missing closure/proof → HALT; wrong order or omitted, duplicated, injected, or post-closure evidence through <spanx style="verb">S_R</spanx> → REJECT</t>
  <t><strong>#:</strong> M17  <vspace blankLines='1'/>
<strong>Mutation:</strong> P10 predicate lacks <spanx style="verb">limitations</spanx>, or verifier ignores it as unknown  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M18  <vspace blankLines='1'/>
<strong>Mutation:</strong> Selected inclusion/consistency proofs supplied without the complete VDS prefix through <spanx style="verb">S_R</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> HALT, no epistemic verdict</t>
  <t><strong>#:</strong> M19  <vspace blankLines='1'/>
<strong>Mutation:</strong> Within committed L, another valid commitment or conflicting profile/claim exists for <spanx style="verb">(instance_owner_iss, request_id, instance_subject)</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M20  <vspace blankLines='1'/>
<strong>Mutation:</strong> Statement has matching <spanx style="verb">sub</spanx>, but <spanx style="verb">iss</spanx> is outside the frozen authorized-admitter set  <vspace blankLines='1'/>
<strong>Expected:</strong> Not an admission; if cited by closure → REJECT</t>
  <t><strong>#:</strong> M21  <vspace blankLines='1'/>
<strong>Mutation:</strong> A replayed <spanx style="verb">RelevantAdmissionπ</spanx> is omitted from <spanx style="verb">ordered_admission_refs</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M22  <vspace blankLines='1'/>
<strong>Mutation:</strong> <spanx style="verb">RelevantAdmissionπ</spanx> occurs after closure but before <spanx style="verb">size(S_R)</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M23  <vspace blankLines='1'/>
<strong>Mutation:</strong> Admission reference is duplicated or references are not in strictly increasing leaf order  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M24  <vspace blankLines='1'/>
<strong>Mutation:</strong> A detached/encrypted payload required by frozen admission rules is unavailable  <vspace blankLines='1'/>
<strong>Expected:</strong> HALT, no epistemic verdict</t>
  <t><strong>#:</strong> M25  <vspace blankLines='1'/>
<strong>Mutation:</strong> A new relevant entry is registered only after <spanx style="verb">S_R</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> Historical claim remains scoped to <spanx style="verb">S_R</spanx>; no claim of future absence</t>
  <t><strong>#:</strong> M26  <vspace blankLines='1'/>
<strong>Mutation:</strong> Same <spanx style="verb">(issuer_id, request_id)</spanx> exists in L1 and L2  <vspace blankLines='1'/>
<strong>Expected:</strong> Each receipt claims completeness only within its committed L; no global uniqueness claim</t>
  <t><strong>#:</strong> M27  <vspace blankLines='1'/>
<strong>Mutation:</strong> Receipt/replay uses a different TS <spanx style="verb">iss</spanx>, checkpoint key, VDS algorithm, or leaf encoding from committed <spanx style="verb">LogIdentityV0</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M28  <vspace blankLines='1'/>
<strong>Mutation:</strong> Matching-<spanx style="verb">sub</spanx> profile/commitment/closure signed by an <spanx style="verb">iss</spanx> other than <spanx style="verb">instance_owner_iss</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> Not a valid lifecycle entry; if cited by a valid object → REJECT</t>
  <t><strong>#:</strong> M29  <vspace blankLines='1'/>
<strong>Mutation:</strong> Admission registered after the pre-closure transcript but before the closure leaf  <vspace blankLines='1'/>
<strong>Expected:</strong> Closure candidate invalid; replay/rebuild/retry, with no epistemic verdict until a valid closure</t>
  <t><strong>#:</strong> M30  <vspace blankLines='1'/>
<strong>Mutation:</strong> Issuer-signed P10 payload contains <spanx style="verb">S_R</spanx>, receipt ref, or final replay/coverage result  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT; post-registration values <bcp14>MUST</bcp14> remain outside the payload</t>
  <t><strong>#:</strong> M31  <vspace blankLines='1'/>
<strong>Mutation:</strong> Mandatory cross-instance limitation bytes are absent, altered, or do not match <spanx style="verb">limitations_digest</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M32  <vspace blankLines='1'/>
<strong>Mutation:</strong> The verifier loads, checks, or executes a profile whose digest differs from <spanx style="verb">InstanceCommitment.profile_digest</spanx>, even if that profile was registered before evidence admission  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M33  <vspace blankLines='1'/>
<strong>Mutation:</strong> Checker source, <spanx style="verb">.olean</spanx> artifact, dependency lock, Lean toolchain, axiom policy, acceptance command, or build manifest differs from <spanx style="verb">VerifierManifestV0</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT; unavailable required artifact → HALT, with no epistemic verdict</t>
  <t><strong>#:</strong> M34  <vspace blankLines='1'/>
<strong>Mutation:</strong> Certificate proves a different, weaker, or certificate-supplied proposition instead of checker-constructed <spanx style="verb">CertificateTargetV0(π, e, c, w₀, w₁)</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
  <t><strong>#:</strong> M35  <vspace blankLines='1'/>
<strong>Mutation:</strong> <spanx style="verb">receipt.verifier_digest ≠ profile.verifier_manifest_digest</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> REJECT</t>
</list></t>

</section>
<section anchor="adversarial-profile-test"><name>Adversarial-Profile Test</name>

<t><list style="symbols">
  <t><strong>#:</strong> <strong>AP1</strong>  <vspace blankLines='1'/>
<strong>Test:</strong> <spanx style="verb">Compatibleπ</spanx> is strict only for frozen <spanx style="verb">eᵈ</spanx> and trivially <spanx style="verb">true</spanx> for all other evidence in <spanx style="verb">Eπ</spanx>  <vspace blankLines='1'/>
<strong>Expected:</strong> Formally passes <spanx style="verb">FormallyUnderdeterminationCapable</spanx>. <strong>Not</strong> a soundness hole in the Lean core or a claim counterexample: the issued receipt proves the true proposition <spanx style="verb">Underdeterminedπ(e, c)</spanx> relative to the profile. An independent profile-adequacy review catches it, and the receipt carries the AP1 limitation (<xref target="security-considerations"/>). Not part of the mathematical core.</t>
</list></t>

<t><strong>Profile-adequacy review</strong> is mandatory for every concrete profile before first use, beginning with the Sandia EFC profile. It is a separate gate outside this document.</t>

</section>
</section>
<section numbered="false" anchor="relationship-to-prior-work"><name>Relationship to Prior Work</name>

<t>The following sources were inspected directly on 2026-09-23 unless otherwise stated. The two Internet-Drafts marked 2026-09-27 were added by the v0.1.1 pre-publication prior-art sweep.</t>

<t>Each item in the following list is one row of the prior-art table.</t>

<t><list style="symbols">
  <t><strong>Work / system:</strong> <strong>Koomullil, arXiv 2605.16407 v1</strong> (<xref target="KOOMULLIL"/>)  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> <strong>Paper-reported (per the source snapshot):</strong> the paper defines Supported/Contradicted/Contested/Unknown; <spanx style="verb">Unknown</spanx> is computed using thresholds <spanx style="verb">θg, θc</spanx> (§5.2). The paper-reported Universal Assurance Card has Certified/Partial/Residue/Abstain verdicts; <spanx style="verb">Abstain</spanx> requires nonempty reasons and <spanx style="verb">residue_coverage = 0</spanx> (§§10.2–10.3). Paper-reported Thm 6.3(v) claims evidence anti-monotonicity of MCR under a monotone evidence-to-constraints map.  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> No concrete P10 world-witness pair bound to the same closed evidence set. The inspected <spanx style="verb">MCR.lean</spanx> contains neither paper-level maximality nor an evidence anti-monotonicity theorem; those claims are therefore not attributed to the verifiable Lean artifact.</t>
  <t><strong>Work / system:</strong> Ascendr, Inc.  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> <strong>Company-affiliated research actor confirmed; commercial product deployment not demonstrated.</strong>  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> —</t>
  <t><strong>Work / system:</strong> <strong>Pramāṇa (arXiv 2605.20312 v1)</strong> (<xref target="PRAMANA"/>)  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> Typed <spanx style="verb">ClaimAttestation</spanx>; <spanx style="verb">verify(claim, source)</spanx> returns VERIFIED/REJECTED/UNVERIFIABLE; a deterministic theorem prover may be an oracle for <spanx style="verb">InferenceClaim</spanx>; A2A/MCP wire extension and source-byte digest.  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> Does not freeze a pre-evidence world class or compatibility semantics. UNVERIFIABLE is an outcome label without a concrete divergent witness pair.</t>
  <t><strong>Work / system:</strong> <strong>ClaimReceipt (arXiv 2609.01992 v1)</strong> (<xref target="CLAIMRECEIPT"/>)  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> Claim sufficiency is defined over executions: identical retained evidence must imply an identical claim value (§2.1, Eq. 1). It explicitly describes the identification boundary/divergent executions, distinguishes contract and evidential abstention (<spanx style="verb">I_C</spanx>, <spanx style="verb">I_E</spanx>, §5.1), freezes the specification before implementation (§4.1), and places a signed manifest and assignment matrix with an OpenTimestamps proof before prospective ingress (§3.3). Coverage is a set property and requires manifest/ingress commitment before outcome.  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> P10 closure/reconciliation follows the same broad prospective-ingress/terminal-reconciliation pattern; generic coverage is not novel to P10. The narrower remainder is that ClaimReceipt does not freeze an explicit world class with executable <spanx style="verb">Compatibleπ</spanx>, nor does INCONCLUSIVE carry a concrete divergent witness pair checked by the Lean kernel and registration-order-bound to the profile/instance.</t>
  <t><strong>Work / system:</strong> <strong>Independent Determinability of Agent Actions (<spanx style="verb">draft-wadkins-agentproto-action-determinability-00</spanx>)</strong> (<xref target="WADKINS-00"/>) — inspected 2026-09-27  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> Defines mechanism-independent determinability requirements for agent transitions. DET-2 requires the specific governing-condition revision to have governed the transition at decision time; prior signing or registration, or availability among multiple compatible candidates, is insufficient. Its candidates are governing-condition sets or policy revisions, not possible worlds assigning different values to an evidential claim. It also requires omission detection or an explicit result that completeness cannot be established when completeness is material.  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> Defines no evidence format, token, audit system, registry, or transparency service. It does not specify a pre-evidence world class with executable <spanx style="verb">Compatibleπ</spanx> and <spanx style="verb">Evalπ</spanx>, a receipt-carried divergent-world pair, Lean certificate checking, or P10-style checkpoint-bounded evidence closure. P10 does not equate its verifier-time recomputation with Wadkins's claim that governing conditions controlled a downstream transition at decision time.</t>
  <t><strong>Work / system:</strong> <strong>The <spanx style="verb">verification.*</spanx> Constraint Family (<spanx style="verb">draft-krausz-verification-state-02</spanx>)</strong> (<xref target="KRAUSZ-02"/>) — inspected 2026-09-27  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> Defines signed claim/ruleset/evidence-bound JWS receipts; <spanx style="verb">verified</spanx>, <spanx style="verb">contradicted</spanx>, <spanx style="verb">indeterminate</spanx>, and <spanx style="verb">not_evaluated</spanx> states; content-addressed evidence sets; local recomputation; immutable content-addressed mapping resolution with digest verification before use and fail-closed mismatch handling; and SCITT-compatible transport. It explicitly states that a pinned evidence set records what the issuer listed but cannot prove disclosure completeness or detect an omission.  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> Does not establish checkpoint-complete evidence coverage and does not require a pre-evidence committed <spanx style="verb">Wπ</spanx> with executable <spanx style="verb">Compatibleπ</spanx> and <spanx style="verb">Evalπ</spanx>, a concrete divergent-world pair, or a Lean proof that both worlds remain compatible with the same closed evidence set while assigning different claim values. P10's narrower remainder is instance-unique profile resolution plus transitive verifier-toolchain/build binding, not digest-checked ruleset resolution as such.</t>
  <t><strong>Work / system:</strong> SCITT Agent Action Capsule (draft-mih-…-02) (<xref target="MIH-AAC-02"/>)  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> SCITT receipt with disposition vocabulary  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> Action disposition, not epistemic underdetermination</t>
  <t><strong>Work / system:</strong> AWS Automated Reasoning checks  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> Formal verdicts (VALID/INVALID/SATISFIABLE/IMPOSSIBLE/TRANSLATION_AMBIGUOUS)  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> No third-party-verifiable receipt or witness pair</t>
  <t><strong>Work / system:</strong> Supervaluationism, version spaces, partial identification  <vspace blankLines='1'/>
<strong>Existing coverage:</strong> “True in all admissible models” and monotone narrowing  <vspace blankLines='1'/>
<strong>What it does not cover relative to <xref target="introduction"/>:</strong> Not receipt/binding systems</t>
</list></t>

<t><strong>Provenance for the Koomullil row:</strong> the complete arXiv HTML v1 was inspected through §§1–17 and the appendices; <spanx style="verb">gkoomullil/proof-carrying-certificates</spanx> was inspected read-only at full commit <spanx style="verb">8e5b718c4fc1a53678f1da9a94499df3b311d065</spanx> (commit timestamp <spanx style="verb">2026-05-12T18:19:05Z</spanx>). <spanx style="verb">README.txt</spanx>, <spanx style="verb">lean_artifact/EmbeddingSensitivity/MCR.lean</spanx> (blob <spanx style="verb">096f15d486f7190d7018317002a3ba2d137eadab</spanx>), and <spanx style="verb">lean_artifact/EmbeddingSensitivity/AxiomAudit.lean</spanx> (blob <spanx style="verb">83899399f1157d99f06bcc611466186bf26d77b9</spanx>) were opened directly. The paper reports threshold-based <spanx style="verb">Unknown</spanx>, Theorem 6.3(v), and the <spanx style="verb">Abstain</spanx> condition. However, the inspected <spanx style="verb">MCR.lean</spanx> has no <spanx style="verb">p_maximal_over_all</spanx> field, maximality theorem, or evidence anti-monotonicity theorem; the last of its three theorems merely repeats <spanx style="verb">p_residue_cert</spanx>. This is a mismatch between paper-level claims and the inspected artifact, not artifact confirmation of those claims. <spanx style="verb">lake build</spanx> was not independently run.</t>

<t><strong>Narrow differentiation after the v0.1.1 sweep:</strong> P10 claims no novelty for independent determinability, decision-time or pre-evidence binding as a general idea, an <spanx style="verb">indeterminate</spanx> receipt, claim/ruleset/evidence binding, content-addressed evidence, local recomputation, SCITT transport, or the need for coverage and omission controls. The remaining claimed profile-level combination is a concrete divergent-world pair from a pre-evidence committed model class, checked under executable <spanx style="verb">Compatibleπ</spanx> and <spanx style="verb">Evalπ</spanx> semantics by Lean and bound to a unique, instance-specific pre-evidence commitment whose exact profile and verifier-manifest digests are independently resolved and used by the P10 certificate verifier, with registration-order and checkpoint-bounded coverage verification.</t>

<section numbered="false" anchor="prior-art-boundary-question"><name>Prior-Art Boundary Question</name>

<ul empty="true"><li>
  <t>Do Pramāṇa, ClaimReceipt, <spanx style="verb">draft-wadkins-agentproto-action-determinability-00</spanx>, or <spanx style="verb">draft-krausz-verification-state-02</spanx> already require a pre-evidence committed model class with executable compatibility and evaluation semantics and carry a concrete divergent-world witness pair checked against the same closed evidence set?</t>
</li></ul>

<t><list style="symbols">
  <t><strong>Review answer: No.</strong></t>
  <t><strong>Pramāṇa:</strong> its commitment is the <spanx style="verb">source_digest</spanx> of retrieved bytes used by <spanx style="verb">verify(claim, source)</spanx>; it has no pre-evidence commitment of a world class/compatibility semantics. UNVERIFIABLE carries no witness pair.</t>
  <t><strong>ClaimReceipt:</strong> it has pre-ingress manifest/specification and coverage commitments, but no explicitly frozen <spanx style="verb">Wπ</spanx> with executable <spanx style="verb">Compatibleπ</spanx>, nor an INCONCLUSIVE receipt carrying a concrete divergent witness pair.</t>
  <t><strong>Independent Determinability of Agent Actions:</strong> its compatible candidates are governing-condition sets or policy revisions, not claim-worlds. It supplies the general compatible-candidate principle, decision-time binding, independent retrospective evaluation, and the requirement to detect omission or report that completeness is unavailable. It deliberately defines no evidence format or transparency service and carries no concrete divergent-world witness pair under frozen executable semantics.</t>
  <t><strong>The <spanx style="verb">verification.*</spanx> Constraint Family:</strong> it supplies a signed and recomputable claim/ruleset/evidence-bound receipt, an <spanx style="verb">indeterminate</spanx> state, content-addressed evidence, and SCITT compatibility. Its receipt cannot establish disclosure completeness or detect an omitted source, and it carries no P10 divergent-world witness proof.</t>
  <t>The claim therefore survives only as the narrower <strong>profile-and-binding combination</strong> stated in <xref target="relationship-to-prior-work"/>: concrete divergent-world witnesses from a pre-evidence committed model class, executable <spanx style="verb">Compatibleπ</spanx> and <spanx style="verb">Evalπ</spanx> checks backed by Lean, a uniquely resolved instance-specific profile and transitively bound verifier manifest, checkpoint-complete evidence coverage, and transparency-log registration-order verification. P10 verifier-time use is not a claim that the verdict governed a downstream action in Wadkins's DET-2 sense.</t>
</list></t>

</section>
</section>
<section numbered="false" anchor="source-snapshot"><name>Source Snapshot</name>

<t>The following sources were inspected directly on 2026-09-23, with the two identified Internet-Drafts added on 2026-09-27. The verification statements below are limited to the cited source versions and inspected artifacts.</t>

<t><strong>Primary sources opened directly (Europe/Belgrade; inspection dates stated above):</strong></t>

<t><list style="symbols">
  <t>Koomullil, arXiv <spanx style="verb">2605.16407v1</spanx> (<xref target="KOOMULLIL"/>), complete HTML; linked GitHub repository at commit <spanx style="verb">8e5b718c4fc1a53678f1da9a94499df3b311d065</spanx>, including <spanx style="verb">README.txt</spanx>, <spanx style="verb">MCR.lean</spanx>, and <spanx style="verb">AxiomAudit.lean</spanx>.</t>
  <t>Pramāṇa, arXiv <spanx style="verb">2605.20312v1</spanx> (<xref target="PRAMANA"/>), complete HTML.</t>
  <t>ClaimReceipt, arXiv <spanx style="verb">2609.01992v1</spanx> (<xref target="CLAIMRECEIPT"/>), complete HTML.</t>
  <t><spanx style="verb">draft-wadkins-agentproto-action-determinability-00</spanx> (<xref target="WADKINS-00"/>), complete Datatracker HTML, dated 2026-09-10 and last updated 2026-09-11.</t>
  <t>IETF Datatracker IPR disclosure 7599, submitted 2026-09-11, naming unpublished pending U.S. provisional application <spanx style="verb">US64/147765</spanx>; the submitter made no licensing declaration at that time. This is a source-reported disclosure record, not a legal conclusion by P10.</t>
  <t><spanx style="verb">draft-krausz-verification-state-02</spanx> (<xref target="KRAUSZ-02"/>), complete Datatracker HTML, published 2026-09-22.</t>
  <t>RFC 9943 (<xref target="RFC9943"/>): §§3, 5.1.3, 6, 7, 9.1, and 9.3. Protected <spanx style="verb">sub</spanx> groups Transparent Statements and supports subject completeness checks; VDS replayability permits checking every registered structure only for an actor with content access. Registration Policy can change and is not a soundness premise. §9.1 confirms that VDS registration order need not equal issuance order; §9.3 confirms selective registration.</t>
  <t>RFC 9943 (<xref target="RFC9943"/>) Figure 3 defines CWT <spanx style="verb">iss</spanx> and <spanx style="verb">sub</spanx> as <spanx style="verb">tstr</spanx>, places the standard SCITT Receipt in COSE unprotected-header label <spanx style="verb">394</spanx>, binds TS identity to a public key, and leaves concrete VDS structures/proofs dependent on the selected VDS profile. P10 therefore additionally freezes <spanx style="verb">LogIdentityV0</spanx> and <spanx style="verb">LeafEncodeV0</spanx>.</t>
  <t>in-toto Attestation v1 README (<xref target="IN-TOTO-V1"/>) and <spanx style="verb">statement.md</spanx> (<xref target="IN-TOTO-STATEMENT"/>): Envelope/Statement/Predicate layers and the rule that a consumer ignores unknown fields unless the predicate specification says otherwise.</t>
  <t>IETF Datatracker important dates: IETF 127 Internet-Draft cutoff <spanx style="verb">2026-11-02 23:59 UTC</spanx>, confirmed on 2026-09-23.</t>
</list></t>

<t><strong>Not independently executed:</strong> Koomullil <spanx style="verb">lake build</spanx>, all pilot experiments, and the ClaimReceipt reference verifier. Their build/test results remain primary-source self-reports. Source inspection confirms only the content of inspected files at the stated commit; specifically, it found that <spanx style="verb">MCR.lean</spanx> contains neither paper-level maximality nor an evidence anti-monotonicity theorem.</t>

<t><strong>Excluded:</strong> existence of an automation task and any market/commercial-priority claim.</t>

</section>
<section numbered="false" anchor="document-history"><name>Document History</name>

<t><spanx style="verb">-00</spanx>: Internet-Draft transcription of P10 Underdetermination Profile v0.1.1 (<xref target="P10-V011"/>), applying ratified Erratum E01 by replacing obsolete notation <spanx style="verb">S_C</spanx> in the evidence-closure section with the actual issuer-signed payload fields, plus citation repairs and informative IETF framing; no other normative change.</t>

<section numbered="false" anchor="v011-2026-09-27"><name>v0.1.1 — 2026-09-27</name>

<t><list style="symbols">
  <t>Added <spanx style="verb">draft-wadkins-agentproto-action-determinability-00</spanx> and <spanx style="verb">draft-krausz-verification-state-02</spanx> to the prior-art boundary.</t>
  <t>Restricted the novelty narrative to the concrete P10 divergent-world, executable-semantics, Lean-proof, checkpoint-coverage, and registration-order combination.</t>
  <t>Added explicit non-claims for the concepts anticipated by those drafts.</t>
  <t>Added the mandatory cross-instance selection limitation and the downstream-action non-claim.</t>
  <t>Added <spanx style="verb">VerifierManifestV0</spanx>, <spanx style="verb">ActiveProfileBindingV0</spanx>, and M31–M35 to bind the exact active profile, checker, build, axiom policy, dependencies, <spanx style="verb">.olean</spanx> files, and Lean toolchain transitively into verification, and to require the checker-constructed <spanx style="verb">CertificateTargetV0</spanx> proposition.</t>
  <t>Made no change to the mathematical definitions of <spanx style="verb">Determinateπ</spanx>, <spanx style="verb">Underdeterminedπ</spanx>, or <spanx style="verb">FormallyUnderdeterminationCapable</spanx>, to evidence-closure semantics, or to existing tests M1–M30 and AP1.</t>
</list></t>

</section>
</section>
<section numbered="false" anchor="acknowledgments"><name>Acknowledgments</name>

<t>AI-assisted tools supported source comparison, transcription checks, build validation, and adversarial review.</t>

<t>The author reviewed and ratified the substantive decisions represented in this document and remains responsible for its content and errors.</t>

</section>


  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA+V9S3MbWXbmHr8iR1o0SSPxIEVSJF1tQyTVxS6SoklKstsx
wUwgE2Q2ASQ6M0EKrShHtSfCrtnaXnjhifBqejNbR9jbjln3/Abrl8x53Vdm
AoSktmMipuzoYgHIm/eee+55fudc3/cbjSIpRvG+9+yi2/HeTqI4i+IizsbJ
JCySdOJdZOkwwR+8T4pJnOf+YZhl82RyW/fjy3gQJ9Mi94Zp5l0dnlxfP2uE
/X4WPzz5gmeNKB1MwjG8KcrCYeHDy4o0Sx/8fJAUhT/tdvxZ5Wm/02kMwiK+
TbP5vpdMhmkjn/XHSZ7Dl8V8CqOdHF+/biTTbN8rsllebHY6e53NRpjF4b53
FQ9mWVLMG/fx/DHNov2G5/k8cformfhFWqT0d/Xl9HHGS6a/T+Nw0niIJ7MY
BxqHyWjfo9n/aRIXw1aa3cLHt0lxN+vve+/S0Vn4wb8qZlGSthcsb8rEaTTC
WXGXZjy/4Ww0YkqdPIQT71wIBd95HrwjnCS/pqfVOzx+h3ca9r2olcL/0U9j
nuBDOhqHH1qDNIv/9BY/gj/H9AMgzb53VxTTfL/dTrNBEuES2h2gINC9s+Pv
7r3o+HvbW3uNxiTNxvDSB1r55evDvb0XW+bPTfVnZ1v9+XJrT3+6vberPt19
ua0+7e7QD07O/es312/8q+ve9fHZ8fn1Pk1Osa1skdcrCqADs9TrDKgD+3kP
OwwfxeN4UnijcB5nXj6NB8kwGdAPm95D9xmNZsiL//hIxn21+8ihv4wHBX0Z
wXD73mZn84Xf2fY7O/RhHmdJnCP3qREO0/E4Kfa9zk4cDuOtna3t/vBl+GJz
O4y2NweDl5uDncFe5+VON957Eb7Y7fKSwuw2LgzJs/CxxdwygzcMgKFhHbg7
bZlZOzSLbq/6qjaSoP0A/1akaY0ji87vui6Br2yK0cFWdLHeztTNm947+F/8
74du6/9j0l4e947OjpGuDZy6dTRACPrvOt0SjZeLRmBToWqntZCsySQHedBy
pQH+s0hSVCl79OZk3+t2WtubL7vtX8eTNEpbm5twfHdfvHB3aMcHEbC5W0va
KE1ITCwe6H3v6LuT8yuQIS4VToAC0xj+B07rkSJEPxmBgPbSode7xS96AyRN
voQIRy3vfRjdw98lGhyls9tRmFe+JY68KrLwPn7Mktu7omax3c4Cop0A62ST
uPCPUGsp5fXIr/BDnDMI8SL1Q5q4H7kLQwVWR8XHx8eWUhrtMBvcAf+0k6j9
+cO3ig+4oO8ue2+vfuF3Nl2aX9/FyF36gLc24IBNciBGAsR+HY6TESjWiyz2
mfDwUTLyD0dpHkfez4BErOt7J7I9RyAs8ic26Oct77ssnOW/Lu3Pz9O4/AVt
zfV3MKfRCOQEEME7PT2sY8bNz9qfe3qNb6/cJ3kIBPqC/Vg2nND/7ORbv9c7
rGxAb+IwtncYTvPZKFZn37akFhL0quWdJXclal4VMZgizhdETXkPKUbvZ1k6
mzaBSINWhai7i2VwPVHHyZ0Ya8SXiiUHvKIvo+yTYwp5Ly57Z73zXkmsgh0Q
TsDO6yE5i3SQjvxTMgOuwfwryCwAwXI4CpMxai6j5hLYlVmRTtJxOstlg87j
Am2KZZx9CZwN/x9GYT+FM1jakcvwIfG+SzKQxO5PbKpv+929BVQPsz9P0JDe
3OlstzY7W93NZ7UUDbMPyQOTs5+3za8fUBcenvZOzi6PD49PLkqWFJFBLPh9
JgfZ+ccPCYjkQexdzYZAoAT+nnvhJIJDCQwP20LUIhIdP4SjWfiUgL5oeb+4
m5WIcxEn9DbzjWHuw7twcltm7yRKrC9cadBZJA0sEu61Ot29vVVJKL8mEn73
5s3Z29PTk9Myt6Xp0LhHh3FWMEOJjDw9PfMukmk8SsC1QZ68Rn/Ef5WC3R9m
c6+HvF+AlJtl8RLq/QwYLE3H4AMkoxJNfhbDjOPS1yXm2lqFubo7Lzq7KzMX
/Zooc3rcO39RVTDoF3kvPPgTnIwxnkVgHGIh+PMWDukYCXYKezkDdlqy9tOW
F8XeWTrLymfrNE4nYRal5e8NE70djbJkUJGScT/MiwTmZ3+vadZdQK1np7xP
3nmK2wsHAMzS6QykondFJyR+Bmvvbu7s7TW96bTl7Wxuf/rh78GCfGYbW8/A
SOp2Orvtvd2X/pbf2eqAT/Vyd8ffvtlaQH/LvFr4ZKPh+74H+wNqHIzrBpqX
UTxEvvNCr7hLssifhhmYB6yxwj4omn4yiXAbkFVhVUfxmO2AIo7WQFrm6eQb
x0GNo/UWMDHYzmjg4pPiCnsDOAJALw/EJfw9SSdwCEbeI8cPPJChowi+vAsL
YLoYBhhPQWTgFOAnd/BF7OWwN96AjYxYiZ88LohnwN6JZvDfUTIcxhmKHZQ6
csj008MsBcsTBgGh1kLW0xPIYlAdhZfk3uAuHtzDK8JbsHbyAqcCrgUs2BO/
G94JCqRIBjm9uY9HFTYbfR9WynCGw0kOtMRpGF8THQoYEokSTrSzY75/6MIb
4oiEA09OJoUuR3+U5HewnGo4wEsnozn8dETuhAdD4nKjGBaZWZPGqUYpjDBJ
YZloToMkp58CN8xwK3ALwBowr/NiID0wL5GL6emBpVxks7jF3DROoggDEc9R
+dMO0Iw+Pk+s//y+0fgpLQemMqXdW+7ZfB5XBiuyZdDyTvJ8FiLTwC5P8XPa
VSLf41082YdprnXXiSZMDFh4Du5rGFHsCN7sK77z+zA+ssI0HDBtQUiPffkl
rCUDQwQeFYaTXw9olkCVNGtqFmdXhvcPow9M7QSNKWCHQj41DD9Ip/zGgdK0
8i59qiTS01SrSIEZmhYfj9Jb4YBi3vRG4MZ6MHSKJIX/TIbxYD4YxW1cTIHC
i6WuHhXfzZsB3z3GfFplaJB5ocNyyOnMbAl8HZwAAXAL2F9Htg+8fgz7GBPZ
h0kGJ06v1ZCTTzEIh0QGOMDN2lwn6QAvxYfNLAp9/sAowdUGpwGQ8ANwOux1
OomdKTLBUerwUZYTFKzBu2dxdpNETdieX4EwKeDv9cDLZ32MTzTVAgNlDKEH
BPI/8KajmQiSKdhzhU8D4/qVdURmQUCMnMN6Y9D0cL74TbdJDlSP4W+QEbLd
mhDjEHRZH0wtxVpqc1BiqQ0r7sCCv73zgquby4AotcVsXSeMlTQLR0CbCN6d
TAaFEsjwkjETXl7nHIwsBg7NYRN554s7Tdif5FrWalmPClMzJ83qBc9Kfql5
ypZ39O5+CipAJDXKhVoFAb9bqiFgxsntpKogZLsr+uEAn8JZbvMsFecJnyHv
NtVy5dQ2617eNDOn36fDplkqTgzID6ZFCiwwSmBgtpRpkVff9vzN7R1fqZgn
FMzjHbzcm4bzURpGKOQWqRlLE+HKUBxrzdNkeiJ9RyA9vXdHVz58OUw+4HaP
QrbymUszjoRpQWS7ukDQIsnZWfj4EaPTMozPw3z/vWbTjx+1WB3wCfLhHX71
/PjqTd9/3xKd8v+0itzYOA/JIAR/kiUUqMWkP6M4/MaGejGtVuk0+zegssgk
wfmE3iR+BF6BcTBwiAeqYNMZXvT8OViYSi9ciirJ75IprpVZ5uNzEiX0rsz6
BbAH+9Kgpq/NAX5aCdeQ2dbL/Na1jx8l7v/99+veLF9m/MBvK2F9fEqz5gER
MZ48xCNcK6tSJC+QSEL4LIg+ftRhbFqvHsHXzyAHIdnO04lPPm4OFJpgEIH+
A4jhA3+BTPn0wz+RyWrkzRj06Sj3Pv3t39XQ4NMP/4N3DCbZUmPYoldrw3w5
Z8H3y3hLRg4O9bz+zw+g4wJ0tukvNI2O4S9vGMIweP7mRl6jvRuS3QFEzyXf
5aN5AtPjU50D6c1rXmO4GoaoWm2H4RTZIfDG4M/ltg5AOsA+8XCkXUB3/WqG
ESaY3GzST0KUlUX6CD4aOSZIGWCjtd5F17zbFjXwILzfXkciNh2IXozekIEC
o5Mh4ad90DkP9pNr9aKoacsgrWxtCpAGIHsANEhEJxLWhhLZ0Z+wvgR2ADla
TAbmEWD6lDYzMJZEgLNRWsU3WoVYVmyMJ6ZAa4aTAPuPJ0sNVvJ6AuKgmyi5
hRcHMiGjB50psVJs0lHGEcYoQcxvZWtzpLFlCuAT8EkeYzxWeMAYBqI3wyHa
JrwnOFutJOHJdFYAAWDc1fhxkoKay4Di8chSxzhQ2WRUJLDXGH8AhiL/XO1K
2WBkSSOWeG40B+mRIrVMzdOVNvGrVJ2z7NnEGIgkL9RwLN3jD4PRDC3N+AMG
Y0GyaCrzqmmfChkM5glWh5CDt4dNRuNbhNPpCGWVWrmyOsXUZBeYONNY+bJs
1wxFOn3N2pVQAXE2Qpmfh3N8+RzNf9Ap8GghGzYMRzkpqURJOCUkkKOipMJN
aP/ALrPzAWuc5RKdGljRuqYloYiIIfqQPh57NKcjfI+OAbJEKavZaZakmY/h
4vLbwYC/RXlKx8Xku6Jyvos5Gv09HZ7gM4c0QL8GDI0c3Qlr431LdYExDqKD
go8wXZNy+5z5RpLM8YtkTGcXjrr2i7UJoHQgaqzQu40nNCf4UVj3Zjv+/Dlz
QecLCab0EaghpWdTVBMYCfDR/2W66p95ZB+YSeLeqVTY57xfrTZU9j+54mjz
W0eTPBCJD6ELEkfGGPjaCUiSGnRWlKGLETlSdZSimaheBv+mcKQkM7721Wzg
seRMs4Lkbei6AE8sk2QHSR+kIY+nFMzq88ATofhrEgMFhrZY1IIMlYxSDWRj
p6PcmdhTPImT/UJSgZgCx+IRgz9xOPY4XeU9wtG4xekhR/TntpUI7jN8DjZr
0SL5YFuFLInVyi0RpbxK8YDo69kkAb0HD1SjmBy0ynkHE1Rv8DP2NI17ioPD
dHNcSs8VtuMwu4/pnOHYcTYA596j9YOoQuMac8YPLDBZTVzT8UtBv87B2B6Y
b0kPFOZbcUXu4zkaGVHuPTt7e3X9rMn/9s7f0N+Xx3/29uTy+Aj/Bk/59FT/
0ZBfXH375u3pkfnLPHn45gzciyN+GD71nI8az856f/GMt/zZm4vrkzfnvdNn
HOIAlonSwYzsDfTR4Vj3YxOuwzBM3ojifABOHHsjrw4vfvfP3RfALf8FfKHN
bncPWJ//42V39wX8B0Yf+W06GNnE7Zs3QP3GYUamCumZaVKAdmuiVM3vgKM8
sF7I0/xLpMx/3ff+uD+Ydl/8VD7ABTsfKpo5HxLNqp9UHmYi1nxU8xpNTefz
EqXd+fb+wvlvRXfrwz/+E0yTeX735Z/8tME8MkxHo/QRuRJMOZY6SMd8Pu7j
AccdYk9WR6jA8kdbdoCGSsy4kX0goBe8Zw+q5FHhaMqrKg/38SP9h7IoWjgK
+Vz00Ds5RWfhJBnCCX7XqRmg1jShgepCpch8ztNPGZ400mn1wTon6EAMNRCc
lL8qNAoEnjJWGljwGDxCQcvBwVhEt2SJLeZc3RWHWV7xnN8l8SNuwyXYNQ/g
WPWUQa/8WzfUKhtUiqtWyPwlASaQYOz2giCD8T4+J8zWyEdQ5PcUPDgyuw9f
27zQaPzVX/2VV4AV3jgHu2w8LeY2X63F697+Nw3P+/Tjf/Me4X9/9ID7mp77
m6b3uN5oHBmzhT8cyLOLBv70429p5B+8x09/Tf/zG/0Gyh5W3gI/o8fqvvnN
Oj3z6W/+zuNTsDZQT3zjfgK/bLx1sy7uhGmxf5ApyRq9ypQ+/fd/rk5K8ko9
ncZZQ1rbs4r//V9+pAkd4zclisN3+OtG48kgSN24/+gOTrOuoRL8kB7FJS94
P3BUo0GpZZZXK6w9QBcPHCY+zCpSoaP8lPkEl4E2Bc8RPtTyDutD9mgk6Wi+
rzJGEqF7oGiM9rc5NkACglUYxZofk0FMZ31lSiLbLdq+oOW9wsQAQjLRRx+D
VMLTjmJthIg9sgQHI3g7xTvC20maY9p2tSmQ0Aw9PvSUuwRTa65CueIHizFF
gVrySDGgYGwkK/wlwa/B8pBb0+PYF0oXna481KoBM6s1CqPROGHdJpNFCQWy
MjayPDR5GDQGS1kKTk+2wMJDNymBj2c0YWUvp+zPkxLB8chcDcLgwCZF8IpG
oZDjbMImLqwM7MqcpkLMQFE4eJ6SXeYNeVPHEURAc6bEMXyDWJ2ioGXJV1dP
wuReUT5RKYq13/9b02OGUYLgUkdQSj/Fn/3+31Dg+b73kIQq40EmMhh006LR
I7yhDPSK3b93HXrJpTxIeUbFGW1tS4N/lo5mHCePwWZpKJ3FuMlrDpYcap1E
Y8I2gk5eX1n08Az0CWhokjXwjDcdyet5ayY5h5yz3qgVw3WfglhdRfSSyOKs
QowRuAQcDUbGkCGdz8ZjBDmxukZBtbJhI5jzmpTcgmTTkCIV7Po4IWVOZ+Gv
ml9kKLCUUW6mPKbcxTp5yQ8YCAyJSvU1ZY1eS5AN81EUtMUTx1nyam58f2Nj
iflqEgIm1a3xK9peXSPBTVgGOHQGG1EvKPJ1GNeI4xMw7/hdWgJIatxFQ8Db
XBRDswJhUEKAIlxIJoUiUpKhlFsl6za9PREwA1jYMIvTOBweIzlj+m/LcgWH
sv3u6Ap8qVv0Uu/G/ManIA/2xMsgCyO3ShtKqIuFKhMnjopdXAVU/4FkXsfx
uB9nlLwjGcjBfONXyIewT0G9oSBjLjYyAnx7rXciIQFmOsQfYDRZ0Z/lGsOj
OHNNQdIiTUeDO9S9OlqgbW8WdEZWV1/KEAhE0IGentzowW50PDmrfqdeJCkN
+IHM6iZPZ9kgvimyODZfqoDqYH4zSgf35ov+LBlFN2OZTHW0lN7LH98gu3le
+CFJxzfTdJTAaPqBcDCIpySKblAUAW3Udw1lISg9YF4HAoqVAmrIKmWWPMlj
s5nJf1uSvDrSup6FepJxJ8unhugHb8lv1AItSOs1wRJBHaIywuPNukEZ7TRf
rZG8lf5hQ58MVK22Puex33zBY/XOyOc/9JsnH1rJfVlqcnh3KeJ0KG6UDPEc
vQbtd0HK75KtlyGDjCz0E1tf1QCDypmRk2KDukTNFrMpyOXPoKQwJ40nrL52
2VLMaLQ2Mty6YGBbmpVv1A/7c7Aa+PtvaqbdKnH3l8xq6VmomZr+2pnbk0f2
ybldmmflkc8bVY1ip3zrieb8onYujEtTAp9Fa9OSpphfuG+yFPXUnEABt0hu
BozYFlHdZMnpseRsWhLTE4nZrFEpzhCYlwODaEa+pJNnGIfF4K5WiMpKKLhy
XI6wNOWsNQWcAwrbdkSUosv4POiwF+VYc46XG3ycMJKJr9dR1IrWt7AQGXZm
dfHpDkUWG1Y1s6FmpQFwYDZZVSZAnf0CAWI220cGwKaYSwhQVeotY83rpxWN
KNas0a1ghFYXFdTRLa7mJRZg6MzvJNNG5qxWeirTpKF2DKC2yaLi4UC16XQ0
t/AKaPJguJJR9QJTJtcarPFjOgSaB+W8gHv/EIsaJXSiMZBIIGhTSuXL1fPG
rKHUaQiP4k+5HJQ88NkkfABPiDBW5DNlNnHMMRPay/mzz6U5gnLq/Oqp8/Wp
Q5Ff2W1vnsSoV4Jve6fXyjJFxMAUPedxMjD5qZ6iCRj7dBCbyJc52OMznSu3
90Hh6xUuBnaCMBhm/0sLcwWHM101y8vjnx8fXgfkPF3o8A96EeQdafvzd/9r
YSzw09/8HZk76mFceBOXLAuFZz8namVMJ8N4BN7BnHUNdE51DKAz9pp8W4om
x9qxq9jzFKACOmNiSGhK2xTiSRxgLkpXN0zDhC12TN5HxFquo+ikOVqLPQsK
ic0mCdYeY6AJz+K+nSnIhMfwdyTLOY6Do+GGFpKqZUjWEDhlcMeIcfgPQTre
zsIM/NM4jlreyZCwPnoMmoA6Hk1ru4jIsOZZNtFMS7DJSQ3PNhpATQ0TAW7I
CYgYBWoKHLeSAGYJeUKxPjmYOeG/EIpUWOHVtA9zkiU+SCKWPW/MZhLKXhBF
BNsuw1EtXBVnyJUgHEktVIuzytZrEGk3KzCSyIEVZTFwZYZYb5adh8NKvoWK
NZYHW1joWwCfMPrlLDJVkTI+8YbC/jgUNMi1tkLFIUfKDsFvYkpRo3YiQAcP
iFitfevw6s/VO/a/UYs4oreB5qyH7POpCko/DtCgUBIa5GeKAWRfbaetXZTj
LrEiZDICxsKsEIWK36wFBfwVrJMJffj+2gtgloHgX7GtBeIBgHOUc43U4mS7
ZP4N7Vveq6crIpoS71XZT+L/vgptYWxzf2GMFF8C7sO68b0NreA/NA3x7xLN
7Y9AZeLPcqyZH6W3N6qkxLjFWFpyo4h341rpaA1ZFqiRl+YDteobihZZ3rYi
wg1KeGs8iSaVPjYVEjcqvoPOvPmBrO2GeJaYWn1HfONbLKnXDJabplOgUstO
DYFlmwgY0qqfcXdc7CcsEkUIDXln9CbCCzGE3FQ5YGk/TBfLSWAKAUIz3hLM
g0S9VcG2sSHVMRZccWODYvdr1RXZJ6ZZ2fh1NAIQbGARQ74KNPMVBpCP4anV
DictAJ1WFW2n0dBprfFZa7PiujiI/NOmXd5gjxC4DCY6z8HGtrxfxFlq7Uzu
GkIHVDEDrxtThoUCvxPQQAzA40GAkPSMZZUABy1nQlUJZKxI4SKEjjkRWRIt
uO2C1CVgDtBOxzA9nW/PvU8//INlVlkxckuMOAFroDowLCKOHBF/xag1g9bH
gZldNdtvbBi+1PIPuE0qALb3dkECNhEgjZULaQ0bMVxKw8d9QTamE2fqdRyw
EBdg1lNZAuYc5KQR5oYsp0ndUQ/MKWyZuneTuyK8KOdXxRIogWRxF9FOJusY
GMVn3WC2jHG4nC1VOHF6sZgjki2bUFGPhvjS7wegQwSetRCJTnMPR76yHzQ0
HRHsliVeg1DnrKptXdD+YA8JVSFEUockNEMmMPnC8Sfv0hQMXdoplzeExf/4
vCZRgxb8ZQXxD3xE/l61os4AlTM9s/5cRImKXGMKGuwZ2mjQVGx3oN5Nxphg
HE9z4w1SvIsc1XSiYu3hCOSHnXN0cg5rpxjaNFnzIx1eKnISrCqiTDO/sSMX
N/fx/AaY9BbBY/Al/vQhym9MguIJLbreaNjpjrUPEmUVDhzDyqkgR1lhLFws
CHn5XGBUXDuw8ESSiW/aHsdREvoUtbCcWOqDJo25uJQ0mUxnojk//fBP10o+
nGJljKkRYVS+m7vZN99cX/EJcNI3TswHKNf06pI5MAedaTH5+WtH4f4EBHqN
ySKajM4pzeXUtnrFUEupoF/8tQPQ18rvrfFGNcOUg7Jrp5zYld2K8XEOt+H8
f5JXN8rsipGzd3EYUX4EjJyCUvdY+/GXHfDAQdOs4QuWhKCdkGiMDGQNDRKK
y7gMKstGj1cG4CWo2kOeLANxcVG1oxBaN464oUHKDg8W3LnpOE4gkgRECPyC
+SO2WUWfcJOEI2+uvu1tbu8Qn8BRLqQCzT4y1QFARdNvv6FHiIpPE5B4cy74
7hvDtPS4iZxpL5kY7S58iO0C3gz2k/znXJel0pFavPe5wqMgl2LFqNZvVyjF
KWhvV2EQOO8xHjEuH/7l7hh55LRV/kNpx3mzBFJDO6VOokEbi9ShZG7Lu+Ch
mQ+wbmUUFqY6hLGZKIhVkKvFvU88p5ybnFF2lNxEbu3hd3O/UgIbf5iChZag
4RwDP8UUVZA3cI2r1LcSgF2H3JSXadXTWqG5pm3sJqsEyhoNUYcapq1B3DYk
mxHbtnNAJfa2JCh7h5lAJV3vEMau2s9k1PhShWCgNiDMIkF8ssmUaSwnqQHE
sI9GHD8mayWRMmzXuaD4JRszjLYAfnKsGrvzQFlcHtixFF3dRU+49ofU68PE
lN8RJbkEjUVGm0Jqxs8/dNjXD1y5AP65MJEXdAOEf0hnSgTDYg7Z1JiqL+Fh
9uS1jcCtGCY5bg8mRcRmGKPhM6DamwlPyqCIOBIWpdoOuYvHYH1gHphMGDZa
+jnXcQwlQCp0B0YCKsNcPCyrdQ2rCwqS4rGF0wLWnpj1CeHjfinWNAyIpcRq
GxPJHkbxMJ7ktKVRPC3uDuAxU3yc4xHkWCKfIhwGSasMMDL+tHWsUbtg5dUU
VlqasafFX0/VlFFsAiwq1oHoTKDDja6Q4bX+/GnP3hr7VOmUE/JB1RuW+/UY
/Oep6+WshaKyHQgRkOwU6RFyO4aYjHCSdVocq0ohzq66uCt61GA7vDK0Bl+q
hawx7krwGozjqP4AFW9n1dYAFEWpNAeo7mC5XwApcdd6+KYSQ3hChdoD4E5g
4n4RdywcQoVPTODEtA7J8+pzledJ+1KxnKsarXYGFVXH+t04eBL8E9GHasPo
eMexC61dNGpJxPIEbSf4YISnbsDAuaKid4yx+Zr0F9awm20yPqa1YWHZE2WR
DaNZDnEyxPN/R+V7EntZepwsL1lHuEDz8nbql1NyUqW5DFHKrnDFzZ2ZABd7
vAc4QR0rY/ZSNOKaw9o2HWS9SMBjISE3Ngyw3wfVimpIKxTs22DoSzHvqbQR
dIUCQaJbXtWZZRlfo/6xIAxT6kbH14+sTD45lSSodd8KViBYQuT8iAbncnGq
GyYhF5lqYMcMoY2BvY9kRBgkneXAFHmMmOdZf4Qg8rAIXaEvsRduA2hc9Vfi
quvOgJZKWBVlaSkMy5cQL6omWilYI3I+OBbgSGNYMHnVWBT6wftj4y4haIhF
pRPMqpdnjYas+FprdpwVCGw1L1YzJlufK6McttDxiYzMxcPHDeVqLDb3nCTi
YyESKGU3sKZqpvRTNEMrv1n7YM31A0ne1chcL0Y/8LngBVR0qCUNFj3f0uS/
+UJNoIXRDc0CAyOr/cOPi+y/MepgxRH48YoGhxXxiOvGqBDmcTMxNQkXycSO
gAOx90fDUyj6GysREg9zyqigFXxjEidxGdXIMSi0+PntN8YqNYg+u5gKJo/8
RV6w8lzqYGY6orEiiT4Hj1ZGoC0awTkrJTLT8bBB409aJZUp15Nd+UGYCKT5
hPkgZmOPnHeW+UtHkOOPfmM0Q2e1HGPRRAsHd1jAaHeRCWsP/SKqk0Sse8Dy
KpUBwpU7NnRwoGgPM60bJB0MZplqJTGw1IGMruWsmg7wtAKNr9UTZ30xXlRH
btBVbWmm16A3wfnF6yqPd54a7a8g/9QnQKFsHIsPa49Wwr/YOSBjdbT1q9Au
m2D1OXouTbPF8DesVJbddCwiemia5oXSkDVOPk/QTjKteMIlzKmKlFWhOJYw
Z7MpJRYXKLbAUWLJmGLCBRWOV9kHub/lHVvah/1YEwCicIdlBtaYpfioOMrJ
hE45YYj4FWQyh08rSgpH1FaUIqYCIVxx8YimjSEVKimKRWgXX++DscQkzKK+
MpHNJFez9dYQNuKzYF7nOLQ08RHIClcYsX1A8ggjb8ifjKt0SpYFnqiCQdIU
TN5/IKJSskXAbOOp9uDJaqbidE0wRURJu0nwHg0ibpXH4RS71U0iPat4xwrV
Ta0IywYqsrRdPqB2ks7qg6nFplh/H3e9ZdePUayGO/opoZogoimk6C2Nzou9
vkKii5Gak2VnNStiyev0AbJiiHiksUYPbFvE4sDAGAvCU3DLHQx8aTCne1hw
+wy0nx9EvOFRiQ3SKMz6CdAgS8hUlmyS5eBd6+iVhdpW8VkVlDMzlF48oYeB
00w4WRv6WVxkaTiQxg0c7qGF3iV4oQNFF0yoDEGPaVbgo/IpxuZm7K5xpIlW
nHrhQ4rsw9LH2VZwBu88OlVNC9Kjjhx1EVQClLLZgRbJShQBI2OyVn/uinpV
zL1UdjEVOQnj1J2bXnMYoWOUJ/KcUFHC33aIs1TbZyMz2AByevcrX1GFrYcc
vhROdmkhdGhxNtRtn+joSMVd4YCL4xhz+twqwT1WqayPz2sqiVCr2QHOt9ev
/Zfez6/enJshVKXSFbAWHIG1nx9eSTQTL9ZBWklQPxmDfNERT7uVDAtsaShr
YaSdzpEqyYZ1TwbkhH0DlceqHExqmWU1CP6+Se1zsfvuugg41umwOrxV4JYS
HVYIOA+HMQkFoCHV2GK8BtbVppVnHPnUlbeTGVVUNaXfDMF440GClbLSAxT3
lGjKEtLqWUrorrya46BhfB7Zy5GyIYmkueaPWMQmjEezkllwqn5jQ+L8E67Y
xTAgBhaYZ/e9QBJyn378R5kY+p9RACJDAULJJLFtYFg/hxOnWO4c82pox1rL
0J5SpIzNzfRTFpSRdv7AhXhyLBllyaTSyjtWYATDR8glwYbpP4eMKq1NLYBk
msEBm6ZsOeNayAprea/gtFoIbOnpocoi6fksfBSbrUhvYzIydNdw2a9lSWyW
39x+nt6cxW775Rb2Whhk82mBjemnd0iYzBuDlkEmHI9nBTGgGVE5Bbm6HKGg
U22hT6jNvXKDrxStMPZ0MtFsvlDAuqhm7dG4BTViJft+NWOk5a4uDHMfVWXE
NeWyFOv+I1tNXX366980Foh0HghzR6YNoAHOkJw1WRsR+o06tdFYphToJXbj
NAyv3FxWEaPOP7xCN8rTqEEFuI9Y9lDDATCW/Y/KyzSr64OamoAvHbqiQdJT
jSgn6qZzowoy1Sdd8xKckpNNaAwQjE4N424on+BOCAvUCc7N1aCmorRR82N3
AYTnlljrHwksPwQDr2iUapakDh6hXsuqDOXHVtdj53k2H2NqhQU2IpgsvYuu
0/m8beICeA7s9sm1CzCdlsd4yQYJdRyAzxYp9IZ0ogRxu2JjeXYuT+rMABoR
fBFVMNK04GXugQtqetg+WQN/sMDCWsGK+tKuOAcLcDPLmgrZPC2/rKuJPtBW
hWRQNTw6WMDRwdIWSiBK31gmQ62B1jRVXWSLK6PMyDtX0opdYuE7jLR0jVG8
/OPN1TEYDkbGjMJ+PPK29l40UDhxk4ma/koarKVqQsiPucGiYo1wrkbtaLhK
7adyLvCF+mEHgcZWLT/eOzw8vrj22h4HFeAPDH/AWbeap2gsCwbJKy6CZU+R
WaosBjhV01lhRGBtA3MyIOeUOe/HuvdMLJ3PNTagZJSjW8MJdWV52SZnjQrV
apf7fbOxhvreqn1nW5ZkA/b2XOZoKIhkzY77DNKRjQ9g59HFQf+Km0YahwrY
VUD/XD6ja+51vEnkUtO1xCiGYLqRB/W1wsGyNJROFRnNJjKeiIIu7mlggwHg
RAKh4tHQOAg6hSRPYrIJqzWr3QvVzLl7KCJncTijuqlLNVYXKgqInayFIUuF
chPDunYGTZOPVYkgifOZolQN+qKsbW3ZYk2pIkEclRukqy3VjOurMlW/ViYV
VxqWqzPtMlJ4W1+Kw0iWkdeLMgpcPdUCnXKRi1L+buv1tQCZ8wZ/ZZAunW3i
4JXvDVjUoV0b2yV/sFcRp9wXpCjCwZ26aC1cdrrQMQRhwL2hw0ViQ10cY6d8
a3vDVOtocuvDVaDwJoeoUd8YV5piuC2TqhzGuxovmX9RRcdj7LjPjgIT28rR
s+hB3LEKDKkfqc2nELHsvcF5SFCL1Yew+6UJYTkuCcbDMX74mGTSOkp+w645
HF9yWqRXFV0BaXpVEfCYeoLR/V7IBlJzLFEtuxQk/gCDFIJEpmor/kSKXEfq
zguku/SOyiXKpm1bcUWp/E7e5Dbb4leqBixYuovZEgosJKo9liqXIpuMkE/w
TPqotIXye/1+lkS36E/iDPH8gcf+ij7DM+d606A78ev3eHy5bTTNDn94bSFF
ZJW6fizAZB4Xr5gmE0gBu/GeHlhpGbTAsxAD2+0SKOH9HXu+TAZ52eLm/75q
U2PdQlRepkQIVlugbvqlFli5aQV73tqd5r5sfTpuYa2NzKFRqLpWVgoe5EIX
qo2E/6eAxOUN7DZ2wyd8jQEWovwbIRJ3Lu3UKlRRERTjRS8mkNW0bAFQ9kup
gCPSLQ65KvkgAy8Xk5aOlhJtpSUoeWla0mHXuWWrWLX0OfhynlWjOlcDgCWr
bviY4rV1slJridK+S1fYPcTemnkJdyBaL62/Ehptc9hyCQVUvErV/8Nb0Y0v
AfnI4PgyElQaS2FQIGee9HXyT18cTV2p7DWxwd8m0+6JA2vf7aOxz0Mn02PB
4SWCXrn2Z/mNGp8pvHrWLVYa/45hI8xKtSsGNWKPZEL1aO38oG6uYsAqh1Fl
kjQ2mR2XCta4ROn3VFTpU9rKe4reuiuhzq9RjQY3yCL1syh/9nkEvJZs2F1K
bPNoz9HAEA54hAg9oli6ftuJNySExAoRKiZJOB43GdD1MzagviC8fgjkHE9r
WPLCvhjAmGFLqHVhm/XKgFuAf9fYOJMQ/9KrOOwbXz6P7Ecu7E6Qc2Cwwe8F
52XB5QgJUIZ160tbStRjV67SR3KZlF7g/ZkuY6s5VFaBgttChatntH23vFGH
6qej+5IkmL5WnUk86fJf00aupiF9f65Ln/G5z9uj44Xup3sjglHPRhI6tr+8
3cVbGuebyyRWbPSvuoqUFJOEaJZtcuWywboG2BRSJgG60rWCOV0pWL1JMPf+
EHe4fN2RMufFvvumDVLaT4eyEDWpZm0VK98IxbluQSKU6W5yO/MltOfKTvZT
NMAw/xKtzyMBo41GSS7J5YQPZNMCUs9Q3d/GEvyUAsf0lkDeVOCbMmu2NWyh
tLB3T0uN75AvR1Ycg2+vDJ5TRSof6jzgQD/nAU01Op94ut8kN2rBvQryM/WY
XQJGM73n+Un3Gm6RwpM6ADc6zbJ574O0/Zy00uFljK7rK5AmCk4wIavwhlrf
xNwbHqjaTyJgGYysYFbBshjXVLqhaeUL9N0B5EmvU1T4pys1kV4kKL7c5G2W
7F1i71FyH/MNTYQvsIQZyN9ROifDSmMMcG/QysIIxFDWIKggpQgwCis9tUuX
uOlrkHy+wY3CU4eVlMyXkfT6Lsk1KsIOHDrl5rpkf8WrX9HJXlEQqgtWLTet
VjBqaKp1u610uNDtLcxdsVqOUpShHulDkY1F7DKxu1L84S46a+rRyxeL1cpX
fYmYeuqpy+9Q9bldBhZcPOfcS8Z4JxNqw1Gs2Vk3lbVEwulsgLRlWnJ9qePp
4N0Y5Mo7Tke59JOxBVIBW+INtwirtZiBrRIWYt8aBirBnCvdW3C2jkJeyjIm
/VG+L7BkeP7BbgtM89ga9T/14kAQQu+pPY26C7G2U4zyDkkJGGx/U19chaAy
vtKGE0scTmKUz0PCdWGuSeTSrravjk3QdWZZ4phOq9vqCtiSgHlWU8xUoWwo
6KwvnKeq8FDgnIbZ8AImlKv4Y8MOH6Y6o8rr9qV8WV05TodFxeGDcvIwOLCk
tSIrvRj/sDqgiWmly5iklUoYcTYWrxKw30sY/AgkCY4yo/Cquj2e02LBJeLc
Q3WhSWCl7PTiyKFBQECLrYTHdDYSkaovJHCG+fd/+RF7GGGeEJ9/1JEnMkuW
hkvBKMw5BJ0Zleysic4hT0FQQWNVxit2DpnFYTbXHSV11DmRKDOH3qXozVWO
1K7CgBsCBhZwjtJNaQqEQPdFze7LjxIA2OzrxkYJCgE2GI2+Dz9zUrgCVybB
GFqvVCmHhPIrlEuk40GN/sDxVXmLhy6LSDuL9K6LeQMSR49YUyxMBULnfoId
OQVjKXdsoVctSYkL7NQ1qOYkejRnfc0511XkfJoUhlp1ENVFgdU4gPWZTgoJ
9qZpe8RN21/OHABYmql+UC3bvUgUNpJLvTHOpG13XSRsVYerH2GNAQ8fsiuA
Se5kMAN7WHTJKH300btJp3TEbkEw58xXlK0spYClU6RjD5B85R73SlNMUVSR
vSed8if3NOY4LkIOwg2yNNcKL/esAhulDPWN0ursSvCrsiSMgM7HEv/Eegh+
nfJ9WEXL3X1SuKGuDOagA/c77J33ynxx7VzbhkWtIG3ph+yio/rwESgXDu7l
5joyi1ESX+NmNT7usxaIo2+eYeLmGd8AdaaCB/Qrb40OCbf/EgyFUg8FV16y
ulpH3O7GxnP0eM66DXSRNtRQ5I8ymjt4797ooO5zoH9zV9AnrmEoX7igObxd
vnqBwjVcIFu54oD0b01ClSd+LFW+FIWmRdur26yuzloRFuEPZxPvBv7vm59S
fVtQHfU1XWG0gre1zwl9jJTrNNEt3UAD+823LBwQanX5r34EJX2MV2sx1hbE
5T0CyZ2mqAHdMxvTNTFB3VVcAeVXB+AhqU4XSzu/tmyibVWJ9l5auarotFJy
OMFV9uFFdcjrx9Sgdk0SnwslzKXjq4y+XR390rRkJv2AgWMQVolp9etCh6i8
YZV37Sw+L46mSzPd/5YNeDUTqpVQaA1V9Pj0e3er75VQq3F63WtPpDLQWMGY
YxDJRb4IXpOXWw9IaPvzTtjL6ryuzB1caEk8pu5NXvlBLXR7lZftLSSC2ejK
vcULx7+otlt2Iq66yG5j4zwtUHTU9+11Dk+3UyNy+LIVLAMjKYDGKfu5tBMD
7VWanO4KxOjWiO5X/3mAjpWmWCN/1cl0evQioMtnpwfDKKYzHvI29qUCY7U+
1bfSNGok2iGJmGAQkH9PyDKN+Kxz3uRwlBDsRDUOENgb+Rhm0UoTq5GL56l7
p3XdbL6Yl52X14jN95WWrVZQu9zBFPnZddcl5MNe+5e0eV2JaDUi+Ay3Ax1E
tpfbBNRtalOcKuScsmCYuy67MBA4Gw0vkrJS97qwvJg88uoCaqdG1bO4Uwfe
Y5aqskK5JrpaqJtMfknjVQtzLRCkHRfA4WsoV6dEHA8OeLjss9E7jZNBbpDq
cyKe0kq7VqcoKj0v2zW9rKSWLnKkUR2KwCFBdU76YFTKqJ151uiYZadCqlmd
6Khdkq0yqGzSyAGhO7X+g47HZo0CMhIdvQ+3URBHJXRjIBt/UIlA+3ZT2epk
zktNhahNDvbF4VpeYdl63tys0WY90z2lvn4a5ytbQmokqK/iX41udb5C7Vtr
+wwgEZUg0I0GVntxjXYy7Up05IAuwNQyoRRUUOBzuxOEVbRsMBgrTahGK/Xo
isTBXRy1Yy5GszoWaNOgP18QmS71L/zSw7lZo7J6hCLVglq3cLITCqa6YpFs
KFctq1whea50S4JU8i6uYHYmWqOjriRGW9+H3EqXnHKd0elmdZ7H3IJDAkxU
NLs4N4XQdEtm0dxvR2kfFml3tCKQkT33Gi0hRltbPAcqorSTKbUdc+v6ZGKo
CJlR98iVPtImyeA05V2JXWs0y5nby0EL4Up/DM/0GqD+2ygFUxWbrW/IvUDu
iSYo9X5wRWCpZdgCSVijgWx5UMpESdpCWwRWFwlLJpVbY1QXcVjtI8HNHA5E
CrelKUQba//nS7qSeBikH5U7PTgRhhoddbKwnl8HUqWKXvE/yD8GV1gV9VZk
iUuLFjDQweLyIQk1c/LZ7jzO03HWUaO0znR0m4KTfl1KWlrqKtmBxf8jyQpj
5JaDr9zWOagWKK50KrZq1Nm1XbxDqSg5rxwWYFR8LE3l2KumrJrATvm456Jq
n7wJL5CIfDJ04FPlfOrCq2VXWmWdZ1e6Mk6DvkzhTeUWORcEtsp1cUAv9+q5
EnlqSoIW82LtrVv6NizlKyw5cg5NatS3VVukKq8s8Q0DxyFh6dzbsnxtelu3
ktkuuWDwfKt7dW0dU/2dcqvxcY3KD1TUsnxbId5g+VTF75K3Pn8OgpYul8Jw
la9CS9cUotNTIswO4kVwGPyuFFXWd2OhHWay7Spkai7ehR88JIRdsKoxEAEg
HXfViQA5RAH3mtC0Qs9MKZu9SpDaRLPstrp3KaVqDO4JL3HnltRs7XAHnwxc
ZTQ29k16X7fLMI0lY4qkOzxTdx8w3+kld1HFquW47pnP18HronoVtdVVA9gX
kpqE8+2LidVBRRtIYZYpJGkZZ/XxYy6lRcS9Jl1DDZbPS4WcIIuxyQbnXpE2
ctlb7ZyAtkluZTlNJ3p9NZqShU5UCawqcMZAMk4Ik6VD4leokUPv+PWhoc5J
ITdeqbrUW4JW2NdwqYwT5aUuVZkT3uwMpL7IEpjV+zS7d5JLlFV4JndumYIl
FqU5g6Hh/Etj1QjklDQA8TY7mzt+Z8/f3FJFLSaxyuknzhhjOBi7qmSTuPCP
MrBhcsoUw3B6iF1+EUdJFWSV8Qpo6TCmWaFiYR0+7lT+GMfTL6q7MmOogis8
60gbr+3lc5S0fO6/S9PxbDRKRsBq2Z8nD97mTme71d150dn1HkAkIFd99+bN
2dvT05NThJ7KgcUiGUIvsGnCg12EU5CcOua5NhVbjmnt5ZNwmt+lBE0T84M7
q2D2MveuuKMSuGOHmJIMUQnIf1BrkvZbDs0c4NGjvwKniRSDqYs7sJK4G1Tw
+3+9bXq//9dB4K397rfbrU1pFzZ1p/lW377Xg9PPMPNDLFLGwIJIfnj7BSqv
cNS+jIEfZ3G718+px6CoKwRPykeBwXJMJI/lca8DRroGGQ+hq8+9b7wOzfF3
v+12Wpuffvh7+NfWOnb8d2Z6fTf2dlpbaw/rylEyJgbYp/44BSMLUxCEChl6
Z4eXGiUm3xmrxC9SUXIwZeJYZDVPIUttSPaAm8JYYq3cb0iivFoYoK1L6RLf
uTGR49EiFiUtVrmbVHq66SMZwDJabO5os3kSJ6RQeCu5pfAYLJwxZb6xCRCl
xxZTB54GKUUlbGgOCjlDdiukZINCrAWotD7xl0yblTDZNaRWlE2z6Iz1qHsl
GCInk0Fr6fE55N72fjgEgZhQSAQRM2GGVzoOConCJdk4BgeGIErZADgSJShu
hABTKSbGqADTa6OllPsX7u2nH/5hoQi5yMLx//7Nv//b34bemiVDNjtb3U2Q
IessRC4ue2e9895yEXI9n3KzRNiNXoHHnkQidhvj+0DWBGrCEoV0LddGvju+
PHl9cnzUZsMH/nh7zp/1Xp0eH1g5NCrvU/vPGj5TLRIMjJrCmScTiUbRhGAW
vc1e++zwggt84w8FlvxIDTbPyEc3SLU8+CqKa9Q+Xub465gRQiaFYt9pSYxh
VZ0aeFvLs6kgleiqIQs3UTBJRn14I5SHt5Is04d3sQ4h6uhqc80Ce61Od2/P
YoHD097J2eXx4fHJxfVyPuBMlq6sHlD0i/VEpBIcVAANDL4vKCG+GVBdKa3o
NCb0+xjvJ8YifP1LKx2Pgnez1W16x79qeV26VFJD7+kaB+7qmTvgUtHVCoXW
NjQzM2viPRq4tplCXKNaGxTWJaSoUSwAuLcWnNwcIuTk5OYY/oVaq7veFB6Q
i54cRJpYW7hCioaLKfi7376gB6kbEWbxyLDiOIT27ii3TmBJkhlgC2bJB402
fANm6rXJWnKOx5SKkXRG/oX1Zcgj8M4tUlq6LblYc3wBNOjRuV1hmOt5tNUI
VsZB3iOs+nUniS7VkEwVlWEOSLoy0hvtKOsCrX6G0Rlreb5Mrq2aRvulIaRR
wYGG5w2s5eMkJykqJ7RPQamTapuADZ8+0swxIiOFlBRQcI5SVBYBVqWgff6l
cZ2u/3cdtyZpQxrr5Pzwzfnh6durk3fH+nbMJ469vvxSjNZyCYkdbvK5EtLR
8tMSomOxGDmxXKOjEuABL/GgqfWkl8FaEKGh7T+G0T0M7Yf4LVUw+oxA80uY
Cb/TCUQOve8dfXdyfgWfIFgSr140xoYx2JeIpyOxWMcxIl+SfOzbbl0ZrGHB
gjlNRnPVVXkIlvOOjq/9TXM07HMulW4Y+dX9mMgrI9UDVKZLr3Q5HPuqamhs
zI91OvxbOM0H7BqQLODer57bgBfnZ4OLwzHmcsFHKJIpdwRRSDNzl1Wz2gkD
L+a1LrtCw6puHSAdck4A0z07alk5dxAEX5sR4twmU4QV3wxaaoWAhQYTW6iS
gCdZDv5fakibqqgzbpPc35M5R0u6bAgs3EpESGdcsBNMGULE7X6c35GnXBA+
6CttAOEzDI/paiYqV2/CI/fY9oOqyOQYqVqcTG51r4GiuvUNzGLzZbbFctni
9L1s0mVfJLp8DlNERqZIdwy+pZrDMeUr7Okeb5g3yEk/L+Yju7mwvp6y3FuG
GyIZiP6vZhTmL5ZXptKq3rPo+Inki3jDNZN6pvmZgsiOMIJpl6MuOWeLxRxq
gMBuudXaCAhey46Y9zocY7tjJeDus3CW/9ppnOtT8MHvbCqB9t1l7+3VL+CD
r5Rn+hozIEebkpxx0db+Iov1n7+/0uBkZZbDTqPNMrDc9oBa85lwXayLB9Pi
JsZDy/fD01LyAyIxlZZHEarbkksIPxilbOBZ23hgtQqtPq+u6qRa7ZnZdomr
Ok3PxNzADkTUMsd0GDeXUYKkj7Big9vqEazMt6Qhnzbw08v2I69QFTPDlCal
xdGisggbh7lFRhjbQcWLCEvVlBurIOR2tlkWu3IH1TwJNemOz02y/zBeiCmF
sg6lRqxYTQnU7bHUCk531uYqhJKcsVKkhAr+TFlTNVwcIUORXpI0bLrSBvRT
eIVoE8mHWXtYRuxWQhOwRVTTX6OHLIciJ6EEcqXe0NONAqRxgOkKqxmVCoZN
2b4ly1Q+p82ZGilwYHXJnO0rg00OsD1uiNCjwd0i4cRYSdvQ8g7DKWhD8JFY
Go2TO//TD/8TRM06Cp6zk2/9Xu+QJc8SAcMDZxaAGZlYh9Kx6rqPlRfzr2JW
mbI1MtPFpJaqaPFFQRuQcr1ZkY4pCnNJwTtaFKUWl6yUsxU6KOitveudnhy1
T87531e965Mr9sbbJ2cXb66uTvDP68ve+dUpfPfm/KZ39urkZ2/fvL1a/9po
XHGXZJGPMf+5b0Wt1DZYcG48MYt4YgauG8trGBuEYRMXR3oOjAu6QWHKkdGS
b7yESHiNcUYtMyg3FOqSC2+cRvEox5uN8bTrmCUfJBjmK0lSqMW3VWUQLzSX
1MdDPAnFyCI5oKPjGFtXUWst9TjS8e312SnWYmEO2OhdBdyjmC4GdHd1Kocv
z8auNaA/b+/VKxhFSZbTnIxkYx/lQWl07KbFt28DIRBCLLLUC17G2/3d7svB
i+GgG25v7ey+HHajcC/ce/Fiby8abvW3ut2os7MdeGvyiEYmewEbC9t+d/O6
+3K/u7ff2f5FAB59cHncOzo7bhUf6Gp4jMXeqLBn+3jcjyOk5ZU0wAGvoW1C
tmv9Udr3gs7ezrC7Hb14uTPc7e51ot1O9+VWd7fT2Qy3+uFm1N3ahTWF/UCC
Fqu8pIcZ7R4awO67Xm693Nvb2tsbdrvbuxH8u7PTHwx2ut0XOzvdlzv94eZO
tLvb3wvWOSkj9dQq9WMlCaRoNTdZBb8f0iUVKgPRxB9TJJED8yZjZ7IB2pJs
ed+COnjArHSxKMQttVTB9Ebi2TfI2zdwTqRKsWkHuiWMyViHlaLdGPfLKQmY
yLpi9XWuai1h1dSsCCahUxXAjYHUn1FcR9tF6qoXOxSvwulCCrNQg1eg4LqC
A0hcW5o1DZ2gPLDfKLyPGZpgoO2lFqczbup5ToLCqOXELriycm6UWTPBIZrt
JOVYTTGXa60WuvRNbeuzc0FlrJZho4QLlYZSXIilY9hkRJZjFyuR1Fxgdxsd
v9hGbtaZx01Ru9oybaraOSy85zsqbHNNe8bi7uQtua9lLDfp0fxi3dFC7bXp
q8qcsdQukzs8FxmCJP/Z9WzqyJPq6rqKYWiVdvfnkqBBPLsKSYWCEzRQZF8H
WmrmZN31yvdc1LR1ynwLLyP9bCinXO3BiycA72iyblYmBrRcYTWoIGOq4TVu
2F71jPVeOr4lIUAoM+73ssJ7JfFq788QpYlaujZV/lMw/D2T12k6cUnQAF8Q
eyPmW8Wn1c0in/QaLGap+A5uQoQD7sqIsXiEaLkwECp8WxsONe2HF7sLf8I2
1SXDOuAUgrrZBzMEs3G+kzlDUWSwrcR1cjdUwIklU6EyxCxHlsQPseqjodhp
QY7sQN07O0kXsji1DbbiPu3VEkoKjTJJS6kiv5QW4vXRLHAKKuKvUwBuUsO+
ksCaZa66DdjutV22uVIkHCSCEwe3kTVz7pfwZCbM/8xwtbW91ejpFwZHuZEl
+7IUc9AXNCHbKK1j3ugbFCw2ohpgOLesyLSqsZUf3Yul0z3mGNngJNP4ApuU
cBBC65NU2VE1MVUXRM/hyXiU9OkGHb5EfUEIdFGIU59pYczVjjXrGH0XkeYg
w/m06asF74Tb9Ybo1JtcxcQ6mrhgWahNGwY1RgOJy+UmgQ5TucKQY/OG6ydu
eGfV4BJJYIVH5a7xNtUpKruI4OjoqOvgVOxVgS7gzQ9UOs7ujeo/LIGUjQ0N
mpuALS52lmWCAOWlMwBdZZFZGDEEvDAuCqZzDy7hk6wR559jrqxooEirbeyM
wGIbjZSmNkxsW6HORDHmR01bR42EVoK1uVq4rmkGlNPkY6uvGuPD4X2nn4m5
gEDdxW7H1a0WjSZXVdfbEbbNBOY5LYadVWNunc5AsisBkv3BcX5NEwJEUJ/V
SaqM75NyZ+vh3ZYFRi83t8+5bzKJeoJsGjwRV1IIRE5CK7lq2Fpym3LBaIL7
hy2EZGkl/9VbO55hwr39Kh7dZmGE/TV5JIqOkcqRM0KX6HCnON+rQAEDgwV8
6AZlJGDTBEIwBHJAvUxgzJ8lxbezPkl84E4Ei7LM/7zwhH3ZZSn8oH1liRSU
wwAoWWzb1V4MgZJkMQaRVFoKDuAavGYIAbXIECVES804X2IqV3LU1rhHIexc
FlI1AL6jSRtq8jx4vQL2lUEffzYtfdel+/+Or187w5xcXNpSf3d7b69p3blh
nga7A9QbbMhsQnhVSn9O5Wrmt62rFjfXQQZGVMt0qiGtwdurnRft7ovdXdha
jkKoF2TcIBCb1IHynhCGk9tShiqxxgIEk2pW/EHwVhobaa2A8ykSYvBG8S3Z
QaoeF0UuQjHM5ix3R0r5taV7YciixcImvujy9aGHF4e4d4jsU3QQhA4cshb8
a6fp7Ta9PYQi4R7utbboJg655YLLvm6zdDbN6+/tyN2LSVXTPTeHTdrngGrY
uLxI2azchDTXuVh9x4sua9E3EJoKAHSvCZlIclOsEeksVGqQdMFWLPVC4u4i
JOOUrjDAfdC1YDnCZv/ut0ALFRuSDBrPu9KInCIaKgE8qjQkx5G2zEjcHQ+t
WXuoxRvlvU5ucdlb2hylK0eoso5EEG1NiFdQwGAglwRyVSy+8mjVy4344tfr
K0/dEMZBDOmBTeWIdN7j8IERZmzQIJn0duVtKTu37vOT64JVtTqXnAsQH7W6
MchM1znythiIVqppZCqAITOk21VjvCGp4euGHBaUEyPlLM6rbcuYlPoWmnEU
LLogZ987lh4fbc397Qur5H9OV0Yq92Q2ilX+FRHPs7FV9V/qjGbdXrGoCVwe
zq1KgFqRmozxCGLtLqnbff5Fd3O3ZEd4YDCmw6FE3rtdEDHe5tb+9p739hph
gBrv65opHOqsBEGl2I3KaEzmwo6eNinfMk1G3M0QBJ741YpUDv7M1GkrG49M
nETKxNq4qYKW0dnUKdsmvoL8myYoIA/EfLOsEX0kTQ90kSEYoNb2D3e6FDNS
bBc2KQ7M5gB/0u1GQ4714X7/R0LHaROOP3B/QSQ5VTur1toh9RhIJaRdhPk9
wy0ncy4NKdoGwM1eCQ7NoCW0dI9UbzUu457Xm7oBmgv7ZaYy5bISTscDXS2f
0n2GJCaOJlG347/rdLuk51CBU0AExSMZwccZ/Dkbe8edLmpRbhBDKLI+eCwo
d4BMovGvbg4DVa5S7v0HbDEwgAzKiYGgErlduVNQjmaTs+IDVe6E18knmbKU
5RYPEOl01IYZWSpUH86lZxP9A9Y+HBmVpSNmxkLK1NLa93pk83+RRUeibRVr
Q6MmVf2O6XMJ2inmCjyB+alsBXrHTsGZU4ZR8m1tP9XX0Q3GZPnSY8bxGW0P
scYhdK5VUzTSWDrsqy7pFZVTxcnFUzJW4M3JNCxUMJzqcsm9MiNxpdqC8mPR
43i3iymDU6LMuJayMWYyZvj6a+4W3fvARDjbwoTu2dY2tdFM5HWcHgidOyaa
T9zo8HU3OcD2pI67KWJcgx2Z3CvWswZ2cSMS6EzMcjHWhLWcqkGyhgQjhw1v
3X5+zZoSSUkDPF3TiQDHOrmh+RW5KWWZS2VflHc5451hHwh72aIo7Q1Qw4/i
6JaUXf3p7p34iOrJ2TFPR7myo41vTlG0LMmR0K6IVQXnjMmhFgHWhoSm/laq
KVscpJDLTfgzFR1UslZ8JOqqiCylArW5aaSr2trarTj5lHKjD77+m4EVlNEs
cmOiY0Yky1K8P/3/AvCyd9mh6AAA

-->

</rfc>

