SCHEMA-05 | space_id pattern rejects hyphenated authority labels its own prose permits | audit/embed | patch-correction | drafted-in-1.1 §11.6 — deferred from 1.0.1 by ADR-0002 | Draft — ratification required |
SPEC-09-emb | reference is optional, so a descriptor can make no testable conformance claim | audit/embed | patch-correction | fixed-in-1.0.1 E13; validator-rule VER404 | Closed |
MOD-02 | Implementation docstring restates the false pixel_hash survival claim | audit/core | patch-correction | fixed-in-1.0.1 E1; README/CLAUDE.md corrected in this branch; models.py Hashes docstring corrected in this branch — it now states E1's survival profile instead of "pixel does not [change]" | Closed |
REC-03 | raw[].sha256 covers re-framed bytes, not the segment as stored in the container | audit/core | patch-correction | fixed-in-1.0.1 E11; validator-rule VER1302 | Closed |
REC-08 | Emitted descriptor omits preprocessing content, reference, and architecture | audit/core | patch-correction | fixed-in-1.0.1 E13; validator-rule VER404/VER405 | Closed |
CPNP-07 | §4 step 3 defines only the success path of colour management | audit/core | patch-correction | fixed-in-1.0.1 E8 | Closed |
CPNP-02 | hdr_present decided by a raw substring scan of the whole file | audit/core | patch-correction | fixed-in-1.0.1 E5 (spec half); implementation documented — not patched | Closed |
REC-10 | Chain has neither chronology nor fidelity — every event shares one timestamp | audit/core | patch-correction | fixed-in-1.0.1 E16; validator-rule VER1201–VER1204 | Closed |
REC-09 | record_id is uuid5 over pixel_hash alone, colliding across distinct Records | audit/core | patch-correction | fixed-in-1.0.1 E16; fixed in this branch (D7.0 #4) | Closed |
REC-05 | One identifier serves both the iptc availability key and the iptc-iim segment | audit/core | patch-correction | fixed-in-1.0.1 E21 | Closed |
REC-06 | stripped_suspected, redacted, and availability_basis are never produced | audit/core | patch-correction | documented — not patched; validator-rule VER901 | Deferred |
MOD-04 | weights_sha256 optional in the internal type despite mandatory weight pinning | audit/core | patch-correction | documented — not patched; ADR-0007 defines the preimage | Deferred |
SPEC-01-core | image.width/height never defined as pre- or post-orientation | audit/core | patch-correction | fixed-in-1.0.1 E2 | Closed |
SPEC-03-core | raw[].segment permits other, but availability has no slot for it | audit/core | patch-correction | fixed-in-1.0.1 E21; drafted-in-1.1 §10.3 | Closed |
HASH-02 | Perceptual digest encoding, bit order, and parameters are unpinned | audit/core | patch-correction | fixed-in-1.0.1 E22; drafted-in-1.1 §2.4 registry | Closed |
CPNP-08 | Out-of-range and malformed Orientation values are undefined by the spec | audit/core | patch-correction | fixed-in-1.0.1 E6 | Closed |
WIRE-01 | hashes_only privacy mode withholds the thumbnail but not the embedding | audit/wire | patch-correction | drafted-in-1.1 §14.5 | Draft — ratification required |
WIRE-04 | No update path: createRecord collisions are treated as success | audit/wire | patch-correction | drafted-in-1.1 §14.6 | Draft — ratification required |
WIRE-05 | rkey truncates pixel_hash to 52 bits and any taken-rkey error counts as success | audit/wire | patch-correction | documented — not patched; drafted-in-1.1 §14.6 | Deferred |
WIRE-07 | No hash-bearing lexicon field carries a pattern or length constraint | audit/wire | patch-correction | drafted-in-1.1 §14.3 | Draft — ratification required |
WIRE-10 | Mapper supports one of three vector carriages and silently degrades for the others | audit/wire | patch-correction | drafted-in-1.1 §14.3; annex E24 | Draft — ratification required |
WIRE-11 | decode_vector hardcodes little-endian fp16 regardless of declared dtype | audit/wire | patch-correction | documented — not patched; annex E24 | Deferred |
WIRE-12 | Lexicon const on dtype/normalization is enforced by neither producer nor consumer | audit/wire | patch-correction | drafted-in-1.1 §14.3 | Draft — ratification required |
WIRE-13 | verVersion/cpnpVersion are defaulted, not propagated from the Record | audit/wire | patch-correction | drafted-in-1.1 §14.2; annex N6 | Draft — ratification required |
WIRE-16 | knownValues is an open set in Lexicon but is modelled as a closed enum | audit/wire | patch-correction | drafted-in-1.1 §14.3 | Draft — ratification required |
WIRE-18 | Wire image.format is unconstrained while the Record schema closes it | audit/wire | patch-correction | drafted-in-1.1 §14.3 | Draft — ratification required |
WIRE-19 | No size bound on the wire beyond the thumbnail blob | audit/wire | patch-correction | drafted-in-1.1 §7 limits + §14.3 | Draft — ratification required |
WIRE-24 | Consumer discards the producer's createdAt for the relay's observation time | audit/wire | patch-correction | documented — not patched; annex E16 | Deferred |
WIRE-25 | A wire record claims VER 1.0 conformance while carrying no Layer 2 content | audit/wire | patch-correction | drafted-in-1.1 §14.8 | Draft — ratification required |
WIRE-29 | Three fields are both required and defaulted, which is contradictory in Lexicon | audit/wire | patch-correction | drafted-in-1.1 §14.3 | Draft — ratification required |
WIRE-32 | Duplicate space_id resolves last-wins in the wire mapper | audit/wire | patch-correction | fixed-in-1.0.1 E18; validator-rule VER401; drafted-in-1.1 §11.4 | Closed |
SPEC-01 | The identity gradient claims pixel_hash survives metadata stripping — it does not | audit/spec | patch-correction | fixed-in-1.0.1 E1 | Closed |
SPEC-02 | §7.1's byte-exact preservation MUST defeats §7.5's redaction-with-proof | audit/spec | patch-correction | fixed-in-1.0.1 E15; validator-rule VER1005; ADR-0006 | Closed |
SPEC-03 | The conformance table marks contextual embeddings mandatory at L3; §8 calls them optional | audit/spec | patch-correction | fixed-in-1.0.1 E13 | Closed |
SPEC-04 | image.width/height undefined for Orientation 5–8 transposes | audit/spec | patch-correction | fixed-in-1.0.1 E2 | Closed |
SPEC-05 | Alpha compositing assumes an 8-bit domain but is ordered before the quantize step | audit/spec | patch-correction | fixed-in-1.0.1 E4 | Closed |
SPEC-06 | The HDR/gain-map step is ordered after decode and colour management | audit/spec | patch-correction | fixed-in-1.0.1 E5 | Closed |
SPEC-07 | §4 disclaims cross-CMM bit-exactness while §3/§12 present pixel_hash as stable identity | audit/spec | patch-correction | fixed-in-1.0.1 E1 | Closed |
SPEC-08 | CPNP-1 ignores gAMA/cHRM/sRGB chunks and EXIF ColorSpace without saying so | audit/spec | patch-correction | fixed-in-1.0.1 E9 | Closed |
SPEC-09 | No ruling on XMP tiff:Orientation versus EXIF tag 274 | audit/spec | patch-correction | fixed-in-1.0.1 E6 | Closed |
SPEC-10 | The animated-source rule lives in Scope and never reaches normative CPNP text | audit/spec | patch-correction | fixed-in-1.0.1 E7 | Closed |
SPEC-11 | The quantize step leaves operation order, value domain, and tie behaviour undefined | audit/spec | patch-correction | fixed-in-1.0.1 E3 | Closed |
SPEC-12 | The pixel_hash preimage does not specify integer serialization | audit/spec | patch-correction | fixed-in-1.0.1 E10 | Closed |
SPEC-13 | The preimage domain tag is VER1: and does not carry cpnp_version | audit/spec | patch-correction | fixed-in-1.0.1 E10 (limitation acknowledged); CPNP-2 must version the tag | Closed |
SPEC-14 | The signing payload is undefined and the signature sits inside what it signs | audit/spec | patch-correction | fixed-in-1.0.1 E17; validator-rule VER1401–VER1403 | Closed |
SPEC-15 | record_id and created_at have no normative definition anywhere | audit/spec | patch-correction | fixed-in-1.0.1 E16 | Closed |
SPEC-16 | The chain is called append-only with no mechanism making that checkable | audit/spec | patch-correction | fixed-in-1.0.1 E16; validator-rule VER1201–VER1204 | Closed |
SPEC-17 | Reconciliation precedence omits platform, which the conflict-source enum admits | audit/spec | patch-correction | fixed-in-1.0.1 E14 | Closed |
SPEC-18 | Four prose object literals list members the schema makes optional | audit/spec | patch-correction | fixed-in-1.0.1 E15/E16/E17 (per-object rulings); remainder documented | Closed |
SPEC-21 | "Full space descriptor" is mandatory at every level and defined nowhere | audit/spec | patch-correction | fixed-in-1.0.1 E13; validator-rule VER404 | Closed |
SPEC-23 | §8 puts a MUST on consumers to filter by a grade that no field carries | audit/spec | patch-correction | fixed-in-1.0.1 E19 | Closed |
SPEC-26 | No behaviour defined for a present-but-unusable ICC profile | audit/spec | patch-correction | fixed-in-1.0.1 E8 | Closed |
SPEC-27 | No field is designated the ecosystem dedup key, and asset identity is undefined | audit/spec | patch-correction | fixed-in-1.0.1 E27; App. D #7 | Closed |
SCH-01 | format is a non-assertive annotation in 2020-12, so date-time/uuid/uri go unchecked | audit/spec | patch-correction | fixed-in-1.0.1 E23; validator-rule VER202 | Closed |
SCH-02 | contentEncoding is likewise non-assertive, so base64 payloads go unchecked | audit/spec | patch-correction | fixed-in-1.0.1 E23; validator-rule VER202/VER1301 | Closed |
SCH-03 | pixel_hash's inert properties entries prove a forgotten additionalProperties: false | audit/spec | patch-correction | fixed-in-1.0.1 (schema delta 2) | Closed |
SCH-04 | Closure is applied inconsistently across sibling objects with no stated policy | audit/spec | patch-correction | fixed-in-1.0.1 (schema delta 3, content_hash); the other seven objects deferred past 1.0.x | Closed |
SCH-06 | embedding.space_id is unconstrained while the descriptor's carries a pattern | audit/spec | patch-correction | validator-rule VER403; drafted-in-1.1 §11.6 | Closed |
SCH-07 | No length constraint on perceptual digests despite §5's exact bit widths | audit/spec | patch-correction | fixed-in-1.0.1 (schema delta 1); validator-rule VER801/VER802 | Closed |
SCH-08 | Base64 and by-reference vectors are undecodable as specified | audit/spec | patch-correction | fixed-in-1.0.1 E24; validator-rule VER601–VER606 | Closed |
SCH-09 | The oneOf forbids carrying an inline vector and a vector_ref together | audit/spec | patch-correction | fixed-in-1.0.1 E24 (exclusivity is intentional) | Closed |
SCH-10 | The space_id pattern contradicts the word "semver" it implements | audit/spec | patch-correction | drafted-in-1.1 §11.6 — deferred from 1.0.1 by ADR-0002 | Draft — ratification required |
SCH-11 | preprocessing is a free-form object, so {} conforms | audit/spec | patch-correction | validator-rule VER405; drafted-in-1.1 | Closed |
SCH-12 | Availability is closed over five families; the raw-segment enum has six | audit/spec | patch-correction | fixed-in-1.0.1 E21; drafted-in-1.1 §10.3 | Closed |
SCH-14 | The §7.5 redaction literal is outright rejected by the redactions[] schema | audit/spec | patch-correction | fixed-in-1.0.1 E15; ADR-0006 decided (§10 REV-18); the 1.1 schema encodes the in-view shape (draft §5.2); validator-rule VER1001/VER1002 | Closed |
SCH-15 | Trust tiers live in a parallel array keyed by an opaque field string | audit/spec | patch-correction | fixed-in-1.0.1 E13/E15 reading; validator-rule VER305/VER1004 | Closed |
SCH-17 | availability.c2pa and provenance.c2pa.status can contradict undetected | audit/spec | patch-correction | fixed-in-1.0.1 E28; validator-rule VER1103 | Closed |
SCH-18 | Nothing requires source_bytes_ref.sha256 to equal identity.content_hash | audit/spec | patch-correction | fixed-in-1.0.1 E25; validator-rule VER1305 | Closed |
SCH-20 | tolerance_cosine admits 0.0001 — a conformance bar everything clears | audit/spec | patch-correction | documented — annex editorial note N5; drafted-in-1.1 §8.2 | Closed |
SCH-21 | conformance_level is optional, so a profile validator has nothing to validate against | audit/spec | patch-correction | validator-rule VER301 (absent ⇒ effective L0) | Closed |
EX-01 | The example's preserved ICC segment decodes to 30 bytes declaring a 3144-byte profile | audit/spec | patch-correction | fixed-in-1.0.1 example edit (b) — digest made self-consistent; truncation documented in E26 | Closed |
EX-02 | The example's @context does not define the dc: prefix it uses | audit/spec | patch-correction | fixed-in-1.0.1 example edit (c) | Closed |
EX-03 | The example asserts a description with no in-asset source | audit/spec | patch-correction | documented — annex E26 (illustrative artifact) | Closed |
EX-04 | The example's chain records one embed event for two embeddings | audit/spec | patch-correction | fixed-in-1.0.1 example edit (d) | Closed |
THESIS-01 | The repo's headline claim is falsified by its own passing test | audit/tests | patch-correction | fixed-in-1.0.1 E1; README/CLAUDE.md corrected in this branch | Closed |
SPEC-PIXHASH-TOL | pixel_hash is claimed as stable identity while ICC bit-exactness is disclaimed | audit/tests | patch-correction | fixed-in-1.0.1 E1/E12 (exact per profile, robust across profiles) | Closed |
SPEC-ORIENT-OOR | Out-of-range and malformed Orientation values are undefined | audit/tests | patch-correction | fixed-in-1.0.1 E6 | Closed |
SCHEMA-EMB-SPACEID-UNPATTERNED | embedding.space_id is unpatterned while the descriptor's is constrained | audit/tests | patch-correction | validator-rule VER403; drafted-in-1.1 §11.6 | Closed |
SCHEMA-PREPROC-EMPTY | preprocessing: {} conforms, voiding §6.1 and §6.2 | audit/tests | patch-correction | validator-rule VER405; drafted-in-1.1 | Closed |
IMPL-RECORD-ID-COLLIDES | record_id collides across distinct Records describing the same asset | audit/tests | patch-correction | fixed-in-1.0.1 E16; fixed in this branch (D7.0 #4) | Closed |
SCRIPT-FUSED-RECIPE-INPUTS | recipe.inputs has no defined referent | audit/tests | patch-correction | fixed-in-1.0.1 E20; validator-rule VER704 | Closed |
SCRIPT-DTYPE-ASSUMED | The migration reader hardcodes fp16 and the base64 carriage | audit/tests | patch-correction | documented — not patched; annex E24 | Deferred |