{
  "tool_id": "art-502-bind-attested-subject",
  "tool_version": "1.0.0",
  "display_name": "Attested Artifact Subject Binder",
  "mcp_name": "bind_attested_subject",
  "mandate_type": "compliance_control",
  "wave": 77,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-502-bind-attested-subject.html",
  "description": "Computes the SPEC.md section 27.4 attested-artifact subject identifier for the sealed output of a pinned non-OCG producer: a spreadsheet, a reconciliation export, a report builder's PDF, anything with a content-addressed manifest but no kernel, no node and no chain. The identifier is sha256 over the JCS canonicalisation of exactly three members, tool_ref plus inputs_digest plus artifact, on the single canonical hash path; there is no fourth member and no wall clock, run identifier, host or session state enters it, so a verifier that never executed the producer recomputes the same value offline from the echoed preimage. tool_ref.manifest_digest is the chainless analogue of the section 17 kernel_digest and is what makes the producer tamper-evident rather than merely its output; its absence is reported, never assumed. Digest strings are hashed verbatim as declared and are never rewritten, so a malformed digest is named rather than silently normalised. Stated limit, normative: an attested-artifact subject carries no section 18 compute proof and no section 16 or 17 re-execution claim, it never evidences that the producer's arithmetic is correct, and the artifact omits replay_verified entirely rather than setting it false because no replay was attempted. This node identifies a subject so that separately signed section 27 approval records can name it; it signs nothing itself and asserts no regulator acceptance or filing sufficiency.",
  "input_schema_ref": "chaingraph/art-502-bind-attested-subject.html#manifest",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [
    {
      "system": "sha256-source",
      "image_id": "sha256:8680e25172057485acdc9fae8651fab076d8ebe76824abf35bf75b8f186568fa",
      "valid_from": "2026-07-10"
    },
    {
      "system": "risc0",
      "image_id": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
      "valid_from": "2026-07-31"
    }
  ],
  "compute_proof_ready": "ready",
  "export_capability": [
    "json"
  ],
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "FizhhKVxvsl4w9VEF1xREY7rKjR8SREF1l5f9Iv4EEoIisNH+w9ipYrpA+wN5T57y4PL+KRTML2OqOxCtFg7/xw27xY55vCsU0Wr9VIZ1YKnw+XMX5e18dwMHGFTbtPQG13P+70VRQgnoeQB/wCxVbx/IRXxaduwM/leQm7cC18idgaQYxecpv0zUvkIidvN1pct47kJ/kgTdLWVtWtisyJ6e6kPQtAZdkaxsEKz1deR5Q12ubcZ/4a7GXMwlCSPKepeY/uMv6hSjhXoVD9DRN6Mz+dCN0rAt2hcqhqsWkcrEpFa8e8qlCqY20wUhDXGuAq8/uZALBTE247KqBPL1w==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:8680e25172057485acdc9fae8651fab076d8ebe76824abf35bf75b8f186568fa",
      "output": {
        "binding_complete": true,
        "findings": [],
        "inputs_digest_source": "derived",
        "no_arithmetic_claim": "An attested-artifact subject carries no §18 compute proof and no §16/§17 re-execution claim. It evidences producer pinning, input binding and content integrity, never that the producer's arithmetic is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "note": "Computes the SPEC.md §27.4 attested-artifact subject identifier for the sealed output of a pinned non-OCG producer, on the one canonical hash path: sha256(JCS({tool_ref, inputs_digest, artifact})), three members exhaustively. Digest strings are hashed verbatim as declared and are never rewritten, so a malformed digest is reported rather than silently normalised. This tool identifies a subject so that separately signed §27 approval records can name it; it neither signs anything itself nor asserts that any filing requirement is met.",
        "preimage_member_count": 3,
        "producer_pinned": true,
        "rationale": [
          "The subject identifier is sha256 over the JCS canonicalisation of exactly three members: tool_ref, inputs_digest and artifact. No wall clock, no run identifier and no host or session state enters it, so a verifier that never executed the producer recomputes the same value offline from subject_preimage alone.",
          "The producer is pinned: tool_ref.manifest_digest is present and well formed, so a changed producer build yields a different subject identifier.",
          "inputs_digest was derived here from the supplied producer inputs through the one canonical JCS path.",
          "This is a subject-identification result only. It evidences producer pinning, input binding and content integrity. It does NOT evidence that the producer's arithmetic is correct, and it is not a claim that any regulator has accepted the artifact."
        ],
        "subject_hash": "sha256:a6b78068a516a9935b9d10d00d6ddc59dc8b70aa8ea203e9a3cde1eb32beaddb",
        "subject_preimage": {
          "artifact": {
            "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
            "content_type": "application/pdf"
          },
          "inputs_digest": "sha256:767474f741796be7a07d007c9bf60bcfcd5260a52f344c1fab11f01b8a8e56bd",
          "tool_ref": {
            "entry": "buildClientMoneyRecon",
            "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
            "tool_id": "acme-safeguarding-recon",
            "tool_version": "4.2.0"
          }
        }
      }
    }
  }
}
