Capability-Bounded Composition
Feasible, then permitted, then best — over a floor that composition cannot weaken.
- Standing
- WITNESSED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
- Last checked
- 2026-09-11 15:26:16 UTC
- Source
AmpersandBoxDesign/box-and-box/test/laws.mjs@e41e5fab63c1· bytes51ffdf3aa3658f18…- Limit
- Cell 16 (deny by default) is proved at the impl tier, which makes the floor real. It does not establish that any composition in this tree grants only what it needs — the cell is the floor, not the pattern.
- Next rung
external— external — the deny-by-default floor (cell 16) checked by someone who did not write it. The suite runs live here and that is this tree checking its own kernel.
Why this page says WITNESSED — the derivation, not the word
- ✓ a witness is named
- ✓ its evidence kind is one the ledger already uses (constructive_witness)
- ✓ the witness path resolves in this tree
- ✓ its rung is in_tree or above (live_deployed)
- ✓ a run is recorded for these exact bytes
- ✓ no claim is cited that could be REFUTED
- ✓ a counterexample is shipped (required once WITNESSED)
- ✓ it has run from the deployed site — 109 laws · 109 passing · 0 failing · 336.4 ms
WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.
Intent
An action may be possible and still not allowed. The governance kernel separates the two as rungs: the alethic rung says what can happen, the deontic rung says what may, and only then does the axiological gradient rank what is best. Deny is the default, grants are explicit and scoped, and composing two governed things never widens what either could do alone.
Technical register
box-and-box, the [&] governance kernel: eight rungs, one bridge running feasible ▸ permitted ▸ best over an un-weakenable safety floor, a certificate on every verdict. 109 enforced kernel laws property-tested at 2000 trials (the suite derives its own total). Cell 16 (⊥ deny default) is proved at the impl tier. Carrier Confinement is the same rule at the OS boundary.
Problem
Ambient authority: a component needs one capability and is handed the environment. Unix permissions, process-wide credentials, an agent with the operator's whole token. Every composition then inherits everything, and the question 'may this proceed?' has no place to be asked.
Solution
Model authority as a distinct rung with its own laws, not a flag on an action. Make deny the identity for the permission operator. Compose by meet on the floor and by the declared operator above it. Attach a certificate to every verdict so a receiver can check the chain rather than the answer.
Real-world analogy
A theatre with a locked stage door. Being able to climb the wall (feasible) is not a ticket (permitted), and the best seat in the house (best) is only a question once you are inside.
Structure — on the surface
An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.
The chapter in WRL — and the chain so far
Chapter 9 of 32 — the fragment _patterns/wrl/chain/capability-bounded-composition.wrl, sealed alone by wrl.js
; CAPABILITY-BOUNDED COMPOSITION — cb_fixed is feasible to write to and NOT permitted (no `configurable`):
; the claim at epoch 1 is Rejected(not_configurable). cb_in fans out to the spinner and to the gate (a Door).
[relay:cb_in]{sig_in, sig_out}
[spinner:cb_fixed](w=16, n=8, rotor=quarter_turn_z){sig_in, socket}
[orb:cb_view]{pose}
[door:cb_gate]{sig_in}
[cb_in] --sig--> {[cb_fixed], [cb_gate]}
[cb_fixed] --socket--> [cb_view]Its test bench _patterns/wrl/chain/capability-bounded-composition.bench.wrl — drives the entry for this chapter's own film; never part of the chain
; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:cb_bench](every 1){sig_out}
[cb_bench] --sig--> [cb_in]module + bench seal to → sem-42e37b3bdb01acf9aaa5fc16967cdc2a37930ceae8fac945eaa8eba41987df39
Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-0e46e77c463806b6954… (the run inputs' own identity, computed by the forge)
| epoch | writer · seq | op | target | rotor | label |
|---|---|---|---|---|---|
| 1 | w1 s1 | SetRotor | cb_fixed | 255.0.0.0 | SetRotor cb_fixed 255.0.0.0 |
Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (34.172s).
Receipts in the last epoch's Film
receipt:w=1,s=1,accepted=c1,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
The Film, epoch by epoch (6)
epoch 1 · sha256:5c7ed970c806dd5351b901e61a1a37a963cb3dcdafdaf2a6976d4251aa88ba50
FILM v0.7 t=1 spinner:cb_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=cb_view,config=fixed orb:cb_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=cb_fixed,fault=0 pulser:cb_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:cb_gate:open=0,next_open=0 relay:cb_in:cur_out=0,next_out=1 wire:w__cb_bench__cb_in:cur=1,nxt=1 wire:w__cb_in__cb_fixed:cur=0,nxt=0 wire:w__cb_in__cb_gate:cur=0,nxt=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=c1,pkey=0.0.255.0.0.0,payload=SetRotor:cb_fixed:255.0.0.0 receipt:w=1,s=1,accepted=c1,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous
epoch 2 · sha256:e4c8eba26d63a76d0f870722a6ad1fcf1f6a7b5257cd75c422e10f1e34043325
FILM v0.7 t=2 spinner:cb_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=cb_view,config=fixed orb:cb_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=cb_fixed,fault=0 pulser:cb_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:cb_gate:open=0,next_open=0 relay:cb_in:cur_out=1,next_out=1 wire:w__cb_bench__cb_in:cur=1,nxt=1 wire:w__cb_in__cb_fixed:cur=0,nxt=1 wire:w__cb_in__cb_gate:cur=0,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=c1,pkey=0.0.255.0.0.0,payload=SetRotor:cb_fixed:255.0.0.0 receipt:w=1,s=1,accepted=c1,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous
epoch 3 · sha256:f484490f2509b231657fd65f95d60e6131623147d20afcd89c662d6b5eb60ebb
FILM v0.7 t=3 spinner:cb_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=cb_view,config=fixed orb:cb_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00b5,0000,0000,00b5,controller=cb_fixed,fault=0 pulser:cb_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:cb_gate:open=0,next_open=1 relay:cb_in:cur_out=1,next_out=1 wire:w__cb_bench__cb_in:cur=1,nxt=1 wire:w__cb_in__cb_fixed:cur=1,nxt=1 wire:w__cb_in__cb_gate:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=c1,pkey=0.0.255.0.0.0,payload=SetRotor:cb_fixed:255.0.0.0 receipt:w=1,s=1,accepted=c1,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous
epoch 4 · sha256:97317efcf0f6b029c92151e80901f861b6483b0b33e00edce90e3ae3877db1fc
FILM v0.7 t=4 spinner:cb_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=cb_view,config=fixed orb:cb_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,0000,00ff,controller=cb_fixed,fault=0 pulser:cb_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:cb_gate:open=1,next_open=1 relay:cb_in:cur_out=1,next_out=1 wire:w__cb_bench__cb_in:cur=1,nxt=1 wire:w__cb_in__cb_fixed:cur=1,nxt=1 wire:w__cb_in__cb_gate:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=c1,pkey=0.0.255.0.0.0,payload=SetRotor:cb_fixed:255.0.0.0 receipt:w=1,s=1,accepted=c1,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous
epoch 5 · sha256:088f6c76c64197c09d8fafa56b08add831b93e888ad16eebaa5b3437811311f3
FILM v0.7 t=5 spinner:cb_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=cb_view,config=fixed orb:cb_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff4c,0000,0000,00b4,controller=cb_fixed,fault=0 pulser:cb_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:cb_gate:open=1,next_open=1 relay:cb_in:cur_out=1,next_out=1 wire:w__cb_bench__cb_in:cur=1,nxt=1 wire:w__cb_in__cb_fixed:cur=1,nxt=1 wire:w__cb_in__cb_gate:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=c1,pkey=0.0.255.0.0.0,payload=SetRotor:cb_fixed:255.0.0.0 receipt:w=1,s=1,accepted=c1,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous
epoch 6 · sha256:04ac7564b7c36109233bbf3e7919b2f50efed4a3778a7de8f8e6d8b9c9dbaf08
FILM v0.7 t=6 spinner:cb_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=cb_view,config=fixed orb:cb_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff02,0000,0000,0000,controller=cb_fixed,fault=0 pulser:cb_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:cb_gate:open=1,next_open=1 relay:cb_in:cur_out=1,next_out=1 wire:w__cb_bench__cb_in:cur=1,nxt=1 wire:w__cb_in__cb_fixed:cur=1,nxt=1 wire:w__cb_in__cb_gate:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=c1,pkey=0.0.255.0.0.0,payload=SetRotor:cb_fixed:255.0.0.0 receipt:w=1,s=1,accepted=c1,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous
A refused world beside it _patterns/wrl/capability-bounded-composition.refused.wrl
profile forge.world.core.v1
; a signal driven straight into a pose port: feasible to type, not permitted by the port table
[pulser:action](every 1){sig_out}
[orb:world]{pose}
[action] --sig--> [world]✗ WRL_ILLEGAL_PORT_PAIR — world (Orb) has no in-port sig_in for a SignalWire
Composes with the 8 chapters before it
The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-f6fa4a47152461120b620ee0915a337f529b627c48cd82cc8a0c0eb8e02dc778: 28 objects, 27 edges (was 24 / 23; every earlier object and edge is still present — checked, or the build refuses).
Links only the chain carries
[rj_r] --sig--> [cb_in]
How to read this board
Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.
| shape | is | and so |
|---|---|---|
| a clock; the only source of signal | Every signal on the board starts at one of these. Nothing else can make one. | |
| a pass-through, so signal can travel | One arrives, any number leave — a relay that fans out is the board's router. | |
| a sink; signal arrives and stops | It latches what reached it and passes nothing on. A door is where a path ends. | |
| rotation: takes signal, drives a pose | The only object on the board that holds a value a claim can rewrite — and only if its config says configurable. | |
| the thing that gets moved | It is driven, never driving: an orb is what you watch to see whether anything happened. | |
| not a WRL role — the book's own drawing of the receipts in the epoch's Film | It counts what the run admitted, and turns red on a Rejected outcome. | |
| SignalWire | signal: a sig_out to a sig_in | Legal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves. |
| SocketControl | control: a socket to a pose | Legal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal. |
Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.
The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.
Syntax — quoted from the tree at build time
The bridge, in the kernel's own words (box-and-box README) opensentience.org/box-and-box/README.md:33
> *decides* `feasible ▸ permitted ▸ best`. `box-and-box compile` is the bridge between the two.
L10 — a backward phase is refused; L14 — deny_default is idempotent under ∧ (from the suite this page runs) AmpersandBoxDesign/box-and-box/test/laws.mjs:96
['L10', 'chain refuses a backward phase', (n) => trial(n, () => { const a = randV(), b = randV();
if (a.pi == null || b.pi == null) return true;
const r = chain(a, b);
if (phaseIdx(a.pi) > phaseIdx(b.pi)) return r.error ? true : 'should refuse';
Forces
Explicit grants are more to write and easier to forget, so the default matters: deny. The floor must survive composition, which means the compose laws have to be property-tested rather than trusted. And the gradient (best) must never be consulted before the floor (permitted), or optimization quietly becomes authorization.
Applicability
Agent runtimes, plugin systems, multi-tenant services, operating-system carriers, any place where 'can' has been standing in for 'may'.
Transformations
- narrowing a grant's scope
- composing two governed bricks (the floor is the meet)
- escalating an unmet obligation back to the deontic rung (ought-implies-can)
- widening authority by composition
- consulting the gradient before the floor
- granting the environment when one capability is needed (Ambient Authority)
A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.
Consequences
'May this proceed, and is it best?' becomes arithmetic with a certificate attached. The cost is the explicit grant, every time; the benefit is that the answer is checkable by someone who did not make it.
Failure mode it answers
Ambient Authority — Granting access to an environment because some part of it needs one capability. Paid for at: AGENCY.md §4 (the phrasing that walks into it); Miller 2003 is the term's source
Witness
Source identity: AmpersandBoxDesign/box-and-box/test/laws.mjs · shape suite · evidence kind constructive_witness · rung live_deployed (A live-run receipt: the staged kernel suite ran from https://opensentience.org/patterns/capability-bounded-composition and reported 109 laws · 109 passing · 0 failing, bound to staged stamp 51ffdf3aa3658f18. Recorded by _patterns/build/run-live.mjs; derived by build.mjs (P26).)
Execution identity: 2026-09-11T15:26:16.294Z on PX13 · bytes 51ffdf3aa3658f18… · repo HEAD e41e5fab63c1
It has already run from this site. On 2026-09-12 the staged bytes at stamp 51ffdf3aa3658f18 were executed by a browser at https://opensentience.org/patterns/capability-bounded-composition and reported 109 laws · 109 passing · 0 failing · 336.4 ms. That recorded run — not a word in the registry — is what puts this witness at rung live_deployed; restage the file and the stamp moves, the receipt stops matching, and the rung falls back (P26).
Staged byte-identical at opensentience.org/witness/src/AmpersandBoxDesign/box-and-box/test/laws.mjs (stamp 51ffdf3aa3658f18).
Counterexample
AmpersandBoxDesign/box-and-box/test/laws.mjs — law L10, marker chain refuses a backward phase
, expected REFUSED.
Scoped to its law, not resolved. The marker sits on L10's own declaration line, so it is that law's statement and not a string borrowed from a neighbour or lifted from its failure path (P28). What could not be done is resolve the id against the suite's own index: laws.mjs exports none, so the build cannot ask the suite whether L10 is enforced or declared-open. Between a bare string match and a resolved law.
The marker here was 'should refuse' until 2026-09-13. That is the string L10 RETURNS WHEN IT FAILS — a law's failure tag, cited as evidence that the law holds. It is the same defect v0.4 shipped on Refusing Join (CD2's failure string used as CD1's marker), and it survived undetected because this record carried no law id and so never reached the check that exists for it. The marker is now L10's own statement, on L10's own declaration line.
What to take away
- from the animationThe same action was refused without a grant and admitted with one; feasibility never moved.
- from the syntaxdeny_default is idempotent under ∧ — composition cannot manufacture permission.
- from the literatureObject-capability discipline; 'ambient authority' is Mark S. Miller's term (Capability Myths Demolished).
- from the witness109 kernel laws × 2000 trials ran on this page, on the same bytes CI runs.
Invariant basis — and how each piece bears
| basis | bears | status |
|---|---|---|
cell 16 | necessary | proved cells.json |
Satisfying a basis is local. Nothing here implies global adequacy unless a theorem or a composition rule says so.
Prior art — and what is not claimed
| work | relation | what it shares | where it differs |
|---|---|---|---|
| Dennis & Van Horn (1966) | antecedent | authority carried by an unforgeable reference | none claimed |
| Miller, Capability Myths Demolished (2003) — 'ambient authority' | terminology precedent | the term for authority available without being passed | the term is Miller's and is used here as he defined it |
| Object-capability discipline | antecedent | participation conveys only what was granted | applied here to composition of assemblies rather than to object references |
Novelty not claimed. This is object-capability discipline. No part of the principle is claimed as new; the contribution, if any, is that it is stated as a composition law with a deny-by-default cell (16) beneath it.
Realizations in the tree
- opensentience.org/box-and-box/README.md deontic rung
- opensentience.org/deontic-arithmetic.html
Relations with other patterns
Carrier Confinement STATED · Refusing Join WITNESSED↩ · State Does Not Grant Authority WITNESSED
A ↩ marks a relation named on the other page. Relations are symmetric here and the reverse is derived, so neither side can go missing by being written once.