Open Agent Rules
Contents
  1. Run the corpus against your implementation
  2. The runner algorithm
  3. Fixtures (265)

Conformance

Run the corpus against your implementation#

Fetch the index, fetch each fixture it names, and run each one: load the fixture's rules against the host described by input.capability, apply the input, and compare against expected. An implementation claiming conformance passes every fixture whose declared capability set it can adopt, and reports the ones it skipped. A skipped fixture is not a passed fixture, and the 139 fixtures the manifest marks baseline may not be skipped at all — their declared capability is one nothing conforming lacks.

curl https://openagentrules.org/spec/1.0/conformance/manifest.json

The runner algorithm#

The requirements below define the evaluation algorithm end to end. Each step is separately identified so a conformance fixture can cite it.

Fixtures (265)#

FixtureCoversWhat it proves
cfg-ambiguous-bare-reference-rejectedOAR-CFG-8A bare reference matching more than one rule is rejected, naming them (baseline)
cfg-bare-reference-prefers-an-exact-qualified-matchOAR-CFG-8A bare reference names the unnamespaced rule exactly, even when a publisher ships the same id (baseline)
cfg-bare-reference-resolves-across-namespacesOAR-CFG-8, OAR-CFG-2An operator writes the bare id; it resolves against every loaded rule whatever its namespace (baseline)
cfg-cannot-alter-what-a-rule-meansOAR-CFG-6A configuration changes whether and how loudly a rule runs, never what it means (baseline)
cfg-disable-treats-a-rule-as-offOAR-CFG-1, OAR-CFG-2, OAR-CONF-7A rule an operator disables behaves exactly as though its enforcement were off (baseline)
cfg-enforcement-replaces-the-declared-valueOAR-CFG-3, OAR-CONF-7A configured enforcement replaces the rule's own (baseline)
cfg-forward-minor-config-rejectedOAR-CFG-1A configuration written against a later minor is rejected, exactly as a document with one is (baseline)
cfg-last-statement-about-a-rule-winsOAR-CFG-7Configuration documents apply in order, and the last statement about a rule wins (baseline)
cfg-mandatory-rule-cannot-be-disabledOAR-CFG-5, OAR-OPS-7A configuration disabling a mandatory rule is rejected, naming the rule (baseline)
cfg-mandatory-rule-cannot-be-downgradedOAR-CFG-5, OAR-OPS-7A configuration downgrading a mandatory rule to monitor is rejected (baseline)
cfg-qualified-reference-disambiguatesOAR-CFG-8, OAR-CFG-3The qualified form is required only when the bare one is actually ambiguous (baseline)
cfg-unknown-rule-reference-rejectedOAR-CFG-4, OAR-CONF-7A configuration naming a rule that is not loaded is rejected, naming it (baseline)
conf-core-anchor-fact-reports-the-core-spellingOAR-CONF-29, OAR-PROF-1, OAR-FACT-15The core fact anchor reports the core identifier however the host spells the moment locally (baseline)
conf-occurrence-anchor-is-host-localOAR-CONF-29, OAR-PROF-4input.anchor is the right-hand side of anchors.core; the core identifier on the left does not select (baseline)
conf-order-suppressor-precedes-only-the-rules-it-namesOAR-CONF-10, OAR-EVAL-18, OAR-EVAL-3A suppressor precedes only the rules it names; every other rule keeps its kind-then-identifier place
conf-rule-set-members-validate-individuallyOAR-CONF-1, OAR-DOC-31A rule set is not itself a schema-bearing document: each member is validated on its own terms (baseline)
conf-selector-on-anchor-uses-the-core-spellingOAR-CONF-29, OAR-SEL-7A selector clause on the core fact anchor matches the core identifier, not the host-local one (baseline)
copy-canonical-double-integralOAR-COPY-4, OAR-COPY-10copy canonical double integral
copy-canonical-double-negativeOAR-COPY-4, OAR-COPY-10copy canonical double negative
copy-canonical-double-negative-zeroOAR-COPY-4, OAR-COPY-10copy canonical double negative zero
copy-canonical-double-smallOAR-COPY-4, OAR-COPY-10copy canonical double small
copy-does-not-change-decisionOAR-COPY-6, OAR-DOC-24Rendered copy is presentation of the decision and does not change the effect or the winning rule
copy-empty-members-remain-presentOAR-COPY-1, OAR-COPY-7copy empty members remain present (baseline)
copy-if-else-and-notOAR-COPY-3, OAR-COPY-7Copy conditionals take the if branch on a non-zero fact, the else branch otherwise, and not inverts the test
copy-if-omits-zeroOAR-COPY-3, OAR-COPY-7, OAR-FACT-25A copy if-branch is omitted when the named fact is the zero value of its type
copy-illegal-construct-rejectedOAR-COPY-3A copy member carrying a construct the binding grammar does not derive is a load error (baseline)
copy-interpolates-factsOAR-COPY-1, OAR-COPY-4, OAR-COPY-7, OAR-COPY-8After the decision, copy bindings substitute declared facts; list<string> joins with comma-space; whitespace in tags is insignificant
copy-list-joinsOAR-COPY-4, OAR-COPY-7A list<string> binding interpolates as its members joined by comma-space
copy-map-type-rejectedOAR-COPY-4A copy binding whose fact type cannot be interpolated is a load error
copy-missing-endif-is-a-load-errorOAR-COPY-3copy missing endif is a load error (baseline)
copy-nonempty-map-list-takes-ifOAR-COPY-3copy nonempty map list takes if
copy-profile-fact-needs-requiresOAR-COPY-5, OAR-FACT-20A copy binding naming a non-core fact the rule does not reach through requires is a load error
copy-unknown-fact-rejectedOAR-COPY-2, OAR-FACT-3A copy binding naming a fact the engine does not declare is a load error, never a runtime default (baseline)
cs-content-length-threshold-is-in-the-ruleOAR-FACT-7, OAR-FACT-16The secrets profile publishes a length; the rule decides what is too long
cs-jailbreak-score-below-threshold-passesOAR-OPS-11, OAR-CONF-25A score below the rule's threshold does not fire; the detector never decided
doc-bare-id-is-the-qualified-identifierOAR-DOC-8, OAR-EVAL-8A rule with no namespace has the bare id as its qualified identifier — no separator, no host name (baseline)
doc-copy-does-not-affect-the-decisionOAR-DOC-24, OAR-EVAL-19Two rules differing only in copy produce the same effect, and copy never reorders them (baseline)
doc-copy-member-outside-the-closed-set-rejectedOAR-DOC-24copy carries a closed set of presentation strings (baseline)
doc-current-minor-loadsOAR-DOC-5Every minor less than or equal to the engine's own is accepted (baseline)
doc-detector-forbidden-for-other-kindsOAR-DOC-23A detector object on any other kind is rejected (baseline)
doc-detector-required-for-detector-kindOAR-DOC-23kind: detector without a detector object is rejected (baseline)
doc-duplicate-qualified-identifier-rejectedOAR-DOC-9Two rules with the same qualified identifier are a load-time rejection (baseline)
doc-empty-flow-rejectedOAR-DOC-15, OAR-CONF-1A flow that is present must be non-empty; the empty list is rejected rather than assigned a meaning (baseline)
doc-enforcement-defaults-to-enforceOAR-DOC-16A document with no enforcement enforces (baseline)
doc-forward-minor-rejectedOAR-DOC-5, OAR-CONF-2A minor greater than the engine's own is refused rather than partly honoured (baseline)
doc-malformed-id-rejectedOAR-DOC-6, OAR-CONF-1id must match the published pattern (baseline)
doc-mandatory-and-overrides-defaultOAR-DOC-17, OAR-DOC-20mandatory defaults to false and overrides to the empty list, so an ordinary rule is suppressible (baseline)
doc-minimal-rule-loads-and-firesOAR-DOC-1, OAR-DOC-2, OAR-DOC-11, OAR-EVAL-3, OAR-CONF-1A document with only the five obligatory fields loads and fires (baseline)
doc-missing-required-field-rejectedOAR-DOC-2, OAR-CONF-1, OAR-CONF-21A document without effect is rejected, naming the field (baseline)
doc-on-error-defaults-to-fail-closedOAR-DOC-18, OAR-OPS-3A rule that cannot be evaluated and declares no on_error blocks under its own identifiers (baseline)
doc-on-fire-defaults-to-emptyOAR-DOC-19, OAR-FACT-10A rule with no on_fire changes no counter, and its condition changes none either (baseline)
doc-qualified-identity-distinguishes-publishersOAR-DOC-8, OAR-EVAL-8, OAR-EVAL-9, OAR-EVAL-19Two documents sharing an id under different namespaces are distinct rules and both load (baseline)
doc-references-do-not-affect-the-decisionOAR-DOC-25Interoperability taxonomy tags never affect a decision (baseline)
doc-related-target-need-not-be-loadedOAR-DOC-30related records lineage, never affects a decision, and its target need not be loaded (baseline)
doc-rule-set-member-must-be-a-documentOAR-DOC-31A rule set containing a member that is not a rule document is rejected (baseline)
doc-rule-set-position-does-not-set-orderOAR-DOC-31, OAR-DOC-28, OAR-EVAL-1A member's position in the collection never affects identity, ordering, or precedence (baseline)
doc-status-does-not-affect-the-decisionOAR-DOC-29status records the author's confidence and is inert (baseline)
doc-transform-forbidden-for-other-effectsOAR-DOC-22A transform object on any other effect is rejected (baseline)
doc-transform-required-for-transform-effectOAR-DOC-22effect: transform without a transform object is rejected
doc-undefined-field-emit-rejectedOAR-DOC-27A field this specification does not define is rejected, naming it (baseline)
doc-undefined-severity-field-rejectedOAR-DOC-27severity was never a field of this format and is rejected (baseline)
doc-undefined-top-level-copy-fields-rejectedOAR-DOC-27The pre-release top-level copy fields are gone and are rejected by name (baseline)
doc-unknown-effect-rejectedOAR-DOC-11effect is a closed enumeration (baseline)
doc-unknown-kind-rejectedOAR-DOC-10kind is a closed enumeration (baseline)
doc-unsupported-major-rejectedOAR-DOC-4, OAR-CONF-2A major version this engine does not implement is refused, not coerced (baseline)
doc-version-checked-before-undefined-fieldOAR-CONF-2oar is checked before any other processing, so a bad version wins over a bad field (baseline)
doc-version-leading-zero-rejectedOAR-DOC-3, OAR-CONF-1A version part with a leading zero is not a version; two engines free to equate 01.0 and 1.0 would disagree about what loads (baseline)
doc-x-extension-is-ignoredOAR-DOC-26An x- extension the engine does not recognise is ignored, and never affects the decision (baseline)
eval-advisories-accumulate-in-evaluation-orderOAR-EVAL-8, OAR-EVAL-19, OAR-EVAL-20, OAR-COPY-7, OAR-COPY-9, OAR-CONF-37Two nudges at one occurrence both appear, in evaluation order, neither discarding the other (baseline)
eval-advisories-omit-a-monitor-ruleOAR-EVAL-20, OAR-EVAL-10A monitor nudge is recorded and does not appear on advisories (baseline)
eval-advisories-omit-a-suppressed-ruleOAR-EVAL-20, OAR-EVAL-14A suppressed nudge does not appear on advisories (baseline)
eval-advisories-warns-accumulateOAR-EVAL-20, OAR-COPY-9, OAR-CONF-37Two warnings at one occurrence both appear, in evaluation order (baseline)
eval-allow-contributes-no-decisionOAR-EVAL-7A rule firing with allow records an explicit pass and never overrides another rule (baseline)
eval-block-short-circuitsOAR-EVAL-4, OAR-CONF-13, OAR-OPS-10The first enforced rule firing with block stops the occurrence; later rules are not evaluated (baseline)
eval-decision-carries-both-identifiersOAR-EVAL-8, OAR-EVAL-9A decision carries the effect, the bare id, and the qualified identifier (baseline)
eval-flow-is-tested-before-whenOAR-EVAL-3when is not evaluated when flow did not match, so a rule the flow excluded cannot raise
eval-flow-matched-then-when-is-evaluatedOAR-EVAL-3When flow does match, when is evaluated and may raise
eval-kind-does-not-decideOAR-EVAL-2, OAR-EVAL-6kind carries no meaning beyond order: a later-ordered rule's effect still wins on precedence (baseline)
eval-mandatory-rule-cannot-be-overriddenOAR-EVAL-17, OAR-OPS-7An overrides entry naming a mandatory rule is a load-time rejection (baseline)
eval-monitor-does-not-short-circuit-or-suppressOAR-EVAL-10, OAR-CONF-11A monitored rule neither short-circuits the occurrence nor suppresses the rule it overrides (baseline)
eval-monitor-records-without-actingOAR-EVAL-10, OAR-OPS-1, OAR-CONF-11, OAR-FIRE-2A monitored rule is evaluated and recorded, contributes no decision and applies no side-effect (baseline)
eval-monitor-rule-that-raises-does-not-blockOAR-EVAL-10, OAR-OPS-1A monitor rule that cannot be evaluated is recorded errored and its on_error is not applied (baseline)
eval-no-rule-fires-is-noneOAR-EVAL-6An occurrence at which nothing fires resolves to none (baseline)
eval-off-is-not-selected-or-recordedOAR-EVAL-11, OAR-OPS-2A rule whose enforcement is off is not selected, not evaluated, and not in the trace (baseline)
eval-off-still-loads-and-reports-load-errorsOAR-EVAL-11, OAR-OPS-2A rule whose enforcement is off remains loaded, so a load-time error in it is still reported (baseline)
eval-order-is-kind-then-qualified-idOAR-EVAL-1, OAR-CONF-10, OAR-OPS-10Evaluation runs schema, policy, invariant, detector, then ascending by qualified identifier (baseline)
eval-overrides-cycle-rejectedOAR-EVAL-16, OAR-CONF-6A suppression cycle is a load-time rejection, naming the rules in it (baseline)
eval-overrides-unresolvable-reference-rejectedOAR-EVAL-13, OAR-CONF-6An overrides entry that resolves to no loaded rule is a load-time rejection, naming it (baseline)
eval-precedence-nudge-over-warnOAR-EVAL-6, OAR-EVAL-20, OAR-CONF-14nudge outranks warn whatever order the two fire in (baseline)
eval-precedence-transform-over-nudge-and-warnOAR-EVAL-6, OAR-EVAL-20, OAR-CONF-14transform outranks nudge, and nudge outranks warn
eval-side-effects-of-losing-rule-still-applyOAR-EVAL-12, OAR-CONF-15on_fire applies to every rule that fired and was enforced, including one whose effect lost precedence (baseline)
eval-side-effects-of-unreached-rule-do-not-applyOAR-EVAL-12A rule never reached because of a short-circuit applies no side-effect (baseline)
eval-suppression-does-not-transitOAR-EVAL-15If A overrides B and B overrides C, A firing suppresses B but not C (baseline)
eval-suppression-withdraws-side-effects-tooOAR-EVAL-14, OAR-CONF-12, OAR-EVAL-12A suppressed rule contributes no decision and applies no side-effect (baseline)
eval-suppressor-is-evaluated-firstOAR-EVAL-18, OAR-EVAL-1A suppressor is evaluated before the rule it names, even when the base order puts the block first (baseline)
eval-suppressor-ordering-disturbs-base-order-leastOAR-EVAL-18Only the constrained pair moves; every other rule keeps its kind-and-identifier place (baseline)
eval-transform-does-not-short-circuitOAR-EVAL-5, OAR-CONF-13A rule firing with transform lets later rules run
expr-additional-builtin-rejectedOAR-EXPR-16A function the engine does not declare is an unknown identifier, not a built-in
expr-aggregate-equality-rejectedOAR-EXPR-21Equality over two aggregate values is rejected at load rather than implemented element-wise
expr-arithmetic-operand-pair-rejectedOAR-EXPR-9An arithmetic operand pair outside the typed set is refused at load (baseline)
expr-chained-relation-rejectedOAR-EXPR-1, OAR-EXPR-4A relation admits at most one relational operator, whatever the precedence table suggests (baseline)
expr-comment-rejectedOAR-EXPR-6A comment is not part of the language (baseline)
expr-division-by-zero-raisesOAR-EXPR-14, OAR-OPS-3, OAR-OPS-4Division by zero raises, and the rule is handled per its on_error (baseline)
expr-dotted-identifier-is-a-single-nameOAR-EXPR-1, OAR-FACT-3, OAR-EXPR-19A dotted identifier is one host-tier name, so tool_args.path is an unknown identifier rather than field selection
expr-double-division-by-zero-raisesOAR-EXPR-14, OAR-OPS-3Division by a double zero raises rather than producing an IEEE infinity, and fail_closed then blocks with the rule's identifiers (baseline)
expr-double-literal-overflow-rejectedOAR-EXPR-21A double literal whose nearest binary64 value is not finite is rejected at load (baseline)
expr-double-overflow-raisesOAR-EXPR-14expr double overflow raises (baseline)
expr-empty-affix-matches-every-stringOAR-EXPR-22An empty prefix, suffix, or substring matches every string
expr-empty-list-literal-rejectedOAR-EXPR-21The empty list literal is rejected because its type cannot be inferred
expr-field-selection-rejectedOAR-EXPR-1There is no field-selection operator: a "." after anything but a name is rejected, naming the construct and its offset
expr-fifth-builtin-rejectedOAR-EXPR-16, OAR-EXPR-23A built-in this specification does not define is an unknown identifier
expr-index-operand-pair-rejectedOAR-EXPR-13An index operand pair outside the typed set is refused at load
expr-index-out-of-range-raisesOAR-EXPR-13, OAR-OPS-3Indexing a list out of range raises, and the rule is handled per its on_error
expr-index-typed-list-of-mapsOAR-EXPR-13list<map> indexed by int yields map, which supports in and size only
expr-int-double-comparison-promotesOAR-EXPR-11, OAR-FACT-23One int and one double compare after promotion, and only for the comparison
expr-int-overflow-raisesOAR-EXPR-15, OAR-FACT-23Integer arithmetic that overflows 64 bits raises rather than wrapping (baseline)
expr-integer-division-truncates-toward-zeroOAR-EXPR-21Integer division truncates toward zero, and the remainder takes the sign of the dividend (baseline)
expr-least-int-value-is-writableOAR-EXPR-21, OAR-FACT-23The magnitude 9223372036854775808 is admitted as the immediate operand of unary minus (baseline)
expr-list-literal-members-must-agreeOAR-EXPR-21A list literal takes the type of its members, which must all agree
expr-list-of-ints-has-no-declarable-typeOAR-EXPR-21, OAR-FACT-22A list literal of agreeing members is still rejected when no list type of that member exists (baseline)
expr-literal-newline-in-string-rejectedOAR-EXPR-1expr literal newline in string rejected (baseline)
expr-map-literal-rejectedOAR-EXPR-1A map literal is outside the grammar (baseline)
expr-map-string-string-is-a-map-for-in-and-sizeOAR-EXPR-21, OAR-EXPR-12, OAR-EXPR-13A map<string,string> host fact answers in and size(), and indexes to a string
expr-map-supports-in-and-sizeOAR-EXPR-19in tests key presence on a map and size counts its members
expr-minimum-integer-unary-node-countOAR-EXPR-17, OAR-EXPR-20expr minimum integer unary node count (baseline)
expr-modulo-by-zero-raisesOAR-EXPR-14Modulo by zero raises (baseline)
expr-modulo-takes-two-intsOAR-EXPR-9% takes two int operands (baseline)
expr-negative-list-index-raisesOAR-EXPR-21, OAR-EXPR-13A negative list index raises, as an out-of-range one does
expr-null-is-an-unknown-identifierOAR-EXPR-7There is no null value: null is rejected as an unknown identifier
expr-oversized-integer-literal-rejectedOAR-EXPR-21, OAR-EXPR-15An integer literal that does not fit 64 bits is rejected at load (baseline)
expr-parse-tree-above-the-declared-limit-rejectedOAR-EXPR-17, OAR-EXPR-20A parse tree above the engine's declared ceiling is refused, and the ceiling is in the capability document (baseline)
expr-parse-tree-of-256-nodes-acceptedOAR-EXPR-17, OAR-EXPR-20An engine accepts a condition whose parse tree holds 256 nodes, the published floor (baseline)
expr-precedence-table-does-not-extend-the-grammarOAR-EXPR-4a < b < c is not derivable, so it is rejected rather than grouped by the precedence table (baseline)
expr-reserved-word-is-lexed-greedilyOAR-EXPR-24A name beginning with a reserved word is one identifier, not two tokens
expr-short-circuit-avoids-a-raiseOAR-EXPR-5A false left operand of && stops the right one from raising (baseline)
expr-short-circuit-guards-a-partial-subexpressionOAR-EXPR-5The right operand is not evaluated when the left decides the result, so the guard holds
expr-single-quoted-words-are-not-referencesOAR-EXPR-1, OAR-FACT-20expr single quoted words are not references (baseline)
expr-size-is-the-only-builtinOAR-EXPR-16size counts Unicode code points on a string, and no other built-in exists
expr-string-builtins-do-not-fold-caseOAR-EXPR-22The string built-ins compare by code point and never fold case
expr-string-builtins-matchOAR-EXPR-16The three string built-ins match a prefix, a suffix, and a substring
expr-string-concatenation-acceptedOAR-EXPR-9+ concatenates two strings
expr-string-escapes-acceptedOAR-EXPR-3The closed escape set is accepted, including a four-digit \u escape
expr-ternary-branches-must-share-a-typeOAR-EXPR-8The ternary condition is bool and its branches share a type
expr-type-confused-comparison-rejectedOAR-EXPR-11A comparison between unrelated types is refused at load rather than silently never firing
expr-typed-accessor-reaches-a-map-memberOAR-EXPR-19, OAR-FACT-9A declared observation function reaches a map member with a type known at load
expr-unary-binds-tighter-than-multiplicationOAR-EXPR-4The precedence table governs how the grammar groups what it does derive (baseline)
expr-unparameterised-map-cannot-be-indexedOAR-EXPR-19A fact of the unparameterised type map may not be indexed; it supports only in and size
expr-unsupported-escape-rejectedOAR-EXPR-3An escape outside the closed set is rejected
fact-condition-outside-requires-rejectedOAR-FACT-20, OAR-CONF-4A condition reaching a profile fact the rule did not declare in requires is refused
fact-condition-type-error-rejectedOAR-FACT-4, OAR-CONF-5A condition that is not type-correct against the declared environment is refused at load
fact-content-provenance-distinguishes-untrusted-tool-dataOAR-FACT-16The content-provenance profile exposes host-attributed segment authority and trust without inspecting content text
fact-copy-runtime-type-error-uses-on-errorOAR-FACT-26, OAR-COPY-5, OAR-COPY-11fact copy runtime type error uses on error
fact-core-tier-needs-no-requiresOAR-FACT-15Every conforming engine provides the core facts, so a rule over them needs no requires at all (baseline)
fact-detector-facts-are-assembled-lazilyOAR-FACT-11, OAR-CONF-9A detector is not run for a rule the selector did not select, so detector://error never fails
fact-detector-observations-are-rule-localOAR-FACT-11A detector finding produced for one rule is not visible to a later rule
fact-detector-reports-observations-rule-owns-thresholdOAR-FACT-5, OAR-FACT-7, OAR-FACT-8, OAR-OPS-11, OAR-CONF-25The detector reports spans and scores; the rule sets the threshold, and two rules may disagree
fact-flow-longer-than-window-rejectedOAR-FACT-13, OAR-PROF-3A flow longer than the host's declared activity window is refused at load
fact-flow-matches-a-non-contiguous-subsequenceOAR-FACT-12flow matches when its steps appear in order in the activity window, contiguous or not
fact-flow-out-of-order-does-not-matchOAR-FACT-12The steps must appear in the order flow gives them
fact-flow-rejected-when-window-is-zeroOAR-PROF-3, OAR-FACT-13A host that tracks no recent activity declares zero and rejects every rule carrying flow (baseline)
fact-host-fact-must-be-namespacedOAR-FACT-14, OAR-FACT-18, OAR-FACT-24A host-tier fact published under a bare name belongs to no tier and is refused
fact-host-fact-must-sit-under-the-host-namespaceOAR-FACT-18, OAR-FACT-24A host-tier fact under a namespace the host does not own is refused
fact-host-fact-zero-at-unreported-occurrenceOAR-FACT-25fact host fact zero at unreported occurrence
fact-host-tier-fact-loads-and-firesOAR-FACT-18, OAR-FACT-21, OAR-CONF-23A rule reaching a host-tier fact through requires.facts loads and fires; the capability document says so
fact-moderation-rule-owns-the-thresholdOAR-FACT-16The classifier reports a score per category and the rule sets the bar
fact-name-of-an-unclaimed-profile-is-not-declaredOAR-FACT-17, OAR-FACT-19, OAR-CONF-20A host that does not claim a profile declares none of its names, so a rule reaching for one is refused (baseline)
fact-non-boolean-condition-rejectedOAR-FACT-4A rejection for a non-boolean result names the type produced and the word bool
fact-observation-function-supplied-by-fixtureOAR-FACT-9, OAR-CONF-26A value supplied under an observation function's name is that function's result for every argument
fact-profile-is-provided-wholeOAR-FACT-16A host claiming a profile provides every member of it, not a convenient subset
fact-requires-facts-reaches-one-nameOAR-FACT-20requires.facts reaches an individual name without claiming the whole profile
fact-requires-unprovided-profile-rejectedOAR-FACT-19, OAR-CONF-4, OAR-CONF-20A rule naming a profile the host does not provide is refused at load, naming both (baseline)
fact-root-must-be-booleanOAR-FACT-4fact root must be boolean (baseline)
fact-runtime-type-error-uses-on-errorOAR-FACT-26fact runtime type error uses on error
fact-tool-fingerprint-canonical-argumentsOAR-FACT-28, OAR-CONF-40fact tool fingerprint canonical arguments
fact-transform-target-is-assembledOAR-FACT-11, OAR-CONF-9A transform target is a fact reference, so it is assembled even when the rule has no when
fact-transform-target-needs-requiresOAR-FACT-20fact transform target needs requires
fact-undeclarable-type-rejectedOAR-FACT-22, OAR-FACT-24A capability document declaring a fact type outside the published set is refused
fact-unknown-identifier-rejectedOAR-FACT-3, OAR-FACT-1, OAR-CONF-5A condition naming something that is not a declared fact or function is refused at load (baseline)
fact-unreported-fact-does-not-take-the-on-error-pathOAR-FACT-25, OAR-OPS-3An unreported fact is not a provider failure, so a fail_closed rule over one does not block
fact-unreported-fact-takes-its-zero-valueOAR-FACT-25, OAR-CONF-9A declared fact the host has nothing to report for reads as the zero value of its type, never a failure
fact-unreported-observation-function-takes-its-zero-valueOAR-FACT-25, OAR-CONF-26An observation function the fixture did not supply returns the zero value of its declared return type
fact-window-is-ordered-oldest-firstOAR-FACT-12The activity window reads oldest step first, so flow reads in the order the steps happened
fact-window-newest-first-would-not-matchOAR-FACT-12The same steps in the opposite order do not match, which is what fixes the window's direction
fire-actions-apply-in-declaration-and-evaluation-orderOAR-FIRE-8The actions of one rule apply in the order listed, and rules apply in evaluation order (baseline)
fire-actions-bind-to-their-core-factsOAR-FIRE-3, OAR-CONF-15increment_counter writes fire_count and increment_breaker writes breaker_count (baseline)
fire-count-counts-increments-not-firingsOAR-FIRE-3, OAR-FIRE-4, OAR-EVAL-19fire_count counts applications of increment_counter, so a rule that fires with no on_fire has zero (baseline)
fire-count-of-escalates-across-occurrencesOAR-FIRE-11, OAR-CONF-31One rule counts and two read the count, so warn-then-block is expressible (baseline)
fire-count-of-non-literal-argument-rejectedOAR-FIRE-11A counter read whose argument is not a string literal is refused at load
fire-count-of-unresolvable-reference-rejectedOAR-FIRE-11A counter read naming no loaded rule is refused at load (baseline)
fire-counter-scope-keys-the-counterOAR-FIRE-10, OAR-FIRE-5, OAR-CONF-33A scoped counter counts each distinct scope value separately
fire-counter-scope-non-string-fact-rejectedOAR-FIRE-10A counter scope naming a fact that is not a string is refused at load
fire-counter-scope-undeclared-profile-fact-rejectedOAR-FIRE-10A counter scope naming a profile fact the rule does not require is refused at load
fire-counter-scope-unknown-fact-rejectedOAR-FIRE-10A counter scope naming a fact the engine does not declare is refused at load (baseline)
fire-counter-scope-with-an-empty-value-stays-scopedOAR-FIRE-10, OAR-CONF-33A rule declaring counter_scope keeps a scoped counter even when the scope value is empty
fire-counters-are-keyed-by-qualified-identifierOAR-FIRE-5Two rules sharing a bare id under different namespaces keep separate counters (baseline)
fire-every-condition-sees-the-same-counter-snapshotOAR-FIRE-6A rule's own increment cannot change the value its own condition just read (baseline)
fire-indirect-scope-requires-declarationOAR-FIRE-11Counter readers declare the target scope dependency
fire-own-count-reads-previous-occurrenceOAR-FIRE-3, OAR-FIRE-6fire own count reads previous occurrence (baseline)
fire-publish-event-writes-no-factOAR-FIRE-3, OAR-FIRE-7publish_event emits a record and is not observable to any condition (baseline)
fire-reset-sets-the-counter-to-zeroOAR-FIRE-3reset_counter and reset_breaker set their bound fact to zero (baseline)
fire-scope-needs-declared-capabilityOAR-FIRE-10, OAR-FACT-20fire scope needs declared capability
fire-unknown-side-effect-rejectedOAR-FIRE-1on_fire draws from a closed vocabulary (baseline)
mcp-bridged-call-factsOAR-FACT-16, OAR-FACT-2The mcp profile's facts and its _for accessors are distinct names and both work
mcp-error-code-is-a-machine-codeOAR-SEL-8A failed bridged call reports a machine error code, never free text, and the rule matches it exactly
mcp-result-projection-accessorsOAR-FACT-9The mcp projection accessors carry declared return types, so a condition over them checks at load
ops-annotate-then-redact-same-spanOAR-OPS-21, OAR-OPS-16Annotating and then redacting the same span yields the redaction followed by the annotation, not the redaction alone
ops-annotation-inside-covering-rewriteOAR-OPS-16, OAR-OPS-21, OAR-OPS-23, OAR-CONF-39ops annotation inside covering rewrite
ops-bare-substitute-prefers-own-namespaceOAR-DOC-8, OAR-OPS-5ops bare substitute prefers own namespace (baseline)
ops-block-discards-accumulated-transformsOAR-OPS-17, OAR-EVAL-6A block at an occurrence discards every accumulated transform: nothing is delivered to mutate
ops-content-anchor-evaluation-is-bufferedOAR-OPS-8A content anchor is evaluated once, over the fully assembled content
ops-detector-produced-facts-reach-the-transformOAR-CONF-25, OAR-FACT-11, OAR-OPS-15A span fact the detector produced at run time is the one the transform rewrites; content comes back changed, not merely reported changed
ops-detector-transform-facts-are-rule-localOAR-FACT-11, OAR-OPS-15Each accumulated transform uses the detector facts assembled for its own rule
ops-error-short-circuit-retains-suppressedOAR-OPS-10ops error short circuit retains suppressed (baseline)
ops-fail-closed-blocks-and-stopsOAR-OPS-3, OAR-OPS-9, OAR-CONF-9, OAR-CONF-25A rule that cannot be evaluated with on_error fail_closed blocks and stops the occurrence (baseline)
ops-fail-open-records-and-continuesOAR-OPS-4A rule that cannot be evaluated with on_error fail_open contributes nothing and evaluation continues (baseline)
ops-load-errors-are-not-routed-through-on-errorOAR-OPS-3, OAR-CONF-5An unknown identifier is a load-time rejection even when on_error says fail_open (baseline)
ops-monitor-outcome-says-which-way-it-wentOAR-OPS-9, OAR-EVAL-10Monitor mode records whether the rule would have fired, which is the only question it exists to answer (baseline)
ops-on-error-bare-reference-stays-in-namespaceOAR-OPS-5A bare on_error reference does not resolve to the same id in another namespace (baseline)
ops-on-error-naming-an-unloaded-rule-rejectedOAR-OPS-5, OAR-CONF-6An on_error naming a rule that is not loaded is a load-time rejection (baseline)
ops-on-error-substitute-not-selected-at-its-anchorOAR-OPS-5The substituted rule need not be selected at this anchor: substitution is a reference into the loaded set, not a second evaluation
ops-on-error-substitutes-another-rules-identifiersOAR-OPS-5on_error naming a rule blocks under that rule's identifiers, and the effect is still block (baseline)
ops-overlapping-transforms-are-not-mergedOAR-OPS-16, OAR-EVAL-19Two transforms whose targets overlap apply in order rather than being merged or reordered
ops-redact-then-annotate-same-spanOAR-OPS-21, OAR-OPS-16Redacting a span and then annotating it yields both, in that order: a zero-width annotation overlaps nothing
ops-skipped-span-recordOAR-OPS-23, OAR-CONF-39ops skipped span record
ops-suppressed-rule-is-traced-through-a-short-circuitOAR-OPS-10, OAR-EVAL-14, OAR-EVAL-18A rule suppressed by a blocking suppressor is recorded suppressed, not omitted as never considered (baseline)
ops-trace-records-every-outcomeOAR-OPS-9, OAR-OPS-10, OAR-CONF-16The trace records fired, passed, errored, monitored, and suppressed, in evaluation order (baseline)
ops-transform-annotate-content-appends-at-the-endOAR-OPS-21annotate on a content target inserts at the end of the content
ops-transform-annotate-inserts-after-the-spanOAR-OPS-21annotate inserts its replacement immediately after the span end and removes nothing
ops-transform-annotate-records-a-zero-width-rewriteOAR-OPS-21, OAR-OPS-16An annotate does not consume the span it annotated, so a later transform over it still applies
ops-transform-annotate-requires-replacementOAR-OPS-13annotate must carry a replacement: an annotation with nothing to annotate with is not a transform
ops-transform-block-discards-the-mutationOAR-OPS-17A block at the occurrence leaves the content untouched
ops-transform-offsets-are-original-coordinatesOAR-OPS-16, OAR-OPS-20A later transform’s offsets are read against the original content, not the earlier output
ops-transform-overlapping-spans-mergeOAR-OPS-20Two overlapping spans in one transform are rewritten once, as a single covering span
ops-transform-redact-may-omit-replacementOAR-OPS-13redact may omit its replacement, and the engine substitutes its own placeholder
ops-transform-redact-with-replacement-is-replaceOAR-OPS-21redact carrying a replacement and replace carrying the same one produce the same rewrite
ops-transform-redact-without-replacement-uses-the-fixed-placeholderOAR-OPS-13, OAR-OPS-21redact with no replacement substitutes exactly the code points [REDACTED]
ops-transform-rejected-when-unimplementedOAR-OPS-18An engine that does not implement content mutation refuses the rule rather than degrading it (baseline)
ops-transform-replace-requires-replacementOAR-OPS-13replace must carry a replacement
ops-transform-span-out-of-range-is-ignoredOAR-OPS-19A span whose range falls outside the content is ignored rather than raising
ops-transform-span-over-an-earlier-rewrite-is-skippedOAR-OPS-16, OAR-OPS-20A span overlapping a range an earlier transform rewrote is not applied, and is not clamped
ops-transform-span-without-start-and-end-rejectedOAR-OPS-19A span carrying neither start nor end cannot be applied
ops-transform-spans-apply-highest-start-firstOAR-OPS-20, OAR-OPS-19, OAR-CONF-34Two spans in one transform are applied from the highest start, so the earlier offsets still land
ops-transform-target-must-be-content-or-a-list-map-factOAR-OPS-14A target naming anything else is a load-time rejection
ops-transform-whole-content-targetOAR-OPS-14, OAR-CONF-34A transform naming the whole content replaces all of it
ops-transforms-accumulate-in-evaluation-orderOAR-OPS-15, OAR-OPS-16, OAR-EVAL-5, OAR-EVAL-8Two transforms at one occurrence both apply, in evaluation order, neither discarding the other
ops-unresolvable-detector-reference-rejectedOAR-OPS-12A kind: detector rule whose reference the engine cannot resolve is refused at load (baseline)
prof-anchor-map-declaring-one-twice-rejectedOAR-PROF-2, OAR-FACT-24A core anchor declared both supported and unsupported is a rejection (baseline)
prof-anchor-map-omitting-a-core-anchor-rejectedOAR-PROF-2, OAR-FACT-24Every core anchor appears exactly once across core and unsupported (baseline)
prof-core-anchor-maps-to-a-local-nameOAR-PROF-1, OAR-CONF-3, OAR-CONF-29A rule names the core anchor; the occurrence names the local one the host mapped it to (baseline)
prof-history-records-admitted-tool-namesOAR-PROF-9, OAR-CONF-40prof history records admitted tool names
prof-host-native-anchor-loadsOAR-PROF-5, OAR-PROF-8, OAR-CONF-3A host-native anchor is a valid document and loads; it is simply not portable, which is not a load failure (baseline)
prof-secrets-claim-requires-a-detectorOAR-OPS-22, OAR-FACT-24A capability document claiming secrets with no registered detector is invalid: zero-valued scores are not the observation
prof-uncatalogued-anchor-rejectedOAR-PROF-5, OAR-DOC-12, OAR-CONF-3An anchor that is neither core nor in the declared host catalogue is a load error, naming the value: a misspelled anchor must not silently never run (baseline)
prof-unsupported-core-anchor-rejectedOAR-PROF-4, OAR-DOC-12, OAR-CONF-3, OAR-CONF-20A rule targeting a core anchor the host declares unsupported is refused, naming the anchor (baseline)
sel-anchor-clause-is-coreOAR-SEL-7, OAR-FACT-15The core fact anchor may be named by a clause without any requires (baseline)
sel-capability-host-string-is-selectableOAR-SEL-3, OAR-FACT-27sel capability host string is selectable
sel-clause-matches-by-membershipOAR-SEL-7, OAR-CONF-8A selector clause matches when the fact it names is a member of the clause list
sel-clause-naming-untyped-fact-rejectedOAR-SEL-3A clause naming a fact that is neither string nor list<string> is a load error
sel-clause-not-matching-deselectsOAR-SEL-7, OAR-CONF-8, OAR-OPS-9A rule whose clause does not match is not selected and does not appear in the trace
sel-clause-outside-core-needs-requiresOAR-FACT-20, OAR-CONF-4A selector clause naming a profile fact the rule does not declare in requires is rejected
sel-clauses-are-conjunctiveOAR-SEL-7Every clause present must match for the rule to be selected
sel-empty-clause-loads-and-never-selectsOAR-SEL-6A clause whose value is the empty list matches nothing; the rule still loads
sel-list-fact-matches-on-intersectionOAR-SEL-7A clause naming a list<string> fact matches on a non-empty intersection
sel-matches-typed-facts-not-proseOAR-SEL-8A clause matches a fact value exactly; it is never a substring or keyword search
sel-unknown-fact-clause-rejectedOAR-SEL-3, OAR-FACT-1A clause naming a fact the engine does not declare is a load error, never a silent match (baseline)