{"audit_request":{"assertions":[{"assertion_id":"A001","condition":"unconditional","line_end":55,"line_start":55,"modality":"observed","object":"contract_packet: 1","predicate":"has_schema","quote":"- **패킷 스키마**: `contract_packet: 1`","scope":"branch contract packet","source_surface":"SURF-ACE388ED0C228D5A6570","subject":"branch contract packet"},{"assertion_id":"A002","condition":"branch 완료 조건 (Work Item done)","line_end":56,"line_start":56,"modality":"must","object":"error·observability 6-field contract와 contract test 통과","predicate":"requires","quote":"- **완료 조건**: error·observability 6필드 contract와 contract test가 통과한다","scope":"branch completion","source_surface":"SURF-ACE388ED0C228D5A6570","subject":"operational-error-observability-foundation branch"},{"assertion_id":"A003","condition":"inherited project decision DEC-CA-SKELETON-OPERATIONAL-CONTRACT-ERROR-ENVELOPE-001@1","line_end":63,"line_start":63,"modality":"must","object":"envelope schema와 error.category enum (단일 owner)","predicate":"owns","quote":"| `DEC-CA-SKELETON-OPERATIONAL-CONTRACT-ERROR-ENVELOPE-001@1` | foundation이 envelope schema와 error.category enum의 단일 owner다 | Work Item 완료 조건에 적용 | [[raw/project-notes/ca-skeleton-operational-contract]] |","scope":"envelope schema, error.category enum","source_surface":"SURF-ACE388ED0C228D5A6570","subject":"foundation"},{"assertion_id":"A004","condition":"D1 결정","line_end":197,"line_start":197,"modality":"must_not","object":"ProblemDetail 사용 (자체 envelope 응답 사용)","predicate":"forbids","quote":"| D1 | `ProblemDetail` 사용 거부, 자체 envelope 응답 사용 | `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C1`, `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C2`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C1`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C3` | `official-standard` (RFC 7807 의 `application/problem+json` + `type` MUST 식별자 — ca-tmpl 의 success/error 대칭 + retryable 1급 필드와 구조적 충돌) + `official-vendor-doc` (Spring ProblemDetail 의 RFC 9457 representation) | RFC 7807/9457 거부의 trade-off: 표준 lock-in 회피 vs 표준 호환성 손실. RFC 7807 `extensions` 메커니즘 (`RFC7807-C3`) 으로 retryable/category 표현 가능했음 |","scope":"API error response format","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"본 branch (foundation)"},{"assertion_id":"A005","condition":"D6 결정","line_end":202,"line_start":202,"modality":"must","object":"error envelope schema, error.category enum, requestId/traceId/correlationId 의미, MDC/log key 표준 (SSOT owner)","predicate":"owns","quote":"| D6 | 본 branch 가 error envelope schema, `error.category` enum, requestId/traceId/correlationId 의미, MDC/log key 표준의 SSOT owner | UNSUPPORTED_DECISION (SSOT ownership 분할은 내부 운영 정책) | N/A | branch ownership 분할은 외부 표준 인용 대상 아님. 부모 §25 SSOT Owner Map 과 정합 |","scope":"envelope schema, error.category enum, ID semantics, MDC/log key standard","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"본 branch (foundation)"},{"assertion_id":"A006","condition":"D10 결정","line_end":206,"line_start":206,"modality":"must","object":"10개 (VALIDATION/AUTH/AUTHZ/NOT_FOUND/CONFLICT/RATE_LIMIT/TRANSIENT_DEPENDENCY/PERMANENT_DEPENDENCY/DATA_INTEGRITY/INTERNAL)","predicate":"has_cardinality","quote":"| D10 | `error.category` enum 10개 (VALIDATION/AUTH/AUTHZ/NOT_FOUND/CONFLICT/RATE_LIMIT/TRANSIENT_DEPENDENCY/PERMANENT_DEPENDENCY/DATA_INTEGRITY/INTERNAL) | `raw/official-docs/google-api-error-format.md#GOOG-ERR-C1` (Google `google.rpc.Code` enum 사례 — NOT_FOUND=5 등 코드 매핑) | `official-vendor-doc` (Google AIP-193) | Google `Code` enum 은 16개 (OK, CANCELLED, INVALID_ARGUMENT 등) — ca-tmpl 10개와 1:1 아님. ca-tmpl enum 은 자체 design. **부모 §6 의 stale 13-목록은 본 enum 으로 정합 필요 (F1) — §21 L814 매핑 기준** |","scope":"error.category enum","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"error.category enum"},{"assertion_id":"A007","condition":"D11 결정","line_end":207,"line_start":207,"modality":"must","object":"snake_case (request_id, trace_id, span_id, correlation_id, tenant_id, user_principal)","predicate":"enforces","quote":"| D11 | MDC Key Standard = snake_case 강제 (`request_id`, `trace_id`, `span_id`, `correlation_id`, `tenant_id`, `user_principal`) | UNSUPPORTED_DECISION (인용된 official-docs 에 snake_case MDC key 강제 표준 없음 — Logback / SLF4J 는 컨벤션 미강제) | N/A | ECS 는 dot notation (`trace.id`), Micrometer 는 dot.case — ca-tmpl 의 snake_case 는 자체 design choice. envelope/header 표현은 D19 매핑 |","scope":"MDC keys","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"MDC Key Standard"},{"assertion_id":"A008","condition":"retryable 응답일 때 (D13)","line_end":209,"line_start":209,"modality":"must","object":"Retry-After 헤더 (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT 권고)","predicate":"requires","quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |","scope":"Retry-After header surfacing","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"retryable 응답"},{"assertion_id":"A009","condition":"D17 error code lifecycle","line_end":213,"line_start":213,"modality":"must_not","object":"rename/재사용 (never-reuse, append-only)","predicate":"forbids","quote":"| D17 | `error.code` 는 안정적 공개 API 계약 — append-only, rename/재사용 금지(never-reuse), 폐기는 compatibility 절차 | `raw/official-docs/stripe-resource-id-convention.md#STRIPE-C2` (opaque string + error message 변경 = backward-compatible 분류 → code 가 안정 계약 표면) + `raw/official-docs/google-api-error-format.md#GOOG-ERR-C4` (모든 error 에 `ErrorInfo` 필수 — machine-readable 식별자) | `company-case-study` + `official-vendor-doc` + UNSUPPORTED_DECISION (never-reuse 자체는 ca-tmpl 운영 정책 — resource-identifier D15 ID never-reuse 대칭) | deprecation 절차(Deprecation/Sunset 헤더 발행 시점) = api-compatibility owner. STRIPE-C2 는 message 변경이 호환임을 말할 뿐 code 불변을 직접 증명하지 않음 (대비 관계로 인용) |","scope":"error.code lifecycle","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"error.code"},{"assertion_id":"A010","condition":"401 AUTH 응답일 때 (D18, cross-branch-SSOT)","line_end":214,"line_start":214,"modality":"must","object":"WWW-Authenticate 헤더 동반","predicate":"requires","quote":"| D18 | `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (RFC 9110 §11.6.1 MUST) | [[raw/branch-notes/feature-security-operational-baseline]] (WWW-Authenticate 발행 owner — 부모 §25 L1086) + RFC 9110 §11.6.1 (raw claim 미보관 — 필요 시 `rfc9110-http-semantics.md` 보강) | `cross-branch-SSOT` | 본 branch 는 envelope/category 측 cross-cite 만 — 헤더 발행 정책은 security-operational-baseline owner. 401 enum row 가 bare 401 을 암시하지 않도록 §구현 가이드 §9 에 명시 |","scope":"AUTH 401 response headers","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"AUTH(401) 응답"},{"assertion_id":"A011","condition":"D19 표현 계층별 매핑","line_end":215,"line_start":215,"modality":"must","object":"MDC=snake_case / envelope meta=camelCase / HTTP header=kebab-case","predicate":"maps_to","quote":"| D19 | 동일 식별자의 표현 계층별 명명 매핑 — MDC=snake_case / envelope meta=camelCase / HTTP header=kebab-case(W3C lowercase) | [[raw/project-notes/ca-skeleton-operational-contract]] §21 (`request_id`↔`meta.requestId`↔`X-Request-Id` 매핑 등록) + §25 (envelope camelCase owner = schema-serialization) | `project-ssot` | **UNSUPPORTED_IMPL_DECISION**: 매핑 방향/케이스 선택 자체는 registry + schema-serialization 분담 결정 — 외부 표준 단일 근거 없음. resource-identifier §9 의 `user.id`/`resource.id`(dot) illustration 은 snake(`user_id`/`resource_id`)로 conform 필요 |","scope":"identifier naming across representation layers","source_surface":"SURF-8A9513DAC91F8CD98D1A","subject":"동일 식별자 (identifier)"},{"assertion_id":"A012","condition":"claim to verify, status=planned","line_end":451,"line_start":451,"modality":"unknown","object":"모든 5xx/validation/auth 응답에서 누락 없이 non-empty","predicate":"requires","quote":"| ca-tmpl envelope 의 `meta.traceId` 가 모든 5xx/validation/auth 응답에서 누락 없이 채워짐 | foundation owner branch — 모든 ControllerAdvice/Filter 에서 동작 보장 필요 | contract test: 각 카테고리별 fixture exception 발생 → response body 의 `meta.traceId` non-empty 확인 | `planned` |","scope":"meta.traceId population","source_surface":"SURF-AD8B78D0302C521CE89B","subject":"ca-tmpl envelope meta.traceId"},{"assertion_id":"A013","condition":"claim to verify (D13), status=planned","line_end":458,"line_start":458,"modality":"unknown","object":"Retry-After 헤더 + envelope error.retryable 함께 존재","predicate":"requires","quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |","scope":"Retry-After + retryable co-existence","source_surface":"SURF-AD8B78D0302C521CE89B","subject":"retryable=true(503/429) 응답"},{"assertion_id":"A014","condition":"claim to verify (D16), status=planned","line_end":461,"line_start":461,"modality":"unknown","object":"server span status=ERROR + exception 이벤트, client 응답엔 stack 부재","predicate":"has_failure_behavior","quote":"| (D16) 5xx 발생 시 server span status=ERROR + `exception` 이벤트 기록, client 응답엔 stack 부재 | OTel 사양은 attribute 정의만 — 실제 SDK wiring + 응답 분리 미검증 | OTel in-memory test exporter: span status ERROR + exception event 존재; 동시에 response body 에 stacktrace 부재 grep | `planned` |","scope":"5xx span recording + response stack absence","source_surface":"SURF-AD8B78D0302C521CE89B","subject":"5xx operational error"},{"assertion_id":"A015","condition":"claim to verify (D17), status=needs-confirmation","line_end":462,"line_start":462,"modality":"unknown","object":"compatibility 검사 실패 (never-reuse gate)","predicate":"forbids","quote":"| (D17) `error.code` rename/삭제/재사용 시 compatibility 검사 실패 | never-reuse 는 정책 — registry-governance 자동 게이트 미검증 | error-codes.yaml diff gate (removed/renamed code 검출 시 build 실패) — registry-governance owner | `needs-confirmation` |","scope":"error.code compatibility gate","source_surface":"SURF-AD8B78D0302C521CE89B","subject":"error.code rename/삭제/재사용"},{"assertion_id":"A016","condition":"해소됨 2026-06-01, status=locally-verified","line_end":465,"line_start":465,"modality":"observed","object":"retryable: true 로 수정 (JWKS 키 회전 가정; retry_after_seconds=5 유지)","predicate":"other","quote":"| (D13/F1 검증) `error-codes.yaml` 의 `AUTH_KID_UNKNOWN` 이 `category=AUTH, retryable=false` 인데 `retry_after_seconds: 5` 보유 — D13(\"retryable 응답만 Retry-After surface\")과 모순 | 2026-06-01 registry 검증에서 발견된 유일 이상치. source 주석(`feature-security-operational-baseline` L88 \"JWKS 미캐시 → 401 + Retry-After 5s\") + `client_safe_message: \"please retry\"` 가 retryable 의도를 시사 | **해소됨 (2026-06-01)**: 사용자 결정 = JWKS 키 회전 가정 → `retryable: true` 로 수정 (option b). `retry_after_seconds=5`/`runbook_link` 유지, §21 runbook 규칙 충족, yaml parse OK. **가역** — 키 고정 정책 전환 시 `false` 복귀(yaml inline 주석 명시) | `locally-verified` (registry 정합 확인; contract-verification:auth-category 테스트는 CI/사용자 실행) |","scope":"AUTH_KID_UNKNOWN retryable/Retry-After","source_surface":"SURF-AD8B78D0302C521CE89B","subject":"error-codes.yaml AUTH_KID_UNKNOWN"},{"assertion_id":"A017","condition":"5xx vs 4xx span 처리 (D16)","line_end":430,"line_start":430,"modality":"must","object":"server span status=ERROR + exception 이벤트 (4xx 는 span ERROR 아님, client 응답 stack 미포함)","predicate":"has_failure_behavior","quote":" - **5xx vs 4xx span 처리** — 모든 5xx(`INTERNAL`/`PERMANENT_DEPENDENCY`/`TRANSIENT_DEPENDENCY`)는 server span `status=ERROR` + `exception` 이벤트. **4xx 는 span ERROR 아님**(unset/OK). client 응답엔 stack 미포함. (D16 Q10/Q11)","scope":"trace span error handling","source_surface":"SURF-D96B8DD3384E0631C812","subject":"5xx operational error (INTERNAL/PERMANENT_DEPENDENCY/TRANSIENT_DEPENDENCY)"},{"assertion_id":"A018","condition":"retryable=true 응답 (D13)","line_end":431,"line_start":431,"modality":"must","object":"Retry-After 헤더 (둘은 함께 존재해야 함)","predicate":"requires","quote":" - **retryable=true + `Retry-After` 부재** — envelope `error.retryable: true`(503/429)인데 `Retry-After` 헤더 없으면 실패. 둘은 *함께* 존재해야 함. (D13)","scope":"retryable response headers","source_surface":"SURF-D96B8DD3384E0631C812","subject":"envelope error.retryable: true (503/429)"},{"assertion_id":"A019","condition":"password/token/secret 등 민감 필드 (annotation 또는 denylist 매칭)","line_end":432,"line_start":432,"modality":"must","object":"omit/mask (default omit)","predicate":"has_failure_behavior","quote":" - **민감 필드 `rejectedValue`** — validation field 가 `password`/`token`/`secret` 등(annotation 또는 denylist 매칭)이면 `rejectedValue` omit/mask. default = omit. (D12 Q6)","scope":"error.details rejectedValue masking","source_surface":"SURF-D96B8DD3384E0631C812","subject":"민감 validation field 의 rejectedValue"},{"assertion_id":"A020","condition":"partial failure (boundary D5 공유)","line_end":434,"line_start":434,"modality":"observed","object":"본 branch VALIDATION category (별도 details shape)","predicate":"consumes","quote":" - **partial failure** — boundary `BATCH_PARTIAL_FAILURE` 는 본 branch `VALIDATION` category 의 consumer 이며 별도 details shape. validation 외 category 의 details 는 `null`. (boundary D5 공유)","scope":"error category consumption","source_surface":"SURF-D96B8DD3384E0631C812","subject":"boundary BATCH_PARTIAL_FAILURE"},{"assertion_id":"A021","condition":"cross-contract dependency (D18)","line_end":437,"line_start":437,"modality":"must","object":"WWW-Authenticate 헤더 발행 정책 (security-operational-baseline D18 owner)","predicate":"delegates","quote":" - [[raw/branch-notes/feature-security-operational-baseline]] 의 `D18` 에 의존 — `WWW-Authenticate` 헤더 *발행 정책* owner. 본 branch 는 401 enum row 가 헤더 의무를 암시함만 명시(bare 401 금지). 발행 방식 변경 시 §9 cross-cite 갱신 필요.","scope":"WWW-Authenticate header publishing","source_surface":"SURF-D96B8DD3384E0631C812","subject":"본 branch (foundation)"},{"assertion_id":"A022","condition":"cross-contract dependency (D19)","line_end":440,"line_start":440,"modality":"must","object":"envelope meta.* camelCase 표기 (schema-serialization-contract owner)","predicate":"delegates","quote":" - [[raw/branch-notes/feature-schema-serialization-contract]] — envelope `meta.*` camelCase 표기 owner. D19 의 snake↔camel 매핑은 이 owner 의 직렬화 규칙에 의존.","scope":"envelope meta camelCase serialization","source_surface":"SURF-D96B8DD3384E0631C812","subject":"본 branch (foundation)"},{"assertion_id":"A023","condition":"cross-contract dependency","line_end":441,"line_start":441,"modality":"observed","object":"본 branch MDC snake_case 표준 (user_id/resource_id 추가 + redaction/PII MDC 분리)","predicate":"consumes","quote":" - [[raw/branch-notes/feature-log-management-contract]] — 본 branch MDC snake_case 표준을 consume(`user_id`/`resource_id` 추가 + redaction/PII MDC 분리). `user_principal` pseudonymization *알고리즘* 도 이 owner(§2 Q12 OUT_OF_BRANCH_SCOPE).","scope":"MDC snake_case standard consumption","source_surface":"SURF-D96B8DD3384E0631C812","subject":"feature-log-management-contract"},{"assertion_id":"A024","condition":"error.category=CONFLICT","line_end":267,"line_start":267,"modality":"must","object":"HTTP 409, retryable default=false (lock-only는 true)","predicate":"has_threshold","quote":"| CONFLICT | invariant/optimistic lock/constraint violation | 409 | false (lock-only는 true) |","scope":"error.category HTTP status/retryable default","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"CONFLICT category"},{"assertion_id":"A025","condition":"error.category=DATA_INTEGRITY","line_end":271,"line_start":271,"modality":"must","object":"HTTP 409, retryable default=false","predicate":"has_threshold","quote":"| DATA_INTEGRITY | DB 무결성 위반 | 409 | false |","scope":"error.category HTTP status/retryable default","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"DATA_INTEGRITY category"},{"assertion_id":"A026","condition":"MDC Key Standard (final)","line_end":281,"line_start":281,"modality":"must","object":"snake_case (MDC key 단위 camelCase / dot.case 금지)","predicate":"enforces","quote":"snake_case 강제. MDC key 단위는 camelCase / dot.case 금지 (envelope/header 표현은 §3 매핑).","scope":"MDC key naming","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"MDC key"},{"assertion_id":"A027","condition":"user_principal MDC key","line_end":290,"line_start":290,"modality":"must_not","object":"HTTP header 노출 (log only, headers forbidden; pseudonymized only)","predicate":"forbids","quote":"| user_principal | security context (pseudonymized only) | log only, headers forbidden |","scope":"user_principal propagation","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"user_principal MDC key"},{"assertion_id":"A028","condition":"ID 명명 표현 계층 매핑 (D19)","line_end":300,"line_start":300,"modality":"must","object":"request_id (MDC snake) / meta.requestId (envelope camel) / X-Request-Id (header kebab)","predicate":"maps_to","quote":"| request id | `request_id` (snake) | `meta.requestId` (camel) | `X-Request-Id` (kebab) |","scope":"request id representation layers","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"request id"},{"assertion_id":"A029","condition":"representation-layer mapping 계약","line_end":306,"line_start":306,"modality":"must","object":"MDC / envelope meta / HTTP header 3-열 1:1 매핑","predicate":"has_cardinality","quote":"- **계약**: 같은 논리 식별자는 위 3-열이 1:1 매핑이어야 함. 표현 case 가 달라도 *의미* 는 동일 (테스트 계약 \"response meta 의 ID 의미가 log MDC key 의미와 다르면 실패\").","scope":"identifier layer mapping","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"같은 논리 식별자 (logical identifier)"},{"assertion_id":"A030","condition":"TRANSIENT_DEPENDENCY, retryable=true","line_end":335,"line_start":335,"modality":"must","object":"Retry-After 헤더 (MUST, RFC9110-C21)","predicate":"requires","quote":"| TRANSIENT_DEPENDENCY | 503 | true | `Retry-After` (MUST, RFC9110-C21) |","scope":"Retry-After surfacing","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"TRANSIENT_DEPENDENCY (503)"},{"assertion_id":"A031","condition":"error.retryable: true 응답","line_end":339,"line_start":339,"modality":"must","object":"Retry-After 헤더 (함께 존재; envelope 만 true + 헤더 부재 = 실패)","predicate":"requires","quote":"- envelope `error.retryable: true` 와 `Retry-After` 헤더는 **함께** 존재해야 함 (envelope 만 true + 헤더 부재 = 실패).","scope":"retryable response headers","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"envelope error.retryable: true"},{"assertion_id":"A032","condition":"5xx 발생 시 (server-side)","line_end":362,"line_start":362,"modality":"must","object":"server span exception 이벤트 (type/message/stacktrace) + span status=ERROR (4xx 대상 아님)","predicate":"has_failure_behavior","quote":"- **모든 5xx** 발생 시 server span 에 `exception` 이벤트(`exception.type`/`exception.message`/`exception.stacktrace`) 기록 + span `status=ERROR`. 4xx 는 대상 아님.","scope":"trace span recording","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"모든 5xx 오류"},{"assertion_id":"A033","condition":"operational error 응답","line_end":363,"line_start":363,"modality":"must_not","object":"stack trace 포함 (exception 세부는 telemetry 전용)","predicate":"forbids","quote":"- **client HTTP 응답에는 stack trace 미포함** (판정 기준 Forbidden 과 정합) — exception 세부는 *telemetry 전용*.","scope":"client error response body","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"client HTTP 응답"},{"assertion_id":"A034","condition":"error code lifecycle (never-reuse, D17)","line_end":371,"line_start":371,"modality":"must_not","object":"rename / 의미 변경 / 재사용 (append-only)","predicate":"forbids","quote":"- `error.code` 는 **append-only** — rename / 의미 변경 / 재사용 금지. 폐기는 삭제가 아니라 deprecated 표시 + compatibility 절차.","scope":"error.code lifecycle","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"error.code"},{"assertion_id":"A035","condition":"401 AUTH 응답 (D18 cross-cite)","line_end":379,"line_start":379,"modality":"must","object":"WWW-Authenticate 헤더 동반 (bare 401 금지; 발행 정책은 security-operational-baseline owner)","predicate":"requires","quote":"- `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (bare 401 금지). 헤더 *발행 정책* 은 security-operational-baseline owner — 본 branch 는 enum 의 401 row 가 헤더 의무를 암시함을 명시만.","scope":"AUTH 401 response headers","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"AUTH(401) 응답"},{"assertion_id":"A036","condition":"inbound header 수신 (D14)","line_end":349,"line_start":349,"modality":"must","object":"CR/LF/제어문자 strip + length cap (RequestLoggingFilter; 값 부재/무효 시 server 생성)","predicate":"validates","quote":"- inbound `X-Request-Id` / `X-Correlation-Id` 수신 → MDC/로그 반영 전 **CR/LF/제어문자 strip** + **length cap** (값 부재/무효 시 server 생성). 위치 = `RequestLoggingFilter` (§0).","scope":"inbound header sanitization","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"inbound X-Request-Id / X-Correlation-Id"},{"assertion_id":"A037","condition":"inbound traceparent 수신 (D15)","line_end":350,"line_start":350,"modality":"must","object":"W3C 4-field format 검증 (무효 시 새 trace 시작, 유효 시 propagation 의무)","predicate":"validates","quote":"- inbound `traceparent` 수신 → W3C 4-field format(`W3C-TC-C2`) 검증. 무효 형식이면 **새 trace 시작** (client 값 무시 — Micrometer propagator 위임). 유효하면 propagation 의무(`W3C-TC-C5`).","scope":"traceparent trust boundary","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"inbound traceparent"},{"assertion_id":"A038","condition":"W3C-TC-C5 MUST NOT","line_end":351,"line_start":351,"modality":"must_not","object":"PII 포함 (outbound 전파 시 동일)","predicate":"forbids","quote":"- `tracestate` 에 PII 금지(`W3C-TC-C5` MUST NOT) — outbound 전파 시 동일.","scope":"tracestate content","source_surface":"SURF-72EB76F9DF890DB30C2F","subject":"tracestate"},{"assertion_id":"A039","condition":"포함 범위 (in scope)","line_end":93,"line_start":93,"modality":"must","object":"structured API response envelope 기준","predicate":"owns","quote":"- structured API response envelope 기준.","scope":"response envelope standard","source_surface":"SURF-E9E027A2DD29A0366F9A","subject":"본 branch (foundation)"},{"assertion_id":"A040","condition":"포함 범위 (in scope)","line_end":95,"line_start":95,"modality":"must","object":"retryable/non-retryable 기준 + 재시도 시점의 Retry-After surfacing (D13)","predicate":"owns","quote":"- retryable/non-retryable 기준 + 재시도 시점의 `Retry-After` surfacing (D13).","scope":"retryable + Retry-After surfacing","source_surface":"SURF-E9E027A2DD29A0366F9A","subject":"본 branch (foundation)"},{"assertion_id":"A041","condition":"제외 범위 (out of scope, delegated)","line_end":108,"line_start":108,"modality":"must_not","object":"JWT 세부 인증 실패 분류 + WWW-Authenticate 헤더 발행 (security-operational-baseline owner; D18 은 cross-cite 만)","predicate":"delegates","quote":"- JWT 세부 인증 실패 분류 + `WWW-Authenticate` 헤더 발행 (security-operational-baseline owner — D18 은 cross-cite 만).","scope":"WWW-Authenticate header publishing","source_surface":"SURF-E9E027A2DD29A0366F9A","subject":"본 branch (foundation)"},{"assertion_id":"A042","condition":"제외 범위 (out of scope, delegated)","line_end":110,"line_start":110,"modality":"must_not","object":"error-codes.yaml / mdc-keys.yaml / metrics.yaml 실제 row 편집 (registry-governance + ca-tmpl repo)","predicate":"delegates","quote":"- error-codes.yaml / mdc-keys.yaml / metrics.yaml 의 실제 row 편집 (registry-governance + ca-tmpl repo).","scope":"registry row editing","source_surface":"SURF-E9E027A2DD29A0366F9A","subject":"본 branch (foundation)"},{"assertion_id":"A043","condition":"제외 범위 (out of scope, delegated)","line_end":111,"line_start":111,"modality":"must_not","object":"429/Retry-After 운영 세부 + W3C trace context propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner)","predicate":"delegates","quote":"- 429/`Retry-After` 운영 세부 + W3C trace context 의 propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner).","scope":"429 Retry-After + W3C propagation/span detail","source_surface":"SURF-E9E027A2DD29A0366F9A","subject":"본 branch (foundation)"}],"candidate_manifest_sha256":"3002743569837dd1497c474b240e003671e06752374242cfadb9bcc9196c1cec","candidates":[{"assertion_a":"A003","assertion_b":"A011","candidate_id":"SEM-B5F2C4DE507C95EBF018","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A004","assertion_b":"A006","candidate_id":"SEM-C19E31B3166E3FCA43EF","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A004","assertion_b":"A008","candidate_id":"SEM-DCA81BE061FDD04ADE53","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A004","assertion_b":"A009","candidate_id":"SEM-2C28756215B3AB65A729","grouping_key":{"condition":"","predicate":"forbids","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A005","assertion_b":"A006","candidate_id":"SEM-7855D6ED5F7E2AAD9F4E","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A005","assertion_b":"A007","candidate_id":"SEM-09DC1E2365788A417072","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A006","assertion_b":"A009","candidate_id":"SEM-8F1EBDE6B1224A44CA2A","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A007","assertion_b":"A011","candidate_id":"SEM-02AD429F73F3E694C83F","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A007","assertion_b":"A023","candidate_id":"SEM-758D99F52611EAF9737E","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A007","assertion_b":"A026","candidate_id":"SEM-063D33567E6D78E1BC4C","grouping_key":{"condition":"","predicate":"enforces","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A007","assertion_b":"A028","candidate_id":"SEM-320A1BF534F6761B7964","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A008","assertion_b":"A013","candidate_id":"SEM-63D10B4ECFF94E360876","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A008","assertion_b":"A018","candidate_id":"SEM-BF281D73CCB49C7E5F6F","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A008","assertion_b":"A030","candidate_id":"SEM-B2E335C7CA031F939D74","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A008","assertion_b":"A031","candidate_id":"SEM-EE340C2051E9C5334D3F","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A008","assertion_b":"A040","candidate_id":"SEM-38CE07295A951CC2C7DE","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A008","assertion_b":"A043","candidate_id":"SEM-1D21E207BFEF972ADE96","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A009","assertion_b":"A015","candidate_id":"SEM-16278FA4106CEFEB8BAD","grouping_key":{"condition":"","predicate":"forbids","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A009","assertion_b":"A034","candidate_id":"SEM-10C8085AA1456C5A07E2","grouping_key":{"condition":"","predicate":"forbids","scope":"error.code lifecycle","subject":"error.code"},"rule_ids":["C6"]},{"assertion_a":"A010","assertion_b":"A021","candidate_id":"SEM-1DE09D6E1DB9637EB0B4","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A010","assertion_b":"A035","candidate_id":"SEM-D7D91C239BCB37EE2EA9","grouping_key":{"condition":"","predicate":"requires","scope":"AUTH 401 response headers","subject":"AUTH(401) 응답"},"rule_ids":["C6"]},{"assertion_a":"A010","assertion_b":"A041","candidate_id":"SEM-616F8B7DB38E097747B5","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A011","assertion_b":"A023","candidate_id":"SEM-2422D454B7273888A61A","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A011","assertion_b":"A028","candidate_id":"SEM-969B85ECC5B31052D50C","grouping_key":{"condition":"","predicate":"maps_to","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A011","assertion_b":"A036","candidate_id":"SEM-F01097F52BD64810D94E","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A012","assertion_b":"A013","candidate_id":"SEM-519A1A83CEE0EEDAF5CF","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A012","assertion_b":"A014","candidate_id":"SEM-E72E6E0A2A97A289CEE6","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A013","assertion_b":"A014","candidate_id":"SEM-62A1EA3B8931BE802BD3","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A013","assertion_b":"A018","candidate_id":"SEM-924E87B41477C4735FBA","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A013","assertion_b":"A030","candidate_id":"SEM-1358C6A3456380F9229B","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A013","assertion_b":"A031","candidate_id":"SEM-27C760B7EB4E434B4358","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A013","assertion_b":"A040","candidate_id":"SEM-D76E162F6332855EBE66","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A013","assertion_b":"A043","candidate_id":"SEM-7CEE14F425CA0E4D0FE0","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A014","assertion_b":"A017","candidate_id":"SEM-D140AA4B90BD53CBBAEA","grouping_key":{"condition":"","predicate":"has_failure_behavior","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A014","assertion_b":"A032","candidate_id":"SEM-2779466E2F879DFD67D7","grouping_key":{"condition":"","predicate":"has_failure_behavior","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A015","assertion_b":"A034","candidate_id":"SEM-4613B311C98244AC9733","grouping_key":{"condition":"","predicate":"forbids","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A017","assertion_b":"A032","candidate_id":"SEM-C8C5E206F886078FC0D4","grouping_key":{"condition":"","predicate":"has_failure_behavior","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A018","assertion_b":"A030","candidate_id":"SEM-F614288667D1510A99CB","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A018","assertion_b":"A031","candidate_id":"SEM-84D91A65870BB263042A","grouping_key":{"condition":"","predicate":"requires","scope":"retryable response headers","subject":""},"rule_ids":["C6"]},{"assertion_a":"A018","assertion_b":"A040","candidate_id":"SEM-CA542189FF8DD78BEFA8","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A018","assertion_b":"A043","candidate_id":"SEM-028201FBFC6A1FFE1B4B","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A021","assertion_b":"A035","candidate_id":"SEM-51578CF67427046088EE","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A021","assertion_b":"A041","candidate_id":"SEM-1F3D6E77794CE72A1D33","grouping_key":{"condition":"","predicate":"delegates","scope":"WWW-Authenticate header publishing","subject":"본 branch (foundation)"},"rule_ids":["C6"]},{"assertion_a":"A028","assertion_b":"A036","candidate_id":"SEM-99444518D74392473F05","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A030","assertion_b":"A031","candidate_id":"SEM-894C51D330DA3E7185BF","grouping_key":{"condition":"","predicate":"requires","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A030","assertion_b":"A040","candidate_id":"SEM-B65B987B005CC7359063","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A030","assertion_b":"A043","candidate_id":"SEM-CE749FF29D98A0672E6E","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A031","assertion_b":"A040","candidate_id":"SEM-727564B5D480838AD626","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A031","assertion_b":"A043","candidate_id":"SEM-1D419A42159A1B17FFF6","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A035","assertion_b":"A041","candidate_id":"SEM-E0BEFE8F1ED0A861B998","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A037","assertion_b":"A038","candidate_id":"SEM-BAB8EED3AE78CB98F290","grouping_key":{"condition":"","predicate":"","scope":"","subject":""},"rule_ids":["C6"]},{"assertion_a":"A040","assertion_b":"A043","candidate_id":"SEM-4B57C669075B5D83F9EB","grouping_key":{"condition":"","predicate":"","scope":"","subject":"본 branch (foundation)"},"rule_ids":["C6"]}],"coverage":{"assertions":43,"candidate_pairs":52,"eligible_surfaces":6,"processed_surfaces":6},"document_sha256":"e7934a7e7d271d8f1d066181cbc3789577a309bd926310745c25a0bc14748049","explicit_blocking":[],"mode":"local","ontology_sha256":"76d41a29233c830e1940ebb3244263e2b9bfb8dd6a01f2a1d1c51ce5a1b10468","output_schema":"semantic-audit-result/v1","schema_version":"semantic-verdict-request/v1","subject":"raw/branch-notes/feature-operational-error-observability-foundation.md"},"audit_request_sha256":"9bdb75adf0f4f30e1067d9057a2000f0904874017fc0fafb9481cb34a3b9e583","audit_result":{"auditor":{"contract_version":"semantic-coherence/v1","model_id":"claude-opus-4-8","run_id":"a4be5e6fb9933e916"},"mode":"local","request_sha256":"9bdb75adf0f4f30e1067d9057a2000f0904874017fc0fafb9481cb34a3b9e583","schema_version":"semantic-audit-result/v1","subject":"raw/branch-notes/feature-operational-error-observability-foundation.md","verdicts":[{"candidate_id":"SEM-B5F2C4DE507C95EBF018","evidence_a":{"line_end":63,"line_start":63,"quote":"| `DEC-CA-SKELETON-OPERATIONAL-CONTRACT-ERROR-ENVELOPE-001@1` | foundation이 envelope schema와 error.category enum의 단일 owner다 | Work Item 완료 조건에 적용 | [[raw/project-notes/ca-skeleton-operational-contract]] |"},"evidence_b":{"line_end":215,"line_start":215,"quote":"| D19 | 동일 식별자의 표현 계층별 명명 매핑 — MDC=snake_case / envelope meta=camelCase / HTTP header=kebab-case(W3C lowercase) | [[raw/project-notes/ca-skeleton-operational-contract]] §21 (`request_id`↔`meta.requestId`↔`X-Request-Id` 매핑 등록) + §25 (envelope camelCase owner = schema-serialization) | `project-ssot` | **UNSUPPORTED_IMPL_DECISION**: 매핑 방향/케이스 선택 자체는 registry + schema-serialization 분담 결정 — 외부 표준 단일 근거 없음. resource-identifier §9 의 `user.id`/`resource.id`(dot) illustration 은 snake(`user_id`/`resource_id`)로 conform 필요 |"},"proof_manifest":null,"rationale":"A003 asserts foundation is single owner of envelope schema and error.category enum; A011 supplies the cross-layer identifier naming mapping (MDC snake / envelope camel / header kebab). The mapping is a compatible detail under the schema foundation owns; it does not take over ownership.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-C19E31B3166E3FCA43EF","evidence_a":{"line_end":197,"line_start":197,"quote":"| D1 | `ProblemDetail` 사용 거부, 자체 envelope 응답 사용 | `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C1`, `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C2`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C1`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C3` | `official-standard` (RFC 7807 의 `application/problem+json` + `type` MUST 식별자 — ca-tmpl 의 success/error 대칭 + retryable 1급 필드와 구조적 충돌) + `official-vendor-doc` (Spring ProblemDetail 의 RFC 9457 representation) | RFC 7807/9457 거부의 trade-off: 표준 lock-in 회피 vs 표준 호환성 손실. RFC 7807 `extensions` 메커니즘 (`RFC7807-C3`) 으로 retryable/category 표현 가능했음 |"},"evidence_b":{"line_end":206,"line_start":206,"quote":"| D10 | `error.category` enum 10개 (VALIDATION/AUTH/AUTHZ/NOT_FOUND/CONFLICT/RATE_LIMIT/TRANSIENT_DEPENDENCY/PERMANENT_DEPENDENCY/DATA_INTEGRITY/INTERNAL) | `raw/official-docs/google-api-error-format.md#GOOG-ERR-C1` (Google `google.rpc.Code` enum 사례 — NOT_FOUND=5 등 코드 매핑) | `official-vendor-doc` (Google AIP-193) | Google `Code` enum 은 16개 (OK, CANCELLED, INVALID_ARGUMENT 등) — ca-tmpl 10개와 1:1 아님. ca-tmpl enum 은 자체 design. **부모 §6 의 stale 13-목록은 본 enum 으로 정합 필요 (F1) — §21 L814 매핑 기준** |"},"proof_manifest":null,"rationale":"A004 forbids ProblemDetail in favor of the custom envelope (D1); A006 states the enum has 10 categories (D10). Different contract properties (response format choice vs enum cardinality) that together describe the same envelope design without conflict.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-DCA81BE061FDD04ADE53","evidence_a":{"line_end":197,"line_start":197,"quote":"| D1 | `ProblemDetail` 사용 거부, 자체 envelope 응답 사용 | `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C1`, `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C2`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C1`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C3` | `official-standard` (RFC 7807 의 `application/problem+json` + `type` MUST 식별자 — ca-tmpl 의 success/error 대칭 + retryable 1급 필드와 구조적 충돌) + `official-vendor-doc` (Spring ProblemDetail 의 RFC 9457 representation) | RFC 7807/9457 거부의 trade-off: 표준 lock-in 회피 vs 표준 호환성 손실. RFC 7807 `extensions` 메커니즘 (`RFC7807-C3`) 으로 retryable/category 표현 가능했음 |"},"evidence_b":{"line_end":209,"line_start":209,"quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |"},"proof_manifest":null,"rationale":"A004 forbids ProblemDetail (D1); A008 requires Retry-After for retryable responses (D13). Independent, compatible facets of the error contract.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-2C28756215B3AB65A729","evidence_a":{"line_end":197,"line_start":197,"quote":"| D1 | `ProblemDetail` 사용 거부, 자체 envelope 응답 사용 | `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C1`, `raw/official-docs/problem-detail-rfc-7807.md#RFC7807-C2`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C1`, `raw/official-docs/spring-problem-detail.md#SPRING-PD-C3` | `official-standard` (RFC 7807 의 `application/problem+json` + `type` MUST 식별자 — ca-tmpl 의 success/error 대칭 + retryable 1급 필드와 구조적 충돌) + `official-vendor-doc` (Spring ProblemDetail 의 RFC 9457 representation) | RFC 7807/9457 거부의 trade-off: 표준 lock-in 회피 vs 표준 호환성 손실. RFC 7807 `extensions` 메커니즘 (`RFC7807-C3`) 으로 retryable/category 표현 가능했음 |"},"evidence_b":{"line_end":213,"line_start":213,"quote":"| D17 | `error.code` 는 안정적 공개 API 계약 — append-only, rename/재사용 금지(never-reuse), 폐기는 compatibility 절차 | `raw/official-docs/stripe-resource-id-convention.md#STRIPE-C2` (opaque string + error message 변경 = backward-compatible 분류 → code 가 안정 계약 표면) + `raw/official-docs/google-api-error-format.md#GOOG-ERR-C4` (모든 error 에 `ErrorInfo` 필수 — machine-readable 식별자) | `company-case-study` + `official-vendor-doc` + UNSUPPORTED_DECISION (never-reuse 자체는 ca-tmpl 운영 정책 — resource-identifier D15 ID never-reuse 대칭) | deprecation 절차(Deprecation/Sunset 헤더 발행 시점) = api-compatibility owner. STRIPE-C2 는 message 변경이 호환임을 말할 뿐 code 불변을 직접 증명하지 않음 (대비 관계로 인용) |"},"proof_manifest":null,"rationale":"Both are forbids, but different scopes: A004 forbids ProblemDetail for the API error response format; A009 forbids error.code rename/reuse in the code lifecycle. No shared property to conflict on.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-7855D6ED5F7E2AAD9F4E","evidence_a":{"line_end":202,"line_start":202,"quote":"| D6 | 본 branch 가 error envelope schema, `error.category` enum, requestId/traceId/correlationId 의미, MDC/log key 표준의 SSOT owner | UNSUPPORTED_DECISION (SSOT ownership 분할은 내부 운영 정책) | N/A | branch ownership 분할은 외부 표준 인용 대상 아님. 부모 §25 SSOT Owner Map 과 정합 |"},"evidence_b":{"line_end":206,"line_start":206,"quote":"| D10 | `error.category` enum 10개 (VALIDATION/AUTH/AUTHZ/NOT_FOUND/CONFLICT/RATE_LIMIT/TRANSIENT_DEPENDENCY/PERMANENT_DEPENDENCY/DATA_INTEGRITY/INTERNAL) | `raw/official-docs/google-api-error-format.md#GOOG-ERR-C1` (Google `google.rpc.Code` enum 사례 — NOT_FOUND=5 등 코드 매핑) | `official-vendor-doc` (Google AIP-193) | Google `Code` enum 은 16개 (OK, CANCELLED, INVALID_ARGUMENT 등) — ca-tmpl 10개와 1:1 아님. ca-tmpl enum 은 자체 design. **부모 §6 의 stale 13-목록은 본 enum 으로 정합 필요 (F1) — §21 L814 매핑 기준** |"},"proof_manifest":null,"rationale":"A005 declares foundation SSOT owner of envelope schema and error.category enum; A006 supplies the enum's cardinality (10). A006 fills in a detail of what A005 owns; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-09DC1E2365788A417072","evidence_a":{"line_end":202,"line_start":202,"quote":"| D6 | 본 branch 가 error envelope schema, `error.category` enum, requestId/traceId/correlationId 의미, MDC/log key 표준의 SSOT owner | UNSUPPORTED_DECISION (SSOT ownership 분할은 내부 운영 정책) | N/A | branch ownership 분할은 외부 표준 인용 대상 아님. 부모 §25 SSOT Owner Map 과 정합 |"},"evidence_b":{"line_end":207,"line_start":207,"quote":"| D11 | MDC Key Standard = snake_case 강제 (`request_id`, `trace_id`, `span_id`, `correlation_id`, `tenant_id`, `user_principal`) | UNSUPPORTED_DECISION (인용된 official-docs 에 snake_case MDC key 강제 표준 없음 — Logback / SLF4J 는 컨벤션 미강제) | N/A | ECS 는 dot notation (`trace.id`), Micrometer 는 dot.case — ca-tmpl 의 snake_case 는 자체 design choice. envelope/header 표현은 D19 매핑 |"},"proof_manifest":null,"rationale":"A005 declares foundation owns the MDC/log key standard; A007 supplies its content (snake_case). Detail of the owned standard, not a competing claim.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-8F1EBDE6B1224A44CA2A","evidence_a":{"line_end":206,"line_start":206,"quote":"| D10 | `error.category` enum 10개 (VALIDATION/AUTH/AUTHZ/NOT_FOUND/CONFLICT/RATE_LIMIT/TRANSIENT_DEPENDENCY/PERMANENT_DEPENDENCY/DATA_INTEGRITY/INTERNAL) | `raw/official-docs/google-api-error-format.md#GOOG-ERR-C1` (Google `google.rpc.Code` enum 사례 — NOT_FOUND=5 등 코드 매핑) | `official-vendor-doc` (Google AIP-193) | Google `Code` enum 은 16개 (OK, CANCELLED, INVALID_ARGUMENT 등) — ca-tmpl 10개와 1:1 아님. ca-tmpl enum 은 자체 design. **부모 §6 의 stale 13-목록은 본 enum 으로 정합 필요 (F1) — §21 L814 매핑 기준** |"},"evidence_b":{"line_end":213,"line_start":213,"quote":"| D17 | `error.code` 는 안정적 공개 API 계약 — append-only, rename/재사용 금지(never-reuse), 폐기는 compatibility 절차 | `raw/official-docs/stripe-resource-id-convention.md#STRIPE-C2` (opaque string + error message 변경 = backward-compatible 분류 → code 가 안정 계약 표면) + `raw/official-docs/google-api-error-format.md#GOOG-ERR-C4` (모든 error 에 `ErrorInfo` 필수 — machine-readable 식별자) | `company-case-study` + `official-vendor-doc` + UNSUPPORTED_DECISION (never-reuse 자체는 ca-tmpl 운영 정책 — resource-identifier D15 ID never-reuse 대칭) | deprecation 절차(Deprecation/Sunset 헤더 발행 시점) = api-compatibility owner. STRIPE-C2 는 message 변경이 호환임을 말할 뿐 code 불변을 직접 증명하지 않음 (대비 관계로 인용) |"},"proof_manifest":null,"rationale":"A006 (enum cardinality 10) and A009 (error.code never-reuse lifecycle) address different contract properties of the error model; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-02AD429F73F3E694C83F","evidence_a":{"line_end":207,"line_start":207,"quote":"| D11 | MDC Key Standard = snake_case 강제 (`request_id`, `trace_id`, `span_id`, `correlation_id`, `tenant_id`, `user_principal`) | UNSUPPORTED_DECISION (인용된 official-docs 에 snake_case MDC key 강제 표준 없음 — Logback / SLF4J 는 컨벤션 미강제) | N/A | ECS 는 dot notation (`trace.id`), Micrometer 는 dot.case — ca-tmpl 의 snake_case 는 자체 design choice. envelope/header 표현은 D19 매핑 |"},"evidence_b":{"line_end":215,"line_start":215,"quote":"| D19 | 동일 식별자의 표현 계층별 명명 매핑 — MDC=snake_case / envelope meta=camelCase / HTTP header=kebab-case(W3C lowercase) | [[raw/project-notes/ca-skeleton-operational-contract]] §21 (`request_id`↔`meta.requestId`↔`X-Request-Id` 매핑 등록) + §25 (envelope camelCase owner = schema-serialization) | `project-ssot` | **UNSUPPORTED_IMPL_DECISION**: 매핑 방향/케이스 선택 자체는 registry + schema-serialization 분담 결정 — 외부 표준 단일 근거 없음. resource-identifier §9 의 `user.id`/`resource.id`(dot) illustration 은 snake(`user_id`/`resource_id`)로 conform 필요 |"},"proof_manifest":null,"rationale":"A007 enforces MDC keys as snake_case; A011 agrees (MDC=snake) and additionally supplies the envelope-camel/header-kebab layers. A011 extends with compatible detail across representation layers.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-758D99F52611EAF9737E","evidence_a":{"line_end":207,"line_start":207,"quote":"| D11 | MDC Key Standard = snake_case 강제 (`request_id`, `trace_id`, `span_id`, `correlation_id`, `tenant_id`, `user_principal`) | UNSUPPORTED_DECISION (인용된 official-docs 에 snake_case MDC key 강제 표준 없음 — Logback / SLF4J 는 컨벤션 미강제) | N/A | ECS 는 dot notation (`trace.id`), Micrometer 는 dot.case — ca-tmpl 의 snake_case 는 자체 design choice. envelope/header 표현은 D19 매핑 |"},"evidence_b":{"line_end":441,"line_start":441,"quote":" - [[raw/branch-notes/feature-log-management-contract]] — 본 branch MDC snake_case 표준을 consume(`user_id`/`resource_id` 추가 + redaction/PII MDC 분리). `user_principal` pseudonymization *알고리즘* 도 이 owner(§2 Q12 OUT_OF_BRANCH_SCOPE)."},"proof_manifest":null,"rationale":"A007 owns/enforces the MDC snake_case standard; A023 states feature-log-management-contract consumes that standard (adding user_id/resource_id). Consumer relationship complements the owner claim without taking it over.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-063D33567E6D78E1BC4C","evidence_a":{"line_end":207,"line_start":207,"quote":"| D11 | MDC Key Standard = snake_case 강제 (`request_id`, `trace_id`, `span_id`, `correlation_id`, `tenant_id`, `user_principal`) | UNSUPPORTED_DECISION (인용된 official-docs 에 snake_case MDC key 강제 표준 없음 — Logback / SLF4J 는 컨벤션 미강제) | N/A | ECS 는 dot notation (`trace.id`), Micrometer 는 dot.case — ca-tmpl 의 snake_case 는 자체 design choice. envelope/header 표현은 D19 매핑 |"},"evidence_b":{"line_end":281,"line_start":281,"quote":"snake_case 강제. MDC key 단위는 camelCase / dot.case 금지 (envelope/header 표현은 §3 매핑)."},"proof_manifest":null,"rationale":"A007 and A026 both enforce snake_case for MDC keys (A026 additionally names camelCase/dot.case as forbidden, restating the same rule). Same property, same value.","verdict":"CONSISTENT"},{"candidate_id":"SEM-320A1BF534F6761B7964","evidence_a":{"line_end":207,"line_start":207,"quote":"| D11 | MDC Key Standard = snake_case 강제 (`request_id`, `trace_id`, `span_id`, `correlation_id`, `tenant_id`, `user_principal`) | UNSUPPORTED_DECISION (인용된 official-docs 에 snake_case MDC key 강제 표준 없음 — Logback / SLF4J 는 컨벤션 미강제) | N/A | ECS 는 dot notation (`trace.id`), Micrometer 는 dot.case — ca-tmpl 의 snake_case 는 자체 design choice. envelope/header 표현은 D19 매핑 |"},"evidence_b":{"line_end":300,"line_start":300,"quote":"| request id | `request_id` (snake) | `meta.requestId` (camel) | `X-Request-Id` (kebab) |"},"proof_manifest":null,"rationale":"A007 enforces MDC=snake_case; A028 gives the concrete request_id mapping (request_id snake / meta.requestId camel / X-Request-Id kebab), consistent with MDC=snake and adding the other layers. Compatible detail.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-63D10B4ECFF94E360876","evidence_a":{"line_end":209,"line_start":209,"quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |"},"evidence_b":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"proof_manifest":null,"rationale":"A008 (retryable requires Retry-After, D13) and A013 (planned contract test: retryable=true 503/429 must carry Retry-After alongside envelope error.retryable) express the same requirement, A013 as its verification claim. No changed meaning.","verdict":"CONSISTENT"},{"candidate_id":"SEM-BF281D73CCB49C7E5F6F","evidence_a":{"line_end":209,"line_start":209,"quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |"},"evidence_b":{"line_end":431,"line_start":431,"quote":" - **retryable=true + `Retry-After` 부재** — envelope `error.retryable: true`(503/429)인데 `Retry-After` 헤더 없으면 실패. 둘은 *함께* 존재해야 함. (D13)"},"proof_manifest":null,"rationale":"A008 and A018 both require Retry-After to accompany retryable responses; 503 MUST is agreed and for 429 both point to the header being present. 'recommended' vs the co-existence invariant are not mutually exclusive (both yield the header present), and 429 specifics are explicitly delegated. Same requirement.","verdict":"CONSISTENT"},{"candidate_id":"SEM-B2E335C7CA031F939D74","evidence_a":{"line_end":209,"line_start":209,"quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |"},"evidence_b":{"line_end":335,"line_start":335,"quote":"| TRANSIENT_DEPENDENCY | 503 | true | `Retry-After` (MUST, RFC9110-C21) |"},"proof_manifest":null,"rationale":"A008 states the general retryable→Retry-After rule (503 MUST); A030 supplies the specific TRANSIENT_DEPENDENCY 503 instance (MUST). A030 is a concrete instantiation, compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-EE340C2051E9C5334D3F","evidence_a":{"line_end":209,"line_start":209,"quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |"},"evidence_b":{"line_end":339,"line_start":339,"quote":"- envelope `error.retryable: true` 와 `Retry-After` 헤더는 **함께** 존재해야 함 (envelope 만 true + 헤더 부재 = 실패)."},"proof_manifest":null,"rationale":"A008 requires Retry-After for retryable responses; A031 states the same for envelope error.retryable:true (fail if header absent). Same requirement direction; the failure-behavior phrasing does not change meaning.","verdict":"CONSISTENT"},{"candidate_id":"SEM-38CE07295A951CC2C7DE","evidence_a":{"line_end":209,"line_start":209,"quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |"},"evidence_b":{"line_end":95,"line_start":95,"quote":"- retryable/non-retryable 기준 + 재시도 시점의 `Retry-After` surfacing (D13)."},"proof_manifest":null,"rationale":"A040 declares foundation owns the retryable criteria + Retry-After surfacing; A008 supplies the concrete rule (503 MUST / 429 recommended). A008 is a detail of what A040 owns.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-1D21E207BFEF972ADE96","evidence_a":{"line_end":209,"line_start":209,"quote":"| D13 | retryable 응답은 `Retry-After` 헤더로 재시도 시점 surface (503/TRANSIENT_DEPENDENCY MUST, 429/RATE_LIMIT + `X-RateLimit-*` 권고) | `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C21` (Retry-After = follow-up request 대기 시간, 503 시 unavailable 예상 시간) + `raw/official-docs/rfc9110-http-semantics.md#RFC9110-C6` (413 temporary → Retry-After SHOULD) | `official-standard` (503/3xx) | 429 의 Retry-After 는 RFC 6585 §4 (본 raw 미보관 — rate-limit-idempotency owner). `X-RateLimit-*` 는 비표준 관례 (headers.yaml 등록). **UNSUPPORTED_IMPL_DECISION**: `retry_after_seconds` 값 자체는 error-codes.yaml project-decision |"},"evidence_b":{"line_end":111,"line_start":111,"quote":"- 429/`Retry-After` 운영 세부 + W3C trace context 의 propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner)."},"proof_manifest":null,"rationale":"A008 requires Retry-After surfacing for retryable responses; A043 delegates the 429/Retry-After operational specifics to the rate-limit-idempotency owner. The delegation covers a narrow 429 slice and does not override the general surfacing rule; scopes are complementary.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-16278FA4106CEFEB8BAD","evidence_a":{"line_end":213,"line_start":213,"quote":"| D17 | `error.code` 는 안정적 공개 API 계약 — append-only, rename/재사용 금지(never-reuse), 폐기는 compatibility 절차 | `raw/official-docs/stripe-resource-id-convention.md#STRIPE-C2` (opaque string + error message 변경 = backward-compatible 분류 → code 가 안정 계약 표면) + `raw/official-docs/google-api-error-format.md#GOOG-ERR-C4` (모든 error 에 `ErrorInfo` 필수 — machine-readable 식별자) | `company-case-study` + `official-vendor-doc` + UNSUPPORTED_DECISION (never-reuse 자체는 ca-tmpl 운영 정책 — resource-identifier D15 ID never-reuse 대칭) | deprecation 절차(Deprecation/Sunset 헤더 발행 시점) = api-compatibility owner. STRIPE-C2 는 message 변경이 호환임을 말할 뿐 code 불변을 직접 증명하지 않음 (대비 관계로 인용) |"},"evidence_b":{"line_end":462,"line_start":462,"quote":"| (D17) `error.code` rename/삭제/재사용 시 compatibility 검사 실패 | never-reuse 는 정책 — registry-governance 자동 게이트 미검증 | error-codes.yaml diff gate (removed/renamed code 검출 시 build 실패) — registry-governance owner | `needs-confirmation` |"},"proof_manifest":null,"rationale":"A009 forbids error.code rename/reuse (never-reuse, append-only); A015 states the compatibility gate that enforces the same never-reuse policy (as a claim to verify). Same rule; A015 is its enforcement/verification restatement.","verdict":"CONSISTENT"},{"candidate_id":"SEM-10C8085AA1456C5A07E2","evidence_a":{"line_end":213,"line_start":213,"quote":"| D17 | `error.code` 는 안정적 공개 API 계약 — append-only, rename/재사용 금지(never-reuse), 폐기는 compatibility 절차 | `raw/official-docs/stripe-resource-id-convention.md#STRIPE-C2` (opaque string + error message 변경 = backward-compatible 분류 → code 가 안정 계약 표면) + `raw/official-docs/google-api-error-format.md#GOOG-ERR-C4` (모든 error 에 `ErrorInfo` 필수 — machine-readable 식별자) | `company-case-study` + `official-vendor-doc` + UNSUPPORTED_DECISION (never-reuse 자체는 ca-tmpl 운영 정책 — resource-identifier D15 ID never-reuse 대칭) | deprecation 절차(Deprecation/Sunset 헤더 발행 시점) = api-compatibility owner. STRIPE-C2 는 message 변경이 호환임을 말할 뿐 code 불변을 직접 증명하지 않음 (대비 관계로 인용) |"},"evidence_b":{"line_end":371,"line_start":371,"quote":"- `error.code` 는 **append-only** — rename / 의미 변경 / 재사용 금지. 폐기는 삭제가 아니라 deprecated 표시 + compatibility 절차."},"proof_manifest":null,"rationale":"A009 and A034 both forbid error.code rename/meaning-change/reuse and require append-only (D17). Same subject, scope, and value.","verdict":"CONSISTENT"},{"candidate_id":"SEM-1DE09D6E1DB9637EB0B4","evidence_a":{"line_end":214,"line_start":214,"quote":"| D18 | `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (RFC 9110 §11.6.1 MUST) | [[raw/branch-notes/feature-security-operational-baseline]] (WWW-Authenticate 발행 owner — 부모 §25 L1086) + RFC 9110 §11.6.1 (raw claim 미보관 — 필요 시 `rfc9110-http-semantics.md` 보강) | `cross-branch-SSOT` | 본 branch 는 envelope/category 측 cross-cite 만 — 헤더 발행 정책은 security-operational-baseline owner. 401 enum row 가 bare 401 을 암시하지 않도록 §구현 가이드 §9 에 명시 |"},"evidence_b":{"line_end":437,"line_start":437,"quote":" - [[raw/branch-notes/feature-security-operational-baseline]] 의 `D18` 에 의존 — `WWW-Authenticate` 헤더 *발행 정책* owner. 본 branch 는 401 enum row 가 헤더 의무를 암시함만 명시(bare 401 금지). 발행 방식 변경 시 §9 cross-cite 갱신 필요."},"proof_manifest":null,"rationale":"A010 requires WWW-Authenticate on AUTH 401 (cross-cite of D18); A021 delegates the actual header-publishing policy to security-operational-baseline. Foundation cross-cites the requirement while delegating publishing; compatible, no takeover.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-D7D91C239BCB37EE2EA9","evidence_a":{"line_end":214,"line_start":214,"quote":"| D18 | `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (RFC 9110 §11.6.1 MUST) | [[raw/branch-notes/feature-security-operational-baseline]] (WWW-Authenticate 발행 owner — 부모 §25 L1086) + RFC 9110 §11.6.1 (raw claim 미보관 — 필요 시 `rfc9110-http-semantics.md` 보강) | `cross-branch-SSOT` | 본 branch 는 envelope/category 측 cross-cite 만 — 헤더 발행 정책은 security-operational-baseline owner. 401 enum row 가 bare 401 을 암시하지 않도록 §구현 가이드 §9 에 명시 |"},"evidence_b":{"line_end":379,"line_start":379,"quote":"- `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (bare 401 금지). 헤더 *발행 정책* 은 security-operational-baseline owner — 본 branch 는 enum 의 401 row 가 헤더 의무를 암시함을 명시만."},"proof_manifest":null,"rationale":"A010 and A035 both require the WWW-Authenticate header on AUTH 401 (D18), both noting the publishing policy is owned by security-operational-baseline. Same requirement and same authority attribution.","verdict":"CONSISTENT"},{"candidate_id":"SEM-616F8B7DB38E097747B5","evidence_a":{"line_end":214,"line_start":214,"quote":"| D18 | `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (RFC 9110 §11.6.1 MUST) | [[raw/branch-notes/feature-security-operational-baseline]] (WWW-Authenticate 발행 owner — 부모 §25 L1086) + RFC 9110 §11.6.1 (raw claim 미보관 — 필요 시 `rfc9110-http-semantics.md` 보강) | `cross-branch-SSOT` | 본 branch 는 envelope/category 측 cross-cite 만 — 헤더 발행 정책은 security-operational-baseline owner. 401 enum row 가 bare 401 을 암시하지 않도록 §구현 가이드 §9 에 명시 |"},"evidence_b":{"line_end":108,"line_start":108,"quote":"- JWT 세부 인증 실패 분류 + `WWW-Authenticate` 헤더 발행 (security-operational-baseline owner — D18 은 cross-cite 만)."},"proof_manifest":null,"rationale":"A010 requires WWW-Authenticate on 401 (cross-cite); A041 places JWT classification + WWW-Authenticate publishing out of scope, delegated to security-operational-baseline. The requirement and its delegation coexist; A041 supplies the ownership boundary.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-2422D454B7273888A61A","evidence_a":{"line_end":215,"line_start":215,"quote":"| D19 | 동일 식별자의 표현 계층별 명명 매핑 — MDC=snake_case / envelope meta=camelCase / HTTP header=kebab-case(W3C lowercase) | [[raw/project-notes/ca-skeleton-operational-contract]] §21 (`request_id`↔`meta.requestId`↔`X-Request-Id` 매핑 등록) + §25 (envelope camelCase owner = schema-serialization) | `project-ssot` | **UNSUPPORTED_IMPL_DECISION**: 매핑 방향/케이스 선택 자체는 registry + schema-serialization 분담 결정 — 외부 표준 단일 근거 없음. resource-identifier §9 의 `user.id`/`resource.id`(dot) illustration 은 snake(`user_id`/`resource_id`)로 conform 필요 |"},"evidence_b":{"line_end":441,"line_start":441,"quote":" - [[raw/branch-notes/feature-log-management-contract]] — 본 branch MDC snake_case 표준을 consume(`user_id`/`resource_id` 추가 + redaction/PII MDC 분리). `user_principal` pseudonymization *알고리즘* 도 이 owner(§2 Q12 OUT_OF_BRANCH_SCOPE)."},"proof_manifest":null,"rationale":"A011 defines the identifier layer-naming mapping; A023 states log-management-contract consumes the MDC snake_case standard. Different facets (naming scheme vs consumer relationship); compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-969B85ECC5B31052D50C","evidence_a":{"line_end":215,"line_start":215,"quote":"| D19 | 동일 식별자의 표현 계층별 명명 매핑 — MDC=snake_case / envelope meta=camelCase / HTTP header=kebab-case(W3C lowercase) | [[raw/project-notes/ca-skeleton-operational-contract]] §21 (`request_id`↔`meta.requestId`↔`X-Request-Id` 매핑 등록) + §25 (envelope camelCase owner = schema-serialization) | `project-ssot` | **UNSUPPORTED_IMPL_DECISION**: 매핑 방향/케이스 선택 자체는 registry + schema-serialization 분담 결정 — 외부 표준 단일 근거 없음. resource-identifier §9 의 `user.id`/`resource.id`(dot) illustration 은 snake(`user_id`/`resource_id`)로 conform 필요 |"},"evidence_b":{"line_end":300,"line_start":300,"quote":"| request id | `request_id` (snake) | `meta.requestId` (camel) | `X-Request-Id` (kebab) |"},"proof_manifest":null,"rationale":"A011 gives the general identifier mapping (snake/camel/kebab); A028 gives the concrete request_id row instantiating that scheme. Same mapping, A028 a compatible instance detail.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-F01097F52BD64810D94E","evidence_a":{"line_end":215,"line_start":215,"quote":"| D19 | 동일 식별자의 표현 계층별 명명 매핑 — MDC=snake_case / envelope meta=camelCase / HTTP header=kebab-case(W3C lowercase) | [[raw/project-notes/ca-skeleton-operational-contract]] §21 (`request_id`↔`meta.requestId`↔`X-Request-Id` 매핑 등록) + §25 (envelope camelCase owner = schema-serialization) | `project-ssot` | **UNSUPPORTED_IMPL_DECISION**: 매핑 방향/케이스 선택 자체는 registry + schema-serialization 분담 결정 — 외부 표준 단일 근거 없음. resource-identifier §9 의 `user.id`/`resource.id`(dot) illustration 은 snake(`user_id`/`resource_id`)로 conform 필요 |"},"evidence_b":{"line_end":349,"line_start":349,"quote":"- inbound `X-Request-Id` / `X-Correlation-Id` 수신 → MDC/로그 반영 전 **CR/LF/제어문자 strip** + **length cap** (값 부재/무효 시 server 생성). 위치 = `RequestLoggingFilter` (§0)."},"proof_manifest":null,"rationale":"A011 concerns identifier naming across layers; A036 concerns inbound header sanitization (CR/LF strip + length cap). Different contract properties for the same identifiers; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-519A1A83CEE0EEDAF5CF","evidence_a":{"line_end":451,"line_start":451,"quote":"| ca-tmpl envelope 의 `meta.traceId` 가 모든 5xx/validation/auth 응답에서 누락 없이 채워짐 | foundation owner branch — 모든 ControllerAdvice/Filter 에서 동작 보장 필요 | contract test: 각 카테고리별 fixture exception 발생 → response body 의 `meta.traceId` non-empty 확인 | `planned` |"},"evidence_b":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"proof_manifest":null,"rationale":"A012 (meta.traceId populated in all 5xx/validation/auth responses) and A013 (Retry-After + retryable co-existence) are independent observability/error-contract verification claims; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-E72E6E0A2A97A289CEE6","evidence_a":{"line_end":451,"line_start":451,"quote":"| ca-tmpl envelope 의 `meta.traceId` 가 모든 5xx/validation/auth 응답에서 누락 없이 채워짐 | foundation owner branch — 모든 ControllerAdvice/Filter 에서 동작 보장 필요 | contract test: 각 카테고리별 fixture exception 발생 → response body 의 `meta.traceId` non-empty 확인 | `planned` |"},"evidence_b":{"line_end":461,"line_start":461,"quote":"| (D16) 5xx 발생 시 server span status=ERROR + `exception` 이벤트 기록, client 응답엔 stack 부재 | OTel 사양은 attribute 정의만 — 실제 SDK wiring + 응답 분리 미검증 | OTel in-memory test exporter: span status ERROR + exception event 존재; 동시에 response body 에 stacktrace 부재 grep | `planned` |"},"proof_manifest":null,"rationale":"A012 (meta.traceId population) and A014 (5xx span status=ERROR + exception event, no stack in response) address different observability guarantees; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-62A1EA3B8931BE802BD3","evidence_a":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"evidence_b":{"line_end":461,"line_start":461,"quote":"| (D16) 5xx 발생 시 server span status=ERROR + `exception` 이벤트 기록, client 응답엔 stack 부재 | OTel 사양은 attribute 정의만 — 실제 SDK wiring + 응답 분리 미검증 | OTel in-memory test exporter: span status ERROR + exception event 존재; 동시에 response body 에 stacktrace 부재 grep | `planned` |"},"proof_manifest":null,"rationale":"A013 (Retry-After/retryable co-existence) and A014 (5xx span recording + response-stack absence) are distinct planned verification claims covering different behaviors; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-924E87B41477C4735FBA","evidence_a":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"evidence_b":{"line_end":431,"line_start":431,"quote":" - **retryable=true + `Retry-After` 부재** — envelope `error.retryable: true`(503/429)인데 `Retry-After` 헤더 없으면 실패. 둘은 *함께* 존재해야 함. (D13)"},"proof_manifest":null,"rationale":"A013 and A018 both require that a retryable=true (503/429) response carry a Retry-After header alongside envelope error.retryable. Same requirement.","verdict":"CONSISTENT"},{"candidate_id":"SEM-1358C6A3456380F9229B","evidence_a":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"evidence_b":{"line_end":335,"line_start":335,"quote":"| TRANSIENT_DEPENDENCY | 503 | true | `Retry-After` (MUST, RFC9110-C21) |"},"proof_manifest":null,"rationale":"A013 states the general retryable 503/429 Retry-After co-existence; A030 supplies the specific TRANSIENT_DEPENDENCY 503 MUST instance. Compatible instantiation.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-27C760B7EB4E434B4358","evidence_a":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"evidence_b":{"line_end":339,"line_start":339,"quote":"- envelope `error.retryable: true` 와 `Retry-After` 헤더는 **함께** 존재해야 함 (envelope 만 true + 헤더 부재 = 실패)."},"proof_manifest":null,"rationale":"A013 and A031 both require Retry-After to be present whenever envelope error.retryable:true (fail if absent). Same requirement.","verdict":"CONSISTENT"},{"candidate_id":"SEM-D76E162F6332855EBE66","evidence_a":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"evidence_b":{"line_end":95,"line_start":95,"quote":"- retryable/non-retryable 기준 + 재시도 시점의 `Retry-After` surfacing (D13)."},"proof_manifest":null,"rationale":"A040 declares foundation owns the retryable criteria + Retry-After surfacing; A013 is the planned verification of that rule. A013 supplies test detail of what A040 owns.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-7CEE14F425CA0E4D0FE0","evidence_a":{"line_end":458,"line_start":458,"quote":"| (D13) retryable=true(503/429) 응답에 `Retry-After` 헤더가 envelope `error.retryable` 와 함께 존재 | RFC9110-C21 은 503/3xx 만 normative — 429 는 RFC 6585; 헤더 발행이 실제 wiring 됐는지 미검증 | contract test: 503/429 fixture → 응답 헤더 `Retry-After` non-empty + envelope retryable=true | `planned` |"},"evidence_b":{"line_end":111,"line_start":111,"quote":"- 429/`Retry-After` 운영 세부 + W3C trace context 의 propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner)."},"proof_manifest":null,"rationale":"A013 requires Retry-After co-existence for 503/429; A043 delegates the 429/Retry-After operational specifics to rate-limit-idempotency. The delegated 429 slice coexists with the general co-existence invariant; scopes complement.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-D140AA4B90BD53CBBAEA","evidence_a":{"line_end":461,"line_start":461,"quote":"| (D16) 5xx 발생 시 server span status=ERROR + `exception` 이벤트 기록, client 응답엔 stack 부재 | OTel 사양은 attribute 정의만 — 실제 SDK wiring + 응답 분리 미검증 | OTel in-memory test exporter: span status ERROR + exception event 존재; 동시에 response body 에 stacktrace 부재 grep | `planned` |"},"evidence_b":{"line_end":430,"line_start":430,"quote":" - **5xx vs 4xx span 처리** — 모든 5xx(`INTERNAL`/`PERMANENT_DEPENDENCY`/`TRANSIENT_DEPENDENCY`)는 server span `status=ERROR` + `exception` 이벤트. **4xx 는 span ERROR 아님**(unset/OK). client 응답엔 stack 미포함. (D16 Q10/Q11)"},"proof_manifest":null,"rationale":"A014 and A017 both state 5xx yields server span status=ERROR + exception event with no stack in the client response (A017 additionally notes 4xx is not ERROR). Same failure behavior.","verdict":"CONSISTENT"},{"candidate_id":"SEM-2779466E2F879DFD67D7","evidence_a":{"line_end":461,"line_start":461,"quote":"| (D16) 5xx 발생 시 server span status=ERROR + `exception` 이벤트 기록, client 응답엔 stack 부재 | OTel 사양은 attribute 정의만 — 실제 SDK wiring + 응답 분리 미검증 | OTel in-memory test exporter: span status ERROR + exception event 존재; 동시에 response body 에 stacktrace 부재 grep | `planned` |"},"evidence_b":{"line_end":362,"line_start":362,"quote":"- **모든 5xx** 발생 시 server span 에 `exception` 이벤트(`exception.type`/`exception.message`/`exception.stacktrace`) 기록 + span `status=ERROR`. 4xx 는 대상 아님."},"proof_manifest":null,"rationale":"A014 and A032 both state 5xx records a server span exception event with span status=ERROR and excludes stack from the client response. Same failure behavior.","verdict":"CONSISTENT"},{"candidate_id":"SEM-4613B311C98244AC9733","evidence_a":{"line_end":462,"line_start":462,"quote":"| (D17) `error.code` rename/삭제/재사용 시 compatibility 검사 실패 | never-reuse 는 정책 — registry-governance 자동 게이트 미검증 | error-codes.yaml diff gate (removed/renamed code 검출 시 build 실패) — registry-governance owner | `needs-confirmation` |"},"evidence_b":{"line_end":371,"line_start":371,"quote":"- `error.code` 는 **append-only** — rename / 의미 변경 / 재사용 금지. 폐기는 삭제가 아니라 deprecated 표시 + compatibility 절차."},"proof_manifest":null,"rationale":"A015 (compatibility gate fails on error.code rename/delete/reuse) and A034 (error.code append-only, no rename/reuse) enforce the same never-reuse policy. Same rule.","verdict":"CONSISTENT"},{"candidate_id":"SEM-C8C5E206F886078FC0D4","evidence_a":{"line_end":430,"line_start":430,"quote":" - **5xx vs 4xx span 처리** — 모든 5xx(`INTERNAL`/`PERMANENT_DEPENDENCY`/`TRANSIENT_DEPENDENCY`)는 server span `status=ERROR` + `exception` 이벤트. **4xx 는 span ERROR 아님**(unset/OK). client 응답엔 stack 미포함. (D16 Q10/Q11)"},"evidence_b":{"line_end":362,"line_start":362,"quote":"- **모든 5xx** 발생 시 server span 에 `exception` 이벤트(`exception.type`/`exception.message`/`exception.stacktrace`) 기록 + span `status=ERROR`. 4xx 는 대상 아님."},"proof_manifest":null,"rationale":"A017 and A032 both state all 5xx produce a server span exception event + span status=ERROR while 4xx is excluded. Same failure behavior.","verdict":"CONSISTENT"},{"candidate_id":"SEM-F614288667D1510A99CB","evidence_a":{"line_end":431,"line_start":431,"quote":" - **retryable=true + `Retry-After` 부재** — envelope `error.retryable: true`(503/429)인데 `Retry-After` 헤더 없으면 실패. 둘은 *함께* 존재해야 함. (D13)"},"evidence_b":{"line_end":335,"line_start":335,"quote":"| TRANSIENT_DEPENDENCY | 503 | true | `Retry-After` (MUST, RFC9110-C21) |"},"proof_manifest":null,"rationale":"A018 gives the general retryable→Retry-After co-existence rule; A030 supplies the specific TRANSIENT_DEPENDENCY 503 MUST instance. Compatible instantiation.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-84D91A65870BB263042A","evidence_a":{"line_end":431,"line_start":431,"quote":" - **retryable=true + `Retry-After` 부재** — envelope `error.retryable: true`(503/429)인데 `Retry-After` 헤더 없으면 실패. 둘은 *함께* 존재해야 함. (D13)"},"evidence_b":{"line_end":339,"line_start":339,"quote":"- envelope `error.retryable: true` 와 `Retry-After` 헤더는 **함께** 존재해야 함 (envelope 만 true + 헤더 부재 = 실패)."},"proof_manifest":null,"rationale":"A018 and A031 both require that envelope error.retryable:true be accompanied by a Retry-After header (fail if absent). Same requirement, same scope.","verdict":"CONSISTENT"},{"candidate_id":"SEM-CA542189FF8DD78BEFA8","evidence_a":{"line_end":431,"line_start":431,"quote":" - **retryable=true + `Retry-After` 부재** — envelope `error.retryable: true`(503/429)인데 `Retry-After` 헤더 없으면 실패. 둘은 *함께* 존재해야 함. (D13)"},"evidence_b":{"line_end":95,"line_start":95,"quote":"- retryable/non-retryable 기준 + 재시도 시점의 `Retry-After` surfacing (D13)."},"proof_manifest":null,"rationale":"A040 declares foundation owns the retryable criteria + Retry-After surfacing; A018 supplies the concrete envelope/header co-existence rule. A018 details what A040 owns.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-028201FBFC6A1FFE1B4B","evidence_a":{"line_end":431,"line_start":431,"quote":" - **retryable=true + `Retry-After` 부재** — envelope `error.retryable: true`(503/429)인데 `Retry-After` 헤더 없으면 실패. 둘은 *함께* 존재해야 함. (D13)"},"evidence_b":{"line_end":111,"line_start":111,"quote":"- 429/`Retry-After` 운영 세부 + W3C trace context 의 propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner)."},"proof_manifest":null,"rationale":"A018 states the retryable Retry-After co-existence rule; A043 delegates the 429/Retry-After operational specifics to rate-limit-idempotency. The narrow 429 delegation coexists with the general invariant; scopes complement.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-51578CF67427046088EE","evidence_a":{"line_end":437,"line_start":437,"quote":" - [[raw/branch-notes/feature-security-operational-baseline]] 의 `D18` 에 의존 — `WWW-Authenticate` 헤더 *발행 정책* owner. 본 branch 는 401 enum row 가 헤더 의무를 암시함만 명시(bare 401 금지). 발행 방식 변경 시 §9 cross-cite 갱신 필요."},"evidence_b":{"line_end":379,"line_start":379,"quote":"- `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (bare 401 금지). 헤더 *발행 정책* 은 security-operational-baseline owner — 본 branch 는 enum 의 401 row 가 헤더 의무를 암시함을 명시만."},"proof_manifest":null,"rationale":"A021 delegates WWW-Authenticate publishing to security-operational-baseline; A035 states the 401 requirement and attributes the publishing policy to that same owner. Same delegation/authority; consistent.","verdict":"CONSISTENT"},{"candidate_id":"SEM-1F3D6E77794CE72A1D33","evidence_a":{"line_end":437,"line_start":437,"quote":" - [[raw/branch-notes/feature-security-operational-baseline]] 의 `D18` 에 의존 — `WWW-Authenticate` 헤더 *발행 정책* owner. 본 branch 는 401 enum row 가 헤더 의무를 암시함만 명시(bare 401 금지). 발행 방식 변경 시 §9 cross-cite 갱신 필요."},"evidence_b":{"line_end":108,"line_start":108,"quote":"- JWT 세부 인증 실패 분류 + `WWW-Authenticate` 헤더 발행 (security-operational-baseline owner — D18 은 cross-cite 만)."},"proof_manifest":null,"rationale":"A021 and A041 both delegate WWW-Authenticate header publishing (out of foundation scope) to security-operational-baseline. Same subject, predicate, scope, and target owner.","verdict":"CONSISTENT"},{"candidate_id":"SEM-99444518D74392473F05","evidence_a":{"line_end":300,"line_start":300,"quote":"| request id | `request_id` (snake) | `meta.requestId` (camel) | `X-Request-Id` (kebab) |"},"evidence_b":{"line_end":349,"line_start":349,"quote":"- inbound `X-Request-Id` / `X-Correlation-Id` 수신 → MDC/로그 반영 전 **CR/LF/제어문자 strip** + **length cap** (값 부재/무효 시 server 생성). 위치 = `RequestLoggingFilter` (§0)."},"proof_manifest":null,"rationale":"A028 gives the request_id representation-layer mapping; A036 gives inbound X-Request-Id sanitization (strip + length cap). Different properties of the same identifier; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-894C51D330DA3E7185BF","evidence_a":{"line_end":335,"line_start":335,"quote":"| TRANSIENT_DEPENDENCY | 503 | true | `Retry-After` (MUST, RFC9110-C21) |"},"evidence_b":{"line_end":339,"line_start":339,"quote":"- envelope `error.retryable: true` 와 `Retry-After` 헤더는 **함께** 존재해야 함 (envelope 만 true + 헤더 부재 = 실패)."},"proof_manifest":null,"rationale":"A030 supplies the specific TRANSIENT_DEPENDENCY 503 Retry-After MUST; A031 the general envelope retryable:true co-existence rule. A030 instantiates A031; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-B65B987B005CC7359063","evidence_a":{"line_end":335,"line_start":335,"quote":"| TRANSIENT_DEPENDENCY | 503 | true | `Retry-After` (MUST, RFC9110-C21) |"},"evidence_b":{"line_end":95,"line_start":95,"quote":"- retryable/non-retryable 기준 + 재시도 시점의 `Retry-After` surfacing (D13)."},"proof_manifest":null,"rationale":"A040 declares foundation owns retryable criteria + Retry-After surfacing; A030 supplies the specific 503 MUST instance. Compatible detail of the owned rule.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-CE749FF29D98A0672E6E","evidence_a":{"line_end":335,"line_start":335,"quote":"| TRANSIENT_DEPENDENCY | 503 | true | `Retry-After` (MUST, RFC9110-C21) |"},"evidence_b":{"line_end":111,"line_start":111,"quote":"- 429/`Retry-After` 운영 세부 + W3C trace context 의 propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner)."},"proof_manifest":null,"rationale":"A030 mandates Retry-After for TRANSIENT_DEPENDENCY 503 (owned); A043 delegates the 429/Retry-After operational specifics elsewhere. Different categories (503 owned vs 429 delegated); scopes complement.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-727564B5D480838AD626","evidence_a":{"line_end":339,"line_start":339,"quote":"- envelope `error.retryable: true` 와 `Retry-After` 헤더는 **함께** 존재해야 함 (envelope 만 true + 헤더 부재 = 실패)."},"evidence_b":{"line_end":95,"line_start":95,"quote":"- retryable/non-retryable 기준 + 재시도 시점의 `Retry-After` surfacing (D13)."},"proof_manifest":null,"rationale":"A040 declares foundation owns retryable criteria + Retry-After surfacing; A031 supplies the concrete envelope retryable:true co-existence rule. A031 details what A040 owns.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-1D419A42159A1B17FFF6","evidence_a":{"line_end":339,"line_start":339,"quote":"- envelope `error.retryable: true` 와 `Retry-After` 헤더는 **함께** 존재해야 함 (envelope 만 true + 헤더 부재 = 실패)."},"evidence_b":{"line_end":111,"line_start":111,"quote":"- 429/`Retry-After` 운영 세부 + W3C trace context 의 propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner)."},"proof_manifest":null,"rationale":"A031 states the general retryable:true Retry-After co-existence; A043 delegates the 429 operational specifics to rate-limit-idempotency. Narrow 429 delegation coexists with the general invariant; scopes complement.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-E0BEFE8F1ED0A861B998","evidence_a":{"line_end":379,"line_start":379,"quote":"- `AUTH`(401) 응답은 `WWW-Authenticate` 헤더 동반 (bare 401 금지). 헤더 *발행 정책* 은 security-operational-baseline owner — 본 branch 는 enum 의 401 row 가 헤더 의무를 암시함을 명시만."},"evidence_b":{"line_end":108,"line_start":108,"quote":"- JWT 세부 인증 실패 분류 + `WWW-Authenticate` 헤더 발행 (security-operational-baseline owner — D18 은 cross-cite 만)."},"proof_manifest":null,"rationale":"A035 requires WWW-Authenticate on 401 and attributes publishing policy to security-operational-baseline; A041 delegates that publishing to the same owner. Same requirement and same authority attribution.","verdict":"CONSISTENT"},{"candidate_id":"SEM-BAB8EED3AE78CB98F290","evidence_a":{"line_end":350,"line_start":350,"quote":"- inbound `traceparent` 수신 → W3C 4-field format(`W3C-TC-C2`) 검증. 무효 형식이면 **새 trace 시작** (client 값 무시 — Micrometer propagator 위임). 유효하면 propagation 의무(`W3C-TC-C5`)."},"evidence_b":{"line_end":351,"line_start":351,"quote":"- `tracestate` 에 PII 금지(`W3C-TC-C5` MUST NOT) — outbound 전파 시 동일."},"proof_manifest":null,"rationale":"A037 validates inbound traceparent (W3C 4-field, restart on invalid); A038 forbids PII in tracestate. Different W3C trace-context constraints; compatible.","verdict":"COMPLEMENTARY"},{"candidate_id":"SEM-4B57C669075B5D83F9EB","evidence_a":{"line_end":95,"line_start":95,"quote":"- retryable/non-retryable 기준 + 재시도 시점의 `Retry-After` surfacing (D13)."},"evidence_b":{"line_end":111,"line_start":111,"quote":"- 429/`Retry-After` 운영 세부 + W3C trace context 의 propagation/span 세부 (rate-limit-idempotency / distributed-tracing owner)."},"proof_manifest":null,"rationale":"A040 declares foundation owns the general retryable criteria + Retry-After surfacing; A043 delegates only the 429/Retry-After operational specifics (and W3C span detail) to other owners. Clean scope split — general contract owned, narrow operational slice delegated; no takeover of the owned responsibility.","verdict":"COMPLEMENTARY"}]},"auditor":{"contract_version":"semantic-coherence/v1","model_id":"claude-opus-4-8","run_id":"a4be5e6fb9933e916"},"auditor_contract_sha256":"1cbc67c27e5183a272687f635e3682a26d56785a1cf144da562eb7edd8f6cbce","coverage":{"candidate_pairs":52,"dropped_pairs":0,"eligible_surfaces":6,"processed_pairs":52,"processed_surfaces":6},"document_id":"d21d3ca6a7591b5e14a2c66eec2554a0c67e94a04e870669ed1f49ec9c81f4b6","document_sha256":"e7934a7e7d271d8f1d066181cbc3789577a309bd926310745c25a0bc14748049","findings":{"blocking":0,"readiness_blocking":0,"verified":0},"mode":"local","ontology_sha256":"5d601b96f0ca4d75eea89e9086c38e3acf2c4f0c7833846ef58c6a5719603126","policy_sha256":"0465598e9c1c4f2c3400ba51bf4719aa4890d60d56dc83304fb2224e660562b7","proof_manifest_sha256":"37517e5f3dc66819f61f5a7bb8ace1921282415f10551d2defa5c3eb0985b570","schema_version":"semantic-certificate/v1","semantic_audit_sha256":"51d83b09626bf0b8d3e6b304248a14cdef6c738f7be13577d80f240acf51ea55","subject":"raw/branch-notes/feature-operational-error-observability-foundation.md","typed_contract_graph_sha256":"481fc3335a494c454ab13ad1d6a6ddccdec99aa8e083f6720ff8886bfa19cc89","verdict":"PASS"}