﻿{
    "schemaVersion":  1,
    "product":  "Simo Windows Control Center",
    "sourceMatrix":  "CLAIM-EVIDENCE.json",
    "contracts":  [
                      {
                          "contractId":  "CONTRACT-APP-7ZIP-V106-STABLE",
                          "capability":  "apps.install.detect.idempotency",
                          "actionId":  "app:7zip.7zip",
                          "environmentIds":  [
                                                 "win11-enterprise-eval-25h2-x64-gex44-lab"
                                             ],
                          "evidenceCaseIds":  [
                                                  "APP-INSTALL-DETECT-IDEMPOTENCY-7ZIP-001"
                                              ],
                          "precondition":  "7zip.7zip absent from Winget installed package state and C:\\Program Files\\7-Zip\\7z.exe absent.",
                          "expectedPlan":  "WILL_CHANGE",
                          "expectedMutation":  "Install 7zip.7zip through Winget when the package is absent.",
                          "expectedPostcondition":  "C:\\Program Files\\7-Zip\\7z.exe exists and Winget exact package state contains 7zip.7zip.",
                          "expectedSecondRunState":  "ALREADY_COMPLIANT plan followed by SKIPPED_ALREADY_COMPLIANT apply.",
                          "expectedRollback":  "NOT_PROVEN for app uninstall or package rollback in this evidence slice.",
                          "expectedFailureState":  "Detection, install, or verification failures must fail-closed with no false success token.",
                          "independentReadback":  "Filesystem readback for 7z.exe plus Winget package state.",
                          "sideEffectBoundary":  "Only the 7-Zip installation state is proven; broader package-manager side effects are not proven.",
                          "notProven":  [
                                            "uninstall rollback",
                                            "all package managers",
                                            "de-DE locale",
                                            "Winget unavailable/outdated/source outage"
                                        ],
                          "artifactScope":  "PUBLIC_STABLE_ZIP_V1.0.6",
                          "publicationStatus":  "EXTERNAL_STABLE_PROMOTION_EVIDENCE_REQUIRED",
                          "verdict":  "EXTERNAL_STABLE_EVIDENCE_REQUIRED",
                          "publicClaimAllowed":  false
                      },
                      {
                          "contractId":  "CONTRACT-CLEANUP-USER-TEMP-V106-STABLE",
                          "capability":  "cleanup.estimate.apply.idempotency.sideEffectBoundary",
                          "actionId":  "cleanup:user-temp",
                          "environmentIds":  [
                                                 "win11-enterprise-eval-25h2-x64-gex44-lab"
                                             ],
                          "evidenceCaseIds":  [
                                                  "CLEANUP-USER-TEMP-CONTROLLED-SIDE-EFFECT-001"
                                              ],
                          "precondition":  "TEMP and TMP point to controlled root C:\\swcc-e2e-cleanup-temp with seeded cleanup children and an outside-root sentinel present.",
                          "expectedPlan":  "WILL_CHANGE",
                          "expectedMutation":  "Delete seeded cleanup children inside the controlled user temp root.",
                          "expectedPostcondition":  "zero temp children remain inside the controlled root and the outside-root sentinel remains unchanged.",
                          "expectedSecondRunState":  "ALREADY_COMPLIANT after first cleanup removes the seeded children.",
                          "expectedRollback":  "NOT_APPLICABLE: cleanup deletion is not represented as reversible rollback in this evidence slice.",
                          "expectedFailureState":  "Cleanup discovery or deletion failures must fail-closed with no false success token.",
                          "independentReadback":  "Filesystem pre/post count for the controlled temp root plus sentinel file readback.",
                          "sideEffectBoundary":  "Mutation is bounded to the controlled temp root; sentinel outside that root must remain unchanged.",
                          "notProven":  [
                                            "all user temp layouts",
                                            "log write failure",
                                            "low disk",
                                            "read-only cleanup target"
                                        ],
                          "artifactScope":  "PUBLIC_STABLE_ZIP_V1.0.6",
                          "publicationStatus":  "EXTERNAL_STABLE_PROMOTION_EVIDENCE_REQUIRED",
                          "verdict":  "EXTERNAL_STABLE_EVIDENCE_REQUIRED",
                          "publicClaimAllowed":  false
                      },
                      {
                          "contractId":  "CONTRACT-DEBLOAT-WINDOWSSTORE-PROTECTED-V106-STABLE",
                          "capability":  "debloat.protectedTarget.failClosed",
                          "actionId":  "debloat:Microsoft.WindowsStore",
                          "environmentIds":  [
                                                 "win11-enterprise-eval-25h2-x64-gex44-lab"
                                             ],
                          "evidenceCaseIds":  [
                                                  "DEBLOAT-PROTECTED-WINDOWSSTORE-BLOCKED-NO-MUTATION-001"
                                              ],
                          "precondition":  "Microsoft.WindowsStore is installed/provisioned before the protected debloat action.",
                          "expectedPlan":  "BLOCKED",
                          "expectedMutation":  "none; protected package must not be removed.",
                          "expectedPostcondition":  "Microsoft.WindowsStore AppX installed/provisioned counts and names remain unchanged.",
                          "expectedSecondRunState":  "BLOCKED again with no mutation; no compliant removal state is allowed for this protected target.",
                          "expectedRollback":  "NOT_APPLICABLE: blocked action performs no mutation to roll back.",
                          "expectedFailureState":  "Protected target is blocked, apply completes with blocks, action status blocked, changed=false.",
                          "independentReadback":  "AppX installed/provisioned counts and names before and after.",
                          "sideEffectBoundary":  "No AppX/provisioned package mutation is allowed for Microsoft.WindowsStore in this contract.",
                          "notProven":  [
                                            "safe removable debloat target",
                                            "Home/Pro Store protection behavior",
                                            "standard-user privilege path"
                                        ],
                          "artifactScope":  "PUBLIC_STABLE_ZIP_V1.0.6",
                          "publicationStatus":  "EXTERNAL_STABLE_PROMOTION_EVIDENCE_REQUIRED",
                          "verdict":  "EXTERNAL_STABLE_EVIDENCE_REQUIRED",
                          "publicClaimAllowed":  false
                      },
                      {
                          "contractId":  "CONTRACT-FEATURE-SANDBOX-PLAN-V106-STABLE",
                          "capability":  "features.plan.dryRun.rebootContract",
                          "actionId":  "feature:Containers-DisposableClientVM",
                          "environmentIds":  [
                                                 "win11-enterprise-eval-25h2-x64-gex44-lab"
                                             ],
                          "evidenceCaseIds":  [
                                                  "FEATURE-WINDOWS-SANDBOX-PLAN-REBOOT-CONTRACT-001"
                                              ],
                          "precondition":  "Containers-DisposableClientVM Windows optional feature is Disabled by DISM before SWCC planning.",
                          "expectedPlan":  "WILL_CHANGE Enable RequiresAdmin=true RequiresReboot=true RebootLikely=true",
                          "expectedMutation":  "dry-run only; no feature enable mutation is performed in this evidence slice.",
                          "expectedPostcondition":  "DISM feature state remains Disabled after SWCC dry-run.",
                          "expectedSecondRunState":  "NOT_PROVEN for real apply; dry-run may be repeated without mutation.",
                          "expectedRollback":  "NOT_PROVEN for real feature enable, reboot, disable, or rollback.",
                          "expectedFailureState":  "Unsupported feature or enable failure must fail-closed with no false success token.",
                          "independentReadback":  "DISM/Get-WindowsOptionalFeature state before and after remained Disabled.",
                          "sideEffectBoundary":  "No feature state mutation is allowed during dry-run.",
                          "notProven":  [
                                            "real feature enable",
                                            "reboot continuation",
                                            "feature rollback",
                                            "unsupported edition behavior"
                                        ],
                          "artifactScope":  "PUBLIC_STABLE_ZIP_V1.0.6",
                          "publicationStatus":  "EXTERNAL_STABLE_PROMOTION_EVIDENCE_REQUIRED",
                          "verdict":  "EXTERNAL_STABLE_EVIDENCE_REQUIRED",
                          "publicClaimAllowed":  false
                      },
                      {
                          "contractId":  "CONTRACT-FAILURE-PROFILE-CATALOG-V106-STABLE",
                          "capability":  "profiles.catalogs.failureHandling.noFalseSuccess",
                          "actionId":  "failure:profile-catalog",
                          "environmentIds":  [
                                                 "win11-enterprise-eval-25h2-x64-gex44-lab"
                                             ],
                          "evidenceCaseIds":  [
                                                  "FAILURE-PROFILE-CATALOG-NO-FALSE-SUCCESS-001"
                                              ],
                          "precondition":  "Guest starts with Windows Sandbox Disabled and 7z.exe command unavailable before invalid profile and invalid app/catalog ID checks.",
                          "expectedPlan":  "CONTROLLED_FAILURE",
                          "expectedMutation":  "none; invalid inputs must fail before system mutation.",
                          "expectedPostcondition":  "Windows Sandbox feature state remains Disabled and 7z.exe command remains unavailable.",
                          "expectedSecondRunState":  "CONTROLLED_FAILURE repeat is expected for the same malformed profile or invalid package ID.",
                          "expectedRollback":  "NOT_APPLICABLE: failure path performs no mutation to roll back.",
                          "expectedFailureState":  "nonzero exit with expected error text, no JSON success objects, no success tokens, and no mutation.",
                          "independentReadback":  "DISM feature state and command discovery for 7z.exe before and after.",
                          "sideEffectBoundary":  "Independent state remains unchanged across invalid profile/catalog failure paths.",
                          "notProven":  [
                                            "full adversarial failure matrix",
                                            "permission denied",
                                            "network interruption",
                                            "process timeout",
                                            "support report write failure"
                                        ],
                          "artifactScope":  "PUBLIC_STABLE_ZIP_V1.0.6",
                          "publicationStatus":  "EXTERNAL_STABLE_PROMOTION_EVIDENCE_REQUIRED",
                          "verdict":  "EXTERNAL_STABLE_EVIDENCE_REQUIRED",
                          "publicClaimAllowed":  false
                      },
                      {
                          "contractId":  "CONTRACT-TWEAK-HIDEFILEEXT-RC1-EVIDENCE",
                          "capability":  "tweaks.registryDword.apply.idempotency.rollback",
                          "actionId":  "tweak:explorer.show-file-extensions",
                          "environmentIds":  [
                                                 "win11-enterprise-eval-25h2-x64-gex44-lab"
                                             ],
                          "evidenceCaseIds":  [
                                                  "TWEAK-REGISTRY-APPLY-IDEMPOTENCY-ROLLBACK-001"
                                              ],
                          "precondition":  "HKCU Explorer Advanced HideFileExt=1 before applying explorer.show-file-extensions.",
                          "expectedPlan":  "WILL_CHANGE",
                          "expectedMutation":  "Set HKCU Explorer Advanced HideFileExt from 1 to 0.",
                          "expectedPostcondition":  "Direct registry readback reports HideFileExt=0.",
                          "expectedSecondRunState":  "ALREADY_COMPLIANT for the same desired registry DWORD state.",
                          "expectedRollback":  "Rollback restores HideFileExt=1 from captured pre-state.",
                          "expectedFailureState":  "Registry write or verification failure must fail-closed with no false success token.",
                          "independentReadback":  "Direct HKCU Explorer Advanced HideFileExt registry readback.",
                          "sideEffectBoundary":  "Only scoped HKCU Explorer Advanced property changes are covered; broader registry side effects are not proven.",
                          "notProven":  [
                                            "global rollback",
                                            "all tweaks",
                                            "standard-user denied write path",
                                            "de-DE locale"
                                        ],
                          "artifactScope":  "PUBLIC_STABLE_ZIP_V1.0.6",
                          "publicationStatus":  "EXTERNAL_STABLE_PROMOTION_EVIDENCE_REQUIRED",
                          "verdict":  "EXTERNAL_STABLE_EVIDENCE_REQUIRED",
                          "publicClaimAllowed":  false
                      },
                      {
                          "contractId":  "CONTRACT-HOME-PC-PUBLIC-DOWNLOAD",
                          "capability":  "publicDownload.homePc.acceptance",
                          "actionId":  "public-download:home-pc-acceptance",
                          "environmentIds":  [
                                                 "home-pc-public-download-acceptance"
                                             ],
                          "artifactScope":  "PUBLIC_STABLE_ZIP_V1.0.6",
                          "publicationStatus":  "EXTERNAL_STABLE_PROMOTION_EVIDENCE_REQUIRED",
                          "verdict":  "EXTERNAL_STABLE_EVIDENCE_REQUIRED",
                          "publicClaimAllowed":  false,
                          "evidenceCaseIds":  [
                                                  "HOME-PC-PUBLIC-DOWNLOAD-ACCEPTANCE"
                                              ],
                          "precondition":  "Public stable ZIP is downloaded from the website and verified against release metadata and SHA256SUMS.",
                          "expectedPlan":  "Acceptance runner verifies public metadata, extracts the package, runs self-check, and exercises bounded representative workflows.",
                          "expectedMutation":  "Only explicitly selected reversible or controlled acceptance mutations are allowed.",
                          "expectedPostcondition":  "Independent readbacks prove the requested state and no unsupported public claim is inferred.",
                          "expectedSecondRunState":  "Idempotent or blocked repeat behavior is recorded per action where applicable.",
                          "expectedRollback":  "Cleanup restores reversible acceptance mutations and records any non-reversible scope as unsupported.",
                          "expectedFailureState":  "Failures must be fail-closed with no false success token.",
                          "independentReadback":  "Hash, filesystem, Winget, AppX, registry, profile, support-report, and health-check readbacks as applicable.",
                          "sideEffectBoundary":  "Only action-contract-scoped mutations are allowed; unexpected changes block stable promotion.",
                          "notProven":  [
                                            "universal Windows support",
                                            "unsigned binary trust beyond SHA-256 verification",
                                            "global rollback for every action",
                                            "unsupported Windows versions or architectures"
                                        ]
                      }
                  ],
    "asOf":  "2026-09-01",
    "status":  "STABLE_CHANNEL_EXTERNAL_EVIDENCE_REQUIRED",
    "publicClaimsAllowed":  false,
    "contractRule":  "Stable-channel action claims require exact-artifact external evidence. Each public claim must match release metadata, public download evidence, disposable E2E evidence, Home-PC acceptance evidence, and the action boundary named by this contract."
}
