SCF corpus backlog
Version: 0.1 · reviewed 2026-08-07
Known gaps in the corpus itself, recorded here rather than left implicit. Each
item is a defect of the standard, not of a product built with it. The corpus
requires evidence for its own claims (SCF-GOV-006), so it must also state
where it is not yet complete.
Structural
| # | Item | Effect | Priority |
|---|---|---|---|
| B-01 | The baseline verification corpus in EVALUATION.md §3 names no method for parts of SCF-GOV, SCF-BLD, SCF-HWE, SCF-LCM, SCF-VUL, SCF-NET, SCF-CRY, SCF-SPC, SCF-IDN, SCF-OPS, SCF-DAT, SCF-PRV and SCF-BOOT. The Constitution now says the product must supply the missing methods, which is correct but shifts work downstream. | conformance claims are uneven between products | high |
| B-02 | Several requirements bundle three to five independently verifiable obligations (SCF-BOOT-004, SCF-CRY-003, SCF-BLD-006, SCF-EVD-004, SCF-ART-001, SCF-UPD-002). HIF requirements are atomic. | line-by-line traceability is harder than it should be | medium |
| B-03 | Requirement headings are not yet uniformly noun phrases; a residue of sentence-style headings remains. | style divergence from HIF | low |
| B-04 | Profiles impose obligations with no Constitution counterpart: session-data destruction between users, reporting of image size and installed surface per release, decommissioning procedure beyond erasure. Either promote them or mark them as profile-local. | profile requirements outrank the Constitution in practice | medium |
| B-05 | Additional evidence named in profiles — escape-attempt corpus, power-loss during update, shared-secret comparison — has no entry in the baseline corpus. | the gate is defined in two places | medium |
Content
| # | Item | Priority |
|---|---|---|
| B-06 | The planned documents listed in en/README.md do not exist. Until they do, their subjects are governed by the Constitution alone, with no method, template or worked detail. | high |
| B-07 | No product profile template and no release record template exist, although SCF-EVD-004 requires a release record. | high |
| B-08 | REFERENCES.md does not exist. Regulatory and standards citations currently live in the research dossier under docs/research/, outside the corpus. | high |
| B-09 | Backup and restore (SCF-DAT-008) is documentation-only at Constitution level; profiles that need a shipped mechanism must say so themselves. | low |
| B-10 | Supply-chain requirements name provenance and attestation but no assurance level; a graded scale would make SCF-ART-003 measurable. | medium |
Language
| # | Item | Priority |
|---|---|---|
| B-11 | The Russian edition is a translation of the English; the English is authoritative. Identifier parity is verified mechanically, wording parity is not. | medium |
| B-12 | Terminology for the new subject area is not yet fixed in a glossary the way HIF fixes its own. | medium |
Review procedure
Before each corpus release: re-run the identifier and structure parity check
between en/ and ru/, re-read the regulatory dates, and close or re-date
every item above. An item that has been open for two corpus releases without a
decision is escalated to the corpus owner.