# GH-PNCC failure receipt error-code evidence binding - Development ID: `DEV-20260810-014` - Persona cognitive author: `ICE-P-ZY001 / 铸渊` - Human responsibility subject: `ICE-GL∞ / 冰朔` - Starting repository head: `1cd8a1b48951775530143c61a3af2d11215d4921` - State: `LOCAL_SOURCE_IMPLEMENTED_FOCUSED_TESTED` ## Corrected runtime fact Failure receipt validation bound repository, terminal event and attribution, but only checked that `errorCode` looked like a stable machine code. A modified receipt could replace the real failure with another syntactically valid code, recompute the outer payload digest and still be accepted for safe binding or replay. The runtime now records the normalized terminal failure code in the same verified session record before writing the immutable failure receipt. Receipt persistence, inspection, recovery binding, replay and post-inspection binding revalidation require the receipt code to equal that exact session-bound value. ## Verification - A regression test first reproduced `SAFE_BIND_PERSISTED_RECEIPT` after changing the real inference failure to `AUTHORIZATION_GRANTED` and recomputing the payload digest. - The same forged receipt now fails with `PERSONA_LIFECYCLE_FAILURE_TERMINAL_EVIDENCE_MISMATCH`. - PNCC focused Rust tests: `52 passed, 0 failed`, including interrupted failure-receipt recovery. - Full Rust suite: `1192 passed, 2 ignored`; integration test: `1 passed`. - Routing suite: `29 passed`; formatting, strict clippy and diff checks passed. - Full product quality, publication and fresh-clone readback remain pending. ## Truth boundary - This stage binds the already externalized stable failure code; raw provider details remain excluded. - It does not expose hidden reasoning, activate an execution limb, add UI, build an artifact or claim deployment/runtime health.