Validation Pack: AOR-3b, generated-document versions and trackable scope

Unit: applied-ontology-readiness Follows: AOR-3, whose job-family item was deferred Decision: ADR-A86 addendum, item 5 (content-hash versions, agreed by the human 2026-09-25)

Invariant

A generated ontology document’s version IRI changes exactly when its content does. The version check and the catalog read only files git tracks or would track, so neither depends on one machine’s build output.

Test cases

ID Given / When / Then Level +/-
AOR3B-01 the job-family surface / rendered / every module’s version IRI is its ontology IRI plus 16 hex digits L1 +
AOR3B-02 same / rendered twice / versions unchanged L2 +
AOR3B-03 a law discharge added after compilation / rendered / manifest version changes, core version does not L1 -
AOR3B-04 an ignored execution/ document importing an undeclared IRI / catalog check / no problem, not catalogued L1 +
AOR3B-05 this repository / catalog check / consistent, no job-family entries L1 +

Commands

python -m unittest surface.test_surface
mise run check:ontology-catalog
mise run check:mtp

Pass: 63 Surface tests, 12 catalog tests and a consistent catalog with three known defects (the insurance sketch and two MORK examples), and MTP structural checks passed.

Artefacts to inspect

Adversarial probe (run by the agent)

A constant version suffix failed AOR3B-03. Scanning with rglob again failed AOR3B-04 and AOR3B-05.

MTP pin

pins.lock.json records a hash of the whole Mork.ttl graph and one per term, so any change to MORK is reviewed deliberately. 53eb210 changed the header (version IRI, Foundation import) without re-pinning, and this change set changed it again. python -m mtp.cli update-pins re-pinned it. The aggregate mise run check runs build:mtp before check:mtp, and build also rewrites the pins, so the pin check can fail only in CI. Separating build from update-pins is an MTP pins decision, which docs/architecture/mork-teaching-pack.md reserves for an ADR, and is not made here.