> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/5.-lpp-admission-kernel/5.13-layer-0-layer-1-interface.md).

# 5.13 Layer 0 / Layer 1 Interface

The Layer 0 / Layer 1 interface separates legitimacy determination from runtime execution governance.

The rule is:

> **Layer 0 determines admissibility.**

> **Layer 1 enforces the resulting constrained execution boundary.**

#### Layer 0 Output

Layer 0 returns:

```
AD ∈ {
    Admit(EP),
    Deny(r),
    Defer(r),
    Collapse(r)
}
```

Only:

```
Admit(EP)
```

contains a valid Execution Permit for the normal execution path.

#### Layer 1 Enforcement

Layer 1 execution is permitted only if a valid Execution Permit exists.

The formal baseline is:

```
Execute₁(a) permitted
⇔
∃ EP such that:

valid(EP)
∧ scope(a) ⊆ scope(EP)
∧ now ∈ validity(EP)
∧ ¬revoked(EP)
```

#### Layer 1 May Restrict Further

Layer 1 may add runtime controls.

For example:

```
Layer 0 Permit:
write to service A
```

Layer 1 may decide:

```
Temporary runtime security state
requires read-only mode.
```

That additional restriction is permitted.

#### Layer 1 May Not Expand

Layer 1 may not transform:

```
Permit:
service A only
```

into:

```
Runtime authorization:
service A + service B + production network
```

The rule is:

```
Layer 1
may restrict
but may not expand
Layer 0 Permit scope.
```

#### Invalid Permit

If Layer 1 receives:

* an invalid Permit,
* expired Permit,
* unverifiable signature,
* mismatched scope,
* mismatched execution environment,
* or other invalid authorization state,

execution must not proceed.

#### Failure Boundary

The original operational semantics defines a baseline failure taxonomy covering conditions such as:

* Admission Kernel unavailable,
* authority-resolution timeout,
* malformed request,
* malformed Authority Object,
* invalid Authority Object signature,
* unavailable revocation state,
* incomplete responsibility chain,
* evidence mismatch,
* undetermined risk tier,
* invalid Permit,
* expired Permit,
* Permit/tool-call scope mismatch,
* conflicting Authority Objects,
* boundary mutation,
* unavailable mandatory human approval,
* unavailable governance constitution,
* unverifiable policy origin,
* incomplete delegation chain,
* execution-environment mismatch,
* and unverifiable Permit signature.

These failure modes establish the interface principle:

> **Layer 1 must never manufacture an executable state from an invalid or unresolved Layer 0 state.**
