Releases: 05oz/certify
Release list
Certify v0.15.0: independence-claim round
CORRECTIONS — v0.15.0 independence-claim round
Dated 2026-08-14. This round changed documentation only.
No certified value changed, and no checker's verification logic changed. An
independence audit found that a set of public sentences asserting a checker shares no
code with the pipeline that produced its certificate are false as written. Each has
been replaced by a measured statement of what is shared, what independence survives,
and what a passing check may and may not be read as. Every checker passes as before,
every tamper battery passes as before, and every mathematical result of Parts A
through M stands. Two independence backstops that did not previously exist were
established before this round was written and are stated in the notes.
This file is an index, not a record. The measured counts and the reasoning behind each
replacement live in each part's note and build log, which are the places they are checked.
Deposited documents whose text changed
| Part | Version | Note | Sentences replaced | Build log |
|---|---|---|---|---|
| A | v0.1.x | paper/ERRATUM-v0.1.2.md (not the deposited PDF) |
2 (§3, and the closing note under the run block) | paper/FIXLOG.md |
| B | v0.2.x | paper/preprint-qec-distances.pdf |
2 (§4.1 the fourth checker; front matter) | paper/FIXLOG-qec.md |
| D | v0.4.0 | qec1435-paper/note.pdf |
1 (§5, the independent verifier) + one SHA-256 manifest line | qec1435-paper/FIXLOG.md |
| E | v0.5.0 | cfr-paper/note.pdf |
2 (§3, and the abstract/trusted-base "independently written" clause; the §1 search claim is true and untouched) | cfr-paper/FIXLOG.md |
| H | v0.8.0 | wedge-paper/note.pdf |
1 (front-matter methods note) | wedge-paper/FIXLOG.md |
| J | v0.10.0 | k34add-paper/note.pdf |
4 (front matter and the artifacts section; located by content, not line) | k34add-paper/FIXLOG.md |
| K | v0.11.0 | wedge2-paper/note.pdf |
1 (front-matter methods note) | wedge2-paper/FIXLOG.md |
| L | v0.12.x | demag-paper/note.pdf |
2 (§5, clause (ii) and the trust paragraph) | demag-paper/FIXLOG.md |
| M | v0.13.0 | zefoz-paper/note.pdf |
1 (§6, the trusted list) | zefoz-paper/FIXLOG.md |
PDF rebuild complete, 2026-08-14. All eight deposited PDFs — B, D, E, H, J, K, L and
M above — were rebuilt from their corrected .tex with tectonic 0.17.0 (pdflatex,
xelatex and latexmk are absent from this machine) and each was verified by
pdftotext -layout extraction, never by timestamp: for every one of the eight, none of
the sentences this round set out to replace survives into the rebuilt text, and every
replacement sentence is present. The extraction check was run de-hyphenated and on token
boundaries, because a crude match reports both false survivors and false absences on
these documents. That check tests the sentences the round had already identified; it
cannot find a false claim the round never flagged, and the adversarial referee pass found
two of those in Parts B and E after the first rebuild. Both are fixed and both papers
were rebuilt again; see the section below. Part A's
paper/preprint-dixmier-poisson.pdf is not in that list: its text was left unchanged
(see the flagged item below), and it was deliberately not rebuilt.
Three of the eight would not compile at all on first attempt: wedge-paper,
wedge2-paper and k34add-paper had acquired a \par inside the non-\long \thanks
argument when this round's replacement paragraphs were written, which halts XeTeX with a
runaway-argument error. The nine occurrences were changed to \endgraf, which produces
the identical paragraph break without the token that trips the runaway check. No word of
prose changed.
The Markdown mirrors, the drafts tree, README.md, the demag sweep record, the k34add
sweep record and certificate README, and the affected checker docstrings carry the same
corrections; they are not deposited separately.
The deposit is versioned. The v0.14.0 DOI keeps resolving to the text containing the
false sentences. This correction lands as a new version with the concept DOI resolving
forward. No existing record was edited in place.
One checker file changed, and its published hash with it
qec1435-scripts/verify_1435.py had its docstring corrected (the disclosure required by
Part D). Its SHA-256 is published in that paper's own manifest, so the manifest line was
updated in the same pass: 2527266d13b604029120ed11174730ef1ed3fe6d5405d8fe3f82c21668ae0d3c
becomes 6e23299bf878165ecef94044efa3e2cf180c5ece4ca60665c7af6d04f237a1b2. Only the
docstring changed; no executable line of that file was touched. Every other checker edited
in this round (check_demag.py, zefoz_checker_pilot.py, check_prof.py, check_lower.py,
qec_lib.py, the three k34add checkers, fibre_check.py) has no published hash anywhere in
the repository, verified by searching for each file's digest before editing.
That last sentence was true of the eight checkers it names and false of the round as a
whole. Two files edited earlier in the batch, kelmans-scripts/refcert.py and
kelmans-scripts/verify_cert.py, do have published digests, in the integrity block of
kelmans-certificates/REGENERATE.md, and both were stale. A reader re-hashing the shipped
scripts against that block would have found a mismatch and been entitled to read it as
tampering. Both lines were updated and all sixteen digests in that block re-verified
against the files they name. REGENERATE.md is inside a *-certificates/ directory and
so is otherwise read-only for this round; the two-line change is recorded here because it
is an exception, and because the alternative was shipping a manifest that contradicts its
own artifacts.
Caught by the pre-release battery, after the corrections were drafted
The Engine 2 re-derivation pass re-executed every measured figure in this round rather
than re-reading it, and three of the round's own replacement sentences did not survive it.
All three are fixed above and in the FIXLOGs; none changes a certified value.
- Part E. The replacement said the longest identical run between the two CFR verifiers
"is seven lines and is pure input/output". Measured, the longest identical run is five
lines and is the header of the distinctness double loop; the longest purely
input/output run is three. A round correcting false independence claims had written a
false measurement into the correction itself. - Part D. The §5 disclosure landed, but the front-matter
\thanksof the same paper
still read "independently written checker code that shares nothing with the generating
pipeline" — so the paper's own §5 refuted its own front matter, which is the §14 failure
mode this protocol exists to prevent. The front matter now records the dependence and
points at §5. Separately, that paper's FIXLOG recorded the newverify_1435.pydigest
as3471eacf..., which is not the file's SHA-256;note.tex,note.mdand this file
had the correct6e23299b...and the FIXLOG was the lone wrong copy. - Part B. The sentence introducing the new third LRAT acceptance was itself written as
an independence claim — "a third acceptance that shares nothing with either" — and is
false on the same measurement: 34 of that replay's 239 executable lines appear in
check_lower.pyorcheck_prof.py. It now states the measurement. The shared lines are
barecontinue/break/else:, flag initialisations, the main guard and a three-line
gzip-open idiom, so the substance stands; the wording did not.
Caught by the adversarial referee, after the first rebuild
A referee session that did no editing was then given a kill-the-paper brief (PROTOCOL
§17). It re-derived the round's measurements independently and reproduced all of them,
and it found four further defects that every earlier pass had missed. Parts B and E were
rebuilt a second time.
- Part B, four stale line counts. The trusted-base section says "Four files, 1,128
lines of Python in total:check_witness.py(95),check_duality.py(73),
check_lower.py(481), andcheck_prof.py(479)… the first three, 649 lines". Adding
the disclosure docstrings in this round tookcheck_lower.pyto 488 lines and
check_prof.pyto 488. The round rewrote prose forty lines away and never re-derived
the counts in the same section. Now 1,144 / 95 / 73 / 488 / 488 / 656, propagated to
the Markdown twin,README.mdandPROVENANCE.md. - Part B, a surviving independence claim. §7 read "re-checked by a separate agent
instance with no access to the pipeline and no shared code" — refuted by the same
paper's own front matter, which now measurescheck_lower.pyat 36 of 358 lines shared
withqec_lib.py. The clause is gone from the note, its twin,README.mdand
PROVENANCE.md. The propagation grep that caught the identical fault in Part D had
never been run for this phrasing. - Part E, a surviving independence claim. The abstract and the trusted-base section
both described the second CFR verifier as "independently written", which §3 of the same
paper now refutes at 26 of 104 shared lines. Both sentences, the section heading and
the source-header comment now state the dependence. The separate §1 claim about the
search remains, deliberately: it is untested, not refuted. - Part B, an overstated characterisation. The replacement sentence for the third LRAT
acceptance said every shared line was one of an enumerated list and that a "three-line
...
v0.14.0 — documentation-correction round
Every released part's prose re-derived against its own artifacts. No certificate file, checker logic, or certified value changed; every checker passes as before and every mathematical result of Parts A through M stands. What changed is documentation: artifact inventories listing files the deposit does not contain, replay instructions that did not run as written, counts and labels contradicted by the shipped artifacts, and several claims the artifacts refute. CORRECTIONS.md indexes the round by part and is generated from the diff, not authored.
v0.13.0 — certified ZEFOZ brackets for 167Er3+:Y2SiO5
Certified existence, curvature and stationary-point type of all twenty published nonzero-field ZEFOZ points of 167Er3+:Y2SiO5, both crystallographic sites. Transition brackets of width 4e-10 MHz, certified gradient bound 3.2e-37 MHz/mT, two-sided brackets on all three Hessian eigenvalues with certified signature, and Krawczyk existence plus local uniqueness within 2.9e-14 mT. At zero field an exact symbolic time-reversal identity certifies all 120 transitions stationary. The completeness question is reported dead per pre-registered kill condition. Three errata in the reference documented and versioned.
v0.12.1 — erratum: gold-value anchor corrected from containment to agreement
Erratum to v0.12.0. The sixteen Maple gold values in OOMMF's demagcoef.cc agree with the certified enclosure midpoints to at least 49.6 digits; as first released the paper asserted they lie inside the enclosures, which is false — the enclosures are ~77 digits tight, so fifteen of the sixteen lie outside, the exact zero being the exception. The build log had already recorded the correct test (FIXLOG decision S4); the correction reached the anchor code but not the prose. No certified enclosure, certificate, or checker changed. Dated erratum footnote in the note; root cause and the resulting propagation gate recorded in the program protocol.
v0.12.0 — certified demagnetization-tensor reference tables
Every finite-difference micromagnetic simulator (OOMMF, MuMax3, magnum.np, Fidimag, MagTense) computes the demagnetizing field from the same Newell tensor, whose closed-form evaluation is known to lose all significant digits to catastrophic cancellation at large cell separations. This release pins the entries rigorously: two-sided enclosures of dyadic rationals from outward-rounded interval arithmetic, with the transcendental pieces enclosed by truncated series. Against them, the naive double-precision route is measured losing about six correct decimal digits per decade of separation — zero correct digits near 300 cells, wrong sign and magnitude beyond — and the crossover with OOMMF's asymptotic expansion is located rigorously. Certificate JSON plus a standard-library checker that re-derives every enclosure and rejects tampering. Review log: demag-paper/FIXLOG.md. Paper: demag-paper/note.pdf
v0.11.0 — the exact logical error probability, superseding the Part H bracket
Replaces the two-sided rational bracket of Part H (doi:10.5281/zenodo.21895825) with a single exact rational value. A MacWilliams-type syndrome-space character sum yields every uncorrectable count in one O(2^n n) pass instead of per-weight enumeration, reaching A_7 = 832,441,445 at distance 5 — a quantity Part H named as beyond a pure-Python checker. The exact values fall strictly inside the Part H brackets (at 0.36 and 0.51 of their widths), so the earlier result stands as the independent check the exact values passed. A standard-library checker re-derives everything from the mechanism list in about two minutes at d=5 and rejects eight classes of tampered certificate. Exact for the independent-mechanism noise model under the stated lookup-table decoder, not the physical circuit; distance-7 codes remain out of reach by this method. Paper: wedge2-paper/note.pdf
v0.10.0 — the k(3,4) extremal graph is not unique: thirteen rigid witnesses
Answers Question 8.1 of Part G (doi:10.5281/zenodo.21890619) in the negative. At least thirteen pairwise non-isomorphic, rigid extremal graphs on 20 vertices, each independently verified {I_3,TT_4}-free over all triples and transitive quadruples. Includes a short proof that the Paley tournament QR_7 appears in every such graph by force rather than design, and the finding that algebraic blow-up constructions reach only 15 vertices where the truth is 21. Paper: k34add-paper/note.pdf
v0.9.0 — Kelmans' 1984 problem verified to 22 vertices
Every 3-connected cubic graph on at most 22 vertices — all 6,339,157 — satisfies Kelmans' 1984 conjecture, together with the applicable strong forms of his equivalence theorem. First recorded computational verification of the problem at any order. Two pipelines sharing no code agree on every count; 43,580 certificates re-verified from graph6 strings by standard-library checkers. Order 24 is attack-side complete (98,101,019 graphs, no failure) with the independent recount outstanding, and is reported at that strength only. Review log: kelmans-paper/FIXLOG.md. Paper: kelmans-paper/note.pdf
v0.8.0 — certified sub-threshold logical error rates for the rotated surface code
Exact uncorrectable-set counts converted to a two-sided exact-rational bracket on the logical error probability, replayable with the Python standard library. Deep sub-threshold (p=1e-3) the certified bracket beats a 10^7-shot Monte Carlo interval by ~18,500x at d=3 and ~626x at d=5 (matching it would need ~4e12 shots). Honest scope: the bracket bounds the independent-mechanism detector error model under a fixed lookup-table decoder, not the physical circuit; at p=1e-2 it still wins at d=3 but loses at d=5 (fat truncation tail, not a threshold crossing). Frontier: exact re-verification at weight 7 exceeds a pure-Python checker. Review log: wedge-paper/FIXLOG.md. Paper: wedge-paper/note.pdf
v0.7.0 — k(3,4) = 21: a previously unknown Erdos-problem value, determined and certified
Determines k(3,4) = r(I_3,L_4) = 21 (Erdos Problem #112; published bounds were 9 <= k(3,4) <= 25): explicit 20-vertex witness + 346-case LRAT-certified exhaustion at N=21, completeness audited, 445 certificates, ~1.02e9 checked proof steps, every certificate replayed by an independent stdlib checker. Clean-room reproducible: the from-definition CNF generator ships. Also 29 <= k(6,3) <= 33 (lower bound new, separately refereed). Review logs: k34-paper/FIXLOG.md, REFEREE-k63.md; sweeps: SWEEP-RECORD-K34-2026-08-11.md. Paper: k34-paper/note.pdf