Skip to content

Releases: DwarfM42/EvidenceRegistry

EvidenceRegistry v0.3.0

Choose a tag to compare

@DwarfM42 DwarfM42 released this 12 Sep 03:35
db4490f

EvidenceRegistry v0.3.0 release notes

Release identity

EvidenceRegistry v0.3.0 is a source-only release of the Rust Core and the AI
Agent Evidence Binder
companion. Verify the annotated v0.3.0 tag, its
resolved commit and source tree, and the matching GitHub Release before
building. The release is not published to crates.io (publish = false) and
provides no prebuilt binaries or binary assets.

Both workspace packages are version 0.3.0:

  • evidence-registry — the Rust Core and read-only Journal CLI;
  • ai-agent-evidence-binder — the separate companion workspace member.

v0.2.0 remains an immutable Core-only historical source release. It did not
contain Binder and its tag, GitHub Release, qualification records, and release
notes are not rewritten by v0.3.0.

Added companion surface

The Binder is a separate workspace component with the public binder example:

  • init creates a fresh Store-backed target and exact Review Request;
  • run persists intent before a single literal-argv managed process dispatch,
    retains every attempt, captures a predeclared bounded output set, and uses
    Store-owned Result/Admission operations where the retained inputs permit;
  • inspect is read-only and reconciles the local bounded ledger with known
    retained Store references across all attempts.

Hermes is the first real-agent adapter/dogfood target. Core and the read-only
evidence-registry journal verify CLI neither require nor configure Hermes.
The Binder ledger is bounded local history, not a Core Record, signature,
custody proof, semantic authority, or execution-authentication mechanism.

Qualification status and boundaries

The exact Binder implementation tree completed native qualification on Windows
x86_64, Linux x86_64, and macOS arm64; the README verification
ledger
identifies the three records. This is
current implementation qualification, not semantic correctness. The annotated
tag, its resolved commit/tree, and matching GitHub Release establish the public
release locator. A future real-agent record, if performed, must bind its own
bounded Request-first Hermes run, retained Result/Admission, and cold
all-attempt inspection.

Historical implementation-tree qualification and Hermes dogfood records remain
useful provenance but do not qualify this documentation revision beyond its
stated bounded facts.

These observations do not establish semantic correctness, reviewer
correctness or identity, independent review, agent authorship, a sandbox,
complete process-tree containment, all adapters/platforms, hostile-writer
resistance, external authorization, universal durability, or production
readiness. STRUCTURALLY_VALID != AUTHORITATIVELY_VALID; Policy acceptance is
not semantic truth.

Repository surface

The release retains the Core's strict Record framing, retained Journal replay,
and selected Store-owned Freeze/Request/Result/Policy/Admission path. The
Journal CLI remains read-only and Journal-only: successful replay leaves
authority_status and admission_status unavailable. The selected lane is not
a general authority engine and does not upgrade generic or legacy paths.

For commands, trust boundaries, and raw-evidence requirements, see the
README, README verification ledger,
and Binder design and trust contract. The GitHub
Release is the public locator for the final tag object, commit, tree, release
body, and release-time evidence pointers; verify it and the annotated tag
directly.

EvidenceRegistry v0.2.0 — source release

Choose a tag to compare

@DwarfM42 DwarfM42 released this 10 Sep 12:15
14aa2d2

EvidenceRegistry v0.2.0

Source-only release for the exact annotated tag v0.2.0, resolved commit 14aa2d2b4ef6342e53e1274acd393b87ab5ee6aa, and source tree 702e2a4a497fb605e7c2b7b63d6904e6112ba3bd.

Included

  • Refined public README and source-release documentation.
  • Cargo package metadata at 0.2.0; crates.io publication remains disabled.
  • Narrow Store-owned selected authority-path runtime retained from the integrated baseline.
  • macOS retained-generation guard construction now avoids duplicate long-lived file descriptors.

Qualification

The release tree passed native Windows, Linux x86_64, and macOS arm64 gates, plus GitHub Actions Linux/macOS/Windows and formal-provenance checks. The macOS descriptor-pressure regression was additionally exercised with 50 default-thread repetitions of freeze_committed_binding.

Scope

This is a tagged source release with no prebuilt binaries. Structural validity is distinct from authoritative validity; the Journal CLI remains read-only, and generic or legacy paths are not upgraded into the selected terminal-authority lane. See README.md and docs/RELEASE-NOTES-v0.2.0.md in the tagged source.

EvidenceRegistry v0.1.0 — source release

Choose a tag to compare

@DwarfM42 DwarfM42 released this 08 Sep 21:31
0d9e825

EvidenceRegistry v0.1.0

Initial source-only release of the Rust library and read-only JSON Journal verification CLI.

Exact source identity

  • Annotated tag: v0.1.0
  • Tag object: df21f2deedc23e0bd1f357ab9135c8f2c32533fe
  • Source commit: 0d9e82523a5b0ff9b6d10710a5f643ac3bf6061e
  • Git tree: 592d0cdfe0b230f540afcd5ef0964a9be7162ad2

Use the official tagged source and the README's For AI agents and Build a release binary instructions. Retain the resolved source identity, built binary hash, exact inputs, raw output and actual exit status. A moving branch is not the release identity. The tag is annotated; no signed-tag claim is made.

Included scope

  • Strict Record framing/identity and supported type-local decoders.
  • Caller-ordered, retained Journal structural/state replay through journal verify.
  • Bounded local Registry namespace validation, with platform-specific storage adapters and explicit limits.
  • A disposable synthetic onboarding example; it neither opens nor mutates a live Registry.
  • Project MIT OR Apache-2.0 license texts and original notices for every locked dependency.

An agent or human can invoke the same interfaces, retain exact evidence, and explain what an operation established. The producer, validator, reviewer, authority and explanatory agent are distinct roles; an explanation is not a substitute for the retained evidence.

Platform verification

The exact source commit above completed the eight native source gates on Windows x86_64, Linux x86_64 and macOS arm64: locked release build, formatting, locked all-target tests, warnings-denied Clippy, release Review Admission tests, release Freeze binding tests, doctests and diff checks.

Native platform All-target tests passed All-target tests ignored
Windows x86_64 261 0
Linux x86_64 280 6
macOS arm64 285 0

Ignored Linux worker tests are not counted as ordinary test executions; their separate supervised execution evidence was retained. They are not macOS tests. The ASCII-path, Unicode-path, malformed-input and missing-input CLI cases produced byte-identical stdout/stderr and identical process exits across the three platforms. The reviewed source also passed the repository's Windows, Linux and macOS hosted CI checks.

This establishes bounded behavior on the tested platforms, not support for every operating system or filesystem, network filesystems, universal durability, strongest power-loss persistence, reproducible binaries, code signing or notarization. Windows deny-write sharing and cooperative Linux/macOS locking have different limits. macOS does not claim protection against surviving fork-without-exec descriptor holders. See the README’s “Platform boundaries” section for the implemented scope.

Boundaries

STRUCTURALLY_VALID != AUTHORITATIVELY_VALID. Successful build, decode, replay, CLI exit or AI explanation does not establish external authority, Policy satisfaction, Review Admission, custody, durability, production trust or permission to mutate a Registry. Positive Freeze semantic authority and successful terminal Review Admission publication remain unavailable.

The CLI fails closed for the exercised invalid inputs: malformed Genesis bytes return STRUCTURAL_REPLAY_REJECTED with exit 1; a missing Genesis file returns INPUT_UNAVAILABLE with exit 6. Retain those results rather than silently skipping inputs or reporting success. A preterminal authority/context failure is not a completed Policy result, and UNAVAILABLE must not be converted into Policy satisfaction or admission.

The ordinary sample vector is standalone, not a successor to the demo Genesis. Historical frozen documents are preserved byte-for-byte; archival paths are not installation/runtime requirements. Proposed bridges to external attestation, transparency and metadata systems remain unimplemented.

Distribution and licensing

EvidenceRegistry is offered under MIT OR Apache-2.0, at your option. Third-party grants and original attributions remain separate.

Use GitHub's source archives or the exact annotated tag. This release does not ship executables, dependency crate archives, vendored dependency implementations, a Rust toolchain/sysroot or native runtime. Cargo retains publish = false; crates.io publication is intentionally outside this first release, not a judgment about registry safety or version identity.

Any future binary/runtime/vendored distribution needs its own exact-payload licensing and platform assessment. This source release does not clear those obligations.