EvidenceRegistry v0.1.0 — source release
EvidenceRegistry v0.1.0
Initial source-only release of the Rust library and read-only JSON Journal verification CLI.
Exact source identity
- Annotated tag:
v0.1.0 - Tag object:
df21f2deedc23e0bd1f357ab9135c8f2c32533fe - Source commit:
0d9e82523a5b0ff9b6d10710a5f643ac3bf6061e - Git tree:
592d0cdfe0b230f540afcd5ef0964a9be7162ad2
Use the official tagged source and the README's For AI agents and Build a release binary instructions. Retain the resolved source identity, built binary hash, exact inputs, raw output and actual exit status. A moving branch is not the release identity. The tag is annotated; no signed-tag claim is made.
Included scope
- Strict Record framing/identity and supported type-local decoders.
- Caller-ordered, retained Journal structural/state replay through
journal verify. - Bounded local Registry namespace validation, with platform-specific storage adapters and explicit limits.
- A disposable synthetic onboarding example; it neither opens nor mutates a live Registry.
- Project MIT OR Apache-2.0 license texts and original notices for every locked dependency.
An agent or human can invoke the same interfaces, retain exact evidence, and explain what an operation established. The producer, validator, reviewer, authority and explanatory agent are distinct roles; an explanation is not a substitute for the retained evidence.
Platform verification
The exact source commit above completed the eight native source gates on Windows x86_64, Linux x86_64 and macOS arm64: locked release build, formatting, locked all-target tests, warnings-denied Clippy, release Review Admission tests, release Freeze binding tests, doctests and diff checks.
| Native platform | All-target tests passed | All-target tests ignored |
|---|---|---|
| Windows x86_64 | 261 | 0 |
| Linux x86_64 | 280 | 6 |
| macOS arm64 | 285 | 0 |
Ignored Linux worker tests are not counted as ordinary test executions; their separate supervised execution evidence was retained. They are not macOS tests. The ASCII-path, Unicode-path, malformed-input and missing-input CLI cases produced byte-identical stdout/stderr and identical process exits across the three platforms. The reviewed source also passed the repository's Windows, Linux and macOS hosted CI checks.
This establishes bounded behavior on the tested platforms, not support for every operating system or filesystem, network filesystems, universal durability, strongest power-loss persistence, reproducible binaries, code signing or notarization. Windows deny-write sharing and cooperative Linux/macOS locking have different limits. macOS does not claim protection against surviving fork-without-exec descriptor holders. See the README’s “Platform boundaries” section for the implemented scope.
Boundaries
STRUCTURALLY_VALID != AUTHORITATIVELY_VALID. Successful build, decode, replay, CLI exit or AI explanation does not establish external authority, Policy satisfaction, Review Admission, custody, durability, production trust or permission to mutate a Registry. Positive Freeze semantic authority and successful terminal Review Admission publication remain unavailable.
The CLI fails closed for the exercised invalid inputs: malformed Genesis bytes return STRUCTURAL_REPLAY_REJECTED with exit 1; a missing Genesis file returns INPUT_UNAVAILABLE with exit 6. Retain those results rather than silently skipping inputs or reporting success. A preterminal authority/context failure is not a completed Policy result, and UNAVAILABLE must not be converted into Policy satisfaction or admission.
The ordinary sample vector is standalone, not a successor to the demo Genesis. Historical frozen documents are preserved byte-for-byte; archival paths are not installation/runtime requirements. Proposed bridges to external attestation, transparency and metadata systems remain unimplemented.
Distribution and licensing
EvidenceRegistry is offered under MIT OR Apache-2.0, at your option. Third-party grants and original attributions remain separate.
Use GitHub's source archives or the exact annotated tag. This release does not ship executables, dependency crate archives, vendored dependency implementations, a Rust toolchain/sysroot or native runtime. Cargo retains publish = false; crates.io publication is intentionally outside this first release, not a judgment about registry safety or version identity.
Any future binary/runtime/vendored distribution needs its own exact-payload licensing and platform assessment. This source release does not clear those obligations.