Repository navigation
PROVENANCE v1.2.0 adds an optional, vendor-neutral research manifest for retaining external research materials with explicit source identity, artifact hashes, attribution, licensing evidence and scope declarations.
The release includes an offline OpenAI Math example, an independent byte verifier, review-driven validation fixes and preservation of the historical Phase 18 archive’s citation metadata.
Release identity
- Version:
v1.2.0 - Final merged commit:
41451bf690597a75f461299dfcbbee559c83e924 - Release DOI: [10.5281/zenodo.23207011](https://doi.org/10.5281/zenodo.23207011) — reserved for this version; publication remains a separate archival step.
- Merged PR: [#20](#20)
- Successful full release gate: [Run 37613070156](https://github.com/QSOLKCB/PROVENANCE/actions/runs/37613070156)
- Changes since v1.1.1: [Compare](v1.1.1...41451bf)
The immutable v1.2.0 tag should target the exact commit above.
Research manifests
The new provenance_research module introduces provenance.research-manifest.v1.
A manifest records:
- The upstream project, repository, exact commit, commit hash algorithm and declared license.
- Retained artifacts with unique keys, portable relative paths, upstream or local origin, roles, SHA-256 content identities and byte counts.
- Explicit reference, copy, adaptation and derivation relationships, including modification notices where required.
- Separate manuscript, formalized and local scopes.
- Relevant declarations, comparator references and optional retained verification receipts.
- Upstream credit, license evidence, NOTICE observations and citation artifacts.
Source commits explicitly declare sha1 or sha256. Copied artifacts must match both the upstream content identity and byte count.
Sealing uses the existing provenance.canonical-json.v1 canonicalization rules and a dedicated research-manifest hash domain:
sha256(b"PROVENANCE/RESEARCH-MANIFEST/v1\0" + canonical_json_bytes(core))
The sealed envelope binds the manifest core to its research identity and explicitly records the identity field’s self-hash exclusion.
Independent verification
Two public entry points support sealing and checking:
seal_research_manifest(core) -> bytes
verify_research_manifest(data, contents) -> dictThe verifier checks canonical encoding, schema validity, manifest identity and retained artifact SHA-256 hashes and byte counts. Artifact bytes come from a caller-supplied mapping keyed by content identity.
Verification performs no network access, path opening or proof execution. Its report keeps byte-integrity results, missing artifacts and errors visible.
Research metadata remains DECLARED. Upstream membership, mathematical validity and license compliance are reported as not_checked; retained receipts do not automatically establish those properties.
Research manifests and retained materials can be carried through existing evidence and custody workflows as ordinary artifacts. Research-specific verification remains an explicit operation.
OpenAI Math example
The release includes a small, pinned offline fixture from openai/math at commit:
adc7f1241b42e322a6451854ab7e4b4c146bf78a
The example covers family 271, associated with Spontaneous magnetization in the quantum Heisenberg ferromagnet, and declaration:
OAI.Heisenberg.spontaneous_magnetization
It retains five unmodified upstream files: the Apache-2.0 license, scope document, Lean challenge, comparator JSON and manuscript citation README. Their Git blob identities were checked against the pinned upstream revision.
OpenAI receives explicit upstream credit. These retained upstream materials preserve their Apache-2.0 licensing; the PROVENANCE implementation remains MPL-2.0.
The Lean challenge contains an upstream sorry. It is retained as a statement/comparator specification and does not constitute a completed proof. The fixture does not include the manuscript PDF, a solution corpus or proof-execution evidence.
Run the example with:
python3 -m examples.openai_math.verifyValidation and verifier fixes
Review feedback produced additional fail-closed behavior:
- Artifact paths reject all Unicode control-category characters, including DEL and C1 controls.
- Malformed artifact roles, origins and references are rejected before operations that could otherwise raise unexpected exceptions.
- Excessively nested input produces a failed verification report.
- Missing artifact lookups remain visible gaps while verification continues.
- Ordinary artifact-store exceptions are recorded with their exception type and message, allowing remaining artifacts to be checked.
- Metadata classification remains unset until the manifest core passes schema validation.
Historical archive integrity
The Phase 18 formal archive retains the historical v1.1.1 citation in formal/CITATION.cff, bound to DOI [10.5281/zenodo.23043860](https://doi.org/10.5281/zenodo.23043860).
The archive excludes the moving root CITATION.cff. Its generation validates the retained historical citation against a pinned digest and fails if those bytes change.
Regression tests exercise the workflow’s archive command, verify archive contents and confirm that later root citation changes do not alter the historical citation.
Compatibility and verification scope
Existing evidence, bundle, custody, package, signature and transfer formats remain unchanged. This release introduces no new runtime dependency or automatic upstream fetching.
The existing FV-01–FV-04 formal evidence remains scoped to the frozen v1.0.0 implementation:
0b1a2eea6c3c2b40a7f2a390fcd3410c75fab742
The new research module is covered by tests but is outside that formal runtime bridge. This release makes no whole-program verification claim and does not adopt or prove the example’s mathematical result.
Validation evidence
The release-grade full workflow completed successfully against the exact final merged commit. It covers the Rust CLI, Python invariant and integration suites, additional hash-seed checks, source cleanliness, tamper detection and real Ollama smoke lanes.
The focused research and historical archive regression suites passed 19 tests. The pinned offline fixture verifier also passed.
Release and archival metadata should retain the final commit SHA and successful workflow link above.