Skip to content

Prepare the complete VSTD 1.2.0 release candidate - #27

Merged
TimeLordRaps merged 34 commits into
mainfrom
codex/post-1.2-professionalization
Sep 1, 2026
Merged

Prepare the complete VSTD 1.2.0 release candidate#27
TimeLordRaps merged 34 commits into
mainfrom
codex/post-1.2-professionalization

Conversation

@TimeLordRaps

@TimeLordRaps TimeLordRaps commented Aug 27, 2026

Copy link
Copy Markdown
Owner

Coordinate > Acronyms: application programming interface (API); continuous integration (CI); GNU Privacy Guard (GPG); JavaScript Object Notation (JSON); RISC Zero (RISC0); Secure Hash Algorithm 256-bit (SHA-256); Software Bill of Materials (SBOM); Supply Chain Integrity, Transparency, and Trust (SCITT); Verifier Standard (VSTD). - Target: VSTD 1.2.0 release candidate against main. - Base: 598c545be3833d6d81bb7e252ca5837f3bb2a449. - Head: dbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7d. - Final Git tree: 36f78119fcbf4748c7e02fed8bc55e2fd389a840. - History: 34 GNU Privacy Guard (GPG)-signed, single-parent commits on one branch. The newest commit uses the bounded automation signing key; this does not claim that every prior commit used the same key. - Release state: UNRELEASED; this pull request does not tag, publish, or deploy version 1.2.0. ## Current human-review status > Refreshed 2026-09-01 after the final generated-procedure presentation repair and exact-tree re-audit. This is a navigation summary, not a substitute for the coordinate-bound review records. | Review stage | Current state | Coordinate and consequence | |---|---|---| | Checkpoints A-D | ACCEPTED at their recorded review coordinates | The required signed repairs are ancestors of the current head. Those historical decisions are not silently rebound to a neighboring tree. | | Checkpoint E — artifact freeze, seal, thaw, lineage, and filesystem-entry identity | ACCEPTED at superseded head b6d97647… / tree ac1d7cca… | Later e9d2b13… is test-only VSTD-5 hardening and 1159839d… is the bounded ZIZK/RISC Zero repair; neither changes the accepted artifact-control implementation. | | Checkpoint F — ZIZK and bounded RISC Zero reference mechanism | ACCEPTED at current head 1159839d… / tree 7d7793e6… | The source-build/image-identifier/proof correspondence and stated residual limitations were accepted. | | Checkpoint G — Graph lifecycle, propagation, and collection-scale assurance | ACCEPTED at current head 1159839d… / tree 7d7793e6… | Tyler accepted the exact-tree audit: 72 targeted tests passed, no blocking objection was found, and the compatibility, lifecycle, propagation, and assurance boundaries were accepted. | | Checkpoint H — Supply Chain Integrity, Transparency, and Trust (SCITT), experimental workflow, and VSTD-3 boundaries | ACCEPTED at superseded head 1159839d… / tree 7d7793e6… | The later documentation-renderer repair does not change the accepted interoperability, workflow, or substrate semantics. | | Checkpoint I — newcomer and public presentation | ACCEPTED at superseded head 833b8ea0… / tree 28bd9ed6… | The later release-workflow repair does not change the accepted documentation renderer or presentation surface. | | Checkpoint J — release truthfulness and merge/release separation | ACCEPTED at superseded head e31bd77b… / tree c53b9140… | The later presentation-only repair preserves the accepted workflow, procedure, metadata, and publication boundaries. | Checkpoint G decision: ACCEPT, recorded 2026-09-01 against head 1159839d3a1cb51726cbb87b46eace1ff58d1943 and tree 7d7793e69a8e41355b5cc4b0faa129d4c2a8433a. Checkpoint H decision: ACCEPT, recorded 2026-09-01 against the same reviewed head and tree. Checkpoint I decision: ACCEPT, recorded 2026-09-01 against head 833b8ea086ee0ccec10737090e68054be0e4cc31 and tree 28bd9ed671625325ec95c8a20917d601363fb5d1. Checkpoint J decision: ACCEPT, recorded 2026-09-01 against head e31bd77b532e8ab7e11005981edd4113a4f4f971 and tree c53b9140503ebb96d88d27f6f51fe5cb91a33c66. No blocking semantic counterexample survived the repaired exact-tree audit. Final merge judgment: merge-ready at head dbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7d / tree 36f78119fcbf4748c7e02fed8bc55e2fd389a840 for explicit maintainer authorization, provided the coordinate and required checks do not change. Merging to main automatically triggers the public GitHub Pages documentation deployment; it does not create the v1.2.0 tag, GitHub release, Zenodo record, or Python Package Index publication. Those remain separate actions. The final checklist item remains intentionally unchecked. No merge, tag, release, publication, or deployment is authorized by this status update. The aggregate change exceeds GitHub's 20,000-line pull-request diff endpoint. Review the signed commits below in order; no individual commit exceeds that endpoint limit. ## Review map | Commit | Review surface | Primary falsification question | |---|---|---| | fbab340e | Current VSTD and VSTD-Graph numbered profiles, schemas, core and Graph checks | Can field names, depth, multiplicity, or propagation strengthen an unmet coordinate? | | 54e5798f | Generic-run capture, validation, inspection, reproduction, and impact | Can a changed or incomplete stable payload validate or reproduce beyond its ceiling? | | e86a4b47 | Artifact freeze, self-closing seal, and additive thaw | Can missing or changed bytes validate, or can thaw mutate the sealed parent? | | 798e99c2 | Bounded SCITT interoperability | Does translation widen a proposition or inherit assurance from placement? | | 3979a564 | Experimental workflow profile | Can allocation, repetition, or hosted labels manufacture assurance? | | 764f33c7 | ZIZK artifact-first references and recorded RISC0 proof | Are proof bytes, public commitments, predicate, and image identifier bound exactly? | | 3cc2186c | VSTD-3 execution and substrate evidence | Does assignment imply trust, responsibility, or unsupported hardware fact? | | 0c7cec41 | Supported Python API and vstd command surface | Is an advertised export unreachable or an optional dependency required by base import? | | 002ff24c | Removal of the unreproducible SimulacraBench rehearsal | Does any current public surface still present that local rehearsal as verification evidence? | | a19bf4eb | Public architecture, terminology, humans/agents/TIME controls | Can a newcomer distinguish profile, depth, claim status, repository contradiction, TRUST, RUST, and ROT? | | 4ceb6049 | Pages, API reference, local definition previews, links, and presentation gates | Are generated pages stale, source links broken, or definitions dependent on a runtime wiki fetch? | | 7d253c9e | Release metadata, deterministic artifacts, SBOM, and hosted gates | Can publication proceed from mismatched Git bytes, metadata, contradiction state, or check coordinate? | | 79ae7ef6 | Executable mode preservation for offline proof commands | Are proof script bytes and executable modes identical to the validated candidate? | | 70706ec5 | Evidence dispatch, evidence-bound VSTD-4/VSTD-5/Graph establishment, assurance replay, schemas, and adversarial tests | Can caller fields, duplicate evidence, unresolved independence, inadmissible ancestry, cycles, or replay tampering create clean assurance? | | ca2b9748 | Public architecture, maturity tables, Graph lifecycle semantics, Pages, and regenerated specimens | Does any public surface still call the implemented mechanisms absent, experimental, or stronger than their evidence? | | 2eba5bd | Python 3.10 deterministic API-reference repair | Can interpreter-specific inherited Enum documentation drift the generated public reference? | | 24bdba9d | Edge-local TRUST dependencies, typed witness-independence failures, and bounded BLAME/GUILT semantics | Can a direct jump, inadmissible intermediate, unresolved conflict, duplicate identity, or unverified obligation manufacture assurance? | | 8893ff6f | Exact deviation localization, conflict-adjudication consequences, and lossless VSTD-5 replay inputs | Can an unselected deviation, inadmissible selected status, or serialization collapse manufacture or erase assurance? | | 31810f66 | Strict VSTD-5 receipt admission, verdict-evidence coverage, Graph subject identity, and diagnostic ancestry | Can schema-invalid shape, missing payload bytes, or an artifact/transformation identifier collision cross the portable boundary? | | c7a02814 | VSTD-5 cross-field semantics and frozen Graph-reader compatibility | Can a redundant digest or class be relabeled, or can a newer assurance invariant narrow historical bytes under the same identifier? | | 3cb54359 | Transitive VSTD-4/VSTD-5 claim identity, negative replay, and identifier/coordinate separation | Can a neighboring claim_id inherit an established VSTD-4 result through shared digests or consistent relabeling? | | 5d0e9a60 | Repository contradiction annunciation for GUILT composition | Does the review objection remain visible at an exact coordinate until a mechanism-level repair exists? | | 5eb38f3d | Separately bound responsibility, obligation applicability, obligation violation, compound evaluation, GUILT composition, serialization, and replay | Can an opaque pass, decorative obligation, coordinate mismatch, duplicated component, or tampered component digest manufacture GUILT? | | 11f243c8 | Repository contradiction annunciation for thaw-lineage verification | Can a self-derived sidecar closure be mistaken for evidence of a sealed parent or historical copy? | | 3f98446f | Supplied-parent thaw status, fail-closed lineage binding, CLI/API/schema/docs, and regressions | Can a fabricated or re-authored sidecar, neighboring parent, invalid seal, followed symlink, or absent anchor manufacture THAWED_CLEAN? | | 19e00bdb | Descendant symbolic-link identity preservation | Can path resolution follow a symbolic link and manufacture recorded or verified target-file agreement? | | 6b8fe413 | Lexical creation-path classification and invocation-owned cleanup | Can a source, destination, or replacement link redirect artifact bytes or cleanup into its target? | | f2c7438c | Repository contradiction annunciation for internal bundle-member aliases | Does the normative/runtime conflict remain visible before the repair is claimed? | | b6d97647 | Internal manifest, payload, seals-container, and seal-envelope lexical closure | Can an internal link, dangling link, reparse-point alias, or special object lend authoritative bytes to a bundle? | | e9d2b13 | Mutation-sensitive VSTD-4 claim-identity digest regression | Can removing claim_id from the canonical admitted-result payload escape the VSTD-5 carried-entry digest? | | 1159839d | Recorded RISC Zero proof, tracked guest image binding, public envelope, report, manifest, and boundaries | Can a valid proof for a neighboring historical image be presented as evidence for the currently tracked guest source? | | 833b8ea0 | Generated documentation token restoration and regression | Can nested inline formatting inside a link become an unresolved token or opaque numeric label in the public Pages artifact? | | e31bd77b | Release immutability ordering, workflow enforcement, documentation, and regression | Can a tag publish a mutable GitHub release because the setting check occurs too late or is merely advisory? | | dbd94c6a | Ordered-procedure rendering and regression | Can generated Pages restart a segmented numbered procedure and visually move tag publication ahead of its prerequisites? | ## Governing architecture - The repository uses the complete VSTD-1 through VSTD-5 object profile ladder and VSTD-Graph-1 through VSTD-Graph-5 collection profile ladder. - Retired partial-profile developmental specifications, identifiers, emitters, and compatibility readers are absent from the current tree. Git history alone preserves their historical existence. - ZIZK artifact-first TRUST is governing architecture, not a side experiment or actor-reputation system. - TRUST is mechanism-earned forward artifact support. ROT is typed degradation of current admissibility without rewriting history. RUST is inverse-TRUST diagnostic traversal through historically recorded contributing ancestry; current revocation or conflict may block TRUST without erasing that diagnostic history. - AssuranceLedger implements hash-chained event serialization and replay, evidence-bound TRUST, strictly degrading ROT, challenge-ledger projection, reverse RUST, unique-descendant concentration, additive conflict resolution, explicit localization, and bounded artifact-relative diagnostic attribution. - RUST alone establishes ancestral diagnostic reachability. BLAME is a separately checked, bounded material-contribution or responsibility relation from an artifact to an exact deviation. GUILT is composed only when the ledger binds three separately earned component events for the same artifact and exact deviation: responsibility or material contribution, applicability of one exact obligation under declared scope and bounds, and violation of that same obligation relative to that deviation. The final GUILT event binds all three component-event digests. One compound mechanism invocation may evaluate the components together only when it emits three separately bound proposition evaluations. GUILT is not reverse BLAME, and neither result becomes actor reputation, moral character, automatic legal liability, or inherited falsity. - VSTD-4 retains its compatibility candidate path as NOT_ESTABLISHED and adds an evidence-bound establishment/recheck path over exact VSTD-1/2/3 and fourteen-rung propositions. - VSTD-5 implements an evidence-bound reference mechanism across seven separation dimensions, exact admitted-certificate binding, duplicate refusal, disagreement preservation, and offline receipt recheck. Assessment remains diagnostic over incomplete inputs; the supported builder and rechecker admit only strict receipt shape with every verdict-material evidence byte. Replay compares every carried VSTD-4 entry coordinate, the bundle claim_id must equal the exact claim identifier retained by the admitted evidence-bound VSTD-4 result, and corroboration_class is part of the mechanism-checked proposition rather than assurance-bearing metadata. Shared binding or certificate digests do not create an identifier alias; no alias-mapping mechanism is implemented. This repository does not claim that a real independent external witness has participated. - VSTD-Graph retains caller-supplied compatibility candidates as NOT_ESTABLISHED and adds an evidence-bound path that reruns every member, ancestor, and reached-edge rating against the exact Graph, collection, members, claim, lifecycle view, mechanisms, roots, and bounds. Frozen VSTD-DATA-0.1 decoding retains separate historical artifact/transformation namespaces. Direct new construction, evidence-bound establishment, and assurance propagation require global cross-kind disjointness. - Actor identity, reputation, assignment, and separation never become computational-validity TRUST. - Freeze preserves exact bytes; seal closes a declared state; encryption is separate; thaw creates a mutable descendant. Authoritative internal freeze.json, payload, seals-container, and seal-envelope entries must have ordinary lexical types and cannot borrow bytes through symbolic links or supported reparse-point aliases. This is distinct from accepted outer parent-bundle and explicit thaw-record read aliases, whose resolved bytes and bindings are still verified. A thaw sidecar is unkeyed lineage metadata: sidecar-only agreement is NOT_ESTABLISHED, and established clean/dirty status requires the actual supplied parent to verify as sealed with every recorded coordinate matching. Current equality does not authenticate the historical copy operation or external continuity. Temporal continuity and realm mappings require separate mechanisms. ## Remaining experimental or external boundaries - Complete hidden-witness PASS/FAIL/UNKNOWN/CONFLICTED trichotomy derivation remains experimental and unimplemented. - No universal scalar support algebra exists. Domain-specific transfer and localization propositions still require truthful mechanisms and observations. - Real independent witnesses, second implementations, cross-implementation replay, operational interoperability, external attacks, and production trust roots remain external evidence rather than repository assertions. - Specific optional proof backends remain bounded by their own recorded mechanisms and maturity. ## Claim boundary This candidate does not claim that: - freeze prevents privileged writes, storage loss, or semantic ROT; - sealing is encryption, preservation, correctness, trusted time, authorization, or ownership; - identity or reputation establishes process validity; - RUST reachability alone proves ancestor falsity, causal responsibility, BLAME, or GUILT; - a technical artifact-relative BLAME/GUILT result concerns an actor's moral character; - a sealed realm declaration or temporal model is thereby true; - a digest, omission, or encryption is a zero-knowledge proof; - a registered mechanism is universally correct outside its named implementation, trust roots, evidence, and bounds; - local or hosted checks establish universal conformance, adoption, or accreditation; or - VSTD 1.2.0 has already been released. ## Exact-head local and hosted validation All current results below use head dbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7d and tree 36f78119fcbf4748c7e02fed8bc55e2fd389a840. - Commit 833b8ea0 changes only the generated-document token restoration order and presentation regressions. It changes no normative source, VSTD receipt schema, numbered profile, Python application programming interface (API), or actor-trust semantics. - Commit e31bd77b changes only the release procedure, tag workflow, changelog, and release regression. It makes the documented immutable-release requirement executable and changes no VSTD receipt schema, numbered profile, Python API, or actor-trust semantics. - Commit dbd94c6a changes only the documentation renderer, presentation regression, and changelog. Generated ordered-list blocks retain their explicit source starts, so release steps 7, 8, and 10 no longer render as step 1. It changes no normative VSTD semantics, schema, Python API, release trigger, or actor-trust rule. - GitHub currently reports immutable releases disabled. The new workflow rejects that state before publication. Enabling the setting, finalizing release metadata with the actual date, tagging, GitHub release publication, Zenodo archival, and Python Package Index publication remain unauthorized and separate from this pull request. - The exact regression failed on parent head 1159839d…: descriptive inline-code links generated null-token markers and rendered as 0. At the current head, 46 generated Hypertext Markup Language (HTML) pages contain no null-token marker, both affected labels are descriptive, and no bare-zero link remains in the browser-visible Standard. - Commit 1159839d changes 13 bounded RISC Zero proof, documentation, manifest/index, and regression files; it changes no VSTD receipt schema, numbered profile, Python API, or actor-trust semantics. - CARGO_NET_OFFLINE=true ./scripts/verify_recorded_proof.sh rebuilt the tracked guest image and verified the replacement non-secret receipt only after the build image ID equaled recorded image 91df751f5764f81ba4995994afb43e87928dc32d23c81799c767794c27eabcff. - The exact adversarial probe preserved the valid new receipt and public envelope but supplied the previous neighboring image ID; RISC Zero rejected the claim digest. - Focused presentation and external-link tests passed: 30 passed. The local complete suite on Windows 11 / Python 3.12 passed: 552 passed, 38 skipped. Branch-aware hosted coverage recorded 83% total coverage. The earlier focused ZIZK and experimental-workflow result remains 33 passed on unchanged mechanism bytes. - Manifest/index, generated API reference, presentation, compilation, and git diff --check passed. TIME.md remains CLEAR; version 1.2.0 remains UNRELEASED. - Exact-commit release candidate generation produced deterministic source ZIP, wheel, source distribution, CycloneDX Software Bill of Materials, and external manifest. Manifest verification, twine check, the 506-text-member public-boundary scan, and installed-wheel command-line/API/artifact-control smoke paths passed. - The commit is signed by automation OpenPGP fingerprint 257B38745D5AC330DB5933639964E5CDED1761F8. Local verification identifies that exact key; the GitHub commit API reports verified=true with reason valid. No Pinentry or human passphrase interaction was required. - Exact-head hosted repository-checks run 33500585392 completed successfully on this exact head: all 16 workflow jobs passed, including conformance-gate; all 17 attached checks were passing. - No tag, release, publication, deployment, or merge occurred. Human semantic review remains unchecked. ## Repaired semantic review blockers Signed commit 24bdba9d closed the two blockers raised against parent head 2eba5bdee2103aea0bd2ad8f39d81cb1f0eb3eca: - TRUST now binds one exact completed transformation edge at a time, requires the complete exact input set and prerequisite TRUST-event digests, and recursively loses current eligibility when an intermediate artifact or transformation becomes inadmissible or conflicted. Historical events remain immutable. - VSTD-5 independence now uses typed binding, identity, separation, and corroboration failures. Duplicate or reused witness identity, declarant reuse, and missing or duplicate assertions cannot yield INDEPENDENT; disagreement may remain independent while preventing corroboration. Signed commit 8893ff6f closes the three distinct blockers found during the next exact-tree review: - Causal localization now requires one exact passing RUST-event digest, checks the selected descendant and ancestor membership, and binds both that event and its deviation-binding digest. BLAME and GUILT therefore inherit an exact deviation coordinate rather than merely a descendant. - Conflict adjudication and current admissibility are separate. Selected artifact and transformation statuses are projected into the current view; REVOKED or FAILED cannot restore dependent TRUST. A resolved non-status conflict remains route-blocking until a mechanism establishes its admissibility effect. Historical conflicts and resolutions remain immutable evidence. - VSTD-5 serializes witnesses, independence assertions, and corroborations as separate ordered arrays. Duplicate, orphan, missing, reused-identity, and disagreement inputs are preserved exactly, so every emitted bounded negative or malformed-input receipt rechecks identically instead of collapsing its own cause. Regression probes cover exact deviation selection and tampering, neighboring and non-passing RUST events, status resolutions in both directions, non-status resolution boundaries, replay of every consequence, malformed witness bundles, duplicate identities, declarant reuse, assertion cardinality, independent disagreement, and exact obligation binding for GUILT. Signed commit 31810f66 closes the remaining portable-record blocker and the associated safe hardening observations raised against 8893ff6f: - assess_witness_corroboration remains permissive and diagnostic, but build_vstd5_receipt now raises rather than returning an object outside the strict VSTD-5 receipt profile. recheck_vstd5_receipt applies the same zero-dependency structural gate before importing evidence or invoking mechanisms. - Valid corroboration, independent disagreement, duplicate/orphan/missing assertions, and reused-identity failures remain schema-valid and exactly replayable. Empty witness/corroboration sets, empty required identifiers, malformed external shape, and missing verdict-material bytes are refused. - A generated mutation parity probe exercised 536 schema-invalid variations of a valid receipt; the runtime gate refused all 536. This is adversarial test evidence over those variations, not a proof over every possible Python mapping. - RUST is explicitly historical diagnostic ancestry rather than current-TRUST admissibility. New assurance subject identity is globally disjoint, and the documentation no longer implies a currently implemented general non-status admissibility-effect mechanism. Signed commit c7a02814 closes the two semantic blockers raised against 31810f66: - recheck_vstd5_receipt compares the complete carried entry_vstd4 object with the admitted evidence-bound VSTD-4 entry. Neighboring result_digest or witness_digest values are schema-valid shapes but are refused as inconsistent portable semantics. - corroboration_class is included in the exact mechanism-checked expected proposition. Relabeling the outer field without matching mechanism evidence degrades assessment to UNKNOWN / NOT_ESTABLISHED and fails exact receipt replay. - The frozen VSTD-DATA-0.1 reader again accepts one identifier occurring once in each historical collection, validates and reproduces that recorded lineage, and still rejects duplicates within either collection. Direct add_* construction, evidence-bound Graph establishment, and AssuranceLedger reject the overlap before stronger propagation. - The schema and serialized identifiers are unchanged. Compatibility graph_level remains caller-supplied and NOT_ESTABLISHED; the stricter rules belong to additive evidence-bound and assurance mechanisms. Signed commit 3cb54359 closes the adjacent VSTD-5 claim-identity blocker found against c7a02814: - EvidenceBoundDepthResult retains the exact claim_id supplied to evidence-bound VSTD-4 establishment and includes it in the result digest surface. - VSTD-5 compares WitnessBundle.claim_id directly with that admitted identifier. A name-only change or a consistently relabeled corroboration proposition now yields UNKNOWN / NOT_ESTABLISHED, even when the original binding and witness digests remain exact. - The bounded negative receipt remains schema-valid and replays identically; changing a positive receipt's bundle claim ID after build is refused by exact replay. - A separate regression proves that the VSTD-4 claim ID remains distinct from ClaimBinding.coordinate.subject; matching the admitted claim ID succeeds even when that coordinate subject differs. - No identifier-alias mechanism was invented. Any future alias requires its own bounded proposition, evidence, and mechanism. Signed commit 5d0e9a60 records the Checkpoint D objection as a live repository contradiction before implementation. It preserves the accepted parent coordinate 3cb54359451833e0c8984c78d3f2de6307f1282d / 2837ca8aae786234013797937ac3644f3864258d and names the exact GUILT overpromotion defect. Signed repair commit 5eb38f3d then closes that recorded contradiction: - ObligationCoordinate binds the obligation identifier and content digest, scope, assumptions, and exclusions. - RESPONSIBILITY_COMPONENT, OBLIGATION_APPLICABILITY, and OBLIGATION_VIOLATION are independent assurance events. Every component binds its mechanism evaluation and the same artifact/deviation coordinate; the two obligation components also bind the same exact obligation. - compose_guilt accepts only established, distinct component events and emits a GUILT event whose payload binds all three component-event digests. An exact passing BLAME event may satisfy the responsibility component only when its event digest and coordinates match. - VerificationSession.evaluate_compound invokes one compound mechanism once while preserving three distinct expected propositions and evaluations. It does not relabel three unrelated calls as one compound check. - The legacy opaque diagnose(GUILT) route now fails closed as NOT_ESTABLISHED; a combined pass, decorative obligation text, topology, or matching field names cannot earn GUILT. - Event serialization and replay preserve the component evidence bytes, compound invocation grouping, component-event digests, order, and hash chain. Missing, duplicated, reordered, mismatched, or tampered components do not replay as established GUILT. - Absence of GUILT does not establish innocence, exoneration, obligation satisfaction, absence of hidden contributors, actor reputation, moral character, or automatic legal liability. - After the mechanism, documentation, schema, public export, and regressions agreed, TIME.md returned to Status: CLEAR; Git history preserves the prior OPEN state. Signed commit 11f243c8 records the Checkpoint E thaw-lineage objection as a live repository contradiction before implementation. Signed child 3f98446f adds the actual-parent boundary, exact coordinate checks, external anchors, strict sidecar parsing, CLI/API changes, documentation, and adversarial regressions, then returns TIME.md to CLEAR. Exact-head hosted run 33330694496 then exposed one adjacent accepted-behavior regression: resolving the supplied descendant path followed a symbolic link before artifact classification. Signed follow-up 19e00bdb changes only that path-normalization seam, preserving the supplied symbolic-link identity so the existing _source_entries refusal applies. The exact Linux regression, complete artifact-control group, full local suite, and exact-head hosted conformance run then passed. No schema, API, test expectation, documentation, or TIME.md choreography was added for that one-line repair. Fresh Checkpoint E review subsequently falsified two neighboring creation paths at head 19e00bdb75527f6580de59752c1378691798356e / tree 6d5f80be2a461ef7e822caa114b1be2ffffb67f0: a top-level freeze-source symbolic link inherited its target's artifact identity, and a dangling thaw-destination symbolic link redirected bytes and lineage metadata to its absent target. Signed child 6b8fe413 preserves the final lexical source or destination entry through classification, rejects every preexisting output entry with an os.path.lexists-style check, uses exclusive creation for file descendants and sidecars, and cleans only entries created by the invocation without traversing a replacement link. Freeze bundle destinations, thaw descendants, and generated sidecars now refuse links to existing or absent targets without mutating those targets. Linux-effective regressions cover source links to files, directories, and absent targets; nested links; bundle-output links; descendant-output links; sidecar-output links; ordinary file and directory success; clean-to-dirty transitions; exclusive-creation races; and failure cleanup. Branch-aware coverage executed all 55 added executable implementation lines and every branch originating on them. Local exact-commit release validation produced deterministic wheel and source-distribution bytes, verified the manifest and Software Bill of Materials, scanned 506 text members across five artifacts for the public boundary, and exercised the installed wheel's API and CLI. The remaining filesystem limit is explicit: lexical checks and exclusive file/sidecar creation narrow final-entry replacement attacks but do not establish universal race freedom against a concurrent privileged process. Read-only aliases for a supplied parent bundle or explicit thaw-record path remain permitted when they resolve to the same verified bytes; content, seals, coordinates, and optional external anchors still govern the result. Signed commit f2c7438c records the confirmed internal bundle-member contradiction at affected head 6b8fe413c1155f877efb2b557cb3ad51342872f1 / tree b67052abe008319e730b7fe2c0cfedfc3614e6f3: on WSL2/ext4, a linked external freeze.json and a linked external valid seal envelope each produced SEALED. It preserves the already accepted outer parent-bundle and explicit thaw-record alias policy and leaves behavior unchanged while TIME.md is OPEN. Signed child b6d97647 closes that exact contradiction. Internal manifest and seal reads now classify the lexical final entry before opening, require ordinary regular files, narrow the classification/open race with no-follow and opened-object identity checks where available, and parse/hash one captured manifest snapshot. The seals container must be an ordinary lexical directory; every direct seal member must be a non-link .json regular file. Payload final entries and descendants use the same link-like and special-object refusal. Seal creation requires lexical absence or an ordinary existing container/target, uses exclusive creation, and removes only invocation-created entries on handled failure without traversing a replacement link. TIME.md returns to CLEAR only in this repair commit. Repaired outcomes include structural FAIL for external, internal-identical, read-only-target, dangling, directory, special-object, symbolic-link, and supported reparse-point internal members; preserved SEALED for ordinary valid members; preserved zero-seal FROZEN_UNSEALED / NOT_ESTABLISHED behavior; preserved ordinary valid-plus-invalid seal conflict semantics; accepted fully verified outer aliases; and sidecar-only thaw history remaining NOT_ESTABLISHED. Ordinary hard-linked manifest and seal files remain accepted regular-file byte-and-path semantics rather than claims of exclusive inode identity. The nine repair files are CHANGELOG.md, TIME.md, docs/API_STABILITY.md, docs/ARCHITECTURE.md, docs/CLAIMS_AND_LIMITS.md, src/verifier/artifact_control/__init__.py, src/verifier/specifications/ARTIFACT_CONTROL.md, standard/ARTIFACT_CONTROL.md, and tests/test_artifact_control.py. The normative and packaged specification copies remain byte-identical. Both new commits are signed with the repository signing key and are linear children: 6b8fe413f2c7438cb6d97647. The remaining boundary is explicit: ordinary hard links do not prove exclusive inode ownership; only directly tested Windows junction/reparse behavior is claimed; mount, network-filesystem, case, Unicode-normalization, and hidden-alias behavior remain host-bounded; and lexical checks, no-follow opening, exclusive creation, and invocation-owned cleanup do not establish universal freedom from concurrent privileged replacement or crash consistency. Signed child e9d2b13e adds the direct mutation-sensitive regression requested after Checkpoint E. Replacing only EvidenceBoundDepthResult.claim_id changes the canonical result digest, and the VSTD-5 carried entry_vstd4.result_digest remains bound to the admitted claim identity. This commit changes regression protection only, not governing VSTD semantics, runtime behavior, schema, or wire identifiers. It is signed by the automation OpenPGP key and GitHub marks the signature Verified. Signed child 1159839d closes the Checkpoint F source/proof correspondence defect. The recorded proof and public envelope were regenerated against image 91df751f…bcff; the governed offline verifier now builds the tracked guest with the locked toolchain, compares that build's image ID with the recorded image, and only then verifies the receipt. The repository manifest binds the refreshed proof, public envelope, self-test result, and report digests. Documentation separates proof-to-image verification from source-build-to-image correspondence and continues to exclude witness truth, actor standing, independent builds, production deployment, and VSTD receipt conformance. These commits supersede every prior tree as the Pull Request coordinate. Earlier objected and accepted coordinates remain immutable historical evidence but are no longer the head. The current human-review state and exact remaining gate are summarized near the top of this description. Passing automation and a reviewer recommendation do not complete human semantic review or authorize merge. ## Compatibility and wire impact - Historical compatibility candidate paths remain readable and retain NOT_ESTABLISHED semantics. - Evidence-bound VSTD-4, VSTD-5, and Graph receipt alternatives are additive reference-mechanism surfaces. - VSTD-GRAPH-ASSURANCE-1 is a typed non-receipt event-log mechanism with exact embedded-evidence replay; it does not silently redefine a numbered profile receipt. - The unreleased VSTD-5 draft schema was replaced before release. No released frozen profile was silently redefined. - Commit 31810f66 does not change that strict schema; it makes the supported builder/rechecker conform to it without adding a base dependency. Permissive assessment remains available but is not mislabeled as a receipt. - Commit 3cb54359 does not change the VSTD-5 JSON schema or serialized identifier. It retains the VSTD-4 claim ID in the internal evidence-bound result/digest and enforces exact bundle equality; existing negative receipt shape remains replayable. - Commit e9d2b13e is test-only regression hardening. It changes no runtime behavior, schema, normative semantics, wire identifier, or public API. - Commit 1159839d replaces one unreleased recorded proof and its bound public metadata, adds an exact source-build/image-ID gate to the governed example verifier, and updates matching non-normative report/manifest surfaces. It changes no numbered VSTD profile, frozen receipt identifier, Python API, or actor-derived trust rule. - Commit 5eb38f3d does not add a numbered object or collection profile and does not redefine a frozen receipt. It additively extends the typed VSTD-GRAPH-ASSURANCE-1 event-log schema and Python API with obligation coordinates and separately replayable GUILT components. The legacy opaque GUILT diagnostic path is deliberately narrowed to fail closed because its former positive result was semantically unsound. - Frozen VSTD-DATA-0.1 decoding and receipt replay retain their original separate artifact/transformation namespaces. Direct new construction, evidence-bound Graph establishment, and the assurance overlay require global cross-kind disjointness because their current evidence/subject coordinates are untyped. No schema or serialized identifier changed. - Artifact control, SCITT, workflow projection, and recorded proof mechanisms remain bounded adjacent surfaces. The thaw status API is additively extended with explicit parent and optional external-anchor inputs; sidecar-only callers now receive NOT_ESTABLISHED rather than an unjustified clean/dirty result. - Internal bundle-member classification changes no public schema or wire identifier. It narrows semantically unsound linked-member acceptance while preserving verified outer read aliases, ordinary hard-link byte-and-path semantics, and historical immutable bundle bytes. - Realm and time-capsule architecture remains non-wire documentation in 1.2.0; it does not claim a universal continuity or cross-realm verifier. Closes #22 Closes #23 Closes #24 Closes #25 Closes #26 ## Checklist - [x] No UNKNOWN or CONFLICTED result was promoted without stronger evidence. - [x] No claim was strengthened through repetition, placement, topology, actor reputation, recursion, or field naming. - [x] Normative sources and packaged specification copies agree byte-for-byte. - [x] The current tree contains no retired partial-profile specifications or readers. - [x] Every review commit is signed and has one parent. - [x] No secret, private repository coordinate, or proprietary operational material is included. - [x] Hosted checks pass on exact head dbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7d in run 33500585392 (16 workflow jobs and 17 attached checks). - [x] Human semantic review is complete.

Final authorization: Tyler authorized merge and the documented release sequence on 2026-09-01. This acceptance is bound to head dbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7d and tree 36f78119fcbf4748c7e02fed8bc55e2fd389a840.

@TimeLordRaps TimeLordRaps added documentation Improvements or additions to documentation enhancement New feature or request release-integrity Release provenance, byte identity, or artifact binding security-boundary Execution, trust, or observation boundary accessibility Barrier affecting people with disabilities labels Aug 27, 2026
@TimeLordRaps TimeLordRaps changed the title Implement post-1.2 professionalization gates Complete VSTD 1.2.0 professionalization gates Aug 27, 2026
@TimeLordRaps

Copy link
Copy Markdown
Owner Author

Refreshed native proof verification — 2026-08-27

The checked-in RISC Zero proof was reverified from the pull-request head in the recorded Linux x86-64 / Windows Subsystem for Linux environment, with locked dependencies and Cargo network access disabled:

CARGO_NET_OFFLINE=true ./scripts/verify_recorded_proof.sh
Finished release profile
PASS: real RISC Zero receipt and public statement verified

Coordinates:

  • pull-request head: d941df438312c82df92015b84f4ee27d70603936
  • cargo-risczero 3.0.6
  • expected image identifier: e1e9bf4f68ef60ff9af6b50e144082bc475cc20cab47e8187201153da597dcd8
  • receipt: examples/zizk_artifact_first/risc0/recorded-proof/receipt.msgpack

This establishes native verification of the recorded bounded proof under the pinned verifier and image identifier. It is not a VSTD receipt mapping, independent reproduction, proof of the witness's external truth, or hosted continuous-integration coverage.

@TimeLordRaps TimeLordRaps changed the title Complete VSTD 1.2.0 professionalization gates Prepare the complete VSTD 1.2.0 release candidate Aug 28, 2026
@TimeLordRaps
TimeLordRaps changed the base branch from codex/v1.2.0-workflow-profile to main August 28, 2026 00:56
@TimeLordRaps
TimeLordRaps force-pushed the codex/post-1.2-professionalization branch 3 times, most recently from c5ef9e8 to 0b088eb Compare August 28, 2026 23:44
Reason: Establish only the full object and Graph numbered-profile semantics in current specifications, schemas, and runtime checks.

Evidence: Normative sources, packaged byte copies, receipt schemas, mechanisms, specimens, and adversarial tests change together.

Coordinate: VSTD-1 through VSTD-5; VSTD-Graph-1 through VSTD-Graph-5; release 1.2.0.

Falsification: A retired partial-profile identifier remains active, packaged specification bytes differ, or a later profile strengthens an unmet prerequisite.

Compatibility: Retired developmental specifications and readers are absent; current serialized identifiers are explicit and fail closed.
Reason: Separate capture, planning, validation, inspection, reproduction, and impact responsibilities while preserving one public run-receipt mechanism.

Evidence: The runtime modules, generic-run specimen, stable-payload reconstruction, and adversarial lifecycle tests change together.

Coordinate: VSTD-1 generic computational run assessment; release 1.2.0.

Falsification: A stable field is omitted from digest reconstruction, an inadmissible receipt validates, or reproduction exceeds its declared ceiling.

Compatibility: New receipts use the current VSTD-1 assessment context; no retired developmental container is emitted or read.
Reason: Bind preserved artifact bytes, declared closure, signatures, and additive thaw lineage without conflating freeze, seal, encryption, or temporal continuity.

Evidence: Normative text, strict schemas, implementation, and tamper-focused tests change together.

Coordinate: Artifact control mechanism 1; VSTD 1.2.0 artifact-first control surface.

Falsification: Missing bytes are treated as preserved, a modified closure validates, or thaw mutates the sealed parent.

Compatibility: Additive mechanism only; it does not redefine numbered-profile receipt semantics or restore retired specifications.
Reason: Translate exact VSTD receipt claims into Supply Chain Integrity, Transparency, and Trust envelopes without inheriting external guarantees by citation or placement.

Evidence: Adapter code, recorded cryptographic specimens, semantic boundary documents, and adversarial interoperability tests change together.

Coordinate: VSTD to SCITT translation seam; release 1.2.0.

Falsification: Translation widens a proposition, ignores a digest mismatch, or treats registration or transparency as VSTD conformance.

Compatibility: Optional additive adapter; base runtime remains dependency-free and current receipt identifiers remain unchanged.
Reason: Represent bounded task allocation and hosted-result observations without upgrading repository or platform state into a verification verdict.

Evidence: Profile model, schema, GitHub projection, command surface, example, experiment manifest, generated index, and tests change together.

Coordinate: Experimental workflow interchange profile; non-normative release 1.2.0 surface.

Falsification: Placement, assignment, repetition, or a hosted label increases assurance without a named checking mechanism.

Compatibility: Optional experimental surface; it does not alter numbered-profile conformance or the base dependency set.
Reason: Make zero-identity and zero-knowledge mechanisms inspectable as artifact-bound references rather than actor-trust shortcuts or a buried side study.

Evidence: Executable fixtures, RISC Zero source, exact recorded proof bytes, public commitments, self-test results, threat boundaries, experiment records, and offline-verification tests change together.

Coordinate: ZIZK artifact-first architecture; bounded optional proof mechanisms for VSTD 1.2.0.

Falsification: A proof artifact is missing or digest-mismatched, identity becomes computational trust, or a backend claim exceeds the predicate actually checked.

Compatibility: Additive reference mechanisms; optional proof backends remain bounded and do not redefine core receipts.
Reason: Keep runtime, software, machine, provider, and optional actor coordinates distinct while exposing exactly what hardware evidence establishes.

Evidence: Hardware models, adapters, provenance checks, command handlers, renamed profile documentation, and capability tests change together.

Coordinate: VSTD-3 execution and substrate evidence; release 1.2.0.

Falsification: Assignment implies trust or responsibility, provider evidence exceeds its binding, or an unsupported substrate validates cleanly.

Compatibility: Existing VSTD-3 serialized identifiers remain exact; documentation moves from ambiguous layer naming to numbered-profile terminology.
Reason: Expose the implemented receipt, artifact, workflow, and hardware mechanisms through one lazy, dependency-bounded package and canonical command surface.

Evidence: Package metadata, lazy exports, command dispatch, API policy, and installed-surface tests change together.

Coordinate: verifier-standard 1.2.0 Python API and vstd command-line interface.

Falsification: Base import requires an optional dependency, an advertised export is unreachable, or command dispatch accepts an unsupported receipt as valid.

Compatibility: The canonical vstd command and retained aliases remain available; current API additions are explicit and no retired receipt reader is restored.
Reason: Eliminate a first-impression example whose local synthetic packet did not reproduce the hosted submission, image, hardware, or public retrieval path.

Evidence: The complete rehearsal, copied upstream snapshot, generated packet, and its repository-only test are removed together.

Coordinate: Public examples and onboarding boundary for release 1.2.0.

Falsification: Any navigation, manifest, test, or current documentation still presents the removed rehearsal as public verification evidence.

Compatibility: No runtime or numbered-profile wire behavior changes; Git history retains the deleted forensic state.
Reason: Give newcomers, maintainers, and agents a concise authoritative reading path, explicit claim limits, terminology discipline, and contradiction escalation surface.

Evidence: Root guidance, architecture map, human and agent controls, issue templates, glossary, concepts guide, and overview assets change together.

Coordinate: Public governance and onboarding surface for VSTD 1.2.0.

Falsification: A first-use acronym is unexplained, numbered profiles are called assurance levels, repository contradiction is confused with runtime conflict, or public prose exceeds implementation.

Compatibility: Documentation and governance only; normative authority remains under standard and dead developmental specifications remain absent.
Reason: Make the authoritative standard, newcomer guides, source-linked API, first-party definition previews, schemas, and reference pages navigable from one commit-addressed Pages build.

Evidence: Deterministic builders, generated source pages, local definition cards, presentation and link gates, Pages workflow, and regression tests change together.

Coordinate: GitHub Pages and repository documentation surface for release 1.2.0.

Falsification: Generated pages are stale, a local link or schema route breaks, a definition card depends on a runtime wiki fetch, or API links do not resolve to source.

Compatibility: Generated HTML is presentation only; Markdown under standard remains normative and no receipt bytes are reinterpreted.
Reason: Bind source, packages, software bill of materials, metadata, contradiction state, cross-platform bytes, and hosted gates to the exact candidate commit.

Evidence: Release procedures, deterministic builder and verifier, metadata checks, continuous-integration workflows, changelog, citation data, and adversarial release tests change together.

Coordinate: verifier-standard 1.2.0 release and packaging boundary.

Falsification: Source members differ from Git, rebuilt artifacts differ across platforms, TIME is not CLEAR, metadata claims release prematurely, or a protected check belongs to another commit.

Compatibility: Packaging and release controls are additive; publication remains a separate maintainer action and no tag or release is created here.
Reason: Preserve the recorded RISC Zero proof commands as directly runnable Unix entrypoints after the Windows history reconstruction.

Evidence: Both script blobs remain byte-identical to the pre-rewrite candidate and only their executable modes are restored.

Coordinate: ZIZK RISC Zero recorded-proof command surface; release 1.2.0.

Falsification: Either script mode differs from the preserved candidate or direct offline invocation loses executable permission.

Compatibility: File-mode repair only; no source, receipt, proof, or schema bytes change.
@TimeLordRaps
TimeLordRaps force-pushed the codex/post-1.2-professionalization branch from 0b088eb to 79ae7ef Compare August 29, 2026 01:55
Reason:
Replace previously documented absence boundaries with executable, fail-closed
reference mechanisms for VSTD-4, VSTD-5, VSTD-Graph profile establishment,
and additive TRUST/ROT/RUST assurance lifecycle analysis.

Evidence:
The implementation dispatches content-addressed evidence to named mechanism
implementations with explicit trust roots and bounds. Receipt recheck paths
rehash embedded bytes, rerun the mechanisms, and compare the complete derived
result. Adversarial tests cover duplicate evidence and paths, challenge,
revocation, staleness, supersession, conflicts, cycles, self-consumption,
corroboration disagreement, incomplete witness separation, lifecycle-driven
trust invalidation, diagnostic RUST, and separately earned BLAME/GUILT.

Coordinate:
Parent 79ae7ef on
codex/post-1.2-professionalization for PR #27.

Falsification:
A forged field-only PASS, repeated evidence, caller-supplied rating, unresolved
independence seam, inadmissible ancestor, changed embedded byte, replaced
built-in mechanism, cycle, or replay divergence must refuse establishment or
produce UNKNOWN/CONFLICTED/FAIL rather than clean assurance.

Compatibility/wire impact:
The historical compatibility candidate paths remain readable and retain
NOT_ESTABLISHED semantics. New evidence-bound receipt alternatives and the
VSTD-GRAPH-ASSURANCE-1 non-receipt log are additive. The unreleased VSTD-5 draft
shape is replaced before release; no frozen released profile is silently
redefined.
Reason:
Align every public control surface with the implemented evidence-bound VSTD-4,
VSTD-5, VSTD-Graph, TRUST, ROT, RUST, BLAME, and GUILT mechanisms so the release
candidate no longer describes shipped reference paths as deferred research.

Evidence:
README, architecture, claims, governance, human and agent guides, roadmap,
change history, SCITT boundaries, Pages, generated API reference, overview
assets, flagship specimens, and the artifact-first experiment index now name
the exact implemented mechanism and preserve its external-evidence limits.
Presentation checks enforce the resulting maturity and terminology contract.

Coordinate:
Parent 70706ec on codex/post-1.2-professionalization for PR #27.

Falsification:
A public page that calls the reference mechanism absent, treats candidate
ratings as established, converts identity into trust, presents diagnostic RUST
as causal blame, or claims external witnesses/interoperability must fail the
presentation or semantic review boundary.

Compatibility/wire impact:
Documentation and generated presentation are synchronized with the additive
runtime/schema work in the parent commit. Historical receipts remain readable;
no released frozen wire identifier is redefined. Regenerated flagship specimens
truthfully carry the current package standard-status coordinate.
Reason:
Python 3.10 supplies the inherited Enum documentation string `An enumeration.`
for an undocumented str/Enum class, while later interpreters expose a different
inherited string. That made the generated API reference interpreter-dependent.

Evidence:
MechanismOutcome now declares its own exact documentation string. The regression
assertion binds that declaration, and Python 3.10 now passes the generated-reference
and full presentation checks locally. Forty-four adjacent assurance and presentation
tests pass after the repair.

Coordinate:
Parent ca2b974 on
codex/post-1.2-professionalization for PR #27; hosted run 33254844371 exposed
the defect only in base Python 3.10.

Falsification:
Running scripts/build_reference.py --check or scripts/check_presentation.py under
Python 3.10 must reproduce the committed docs/reference.html exactly. Any inherited
interpreter-specific Enum summary is a failure.

Compatibility/wire impact:
No receipt, schema, runtime verdict, or public callable changes. This adds an explicit
class docstring and a regression assertion so generated documentation is stable across
the advertised Python 3.10 through 3.13 range.
Reason:
Close two semantic-review blockers and make BLAME/GUILT's distinction mechanism-bound rather than field-derived.

Evidence:
The prior runtime retained descendant TRUST after an intermediate artifact was revoked, and duplicate witness identity could still yield computed_independence=INDEPENDENT. Both counterexamples were reproduced at 2eba5bd before this change.

Coordinate:
VSTD-GRAPH-ASSURANCE-1 TRUST/conflict events; unreleased VSTD-5 witness result; artifact-relative diagnostic attribution.

Falsification:
Reject the change if TRUST can skip a transformation, remain current after a required artifact/edge degrades or conflicts, or if duplicate/missing/reused witness identity or independence assertions can yield INDEPENDENT. Reject GUILT if its exact violated obligation is not part of the mechanism-checked proposition.

Compatibility and wire impact:
This intentionally revises unreleased VSTD-GRAPH-ASSURANCE-1 and VSTD-5 shapes and the unreleased record_trust call surface before 1.2.0. No released receipt identifier is silently redefined. Historical Graph bytes and recorded events remain immutable; current eligibility is derived additively.
Reason:
Close three semantic-review blockers without weakening UNKNOWN, conflict retention, or immutable historical evidence.

Evidence:
At parent 24bdba9, BLAME could be established without selecting one of two descendant deviations; resolving a status conflict to REVOKED restored dependent TRUST while leaving the historical VALID state visible; and a duplicate VSTD-5 independence assertion was collapsed by receipt serialization so the emitted receipt failed its own rechecker.

Coordinate:
VSTD-GRAPH-ASSURANCE-1 causal localization, conflict-resolution current-state overlay, edge-local TRUST filtering, and the unreleased VSTD-5 witness bundle/receipt.

Falsification:
Reject this change if localization can omit or substitute its passing RUST event and deviation binding; if selecting REVOKED or FAILED can restore current TRUST; if arbitrary conflict adjudication implies admissibility; or if any emitted duplicate, orphan, missing, reused-identity, or negative witness input fails exact build-to-recheck replay.

Compatibility and wire impact:
This intentionally revises the unreleased VSTD-GRAPH-ASSURANCE-1 localization shape and localize_cause call, plus the unreleased VSTD-5 bundle shape, before 1.2.0. VSTD-Graph-1 receipts remain immutable and own no resolution transition; the separate non-receipt assurance overlay retains historical conflict and resolution evidence. No released receipt identifier is silently redefined.
Reason:
Close the remaining VSTD-5 semantic-review blocker: assessment of malformed inputs is diagnostic, while a supported receipt builder and rechecker must never name a schema-invalid object as a portable receipt.

Evidence:
At parent 8893ff6, empty witness or corroboration sets, empty claim/declarant/witness identifiers, and invalid receipt identifiers could be emitted and replayed even though vstd5_receipt.json rejected them. Artifact and transformation identifiers could also overlap, leaving the Graph assurance subject coordinate ambiguous.

Mechanism:
Add a zero-dependency structural and verdict-evidence gate shared by build_vstd5_receipt and recheck_vstd5_receipt; retain permissive UNKNOWN / NOT_ESTABLISHED assessment; keep representable duplicate, orphan, missing, reused-identity, and disagreement receipts replayable; require globally disjoint Graph object identifiers; and align the Standard, architecture, stability, and release-candidate surfaces.

Falsification:
Reject this change if the builder returns any tested schema-invalid receipt, if the rechecker accepts malformed external shape before mechanism replay, if valid positive or representable negative receipts fail strict schema validation and exact replay, or if an artifact/transformation identifier collision survives Graph validation.

Compatibility and wire impact:
The strict VSTD-5 schema is unchanged. This repairs the supported unreleased builder/rechecker contract before 1.2.0 and narrows portable admission without weakening malformed-input diagnostics. Graph identifiers become globally disjoint because the existing assurance subject field is untyped. Historical receipt bytes remain unchanged; no released profile identifier is redefined.
Reason:
Close two semantic-review blockers without weakening the strict VSTD-5 shape gate or retroactively narrowing the frozen VSTD-DATA-0.1 reader.

Evidence:
At parent 31810f6, a schema-valid VSTD-5 receipt could relabel entry_vstd4.witness_digest or corroboration_class and still replay as CORROBORATED / ESTABLISHED. The same parent also rejected a historical VSTD-DATA-0.1 payload whose artifact and transformation collections each used the same identifier even though the frozen schema and v1.1.3 reader admitted separate namespaces.

Mechanism:
Compare every carried VSTD-4 entry coordinate with the admitted entry; make corroboration_class part of the exact mechanism-checked proposition; retain separate frozen artifact/transformation namespaces during decoding and receipt replay; keep direct new construction strict; and reject cross-kind overlap at evidence-bound Graph establishment and AssuranceLedger boundaries.

Falsification:
Reject this change if either schema-valid cross-field relabeling retains an established replay; if within-kind duplicates can replace recorded evidence; if a frozen two-namespace receipt cannot validate and reproduce; or if an overlapping historical graph can enter evidence-bound establishment or assurance propagation.

Compatibility and wire impact:
No schema or serialized identifier changes. VSTD-5 is unreleased and its existing fields now receive the semantics their names claim. VSTD-DATA-0.1 historical bytes regain the v1.1.3 two-namespace reader behavior, while stricter additive mechanisms remain fail-closed. Compatibility graph_level remains caller-supplied and NOT_ESTABLISHED.
Retain the claim_id used by evidence-bound VSTD-4 establishment and require VSTD-5 witness bundles to use that exact identifier. A shared binding or certificate digest no longer permits a neighboring claim ID to acquire an established corroboration result.

Keep claim identity distinct from ClaimBinding.coordinate.subject, preserve representable UNKNOWN receipts, and cover name-only, mechanism-consistent relabeling, replay tampering, and offline replay.
@TimeLordRaps
TimeLordRaps merged commit 3489953 into main Sep 1, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

accessibility Barrier affecting people with disabilities documentation Improvements or additions to documentation enhancement New feature or request release-integrity Release provenance, byte identity, or artifact binding security-boundary Execution, trust, or observation boundary

Projects

None yet

1 participant