Prepare the complete VSTD 1.2.0 release candidate - #27
Merged
Conversation
This was referenced Aug 27, 2026
Owner
Author
Refreshed native proof verification — 2026-08-27The checked-in RISC Zero proof was reverified from the pull-request head in the recorded Linux x86-64 / Windows Subsystem for Linux environment, with locked dependencies and Cargo network access disabled: Coordinates:
This establishes native verification of the recorded bounded proof under the pinned verifier and image identifier. It is not a VSTD receipt mapping, independent reproduction, proof of the witness's external truth, or hosted continuous-integration coverage. |
This was referenced Aug 27, 2026
TimeLordRaps
changed the base branch from
codex/v1.2.0-workflow-profile
to
main
August 28, 2026 00:56
TimeLordRaps
force-pushed
the
codex/post-1.2-professionalization
branch
3 times, most recently
from
August 28, 2026 23:44
c5ef9e8 to
0b088eb
Compare
Reason: Establish only the full object and Graph numbered-profile semantics in current specifications, schemas, and runtime checks. Evidence: Normative sources, packaged byte copies, receipt schemas, mechanisms, specimens, and adversarial tests change together. Coordinate: VSTD-1 through VSTD-5; VSTD-Graph-1 through VSTD-Graph-5; release 1.2.0. Falsification: A retired partial-profile identifier remains active, packaged specification bytes differ, or a later profile strengthens an unmet prerequisite. Compatibility: Retired developmental specifications and readers are absent; current serialized identifiers are explicit and fail closed.
Reason: Separate capture, planning, validation, inspection, reproduction, and impact responsibilities while preserving one public run-receipt mechanism. Evidence: The runtime modules, generic-run specimen, stable-payload reconstruction, and adversarial lifecycle tests change together. Coordinate: VSTD-1 generic computational run assessment; release 1.2.0. Falsification: A stable field is omitted from digest reconstruction, an inadmissible receipt validates, or reproduction exceeds its declared ceiling. Compatibility: New receipts use the current VSTD-1 assessment context; no retired developmental container is emitted or read.
Reason: Bind preserved artifact bytes, declared closure, signatures, and additive thaw lineage without conflating freeze, seal, encryption, or temporal continuity. Evidence: Normative text, strict schemas, implementation, and tamper-focused tests change together. Coordinate: Artifact control mechanism 1; VSTD 1.2.0 artifact-first control surface. Falsification: Missing bytes are treated as preserved, a modified closure validates, or thaw mutates the sealed parent. Compatibility: Additive mechanism only; it does not redefine numbered-profile receipt semantics or restore retired specifications.
Reason: Translate exact VSTD receipt claims into Supply Chain Integrity, Transparency, and Trust envelopes without inheriting external guarantees by citation or placement. Evidence: Adapter code, recorded cryptographic specimens, semantic boundary documents, and adversarial interoperability tests change together. Coordinate: VSTD to SCITT translation seam; release 1.2.0. Falsification: Translation widens a proposition, ignores a digest mismatch, or treats registration or transparency as VSTD conformance. Compatibility: Optional additive adapter; base runtime remains dependency-free and current receipt identifiers remain unchanged.
Reason: Represent bounded task allocation and hosted-result observations without upgrading repository or platform state into a verification verdict. Evidence: Profile model, schema, GitHub projection, command surface, example, experiment manifest, generated index, and tests change together. Coordinate: Experimental workflow interchange profile; non-normative release 1.2.0 surface. Falsification: Placement, assignment, repetition, or a hosted label increases assurance without a named checking mechanism. Compatibility: Optional experimental surface; it does not alter numbered-profile conformance or the base dependency set.
Reason: Make zero-identity and zero-knowledge mechanisms inspectable as artifact-bound references rather than actor-trust shortcuts or a buried side study. Evidence: Executable fixtures, RISC Zero source, exact recorded proof bytes, public commitments, self-test results, threat boundaries, experiment records, and offline-verification tests change together. Coordinate: ZIZK artifact-first architecture; bounded optional proof mechanisms for VSTD 1.2.0. Falsification: A proof artifact is missing or digest-mismatched, identity becomes computational trust, or a backend claim exceeds the predicate actually checked. Compatibility: Additive reference mechanisms; optional proof backends remain bounded and do not redefine core receipts.
Reason: Keep runtime, software, machine, provider, and optional actor coordinates distinct while exposing exactly what hardware evidence establishes. Evidence: Hardware models, adapters, provenance checks, command handlers, renamed profile documentation, and capability tests change together. Coordinate: VSTD-3 execution and substrate evidence; release 1.2.0. Falsification: Assignment implies trust or responsibility, provider evidence exceeds its binding, or an unsupported substrate validates cleanly. Compatibility: Existing VSTD-3 serialized identifiers remain exact; documentation moves from ambiguous layer naming to numbered-profile terminology.
Reason: Expose the implemented receipt, artifact, workflow, and hardware mechanisms through one lazy, dependency-bounded package and canonical command surface. Evidence: Package metadata, lazy exports, command dispatch, API policy, and installed-surface tests change together. Coordinate: verifier-standard 1.2.0 Python API and vstd command-line interface. Falsification: Base import requires an optional dependency, an advertised export is unreachable, or command dispatch accepts an unsupported receipt as valid. Compatibility: The canonical vstd command and retained aliases remain available; current API additions are explicit and no retired receipt reader is restored.
Reason: Eliminate a first-impression example whose local synthetic packet did not reproduce the hosted submission, image, hardware, or public retrieval path. Evidence: The complete rehearsal, copied upstream snapshot, generated packet, and its repository-only test are removed together. Coordinate: Public examples and onboarding boundary for release 1.2.0. Falsification: Any navigation, manifest, test, or current documentation still presents the removed rehearsal as public verification evidence. Compatibility: No runtime or numbered-profile wire behavior changes; Git history retains the deleted forensic state.
Reason: Give newcomers, maintainers, and agents a concise authoritative reading path, explicit claim limits, terminology discipline, and contradiction escalation surface. Evidence: Root guidance, architecture map, human and agent controls, issue templates, glossary, concepts guide, and overview assets change together. Coordinate: Public governance and onboarding surface for VSTD 1.2.0. Falsification: A first-use acronym is unexplained, numbered profiles are called assurance levels, repository contradiction is confused with runtime conflict, or public prose exceeds implementation. Compatibility: Documentation and governance only; normative authority remains under standard and dead developmental specifications remain absent.
Reason: Make the authoritative standard, newcomer guides, source-linked API, first-party definition previews, schemas, and reference pages navigable from one commit-addressed Pages build. Evidence: Deterministic builders, generated source pages, local definition cards, presentation and link gates, Pages workflow, and regression tests change together. Coordinate: GitHub Pages and repository documentation surface for release 1.2.0. Falsification: Generated pages are stale, a local link or schema route breaks, a definition card depends on a runtime wiki fetch, or API links do not resolve to source. Compatibility: Generated HTML is presentation only; Markdown under standard remains normative and no receipt bytes are reinterpreted.
Reason: Bind source, packages, software bill of materials, metadata, contradiction state, cross-platform bytes, and hosted gates to the exact candidate commit. Evidence: Release procedures, deterministic builder and verifier, metadata checks, continuous-integration workflows, changelog, citation data, and adversarial release tests change together. Coordinate: verifier-standard 1.2.0 release and packaging boundary. Falsification: Source members differ from Git, rebuilt artifacts differ across platforms, TIME is not CLEAR, metadata claims release prematurely, or a protected check belongs to another commit. Compatibility: Packaging and release controls are additive; publication remains a separate maintainer action and no tag or release is created here.
Reason: Preserve the recorded RISC Zero proof commands as directly runnable Unix entrypoints after the Windows history reconstruction. Evidence: Both script blobs remain byte-identical to the pre-rewrite candidate and only their executable modes are restored. Coordinate: ZIZK RISC Zero recorded-proof command surface; release 1.2.0. Falsification: Either script mode differs from the preserved candidate or direct offline invocation loses executable permission. Compatibility: File-mode repair only; no source, receipt, proof, or schema bytes change.
TimeLordRaps
force-pushed
the
codex/post-1.2-professionalization
branch
from
August 29, 2026 01:55
0b088eb to
79ae7ef
Compare
Reason: Replace previously documented absence boundaries with executable, fail-closed reference mechanisms for VSTD-4, VSTD-5, VSTD-Graph profile establishment, and additive TRUST/ROT/RUST assurance lifecycle analysis. Evidence: The implementation dispatches content-addressed evidence to named mechanism implementations with explicit trust roots and bounds. Receipt recheck paths rehash embedded bytes, rerun the mechanisms, and compare the complete derived result. Adversarial tests cover duplicate evidence and paths, challenge, revocation, staleness, supersession, conflicts, cycles, self-consumption, corroboration disagreement, incomplete witness separation, lifecycle-driven trust invalidation, diagnostic RUST, and separately earned BLAME/GUILT. Coordinate: Parent 79ae7ef on codex/post-1.2-professionalization for PR #27. Falsification: A forged field-only PASS, repeated evidence, caller-supplied rating, unresolved independence seam, inadmissible ancestor, changed embedded byte, replaced built-in mechanism, cycle, or replay divergence must refuse establishment or produce UNKNOWN/CONFLICTED/FAIL rather than clean assurance. Compatibility/wire impact: The historical compatibility candidate paths remain readable and retain NOT_ESTABLISHED semantics. New evidence-bound receipt alternatives and the VSTD-GRAPH-ASSURANCE-1 non-receipt log are additive. The unreleased VSTD-5 draft shape is replaced before release; no frozen released profile is silently redefined.
Reason: Align every public control surface with the implemented evidence-bound VSTD-4, VSTD-5, VSTD-Graph, TRUST, ROT, RUST, BLAME, and GUILT mechanisms so the release candidate no longer describes shipped reference paths as deferred research. Evidence: README, architecture, claims, governance, human and agent guides, roadmap, change history, SCITT boundaries, Pages, generated API reference, overview assets, flagship specimens, and the artifact-first experiment index now name the exact implemented mechanism and preserve its external-evidence limits. Presentation checks enforce the resulting maturity and terminology contract. Coordinate: Parent 70706ec on codex/post-1.2-professionalization for PR #27. Falsification: A public page that calls the reference mechanism absent, treats candidate ratings as established, converts identity into trust, presents diagnostic RUST as causal blame, or claims external witnesses/interoperability must fail the presentation or semantic review boundary. Compatibility/wire impact: Documentation and generated presentation are synchronized with the additive runtime/schema work in the parent commit. Historical receipts remain readable; no released frozen wire identifier is redefined. Regenerated flagship specimens truthfully carry the current package standard-status coordinate.
Reason: Python 3.10 supplies the inherited Enum documentation string `An enumeration.` for an undocumented str/Enum class, while later interpreters expose a different inherited string. That made the generated API reference interpreter-dependent. Evidence: MechanismOutcome now declares its own exact documentation string. The regression assertion binds that declaration, and Python 3.10 now passes the generated-reference and full presentation checks locally. Forty-four adjacent assurance and presentation tests pass after the repair. Coordinate: Parent ca2b974 on codex/post-1.2-professionalization for PR #27; hosted run 33254844371 exposed the defect only in base Python 3.10. Falsification: Running scripts/build_reference.py --check or scripts/check_presentation.py under Python 3.10 must reproduce the committed docs/reference.html exactly. Any inherited interpreter-specific Enum summary is a failure. Compatibility/wire impact: No receipt, schema, runtime verdict, or public callable changes. This adds an explicit class docstring and a regression assertion so generated documentation is stable across the advertised Python 3.10 through 3.13 range.
Reason: Close two semantic-review blockers and make BLAME/GUILT's distinction mechanism-bound rather than field-derived. Evidence: The prior runtime retained descendant TRUST after an intermediate artifact was revoked, and duplicate witness identity could still yield computed_independence=INDEPENDENT. Both counterexamples were reproduced at 2eba5bd before this change. Coordinate: VSTD-GRAPH-ASSURANCE-1 TRUST/conflict events; unreleased VSTD-5 witness result; artifact-relative diagnostic attribution. Falsification: Reject the change if TRUST can skip a transformation, remain current after a required artifact/edge degrades or conflicts, or if duplicate/missing/reused witness identity or independence assertions can yield INDEPENDENT. Reject GUILT if its exact violated obligation is not part of the mechanism-checked proposition. Compatibility and wire impact: This intentionally revises unreleased VSTD-GRAPH-ASSURANCE-1 and VSTD-5 shapes and the unreleased record_trust call surface before 1.2.0. No released receipt identifier is silently redefined. Historical Graph bytes and recorded events remain immutable; current eligibility is derived additively.
Reason: Close three semantic-review blockers without weakening UNKNOWN, conflict retention, or immutable historical evidence. Evidence: At parent 24bdba9, BLAME could be established without selecting one of two descendant deviations; resolving a status conflict to REVOKED restored dependent TRUST while leaving the historical VALID state visible; and a duplicate VSTD-5 independence assertion was collapsed by receipt serialization so the emitted receipt failed its own rechecker. Coordinate: VSTD-GRAPH-ASSURANCE-1 causal localization, conflict-resolution current-state overlay, edge-local TRUST filtering, and the unreleased VSTD-5 witness bundle/receipt. Falsification: Reject this change if localization can omit or substitute its passing RUST event and deviation binding; if selecting REVOKED or FAILED can restore current TRUST; if arbitrary conflict adjudication implies admissibility; or if any emitted duplicate, orphan, missing, reused-identity, or negative witness input fails exact build-to-recheck replay. Compatibility and wire impact: This intentionally revises the unreleased VSTD-GRAPH-ASSURANCE-1 localization shape and localize_cause call, plus the unreleased VSTD-5 bundle shape, before 1.2.0. VSTD-Graph-1 receipts remain immutable and own no resolution transition; the separate non-receipt assurance overlay retains historical conflict and resolution evidence. No released receipt identifier is silently redefined.
Reason: Close the remaining VSTD-5 semantic-review blocker: assessment of malformed inputs is diagnostic, while a supported receipt builder and rechecker must never name a schema-invalid object as a portable receipt. Evidence: At parent 8893ff6, empty witness or corroboration sets, empty claim/declarant/witness identifiers, and invalid receipt identifiers could be emitted and replayed even though vstd5_receipt.json rejected them. Artifact and transformation identifiers could also overlap, leaving the Graph assurance subject coordinate ambiguous. Mechanism: Add a zero-dependency structural and verdict-evidence gate shared by build_vstd5_receipt and recheck_vstd5_receipt; retain permissive UNKNOWN / NOT_ESTABLISHED assessment; keep representable duplicate, orphan, missing, reused-identity, and disagreement receipts replayable; require globally disjoint Graph object identifiers; and align the Standard, architecture, stability, and release-candidate surfaces. Falsification: Reject this change if the builder returns any tested schema-invalid receipt, if the rechecker accepts malformed external shape before mechanism replay, if valid positive or representable negative receipts fail strict schema validation and exact replay, or if an artifact/transformation identifier collision survives Graph validation. Compatibility and wire impact: The strict VSTD-5 schema is unchanged. This repairs the supported unreleased builder/rechecker contract before 1.2.0 and narrows portable admission without weakening malformed-input diagnostics. Graph identifiers become globally disjoint because the existing assurance subject field is untyped. Historical receipt bytes remain unchanged; no released profile identifier is redefined.
Reason: Close two semantic-review blockers without weakening the strict VSTD-5 shape gate or retroactively narrowing the frozen VSTD-DATA-0.1 reader. Evidence: At parent 31810f6, a schema-valid VSTD-5 receipt could relabel entry_vstd4.witness_digest or corroboration_class and still replay as CORROBORATED / ESTABLISHED. The same parent also rejected a historical VSTD-DATA-0.1 payload whose artifact and transformation collections each used the same identifier even though the frozen schema and v1.1.3 reader admitted separate namespaces. Mechanism: Compare every carried VSTD-4 entry coordinate with the admitted entry; make corroboration_class part of the exact mechanism-checked proposition; retain separate frozen artifact/transformation namespaces during decoding and receipt replay; keep direct new construction strict; and reject cross-kind overlap at evidence-bound Graph establishment and AssuranceLedger boundaries. Falsification: Reject this change if either schema-valid cross-field relabeling retains an established replay; if within-kind duplicates can replace recorded evidence; if a frozen two-namespace receipt cannot validate and reproduce; or if an overlapping historical graph can enter evidence-bound establishment or assurance propagation. Compatibility and wire impact: No schema or serialized identifier changes. VSTD-5 is unreleased and its existing fields now receive the semantics their names claim. VSTD-DATA-0.1 historical bytes regain the v1.1.3 two-namespace reader behavior, while stricter additive mechanisms remain fail-closed. Compatibility graph_level remains caller-supplied and NOT_ESTABLISHED.
Retain the claim_id used by evidence-bound VSTD-4 establishment and require VSTD-5 witness bundles to use that exact identifier. A shared binding or certificate digest no longer permits a neighboring claim ID to acquire an established corroboration result. Keep claim identity distinct from ClaimBinding.coordinate.subject, preserve representable UNKNOWN receipts, and cover name-only, mechanism-consistent relabeling, replay tampering, and offline replay.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Coordinate > Acronyms: application programming interface (API); continuous integration (CI); GNU Privacy Guard (GPG); JavaScript Object Notation (JSON); RISC Zero (RISC0); Secure Hash Algorithm 256-bit (SHA-256); Software Bill of Materials (SBOM); Supply Chain Integrity, Transparency, and Trust (SCITT); Verifier Standard (VSTD). - Target: VSTD 1.2.0 release candidate against
main. - Base:598c545be3833d6d81bb7e252ca5837f3bb2a449. - Head:dbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7d. - Final Git tree:36f78119fcbf4748c7e02fed8bc55e2fd389a840. - History: 34 GNU Privacy Guard (GPG)-signed, single-parent commits on one branch. The newest commit uses the bounded automation signing key; this does not claim that every prior commit used the same key. - Release state:UNRELEASED; this pull request does not tag, publish, or deploy version 1.2.0. ## Current human-review status > Refreshed 2026-09-01 after the final generated-procedure presentation repair and exact-tree re-audit. This is a navigation summary, not a substitute for the coordinate-bound review records. | Review stage | Current state | Coordinate and consequence | |---|---|---| | Checkpoints A-D | ACCEPTED at their recorded review coordinates | The required signed repairs are ancestors of the current head. Those historical decisions are not silently rebound to a neighboring tree. | | Checkpoint E — artifact freeze, seal, thaw, lineage, and filesystem-entry identity | ACCEPTED at superseded headb6d97647…/ treeac1d7cca…| Latere9d2b13…is test-only VSTD-5 hardening and1159839d…is the bounded ZIZK/RISC Zero repair; neither changes the accepted artifact-control implementation. | | Checkpoint F — ZIZK and bounded RISC Zero reference mechanism | ACCEPTED at current head1159839d…/ tree7d7793e6…| The source-build/image-identifier/proof correspondence and stated residual limitations were accepted. | | Checkpoint G — Graph lifecycle, propagation, and collection-scale assurance | ACCEPTED at current head1159839d…/ tree7d7793e6…| Tyler accepted the exact-tree audit: 72 targeted tests passed, no blocking objection was found, and the compatibility, lifecycle, propagation, and assurance boundaries were accepted. | | Checkpoint H — Supply Chain Integrity, Transparency, and Trust (SCITT), experimental workflow, and VSTD-3 boundaries | ACCEPTED at superseded head1159839d…/ tree7d7793e6…| The later documentation-renderer repair does not change the accepted interoperability, workflow, or substrate semantics. | | Checkpoint I — newcomer and public presentation | ACCEPTED at superseded head833b8ea0…/ tree28bd9ed6…| The later release-workflow repair does not change the accepted documentation renderer or presentation surface. | | Checkpoint J — release truthfulness and merge/release separation | ACCEPTED at superseded heade31bd77b…/ treec53b9140…| The later presentation-only repair preserves the accepted workflow, procedure, metadata, and publication boundaries. | Checkpoint G decision:ACCEPT, recorded 2026-09-01 against head1159839d3a1cb51726cbb87b46eace1ff58d1943and tree7d7793e69a8e41355b5cc4b0faa129d4c2a8433a. Checkpoint H decision:ACCEPT, recorded 2026-09-01 against the same reviewed head and tree. Checkpoint I decision:ACCEPT, recorded 2026-09-01 against head833b8ea086ee0ccec10737090e68054be0e4cc31and tree28bd9ed671625325ec95c8a20917d601363fb5d1. Checkpoint J decision:ACCEPT, recorded 2026-09-01 against heade31bd77b532e8ab7e11005981edd4113a4f4f971and treec53b9140503ebb96d88d27f6f51fe5cb91a33c66. No blocking semantic counterexample survived the repaired exact-tree audit. Final merge judgment: merge-ready at headdbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7d/ tree36f78119fcbf4748c7e02fed8bc55e2fd389a840for explicit maintainer authorization, provided the coordinate and required checks do not change. Merging tomainautomatically triggers the public GitHub Pages documentation deployment; it does not create thev1.2.0tag, GitHub release, Zenodo record, or Python Package Index publication. Those remain separate actions. The final checklist item remains intentionally unchecked. No merge, tag, release, publication, or deployment is authorized by this status update. The aggregate change exceeds GitHub's 20,000-line pull-request diff endpoint. Review the signed commits below in order; no individual commit exceeds that endpoint limit. ## Review map | Commit | Review surface | Primary falsification question | |---|---|---| |fbab340e| Current VSTD and VSTD-Graph numbered profiles, schemas, core and Graph checks | Can field names, depth, multiplicity, or propagation strengthen an unmet coordinate? | |54e5798f| Generic-run capture, validation, inspection, reproduction, and impact | Can a changed or incomplete stable payload validate or reproduce beyond its ceiling? | |e86a4b47| Artifact freeze, self-closing seal, and additive thaw | Can missing or changed bytes validate, or can thaw mutate the sealed parent? | |798e99c2| Bounded SCITT interoperability | Does translation widen a proposition or inherit assurance from placement? | |3979a564| Experimental workflow profile | Can allocation, repetition, or hosted labels manufacture assurance? | |764f33c7| ZIZK artifact-first references and recorded RISC0 proof | Are proof bytes, public commitments, predicate, and image identifier bound exactly? | |3cc2186c| VSTD-3 execution and substrate evidence | Does assignment imply trust, responsibility, or unsupported hardware fact? | |0c7cec41| Supported Python API andvstdcommand surface | Is an advertised export unreachable or an optional dependency required by base import? | |002ff24c| Removal of the unreproducible SimulacraBench rehearsal | Does any current public surface still present that local rehearsal as verification evidence? | |a19bf4eb| Public architecture, terminology, humans/agents/TIME controls | Can a newcomer distinguish profile, depth, claim status, repository contradiction, TRUST, RUST, and ROT? | |4ceb6049| Pages, API reference, local definition previews, links, and presentation gates | Are generated pages stale, source links broken, or definitions dependent on a runtime wiki fetch? | |7d253c9e| Release metadata, deterministic artifacts, SBOM, and hosted gates | Can publication proceed from mismatched Git bytes, metadata, contradiction state, or check coordinate? | |79ae7ef6| Executable mode preservation for offline proof commands | Are proof script bytes and executable modes identical to the validated candidate? | |70706ec5| Evidence dispatch, evidence-bound VSTD-4/VSTD-5/Graph establishment, assurance replay, schemas, and adversarial tests | Can caller fields, duplicate evidence, unresolved independence, inadmissible ancestry, cycles, or replay tampering create clean assurance? | |ca2b9748| Public architecture, maturity tables, Graph lifecycle semantics, Pages, and regenerated specimens | Does any public surface still call the implemented mechanisms absent, experimental, or stronger than their evidence? | | 2eba5bd | Python 3.10 deterministic API-reference repair | Can interpreter-specific inherited Enum documentation drift the generated public reference? | |24bdba9d| Edge-local TRUST dependencies, typed witness-independence failures, and bounded BLAME/GUILT semantics | Can a direct jump, inadmissible intermediate, unresolved conflict, duplicate identity, or unverified obligation manufacture assurance? | |8893ff6f| Exact deviation localization, conflict-adjudication consequences, and lossless VSTD-5 replay inputs | Can an unselected deviation, inadmissible selected status, or serialization collapse manufacture or erase assurance? | |31810f66| Strict VSTD-5 receipt admission, verdict-evidence coverage, Graph subject identity, and diagnostic ancestry | Can schema-invalid shape, missing payload bytes, or an artifact/transformation identifier collision cross the portable boundary? | |c7a02814| VSTD-5 cross-field semantics and frozen Graph-reader compatibility | Can a redundant digest or class be relabeled, or can a newer assurance invariant narrow historical bytes under the same identifier? | |3cb54359| Transitive VSTD-4/VSTD-5 claim identity, negative replay, and identifier/coordinate separation | Can a neighboringclaim_idinherit an established VSTD-4 result through shared digests or consistent relabeling? | |5d0e9a60| Repository contradiction annunciation for GUILT composition | Does the review objection remain visible at an exact coordinate until a mechanism-level repair exists? | |5eb38f3d| Separately bound responsibility, obligation applicability, obligation violation, compound evaluation, GUILT composition, serialization, and replay | Can an opaque pass, decorative obligation, coordinate mismatch, duplicated component, or tampered component digest manufacture GUILT? | |11f243c8| Repository contradiction annunciation for thaw-lineage verification | Can a self-derived sidecar closure be mistaken for evidence of a sealed parent or historical copy? | |3f98446f| Supplied-parent thaw status, fail-closed lineage binding, CLI/API/schema/docs, and regressions | Can a fabricated or re-authored sidecar, neighboring parent, invalid seal, followed symlink, or absent anchor manufactureTHAWED_CLEAN? | |19e00bdb| Descendant symbolic-link identity preservation | Can path resolution follow a symbolic link and manufacture recorded or verified target-file agreement? | |6b8fe413| Lexical creation-path classification and invocation-owned cleanup | Can a source, destination, or replacement link redirect artifact bytes or cleanup into its target? | |f2c7438c| Repository contradiction annunciation for internal bundle-member aliases | Does the normative/runtime conflict remain visible before the repair is claimed? | |b6d97647| Internal manifest, payload, seals-container, and seal-envelope lexical closure | Can an internal link, dangling link, reparse-point alias, or special object lend authoritative bytes to a bundle? | |e9d2b13| Mutation-sensitive VSTD-4 claim-identity digest regression | Can removingclaim_idfrom the canonical admitted-result payload escape the VSTD-5 carried-entry digest? | |1159839d| Recorded RISC Zero proof, tracked guest image binding, public envelope, report, manifest, and boundaries | Can a valid proof for a neighboring historical image be presented as evidence for the currently tracked guest source? | |833b8ea0| Generated documentation token restoration and regression | Can nested inline formatting inside a link become an unresolved token or opaque numeric label in the public Pages artifact? | |e31bd77b| Release immutability ordering, workflow enforcement, documentation, and regression | Can a tag publish a mutable GitHub release because the setting check occurs too late or is merely advisory? | |dbd94c6a| Ordered-procedure rendering and regression | Can generated Pages restart a segmented numbered procedure and visually move tag publication ahead of its prerequisites? | ## Governing architecture - The repository uses the complete VSTD-1 through VSTD-5 object profile ladder and VSTD-Graph-1 through VSTD-Graph-5 collection profile ladder. - Retired partial-profile developmental specifications, identifiers, emitters, and compatibility readers are absent from the current tree. Git history alone preserves their historical existence. - ZIZK artifact-first TRUST is governing architecture, not a side experiment or actor-reputation system. - TRUST is mechanism-earned forward artifact support. ROT is typed degradation of current admissibility without rewriting history. RUST is inverse-TRUST diagnostic traversal through historically recorded contributing ancestry; current revocation or conflict may block TRUST without erasing that diagnostic history. -AssuranceLedgerimplements hash-chained event serialization and replay, evidence-bound TRUST, strictly degrading ROT, challenge-ledger projection, reverse RUST, unique-descendant concentration, additive conflict resolution, explicit localization, and bounded artifact-relative diagnostic attribution. - RUST alone establishes ancestral diagnostic reachability.BLAMEis a separately checked, bounded material-contribution or responsibility relation from an artifact to an exact deviation.GUILTis composed only when the ledger binds three separately earned component events for the same artifact and exact deviation: responsibility or material contribution, applicability of one exact obligation under declared scope and bounds, and violation of that same obligation relative to that deviation. The final GUILT event binds all three component-event digests. One compound mechanism invocation may evaluate the components together only when it emits three separately bound proposition evaluations. GUILT is not reverse BLAME, and neither result becomes actor reputation, moral character, automatic legal liability, or inherited falsity. - VSTD-4 retains its compatibility candidate path asNOT_ESTABLISHEDand adds an evidence-bound establishment/recheck path over exact VSTD-1/2/3 and fourteen-rung propositions. - VSTD-5 implements an evidence-bound reference mechanism across seven separation dimensions, exact admitted-certificate binding, duplicate refusal, disagreement preservation, and offline receipt recheck. Assessment remains diagnostic over incomplete inputs; the supported builder and rechecker admit only strict receipt shape with every verdict-material evidence byte. Replay compares every carried VSTD-4 entry coordinate, the bundleclaim_idmust equal the exact claim identifier retained by the admitted evidence-bound VSTD-4 result, andcorroboration_classis part of the mechanism-checked proposition rather than assurance-bearing metadata. Shared binding or certificate digests do not create an identifier alias; no alias-mapping mechanism is implemented. This repository does not claim that a real independent external witness has participated. - VSTD-Graph retains caller-supplied compatibility candidates asNOT_ESTABLISHEDand adds an evidence-bound path that reruns every member, ancestor, and reached-edge rating against the exact Graph, collection, members, claim, lifecycle view, mechanisms, roots, and bounds. FrozenVSTD-DATA-0.1decoding retains separate historical artifact/transformation namespaces. Direct new construction, evidence-bound establishment, and assurance propagation require global cross-kind disjointness. - Actor identity, reputation, assignment, and separation never become computational-validity TRUST. - Freeze preserves exact bytes; seal closes a declared state; encryption is separate; thaw creates a mutable descendant. Authoritative internalfreeze.json, payload, seals-container, and seal-envelope entries must have ordinary lexical types and cannot borrow bytes through symbolic links or supported reparse-point aliases. This is distinct from accepted outer parent-bundle and explicit thaw-record read aliases, whose resolved bytes and bindings are still verified. A thaw sidecar is unkeyed lineage metadata: sidecar-only agreement isNOT_ESTABLISHED, and established clean/dirty status requires the actual supplied parent to verify as sealed with every recorded coordinate matching. Current equality does not authenticate the historical copy operation or external continuity. Temporal continuity and realm mappings require separate mechanisms. ## Remaining experimental or external boundaries - Complete hidden-witnessPASS/FAIL/UNKNOWN/CONFLICTEDtrichotomy derivation remains experimental and unimplemented. - No universal scalar support algebra exists. Domain-specific transfer and localization propositions still require truthful mechanisms and observations. - Real independent witnesses, second implementations, cross-implementation replay, operational interoperability, external attacks, and production trust roots remain external evidence rather than repository assertions. - Specific optional proof backends remain bounded by their own recorded mechanisms and maturity. ## Claim boundary This candidate does not claim that: - freeze prevents privileged writes, storage loss, or semantic ROT; - sealing is encryption, preservation, correctness, trusted time, authorization, or ownership; - identity or reputation establishes process validity; - RUST reachability alone proves ancestor falsity, causal responsibility, BLAME, or GUILT; - a technical artifact-relative BLAME/GUILT result concerns an actor's moral character; - a sealed realm declaration or temporal model is thereby true; - a digest, omission, or encryption is a zero-knowledge proof; - a registered mechanism is universally correct outside its named implementation, trust roots, evidence, and bounds; - local or hosted checks establish universal conformance, adoption, or accreditation; or - VSTD 1.2.0 has already been released. ## Exact-head local and hosted validation All current results below use headdbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7dand tree36f78119fcbf4748c7e02fed8bc55e2fd389a840. - Commit833b8ea0changes only the generated-document token restoration order and presentation regressions. It changes no normative source, VSTD receipt schema, numbered profile, Python application programming interface (API), or actor-trust semantics. - Commite31bd77bchanges only the release procedure, tag workflow, changelog, and release regression. It makes the documented immutable-release requirement executable and changes no VSTD receipt schema, numbered profile, Python API, or actor-trust semantics. - Commitdbd94c6achanges only the documentation renderer, presentation regression, and changelog. Generated ordered-list blocks retain their explicit source starts, so release steps 7, 8, and 10 no longer render as step 1. It changes no normative VSTD semantics, schema, Python API, release trigger, or actor-trust rule. - GitHub currently reports immutable releases disabled. The new workflow rejects that state before publication. Enabling the setting, finalizing release metadata with the actual date, tagging, GitHub release publication, Zenodo archival, and Python Package Index publication remain unauthorized and separate from this pull request. - The exact regression failed on parent head1159839d…: descriptive inline-code links generated null-token markers and rendered as0. At the current head, 46 generated Hypertext Markup Language (HTML) pages contain no null-token marker, both affected labels are descriptive, and no bare-zero link remains in the browser-visible Standard. - Commit1159839dchanges 13 bounded RISC Zero proof, documentation, manifest/index, and regression files; it changes no VSTD receipt schema, numbered profile, Python API, or actor-trust semantics. -CARGO_NET_OFFLINE=true ./scripts/verify_recorded_proof.shrebuilt the tracked guest image and verified the replacement non-secret receipt only after the build image ID equaled recorded image91df751f5764f81ba4995994afb43e87928dc32d23c81799c767794c27eabcff. - The exact adversarial probe preserved the valid new receipt and public envelope but supplied the previous neighboring image ID; RISC Zero rejected the claim digest. - Focused presentation and external-link tests passed: 30 passed. The local complete suite on Windows 11 / Python 3.12 passed: 552 passed, 38 skipped. Branch-aware hosted coverage recorded 83% total coverage. The earlier focused ZIZK and experimental-workflow result remains 33 passed on unchanged mechanism bytes. - Manifest/index, generated API reference, presentation, compilation, andgit diff --checkpassed.TIME.mdremainsCLEAR; version 1.2.0 remainsUNRELEASED. - Exact-commit release candidate generation produced deterministic source ZIP, wheel, source distribution, CycloneDX Software Bill of Materials, and external manifest. Manifest verification,twine check, the 506-text-member public-boundary scan, and installed-wheel command-line/API/artifact-control smoke paths passed. - The commit is signed by automation OpenPGP fingerprint257B38745D5AC330DB5933639964E5CDED1761F8. Local verification identifies that exact key; the GitHub commit API reportsverified=truewith reasonvalid. No Pinentry or human passphrase interaction was required. - Exact-head hosted repository-checks run 33500585392 completed successfully on this exact head: all 16 workflow jobs passed, includingconformance-gate; all 17 attached checks were passing. - No tag, release, publication, deployment, or merge occurred. Human semantic review remains unchecked. ## Repaired semantic review blockers Signed commit24bdba9dclosed the two blockers raised against parent head2eba5bdee2103aea0bd2ad8f39d81cb1f0eb3eca: - TRUST now binds one exact completed transformation edge at a time, requires the complete exact input set and prerequisite TRUST-event digests, and recursively loses current eligibility when an intermediate artifact or transformation becomes inadmissible or conflicted. Historical events remain immutable. - VSTD-5 independence now uses typed binding, identity, separation, and corroboration failures. Duplicate or reused witness identity, declarant reuse, and missing or duplicate assertions cannot yieldINDEPENDENT; disagreement may remain independent while preventing corroboration. Signed commit8893ff6fcloses the three distinct blockers found during the next exact-tree review: - Causal localization now requires one exact passing RUST-event digest, checks the selected descendant and ancestor membership, and binds both that event and its deviation-binding digest. BLAME and GUILT therefore inherit an exact deviation coordinate rather than merely a descendant. - Conflict adjudication and current admissibility are separate. Selected artifact and transformation statuses are projected into the current view;REVOKEDorFAILEDcannot restore dependent TRUST. A resolved non-status conflict remains route-blocking until a mechanism establishes its admissibility effect. Historical conflicts and resolutions remain immutable evidence. - VSTD-5 serializes witnesses, independence assertions, and corroborations as separate ordered arrays. Duplicate, orphan, missing, reused-identity, and disagreement inputs are preserved exactly, so every emitted bounded negative or malformed-input receipt rechecks identically instead of collapsing its own cause. Regression probes cover exact deviation selection and tampering, neighboring and non-passing RUST events, status resolutions in both directions, non-status resolution boundaries, replay of every consequence, malformed witness bundles, duplicate identities, declarant reuse, assertion cardinality, independent disagreement, and exact obligation binding for GUILT. Signed commit31810f66closes the remaining portable-record blocker and the associated safe hardening observations raised against8893ff6f: -assess_witness_corroborationremains permissive and diagnostic, butbuild_vstd5_receiptnow raises rather than returning an object outside the strict VSTD-5 receipt profile.recheck_vstd5_receiptapplies the same zero-dependency structural gate before importing evidence or invoking mechanisms. - Valid corroboration, independent disagreement, duplicate/orphan/missing assertions, and reused-identity failures remain schema-valid and exactly replayable. Empty witness/corroboration sets, empty required identifiers, malformed external shape, and missing verdict-material bytes are refused. - A generated mutation parity probe exercised 536 schema-invalid variations of a valid receipt; the runtime gate refused all 536. This is adversarial test evidence over those variations, not a proof over every possible Python mapping. - RUST is explicitly historical diagnostic ancestry rather than current-TRUST admissibility. New assurance subject identity is globally disjoint, and the documentation no longer implies a currently implemented general non-status admissibility-effect mechanism. Signed commitc7a02814closes the two semantic blockers raised against31810f66: -recheck_vstd5_receiptcompares the complete carriedentry_vstd4object with the admitted evidence-bound VSTD-4 entry. Neighboringresult_digestorwitness_digestvalues are schema-valid shapes but are refused as inconsistent portable semantics. -corroboration_classis included in the exact mechanism-checked expected proposition. Relabeling the outer field without matching mechanism evidence degrades assessment toUNKNOWN / NOT_ESTABLISHEDand fails exact receipt replay. - The frozenVSTD-DATA-0.1reader again accepts one identifier occurring once in each historical collection, validates and reproduces that recorded lineage, and still rejects duplicates within either collection. Directadd_*construction, evidence-bound Graph establishment, andAssuranceLedgerreject the overlap before stronger propagation. - The schema and serialized identifiers are unchanged. Compatibilitygraph_levelremains caller-supplied andNOT_ESTABLISHED; the stricter rules belong to additive evidence-bound and assurance mechanisms. Signed commit3cb54359closes the adjacent VSTD-5 claim-identity blocker found againstc7a02814: -EvidenceBoundDepthResultretains the exactclaim_idsupplied to evidence-bound VSTD-4 establishment and includes it in the result digest surface. - VSTD-5 comparesWitnessBundle.claim_iddirectly with that admitted identifier. A name-only change or a consistently relabeled corroboration proposition now yieldsUNKNOWN / NOT_ESTABLISHED, even when the original binding and witness digests remain exact. - The bounded negative receipt remains schema-valid and replays identically; changing a positive receipt's bundle claim ID after build is refused by exact replay. - A separate regression proves that the VSTD-4 claim ID remains distinct fromClaimBinding.coordinate.subject; matching the admitted claim ID succeeds even when that coordinate subject differs. - No identifier-alias mechanism was invented. Any future alias requires its own bounded proposition, evidence, and mechanism. Signed commit5d0e9a60records the Checkpoint D objection as a live repository contradiction before implementation. It preserves the accepted parent coordinate3cb54359451833e0c8984c78d3f2de6307f1282d/2837ca8aae786234013797937ac3644f3864258dand names the exact GUILT overpromotion defect. Signed repair commit5eb38f3dthen closes that recorded contradiction: -ObligationCoordinatebinds the obligation identifier and content digest, scope, assumptions, and exclusions. -RESPONSIBILITY_COMPONENT,OBLIGATION_APPLICABILITY, andOBLIGATION_VIOLATIONare independent assurance events. Every component binds its mechanism evaluation and the same artifact/deviation coordinate; the two obligation components also bind the same exact obligation. -compose_guiltaccepts only established, distinct component events and emits a GUILT event whose payload binds all three component-event digests. An exact passing BLAME event may satisfy the responsibility component only when its event digest and coordinates match. -VerificationSession.evaluate_compoundinvokes one compound mechanism once while preserving three distinct expected propositions and evaluations. It does not relabel three unrelated calls as one compound check. - The legacy opaquediagnose(GUILT)route now fails closed asNOT_ESTABLISHED; a combined pass, decorative obligation text, topology, or matching field names cannot earn GUILT. - Event serialization and replay preserve the component evidence bytes, compound invocation grouping, component-event digests, order, and hash chain. Missing, duplicated, reordered, mismatched, or tampered components do not replay as established GUILT. - Absence of GUILT does not establish innocence, exoneration, obligation satisfaction, absence of hidden contributors, actor reputation, moral character, or automatic legal liability. - After the mechanism, documentation, schema, public export, and regressions agreed,TIME.mdreturned toStatus: CLEAR; Git history preserves the prior OPEN state. Signed commit11f243c8records the Checkpoint E thaw-lineage objection as a live repository contradiction before implementation. Signed child3f98446fadds the actual-parent boundary, exact coordinate checks, external anchors, strict sidecar parsing, CLI/API changes, documentation, and adversarial regressions, then returnsTIME.mdtoCLEAR. Exact-head hosted run33330694496then exposed one adjacent accepted-behavior regression: resolving the supplied descendant path followed a symbolic link before artifact classification. Signed follow-up19e00bdbchanges only that path-normalization seam, preserving the supplied symbolic-link identity so the existing_source_entriesrefusal applies. The exact Linux regression, complete artifact-control group, full local suite, and exact-head hosted conformance run then passed. No schema, API, test expectation, documentation, orTIME.mdchoreography was added for that one-line repair. Fresh Checkpoint E review subsequently falsified two neighboring creation paths at head19e00bdb75527f6580de59752c1378691798356e/ tree6d5f80be2a461ef7e822caa114b1be2ffffb67f0: a top-level freeze-source symbolic link inherited its target's artifact identity, and a dangling thaw-destination symbolic link redirected bytes and lineage metadata to its absent target. Signed child6b8fe413preserves the final lexical source or destination entry through classification, rejects every preexisting output entry with anos.path.lexists-style check, uses exclusive creation for file descendants and sidecars, and cleans only entries created by the invocation without traversing a replacement link. Freeze bundle destinations, thaw descendants, and generated sidecars now refuse links to existing or absent targets without mutating those targets. Linux-effective regressions cover source links to files, directories, and absent targets; nested links; bundle-output links; descendant-output links; sidecar-output links; ordinary file and directory success; clean-to-dirty transitions; exclusive-creation races; and failure cleanup. Branch-aware coverage executed all 55 added executable implementation lines and every branch originating on them. Local exact-commit release validation produced deterministic wheel and source-distribution bytes, verified the manifest and Software Bill of Materials, scanned 506 text members across five artifacts for the public boundary, and exercised the installed wheel's API and CLI. The remaining filesystem limit is explicit: lexical checks and exclusive file/sidecar creation narrow final-entry replacement attacks but do not establish universal race freedom against a concurrent privileged process. Read-only aliases for a supplied parent bundle or explicit thaw-record path remain permitted when they resolve to the same verified bytes; content, seals, coordinates, and optional external anchors still govern the result. Signed commitf2c7438crecords the confirmed internal bundle-member contradiction at affected head6b8fe413c1155f877efb2b557cb3ad51342872f1/ treeb67052abe008319e730b7fe2c0cfedfc3614e6f3: on WSL2/ext4, a linked externalfreeze.jsonand a linked external valid seal envelope each producedSEALED. It preserves the already accepted outer parent-bundle and explicit thaw-record alias policy and leaves behavior unchanged whileTIME.mdisOPEN. Signed childb6d97647closes that exact contradiction. Internal manifest and seal reads now classify the lexical final entry before opening, require ordinary regular files, narrow the classification/open race with no-follow and opened-object identity checks where available, and parse/hash one captured manifest snapshot. The seals container must be an ordinary lexical directory; every direct seal member must be a non-link.jsonregular file. Payload final entries and descendants use the same link-like and special-object refusal. Seal creation requires lexical absence or an ordinary existing container/target, uses exclusive creation, and removes only invocation-created entries on handled failure without traversing a replacement link.TIME.mdreturns toCLEARonly in this repair commit. Repaired outcomes include structuralFAILfor external, internal-identical, read-only-target, dangling, directory, special-object, symbolic-link, and supported reparse-point internal members; preservedSEALEDfor ordinary valid members; preserved zero-sealFROZEN_UNSEALED/NOT_ESTABLISHEDbehavior; preserved ordinary valid-plus-invalid seal conflict semantics; accepted fully verified outer aliases; and sidecar-only thaw history remainingNOT_ESTABLISHED. Ordinary hard-linked manifest and seal files remain accepted regular-file byte-and-path semantics rather than claims of exclusive inode identity. The nine repair files areCHANGELOG.md,TIME.md,docs/API_STABILITY.md,docs/ARCHITECTURE.md,docs/CLAIMS_AND_LIMITS.md,src/verifier/artifact_control/__init__.py,src/verifier/specifications/ARTIFACT_CONTROL.md,standard/ARTIFACT_CONTROL.md, andtests/test_artifact_control.py. The normative and packaged specification copies remain byte-identical. Both new commits are signed with the repository signing key and are linear children:6b8fe413→f2c7438c→b6d97647. The remaining boundary is explicit: ordinary hard links do not prove exclusive inode ownership; only directly tested Windows junction/reparse behavior is claimed; mount, network-filesystem, case, Unicode-normalization, and hidden-alias behavior remain host-bounded; and lexical checks, no-follow opening, exclusive creation, and invocation-owned cleanup do not establish universal freedom from concurrent privileged replacement or crash consistency. Signed childe9d2b13eadds the direct mutation-sensitive regression requested after Checkpoint E. Replacing onlyEvidenceBoundDepthResult.claim_idchanges the canonical result digest, and the VSTD-5 carriedentry_vstd4.result_digestremains bound to the admitted claim identity. This commit changes regression protection only, not governing VSTD semantics, runtime behavior, schema, or wire identifiers. It is signed by the automation OpenPGP key and GitHub marks the signature Verified. Signed child1159839dcloses the Checkpoint F source/proof correspondence defect. The recorded proof and public envelope were regenerated against image91df751f…bcff; the governed offline verifier now builds the tracked guest with the locked toolchain, compares that build's image ID with the recorded image, and only then verifies the receipt. The repository manifest binds the refreshed proof, public envelope, self-test result, and report digests. Documentation separates proof-to-image verification from source-build-to-image correspondence and continues to exclude witness truth, actor standing, independent builds, production deployment, and VSTD receipt conformance. These commits supersede every prior tree as the Pull Request coordinate. Earlier objected and accepted coordinates remain immutable historical evidence but are no longer the head. The current human-review state and exact remaining gate are summarized near the top of this description. Passing automation and a reviewer recommendation do not complete human semantic review or authorize merge. ## Compatibility and wire impact - Historical compatibility candidate paths remain readable and retainNOT_ESTABLISHEDsemantics. - Evidence-bound VSTD-4, VSTD-5, and Graph receipt alternatives are additive reference-mechanism surfaces. -VSTD-GRAPH-ASSURANCE-1is a typed non-receipt event-log mechanism with exact embedded-evidence replay; it does not silently redefine a numbered profile receipt. - The unreleased VSTD-5 draft schema was replaced before release. No released frozen profile was silently redefined. - Commit31810f66does not change that strict schema; it makes the supported builder/rechecker conform to it without adding a base dependency. Permissive assessment remains available but is not mislabeled as a receipt. - Commit3cb54359does not change the VSTD-5 JSON schema or serialized identifier. It retains the VSTD-4 claim ID in the internal evidence-bound result/digest and enforces exact bundle equality; existing negative receipt shape remains replayable. - Commite9d2b13eis test-only regression hardening. It changes no runtime behavior, schema, normative semantics, wire identifier, or public API. - Commit1159839dreplaces one unreleased recorded proof and its bound public metadata, adds an exact source-build/image-ID gate to the governed example verifier, and updates matching non-normative report/manifest surfaces. It changes no numbered VSTD profile, frozen receipt identifier, Python API, or actor-derived trust rule. - Commit5eb38f3ddoes not add a numbered object or collection profile and does not redefine a frozen receipt. It additively extends the typedVSTD-GRAPH-ASSURANCE-1event-log schema and Python API with obligation coordinates and separately replayable GUILT components. The legacy opaque GUILT diagnostic path is deliberately narrowed to fail closed because its former positive result was semantically unsound. - FrozenVSTD-DATA-0.1decoding and receipt replay retain their original separate artifact/transformation namespaces. Direct new construction, evidence-bound Graph establishment, and the assurance overlay require global cross-kind disjointness because their current evidence/subject coordinates are untyped. No schema or serialized identifier changed. - Artifact control, SCITT, workflow projection, and recorded proof mechanisms remain bounded adjacent surfaces. The thaw status API is additively extended with explicit parent and optional external-anchor inputs; sidecar-only callers now receiveNOT_ESTABLISHEDrather than an unjustified clean/dirty result. - Internal bundle-member classification changes no public schema or wire identifier. It narrows semantically unsound linked-member acceptance while preserving verified outer read aliases, ordinary hard-link byte-and-path semantics, and historical immutable bundle bytes. - Realm and time-capsule architecture remains non-wire documentation in 1.2.0; it does not claim a universal continuity or cross-realm verifier. Closes #22 Closes #23 Closes #24 Closes #25 Closes #26 ## Checklist - [x] NoUNKNOWNorCONFLICTEDresult was promoted without stronger evidence. - [x] No claim was strengthened through repetition, placement, topology, actor reputation, recursion, or field naming. - [x] Normative sources and packaged specification copies agree byte-for-byte. - [x] The current tree contains no retired partial-profile specifications or readers. - [x] Every review commit is signed and has one parent. - [x] No secret, private repository coordinate, or proprietary operational material is included. - [x] Hosted checks pass on exact headdbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7din run33500585392(16 workflow jobs and 17 attached checks). - [x] Human semantic review is complete.Final authorization: Tyler authorized merge and the documented release sequence on 2026-09-01. This acceptance is bound to head
dbd94c6abe0722b9ffb60ff92ec1c4f5b65f0c7dand tree36f78119fcbf4748c7e02fed8bc55e2fd389a840.