Releases: TimeLordRaps/verifier
Release list
VSTD v1.2.0
Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).
Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:
gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifierPublic surface and integrations
- Restructure the public first-view path around one bounded project description, one
deterministic demonstration, one canonical maturity table, skeptical claim limits,
contributor routes, and release/citation boundaries; align Pages and package metadata
without changing normative or serialized-receipt semantics. - Normalize the public architecture as a verification complex of named closure
coordinates and cumulative numbered profiles; reserve VSTD-4 rung, candidate depth,
verification order, compatibility level, and checker-cost tier for their distinct uses. - Add experimental workflow profile 0.1 with deterministic canonicalization, strict
validation, bounded work-allocation records, additive amendments and challenges,
explicit unresolved horizons, and verdict-neutral platform events. - Add a normalized GitHub adapter for issues, commits, workflow runs, artifacts, and
pull requests. Successful workflows and merges retainverification_effect = NONE
unless a separate native result is explicitly mapped through a bound VSTD receipt. - Add
vstd experiment validateandvstd experiment github-eventsas offline,
verdict-neutral entry points. Repository artifacts are explicitlyNOT_CHECKEDwith
exit code 2 unless their root is supplied. - Add a machine-readable schema, checked-in verdict-neutral specimen, generated
experiment index, adversarial tests, and a runnable offline example. - Add a generated CLI/API reference page and presentation gates that reject stale
reference or experiment-index content. - Clarify VSTD's role as a verification-domain language and interchange layer that
preserves, rather than replaces or strengthens, native verifier results. - Add the experimental SCITT adapter, rerunnable real-COSE specimen with ephemeral keys, explicit semantic
boundary, and adversarial composition tests without claiming IETF review or payload
truth from registration. - Surface zero-identity/zero-knowledge (ZIZK) artifact-first TRUST as governing
architecture, publish the bounded RISC Zero reference mechanism and exact recorded
public proof artifacts, and keep only unfinished mechanisms experimental while
preserving unresolved horizons and native-system authority. - Bind the recorded RISC Zero proof to the image produced from the tracked guest and
locked toolchain in the governed offline verifier, rather than accepting source/proof
correspondence from a neighboring historical image identifier. - Formally distinguish TRUST as mechanism-earned forward artifact support, ROT as typed
time-indexed degradation of current admissibility, and RUST as an inverse-TRUST memetic
causal backtrace toward recorded ancestor states. None is actor-tied trust or a scalar;
reachability alone never infers guilt, responsibility, or causal localization. - Present current reports, schemas, module descriptions, and examples under the full
VSTD-1 and VSTD-2 numbered-profile identifiers; remove retired partial-profile object identifiers from
active readers and add a regression preventing their return. - Add normative artifact-control mechanism version 1 with exact-byte file/directory
freezing, SHA-256 plus SHA3-256 artifact-derived identities, observable read-only
guards, readable finite self-closing Ed25519 seals, external anchor checks, and
copy-on-write thaw descendants. Sealing is not encryption and supplies no actor trust,
semantic correctness, trusted time, or numbered VSTD profile result. - Document multi-temporal realms, discrete and continuous coexistence, causal and
problem-space partial orders, atemporal versus temporal capsules, explicit cross-realm
mappings, and future constrained language-model transition verification without
claiming continuous mediation, inference-law implementation, or textual truth.
Claim boundaries and validation
- Require
thawed_artifact_statusandvstd artifact statusto verify an actual supplied,
cleanly sealed parent and every recorded parent coordinate before returning
THAWED_CLEANorTHAWED_DIRTY. Sidecar-only agreement is nowNOT_ESTABLISHED; even a
verified current match does not authenticate the historical copy operation or external
parent continuity. - Preserve final filesystem-entry identity during artifact creation: freeze refuses
symbolic-link sources, and bundle, thaw-descendant, and sidecar outputs refuse every
preexisting lexical entry, including dangling symbolic links, without claiming universal
race-free filesystem security. - Require authoritative freeze-manifest, payload, seals-container, and seal-envelope
members to have ordinary lexical types; linked external or in-bundle targets cannot lend
bytes to bundle closure, while verified outer read aliases and ordinary hard-link
byte-and-path semantics remain explicitly distinct. - Remove the live SimulacraBench rehearsal and its front-door promotion; the repository
never contained or reproduced the submission, hosted image, hardware, or protected
evaluation identified by that name. - Correct generic-run wording: digest validation is an integrity check, external
references remain unattested until dereferenced and verified, same-path output
extraction is not independent verification, and unverified determinism isUNKNOWN. - Publish a Pages guide index and enforce language, title, viewport, main-region, skip-link,
image-alt, labelled-navigation, generated-reference, and local-link checks in CI. - Preserve explicit ordered-list starting numbers in generated Pages so procedures split
by code blocks retain their source step numbers instead of restarting at one. - Require CodeQL security-extended Python analysis in the protected repository-check
aggregate with only read access to content and write access to security results. - Fail closed on malformed generic-run receipts, publish their exact schema, and dispatch
VSTD-1by its required receipt profile. - Package every normative specification, verify byte identity, and smoke-test the built
wheel outside the source checkout so installed specification bindings cannot silently
become unavailable. - Bind the bundled checker to VSTD-1, record actor and execution separation explicitly,
and never infer independent actors from a historical field name, repeated runs, or
matching results. - Reject self-promoted independence even when every supplied status and digest agrees;
the generic-run compatibility path never derivesEVIDENCEDfrom serialized references.
The distinct VSTD-5 path reruns all seven separation propositions and does not upgrade
the legacy generic-run fields. - Require the real optional SCITT/COSE cryptographic example in the protected
repository-check aggregate
rather than allowing its dependency-gated tests to disappear from the base matrix. - Close generic-run control structures while retaining the released refutation-extension
map, make common receipt commands honor--json, and lockvalidateas an
integrity/profile check rather than a claim verifier.
Graph and conformance semantics
- Add a zero-dependency evidence execution core that resolves and rehashes exact evidence
bytes, pins a registered mechanism implementation digest, enforces byte/item bounds,
reruns the mechanism, and preservesPASS,FAIL, orUNKNOWNunder explicit trust roots. - Add an evidence-bound VSTD-4 path and replayable receipt form. Compatibility
vstd4_depthremains aNOT_ESTABLISHEDcandidate; only exact passing VSTD-1/2/3 and
fourteen-rung mechanisms plus an accepted kernel witness admit VSTD-5. - Implement the VSTD-5 reference mechanism and receipt: seven evidence-bound separation
dimensions, duplicate-witness/evidence refusal, exact admitted-certificate and
corroboration binding, typed binding/identity/separation/corroboration errors,
disagreement preservation, embedded evidence, and offline result recheck. Independence
fails closed on any identity or separation defect without parsing error-message text.
Witness identities and assertions serialize separately and in order, so duplicate,
orphan, missing, and reused-identity error inputs remain replayable instead of collapsing
during receipt construction. Keep permissive malformed-input assessment distinct from
portable receipt admission: the builder now raises unless the strict schema and complete
verdict-material evidence coverage hold, and the rechecker applies the same zero-dependency
gate before replay. The rechecker also compares the complete carried VSTD-4 entry, and
corroboration_classis mechanism-bound rather than relabelable metadata. This does not
claim a real external witness or independent implementation; a positive observation with
unresolved independence is overallUNKNOWN. - Add evidence-bound Graph profile computation and replay. The compatibility
graph_level
path remains caller-supplied; the new path reruns every member, ancestor, and reached-edge
rating mechanism bound to the exact Graph, members, collection, and claim before profile
1–5 can reportESTABLISHED. Profile zero remainsNOT_ESTABLISHED. - Add
VSTD-GRAPH-ASSURANCE-1andAssuranceLedgerfor hash-chained edge-local TRUST, ROT, RUST,
challenge-ledger projection, additive conflict declaration/resolution, structural RUST concentration,
explicit causal localization, and bounded artifact-relative BLAME/GUILT propositions.
Each TRUST event binds one exact transformation, its inputs/output, the historical Graph,
and prerequisite TRUST even...
VSTD v1.1.3
Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).
Correction recorded 2026-08-22: the initial notes reported UNSIGNED because the clean release runner did not import the maintainer's public key before calling local git verify-tag. GitHub's tag-object verification reports the existing signature as valid. This correction changes release metadata only; the tag and release assets are unchanged.
Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:
gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier- Canonicalize source ZIP timestamps in UTC and remove host ZIP metadata, so the
same Git coordinate produces byte-identical source archives on Windows and Linux. - Canonicalize generated wheel and source-distribution newlines, archive member
order, modes, timestamps, and ownership. Rebuild wheelRECORDafter normalization
and use compression-independent ZIP members plus a stable USTAR/gzip container. - Normalize common HTTPS and SSH spellings of the Git origin before recording the
public repository coordinate in a release manifest. - Require CI to build the complete release artifact set independently on Windows and
Linux and fail the conformance gate unless every resulting byte is identical. - Record that
v1.1.2remained a signed, tested, and attested GitHub-only release:
its protected PyPI deployment was cancelled after cross-platform build differences
were detected, before any Python distribution was uploaded.
VSTD v1.1.2
Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).
Correction recorded 2026-08-22: the initial notes reported UNSIGNED because the clean release runner did not import the maintainer's public key before calling local git verify-tag. GitHub's tag-object verification reports the existing signature as valid. This correction changes release metadata only; the tag and release assets are unchanged.
Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:
gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier-
Rename the import package
verifiabletoverifierand the distribution
verifiable-standardtoverifier-standard, so no published name reuses the ordinary-English
adjective or the maintainer's former project name. Thevstd,verifier, and
verifiablecommand names all continue to work;verifiableis a command name only
and no longer names an import package. -
Derive the release source-archive name from the manifest during verification, so
manifests published throughv1.1.1that bindverifiable-standard-<release>.zip
remain verifiable without republishing. -
Record the import-package, distribution, and archive renames in
WIRE_IDENTIFIERS.md. No receipt wire identifier, schema$id, or canonical digest
changes. -
Attribute the specifications, distribution metadata, and governance decision rights to
TimeLordRaps. The legal name remains the copyright holder inNOTICE. -
Add a normalized, byte-reproducible Python source distribution beside the reproducible
wheel; verify their name, version, import package, and frozen console-script set before
release. -
Publish only the tested wheel and source distribution through PyPI Trusted Publishing
after explicit approval in the protectedpypienvironment. The GitHub release keeps
the full source ZIP and external byte manifest as the public provenance coordinate. -
Document that the unrelated PyPI project named
verifiershares the same import name
and must not be co-installed; this is an ecosystem collision boundary, not a claim to
that distribution coordinate. -
Rename the VSTD-2 section 7 lifecycle term
VERIFIABLEtoGEOMETRY_INSPECTABLE
and record inWIRE_IDENTIFIERS.mdthat the section 7 vocabulary is prose-only, so
no status token reuses the maintainer's name and no wire value changes. -
Label the reference emulator's synthetic accelerator descriptor
vendoras
EMULATEDinstead of the maintainer's name, so fabricated hardware evidence cannot
read as maintainer attestation. -
Remove maintainer-scoped phrasing from normative specification prose: conformance is
defined by the documents, and the independent auditor role is named by the standard
rather than by the maintainer. -
Correct the SimulacraBench synthetic specimen additively: unobserved private
artifacts now remainIDENTIFIED, and the public challenge stops at
CHALLENGEDwithout a founder-authored adjudication. -
Require content-bound observed bytes before deriving
AVAILABLEorPORTABLE;
locator and retention declarations alone no longer elevate availability. -
Expand the public presentation gate to reject drive-qualified paths, private
locator schemes, deployment fields, local model artifact filenames, business
operations identifiers, common secret shapes, and email addresses.
VSTD v1.1.1
Source tag signature status: UNSIGNED.
Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. Verify an asset with:
gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier- Replace the overview's generic maturity badges with the exact status of every
object and graph layer, so the presentation cannot imply evidence or
implementation maturity that the specifications do not establish. - Enforce those visual labels in the presentation gate and publish canonical
receipt schemas at their declared GitHub Pages$idroutes. - Add contributor guardrails for the live schema routes, the Python 3.10 floor,
and the immediate-publication consequences of edits to Pages content.
VSTD v1.1.0
Source tag signature status: UNSIGNED.
Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. Verify an asset with:
gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier- Add
vstd demo, a deterministic four-scenario adversarial demonstration that
rejects a proof grounded to the wrong artifact, preserves a checkedUNKNOWN,
rejects verification-cost inflation, and exposes a revoked transitive ancestor. - Publish the replayable demo specimens, a newcomer quickstart, a public technical
roadmap, an ecosystem boundary map, and a focused project overview site. - Make
vstdthe canonical cross-platform command while retainingverifierand
verifiableas compatibility aliases. This avoids collision with Windows Driver
Verifier without breaking previously issued command references. - Replace the unused adopter-migration document name with an implementation
compatibility note; no external adoption or adopter migration is implied. - Add automated checks for documentation links, version agreement, public-boundary
language, packaged demo behavior, and checked-in specimen determinism. - Add repository-level instructions that keep automated contributors inside VSTD's
fail-closed claim, dependency, compatibility, and public/private boundaries.
VSTD v1.0.1
Source tag signature status: UNSIGNED.
Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. Verify an asset with:
gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier- State explicitly that each VSTD layer requires its own evidence: layer 4 does not
supply, entail, upgrade, or repair layers 3, 2, or 1. - Replace unsupported Tarski, generic NP-certificate, CNF-equals-3-SAT, and
physical-world co-NP claims with bounded statements tied to implemented formal
languages and declared observation surfaces. - Replace adopter-migration framing with a frozen wire-identifier and historical
project-filename registry; no external adoption is claimed. - Generate source releases from exact public Git objects and publish a separate
manifest binding the resolvable ref, commit, archive digest, file set, and member
bytes. Line-ending equivalence is not accepted as byte identity. - Add a side-effect-free manifest plan command and make unsandboxed execution visible
at the CLI and README boundary without pretending declared-path checks sandbox the
subprocess. - Test the advertised Python 3.10 through 3.13 range, add release-integrity and
installed-wheel jobs, and expose one required conformance gate for branch protection. - Add a tag-triggered release workflow that refuses non-main or unconformed commits,
rebuilds and smoke-tests exact artifacts, records tag signature status without
relabeling it, and creates GitHub/Sigstore attestations for every uploaded asset. - Add structured ambiguity, counterexample, and implementation feedback surfaces plus
public conduct and pull-request consequence checks.
VSTD v1.0.0 — Two-Axis Verification Ladder
VSTD two-axis ladder and refutability
VSTD v1.0.0 makes specification numbers verification-depth layers rather than release revisions. The object axis is VSTD-1 through VSTD-5; the collection axis is VSTD-Graph-1 through VSTD-Graph-5. Repository releases remain semantic versions.
Included
- VSTD-1 through VSTD-4 implemented reference surfaces; VSTD-5 is explicitly draft
- fourteen-rung computed VSTD-4 depth and a fail-closed VSTD-5 entry gate
VSTD4-GDC-1grounded PASS/FAIL/UNKNOWN decision certificates- isolated bounded reference kernel for
UP,WIDTH-K, andRES;SAT-PRESERVINGis declared but unimplemented - machine-readable refutation surfaces, availability, precommitment using the existing anchor interface, append-only challenges, monotonic degradation, and
RefutabilityClosure - computed VSTD-Graph level from membership, provenance closure, status admissibility, and transformation-edge evidence, with a certificate for the next unreachable level
- scalable
docs/layers/anddocs/profiles/layout plus migration aliases - layer-oriented schemas while retaining frozen historical receipt wire identifiers
- exact specification bytes packaged with the wheel so installed verifier descriptors compute real hashes outside a source checkout
Verification performed
- internal source suite: 300 passed
- clean installed-wheel public suite: 221 passed, 3 skipped
- Ruff and mypy passed
- launch-readiness audit: READY (7/7 gates pass)
- source archive built twice byte-identically
- wheel built twice byte-identically with
SOURCE_DATE_EPOCH=1787356800 - isolated wheel installation, installed descriptor hashes, and both
verifier/verifiableCLI aliases passed - final allowlisted public tree: 127 files including its release manifest
- boundary scan: zero matches for private project names, local/home-directory paths, or email addresses; zero broken relative Markdown links
- GitHub
conformancepassed on the pull request, mergedmain, and tagv1.0.0
Artifact digests
verifiable-standard-1.0.0.zip:fa4917e2b047501a9d8b64247e777497f13307f6a23ce3b3a88b70bbd3e74020verifiable_standard-1.0.0-py3-none-any.whl:89c7fe1b77fb5efccbf4caa05924a8501dd4b57392b35b75bfa55ddbac0d1340
Compatibility and claim boundary
Existing v0.1.0 and v0.2.0 tags/releases are untouched. Their historical VSTD-0.1, VSTD-0.2, VSTD-3.0, and VSTD-DATA-0.1 receipt wire identifiers remain frozen and readable; only specification paths and conceptual layer names change.
A VSTD-4 result establishes only the grounded, bounded decision described by its exact claim coordinate, roots, verifier descriptor, exclusions, and certificate. This release does not establish evidence authenticity beyond the declared trust roots, physical-world completeness, an external implementation, interoperability, a security audit, independent witnessing, accredited certification, or VSTD-5 conformance. UNKNOWN, UNSUPPORTED, FAIL, and PASS remain distinct.
Licensed under Apache-2.0. Edited and published by Tyler Roost / TimeLordRaps.
VSTD v0.2.0 — Universal Accelerator Accountability
Historical-coordinate notice (added 2026-08-27): This page records the tagged
repository releasev0.2.0; that semantic-version coordinate is not the current VSTD-2
layer. The accelerator surface described below is now named VSTD-3, while issued
receipts retain the frozenVSTD-3.0wire identifier. The tag and attached assets
remain unchanged. References below to the historicalconformanceworkflow name
identify a repository job, not an earned VSTD conformance result. See
the current identifier map.
VSTD 3: Universal Accelerator Accountability
VSTD v0.2.0 adds a normative, evidence-bounded standard and reference implementation for accelerator identity, firmware evidence, execution evidence, accounting continuity, complete-mediation claims within declared boundaries, fleet completeness, and provenance propagation.
Included
- VSTD 3.0 normative specification and strict JSON Schemas
- deterministic virtual accelerator and adversarial conformance suite
- 37-profile data-driven accelerator registry
- NVIDIA and AMD host-observed adapters with opaque attestation preservation
- strict provider-evidence boundaries for Google TPU, AWS Neuron, and Microsoft Maia
- continuity, reset anchoring, partition/topology, fleet, and provenance validation
vstd hardware,continuity,fleet,evidence, andclaimsCLI families- threat model, migration guide, vendor integration guide, references, and translated claim limits
Verification performed
- public checkout: 105 passed, 2 skipped
- internal full suite: 152 passed, 3 skipped
- Ruff and mypy passed
- source archive built twice byte-identically
- wheel built twice byte-identically using
SOURCE_DATE_EPOCH=1787270400 - clean wheel install and virtual accelerator receipt verification passed
- GitHub conformance and stdlib-smoke checks passed
Artifact digests
verifiable-standard-0.2.0.zip:b23b4e939109fc9c73d8044d59c4fd8a7cffd7c5d005494446f5d6ef078c169fverifiable_standard-0.2.0-py3-none-any.whl:8a06d78652f6cbf837b0deab57dc5fe085482523af090356202a128bc8c2c79e
Claim boundary in plain language
A VSTD receipt can support only the claims justified by its evidence, independent verification, declared conformance profile, and observation boundary. This release does not establish vendor endorsement, accredited certification, physical-world completeness, or universal observation of accelerator activity. HMAC evidence is test-only. Opaque vendor evidence remains unverified unless an independent verifier is configured. UNKNOWN, UNSUPPORTED, and FAIL remain distinct from PASS.
Licensed under Apache-2.0. Edited and published by Tyler Roost / TimeLordRaps.
VSTD v0.1.0
Historical-coordinate notice (added 2026-08-27): This page records the tagged
v0.1.0release and does not describe the current architecture. Current specification
names are VSTD-1, VSTD-2, VSTD-3, and VSTD-Graph-1.VSTD-0.1,
VSTD-0.2,VSTD-3.0, andVSTD-DATA-0.1remain frozen receipt wire
identifiers because issued artifacts must stay readable; they are not current standard
names. The tag and attached assets remain unchanged. References below to the historical
conformanceworkflow name identify a repository job, not an earned VSTD conformance
result. See the current identifier map.
VSTD v0.1.0
First public alpha release of VSTD, an independent project specification and reference implementation for bounded, machine-checkable evidence attached to computational claims and provenance graphs.
Included
- VSTD-0.1 receipt specification
- VSTD-DATA-0.1 provenance-hypergraph specification
- experimental VSTD-0.2 verification geometry
- JSON schemas, target-neutral Python reference subset, examples, and conformance tests
- plain-language
CLAIMS_AND_LIMITS.md - non-normative predictive-AI and competition-evaluation profile
- confidential reporting through GitHub private vulnerability reports
Verification
- merged-main GitHub Actions conformance and stdlib-smoke jobs passed
- extracted public tree: 61 tests passed; 2 optional-dependency tests skipped
- deterministic source archive SHA-256:
e15f7d58d3e44e70439f5d7f5facb5cde9e3c0f98be293f109bd9372ca6cf179 - deterministic wheel build and isolated no-dependency lifecycle reached
BITWISE_IDENTICAL
Claim boundary
A passing VSTD result is relative to its identified subject, verification surface, mechanism, bound evidence, trust roots, and horizons. It does not by itself prove complete real-world provenance, legal rights, empirical truth, general AI safety, organizer adoption, or competition standing.
Licensed under Apache License 2.0. VSTD is not affiliated with or endorsed by the Apache Software Foundation.