Skip to content

Releases: TimeLordRaps/verifier

VSTD v1.2.0

Choose a tag to compare

@github-actions github-actions released this 01 Sep 15:42
Immutable release. Only release title and notes can be modified.
v1.2.0
dcc9e95

Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).

Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:

gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier

Public surface and integrations

  • Restructure the public first-view path around one bounded project description, one
    deterministic demonstration, one canonical maturity table, skeptical claim limits,
    contributor routes, and release/citation boundaries; align Pages and package metadata
    without changing normative or serialized-receipt semantics.
  • Normalize the public architecture as a verification complex of named closure
    coordinates and cumulative numbered profiles; reserve VSTD-4 rung, candidate depth,
    verification order, compatibility level, and checker-cost tier for their distinct uses.
  • Add experimental workflow profile 0.1 with deterministic canonicalization, strict
    validation, bounded work-allocation records, additive amendments and challenges,
    explicit unresolved horizons, and verdict-neutral platform events.
  • Add a normalized GitHub adapter for issues, commits, workflow runs, artifacts, and
    pull requests. Successful workflows and merges retain verification_effect = NONE
    unless a separate native result is explicitly mapped through a bound VSTD receipt.
  • Add vstd experiment validate and vstd experiment github-events as offline,
    verdict-neutral entry points. Repository artifacts are explicitly NOT_CHECKED with
    exit code 2 unless their root is supplied.
  • Add a machine-readable schema, checked-in verdict-neutral specimen, generated
    experiment index, adversarial tests, and a runnable offline example.
  • Add a generated CLI/API reference page and presentation gates that reject stale
    reference or experiment-index content.
  • Clarify VSTD's role as a verification-domain language and interchange layer that
    preserves, rather than replaces or strengthens, native verifier results.
  • Add the experimental SCITT adapter, rerunnable real-COSE specimen with ephemeral keys, explicit semantic
    boundary, and adversarial composition tests without claiming IETF review or payload
    truth from registration.
  • Surface zero-identity/zero-knowledge (ZIZK) artifact-first TRUST as governing
    architecture, publish the bounded RISC Zero reference mechanism and exact recorded
    public proof artifacts, and keep only unfinished mechanisms experimental while
    preserving unresolved horizons and native-system authority.
  • Bind the recorded RISC Zero proof to the image produced from the tracked guest and
    locked toolchain in the governed offline verifier, rather than accepting source/proof
    correspondence from a neighboring historical image identifier.
  • Formally distinguish TRUST as mechanism-earned forward artifact support, ROT as typed
    time-indexed degradation of current admissibility, and RUST as an inverse-TRUST memetic
    causal backtrace toward recorded ancestor states. None is actor-tied trust or a scalar;
    reachability alone never infers guilt, responsibility, or causal localization.
  • Present current reports, schemas, module descriptions, and examples under the full
    VSTD-1 and VSTD-2 numbered-profile identifiers; remove retired partial-profile object identifiers from
    active readers and add a regression preventing their return.
  • Add normative artifact-control mechanism version 1 with exact-byte file/directory
    freezing, SHA-256 plus SHA3-256 artifact-derived identities, observable read-only
    guards, readable finite self-closing Ed25519 seals, external anchor checks, and
    copy-on-write thaw descendants. Sealing is not encryption and supplies no actor trust,
    semantic correctness, trusted time, or numbered VSTD profile result.
  • Document multi-temporal realms, discrete and continuous coexistence, causal and
    problem-space partial orders, atemporal versus temporal capsules, explicit cross-realm
    mappings, and future constrained language-model transition verification without
    claiming continuous mediation, inference-law implementation, or textual truth.

Claim boundaries and validation

  • Require thawed_artifact_status and vstd artifact status to verify an actual supplied,
    cleanly sealed parent and every recorded parent coordinate before returning
    THAWED_CLEAN or THAWED_DIRTY. Sidecar-only agreement is now NOT_ESTABLISHED; even a
    verified current match does not authenticate the historical copy operation or external
    parent continuity.
  • Preserve final filesystem-entry identity during artifact creation: freeze refuses
    symbolic-link sources, and bundle, thaw-descendant, and sidecar outputs refuse every
    preexisting lexical entry, including dangling symbolic links, without claiming universal
    race-free filesystem security.
  • Require authoritative freeze-manifest, payload, seals-container, and seal-envelope
    members to have ordinary lexical types; linked external or in-bundle targets cannot lend
    bytes to bundle closure, while verified outer read aliases and ordinary hard-link
    byte-and-path semantics remain explicitly distinct.
  • Remove the live SimulacraBench rehearsal and its front-door promotion; the repository
    never contained or reproduced the submission, hosted image, hardware, or protected
    evaluation identified by that name.
  • Correct generic-run wording: digest validation is an integrity check, external
    references remain unattested until dereferenced and verified, same-path output
    extraction is not independent verification, and unverified determinism is UNKNOWN.
  • Publish a Pages guide index and enforce language, title, viewport, main-region, skip-link,
    image-alt, labelled-navigation, generated-reference, and local-link checks in CI.
  • Preserve explicit ordered-list starting numbers in generated Pages so procedures split
    by code blocks retain their source step numbers instead of restarting at one.
  • Require CodeQL security-extended Python analysis in the protected repository-check
    aggregate with only read access to content and write access to security results.
  • Fail closed on malformed generic-run receipts, publish their exact schema, and dispatch
    VSTD-1 by its required receipt profile.
  • Package every normative specification, verify byte identity, and smoke-test the built
    wheel outside the source checkout so installed specification bindings cannot silently
    become unavailable.
  • Bind the bundled checker to VSTD-1, record actor and execution separation explicitly,
    and never infer independent actors from a historical field name, repeated runs, or
    matching results.
  • Reject self-promoted independence even when every supplied status and digest agrees;
    the generic-run compatibility path never derives EVIDENCED from serialized references.
    The distinct VSTD-5 path reruns all seven separation propositions and does not upgrade
    the legacy generic-run fields.
  • Require the real optional SCITT/COSE cryptographic example in the protected
    repository-check aggregate
    rather than allowing its dependency-gated tests to disappear from the base matrix.
  • Close generic-run control structures while retaining the released refutation-extension
    map, make common receipt commands honor --json, and lock validate as an
    integrity/profile check rather than a claim verifier.

Graph and conformance semantics

  • Add a zero-dependency evidence execution core that resolves and rehashes exact evidence
    bytes, pins a registered mechanism implementation digest, enforces byte/item bounds,
    reruns the mechanism, and preserves PASS, FAIL, or UNKNOWN under explicit trust roots.
  • Add an evidence-bound VSTD-4 path and replayable receipt form. Compatibility
    vstd4_depth remains a NOT_ESTABLISHED candidate; only exact passing VSTD-1/2/3 and
    fourteen-rung mechanisms plus an accepted kernel witness admit VSTD-5.
  • Implement the VSTD-5 reference mechanism and receipt: seven evidence-bound separation
    dimensions, duplicate-witness/evidence refusal, exact admitted-certificate and
    corroboration binding, typed binding/identity/separation/corroboration errors,
    disagreement preservation, embedded evidence, and offline result recheck. Independence
    fails closed on any identity or separation defect without parsing error-message text.
    Witness identities and assertions serialize separately and in order, so duplicate,
    orphan, missing, and reused-identity error inputs remain replayable instead of collapsing
    during receipt construction. Keep permissive malformed-input assessment distinct from
    portable receipt admission: the builder now raises unless the strict schema and complete
    verdict-material evidence coverage hold, and the rechecker applies the same zero-dependency
    gate before replay. The rechecker also compares the complete carried VSTD-4 entry, and
    corroboration_class is mechanism-bound rather than relabelable metadata. This does not
    claim a real external witness or independent implementation; a positive observation with
    unresolved independence is overall UNKNOWN.
  • Add evidence-bound Graph profile computation and replay. The compatibility graph_level
    path remains caller-supplied; the new path reruns every member, ancestor, and reached-edge
    rating mechanism bound to the exact Graph, members, collection, and claim before profile
    1–5 can report ESTABLISHED. Profile zero remains NOT_ESTABLISHED.
  • Add VSTD-GRAPH-ASSURANCE-1 and AssuranceLedger for hash-chained edge-local TRUST, ROT, RUST,
    challenge-ledger projection, additive conflict declaration/resolution, structural RUST concentration,
    explicit causal localization, and bounded artifact-relative BLAME/GUILT propositions.
    Each TRUST event binds one exact transformation, its inputs/output, the historical Graph,
    and prerequisite TRUST even...
Read more

VSTD v1.1.3

Choose a tag to compare

@github-actions github-actions released this 23 Aug 02:55
v1.1.3
13c3cc1

Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).

Correction recorded 2026-08-22: the initial notes reported UNSIGNED because the clean release runner did not import the maintainer's public key before calling local git verify-tag. GitHub's tag-object verification reports the existing signature as valid. This correction changes release metadata only; the tag and release assets are unchanged.

Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:

gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier
  • Canonicalize source ZIP timestamps in UTC and remove host ZIP metadata, so the
    same Git coordinate produces byte-identical source archives on Windows and Linux.
  • Canonicalize generated wheel and source-distribution newlines, archive member
    order, modes, timestamps, and ownership. Rebuild wheel RECORD after normalization
    and use compression-independent ZIP members plus a stable USTAR/gzip container.
  • Normalize common HTTPS and SSH spellings of the Git origin before recording the
    public repository coordinate in a release manifest.
  • Require CI to build the complete release artifact set independently on Windows and
    Linux and fail the conformance gate unless every resulting byte is identical.
  • Record that v1.1.2 remained a signed, tested, and attested GitHub-only release:
    its protected PyPI deployment was cancelled after cross-platform build differences
    were detected, before any Python distribution was uploaded.

VSTD v1.1.2

Choose a tag to compare

@github-actions github-actions released this 23 Aug 02:03
v1.1.2
8c8b21c

Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).

Correction recorded 2026-08-22: the initial notes reported UNSIGNED because the clean release runner did not import the maintainer's public key before calling local git verify-tag. GitHub's tag-object verification reports the existing signature as valid. This correction changes release metadata only; the tag and release assets are unchanged.

Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:

gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier
  • Rename the import package verifiable to verifier and the distribution
    verifiable-standard to verifier-standard, so no published name reuses the ordinary-English
    adjective or the maintainer's former project name. The vstd, verifier, and
    verifiable command names all continue to work; verifiable is a command name only
    and no longer names an import package.

  • Derive the release source-archive name from the manifest during verification, so
    manifests published through v1.1.1 that bind verifiable-standard-<release>.zip
    remain verifiable without republishing.

  • Record the import-package, distribution, and archive renames in
    WIRE_IDENTIFIERS.md. No receipt wire identifier, schema $id, or canonical digest
    changes.

  • Attribute the specifications, distribution metadata, and governance decision rights to
    TimeLordRaps. The legal name remains the copyright holder in NOTICE.

  • Add a normalized, byte-reproducible Python source distribution beside the reproducible
    wheel; verify their name, version, import package, and frozen console-script set before
    release.

  • Publish only the tested wheel and source distribution through PyPI Trusted Publishing
    after explicit approval in the protected pypi environment. The GitHub release keeps
    the full source ZIP and external byte manifest as the public provenance coordinate.

  • Document that the unrelated PyPI project named verifier shares the same import name
    and must not be co-installed; this is an ecosystem collision boundary, not a claim to
    that distribution coordinate.

  • Rename the VSTD-2 section 7 lifecycle term VERIFIABLE to GEOMETRY_INSPECTABLE
    and record in WIRE_IDENTIFIERS.md that the section 7 vocabulary is prose-only, so
    no status token reuses the maintainer's name and no wire value changes.

  • Label the reference emulator's synthetic accelerator descriptor vendor as
    EMULATED instead of the maintainer's name, so fabricated hardware evidence cannot
    read as maintainer attestation.

  • Remove maintainer-scoped phrasing from normative specification prose: conformance is
    defined by the documents, and the independent auditor role is named by the standard
    rather than by the maintainer.

  • Correct the SimulacraBench synthetic specimen additively: unobserved private
    artifacts now remain IDENTIFIED, and the public challenge stops at
    CHALLENGED without a founder-authored adjudication.

  • Require content-bound observed bytes before deriving AVAILABLE or PORTABLE;
    locator and retention declarations alone no longer elevate availability.

  • Expand the public presentation gate to reject drive-qualified paths, private
    locator schemes, deployment fields, local model artifact filenames, business
    operations identifiers, common secret shapes, and email addresses.

VSTD v1.1.1

Choose a tag to compare

@github-actions github-actions released this 22 Aug 17:50
9983313

Source tag signature status: UNSIGNED.

Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. Verify an asset with:

gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier
  • Replace the overview's generic maturity badges with the exact status of every
    object and graph layer, so the presentation cannot imply evidence or
    implementation maturity that the specifications do not establish.
  • Enforce those visual labels in the presentation gate and publish canonical
    receipt schemas at their declared GitHub Pages $id routes.
  • Add contributor guardrails for the live schema routes, the Python 3.10 floor,
    and the immediate-publication consequences of edits to Pages content.

VSTD v1.1.0

Choose a tag to compare

@github-actions github-actions released this 22 Aug 17:27
67990c6

Source tag signature status: UNSIGNED.

Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. Verify an asset with:

gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier
  • Add vstd demo, a deterministic four-scenario adversarial demonstration that
    rejects a proof grounded to the wrong artifact, preserves a checked UNKNOWN,
    rejects verification-cost inflation, and exposes a revoked transitive ancestor.
  • Publish the replayable demo specimens, a newcomer quickstart, a public technical
    roadmap, an ecosystem boundary map, and a focused project overview site.
  • Make vstd the canonical cross-platform command while retaining verifier and
    verifiable as compatibility aliases. This avoids collision with Windows Driver
    Verifier without breaking previously issued command references.
  • Replace the unused adopter-migration document name with an implementation
    compatibility note; no external adoption or adopter migration is implied.
  • Add automated checks for documentation links, version agreement, public-boundary
    language, packaged demo behavior, and checked-in specimen determinism.
  • Add repository-level instructions that keep automated contributors inside VSTD's
    fail-closed claim, dependency, compatibility, and public/private boundaries.

VSTD v1.0.1

Choose a tag to compare

@github-actions github-actions released this 22 Aug 16:41
6b8ca66

Source tag signature status: UNSIGNED.

Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. Verify an asset with:

gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier
  • State explicitly that each VSTD layer requires its own evidence: layer 4 does not
    supply, entail, upgrade, or repair layers 3, 2, or 1.
  • Replace unsupported Tarski, generic NP-certificate, CNF-equals-3-SAT, and
    physical-world co-NP claims with bounded statements tied to implemented formal
    languages and declared observation surfaces.
  • Replace adopter-migration framing with a frozen wire-identifier and historical
    project-filename registry; no external adoption is claimed.
  • Generate source releases from exact public Git objects and publish a separate
    manifest binding the resolvable ref, commit, archive digest, file set, and member
    bytes. Line-ending equivalence is not accepted as byte identity.
  • Add a side-effect-free manifest plan command and make unsandboxed execution visible
    at the CLI and README boundary without pretending declared-path checks sandbox the
    subprocess.
  • Test the advertised Python 3.10 through 3.13 range, add release-integrity and
    installed-wheel jobs, and expose one required conformance gate for branch protection.
  • Add a tag-triggered release workflow that refuses non-main or unconformed commits,
    rebuilds and smoke-tests exact artifacts, records tag signature status without
    relabeling it, and creates GitHub/Sigstore attestations for every uploaded asset.
  • Add structured ambiguity, counterexample, and implementation feedback surfaces plus
    public conduct and pull-request consequence checks.

VSTD v1.0.0 — Two-Axis Verification Ladder

Choose a tag to compare

@TimeLordRaps TimeLordRaps released this 22 Aug 14:44
d49e439

VSTD two-axis ladder and refutability

VSTD v1.0.0 makes specification numbers verification-depth layers rather than release revisions. The object axis is VSTD-1 through VSTD-5; the collection axis is VSTD-Graph-1 through VSTD-Graph-5. Repository releases remain semantic versions.

Included

  • VSTD-1 through VSTD-4 implemented reference surfaces; VSTD-5 is explicitly draft
  • fourteen-rung computed VSTD-4 depth and a fail-closed VSTD-5 entry gate
  • VSTD4-GDC-1 grounded PASS/FAIL/UNKNOWN decision certificates
  • isolated bounded reference kernel for UP, WIDTH-K, and RES; SAT-PRESERVING is declared but unimplemented
  • machine-readable refutation surfaces, availability, precommitment using the existing anchor interface, append-only challenges, monotonic degradation, and RefutabilityClosure
  • computed VSTD-Graph level from membership, provenance closure, status admissibility, and transformation-edge evidence, with a certificate for the next unreachable level
  • scalable docs/layers/ and docs/profiles/ layout plus migration aliases
  • layer-oriented schemas while retaining frozen historical receipt wire identifiers
  • exact specification bytes packaged with the wheel so installed verifier descriptors compute real hashes outside a source checkout

Verification performed

  • internal source suite: 300 passed
  • clean installed-wheel public suite: 221 passed, 3 skipped
  • Ruff and mypy passed
  • launch-readiness audit: READY (7/7 gates pass)
  • source archive built twice byte-identically
  • wheel built twice byte-identically with SOURCE_DATE_EPOCH=1787356800
  • isolated wheel installation, installed descriptor hashes, and both verifier / verifiable CLI aliases passed
  • final allowlisted public tree: 127 files including its release manifest
  • boundary scan: zero matches for private project names, local/home-directory paths, or email addresses; zero broken relative Markdown links
  • GitHub conformance passed on the pull request, merged main, and tag v1.0.0

Artifact digests

  • verifiable-standard-1.0.0.zip: fa4917e2b047501a9d8b64247e777497f13307f6a23ce3b3a88b70bbd3e74020
  • verifiable_standard-1.0.0-py3-none-any.whl: 89c7fe1b77fb5efccbf4caa05924a8501dd4b57392b35b75bfa55ddbac0d1340

Compatibility and claim boundary

Existing v0.1.0 and v0.2.0 tags/releases are untouched. Their historical VSTD-0.1, VSTD-0.2, VSTD-3.0, and VSTD-DATA-0.1 receipt wire identifiers remain frozen and readable; only specification paths and conceptual layer names change.

A VSTD-4 result establishes only the grounded, bounded decision described by its exact claim coordinate, roots, verifier descriptor, exclusions, and certificate. This release does not establish evidence authenticity beyond the declared trust roots, physical-world completeness, an external implementation, interoperability, a security audit, independent witnessing, accredited certification, or VSTD-5 conformance. UNKNOWN, UNSUPPORTED, FAIL, and PASS remain distinct.

Licensed under Apache-2.0. Edited and published by Tyler Roost / TimeLordRaps.

VSTD v0.2.0 — Universal Accelerator Accountability

Choose a tag to compare

@TimeLordRaps TimeLordRaps released this 22 Aug 00:38
b0e9b20

Historical-coordinate notice (added 2026-08-27): This page records the tagged
repository release v0.2.0; that semantic-version coordinate is not the current VSTD-2
layer. The accelerator surface described below is now named VSTD-3, while issued
receipts retain the frozen VSTD-3.0 wire identifier. The tag and attached assets
remain unchanged. References below to the historical conformance workflow name
identify a repository job, not an earned VSTD conformance result. See
the current identifier map.

VSTD 3: Universal Accelerator Accountability

VSTD v0.2.0 adds a normative, evidence-bounded standard and reference implementation for accelerator identity, firmware evidence, execution evidence, accounting continuity, complete-mediation claims within declared boundaries, fleet completeness, and provenance propagation.

Included

  • VSTD 3.0 normative specification and strict JSON Schemas
  • deterministic virtual accelerator and adversarial conformance suite
  • 37-profile data-driven accelerator registry
  • NVIDIA and AMD host-observed adapters with opaque attestation preservation
  • strict provider-evidence boundaries for Google TPU, AWS Neuron, and Microsoft Maia
  • continuity, reset anchoring, partition/topology, fleet, and provenance validation
  • vstd hardware, continuity, fleet, evidence, and claims CLI families
  • threat model, migration guide, vendor integration guide, references, and translated claim limits

Verification performed

  • public checkout: 105 passed, 2 skipped
  • internal full suite: 152 passed, 3 skipped
  • Ruff and mypy passed
  • source archive built twice byte-identically
  • wheel built twice byte-identically using SOURCE_DATE_EPOCH=1787270400
  • clean wheel install and virtual accelerator receipt verification passed
  • GitHub conformance and stdlib-smoke checks passed

Artifact digests

  • verifiable-standard-0.2.0.zip: b23b4e939109fc9c73d8044d59c4fd8a7cffd7c5d005494446f5d6ef078c169f
  • verifiable_standard-0.2.0-py3-none-any.whl: 8a06d78652f6cbf837b0deab57dc5fe085482523af090356202a128bc8c2c79e

Claim boundary in plain language

A VSTD receipt can support only the claims justified by its evidence, independent verification, declared conformance profile, and observation boundary. This release does not establish vendor endorsement, accredited certification, physical-world completeness, or universal observation of accelerator activity. HMAC evidence is test-only. Opaque vendor evidence remains unverified unless an independent verifier is configured. UNKNOWN, UNSUPPORTED, and FAIL remain distinct from PASS.

Licensed under Apache-2.0. Edited and published by Tyler Roost / TimeLordRaps.

VSTD v0.1.0

Choose a tag to compare

@TimeLordRaps TimeLordRaps released this 21 Aug 23:20
e3e824d

Historical-coordinate notice (added 2026-08-27): This page records the tagged
v0.1.0 release and does not describe the current architecture. Current specification
names are VSTD-1, VSTD-2, VSTD-3, and VSTD-Graph-1. VSTD-0.1,
VSTD-0.2, VSTD-3.0, and VSTD-DATA-0.1 remain frozen receipt wire
identifiers because issued artifacts must stay readable; they are not current standard
names. The tag and attached assets remain unchanged. References below to the historical
conformance workflow name identify a repository job, not an earned VSTD conformance
result. See the current identifier map.

VSTD v0.1.0

First public alpha release of VSTD, an independent project specification and reference implementation for bounded, machine-checkable evidence attached to computational claims and provenance graphs.

Included

  • VSTD-0.1 receipt specification
  • VSTD-DATA-0.1 provenance-hypergraph specification
  • experimental VSTD-0.2 verification geometry
  • JSON schemas, target-neutral Python reference subset, examples, and conformance tests
  • plain-language CLAIMS_AND_LIMITS.md
  • non-normative predictive-AI and competition-evaluation profile
  • confidential reporting through GitHub private vulnerability reports

Verification

  • merged-main GitHub Actions conformance and stdlib-smoke jobs passed
  • extracted public tree: 61 tests passed; 2 optional-dependency tests skipped
  • deterministic source archive SHA-256: e15f7d58d3e44e70439f5d7f5facb5cde9e3c0f98be293f109bd9372ca6cf179
  • deterministic wheel build and isolated no-dependency lifecycle reached BITWISE_IDENTICAL

Claim boundary

A passing VSTD result is relative to its identified subject, verification surface, mechanism, bound evidence, trust roots, and horizons. It does not by itself prove complete real-world provenance, legal rights, empirical truth, general AI safety, organizer adoption, or competition standing.

Licensed under Apache License 2.0. VSTD is not affiliated with or endorsed by the Apache Software Foundation.