Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).
Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:
gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifierPublic surface and integrations
- Restructure the public first-view path around one bounded project description, one
deterministic demonstration, one canonical maturity table, skeptical claim limits,
contributor routes, and release/citation boundaries; align Pages and package metadata
without changing normative or serialized-receipt semantics. - Normalize the public architecture as a verification complex of named closure
coordinates and cumulative numbered profiles; reserve VSTD-4 rung, candidate depth,
verification order, compatibility level, and checker-cost tier for their distinct uses. - Add experimental workflow profile 0.1 with deterministic canonicalization, strict
validation, bounded work-allocation records, additive amendments and challenges,
explicit unresolved horizons, and verdict-neutral platform events. - Add a normalized GitHub adapter for issues, commits, workflow runs, artifacts, and
pull requests. Successful workflows and merges retainverification_effect = NONE
unless a separate native result is explicitly mapped through a bound VSTD receipt. - Add
vstd experiment validateandvstd experiment github-eventsas offline,
verdict-neutral entry points. Repository artifacts are explicitlyNOT_CHECKEDwith
exit code 2 unless their root is supplied. - Add a machine-readable schema, checked-in verdict-neutral specimen, generated
experiment index, adversarial tests, and a runnable offline example. - Add a generated CLI/API reference page and presentation gates that reject stale
reference or experiment-index content. - Clarify VSTD's role as a verification-domain language and interchange layer that
preserves, rather than replaces or strengthens, native verifier results. - Add the experimental SCITT adapter, rerunnable real-COSE specimen with ephemeral keys, explicit semantic
boundary, and adversarial composition tests without claiming IETF review or payload
truth from registration. - Surface zero-identity/zero-knowledge (ZIZK) artifact-first TRUST as governing
architecture, publish the bounded RISC Zero reference mechanism and exact recorded
public proof artifacts, and keep only unfinished mechanisms experimental while
preserving unresolved horizons and native-system authority. - Bind the recorded RISC Zero proof to the image produced from the tracked guest and
locked toolchain in the governed offline verifier, rather than accepting source/proof
correspondence from a neighboring historical image identifier. - Formally distinguish TRUST as mechanism-earned forward artifact support, ROT as typed
time-indexed degradation of current admissibility, and RUST as an inverse-TRUST memetic
causal backtrace toward recorded ancestor states. None is actor-tied trust or a scalar;
reachability alone never infers guilt, responsibility, or causal localization. - Present current reports, schemas, module descriptions, and examples under the full
VSTD-1 and VSTD-2 numbered-profile identifiers; remove retired partial-profile object identifiers from
active readers and add a regression preventing their return. - Add normative artifact-control mechanism version 1 with exact-byte file/directory
freezing, SHA-256 plus SHA3-256 artifact-derived identities, observable read-only
guards, readable finite self-closing Ed25519 seals, external anchor checks, and
copy-on-write thaw descendants. Sealing is not encryption and supplies no actor trust,
semantic correctness, trusted time, or numbered VSTD profile result. - Document multi-temporal realms, discrete and continuous coexistence, causal and
problem-space partial orders, atemporal versus temporal capsules, explicit cross-realm
mappings, and future constrained language-model transition verification without
claiming continuous mediation, inference-law implementation, or textual truth.
Claim boundaries and validation
- Require
thawed_artifact_statusandvstd artifact statusto verify an actual supplied,
cleanly sealed parent and every recorded parent coordinate before returning
THAWED_CLEANorTHAWED_DIRTY. Sidecar-only agreement is nowNOT_ESTABLISHED; even a
verified current match does not authenticate the historical copy operation or external
parent continuity. - Preserve final filesystem-entry identity during artifact creation: freeze refuses
symbolic-link sources, and bundle, thaw-descendant, and sidecar outputs refuse every
preexisting lexical entry, including dangling symbolic links, without claiming universal
race-free filesystem security. - Require authoritative freeze-manifest, payload, seals-container, and seal-envelope
members to have ordinary lexical types; linked external or in-bundle targets cannot lend
bytes to bundle closure, while verified outer read aliases and ordinary hard-link
byte-and-path semantics remain explicitly distinct. - Remove the live SimulacraBench rehearsal and its front-door promotion; the repository
never contained or reproduced the submission, hosted image, hardware, or protected
evaluation identified by that name. - Correct generic-run wording: digest validation is an integrity check, external
references remain unattested until dereferenced and verified, same-path output
extraction is not independent verification, and unverified determinism isUNKNOWN. - Publish a Pages guide index and enforce language, title, viewport, main-region, skip-link,
image-alt, labelled-navigation, generated-reference, and local-link checks in CI. - Preserve explicit ordered-list starting numbers in generated Pages so procedures split
by code blocks retain their source step numbers instead of restarting at one. - Require CodeQL security-extended Python analysis in the protected repository-check
aggregate with only read access to content and write access to security results. - Fail closed on malformed generic-run receipts, publish their exact schema, and dispatch
VSTD-1by its required receipt profile. - Package every normative specification, verify byte identity, and smoke-test the built
wheel outside the source checkout so installed specification bindings cannot silently
become unavailable. - Bind the bundled checker to VSTD-1, record actor and execution separation explicitly,
and never infer independent actors from a historical field name, repeated runs, or
matching results. - Reject self-promoted independence even when every supplied status and digest agrees;
the generic-run compatibility path never derivesEVIDENCEDfrom serialized references.
The distinct VSTD-5 path reruns all seven separation propositions and does not upgrade
the legacy generic-run fields. - Require the real optional SCITT/COSE cryptographic example in the protected
repository-check aggregate
rather than allowing its dependency-gated tests to disappear from the base matrix. - Close generic-run control structures while retaining the released refutation-extension
map, make common receipt commands honor--json, and lockvalidateas an
integrity/profile check rather than a claim verifier.
Graph and conformance semantics
-
Add a zero-dependency evidence execution core that resolves and rehashes exact evidence
bytes, pins a registered mechanism implementation digest, enforces byte/item bounds,
reruns the mechanism, and preservesPASS,FAIL, orUNKNOWNunder explicit trust roots. -
Add an evidence-bound VSTD-4 path and replayable receipt form. Compatibility
vstd4_depthremains aNOT_ESTABLISHEDcandidate; only exact passing VSTD-1/2/3 and
fourteen-rung mechanisms plus an accepted kernel witness admit VSTD-5. -
Implement the VSTD-5 reference mechanism and receipt: seven evidence-bound separation
dimensions, duplicate-witness/evidence refusal, exact admitted-certificate and
corroboration binding, typed binding/identity/separation/corroboration errors,
disagreement preservation, embedded evidence, and offline result recheck. Independence
fails closed on any identity or separation defect without parsing error-message text.
Witness identities and assertions serialize separately and in order, so duplicate,
orphan, missing, and reused-identity error inputs remain replayable instead of collapsing
during receipt construction. Keep permissive malformed-input assessment distinct from
portable receipt admission: the builder now raises unless the strict schema and complete
verdict-material evidence coverage hold, and the rechecker applies the same zero-dependency
gate before replay. The rechecker also compares the complete carried VSTD-4 entry, and
corroboration_classis mechanism-bound rather than relabelable metadata. This does not
claim a real external witness or independent implementation; a positive observation with
unresolved independence is overallUNKNOWN. -
Add evidence-bound Graph profile computation and replay. The compatibility
graph_level
path remains caller-supplied; the new path reruns every member, ancestor, and reached-edge
rating mechanism bound to the exact Graph, members, collection, and claim before profile
1–5 can reportESTABLISHED. Profile zero remainsNOT_ESTABLISHED. -
Add
VSTD-GRAPH-ASSURANCE-1andAssuranceLedgerfor hash-chained edge-local TRUST, ROT, RUST,
challenge-ledger projection, additive conflict declaration/resolution, structural RUST concentration,
explicit causal localization, and bounded artifact-relative BLAME/GUILT propositions.
Each TRUST event binds one exact transformation, its inputs/output, the historical Graph,
and prerequisite TRUST events; current eligibility recursively fails closed when any bound
dependency degrades or conflicts. Duplicate paths remain set-valued, historical graph bytes
remain immutable, and topology alone earns no causal or moral conclusion. BLAME establishes
bounded responsibility or material contribution. GUILT is not BLAME in the opposite
direction: it composes separately bound responsibility, exact scoped-obligation
applicability, and same-obligation violation components, then binds their exact event
digests. One compound mechanism may emit all three component evaluations in one invocation;
an opaque combined pass or decorative obligation string remainsNOT_ESTABLISHED.
Localization binds one exact passing RUST event and descendant-deviation proposition.
Neither result establishes actor morality, reputation, automatic legal liability,
innocence, exoneration, obligation satisfaction, or absence of hidden contributors.
Status-conflict resolution projects the
selected state into current admissibility; arbitrary resolved predicates remain blocked.
The current runtime has no general non-status admissibility-effect mechanism. RUST follows
historically recorded contributing ancestry even when current lifecycle state excludes a
route from TRUST. New construction, evidence-bound Graph establishment, and assurance
propagation require globally disjoint artifact/transformation identifiers so an untyped
subject_idcannot ambiguously name both; the frozenVSTD-DATA-0.1reader retains its
original two namespaces.
Add complete offline event replay,
current TRUST filtering, and deduplicated descendant reassessment discovery. -
Preserve incompatible Graph assertions as evidence-linked conflict records and label
rating-derived Graph profile numbers asCALLER_SUPPLIEDcandidates with conformanceNOT_ESTABLISHED. -
Classify the current VSTD-4 candidate-depth calculation as a structural result over
caller-supplied rung references with conformanceNOT_ESTABLISHED; reject that
candidate at the VSTD-5 entry gate even when its candidate depth is 14. -
Label compatibility Graph 2–5 candidates consistently while separately presenting the
implemented evidence-bound reference paths. Bind complete challenge-ledger state into an
additive current Graph view without mutating history.
Release and maintainer controls
- Mark 1.2.0 metadata as an unreleased release candidate, omit any fabricated release
date, and require the exact tagged checkout to haveTIME.mdset toStatus: CLEAR. - Move the immutable-release setting check before tag creation in the documented release
sequence and enforce it again in the tag workflow, so a disabled setting stops
publication rather than producing a mutable release. - Make package/reference status identify VSTD-5 as the highest exposed project
specification with an evidence-bound reference mechanism, without claiming a real
independent witness, and require finalized release metadata in the tag workflow. - Publish the architecture ownership map linking normative documents, runtime validators,
schemas, and conformance tests. - Document the five-As human traversal over existing receipt, Graph, hardware, certificate,
reproduction, and SCITT machinery without adding a serialized receipt format; reject duplicate Graph
identifiers and reproduction-fidelity states inferred from declarations, matching verdicts, or
mismatching runs. - Restore the three non-overlapping operating controls:
AGENTS.mdfor automated work,
HUMANS.mdfor human five-As reasoning, andTIME.mdfor current repository
contradictions. Development may recordOPEN; the exact tagged checkout must be
CLEARbefore publication. - Replace the developmental profile-numbered generic-run container with required neutral
assessment_context; preserve its mechanism, bound, commitment, and refutation
coordinates without carrying a VSTD-4 conformance field.