Skip to content

VSTD v1.2.0

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Sep 15:42
· 2 commits to main since this release
Immutable release. Only release title and notes can be modified.
v1.2.0
dcc9e95

Source tag signature status: SIGNED_AND_GITHUB_VERIFIED (valid).

Every uploaded asset is bound to the exact public commit by the external release manifest and a GitHub artifact attestation. The wheel and source distribution published to PyPI are the same tested files attached here. Verify a GitHub asset with:

gh attestation verify PATH_TO_ASSET --repo TimeLordRaps/verifier

Public surface and integrations

  • Restructure the public first-view path around one bounded project description, one
    deterministic demonstration, one canonical maturity table, skeptical claim limits,
    contributor routes, and release/citation boundaries; align Pages and package metadata
    without changing normative or serialized-receipt semantics.
  • Normalize the public architecture as a verification complex of named closure
    coordinates and cumulative numbered profiles; reserve VSTD-4 rung, candidate depth,
    verification order, compatibility level, and checker-cost tier for their distinct uses.
  • Add experimental workflow profile 0.1 with deterministic canonicalization, strict
    validation, bounded work-allocation records, additive amendments and challenges,
    explicit unresolved horizons, and verdict-neutral platform events.
  • Add a normalized GitHub adapter for issues, commits, workflow runs, artifacts, and
    pull requests. Successful workflows and merges retain verification_effect = NONE
    unless a separate native result is explicitly mapped through a bound VSTD receipt.
  • Add vstd experiment validate and vstd experiment github-events as offline,
    verdict-neutral entry points. Repository artifacts are explicitly NOT_CHECKED with
    exit code 2 unless their root is supplied.
  • Add a machine-readable schema, checked-in verdict-neutral specimen, generated
    experiment index, adversarial tests, and a runnable offline example.
  • Add a generated CLI/API reference page and presentation gates that reject stale
    reference or experiment-index content.
  • Clarify VSTD's role as a verification-domain language and interchange layer that
    preserves, rather than replaces or strengthens, native verifier results.
  • Add the experimental SCITT adapter, rerunnable real-COSE specimen with ephemeral keys, explicit semantic
    boundary, and adversarial composition tests without claiming IETF review or payload
    truth from registration.
  • Surface zero-identity/zero-knowledge (ZIZK) artifact-first TRUST as governing
    architecture, publish the bounded RISC Zero reference mechanism and exact recorded
    public proof artifacts, and keep only unfinished mechanisms experimental while
    preserving unresolved horizons and native-system authority.
  • Bind the recorded RISC Zero proof to the image produced from the tracked guest and
    locked toolchain in the governed offline verifier, rather than accepting source/proof
    correspondence from a neighboring historical image identifier.
  • Formally distinguish TRUST as mechanism-earned forward artifact support, ROT as typed
    time-indexed degradation of current admissibility, and RUST as an inverse-TRUST memetic
    causal backtrace toward recorded ancestor states. None is actor-tied trust or a scalar;
    reachability alone never infers guilt, responsibility, or causal localization.
  • Present current reports, schemas, module descriptions, and examples under the full
    VSTD-1 and VSTD-2 numbered-profile identifiers; remove retired partial-profile object identifiers from
    active readers and add a regression preventing their return.
  • Add normative artifact-control mechanism version 1 with exact-byte file/directory
    freezing, SHA-256 plus SHA3-256 artifact-derived identities, observable read-only
    guards, readable finite self-closing Ed25519 seals, external anchor checks, and
    copy-on-write thaw descendants. Sealing is not encryption and supplies no actor trust,
    semantic correctness, trusted time, or numbered VSTD profile result.
  • Document multi-temporal realms, discrete and continuous coexistence, causal and
    problem-space partial orders, atemporal versus temporal capsules, explicit cross-realm
    mappings, and future constrained language-model transition verification without
    claiming continuous mediation, inference-law implementation, or textual truth.

Claim boundaries and validation

  • Require thawed_artifact_status and vstd artifact status to verify an actual supplied,
    cleanly sealed parent and every recorded parent coordinate before returning
    THAWED_CLEAN or THAWED_DIRTY. Sidecar-only agreement is now NOT_ESTABLISHED; even a
    verified current match does not authenticate the historical copy operation or external
    parent continuity.
  • Preserve final filesystem-entry identity during artifact creation: freeze refuses
    symbolic-link sources, and bundle, thaw-descendant, and sidecar outputs refuse every
    preexisting lexical entry, including dangling symbolic links, without claiming universal
    race-free filesystem security.
  • Require authoritative freeze-manifest, payload, seals-container, and seal-envelope
    members to have ordinary lexical types; linked external or in-bundle targets cannot lend
    bytes to bundle closure, while verified outer read aliases and ordinary hard-link
    byte-and-path semantics remain explicitly distinct.
  • Remove the live SimulacraBench rehearsal and its front-door promotion; the repository
    never contained or reproduced the submission, hosted image, hardware, or protected
    evaluation identified by that name.
  • Correct generic-run wording: digest validation is an integrity check, external
    references remain unattested until dereferenced and verified, same-path output
    extraction is not independent verification, and unverified determinism is UNKNOWN.
  • Publish a Pages guide index and enforce language, title, viewport, main-region, skip-link,
    image-alt, labelled-navigation, generated-reference, and local-link checks in CI.
  • Preserve explicit ordered-list starting numbers in generated Pages so procedures split
    by code blocks retain their source step numbers instead of restarting at one.
  • Require CodeQL security-extended Python analysis in the protected repository-check
    aggregate with only read access to content and write access to security results.
  • Fail closed on malformed generic-run receipts, publish their exact schema, and dispatch
    VSTD-1 by its required receipt profile.
  • Package every normative specification, verify byte identity, and smoke-test the built
    wheel outside the source checkout so installed specification bindings cannot silently
    become unavailable.
  • Bind the bundled checker to VSTD-1, record actor and execution separation explicitly,
    and never infer independent actors from a historical field name, repeated runs, or
    matching results.
  • Reject self-promoted independence even when every supplied status and digest agrees;
    the generic-run compatibility path never derives EVIDENCED from serialized references.
    The distinct VSTD-5 path reruns all seven separation propositions and does not upgrade
    the legacy generic-run fields.
  • Require the real optional SCITT/COSE cryptographic example in the protected
    repository-check aggregate
    rather than allowing its dependency-gated tests to disappear from the base matrix.
  • Close generic-run control structures while retaining the released refutation-extension
    map, make common receipt commands honor --json, and lock validate as an
    integrity/profile check rather than a claim verifier.

Graph and conformance semantics

  • Add a zero-dependency evidence execution core that resolves and rehashes exact evidence
    bytes, pins a registered mechanism implementation digest, enforces byte/item bounds,
    reruns the mechanism, and preserves PASS, FAIL, or UNKNOWN under explicit trust roots.

  • Add an evidence-bound VSTD-4 path and replayable receipt form. Compatibility
    vstd4_depth remains a NOT_ESTABLISHED candidate; only exact passing VSTD-1/2/3 and
    fourteen-rung mechanisms plus an accepted kernel witness admit VSTD-5.

  • Implement the VSTD-5 reference mechanism and receipt: seven evidence-bound separation
    dimensions, duplicate-witness/evidence refusal, exact admitted-certificate and
    corroboration binding, typed binding/identity/separation/corroboration errors,
    disagreement preservation, embedded evidence, and offline result recheck. Independence
    fails closed on any identity or separation defect without parsing error-message text.
    Witness identities and assertions serialize separately and in order, so duplicate,
    orphan, missing, and reused-identity error inputs remain replayable instead of collapsing
    during receipt construction. Keep permissive malformed-input assessment distinct from
    portable receipt admission: the builder now raises unless the strict schema and complete
    verdict-material evidence coverage hold, and the rechecker applies the same zero-dependency
    gate before replay. The rechecker also compares the complete carried VSTD-4 entry, and
    corroboration_class is mechanism-bound rather than relabelable metadata. This does not
    claim a real external witness or independent implementation; a positive observation with
    unresolved independence is overall UNKNOWN.

  • Add evidence-bound Graph profile computation and replay. The compatibility graph_level
    path remains caller-supplied; the new path reruns every member, ancestor, and reached-edge
    rating mechanism bound to the exact Graph, members, collection, and claim before profile
    1–5 can report ESTABLISHED. Profile zero remains NOT_ESTABLISHED.

  • Add VSTD-GRAPH-ASSURANCE-1 and AssuranceLedger for hash-chained edge-local TRUST, ROT, RUST,
    challenge-ledger projection, additive conflict declaration/resolution, structural RUST concentration,
    explicit causal localization, and bounded artifact-relative BLAME/GUILT propositions.
    Each TRUST event binds one exact transformation, its inputs/output, the historical Graph,
    and prerequisite TRUST events; current eligibility recursively fails closed when any bound
    dependency degrades or conflicts. Duplicate paths remain set-valued, historical graph bytes
    remain immutable, and topology alone earns no causal or moral conclusion. BLAME establishes
    bounded responsibility or material contribution. GUILT is not BLAME in the opposite
    direction: it composes separately bound responsibility, exact scoped-obligation
    applicability, and same-obligation violation components, then binds their exact event
    digests. One compound mechanism may emit all three component evaluations in one invocation;
    an opaque combined pass or decorative obligation string remains NOT_ESTABLISHED.
    Localization binds one exact passing RUST event and descendant-deviation proposition.
    Neither result establishes actor morality, reputation, automatic legal liability,
    innocence, exoneration, obligation satisfaction, or absence of hidden contributors.
    Status-conflict resolution projects the
    selected state into current admissibility; arbitrary resolved predicates remain blocked.
    The current runtime has no general non-status admissibility-effect mechanism. RUST follows
    historically recorded contributing ancestry even when current lifecycle state excludes a
    route from TRUST. New construction, evidence-bound Graph establishment, and assurance
    propagation require globally disjoint artifact/transformation identifiers so an untyped
    subject_id cannot ambiguously name both; the frozen VSTD-DATA-0.1 reader retains its
    original two namespaces.
    Add complete offline event replay,
    current TRUST filtering, and deduplicated descendant reassessment discovery.

  • Preserve incompatible Graph assertions as evidence-linked conflict records and label
    rating-derived Graph profile numbers as CALLER_SUPPLIED candidates with conformance NOT_ESTABLISHED.

  • Classify the current VSTD-4 candidate-depth calculation as a structural result over
    caller-supplied rung references with conformance NOT_ESTABLISHED; reject that
    candidate at the VSTD-5 entry gate even when its candidate depth is 14.

  • Label compatibility Graph 2–5 candidates consistently while separately presenting the
    implemented evidence-bound reference paths. Bind complete challenge-ledger state into an
    additive current Graph view without mutating history.

Release and maintainer controls

  • Mark 1.2.0 metadata as an unreleased release candidate, omit any fabricated release
    date, and require the exact tagged checkout to have TIME.md set to Status: CLEAR.
  • Move the immutable-release setting check before tag creation in the documented release
    sequence and enforce it again in the tag workflow, so a disabled setting stops
    publication rather than producing a mutable release.
  • Make package/reference status identify VSTD-5 as the highest exposed project
    specification with an evidence-bound reference mechanism, without claiming a real
    independent witness, and require finalized release metadata in the tag workflow.
  • Publish the architecture ownership map linking normative documents, runtime validators,
    schemas, and conformance tests.
  • Document the five-As human traversal over existing receipt, Graph, hardware, certificate,
    reproduction, and SCITT machinery without adding a serialized receipt format; reject duplicate Graph
    identifiers and reproduction-fidelity states inferred from declarations, matching verdicts, or
    mismatching runs.
  • Restore the three non-overlapping operating controls: AGENTS.md for automated work,
    HUMANS.md for human five-As reasoning, and TIME.md for current repository
    contradictions. Development may record OPEN; the exact tagged checkout must be
    CLEAR before publication.
  • Replace the developmental profile-numbered generic-run container with required neutral
    assessment_context; preserve its mechanism, bound, commitment, and refutation
    coordinates without carrying a VSTD-4 conformance field.