Skip to content

Releases: eddyflores100-lang/alethech

alethech v0.7.0 — atomic import + fail-closed + artifact hash + spec cleanup

Choose a tag to compare

@eddyflores100-lang eddyflores100-lang released this 28 Sep 01:47

What changed

Second external audit identified 5 real findings. All closed.

🔴 P1-1: Atomic import transaction

  • Refactored import to use staging: build in-memory representation of post-import state, verify EVERYTHING, then write atomically
  • If any verification step fails, target store is untouched
  • Architecture: package → parse → verify → stage → verify staged → atomic write

🔴 P1-2: Fail-closed checkpoint semantics

  • verify_store: checkpoint count mismatch is now an ERROR, not a warning
  • Previously: count mismatch → warning + continuity_verified=True (semantically incoherent)
  • Now: count mismatch → error, continuity NOT verified

🔴 P1-3: Artifact hash check during import (fail-closed)

  • Import now verifies SHA256(content) == filename before staging artifact
  • Previously: artifact written first, hash mismatch discovered later by verify (too late)
  • Now: corrupted/tampered artifact rejected BEFORE any writes

🔴 P1-4: Spec drift — MemexExport → AlethechExport

  • Renamed manifest type from MemexExport to AlethechExport
  • Backward-compatible: import accepts legacy MemexExport with warning
  • Removed all did:memex references from spec docs
  • Removed all memex init/commit/verify/... CLI references in spec

🟠 P1-5: Trust gate for IdentityRecordV2

  • Import now applies --trust-unknown-identities gate to v2 identities (same as legacy)
  • Previously: v2 identities written without trust check
  • Now: unknown v2 identities rejected without --trust-unknown-identities

Tests

  • 230 tests passing (was 225)
  • tests/test_070_audit_fixes.py — 5 adversarial tests:
    • TestAtomicImport: failed checkpoint leaves target unchanged
    • TestFailClosedCheckpoint: count mismatch is error not warning
    • TestArtifactHashCheck: corrupted artifact rejected + atomicity
    • TestTrustGateV2: unknown v2 identity rejected without trust flag
    • TestMutationGuards: artifact hash check is enforced

Stats

alethech v0.6.0 — conformance + import hardening + anti-rollback

Choose a tag to compare

@eddyflores100-lang eddyflores100-lang released this 28 Sep 01:38

What changed

Repo identity fix

  • Moved legacy/memex to separate repo: eddyflores100-lang/memex-legacy
  • alethech repo now has exactly 1 branch (main), no legacy branches
  • Updated README with crystal-clear "What this repo IS / is NOT" section
  • Any visitor now sees only alethech — no confusion with memex possible

Finding 1: Conformance criptográfico independiente

  • Created conformance/ directory with 15 adversarial test vectors
  • Categories: valid/, invalid_signature/, invalid_key/, numeric/, unicode/
  • conformance/generate_vectors.py — reproducible vector generation
  • External implementations (Rust, TypeScript) can test against these vectors
  • tests/test_conformance_vectors.py — 16 tests

Finding 2: Hardening de import/export

  • 5 security defenses in import command:
    • Path traversal rejection
    • Symlink rejection (input + all files)
    • File size limit (50 MB max per file)
    • File count limit (10000 max)
    • Total size limit (500 MB max)
  • tests/test_import_hardening.py — 7 adversarial tests

Finding 3: Anti-rollback formal

  • Added sequence field to Checkpoint (monotonic counter)
  • Sequence is part of signed payload (cannot be tampered)
  • Backward-compatible: old checkpoints default to sequence=0
  • Consumer can detect: sequence < N (rollback), sequence == N (replay)
  • System clock is NOT the authority — sequence is
  • tests/test_anti_rollback.py — 6 tests

Stats

alethech v0.5.8 — JCS RFC 8785 conformance fix

Choose a tag to compare

@eddyflores100-lang eddyflores100-lang released this 28 Sep 01:04

What changed

Two JCS bugs in 0.5.7, both caught by external audit:

Bug 1: -0 was preserved as -0

  • RFC 8785 erratum + ECMAScript spec: -0 MUST serialize as "0" (sign NOT preserved)
  • 0.5.7 was returning "-0" — incorrect
  • Now correctly returns "0"

Bug 2: Positive exponents had + stripped

  • RFC 8785 / ECMAScript requires + for positive exponents: "1e+21", not "1e21"
  • 0.5.7 was returning "1e21" — incorrect
  • Now correctly returns "1e+21"

Both bugs were caught by review of the 0.5.7 JCS test suite, which was passing but asserting INCORRECT expectations. This is exactly the failure mode tonydzi warned about:

a test that cannot fail when the property is violated does not prove the property.

Verification

  • All 56 JCS conformance tests pass with corrected expectations
  • Full suite: 196 tests passing
  • PyPI 0.5.8 install verified: -0.0 → "0", 1e21 → "1e+21", 1e-7 → "1e-7"

Note on 0.5.7

alethech 0.5.7 on PyPI contains these bugs and should not be used. Yank requested. Use 0.5.8+.

Stats

alethech v0.5.7 — protocol closed

Choose a tag to compare

@eddyflores100-lang eddyflores100-lang released this 28 Sep 00:55

What changed

0.5.6 — Two bloqueantes closed

#1 Checkpoint continuity

  • verify_store() now requires checkpoint.head_commit_id to be an ANCESTOR of the current HEAD
  • Previously only checked presence + count match, allowing a "dark gap" where HEAD didn't descend from the checkpoint
  • New error: checkpoint_continuity_failed

#2 Root binding

  • Explicit root_id binding between RootAuthority ↔ IdentityRecord ↔ ControlEvent
  • Previously only verified signatures, not that they were bound to the SAME root authority
  • New errors: identity_root_binding_failed, control_event_root_binding_failed

0.5.7 — JCS RFC 8785 conformance

  • 56 test vectors covering integer/float serialization, -0 preservation, scientific notation format, UTF-16 key ordering with surrogate pairs, string escaping, NaN/Infinity rejection
  • Fixed canonical.py to match ECMAScript Number.prototype.toString() algorithm
  • Fixed: 1e+21 → 1e21, 1e-07 → 1e-7, 3.0 → 3, large integer-valued floats now use shortest round-trip decimal

Stats

  • 196 tests passing
  • 8 mutation-guard paths (3 code-level reachability + 2 recall-seam + 1 checkpoint + 2 root binding)
  • 0 open issues, 0 open PRs
  • License: MIT
  • Python: 3.10–3.13

Semantic guarantees

commit ∈ ancestry(cutoff_head)  →  VALID_HISTORICAL
commit ∉ ancestry(cutoff_head)  →  NOT_IN_PROVEN_PRE_ROTATION_HISTORY

No temporal claims. No REVOKED_KEY_AFTER_CUTOFF verdict.

Install

pip install alethech
alethech init
alethech commit --content file.json
alethech verify