Skip to content

Releases: thomaswillner/llm-errata

LLM Errata v0.4.1

Choose a tag to compare

@thomaswillner thomaswillner released this 14 Aug 04:12
4ed5d01

LLM Errata v0.4.1 is an integrity and conformance hardening release.

Highlights:

  • immutable source-target and metadata-only release binding;
  • append-only, bidirectional publication supersession chains;
  • gate-specific G3–G5 structural validation separated from qualification;
  • exact same-erratum G4 adapter-receipt and validator binding;
  • complete three-system G5 experiment contract;
  • byte-preserving shared G2 surface digest;
  • fail-closed malformed evidence across G2–G6;
  • full-width SHA-256 state roots and clearer snapshot limitations.

Validation: exact-head independent standards/spec reviews passed; Python 3.11 and 3.13 CI passed; 390 repository tests passed.

Production verdict remains NOT_PROD_READY. G2–G6 remain BLOCKED; this experimental release does not claim production readiness, external conformance, audited production cryptography, independent implementations, operated-system interoperability, or operational certification.

Copyright remains Thomas Rainer Willner. Commercial and non-commercial clean-room specification implementations require attribution to LLM Errata, Thomas Willner, and this repository. Reference code remains personal-use/non-commercial unless separately licensed.

LLM Errata 0.4.0 — First Materially Improved Experimental Release

Choose a tag to compare

@thomaswillner thomaswillner released this 14 Aug 00:34
b21e4c1

LLM Errata 0.4.0 — first materially improved experimental release

LLM Errata 0.4.0 is a substantially stronger public baseline for evaluating and extending post-export AI-memory correction, supersession, and erasure workflows.

It is an experimental conformance proposal and tested reference implementation. It is NOT_PROD_READY. Publishing this release does not certify production safety, interoperability, complete deletion, or semantic absence.

What improved

  • Complete internal Phase 2 schemas, protocol vectors, semantic probes, durable quarantine checkpoints, and receipt-binding mutations.
  • Complete external adapter interface without hidden reference-ledger coupling.
  • Provider-neutral adapter-conformance corpus with exact target-instance tracing and complete expected outcomes.
  • Bounded proposition-multiplicity preservation checks.
  • Executable validator anti-vacuity attacks for empty receipts, no-op feed verification, and constant-unknown aggregation.
  • Canonical corpus identity, exact scalar-type validation, normative-history reachability, tracked-byte execution, external repository/source identity, construction and execution timeouts, package isolation, lazy-import isolation, and dependency-manifest binding.
  • Same-importer conflict persistence, explicit split-view limitations, truthful empty-lineage handling, phase-specific checkpoint coverage, and content-free erasure evidence.
  • GitHub Actions upgraded to immutable Node 24 action pins while preserving Python 3.11 and 3.13 validation.

Contributor credit

Rastislav Drahoš / DanceNitra materially advanced this release by reporting adapter-coverage and empty-lineage defects, split-view limitations, hidden ledger coupling, incomplete adapter behavior, duplicate-preservation blind spots, and validator anti-vacuity failures. The immutable MIT-licensed candidate fixture remains at DanceNitra/agora@2ba1e299b3483b9038d03387345702427608b90b; its copyright remains with its contributor. LLM Errata independently authored its accepted corpus and validator without copying or vendoring the external runner or fixtures.

Frank Denis / jedisct1 pointed to jedisct1/ed25519.py, which is recorded as a useful pure-Python comparison oracle. It was not copied, vendored, or treated as production cryptography.

Open production-readiness work

  • G2 BLOCKED: no qualifying independent review of the complete current conformance surface.
  • G3 BLOCKED: production cryptography is not yet an audited constant-time exact build with independently reviewed key lifecycle.
  • G4 BLOCKED: two independently established adapters and a separately produced third-party validator are not yet available.
  • G5 BLOCKED: no completed experiment across three independently operated real memory systems.
  • G6 BLOCKED: no complete independent measured operational-security, observability, recovery, compatibility, and performance report.

These are continuing development and validation tracks. External review is welcome whenever users or reviewers engage, but silence is neither approval nor a reason to withhold an honestly scoped experimental release.

Ownership and licence

  • Repository-authored work remains copyright Thomas Rainer Willner.
  • Independent commercial and non-commercial implementations of the specification are permitted under the irrevocable worldwide royalty-free implementation grant, with accessible attribution to LLM Errata, Thomas Willner, and https://github.com/thomaswillner/llm-errata.
  • Reference Code in prototype/, scripts/, and tests/ remains personal-use restricted under the repository licence.
  • Version 0.2.0 and earlier retain their irrevocable Apache License 2.0 grant.
  • No endorsement, sponsorship, certification, audit, partnership, exclusivity, patent grant, or transfer of contributor copyright is implied.

Verification

LLM Errata 0.3.0 — Phase 2 Conformance Surface

Choose a tag to compare

@thomaswillner thomaswillner released this 14 Aug 00:34

LLM Errata 0.3.0

Historical release metadata backfill for the existing immutable v0.3.0 tag at e5b4c660b506101f28d840cb651e0c6810994f01. The tag has not been moved.

This version introduced the Phase 2 conformance surface and changed repository licensing. Version 0.2.0 and earlier remain under their irrevocable Apache License 2.0 grant. Version 0.3.0 Reference Code is governed by the repository licence at this tag.

This historical version is not production ready and is no longer the supported release after v0.4.0 publication. See the tag’s CHANGELOG.md, LICENSE, and SECURITY.md for exact contemporaneous terms.

LLM Errata 0.2.0 — Public Concept Proposal and Phase 1 Proof

Choose a tag to compare

@thomaswillner thomaswillner released this 07 Aug 01:10

An imported memory is a dependency, not a copy. When its source is corrected, superseded, or erased, the importer should quarantine its known descendants, rebuild them from valid inputs, and report anything it could not verify.

This is a concept proposal and a request for technical challenge. It is not a production protocol, not a standard, and not a claim of invention.

What is in it

  • A runnable proof. make demo runs one supersession across three deliberately different stores. It exits 2. Both inspectable stores are fully repaired, all three probes pass, and the aggregate is still partial, because one required store cannot show its own state. That refusal is the deliverable. A demo where everything passes proves only that the demo was built to pass.
  • A bounded, dated, falsifiable claim, with the conditions under which it should be narrowed or withdrawn written down before anyone challenges it.
  • A prior-art record whose citations check out, pinned to arXiv versions, draft revisions, and commit SHAs, with the sources that remain unpinned listed as an open risk rather than hidden.
  • Tooling that can fail. The claim guard is anchored to exact sentences and proved by negative tests; a corpus asserting a world first is rejected, not congratulated.

What changed since the unpublished 0.1.0

Quarantine-before-repair is no longer claimed as a contribution. MemoRepair reached the same ordering independently in May 2026 and was missed by the original screen. Three further collisions were added. The four-part conjunction survives, and the record says why in the matrix rather than in an argument.

Two security defects found by adversarial review after the suite was already green are fixed, each with a test that failed first.

HARD_PROBLEMS.md screens the three problems the proposal declares out of scope. Proving semantic absence is still open. The other two have materially advanced.

The most useful thing you can do

Break it. A prior-art collision that retires the claim is a success for this project, not an attack on it. CONTRIBUTING.md has the evidence requirements, and there is an issue form for exactly that.

Version 0.1.0 was written on 2026-08-01 and never published. It stays in the changelog as a dated entry because the prior-art claim is stated as of that date and must not be back-dated to match a later release.