SEMAPRAX v0.6.0
Pre-releaseSEMAPRAX v0.6.0 is alpha research software.
Changes
-
Keep the frozen private Component v7 WIT identity at
0.5.0while the crate
advances to0.6.0, and repin the version-bound public-generic Component
known answers against independently emitted success and contract-failure
fixtures. The four exact Component CI contract tests pass locally; hosted
release evidence remains pending. -
Pin the Wavect GmbH release verifier to GitHub's immutable owner/repository
OIDC subject and require matching subject and ID extensions in the verified
Fulcio certificate. This is local offline verification, not hosted signature
evidence until the authorized v0.6.0 tag gate publishes immutable assets. -
Observe Core Wasm record-
Bytescopy-out only after the generated Node
facade returns owned bytes from its settled JS arena, with strict transport
refusal controls. Physical Wasm free, instruction-fuel parity and hosted
target acceptance remain open. -
Project a frozen malformed-result carrier recipe through generated TypeScript
against the compiler-produced checked Wasm provider, alongside exact
descriptor/binding and once-only result-release controls. This is local
compiled-provider evidence, not the full hostile or hosted R06 matrix. -
Bridge explicit held signed root/leaf generations into the existing resolver
subject cache after fresh lock-bound artifact reads. CLI lock-bound fetch and
the bridge share the extracted held cache writer; copied subjects carry no
persistent signature/freshness authority and failures retain uncertain prefixes. -
Add explicit offline artifact reads from a held signed Registry-v3 generation,
bound to exact Lock-v3 and independently admitted manifests. Reads replay
trusted-time freshness and recheck ACTIVE before returning immutable bytes;
no reusable bearer token, ambient path read or execution authority is added. -
Add an explicit local Registry-v3 generation store coordinating signed trust,
full root/leaf Lock-v3 selection and exact core artifacts, with one-way v1
migration and exact interrupted-commit recovery. Receipts remain evidence;
no fetch/read/execution capability or hosted registry support is added. -
Add pure offline signed metadata-v2 verification for producer-backed
Registry-v3 linked roots and leaves, exact lock/artifact checks, and a one-way
Checkpoint-v2 protocol floor preserving prior version/digest high-water marks.
Candidates remain non-authoritative; managed-host/fetch integration is separate. -
Add independently verified dependency-free Build-v1 leaf manifests and an
additive producer-backed Registry-v3. A real linked root/leaf catalog now
reproduces Lock-v3 bytes and checks exact source/report/dependency closure;
focused tamper, yank, missing-leaf and API-claim controls pass locally.
Existing profiles remain unchanged; trusted v3 distribution is separate. -
Add a separate private authenticated-native-allocating.v1 handoff for a
closed checked Bytes body/callee subset. An explicit-context reservation,
canonical lease settlement and all-leaf result preflight preserve sticky
failure through generated C11/C++17 callers. Focused controls cover real
allocating callees, reservation/body/postcondition refusals, oversized
results and missing-drop/dispatch controls; the actual legacy runtime
emitter retains its frozen bytes. General-body, cross-backend, hosted and
public acceptance remain open. -
Add a separate private authenticated-native-moves.v1 handoff that executes
checked flat-Bytesrecord movement bodies through generated C11/C++17
callers. Focused physical controls cover both branches, malformed/legacy
refusals, identity-body omission, and postcondition-failure settlement;
allocating/status-producing bodies and public acceptance remain open. -
Add an explicit local registry trust host with held owner-private storage,
independently pinned bootstrap, immutable signed-evidence/checkpoint and
selected-artifact generations, one durableACTIVEpivot, and exact
fail-stop recovery. Focused local crash-point and hostile-state tests pass;
this adds no fetch/network authority or physical power-loss claim. -
Correct catalog-normalizer JSON control escapes at
\\u0010–\\u001f
and exercise ten oracle-frozen controls across interpreter, native C and
Core Wasm. The maximal 65,536-byte response still exhausts the unchanged
100M-step fuel bound, so the catalog acceptance milestone remains open. -
Add a TUF-style local registry verifier with independently installed roots,
namespace-delegated Ed25519 thresholds, dual-threshold root rotation, exact
registry/manifest bindings, freshness, rollback and yank checks. Results are
non-authoritative checkpoint candidates; the managed durable host above is
separate, and trusted distribution remains open. -
Compact catalog-normalizer scalar projection helpers and avoid a repeated
label walk when summing accepted record quantities. The 18-case focused
interpreter/native C O0/O2/Core Wasm oracle selector passes, but the exact
65,536-byte/256-record plain response still exhausts 100M fuel; enriched
maximal output and the full owning gate remain unverified (#286 open). -
Add a dispatch-only Windows confinement runtime gate that requires nonzero
execution of restricted-token child launch, job limit/membership, scratch
DACL, descendant refusal and test-owned descendant timeout, normal/nonzero
settlement, timeout cancellation, and filesystem-stage refusal with
handle-count cleanup. The gate uses
test-key-signed capsule fixture bytes (not a release trust anchor), requires
successfultaskkill /Tand direct Cargo PID absence on
timeout, and checks exact marker/scratch cleanup. Descendant quiescence is
not independently enumerated. The original two-test slice passed on exact
checkoutc6bf9902; the historical five-test selector passed in hosted
Windows run35988348061at3d4220b6. Current source uses the shared
signed-capsule verifier and capsule-v1 architecture codes 3/4 for Windows,
with a historical nine-test selector (six runtime cases plus three admission refusals).
That selector passed on exact checkoutc608b8d8in hosted Windows Server
2025 run35992373373(9 passed, 0 failed, 0 ignored). Artifact-byte binding and production
support remain unverified. A tenth selected Windows case now exercises a
real inheritable broad ACE on a private parent and requires the created
scratch DACL to stay protected with only its intended explicit ACE; the
expanded selector passed atf4d3291fin hosted Windows Server 2025 run
35993882814(10 passed, 0 failed, 0 ignored). -
Harden additive lock-bound offline fetch with held-directory authority,
bounded retained inputs, private staging and no-replace cache publication.
Failures retain stages or a published prefix for explicit reconciliation,
without pathname rollback or a misleading success receipt; unsupported
hosts refuse before cache effects. -
Re-pin exact Semantic Workspace Change and Operations artifact/evidence/receipt
KATs to the expanded Project graph and serialized limits while retaining
domain, reference, API/CLI parity, tamper, replay, budget, and stale/no-write
assertions. -
Keep the standalone compiler archive independent of unpublished crates by
moving the private OCI emitter and all hostile tests into one internal
compiler module. Preserve the typed input boundary, exact artifact bytes,
credential refusal, and unchanged no-signing/no-registry-publication scope. -
Keep the private public-generic Component runtime inside its ambient-authority
source contract: acquire a checked-in canonical project explicitly, replay
against pinned identities, and authenticate exact Component bytes before
typed execution. This does not widen public Component support. -
Generate canonical descriptor-bound TypeScript/Wasm carrier frames and run
the generated package against the compiler-owned provider lifecycle. Add the
privatesemaprax.authenticated-native-identity.v1C profile, which rejects
malformed or drifted frame metadata before physical work and invokes one
compiler-checked flat owned-Bytesidentity endpoint across C, C++, and Rust.
These are local, unpublished profiles; broader shapes, shared-corpus and
hosted acceptance remain open. -
Settle borrowed arguments and returned
Bytesat the native Agent stage
boundary, retaining sticky failure and strict post-drop receipts. Local
controls cover success, contract failure, cancellation, omitted drops,
malformed receipts, and duplicate calls; native instruction fuel, complete
finalizer accounting, compound cleanup failures, and Wasm parity remain open. -
Emit the internal
public-generic-wasm-provider.v1endpoint as a
deterministic zero-import Core Wasm module with exact descriptor/binding
replay, normalized artifact binding, canonical carrier SHA-256 validation,
module-owned scratch and opaque lifecycle handles, checked HIR invocation,
two-pass result export, and explicit release/close operations. The generated
TypeScript runtime now delegates provider lifecycle to those exports. The
subsequent canonical carrier migration makes that package interoperable;
#229 and the broader #162 matrix remain open for their larger acceptance
scope. -
Add the internal
public-generic-wasm-provider.v1Project profile as the
first compiler-owned target foundation for #229. Package Manifest v1 now
selects exactly one concrete checked generic owned-record endpoint, derives
its Public Generic Descriptor v1, independently replays it against the exact
linked program and project revision, and binds the verified digest into
Project Lock v1. Web, npm, native, and Agent Transport artifact routes remain
fail-closed until the Core Wasm provider emitter exists. The #162 native
generated-caller settlement gate now shares this compiler-derived descriptor,
binding, instance, cleanup, and leaf identity across C, C++, Rust, and the
executed reference provider; the endpoint body remains the explicit reversal
fixture, so neither issue is closed by this phase. -
Make the push-driven CI and Docs workflows latest-ref only: a newer run now
cancels its in-progress predecessor instead of spending hosted runner minutes
completing already-superseded matrices or documentation builds. -
Extend the bounded resumable-effect source profile from one site to one to
eight direct sequential Copy-scalaryieldsites. The deterministic plan now
carries ordered per-site states and yield-free resume projections; the public
interpreter uses an opaque in-memory request/answer history, while private
native-O0/-O2and Core Wasm runners replay the same projections. Every
historical request is checked, and bindings commit exact arguments plus
prior answer bits. This remains pure replay, not live-frame/liveness
lowering: control-dependent yields, owned state, durability, scheduling and
public target ABIs remain open. Distinct request/response assignment sites
fail closed withSPX-T299;letand tail sites retain distinct types
(#204). The original one-siteResumablePlan, exhaustiveResumableStep
and start/resume functions remain source-compatible; sequential lowering and
execution use additive plan, step and start/resume surfaces. -
Add the initial deterministic compiler-owned three-state HIR plan for the
single-top-level, Copy-scalaryieldslice (subsequently widened above).
Resume state now binds the exact
checked program, yield site, and bit-exact original arguments. Closed
projections now isolate disconnected yielding functions while retaining the
selected and authored-entrypoint direct-call closures; retained non-scalar,
effectful, owned-cleanup, generic and function-reference surfaces, all
authored nominal/authority surfaces, reachable yielding callees, retained
incoming callers, forged projections,
and stale bindings fail closed. The interpreter consumes the plan identities,
whilecfg(test)-only
native-O0/-O2and Core Wasm runners execute independently validated
yield-free projections, preserving exact normalized prefix/suffix arithmetic
and pre/postcondition failures. Ordinary native/Wasm emitters still refuse
yields; arbitrary NaN-payload preservation across the JavaScript Wasm test
adapter, public continuation ABI, external-await runtime seam, durable source
checkpoint, Agent migration, and general live-frame/control-dependent yield
lowering are not claimed. The reference v1 journal additionally completes
an already-observed partial turn without redispatch and never repeats cleanup for an in-memory
replayed terminal; its unchanged wire has no durable append or cleanup
settlement, so decoded terminal cleanup and crash recovery remain ambiguous
and unclaimed (#204). -
Add a deterministic, non-executing cross-language benchmark reproduction
capsule that binds exact task and adapter inventories, equivalence files,
public and hidden trees (including empty directories), and per-language
adapter policy. Stable descriptor-backed reads reject path swaps, and a
matching capsule says only that scoring inputs match, never that a model or
toolchain ran (#211). -
Compose the task-service reference application and generated service
scaffold withstd.tracing's pure trace-context and secret-classification
policy now that reachability pruning admits the dependency closure. Valid,
malformed, and caller-classified-secret cases join the existing backend
parity gate; no logging, span emission/export, or host authority is added
(#194). -
Record the first hosted Windows compilation evidence for the production
provisioner confinement module. The successful Windows Server 2025 job
compiled thecfg(windows)code at the exact recorded revision but selected
no confinement test function, so runtime confinement evidence remains open
(#236). -
Add an offline, unavailable-only admission gate for future external coding-
agent baselines. It binds the owner-pinned task inventory bytes and Zero
source revision to closed toolchain, interface, model, and reviewed-port
provenance without running a model or treating provenance as execution
evidence (#107). -
Carry exact empty
Bytesarguments through source-native Core Wasm Agent
stages using the existing named slice/range/copy ownership path, with
interpreter, native-O0/-O2, and Core Wasm parity plus a retained
malformed-carrier refusal (#143). -
Harden generated package preview verification around a flat physical-file
inventory and private verified snapshots before optional npm or Cargo dry-
runs. Package publication, signing, registry credentials, and support-policy
promotion remain outside this tool (#145). -
Harden the paired-agent pilot's stale-recovery metric so only an exact,
well-formed conditional write to the drifted source can count as recovery,
and only the gateway's exact stale-precondition refusal can count as a
rejected stale write. Reads, unrelated paths, malformed commands, and other
failures now fail closed instead of producing optimistic evidence. Fresh
cohorts now have a digest-bound reviewer packet and exact 18-tuple audit:
direct treatment labels are withheld, task content remains visible, and
hostile or drifted evidence fails closed without backfilling the historical
cohort (#105). -
Preserve
i64::MINwhen source-native Agent stage arguments are synthesized
for Core Wasm and native C11 execution. A four-leg regression now exercises
the value through the interpreter, native-O0, native-O2, and Core Wasm,
while empty byte literals retain their stable refusal (#182). -
Add a binding-first Lean-kernel certificate recheck that re-derives the
source, exact obligation selector, Lean document, and Wasm artifact before
consulting caller-supplied kernel authority, then requires exact recorded
axiom results. Kernel-confirmed evidence can now be associated with one exact
retained ProjectProgramRootand appended to its assurance manifest through
an opaque verified token; sibling projects, altered source, subset
certificates, and replayed revisions fail before attachment. No process,
filesystem, network, or tool-discovery authority is added to the compiler
(#186). -
Preserve every failing real-distribution role in the provisioned Linux
doctor diagnostics instead of stopping at Node's first failure. Hosted run
35472257722 remains red (12/13 in both suites): Clang passed, Node received
SIGSEGV, and Rust's exact termination awaits the next instrumented run;
confinement policy and WP-05 status are unchanged (#61). -
Track AArch64 Linux doctor confinement separately with a dispatch-only native
Arm runner and an exact 24-case plan. The committed evidence is limited to a
historical local Docker Desktop Arm VM run (24/26); the two real-distribution
fixtures remain excluded for missing selector/bundle preconditions, and no
hosted, current-head, or physical-device support claim is made (#279). -
Compose
std.tracingtrace-context field admission with the existing
std.log.redactsix-flag caller classification, preserving
malformed-context refusal and left-to-right lazy evaluation. It does not
inspect bytes or tracestate and remains a pure policy layer with no span
generator, exporter, sink, or transport authority (#193). -
Version and digest the public-generic hostile corpus, pinning 17 shared case
outcomes plus exact bytes for 9 structured-descriptor and 6
malformed-trusted cases in one deterministic manifest while correcting
stale evidence counts. Persistent compiled source mutants now prove that
five previously untested descriptor-envelope refusals are individually live
in the generated Rust, shared C11/C++17, and TypeScript consumers, and that
weakening each branch reaches the provider before clean settlement.
Exact-current-head hosted evidence, carrier-side consumer hostility, and real
generated endpoints remain outstanding (#173). -
Drive the private frozen iterative Agent loop through the existing sealed
interpreter, native C11-O0/-O2, and Core Wasm stage backends. The local
parity gate covers proposal admission, fresh consumed grants, injected binary
reads, continued and terminal reductions, cancellation, malformed proposals,
lifecycle ceilings, and semantic evidence settlement while leaving production
wrappers interpreter-only. It also fixes canonical lexical selection of ten-
plus synthesized Wasm projection exports without reordering driver, decode, or
cleanup plans. Native/Wasm interpreter-fuel and hosted evidence remain open
(#182). -
Extend the source-live repair preview with an explicitly selected OpenCode
Provider-Adapter route, durable V2 receipts, a restart-stable absolute
deadline, and checkpoint identity bound to the chosen executable and
scratch path. Terminal recovery now replays recorded provider bytes without
pre-deriving fixture diagnostics or redispatching, binds corrective turns to
the actual canonical prior effect, and rejects tampered settled responses.
A public embedding seam can now inject one opaque, host-selected,
fixed-buffer candidate-test observer: its canonical result is bound to the
exact candidate/base/source/capability, settled as typed feedback for a later
provider turn, and replayed without redispatch. Executable bytes and metadata
are bound, run/export scratch state is cleaned before reuse, and foreign or
tainted observations fail closed. The ordinary CLI still grants no test or
publication authority; the scripted V1 seam stays frozen for offline
regression coverage (#116). -
Add whole-line UTF-8 validation and checked nonnegative
i64total helpers
to the catalog-normalizer example, with malformed-scalar, boundary-total,
backend-parity, and mutation-control regressions. This is a
bounded foundation tranche; the complete record parser, canonical writer,
duplicate handling, and independent oracle remain open (#124). -
Have tag release jobs produce pinned GitHub build-provenance attestations
for each platform archive and keylessly sign the final aggregate provenance
with pinned cosign tooling. Release publication now carries those bundles
beside the manifest and provenance, while policy and tests distinguish the
GitHub OIDCsubclaim from the Fulcio workflow-URL certificate identity.
A bounded offline verifier now closes the Sigstore v0.3 framing, GitHub
workflow-v1 predicate structure, exact archive inventory, and aggregate
manifest/provenance/claim bindings before invoking an explicit verifier
capability.SigstoreOfflineVerifiersupplies the standalone CLI's default
pure implementation, checking certificate-chain and pinned identity,
DSSE/message signatures, signed time, and transparency-log evidence against
exact caller-supplied historical trusted-root bytes. An embedding host can
still inject another capability. Verification performs no network or root
refresh and does not establish current revocation state, publication,
reproducibility, or support. No signed hosted release is claimed yet (#168). -
Stop Universal Semantic Transaction v1 from refusing every project with a
commented bundled dependency (#274).ProjectCandidate::apply's
materializestep re-derived every source in the revision through the
comment-dropping canonical formatter, so the comment-free precondition had
to span the complete workspace -- including compiler-bundled dependency
source (std.authcarries 253 comment lines,std.jobs34) that no project
can edit, makingSPX-G525unsatisfiable by construction rather than by
authoring.materializenow preserves an untouched program's exact base
bytes, and the newsrc/project/semantic_transaction/canonical_sources.rs
enforces comment-free canonical source differentially, of exactly the
sources a transaction rewrites or drops. A comment in a rewritten source is
still refused withSPX-G525, and theSPX-G525regression that proves it
is unchanged. -
Run a real Lean kernel against the
proof_exportobligation export for the
first time (#186). The module shipped with noLeanKernelimplementation and
no evidence Lean accepts its generated proofs -- every test replayed
synthesized output.scripts/lean-export-gate.pyis that implementation,
deliberately outside the crate so the compiler gains no ambient process
authority: it confirms the host runs the pinnedleanprover/lean4:v4.34.0
(the same pinproofs/kernel0-leanuses), checks the committed golden
document plus two seeded variants, and compares each result byte-for-byte
against transcripts committed undersrc/proof_export/testdata/, so recorded
evidence cannot silently go stale. Results:omegadischarges both the
checked-range obligation and the postcondition, axiom-clean and
byte-reproducible across runs; a seededsorryis refused; and a vacuously
weakened conclusion is accepted by the kernel with an axiom set cleaner
than the honest proof's -- recorded as data, because it is precisely why a
certificate bindslean_source_sha256andverify_certificate_against_source
re-renders the document from source instead of trusting the embedded bytes.
Fixes one real fail-open the real kernel exposed: Lean 4.34.0 prints
declaration uses `sorry`with backticks, so both single-quoted spellings
kernel_report::parsewas written against (from synthesized fixtures) were
dead against the very toolchain the module pins, leaving only thesorryAx
clause load-bearing; quoting is now normalized. All kernel evidence is
local-host only -- hosted CI provisions no Lean toolchain, the gate is not
inscripts/quality.shand not inrelease-gate's blocker set, and every
certificate now carries that as an explicit nonclaim. -
Narrow
ProjectFrontendCache's AST-level invalidation (src/project/incremental.rs):
a provider module's own changed/added/removed source still invalidates its
frontend cache entry, but an unrelated consumer that only imports from that
provider no longer loses its entry through the old transitive reverse-import
closure. Parsing and canonicalizing one file is a pure function of that
file's own bytes, so a reused entry is bit-identical to a fresh reparse
regardless of what any provider did, and every cross-module check (import
stub validation, the checked-HIR cache's own exactsynthetic-equality
gate) still reruns unconditionally against the current build's sources, so
a provider's exported-surface change is still caught -- narrowing this set
only decides which unaffected files skip a redundant reparse. On
examples/calculator-project, a provider body edit went from 0 modules
cloned / all 3 reparsed (80 AST nodes) to 2 modules cloned / 1 reparsed
(32 AST nodes), matching the existing local-body-edit case instead of being
its expensive opposite (#130, #131). -
Add
scripts/generated-package-release.py(prepare/check), a
release-preparation and dry-run-only layer around the existing Project v8
owned-data-api.v1generated npm/Rust packages: closed-inventory,
secret/local-path, and no-private-dependency admission; deterministic
README/LICENSE/checksum-manifest wrapping; and acheckstep that only
ever runsnpm pack --dry-run/cargo publish --dry-run(never
--publish, never near a live registry credential). Prepares (but does not
make) the maintainer publication decision drafted in
docs/GENERATED-PACKAGE-PUBLICATION-DECISION-DRAFT-V1.md; nothing is
published by this change (#145). -
Refuse a bundled dependency member that names an authored type at the Useful
Data workspace linker boundary, by name, rather than admitting it into a
declaration set that deliberately holds no authored type and letting it
surface much later asinline-array slot references an unknown typeinside
inline-array capacity analysis. Drop such a member from the retained
dependency inventory when nothing reaches it, so a bundled package may still
declare a generic record. This restoressemaprax new --template service,
which therecord Secret<T>added to the bundledstd.authhad broken for
every scaffolded project (#268). -
Execute the unchanged native reference provider inside freestanding Core Wasm
at O0/O2 under both V8 tiers, with in-module allocation, ownership registries,
multi-call copy-in/export/release and no host imports. Add a bounded private
transport, exact native/corpus comparison, allocator self-tests, hostile-range
and lifecycle tests, deterministic artifacts, canonical replay, and compiled
semantic mutation controls for #162. This is a C11-reference fixture, not a
Semaprax-generated generic endpoint, public Wasm ABI, PG-7 completion or hosted
promotion. Actual Rust-renderer equality remains a separately selected gate. -
Enforce single-owner, non-reentrant native reference-provider admission with
one atomic owner/entry word; retain ownership until the last provider closes,
and isolate failure injection, traces and sticky diagnostics per caller thread.
Reject misuse without touching caller output/owning aliases or reporting false
zero-resource counters. Extend #162 with deterministic pthread misuse/handoff,
exact/+1 thread-identity admission, sanitizer, replay and mutation gates. This
enforces the existing synchronous restriction, not concurrent execution,
compiled generic-provider support, PG-7 completion or hosted promotion. -
Harden the host-owned TypeScript/Wasm reference caller: authenticate immutable
module-byte snapshots, reject unverifiable precompiled modules, isolate private
descriptor/binding authority, enforce one in-flight owner and exact framed
payload bounds, preflight complete result frames, and propagate primary plus
secondary cleanup failures. Extend #162 with 108 settlement cases, 32 host
regression groups, 13 authenticated module subjects, two V8 Wasm execution
tiers, fresh C/C++ semantic comparison, strict replay and twelve type-checked
behavioral mutants. Add actual-generator byte-equality gates without claiming
those Rust gates have run, compiled-provider support, PG-7 completion or hosted
promotion. No existing native ABI or public rejection profile is widened. -
Propagate explicit native release failures through C11/C++17 calling consumers
without exposing a decoded success or overwriting earlier failures. Add
checked close with retained ownership, reverse caller rollback, bounded
encoding/export/decode, and per-invocation injection isolation. Implement
corresponding Rust settlement and fallible codecs, with separate Cargo
regressions. Extend #162 by 112 shared consumer cases, independent caller
counters, replay evidence and eleven compiled semantic negative controls;
actual generator/Rust execution remains a distinct gate, and full PG-7,
compiled Wasm and hosted promotion are not claimed. -
Return real native input/result release failures without overwriting an earlier
call's settlement. Extend #162 with actual per-leaf result allocation/copy and
export preflight failures, pre-rollback byte checks, exact 16 MiB success,
compound reverse cleanup, and 72 pinned physical-phase cases with a third
independently replayed evidence artifact. Legacy logical trace bytes and
public ABI declarations remain unchanged; full PG-7 and generated-consumer
failure propagation are not claimed. -
Prevent stale native public-generic handles from reviving when heap addresses
are reused; validate provider identities before access/close and pin bounded,
non-recycled identities plus exact/+1 live-resource admission. Isolate
settlement between sibling prepared inputs so an earlier success cannot mask
a later failure as success-without-result. Extend #162 with lifecycle/recreation,
identity-exhaustion, 8,192-call stress and paired replay evidence; public ABI
signatures and unsupported/unpublished status remain unchanged. -
Share one bounded, digest-pinned public-generic settlement manifest across the
existing model/native harnesses; preserve primary failures before cleanup and
reverse every native result rollback. Add per-case native observations, real
allocation/compound-failure regressions, retained trace expectations, and
portable sanitizer/replay evidence. This advances the fixture subset of #162;
it does not close PG-7 or widen public ownership support.
These unsigned archives are not notarized and make no cross-host reproducible-build claim.
SHA-256 checksums are integrity facts, not signatures.