Skip to content

VSTD 1.2.0 release-candidate maintainer review #21

Description

@TimeLordRaps

Coordinate

Review seams

  1. Verifier Standard (VSTD) claim/evidence binding and preservation of UNKNOWN, CONFLICTED, and NOT_ESTABLISHED.
  2. Actor independence: distinct actors and execution seams must be evidence-bound, not inferred from serialized fields, references, repetition, or placement.
  3. VSTD-4 and VSTD-Graph candidate/conformance ceilings, including VSTD-5 rejection of unearned readiness.
  4. Frozen generic-run compatibility and the legacy, non-dispatching meaning of layer4_binding.
  5. Supply Chain Integrity, Transparency, and Trust (SCITT) interoperability as adjacent signature/registration evidence rather than payload truth.
  6. Governing zero-identity/zero-knowledge (ZIZK) artifact-first architecture; process-bound TRUST, ROT, and RUST; cryptographic enclosure for confidential witnesses; and the bounded RISC Zero and identity-disclosure mechanisms.
  7. AGENTS.md, HUMANS.md, and TIME.md as non-overlapping maintainer controls.
  8. Public presentation, GitHub Pages, security analysis, packaging, and exact-head release gates.

Required interpretation

  • Identity or reputation alone cannot strengthen an artifact-bound result; checked identity may establish only the exact attribution, authorization, or separation proposition earned by its mechanism.
  • Zero identity means zero identity-derived verdict weight, not anonymity. Architectural zero knowledge presumes no unevidenced proposition; when a witness is confidential, cryptographic zero knowledge may enclose the exact program, predicate, commitments, output, parameters, and verifier only through a named proof system.
  • TRUST is mechanism-earned artifact support moving forward across checked transformations. ROT is typed time-indexed degradation of current admissibility without rewriting historical receipts. RUST is the inverse-TRUST memetic causal backtrace over recorded ancestor states; diagnostic reachability alone does not establish falsehood, guilt, responsibility, intervention-level causal localization, or automatic ancestor falsification. None is actor-tied trust or a scalar.
  • Historical receipts remain immutable and readable. Current admissibility may change without rewriting historical status.
  • Green repository checks are evidence about their named checks, not VSTD conformance, external adoption, or maintainer approval.

File-to-seam review matrix

Passing automation supplies evidence for the named checks below; it does not record the
maintainer disposition. Review each row against the pull-request diff and mark the
corresponding checklist only after the invariant and falsification boundary are acceptable.

Seam Primary review surfaces Reject the candidate if Current evidence Disposition
1. Claim/evidence binding standard/LADDER.md; docs/CLAIMS_AND_LIMITS.md; src/verifier/core/checker.py; src/verifier/core/run.py; src/verifier/core/run_validation.py; tests/test_assurance_flow_invariants.py; tests/test_generic_run.py A declaration, digest, field name, or missing mechanism strengthens a claim. Full suite, generic-run adversarial tests, presentation gate PENDING MAINTAINER REVIEW
2. Actor independence src/verifier/core/run.py; src/verifier/core/run_reproduction.py; src/verifier/core/run_validation.py; generic-run schemas and examples; tests/test_generic_run.py; tests/test_assurance_flow_invariants.py References, repeated runs, matching results, or placement emerge as evidence-bound distinct actors or execution seams. Independence falsification and same-result rerun tests PENDING MAINTAINER REVIEW
3. VSTD-4 and Graph ceilings standard/LADDER.md; src/verifier/core/depth.py; src/verifier/data/graph_level.py; tests/test_vstd4_depth.py; tests/test_graph_level.py Caller-supplied ratings or structural candidates become established conformance, or VSTD-5 accepts unearned readiness. Depth, duplicate-path, cycle, conflict, and candidate-label tests PENDING MAINTAINER REVIEW
4. Historical layer4_binding standard/WIRE_IDENTIFIERS.md; src/verifier/core/run.py; src/verifier/core/run_support.py; src/verifier/core/run_validation.py; generic-run receipt schema; tests/test_generic_run.py; tests/test_vstd3_backward_compatibility.py Historical bytes or reads break, the name drives VSTD-4 dispatch, or current writing silently changes frozen meaning. Compatibility fixtures, strict-profile validation, packaged specifications PENDING MAINTAINER REVIEW
5. SCITT interoperability docs/standards/VSTD_SCITT_CROSSWALK.md; src/verifier/interoperability/scitt/adapter.py; SCITT examples; tests/test_scitt_interop.py; tests/test_scitt_crypto_example.py Signature or registration success manufactures payload truth, VSTD correctness, or actor independence. Required real COSE path plus adversarial composition tests PENDING MAINTAINER REVIEW
6. ZIZK TRUST/ROT/RUST architecture README.md; docs/ARCHITECTURE.md; standard/LADDER.md; examples/zizk_artifact_first/; experiments/artifact_first_mechanisms/; tests/test_zizk_artifact_first.py Governing architecture is buried as a side experiment; actor identity becomes TRUST; ROT rewrites historical truth; RUST loses its memetic backtrace semantics; or diagnostic ancestry becomes guilt, falsehood, or causal localization. Tracked proof artifacts, manifest binding, supported-Linux offline verification, ZIZK tests PENDING MAINTAINER REVIEW
7. Maintainer controls AGENTS.md; HUMANS.md; TIME.md; scripts/check_time_status.py; tests/test_presentation_surface.py Agent rules, human reasoning, and live repository contradictions overlap, or publication proceeds with live TIME contradictions. TIME.md clear, release-status and presentation tests PENDING MAINTAINER REVIEW
8. Release and public presentation .github/workflows/; scripts/release_artifacts.py; scripts/check_release_boundary.py; docs/API_STABILITY.md; docs/; scripts/build_reference.py; tests/test_public_api.py; tests/test_release_artifacts.py; tests/test_presentation_surface.py Repository checks are described as VSTD conformance, exact artifacts are not reproducible, private boundaries leak, or first-use/public claims exceed implementation. Exact-head local build, 476-member boundary scan, deterministic CycloneDX SBOM, installed-wheel smoke, branch-coverage artifact, hosted run and CodeQL PENDING MAINTAINER REVIEW

Review order for the stacked candidate

  1. Review pull request Prepare the complete VSTD 1.2.0 release candidate #27 first: 60 files, 2,530 additions, and 1,232 deletions relative to Prepare VSTD 1.2.0 and restore the public boundary #20.
  2. Review pull request Prepare VSTD 1.2.0 and restore the public boundary #20 for the underlying release semantics: 275 files, 25,486 additions, and 5,222 deletions relative to main.
  3. Do not record final disposition against Prepare VSTD 1.2.0 and restore the public boundary #20 until Prepare the complete VSTD 1.2.0 release candidate #27 has landed into its branch and the resulting Prepare VSTD 1.2.0 and restore the public boundary #20 head has rerun all protected checks.
  4. Treat the cumulative comparison main...codex/post-1.2-professionalization as the current complete candidate: 290 files, 27,127 additions, and 5,567 deletions.

A four-hour pass can be a risk-prioritized maintainer disposition over the eight seams; it is not an exhaustive line-by-line review of approximately 32,000 changed lines.

Exact-head evidence

  • Cumulative head has a good GNU Privacy Guard signature from key F5537E7240663768250B315091A5B5158391B78C.
  • Main-branch protection requires signed commits; all 48 cumulative candidate commits are GitHub-verified with reason valid.
  • Local full suite: 405 passed.
  • At the cumulative head, current reports and examples name VSTD-1, VSTD-2, and VSTD-Graph-1; removed 0.x specification filenames are absent from every live GitHub branch, while issued 0.x wire identifiers and tagged release bytes remain frozen historical compatibility evidence.
  • The v0.1.0 and v0.2.0 GitHub release pages carry additive historical-coordinate notices directing readers to the current identifier map; their tags and attached artifact bytes were not changed.
  • On 2026-08-27, in the documented Ubuntu 24.04 Linux environment under Windows Subsystem for Linux 2, direct network-offline RISC Zero 3.0.6 verification at the cumulative head accepted the exact tracked receipt and public envelope against the pinned image identifier without the private witness.
  • Artifact-first manifest and repository-bound artifacts verify at sha256:756425630fcb8552cd0892c1ba64a3150fbb3c021b0d930b9cf4f5e86bf6b4fe.
  • Exact-commit package build, manifest verification, CycloneDX 1.6 Software Bill of Materials validation, Twine validation, installed-wheel smoke, Pages, presentation, and release-boundary checks pass; the boundary scan covered 476 text members across 5 artifacts.
  • All 15 workflow jobs passed on the cumulative head in run 33090567593; the pull request reports 16 checks including the adjacent GitHub CodeQL result.
  • CodeQL passed on the cumulative pull-request merge ref; GitHub currently reports 0 open code-scanning, Dependabot, and secret-scanning alerts.
  • GitHub reports pull requests Prepare VSTD 1.2.0 and restore the public boundary #20 and Prepare the complete VSTD 1.2.0 release candidate #27 as clean and mergeable; Prepare VSTD 1.2.0 and restore the public boundary #20 does not yet contain Prepare the complete VSTD 1.2.0 release candidate #27, and no review approval is currently recorded.
  • TIME.md is Status: CLEAR.
  • Version 1.2.0 remains intentionally UNRELEASED; publication requires a later explicit metadata finalization and tag decision.

Falsification condition

Request changes if declarations, names, hashes, repetition, graph multiplicity, actor reputation, placement, SCITT registration, or satisfiability can increase assurance without a named mechanism validating the exact proposition and evidence binding; if mechanism separation becomes actor independence; if recorded ancestry becomes causal proof; if UNKNOWN or CONFLICTED is cleaned; if a candidate becomes conformance; or if any exact-head evidence above fails.

Maintainer disposition

  • Select an exact private conduct-reporting route and replace the nonexistent
    "private GitHub channel" instruction in CODE_OF_CONDUCT.md; do not repurpose public
    issues or silently treat security advisories as the general conduct mechanism.
  • Decide whether normative releases require an approving reviewer independent of the
    pull-request author, then align branch protection and governance text with that actual
    control.
  • Review the eight seams above and the corresponding pull-request diff.
  • Record APPROVED here when the normative, compatibility, security, and release boundaries are acceptable, or record exact requested changes.
  • Merge only after that disposition is recorded.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

release-integrityRelease provenance, byte identity, or artifact bindingsecurity-boundaryExecution, trust, or observation boundaryspecificationNormative VSTD specification text or schema

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions