Skip to content

Prepare VSTD 1.2.0 and restore the public boundary - #20

Closed
TimeLordRaps wants to merge 39 commits into
mainfrom
codex/v1.2.0-workflow-profile
Closed

Prepare VSTD 1.2.0 and restore the public boundary#20
TimeLordRaps wants to merge 39 commits into
mainfrom
codex/v1.2.0-workflow-profile

Conversation

@TimeLordRaps

@TimeLordRaps TimeLordRaps commented Aug 25, 2026

Copy link
Copy Markdown
Owner

Coordinate

  • Public repository: TimeLordRaps/verifier
  • Head: codex/v1.2.0-workflow-profile@039ba96517ebebe733e3f728aa52989233f8b010
  • Base: main@598c545be3833d6d81bb7e252ca5837f3bb2a449
  • Governance review: VSTD 1.2.0 release-candidate maintainer review #21
  • Package coordinate: 1.2.0 release candidate; this pull request does not merge, tag, or publish it.
  • Head signature: good GNU Privacy Guard signature from key F5537E7240663768250B315091A5B5158391B78C.
  • Branch protection: required signed commits enabled; all 39 commits in this pull request are GitHub-verified.

Current state: exact-head local and hosted checks pass and GitHub reports the pull request mergeable. No maintainer approval has been recorded; green repository checks are not self-authorization to merge and are not a VSTD conformance result.

Stacked terminology note: pull request #27, at
edf591b40242a74e4b893e7938a0eb60a572c818, formally defines TRUST, ROT, and RUST
and distinguishes architectural zero knowledge from its optional cryptographic
zero-knowledge enclosure. Those additions are not part of this pull request's head
until #27 lands into this branch.

The file-to-seam review matrix and maintainer disposition remain tracked in issue #21; this pull request does not convert passing automation into human approval.

What this pull request changes

Verification semantics and compatibility

  • Preserves frozen receipt discriminators, historical bytes, and compatibility reads.
  • Keeps historical generic-run layer4_binding readable and newly emitted under the frozen profile while classifying it as legacy generic assessment context, not VSTD-4 dispatch or conformance.
  • Prevents declarations, arbitrary references, matching outputs, repeated runs, process placement, or machine placement from self-promoting actor independence.
  • Restricts reproduction claims to the exact declared-output and execution-outcome scope.
  • Keeps VSTD-4 and VSTD-Graph computations explicitly candidate-level with conformance NOT_ESTABLISHED where no evidence-binding adapter exists; VSTD-5 rejects unearned readiness.
  • Preserves duplicate-path, cycle, conflict, challenge, revocation, staleness, and supersession boundaries without inventing the unfinished propagation algebra.

Governing artifact-first architecture

  • Presents zero-identity/zero-knowledge (ZIZK) artifact-first TRUST as governing VSTD architecture rather than an experimental research track.
  • Defines zero identity as the rule that identity or reputation alone cannot strengthen an artifact-bound result; it is not anonymity or absence of identifiers.
  • Limits zero knowledge to a named proof mechanism's exact formal property, predicate, parameters, and assumptions; it is not a property of VSTD generally.
  • Preserves TRUST as bounded forward causal-provenance flow and RUST as a memetic causal backtrace over recorded ancestor states. RUST reaches diagnostic ancestry; it does not by itself establish guilt, intervention-level causal localization, responsibility, or automatic ancestor falsification.
  • Limits “experimental” to event serialization, TRUST-transfer algebra, RUST concentration/localization, complete trichotomy derivation, and specific unfinished optional proof backends.
  • Surfaces the bounded identity-disclosure evaluator and RISC Zero reference mechanism under examples/zizk_artifact_first/, including the tracked public receipt, public envelope, self-test result, source, exact digests, and verifier command.

Public and maintainer surfaces

  • Restores AGENTS.md, HUMANS.md, and TIME.md as non-overlapping agent, human, and repository-contradiction controls.
  • Adds the five-As human traversal over existing VSTD machinery without creating a competing ontology or wire format.
  • Reworks README and GitHub Pages navigation for newcomer-first reading, explicit acronym expansion, first-viewport actions, canonical site metadata, an explicit unreleased-candidate coordinate, runnable examples, maturity boundaries, and direct access to the artifact-first mechanisms.
  • Replaces the self-certifying “Conformance” workflow/badge label with “Repository checks.” The protected conformance-gate job identifier remains unchanged solely because branch protection requires that exact status context.
  • Adds pinned GitHub CodeQL Python analysis with security-extended queries and makes it a protected-gate dependency.
  • Keeps SCITT/COSE verification adjacent to payload truth: signature or registration success cannot manufacture VSTD correctness or actor independence.
  • Adds exact-head release, presentation, Pages, package reproducibility, installed-wheel, and public-boundary controls. Version 1.2.0 remains intentionally UNRELEASED pending a separate finalization decision.

Exact-head evidence

  • Local full suite: 387 passed.
  • Presentation, acronym, generated-reference, experiment-index, specification-copy, Pages, compile, and diff-integrity checks pass.
  • In the documented supported Ubuntu 24.04 Linux environment under Windows Subsystem for Linux 2, CARGO_NET_OFFLINE=true ./scripts/verify_recorded_proof.sh rebuilt the cached verifier path and returned PASS for the tracked RISC Zero receipt and public envelope against the pinned image identifier; no private witness or salt was used.
  • The artifact-first experiment manifest and every repo: artifact digest verify; current manifest digest: sha256:20a9060d8244ed1af59d0ea2e058dc412b08c5b4851c4abcbf7994059e2b093f.
  • Exact-Git-object source ZIP, reproducible wheel, source distribution, and external manifest build and verify from HEAD.
  • twine check passes; the public-boundary scan checked 446 text members across 3 archives.
  • The exact committed wheel passes demo, plan, run, validate, reproduce, compatibility-alias, and installed-specification checks outside the source checkout.
  • All 14 jobs in exact-head hosted run 33036499955 passed: Python 3.10–3.13, standard-library smoke, SCITT cryptography, Linux/Windows release integrity, cross-platform reproducibility, installed-wheel smoke, Pages/presentation, CodeQL, and the protected repository-check aggregate.
  • CodeQL analyzed the pull-request merge ref with 0 results across 50 rules; the separate GitHub CodeQL status also passed.
  • TIME.md is Status: CLEAR.

Compatibility boundary

  • No frozen schema identifier, receipt discriminator, or released receipt byte is silently redefined.
  • No current mechanism establishes external adoption, independent implementation, complete physical provenance, Graph rating-to-evidence validation, challenge-to-Graph propagation, actor-independence binding, complete TRUST/RUST algebra, or public SCITT transparency anchoring.
  • Historical PASS remains immutable while current admissibility may change; UNKNOWN, CONFLICTED, and NOT_ESTABLISHED remain visible.

Falsification condition

Request changes if any field name, declaration, digest, repetition, graph multiplicity, actor reputation, runtime placement, SCITT registration, or satisfiable formula can increase assurance without a named mechanism validating the exact proposition and evidence binding; if mechanism separation is presented as evidence-bound actor independence; if recorded reachability is presented as causal localization; if UNKNOWN or CONFLICTED becomes clean; if current candidate/conformance boundaries disappear; or if any exact-head check above cannot be reproduced.

Maintainer checklist

  • TIME.md is Status: CLEAR.
  • Exact-head local and hosted gates pass.
  • Frozen compatibility and current candidate/conformance boundaries are explicit.
  • ZIZK architecture and bounded reference mechanisms are publicly discoverable.
  • This pull request does not tag or publish version 1.2.0.
  • Maintainer has reviewed the semantic, compatibility, security, and release boundaries and recorded a disposition in VSTD 1.2.0 release-candidate maintainer review #21.

TimeLordRaps and others added 30 commits August 23, 2026 05:23
Rejects "Zero Identity" as a public label: the construction withholds civil
identity while retaining pseudonym, key, trust root, issuer, and revocation
coordinates. Adds a non-normative semantic model, threat model, standard-library
evaluator, 14 fixtures, and 39 tests that keep UNKNOWN and CONFLICTED intact.

Coordinate: no layer, base 598c545, seam experiments/zizk_vstd/zero_identity.
Falsification: any record reaching ACCEPTED_BOUNDED with a REFUTED property, or
unlinkability reaching SUPPORTED, refutes the model.
Compatibility: no wire identifier, schema $id, receipt digest, console alias,
lifecycle token, dependency, or conformance behavior changed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Authorization alone cannot tell a first-party claim from a relayed one, so the
profile now keeps three questions apart: whether a key was permitted a scope,
who is speaking and at what remove, and how the key obtained its authority.

Authorship degree covers originator, delegate, relay, and aggregator roles; an
absent role stays UNKNOWN rather than defaulting to origination, and a
non-originator claiming origination is REFUTED. Credential ancestry records
issuance, delegation, and rotation links, mirroring the recorded-lineage
discipline of VSTD-Graph-1: a revoked ancestor or a scope-widening delegation is
REFUTED, while an unattested link, a chain missing its trust root, and an
unattested rotation stay UNKNOWN. Neither property can reach SUPPORTED.

Adds seven fixtures (21 total) and eighteen tests (57 total). Records that
ancestry enlarges the correlation surface, so authorship provenance and
unlinkability are in direct tension, resolved toward provenance with the cost
stated.

Coordinate: no layer, base 598c545, seam experiments/zizk_vstd/zero_identity.
Falsification: authorship_degree or credential_ancestry reaching SUPPORTED, a
relayed role read as first-party authorship, or a revoked ancestor evaluating as
anything other than a refutation.
Compatibility: no wire identifier, schema $id, receipt digest, console alias,
lifecycle token, dependency, or conformance behavior changed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Records the round-1 result and tightens the evaluator where review found it
inferring more than the evidence carried.

Required public coordinates now cover the pseudonym, the key identifier, and
the declared trust roots, and a minimization request that removes any of them
is REJECTED whether it names the leaf or a parent path. Authentication requires
a pseudonym and a key identifier bound to a declared root; authorization
requires an issuer that is itself declared. Authorship degree must be a
non-negative integer, so a boolean or a negative remove stays UNKNOWN rather
than being read as origination.

A shared pseudonymous coordinate no longer refutes independence. It refutes
independent corroboration from that coordinate, which the record already
carries, but actor independence is a claim about people and stays UNKNOWN from
a single record. The fixture moves from rejected_ to unknown_ to say so.

The round-1 report separates four evidence classes and states a ceiling for
each: semantic results, external attestations, declared assumptions, and
protocol guarantees. It records the terminology decision, the claims currently
justified, the claims still prohibited, and the failed tests, of which there
are none.

22 fixtures and 65 tests, all passing; repository suite 255 passed, 3 skipped;
presentation gate clean.

Coordinate: no layer, base 598c545, seam experiments/zizk_vstd/zero_identity.
Falsification: absence of a required coordinate producing a favourable result,
a parent-path deletion bypassing a protected leaf, or unlinkability,
authorship_degree, or credential_ancestry reaching SUPPORTED.
Compatibility: no wire identifier, schema $id, receipt digest, console alias,
lifecycle token, dependency, or conformance behavior changed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Merge the bounded identity-disclosure and real zero-knowledge experiments into one experimental tree, then define the actor-blind Tier 0 reverification boundary. Agreement remains non-accumulating, divergence requires a checkable comparable trace, and UNKNOWN and CONFLICTED remain first-class outcomes.

Keep rust as an optional object-bound analytical view with no verdict authority, distinguish the two existing STALE enum families, and record the ZK journal trichotomy correction without implementing or reserving a wire profile.

Relocate the Round 1 zero-knowledge report beside its experiment. The repository-level ZK containment test remains the sole deliberate file outside experiments/zizk_vstd.

Validation: 22 ZI fixtures, 65 ZI tests, 3 ZK containment tests, 258 repository tests passed with 3 pre-existing skips, presentation gate passed, and compileall passed.
# Conflicts:
#	AGENTS.md
#	ROADMAP.md
#	docs/profiles/experimental-workflow.md
#	docs/reference.html
#	examples/experimental_workflow/README.md
#	examples/experimental_workflow/demo.py
#	experiments/INDEX.md
#	scripts/build_reference.py
#	tests/test_experimental_workflow_profile.py
# Conflicts:
#	docs/ECOSYSTEM.md
Bind generic receipts to a strict profile and package every specification for installed-wheel validation. Record actor independence without inferring it from matching runs, preserve Graph conflicts, and mark supplied-rating levels as non-conformant candidates. Add architecture, schema, packaging, and adversarial coverage.
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@TimeLordRaps TimeLordRaps added this to the v1.2.0 milestone Aug 27, 2026
@TimeLordRaps TimeLordRaps added specification Normative VSTD specification text or schema documentation Improvements or additions to documentation release-integrity Release provenance, byte identity, or artifact binding security-boundary Execution, trust, or observation boundary labels Aug 27, 2026
State Artifact support as forward causal-provenance flow and Rust as a memetic
backtrace over recorded ancestor states without promoting diagnostic reachability
into guilt or intervention-level localization. Correct validator and
repository-check wording, improve release-note structure, and move the newcomer
actions into the first viewport with canonical site metadata.

Coordinate: VSTD architecture and v1.2.0 public/release surfaces; no wire-format
change.

Falsification: any revised surface must not imply that reachability proves
responsibility, that generic validation verifies external evidence, or that
repository checks establish VSTD conformance.

Compatibility: frozen identifiers, schemas, receipt bytes, and runtime behavior
are unchanged.
@TimeLordRaps

Copy link
Copy Markdown
Owner Author

Superseded by #27. Pull request #27 contains this pull request's head, now targets main, and is the single VSTD 1.2.0 review surface. Closing #20 avoids two independent merges; it does not claim that VSTD 1.2.0 has been merged, tagged, published, or released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation release-integrity Release provenance, byte identity, or artifact binding security-boundary Execution, trust, or observation boundary specification Normative VSTD specification text or schema

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants