Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
fbab340
Define the current VSTD profile ladder
TimeLordRaps Aug 29, 2026
54e5798
Decompose the generic run runtime
TimeLordRaps Aug 29, 2026
e86a4b4
Add artifact freeze and self-closing seals
TimeLordRaps Aug 29, 2026
798e99c
Add bounded SCITT interoperability
TimeLordRaps Aug 29, 2026
3979a56
Add the experimental workflow profile
TimeLordRaps Aug 29, 2026
764f33c
Publish the ZIZK artifact-first reference mechanisms
TimeLordRaps Aug 29, 2026
3cc2186
Ground VSTD-3 execution evidence
TimeLordRaps Aug 29, 2026
0c7cec4
Define the supported public runtime API
TimeLordRaps Aug 29, 2026
002ff24
Remove the unreproducible SimulacraBench rehearsal
TimeLordRaps Aug 29, 2026
a19bf4e
Professionalize the public architecture and controls
TimeLordRaps Aug 29, 2026
4ceb604
Build reviewable documentation and API references
TimeLordRaps Aug 29, 2026
7d253c9
Harden the VSTD 1.2.0 release boundary
TimeLordRaps Aug 29, 2026
79ae7ef
Restore executable proof entrypoints
TimeLordRaps Aug 29, 2026
70706ec
feat: implement evidence-bound assurance mechanisms
TimeLordRaps Aug 29, 2026
ca2b974
docs: present executable assurance architecture
TimeLordRaps Aug 29, 2026
2eba5bd
fix: stabilize enum reference text on Python 3.10
TimeLordRaps Aug 29, 2026
24bdba9
Bind TRUST dependencies and witness independence
TimeLordRaps Aug 29, 2026
8893ff6
Bind deviations and replay assurance
TimeLordRaps Aug 29, 2026
31810f6
Enforce strict portable receipt boundaries
TimeLordRaps Aug 29, 2026
c7a0281
Bind portable semantics and preserve frozen readers
TimeLordRaps Aug 29, 2026
3cb5435
fix(vstd5): bind bundles to admitted claim identity
TimeLordRaps Aug 29, 2026
5d0e9a6
docs(time): record GUILT composition contradiction
TimeLordRaps Aug 30, 2026
5eb38f3
fix(assurance): compose GUILT from bound components
TimeLordRaps Aug 30, 2026
11f243c
docs(time): record thaw-lineage verification contradiction
TimeLordRaps Aug 30, 2026
3f98446
fix(artifact-control): verify thaw lineage against sealed parent
TimeLordRaps Aug 30, 2026
19e00bd
fix(artifact-control): preserve descendant symlink identity
TimeLordRaps Aug 30, 2026
6b8fe41
fix(artifact-control): preserve lexical creation paths
TimeLordRaps Aug 30, 2026
f2c7438
docs(time): record linked bundle-member contradiction
TimeLordRaps Aug 30, 2026
b6d9764
fix(artifact-control): reject linked internal bundle members
TimeLordRaps Aug 30, 2026
e9d2b13
test(vstd5): pin claim identity in entry digest
TimeLordRaps Aug 31, 2026
1159839
fix(zizk): bind recorded proof to tracked image
TimeLordRaps Aug 31, 2026
833b8ea
fix(docs): preserve formatted link labels
TimeLordRaps Sep 1, 2026
e31bd77
fix(release): require immutable publication
TimeLordRaps Sep 1, 2026
dbd94c6
fix(docs): preserve procedure numbering
TimeLordRaps Sep 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,5 @@
*.py text eol=lf
*.toml text eol=lf
*.yml text eol=lf
*.cose binary
*.msgpack binary
4 changes: 2 additions & 2 deletions .github/ISSUE_TEMPLATE/implementation-report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ labels: ["implementation", "interoperability"]
body:
- type: markdown
attributes:
value: An implementation report is evidence of an attempt, not endorsement, adoption, certification, or conformance unless the stated tests establish that bounded result.
value: An implementation report for the Verifier Standard (VSTD) is evidence of an attempt, not endorsement, adoption, certification, or conformance unless the stated tests establish that bounded result.
- type: input
id: implementation
attributes:
Expand All @@ -17,7 +17,7 @@ body:
id: coordinate
attributes:
label: VSTD coordinate
description: Release, layer, wire identifier, and supported profile.
description: Release, numbered profile or closure coordinate, serialized receipt identifier, and supported receipt or application profile.
validations:
required: true
- type: textarea
Expand Down
6 changes: 3 additions & 3 deletions .github/ISSUE_TEMPLATE/specification-ambiguity.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,13 @@ labels: ["specification", "needs-triage"]
body:
- type: markdown
attributes:
value: Do not include secrets or vulnerability details. Use private vulnerability reporting for security-sensitive findings.
value: Report ambiguity in the Verifier Standard (VSTD) without including secrets or vulnerability details. Use private vulnerability reporting for security-sensitive findings.
- type: input
id: coordinate
attributes:
label: Exact coordinate
description: File, section, schema field, layer, and release or commit.
placeholder: standard/VSTD-4.md section 2.10 at v1.0.1
description: File, section, schema field, numbered profile or closure coordinate, and release or commit.
placeholder: standard/VSTD-4.md section X at release or commit Y
validations:
required: true
- type: textarea
Expand Down
7 changes: 5 additions & 2 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
## Coordinate

- VSTD layer/profile:
> **Acronyms:** Verifier Standard (VSTD).

- VSTD numbered profile or closure coordinate:
- Repository release or target commit:
- Claim, schema, or implementation seam:

Expand All @@ -13,7 +15,7 @@

## Consequences

- Compatibility and frozen-wire impact:
- Serialized-format and compatibility impact:
- Trust roots, unknowns, residuals, and horizons:
- Downstream documents, schemas, examples, and receipts reviewed:

Expand All @@ -23,3 +25,4 @@
- [ ] I did not strengthen a claim without stronger evidence.
- [ ] I did not include secrets, private data, or proprietary operational material.
- [ ] Normative text, machine-readable surfaces, examples, and tests agree.
- [ ] README maturity, claims guidance, generated reference, and Pages status still agree.
7 changes: 7 additions & 0 deletions .github/external-links-allowlist.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# One exact URL or trailing-* prefix and a tab-separated reason per line.
# Entries are limited to publishers that reject this audit's automated request.
https://doi.org/10.1145/263699.263712 Publisher returns HTTP 403 to automated probes.
https://journals.ametsoc.org/view/journals/mwre/78/1/1520-0493_1950_078_0001_vofeit_2_0_co_2.xml Publisher returns HTTP 403 to automated probes.
https://onlinelibrary.wiley.com/doi/abs/10.1111/j.1430-9134.2001.00173.x Publisher returns HTTP 403 to automated probes.
https://rss.onlinelibrary.wiley.com/doi/10.1111/j.2517-6161.1952.tb00104.x Publisher returns HTTP 403 to automated probes.
https://www.sciencedirect.com/science/article/pii/S1574013710000560 Publisher returns HTTP 400 to automated probes.
109 changes: 99 additions & 10 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
name: conformance
name: repository-checks

on:
push:
branches: [main]
tags: ["v*"]
pull_request:

permissions:
Expand All @@ -22,6 +24,29 @@ jobs:
- run: python -m pip install ".[test]"
- run: python -m pytest -q

coverage:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- run: python -m pip install ".[test]"
- name: Record bounded branch-coverage evidence
run: |
python -m coverage run --branch --source=src/verifier -m pytest -q
python -m coverage report --show-missing --skip-covered | tee -a "$GITHUB_STEP_SUMMARY"
python -m coverage json --pretty-print -o coverage.json
python -m coverage xml -o coverage.xml
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: branch-coverage-python-3.12
path: |
coverage.json
coverage.xml
if-no-files-found: error
retention-days: 14

stdlib-smoke:
runs-on: ubuntu-latest
strategy:
Expand All @@ -35,6 +60,32 @@ jobs:
python-version: ${{ matrix.python-version }}
- run: PYTHONPATH=src python -S -c "import verifier; from verifier.core.run import load_manifest; print(verifier.__version__)"

scitt-crypto:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- run: python -m pip install ".[test,scitt]"
- name: Require the real SCITT/COSE statement and receipt path
run: |
python -c "import cbor2, cryptography, scitt_cose"
python -m pytest -q tests/test_scitt_crypto_example.py

artifact-seal:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- run: python -m pip install ".[test,seal]"
- name: Require exact-byte freeze and finite self-closing seal behavior
run: |
python -c "import cryptography"
python -m pytest -q tests/test_artifact_control.py

release-integrity:
runs-on: ${{ matrix.os }}
strategy:
Expand All @@ -58,7 +109,7 @@ jobs:
shell: bash
- run: python -m twine check dist/release-integrity/*.whl dist/release-integrity/*.tar.gz
shell: bash
- run: python scripts/check_release_boundary.py dist/release-integrity/*.zip dist/release-integrity/*.whl dist/release-integrity/*.tar.gz
- run: python scripts/check_release_boundary.py dist/release-integrity/*.zip dist/release-integrity/*.whl dist/release-integrity/*.tar.gz dist/release-integrity/*.manifest.json dist/release-integrity/*.cdx.json
shell: bash
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
Expand Down Expand Up @@ -96,12 +147,21 @@ jobs:
- run: python -m pip wheel --no-cache-dir --no-deps --wheel-dir dist .
- run: python -m venv /tmp/vstd-wheel
- run: /tmp/vstd-wheel/bin/python -m pip install --no-deps dist/*.whl
- run: /tmp/vstd-wheel/bin/vstd demo --json
- run: /tmp/vstd-wheel/bin/vstd plan examples/generic_run/manifest.json --json
- run: /tmp/vstd-wheel/bin/vstd run examples/generic_run/manifest.json --output /tmp/vstd-receipt
- run: /tmp/vstd-wheel/bin/vstd validate /tmp/vstd-receipt
- run: /tmp/vstd-wheel/bin/vstd reproduce /tmp/vstd-receipt --rerun
- run: /tmp/vstd-wheel/bin/verifier demo --scenario honest-unknown --json
- name: Exercise the installed wheel outside the source checkout
run: |
cd /tmp
/tmp/vstd-wheel/bin/vstd demo --json
/tmp/vstd-wheel/bin/vstd plan "$GITHUB_WORKSPACE/examples/generic_run/manifest.json" --json
/tmp/vstd-wheel/bin/vstd run "$GITHUB_WORKSPACE/examples/generic_run/manifest.json" --output /tmp/vstd-receipt
/tmp/vstd-wheel/bin/vstd validate /tmp/vstd-receipt
/tmp/vstd-wheel/bin/vstd reproduce /tmp/vstd-receipt --rerun
/tmp/vstd-wheel/bin/verifier demo --scenario honest-unknown --json
/tmp/vstd-wheel/bin/python -c 'import json; from pathlib import Path; from verifier.core.checker import IndependentAuditor; receipt=json.loads(Path("/tmp/vstd-receipt/receipt.json").read_text()); hashes=(receipt["assessment_context"]["verifier"]["specification_hash"], IndependentAuditor.verifier_descriptor().specification_hash); assert all(value.startswith("sha256:") for value in hashes), hashes'
printf 'installed-wheel-artifact\n' > /tmp/vstd-wheel-artifact.bin
/tmp/vstd-wheel/bin/vstd artifact freeze /tmp/vstd-wheel-artifact.bin /tmp/vstd-wheel-artifact --json
/tmp/vstd-wheel/bin/vstd artifact verify /tmp/vstd-wheel-artifact --freeze-only --json
/tmp/vstd-wheel/bin/python -c 'import inspect; from verifier import thawed_artifact_status; assert "parent_bundle" in inspect.signature(thawed_artifact_status).parameters'
/tmp/vstd-wheel/bin/vstd artifact status --help | grep -- --parent-bundle

presentation:
runs-on: ubuntu-latest
Expand All @@ -111,25 +171,54 @@ jobs:
with:
python-version: "3.12"
- run: python scripts/check_presentation.py
- run: python scripts/build_pages.py --output _site
- run: python scripts/build_pages.py --output _site --source-ref "$GITHUB_SHA"
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: pages-preview-${{ github.sha }}
path: _site
if-no-files-found: error
retention-days: 14

codeql:
name: CodeQL (Python)
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: python
queries: security-extended
- uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9

# This identifier remains stable because main branch protection requires it.
conformance-gate:
if: always()
needs: [base, stdlib-smoke, release-integrity, release-reproducibility, installed-wheel-smoke, presentation]
needs: [base, coverage, stdlib-smoke, scitt-crypto, artifact-seal, release-integrity, release-reproducibility, installed-wheel-smoke, presentation, codeql]
runs-on: ubuntu-latest
steps:
- name: Require every declared support and artifact check
env:
BASE: ${{ needs.base.result }}
COVERAGE: ${{ needs.coverage.result }}
STDLIB: ${{ needs.stdlib-smoke.result }}
SCITT: ${{ needs.scitt-crypto.result }}
ARTIFACT_SEAL: ${{ needs.artifact-seal.result }}
RELEASE: ${{ needs.release-integrity.result }}
REPRODUCIBLE: ${{ needs.release-reproducibility.result }}
WHEEL: ${{ needs.installed-wheel-smoke.result }}
PRESENTATION: ${{ needs.presentation.result }}
CODEQL: ${{ needs.codeql.result }}
run: |
test "$BASE" = success
test "$COVERAGE" = success
test "$STDLIB" = success
test "$SCITT" = success
test "$ARTIFACT_SEAL" = success
test "$RELEASE" = success
test "$REPRODUCIBLE" = success
test "$WHEEL" = success
test "$PRESENTATION" = success
test "$CODEQL" = success
27 changes: 27 additions & 0 deletions .github/workflows/external-links.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
name: external-link-audit

on:
schedule:
- cron: "23 11 * * 2"
workflow_dispatch:

permissions:
contents: read

jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Audit external documentation links with retry
run: python scripts/check_external_links.py --retries 2 --workers 8 --report external-links.json
- if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: external-link-audit-${{ github.run_id }}
path: external-links.json
if-no-files-found: error
retention-days: 14
2 changes: 1 addition & 1 deletion .github/workflows/pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5.0.0
- name: Assemble site and canonical schema routes
run: python scripts/build_pages.py --output _site
run: python scripts/build_pages.py --output _site --source-ref "$GITHUB_SHA"
- uses: actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b # v4.0.0
with:
path: _site
Expand Down
34 changes: 29 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@ jobs:
with:
python-version: "3.12"

- name: Require TIME CLEAR in the exact tagged checkout
run: python scripts/check_time_status.py

- name: Require a protected-main commit and matching package version
env:
GH_TOKEN: ${{ github.token }}
Expand All @@ -36,6 +39,18 @@ jobs:
test "$VERSION" = "$PACKAGE_VERSION"
test "$(gh api "repos/$GITHUB_REPOSITORY/commits/$GITHUB_SHA/check-runs" --jq '[.check_runs[] | select(.name == "conformance-gate" and .conclusion == "success")] | length')" -ge 1

- name: Require immutable GitHub releases before publication
env:
GH_TOKEN: ${{ github.token }}
run: |
test "$(gh api \
-H "X-GitHub-Api-Version: 2026-03-10" \
"repos/$GITHUB_REPOSITORY/immutable-releases" \
--jq '.enabled')" = true

- name: Require finalized release metadata in the exact tagged checkout
run: python scripts/check_release_metadata.py --version "${GITHUB_REF_NAME#v}"

- name: Re-run conformance on the tagged checkout
run: |
python -m pip install ".[test,release]"
Expand All @@ -52,15 +67,17 @@ jobs:
- name: Smoke-test the exact wheel
run: |
python -m twine check dist/*.whl dist/*.tar.gz
python scripts/check_release_boundary.py dist/*.zip dist/*.whl dist/*.tar.gz
python scripts/check_release_boundary.py dist/*.zip dist/*.whl dist/*.tar.gz dist/*.manifest.json dist/*.cdx.json
python -m venv /tmp/vstd-release-wheel
/tmp/vstd-release-wheel/bin/python -m pip install --no-deps dist/*.whl
cd /tmp
/tmp/vstd-release-wheel/bin/vstd demo --json
/tmp/vstd-release-wheel/bin/vstd plan examples/generic_run/manifest.json --json
/tmp/vstd-release-wheel/bin/vstd run examples/generic_run/manifest.json --output /tmp/vstd-release-receipt
/tmp/vstd-release-wheel/bin/vstd plan "$GITHUB_WORKSPACE/examples/generic_run/manifest.json" --json
/tmp/vstd-release-wheel/bin/vstd run "$GITHUB_WORKSPACE/examples/generic_run/manifest.json" --output /tmp/vstd-release-receipt
/tmp/vstd-release-wheel/bin/vstd validate /tmp/vstd-release-receipt
/tmp/vstd-release-wheel/bin/vstd reproduce /tmp/vstd-release-receipt --rerun
/tmp/vstd-release-wheel/bin/vstd hardware list --json >/dev/null
/tmp/vstd-release-wheel/bin/python -c 'import json; from pathlib import Path; from verifier.core.checker import IndependentAuditor; receipt=json.loads(Path("/tmp/vstd-release-receipt/receipt.json").read_text()); hashes=(receipt["assessment_context"]["verifier"]["specification_hash"], IndependentAuditor.verifier_descriptor().specification_hash); assert all(value.startswith("sha256:") for value in hashes), hashes'

- name: Attest every published artifact
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
Expand All @@ -69,6 +86,7 @@ jobs:
dist/*.zip
dist/*.whl
dist/*.tar.gz
dist/*.cdx.json
dist/*.manifest.json

- name: Write bounded release notes
Expand Down Expand Up @@ -100,17 +118,23 @@ jobs:
' CHANGELOG.md
} > release-notes.md

- name: Publish only the tested and attested artifacts
- name: Assemble a complete draft release
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release create "$GITHUB_REF_NAME" \
dist/*.zip dist/*.whl dist/*.tar.gz dist/*.manifest.json \
dist/*.zip dist/*.whl dist/*.tar.gz dist/*.cdx.json dist/*.manifest.json \
--repo "$GITHUB_REPOSITORY" \
--verify-tag \
--draft \
--title "VSTD ${GITHUB_REF_NAME}" \
--notes-file release-notes.md

- name: Publish the complete draft atomically
env:
GH_TOKEN: ${{ github.token }}
run: gh release edit "$GITHUB_REF_NAME" --repo "$GITHUB_REPOSITORY" --draft=false

- name: Stage only the Python distributions for PyPI
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
Expand Down
9 changes: 5 additions & 4 deletions .zenodo.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"name": "Roost, Tyler"
}
],
"description": "A two-axis verification ladder and reference implementation for bounded claims, provenance graphs, substrate accountability, grounded refutation certificates, and computed verification depth.",
"description": "Release-candidate metadata for a verification-domain language and Python reference implementation that packages bounded computational claims with explicit evidence, checking mechanisms, limits, refutation conditions, provenance, and reproducibility information. It does not replace native domain verifiers or strengthen their results. Publication metadata is assigned only after the release exists.",
"keywords": [
"verification",
"provenance",
Expand All @@ -13,10 +13,11 @@
"software supply chain",
"accelerator accountability",
"refutability",
"proof certificates"
"proof certificates",
"bounded claims"
],
"license": "Apache-2.0",
"title": "VSTD: A Two-Axis Ladder for Refutable Verification",
"version": "1.1.3",
"title": "Verifier Standard (VSTD): Bounded, Refutable Evidence for Computational Claims",
"version": "1.2.0",
"upload_type": "software"
}
Loading
Loading