fips205-slhdsa-verified/verification
mrwulf c80c2bba5b provenance: name the pin the machine actually enforces
Round-8 review (GPT-5.6, register key `slh-provenance-contradictory`, HIGH),
raised in round 7 and unfixed since.

The machine-enforced subject is unambiguous and appears in PROVENANCE.json and
extract.sh:

    fips205-source @ a3ce8e8644fe302019ed7ae271912333f1476de4

It appeared in ZERO markdown files. The prose instead named three other
revisions across four documents — README `797b4ef`, TRUSTED-BASE `3153988`,
ATTESTATION-BASIS `c945821` — so a reader could not tell which Rust the proofs
are about. Subject identity is part of the attestation object: a proof about a
model is not evidence for an unspecified source revision.

  README.md            current snapshot head -> a3ce8e8, with the lineage
                       bea1051 -> 797b4ef -> a3ce8e8 stated explicitly and
                       matching PROVENANCE.json's own upstream_deviation text
  TRUSTED-BASE.md      current snapshot head -> a3ce8e8
  ATTESTATION-BASIS.md subject -> a3ce8e8, AND the "four model_integrity_sha256
                       hashes" claim corrected: only TWO (Types.lean,
                       Funs.lean) are regenerated by extract.sh; the two
                       *External.lean files are hand-maintained and separately
                       byte-pinned. Stating four invites a reproducer to expect
                       extraction to produce files it never touches.

RECORDED-RUN.md IS DELIBERATELY NOT REWRITTEN. It records a run that really
happened on 2026-07-24 against `797b4ef`. Editing the identity of a past run to
match today's pin would falsify the record rather than correct it. It now
carries a header saying so and naming the current pin.

Independent extraction remains UNVERIFIED — no third party has regenerated the
Lean from the Rust. That is unchanged by this commit and is stated where a
reader will meet it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-03 15:28:57 +02:00
..
gen/SlhVerify TypesExternal: correct a header that described a type the file no longer contains 2026-07-28 10:16:57 +02:00
Proofs review round 5: bind the policy, the specification bodies, and the harness 2026-07-27 22:57:46 +02:00
AUDIT-MANIFEST.txt review round 6: pin the auditor, purge every olean, pin gen/ as a set 2026-07-28 09:22:12 +02:00
check-selftest.sh round 8: self-deriving harness pins, honest extraction guarantees, attestation basis 2026-07-28 14:40:39 +02:00
check.sh round 8: self-deriving harness pins, honest extraction guarantees, attestation basis 2026-07-28 14:40:39 +02:00
drill.sh drill: the post-flight drill becomes a button (drill.sh) 2026-07-23 15:36:00 +02:00
extract.sh re-pin source @ a3ce8e8 (extraction-script honesty fixes) and rotate extract.sh's harness pin 2026-07-28 14:42:46 +02:00
lean-guard lean-guard: surface clamp/kill diagnostics on stderr (operator incident 2026-07-24) 2026-07-24 21:37:05 +02:00
PROVENANCE.json re-pin source @ a3ce8e8 (extraction-script honesty fixes) and rotate extract.sh's harness pin 2026-07-28 14:42:46 +02:00
RECORDED-RUN.md provenance: name the pin the machine actually enforces 2026-08-03 15:28:57 +02:00