lean-transparency-log/entries/ltl-accumulator-verified.attestation.json

968 lines
22 KiB
JSON
Raw Permalink Normal View History

{
"certificates": [
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.ConsRec",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [],
"name": "LTLAcc.Hash",
"observed_axioms": [],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"LTLAcc.sha256"
],
"name": "LTLAcc.IsCollision",
"observed_axioms": [
"LTLAcc.sha256"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.MTH",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.MTH_single",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.MTH_split",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.Path",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.Root",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.Root_left",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.Root_one",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.Root_one_cons",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.Root_right",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.acceptCons",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.acceptCons_sound",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.acceptIncl",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.acceptIncl_complete",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.acceptIncl_sound",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.consRecBinding",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"Quot.sound"
],
"name": "LTLAcc.consRec_base_false_eq",
"observed_axioms": [
"propext",
"Classical.choice",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext"
],
"name": "LTLAcc.consRec_base_true_eq",
"observed_axioms": [
"propext"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.consRec_some_le",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [],
"name": "LTLAcc.domsep",
"observed_axioms": [],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext"
],
"name": "LTLAcc.eq_dropLast_append_of_getLast?",
"observed_axioms": [
"propext"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"Quot.sound"
],
"name": "LTLAcc.exists_singleton_of_length_one",
"observed_axioms": [
"propext",
"Classical.choice",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractCons",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractConsNode",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractCons_correct",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractCons_correct_paper",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractCons_nonvacuous",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractIncl",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractIncl_correct",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractIncl_nonvacuous",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractMTH",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractMTH_correct",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.extractMTH_nonvacuous",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.fork_distinct",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.getD_drop",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.getD_take",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"LTLAcc.sha256"
],
"name": "LTLAcc.hleaf",
"observed_axioms": [
"LTLAcc.sha256"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"LTLAcc.sha256"
],
"name": "LTLAcc.hnode",
"observed_axioms": [
"LTLAcc.sha256"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext"
],
"name": "LTLAcc.hnode_preimage_inj",
"observed_axioms": [
"propext"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.incl_complete",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [],
"name": "LTLAcc.instDecidableEqHash",
"observed_axioms": [],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext"
],
"name": "LTLAcc.instInhabitedHash",
"observed_axioms": [
"propext"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.kbelow",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.kbelow_eq_of_pow2_between",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.kbelow_lt",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.kbelow_pos",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.kbelow_pow2",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.kbelow_prefix_eq",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.le_two_kbelow",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.pinAccept",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.pinAccept_monotone",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.pinExtract",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.pin_prefix_correct",
"observed_axioms": [
"propext",
"Classical.choice",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"name": "LTLAcc.pin_prefix_nonvacuous",
"observed_axioms": [
"propext",
"LTLAcc.sha256",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.pow2_exp_unique",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext"
],
"name": "LTLAcc.take_all",
"observed_axioms": [
"propext"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [],
"name": "LTLAcc.take_append_drop",
"observed_axioms": [],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Classical.choice",
"Quot.sound"
],
"name": "LTLAcc.take_drop_prefix",
"observed_axioms": [
"propext",
"Classical.choice",
"Quot.sound"
],
"status": "proven"
},
{
"axiom_status": "clean",
"diagnostics": [],
"expected_axioms": [
"propext",
"Quot.sound"
],
"name": "LTLAcc.take_take_le",
"observed_axioms": [
"propext",
"Quot.sound"
],
"status": "proven"
}
],
"environment": {
"env_script": "~/aeneas-toolchain/env.sh",
"lake_version": "Lake version 5.0.0-src+3dc1a08 (Lean version 4.30.0-rc2)",
"lean_project_dir": "$AENEAS_HOME/backends/lean",
"lean_version": "Lean (version 4.30.0-rc2, x86_64-unknown-linux-gnu, commit 3dc1a088b6d2d8eafe25a7cd7ec7b58d731bd7cc, Release)"
},
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"issued_at": "2026-08-07T08:13:55Z",
"machine_protection": {
"lean_guard": "verification/lean-guard",
"note": "All Lean compiles route through the repo's lean-guard (memory cap, core pinning, timeout, single-flight lock) when configured."
},
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"provider": "local-provider",
"replay": {
"axiom_attempted": true,
"axiom_diagnostics": [],
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"axiom_log_path": "/tmp/claude-1000/-home-oho-GitClone-Claude-FormalVerification/371a28b5-864a-4953-a400-61066a13ba91/scratchpad/rehearsal/replay-logs/ltl-accumulator-verified/axiom-audit.log",
"axiom_ok": true,
"check_attempted": true,
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"check_log_path": "/tmp/claude-1000/-home-oho-GitClone-Claude-FormalVerification/371a28b5-864a-4953-a400-61066a13ba91/scratchpad/rehearsal/replay-logs/ltl-accumulator-verified/lean-check.log",
"check_ok": true,
"checked_files": 12,
"diagnostics": [],
"failed_files": []
},
"schema_version": 1,
"scope": {
"deployment_constraints": [
"Attestation scope: this corpus kernel-checks the listed theorems about the mechanized recursive accumulator model. Correspondence with the deployed inclusion verifier is supported by finite differential testing over the pinned families. The deployed consistency verifier is not extensionally equal to the model; applying the mechanized soundness result to the deployed consumer flow additionally relies on an unmechanized authentic-size/root invariant (KNOWN-GAPS 14/15)."
],
"exclusions": [
"SHA-256 collision resistance (the single opaque boundary axiom; soundness theorems CONSTRUCT collisions)",
"deployed-verifier extensional equality (KNOWN-GAPS 14/15 - lied-size divergence, one-sided; refinement invariant unmechanized)",
"signature/STH layer and evidence transferability (gap 4)",
"asymptotic cost claims (gap 9)"
],
"guarantees": []
},
"signature": {
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"payload_digest_sha256": "d6ce3db99a6d44ca1a46045b16cc9794e352933c5df851d31520f1f20e1cfa26",
"public_key_fingerprint_sha256": "874c8a008a607021528b2493fa1caf059f9d5c123d29193dfabc09a6d1e7a56a",
"scheme": "openssl-ed25519",
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"signature_base64": "LN1LG5onL49h9DM1xFyFHgPUrtcnJRia/KTFRgzKGV5gtJEz0bRi5aVdL7JdZKr+N3oU7CmRZoacZKd82fOXBg==",
"signing_backend": "verified-dalek-serial",
"status": "signed"
},
"subject": {
"component": "ltl-accumulator-verified",
"kind": "merkle_accumulator",
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"repo_commit": "2a886b6be9b6efd3b690932957d32f87d20cd274",
"repo_url": "https://github.com/saymrwulf/ltl-accumulator-verified.git",
"verification_dir": "verification",
"verified_backend": "rfc9162-sha256/lean-model"
}
}