lean-transparency-log/receipts/dalek-ed25519-verified.receipt.json

61 lines
13 KiB
JSON
Raw Permalink Normal View History

{
"hash_algorithm": "RFC9162_SHA256",
"inclusion_proof": [
"8cb258d657f1fd00baaa9e0091e26c316cb69b591cb249a9543f51cade57c50a",
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"d67b2bcdec474671f1b05528a4cbdb2a070254ad74e0e865d1f17862c69634b0",
"d564975516d79d8fc6b0c17db318223ae86a918f050ba508c5f4134951b7b6f9",
"9a15b9a1379edc07ae43d3fc61b52dc4446b56770bff6538e88ed98746ac2283",
"de919cde8d009748e525def5a1dfd5516f2fd134546a7cf67afda982416ac547"
],
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"leaf_hash": "fd7a2579b37fe9a2a8e49ee52914d0525b09e7d034762c5c176cea31aa321718",
"leaf_index": 13,
"log_id": "205e4c389cb143e08f0d2d58bdc8e425e47e3cbe7f2108cc58bbe835d2cc41d7",
"schema_version": 1,
"sth": {
"hash_algorithm": "RFC9162_SHA256",
"log_id": "205e4c389cb143e08f0d2d58bdc8e425e47e3cbe7f2108cc58bbe835d2cc41d7",
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"root_hash": "7ee239406890cf4ad59cc83ac3faa3d5cc48b29202159ee8c25bffd9737d32d8",
"schema_version": 1,
"signatures": {
"ed25519": {
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"payload_digest_sha256": "17b3343429fea975478e490c4e1bee91af777478246da8f7020411825a576fcf",
"public_key_fingerprint_sha256": "874c8a008a607021528b2493fa1caf059f9d5c123d29193dfabc09a6d1e7a56a",
"scheme": "openssl-ed25519",
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"signature_base64": "22sH3zEgUerjNeXAPIH/TBnnfEawDF+2mFUK20aEyXZ1y8yAayS+NqTOnSTKnfsLzEM8wSBq0At6xQB+cLaFAA==",
"signing_backend": "verified-dalek-serial",
"signing_provenance": {
"self_inclusion": "verified",
"signing_backend": "verified-dalek-serial",
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"signing_library_certificates_proven": "44/44",
"signing_library_component": "dalek-ed25519-verified",
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"signing_library_leaf_index": 13,
"signing_library_source_commit": "aa0f6abc327ba2a54a534b21608ca8996cf73682"
},
"status": "signed"
},
"ml_dsa": {
"reason": "A backend appears available, but no ML-DSA signing key was configured for this log.",
"scheme": "ML-DSA-65",
"standard": "FIPS 204",
"status": "not_configured"
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
},
"slh_dsa": {
"mode": "deterministic",
"parameter_set": "SLH-DSA-SHA2-128s",
"payload_digest_sha256": "17b3343429fea975478e490c4e1bee91af777478246da8f7020411825a576fcf",
"public_key_fingerprint_sha256": "d92a8b6069f6ccb7f953a6fd35f34a11877549d431dde782491e04adf0b5191a",
"scheme": "openssl-slh-dsa-sha2-128s",
"signature_base64": "cZJWXOGbxHhIUkyenMvlEQzm/QO7WZXQTrt8L9fFwC54oVcCp7j1Iy+GKsLsPkpvcifjNDjVTlAMFzaRipKd1RY418TEnN3VBbU+r1WHkgrYdVHFw00jajknipYKN1xix+5qwyCKRDVu94Q7/ptdRoFyifVKjRSOi5w4rzCgWtVncxvWEkp/p2HTtwftgmwXP2dbEwUi5nUE9lMlKnpFalhR7lT1+tp022Dx7vfOHQaA/6mgOnBx0rr1p2p4zCXlrrxnCjehDxjBqDrAr95ssS3gvxUbOgiSsf7vDU/IK0/gK8AC3cFB14kheuit5aL56PkuMeZlMAc2gp1SmOJ4RQXR2hNlrOkJ6ZADrvIeS9ZlaFCLgHPKLKWES1WOAxC3dqWLO5q7CdBpw3rA6FhFJzVJuunu7v6He7np8kbHE9SxoQoAZnzJDh/8xqdZGiM9+riSplooJxQ0CFjXlL/ZXh1p8wVnL5bn7l4OpGJUQlt/ew7RfcnILOT5oNQ9DyFUvIPwbSt74/vL91Rjy6vSCgmDS2/Q1aFUJ7BMTvkkcaWdd39TQ4F6e99ZN04bAfdDFAmg1lmvWpxw0pjV+t5LetBnCahSgeSPm1DHlHeW7n7Ipf0VDLnDupjmFrLnEIy0MgU/c1rI5KPRdTxFu5EZP9IcMmqZ4/+3CZNhhSbRgw/DIpfAqpt5evPlsnPqqWJ7rXOSKAgX38yUP7I91iKmyzV7lLZBExPkIeWVvugoDQdCyeet0NP/iEbor8BT9DhOtBjPCHvaHhm8zuO0MiOUcPtZy9RIrBzgASVzbQuaxqAbGTQ6U1LqZmgWay7CNhVVNJ7W3oIcuNWkfay2nfFspKTBtRA1Apw9zCCv9XMNRWLwlpWqvCE+Bx38TzgFGypBApU2vHElOvBBs54AF8yuB/qWkQlsRW+Qc+4PXb80tplizeiqoI51gzH0A2ft7zvc0fIhiWntX7xxQ88xo4VRETT9DByMcBrfstUe485QmzgtH1HdyNbv+aDITCZoX9wSlHrzgNcAPNyU5qKZHrIOMv5pCDUZJ/r+41pDtcjajFDu+nPlv+riHqxVjBs3kZ0QsoPts3bxtmATzFmUQk93DhC3eHAiqfYC+R8qeDfcTjic8v6L/xDb5vOJkWpotFAOwK+CP+f5ErFIKwbNn5jMxg53Uc8WfRzJef2xhryVacSJ/65oILzFqp4NzpOP/S+1x2mQxiPMv9F/TvsPYPCFdUMlzjC2NZgZ69/0ptocmpEvuUBUd4zb34UvZ0gp4SXjgMgVgmYgkT1jjU2fz6jhQIuENtwzJVWLgdHa4ZWAygfPnVcYm2NLPE9kmlxxGMBhXJeqDTDTtkTEYYfI8Nx/O2Kb0GvXx2MyDOUy3kLG1SZn7dxPK8/Tllv0EnrEfCZ0fuMgsHCJbAnuCkrVMk2Y9b03G8wSks51TvbbieOcNgTr2KXCneezhOVj8S2JpcfB/6bR8ECkXirY/QVZJaY75YrKWEIE40n01k36LvWPBhrsDkIBgWPzVoAfm8zfknv4pLHDrTmujD1oLOdKI/fmjspbDqJe2InpnxM10LRNAa6zQ1qunwqbuIiIZMfqFw28E90O2X4/7HH9oAEPpkkK50Ch6Jbid5hd1DC1iSOyFtA6Go2yxHqVH5lDTwWigGCe+0ifX9rfaEAQ+5D4sYn+56jkHqKm07TgaPK/Mu3iCPcoJNVF4mdtDhFnlVwDWQGuABMYUEYsBaf8eWsBsN7UFaoim3JyS3MjTbFIK8gQ6sl+j/eiewBCzgzh4HNMV+UQzHEsAXazswMdGhc4KJZSRU7HaDDNB9FzJjvg5LH9EUuOltWm5Xjebk0xEM6haKWdvGdE98XkKJcjyslkiBbRmzDQ6lzGWGKp8xBM4WxPk337szvIr8RIC65f9sB+ZiR4ofJ7UyDtw0+UihW5CeXoY7OfHCBDRN6m8Ru4Bit3m9gFiOY9+bVMfwd+M5ucI3rlTA2MsTSFj5Z2vtY9m2DHNa1vWe/8nAwtKvQSTOLeAWBW70WvN2zq4I8RN7wTgr+jMOjg/KWdRqkmZJPHShSUqrX5BEyrEjrJZE4qwXPQQ99iUmFhKYvtsIkqsWh5/iye6+W0OmOIFR/tjx4BozMKF9WRko60NetlSN7Q+FlfvbG4n5wJs9UbQYKZYziwO6ybD7PtcAoHhRsnvV5Jw2lFJa3am/yOJAGMgTJhLLxw7pIGhRxq2AZMoVyz0XkTu2Fx96yRf2ROfV2uMUDqaKTEsGbUG6pMGhb2HFwk/RsnknXPV3Jk29WOtJgO0VJTRBTXkGGwu4NQ076TXyN6A/Oz6rBCJ8Fa94BRN5tfwJLs/GCG+CoE+QjKPbl+Q2Be/HS8AWAzY6z5H7Dju923CPX25zFFzO53hQcjLFuVL3gDKrOGLsCEFYmYQtidAGC0N57aGceCkOYOxGYqzeB7cz3re3PSGQM63ccjbLyxIomJ9fACkSx67jEnu9hZDT4OkLwoLzZRQt+J/E2qzCFV7TvxQCWqVexAo9hoHm6WDH9EhXf5vUiHMruxj9gRxgu7id+iAttOd+BKaYDznMC9MhFBC6iBSAqUVQgvhHfldNxXMGfCapXTFy+eYxP2YF3IwPLVKZAnL4ev9tHzuUkcQwC3SXKtuQN2Ku2FzAHir8LeWGNLHwV+IaAXSgqELbVKcwcuiX+cIeig0Lj4vfGe5mwZFGf7R9QU1tRliiep8zu0bEDn759+OA9eIGvfwSJdfcVMy3KtgfMzUETKpQJpkvhadCZs68LQWVx47H6mJwbmNL1ly2sD+MAUvfsDgph09Uib59t4UKpQGdiI6AjvK3LsEvPAgCUNpPSSVtSEDRu1p2UMXW6p/yGnhygNp7ikUnZ8LjWOI0ux28kweTyCb+GEPBBb5hhqpWUsBpLtXtWDkBjxCWEiU6MlJnMHu4DXtSMYRF3n+PYiaCa+RWlvHGF0uS/PCeZHfbOuOhAlp3ptCw16DwSXyjTOMOoeGwx4+yy3qp18htLyFXVwgritx+4EDeRSM3kzfLSM7DhERQwVCkkEeslE7t0MbNvMK906sEAit8brpb+2D36jmtZdETw8kkkDPTHegs9zTveFTrlYyqa5M9jF7O2eW+lCg4bnZfXcY2gldTzvbmWRki06BdbYPOrhEnA8i2ToQtNf5AmfeuijlMA3UzB5t229ib6iSghM75MA5w/e+VJawKIr9qehZ+lh1Wz7ducYOF8rT6Q6XbVW0vCs3Vr4Q4T2IniMbYlraVM2+SKBgVb9XnFP50iUfxEWc8g8Urdj0ImhAumx9IxVz2vBJUlbvcyfHSc9KneIzM5Q9DpbRFztPhAKOTDRpfAbjeOwTCcQ2cjbCnxRnDKO/y0Obmu7wJnDRAYGSHqpJdtEPGrvBG0L1Nl4P+uS5HrYkCO4D0JVUrrzTKvfdTaz38qjdkU6FJvB0XNRDs0jHpBKhbMd5Lu0N7EYyVmLX599IP2XTqpds9T2Zey7DZhaXmrAxEWZzvU0kRQawp3nBfAZIEY5deuWAPAP9GkGYvsYjvUfI7zmSC8ArNt3skZz9H+dAQ73icpGwTCPdJ/qTs34+Vquee4+4HqVQMDZjczcUEJNMm0NpX4uzZ4lwOnDrVk82LVVaMtYGlBVbw2Ivz2YrwPQOtIV1Izo7K9wxxdwGSbY2E6hGVKgy9tN5knAEuWVq5IEUmAAmWwlgpiBHOy7qRlADp4p5qWuVkzIS+dQDTKxI+EtK6O4DdTWGVrWnY26uLGwnde5jWSedQfpoIMeShfMs5G9f41Wa+UDZsTfopPnIlM8VVMrflUe0afqrWqPY52sJS9W9NVfu4QDJMIrrKT8ZhTr+ATbIw0FZpSCLI9UQjLuiK0ssXsW14ocYWa7zWnHzdqxssVzv7IMD7K3vmV94VHgcJEIO5eFtxNeX8GiymvVEQH6VTPCXRqZWWDoiEYasvt6Ww9/77jH/sXZLj+joNKidHchOY6H2l119w+Je7gD8xk8N57IKqVKYsscvIdVZJBuGDEYlwwaFLOqaY6kIOZ/z8VGR1xieiLlehaz+R5GG7
"signing_backend": "openssl",
"standard": "FIPS 205",
"status": "signed"
}
},
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"timestamp": "2026-08-07T15:10:52Z",
"tree_size": 19,
"type": "pacta.transparency.signed_tree_head.v1"
},
entries 13-18: re-attest the estate at 44 certs/fork + first SLH-DSA leaf; heads now dual-signed Six new leaves (tree 13 -> 19, root 7ee23940…): [13-16] dalek/anza/risc0/betrusted-ed25519-verified — re-attested at 44 certificates each (27 main + 4 apex + 13 scalar; the leaf 8-11 generation recorded 16). The delta is the P0-P2 hardening campaign: scalar statements bound, kernel-side axiom gate, driver surface with cones, declaration coverage both directions, the accounting identity. [17] ltl-accumulator-verified — 61 certificates; the log again carries proofs of its own Merkle machinery, at the hardened state. [18] fips205-slhdsa-verified — FIRST post-quantum leaf: 11 certificates over the SLH-DSA-SHA2-128s verify path, apex fips205.slh_verify_128s_accepts_iff. Heads from tree 14 on carry a second, ADDITIVE signature: SLH-DSA-SHA2-128s (FIPS 205), deterministic, over the same payload as the Ed25519 signature. provider.slhdsa.pub ships beside the Ed25519 key. Ed25519 remains the signature consumers must check; verify.py now judges slh_dsa fail-closed where present (INVALID/WRONG-KEY/NO-PUBKEY fail; older heads report ABSENT, allowed; pre-3.5 OpenSSL degrades loudly, never silently). The ml_dsa slot stays not_configured — truthfully. Honesty, unchanged by any of it: the certificates cover VERIFICATION paths of the extracted Lean models; no signing operation is proven for any algorithm; leaves are Ed25519-signed at issuance only. Append-only law checked byte-for-byte before this commit: entries 000000-000012 identical, the six prior heads an exact prefix of the history. verify.py --all: RESULT OK [full]. verify_selftest.py: GREEN (13 cases). Quorum gate: 5-way Ed25519 + 2-way SLH-DSA (incl. the verifier built from the pinned proven source), all accept, all reject corruption. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-07 15:11:59 +00:00
"tree_size": 19,
"type": "pacta.transparency.receipt.v1"
}