ltl-accumulator-verified/verification/HARNESS.sha256

16 lines
1.3 KiB
Text
Raw Normal View History

verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
e7d422f0be9a9e6f5465058292e30c711d52856428da2b01c470a57ec181540c AUDIT-MANIFEST.txt
Round-7 F2: account for every constant the kernel sees THE DEFECT, demonstrated by a reviewer with a working payload. The driver surface is reported by an `#eval` inside Proofs/Inventory.lean. Anything declared AFTER that command is in the compiled object file but does not exist in the environment while the command runs, so the walk cannot see it. The reviewer appended def bait : Nat := 0 theorem bait.smuggled : forall n : Nat, n + 0 = n := ... re-pinned, and ran the button. It printed "no axiom, no claim", the statement digest was BYTE-IDENTICAL to the clean tree, and the run went green — while a theorem with a real axiom cone sat in the environment. In neither walk: not corpus, because an instrument is not corpus; not driver surface, because it post-dates the emitter. In no allowlist. Pinned by nothing. This repository also had no kernel-side scan at all. Its axiom gate was a source-text grep, evadable by a leading space — which its own selftest case 12 already exploited. THE FIX, ported from the ed25519 forks: · a kernel-side axiom-declaration gate that reads every compiled .olean via readModuleData. It sees what was actually stored, regardless of indentation, attributes, privacy, or where a declaration sits relative to any #eval. Membership self-derives from the manifest and the module count must match, so a deleted artifact cannot make the scan vacuous. · the ACCOUNTING IDENTITY, as set containment: every constant the kernel sees in corpus inventory union instrument surface The two walks read ENVIRONMENTS; the gate reads OBJECT FILES. What a walk cannot see because of where it sits in a file, the object file still holds. That asymmetry is the entire content of this fix. Compared as SETS deliberately. Counts cannot express the relation — an object file may hold two physical copies of one lazily-materialised equation lemma while an environment holds one constant per name — and arithmetic between those views misled the ed25519 version twice before it was stated as containment. PLACEMENT differs from the forks, for a reason worth recording: there the audit drivers are members of the compile manifest, so a gate beside the compile phase finds them. Here AxiomCheck is compiled by Phase 3 and Inventory by Phase 3b, so an earlier gate fails on a missing artifact — which it did, correctly, on the first port. It runs inside Phase 3b, because the instruments are exactly what it must see. VERIFIED with the reviewer's own payload, which previously went green: ACCOUNTING FAILED: the kernel holds constants that neither walk accounts for: bait bait.smuggled selftest_audit.sh: 14 attack cases -> 15. Note in the new case, because it cost two iterations: `theorem bait.smuggled : True := trivial` does NOT exercise this gate — Phase 1's stub audit greps for `: True :=` and catches it first. Real defence in depth, but the naive payload never reaches the gate under test, so the case uses the reviewer's original. Two residues fixed while adding it, both the same shape: a case that was last when written, leaving state the next case inherits. Case 13 restored AxiomCheck.lean but not its pin; case 9 left its rogue gen file. Fixed at the point of use so each case keeps testing what it tested before. Button green (234 declarations across 11 modules, all accounted for), 15/15 self-test green, ATTESTATION GREEN with fidelity.
2026-08-02 00:51:55 +00:00
857a92d50d44c5fe4db2bfdb4fc3a28f7b345b369414a140a66298fd6ff1b0fe check.sh
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
070147e2667053bd5d5e1174b969fc6c91bfcf15ded1a5bff57754e15f416885 fidelity/lean_defs.py
5d82462a002ac9fc782e95afe78b7719ba64b6410b5d2bfa620fe5317367dbf2 fidelity/run_fidelity.py
503babb3f4e6aff82ebd59e8752469ecd60fba440ed3b11b3f97c2b655fbd9bf gen/LTLAcc/HashExternal.lean
f1eb5cdd158e30df14c59065fe2050448c77b5262b282208fa831d050f6b6a71 inventory-allowlist.txt
f66fb98d2a09503d9bd0d60dc964545eea6dc94b9bbb9246d1021195b79f2601 inventory_gate.sh
736ea4be712e1b5bcda10ecb466f0dec7008a2a36eabdfd77563976299c43cce lean-guard
ce4c4e3d87434b9663f46de25ce34b48a0cf0d392e0a320a0787b4674a2d7b61 lean-toolchain
eda93f520546a692926b2a46bcb79332e1795879e5083327a8bf2404aca5cf87 Proofs/AxiomCheck.lean
P2-b: close classes 9 and 15 — the instruments, and the places nothing looked CLASS 15 — a Lean file where no phase was looking. The dead-file scan read Proofs/*.lean and gen/LTLAcc/*.lean and nothing else. A module at the verification root, or under any other gen/ subdirectory, was neither compiled nor rejected — while remaining importable by name, since LEAN_PATH contains both roots. That is a source of the corpus that no phase reads and no pin covers, which is exactly what the dead-file gate exists to forbid; it was simply looking in two places instead of everywhere. Now nothing may live in either root but the two enumerated sets. CLASS 9 — the instruments' own declaration surface. AxiomCheck.lean and Inventory.lean perform the audit and are therefore not corpus, so nothing inventoried what THEY declare. Inventory.lean now walks both: AxiomCheck by module index, and itself as the module still being elaborated, whose declarations are the ones the environment reports with no originating module. That is what makes the inventory cover the instrument that produces it rather than exempting itself. The policy is not "declare nothing" — this file legitimately declares its machinery. It is that an instrument may declare only inert definitions. An axiom here would widen the trusted base without appearing in any certificate's cone; a theorem here would be a claim no certificate covers and no allowlist pins. A flat ban on theorems was WRONG and was measured to be wrong: defining a function by well-founded recursion makes the elaborator emit its own obligations, and axiomCone._proof_1 rejected this very file. The distinction that holds is whether a theorem is a claim someone wrote or an artefact of a definition declared alongside it — an artefact's name extends the name of a constant declared with it. Observed surface: 18 declarations, 16 def and 2 generated obligations, no axiom, no standalone claim. The drivers are byte-pinned already, so this does not pin WHICH definitions they contain — that would add a thing to maintain without adding a thing to catch. It adds the property byte-pinning cannot give: that no instrument declares an axiom or a claim, whatever its bytes are. selftest_audit.sh: 10 cases -> 14. Case 12 uses an INDENTED axiom, because Phase 1's source grep catches an unindented one and the point is to reach the kernel-side walk standing behind it. TWO DEFECTS IN THE TEST HARNESS, found while adding the cases. · The scratch tree copied verification/ only, but the button also reads README.md and STATEMENT-MAP.md from the repository root. check.sh therefore ALWAYS died in Phase 3c in the scratch tree, which made every `if check.sh; then <attack not caught>` guard unfirable — check.sh could not pass in there even with no attack at all. Only the diagnostic greps were doing any work. The documents are now copied, and the negative test below proves the guard is live: with the driver-surface check disabled, check.sh PASSES a tree whose inventory driver declares `axiom driver_cheat : False`. · Case 9 was the last case when it was written and left its rogue gen file in place. Harmless then; the new cases inherited it. Cleaned up between the blocks rather than inside case 9, so that case still tests what it did. Also fixed while here: Phase 3b compared the compile manifest against Inventory.lean by grepping the WHOLE FILE for a backticked module name, so prose counted — a doc comment naming a module broke the count, and in the other direction a doc mention of a module missing from the array would have satisfied the presence check and hidden the omission. It now reads the arrays. Both new gates negative-tested by removal. Button green, self-test green.
2026-07-31 12:18:40 +00:00
de5cdf01724fd4333b0652769bfede3ee150fedfa0a6c4ffbc8e7ab065843928 Proofs/Inventory.lean
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
0b8a0fc6947af1d1e600a756eb2b07dc88d189b21df3220c4501a41be8b33f1e run_bare.sh
Round-7 F2: account for every constant the kernel sees THE DEFECT, demonstrated by a reviewer with a working payload. The driver surface is reported by an `#eval` inside Proofs/Inventory.lean. Anything declared AFTER that command is in the compiled object file but does not exist in the environment while the command runs, so the walk cannot see it. The reviewer appended def bait : Nat := 0 theorem bait.smuggled : forall n : Nat, n + 0 = n := ... re-pinned, and ran the button. It printed "no axiom, no claim", the statement digest was BYTE-IDENTICAL to the clean tree, and the run went green — while a theorem with a real axiom cone sat in the environment. In neither walk: not corpus, because an instrument is not corpus; not driver surface, because it post-dates the emitter. In no allowlist. Pinned by nothing. This repository also had no kernel-side scan at all. Its axiom gate was a source-text grep, evadable by a leading space — which its own selftest case 12 already exploited. THE FIX, ported from the ed25519 forks: · a kernel-side axiom-declaration gate that reads every compiled .olean via readModuleData. It sees what was actually stored, regardless of indentation, attributes, privacy, or where a declaration sits relative to any #eval. Membership self-derives from the manifest and the module count must match, so a deleted artifact cannot make the scan vacuous. · the ACCOUNTING IDENTITY, as set containment: every constant the kernel sees in corpus inventory union instrument surface The two walks read ENVIRONMENTS; the gate reads OBJECT FILES. What a walk cannot see because of where it sits in a file, the object file still holds. That asymmetry is the entire content of this fix. Compared as SETS deliberately. Counts cannot express the relation — an object file may hold two physical copies of one lazily-materialised equation lemma while an environment holds one constant per name — and arithmetic between those views misled the ed25519 version twice before it was stated as containment. PLACEMENT differs from the forks, for a reason worth recording: there the audit drivers are members of the compile manifest, so a gate beside the compile phase finds them. Here AxiomCheck is compiled by Phase 3 and Inventory by Phase 3b, so an earlier gate fails on a missing artifact — which it did, correctly, on the first port. It runs inside Phase 3b, because the instruments are exactly what it must see. VERIFIED with the reviewer's own payload, which previously went green: ACCOUNTING FAILED: the kernel holds constants that neither walk accounts for: bait bait.smuggled selftest_audit.sh: 14 attack cases -> 15. Note in the new case, because it cost two iterations: `theorem bait.smuggled : True := trivial` does NOT exercise this gate — Phase 1's stub audit greps for `: True :=` and catches it first. Real defence in depth, but the naive payload never reaches the gate under test, so the case uses the reviewer's original. Two residues fixed while adding it, both the same shape: a case that was last when written, leaving state the next case inherits. Case 13 restored AxiomCheck.lean but not its pin; case 9 left its rogue gen file. Fixed at the point of use so each case keeps testing what it tested before. Button green (234 declarations across 11 modules, all accounted for), 15/15 self-test green, ATTESTATION GREEN with fidelity.
2026-08-02 00:51:55 +00:00
473e2463d9c26653c8435ad6758044742f200eb13ea0db4b8f076466c08bd87a selftest_audit.sh
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
3d5898161d663eccad162269a5a6c102319077e22e1f2d89a8bfcab6926d29f6 selftest-harness.sh
cf6d4d8210e224a054d4ab693c28c83e7a9ddebda05da47d6ec311d825a606c0 selftest_statements.sh