ltl-accumulator-verified/verification/HARNESS.sha256

18 lines
1.4 KiB
Text
Raw Normal View History

verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
e7d422f0be9a9e6f5465058292e30c711d52856428da2b01c470a57ec181540c AUDIT-MANIFEST.txt
accumulator: a run that is not attestation-ready must not exit 0, and must name its subject Two round-7/8 findings, both closed here. `acc-exit0-fidelity` — CRITICAL, raised INDEPENDENTLY by both reviewers (Claude F1, GPT-5.6 F10) and lost from the round-8 work list by the F-number collision the finding register now prevents. check.sh emitted a careful pair of markers — ATTESTATION GREEN only when fidelity actually ran — and then returned 0 either way. The marker discipline was right; the exit code contradicted it. A caller doing the obvious thing ./check.sh && append read success from a run whose own last line said NOT attestation-ready. And because pacta is not part of this estate, the skip branch is the ONLY branch a third party ever takes: for everyone but the author the button always returned 0 without ever checking definition fidelity. Reproduced here before fixing — PACTA_SRC=/nonexistent ./check.sh printed "FIDELITY NOT RUN" and exited 0. An exit code is what programs read. The contract is now: fidelity ran exit 0 ATTESTATION GREEN SKIP_FIDELITY=1 exit 3 explicit opt-out, distinguishable, not success pacta absent exit 1 nobody opted out; a real failure to establish the property the button exists for All three verified. The self-tests are unaffected: every SKIP_FIDELITY case already expected a non-zero exit and asserts on a diagnostic from an earlier phase, and the control compiles modules directly rather than invoking check.sh. 29 assertions across the three self-tests, all green. `pacta-subject-unpinned` — HIGH, GPT-5.6 round 8. Phase 4 compared this repository's Lean definitions against "the deployed verifier" by importing whatever sat at $PACTA_SRC — no repository, no commit, no clean state, no hashes. It pinned the fidelity OUTPUTS while leaving the SUBJECT anonymous, so any program producing the same finite family of answers passed, and the recorded result named no version of the thing it agreed with. fidelity/pacta_pin.py pins the transitive set of pacta modules the harness ACTUALLY LOADS — discovered by importing its entry point and reading sys.modules, a membership property rather than a directory glob. A glob would pin files the comparison never touches and miss anything loaded from elsewhere; this estate has been bitten by name-shaped measurement before. Five modules at pacta cd3b1bc — the same checkout the reviewer independently recorded. Negative-tested, all three rejected by name: tampered bytes, a module loaded but absent from the pin, and the pin file deleted. Refusing to pin a dirty pacta tree is also enforced — a pin taken over uncommitted edits names a subject nobody else can obtain. PACTA-PIN.sha256 joins HARNESS_EXTRA. It is not executable, so it would otherwise have sat outside the harness set, and a subject pin an attacker may rewrite pins nothing — the same shape as the forgeable .audit-basis that remains open as `auditonly-basis-forgeable`. This does not widen the claim: byte identity of a source tree is not proof the deployed service runs it, and finite-family agreement is not extensional equality. It names the subject. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-02 19:40:35 +00:00
29b20810b6d365d8aa0b1affbbd4e3a38f03f302eb839d10a314e94a60b46da7 check.sh
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
070147e2667053bd5d5e1174b969fc6c91bfcf15ded1a5bff57754e15f416885 fidelity/lean_defs.py
accumulator: a run that is not attestation-ready must not exit 0, and must name its subject Two round-7/8 findings, both closed here. `acc-exit0-fidelity` — CRITICAL, raised INDEPENDENTLY by both reviewers (Claude F1, GPT-5.6 F10) and lost from the round-8 work list by the F-number collision the finding register now prevents. check.sh emitted a careful pair of markers — ATTESTATION GREEN only when fidelity actually ran — and then returned 0 either way. The marker discipline was right; the exit code contradicted it. A caller doing the obvious thing ./check.sh && append read success from a run whose own last line said NOT attestation-ready. And because pacta is not part of this estate, the skip branch is the ONLY branch a third party ever takes: for everyone but the author the button always returned 0 without ever checking definition fidelity. Reproduced here before fixing — PACTA_SRC=/nonexistent ./check.sh printed "FIDELITY NOT RUN" and exited 0. An exit code is what programs read. The contract is now: fidelity ran exit 0 ATTESTATION GREEN SKIP_FIDELITY=1 exit 3 explicit opt-out, distinguishable, not success pacta absent exit 1 nobody opted out; a real failure to establish the property the button exists for All three verified. The self-tests are unaffected: every SKIP_FIDELITY case already expected a non-zero exit and asserts on a diagnostic from an earlier phase, and the control compiles modules directly rather than invoking check.sh. 29 assertions across the three self-tests, all green. `pacta-subject-unpinned` — HIGH, GPT-5.6 round 8. Phase 4 compared this repository's Lean definitions against "the deployed verifier" by importing whatever sat at $PACTA_SRC — no repository, no commit, no clean state, no hashes. It pinned the fidelity OUTPUTS while leaving the SUBJECT anonymous, so any program producing the same finite family of answers passed, and the recorded result named no version of the thing it agreed with. fidelity/pacta_pin.py pins the transitive set of pacta modules the harness ACTUALLY LOADS — discovered by importing its entry point and reading sys.modules, a membership property rather than a directory glob. A glob would pin files the comparison never touches and miss anything loaded from elsewhere; this estate has been bitten by name-shaped measurement before. Five modules at pacta cd3b1bc — the same checkout the reviewer independently recorded. Negative-tested, all three rejected by name: tampered bytes, a module loaded but absent from the pin, and the pin file deleted. Refusing to pin a dirty pacta tree is also enforced — a pin taken over uncommitted edits names a subject nobody else can obtain. PACTA-PIN.sha256 joins HARNESS_EXTRA. It is not executable, so it would otherwise have sat outside the harness set, and a subject pin an attacker may rewrite pins nothing — the same shape as the forgeable .audit-basis that remains open as `auditonly-basis-forgeable`. This does not widen the claim: byte identity of a source tree is not proof the deployed service runs it, and finite-family agreement is not extensional equality. It names the subject. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-02 19:40:35 +00:00
9661bc2d33e907453ab4378da918589a709127b2e117ef1fd578d4e0472edf87 fidelity/pacta_pin.py
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
5d82462a002ac9fc782e95afe78b7719ba64b6410b5d2bfa620fe5317367dbf2 fidelity/run_fidelity.py
503babb3f4e6aff82ebd59e8752469ecd60fba440ed3b11b3f97c2b655fbd9bf gen/LTLAcc/HashExternal.lean
f1eb5cdd158e30df14c59065fe2050448c77b5262b282208fa831d050f6b6a71 inventory-allowlist.txt
f66fb98d2a09503d9bd0d60dc964545eea6dc94b9bbb9246d1021195b79f2601 inventory_gate.sh
736ea4be712e1b5bcda10ecb466f0dec7008a2a36eabdfd77563976299c43cce lean-guard
ce4c4e3d87434b9663f46de25ce34b48a0cf0d392e0a320a0787b4674a2d7b61 lean-toolchain
accumulator: a run that is not attestation-ready must not exit 0, and must name its subject Two round-7/8 findings, both closed here. `acc-exit0-fidelity` — CRITICAL, raised INDEPENDENTLY by both reviewers (Claude F1, GPT-5.6 F10) and lost from the round-8 work list by the F-number collision the finding register now prevents. check.sh emitted a careful pair of markers — ATTESTATION GREEN only when fidelity actually ran — and then returned 0 either way. The marker discipline was right; the exit code contradicted it. A caller doing the obvious thing ./check.sh && append read success from a run whose own last line said NOT attestation-ready. And because pacta is not part of this estate, the skip branch is the ONLY branch a third party ever takes: for everyone but the author the button always returned 0 without ever checking definition fidelity. Reproduced here before fixing — PACTA_SRC=/nonexistent ./check.sh printed "FIDELITY NOT RUN" and exited 0. An exit code is what programs read. The contract is now: fidelity ran exit 0 ATTESTATION GREEN SKIP_FIDELITY=1 exit 3 explicit opt-out, distinguishable, not success pacta absent exit 1 nobody opted out; a real failure to establish the property the button exists for All three verified. The self-tests are unaffected: every SKIP_FIDELITY case already expected a non-zero exit and asserts on a diagnostic from an earlier phase, and the control compiles modules directly rather than invoking check.sh. 29 assertions across the three self-tests, all green. `pacta-subject-unpinned` — HIGH, GPT-5.6 round 8. Phase 4 compared this repository's Lean definitions against "the deployed verifier" by importing whatever sat at $PACTA_SRC — no repository, no commit, no clean state, no hashes. It pinned the fidelity OUTPUTS while leaving the SUBJECT anonymous, so any program producing the same finite family of answers passed, and the recorded result named no version of the thing it agreed with. fidelity/pacta_pin.py pins the transitive set of pacta modules the harness ACTUALLY LOADS — discovered by importing its entry point and reading sys.modules, a membership property rather than a directory glob. A glob would pin files the comparison never touches and miss anything loaded from elsewhere; this estate has been bitten by name-shaped measurement before. Five modules at pacta cd3b1bc — the same checkout the reviewer independently recorded. Negative-tested, all three rejected by name: tampered bytes, a module loaded but absent from the pin, and the pin file deleted. Refusing to pin a dirty pacta tree is also enforced — a pin taken over uncommitted edits names a subject nobody else can obtain. PACTA-PIN.sha256 joins HARNESS_EXTRA. It is not executable, so it would otherwise have sat outside the harness set, and a subject pin an attacker may rewrite pins nothing — the same shape as the forgeable .audit-basis that remains open as `auditonly-basis-forgeable`. This does not widen the claim: byte identity of a source tree is not proof the deployed service runs it, and finite-family agreement is not extensional equality. It names the subject. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-02 19:40:35 +00:00
6f39303b336aedc4da8381712de8180282e39c0725226c292fce15b47f9beb88 PACTA-PIN.sha256
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
eda93f520546a692926b2a46bcb79332e1795879e5083327a8bf2404aca5cf87 Proofs/AxiomCheck.lean
P2-b: close classes 9 and 15 — the instruments, and the places nothing looked CLASS 15 — a Lean file where no phase was looking. The dead-file scan read Proofs/*.lean and gen/LTLAcc/*.lean and nothing else. A module at the verification root, or under any other gen/ subdirectory, was neither compiled nor rejected — while remaining importable by name, since LEAN_PATH contains both roots. That is a source of the corpus that no phase reads and no pin covers, which is exactly what the dead-file gate exists to forbid; it was simply looking in two places instead of everywhere. Now nothing may live in either root but the two enumerated sets. CLASS 9 — the instruments' own declaration surface. AxiomCheck.lean and Inventory.lean perform the audit and are therefore not corpus, so nothing inventoried what THEY declare. Inventory.lean now walks both: AxiomCheck by module index, and itself as the module still being elaborated, whose declarations are the ones the environment reports with no originating module. That is what makes the inventory cover the instrument that produces it rather than exempting itself. The policy is not "declare nothing" — this file legitimately declares its machinery. It is that an instrument may declare only inert definitions. An axiom here would widen the trusted base without appearing in any certificate's cone; a theorem here would be a claim no certificate covers and no allowlist pins. A flat ban on theorems was WRONG and was measured to be wrong: defining a function by well-founded recursion makes the elaborator emit its own obligations, and axiomCone._proof_1 rejected this very file. The distinction that holds is whether a theorem is a claim someone wrote or an artefact of a definition declared alongside it — an artefact's name extends the name of a constant declared with it. Observed surface: 18 declarations, 16 def and 2 generated obligations, no axiom, no standalone claim. The drivers are byte-pinned already, so this does not pin WHICH definitions they contain — that would add a thing to maintain without adding a thing to catch. It adds the property byte-pinning cannot give: that no instrument declares an axiom or a claim, whatever its bytes are. selftest_audit.sh: 10 cases -> 14. Case 12 uses an INDENTED axiom, because Phase 1's source grep catches an unindented one and the point is to reach the kernel-side walk standing behind it. TWO DEFECTS IN THE TEST HARNESS, found while adding the cases. · The scratch tree copied verification/ only, but the button also reads README.md and STATEMENT-MAP.md from the repository root. check.sh therefore ALWAYS died in Phase 3c in the scratch tree, which made every `if check.sh; then <attack not caught>` guard unfirable — check.sh could not pass in there even with no attack at all. Only the diagnostic greps were doing any work. The documents are now copied, and the negative test below proves the guard is live: with the driver-surface check disabled, check.sh PASSES a tree whose inventory driver declares `axiom driver_cheat : False`. · Case 9 was the last case when it was written and left its rogue gen file in place. Harmless then; the new cases inherited it. Cleaned up between the blocks rather than inside case 9, so that case still tests what it did. Also fixed while here: Phase 3b compared the compile manifest against Inventory.lean by grepping the WHOLE FILE for a backticked module name, so prose counted — a doc comment naming a module broke the count, and in the other direction a doc mention of a module missing from the array would have satisfied the presence check and hidden the omission. It now reads the arrays. Both new gates negative-tested by removal. Button green, self-test green.
2026-07-31 12:18:40 +00:00
de5cdf01724fd4333b0652769bfede3ee150fedfa0a6c4ffbc8e7ab065843928 Proofs/Inventory.lean
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
0b8a0fc6947af1d1e600a756eb2b07dc88d189b21df3220c4501a41be8b33f1e run_bare.sh
Round-7 F2: account for every constant the kernel sees THE DEFECT, demonstrated by a reviewer with a working payload. The driver surface is reported by an `#eval` inside Proofs/Inventory.lean. Anything declared AFTER that command is in the compiled object file but does not exist in the environment while the command runs, so the walk cannot see it. The reviewer appended def bait : Nat := 0 theorem bait.smuggled : forall n : Nat, n + 0 = n := ... re-pinned, and ran the button. It printed "no axiom, no claim", the statement digest was BYTE-IDENTICAL to the clean tree, and the run went green — while a theorem with a real axiom cone sat in the environment. In neither walk: not corpus, because an instrument is not corpus; not driver surface, because it post-dates the emitter. In no allowlist. Pinned by nothing. This repository also had no kernel-side scan at all. Its axiom gate was a source-text grep, evadable by a leading space — which its own selftest case 12 already exploited. THE FIX, ported from the ed25519 forks: · a kernel-side axiom-declaration gate that reads every compiled .olean via readModuleData. It sees what was actually stored, regardless of indentation, attributes, privacy, or where a declaration sits relative to any #eval. Membership self-derives from the manifest and the module count must match, so a deleted artifact cannot make the scan vacuous. · the ACCOUNTING IDENTITY, as set containment: every constant the kernel sees in corpus inventory union instrument surface The two walks read ENVIRONMENTS; the gate reads OBJECT FILES. What a walk cannot see because of where it sits in a file, the object file still holds. That asymmetry is the entire content of this fix. Compared as SETS deliberately. Counts cannot express the relation — an object file may hold two physical copies of one lazily-materialised equation lemma while an environment holds one constant per name — and arithmetic between those views misled the ed25519 version twice before it was stated as containment. PLACEMENT differs from the forks, for a reason worth recording: there the audit drivers are members of the compile manifest, so a gate beside the compile phase finds them. Here AxiomCheck is compiled by Phase 3 and Inventory by Phase 3b, so an earlier gate fails on a missing artifact — which it did, correctly, on the first port. It runs inside Phase 3b, because the instruments are exactly what it must see. VERIFIED with the reviewer's own payload, which previously went green: ACCOUNTING FAILED: the kernel holds constants that neither walk accounts for: bait bait.smuggled selftest_audit.sh: 14 attack cases -> 15. Note in the new case, because it cost two iterations: `theorem bait.smuggled : True := trivial` does NOT exercise this gate — Phase 1's stub audit greps for `: True :=` and catches it first. Real defence in depth, but the naive payload never reaches the gate under test, so the case uses the reviewer's original. Two residues fixed while adding it, both the same shape: a case that was last when written, leaving state the next case inherits. Case 13 restored AxiomCheck.lean but not its pin; case 9 left its rogue gen file. Fixed at the point of use so each case keeps testing what it tested before. Button green (234 declarations across 11 modules, all accounted for), 15/15 self-test green, ATTESTATION GREEN with fidelity.
2026-08-02 00:51:55 +00:00
473e2463d9c26653c8435ad6758044742f200eb13ea0db4b8f076466c08bd87a selftest_audit.sh
verification: pin the harness, audit drivers and policy files (P1-c) This repository has the estate's strongest gates, which makes them the most valuable to switch off. Until now every one of them was executed by scripts that nothing pinned. Phase 0c requires every harness file to match HARNESS.sha256 — 15 files: check.sh, lean-guard, inventory_gate.sh, run_bare.sh, all three self-tests, both audit drivers (Proofs/Inventory.lean, Proofs/AxiomCheck.lean), the policy tables (inventory-allowlist.txt, AUDIT-MANIFEST.txt), the toolchain pin, the fidelity harness and its Python transcription, and the extracted model. WHICH files must be pinned is policy and lives in check.sh, never in the map being consulted: the required set is derived from the filesystem (the executable bit, plus gen/**.lean, plus an explicit list for the rest), so deleting a pin entry is a set mismatch rather than a silent un-pinning. gen/LTLAcc/HashExternal.lean was previously bound by nothing at all — it was compiled and trusted. It is now pinned, and the derivation is by set, so a new model file fails closed. selftest_audit.sh case 9 is split rather than relabelled. Phase 0c now catches an unpinned rogue gen module BEFORE the dead-file gate runs, so asserting only the new diagnostic would have quietly retired the dead-file gate from the test suite. 9a asserts the harness-set mismatch on the unpinned file; 9b pins it — an author who added it deliberately — and asserts Phase 2 still dies with DEAD FILE (gen). Ten cases now, all defeated. KNOWN-GAPS and the trusted base record the circularity plainly: an author who edits a script and refreshes its pin in one commit passes every phase. The pin removes the silent path, not the possibility. Review at the pinned commit remains the consumer's protection. Verified green after the fix: button (75s), harness self-test, binding self-test, and the ten-case audit self-test. ATTESTATION GREEN (Lean + fidelity), all fidelity case counts identical to the pre-change run. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-29 18:13:21 +00:00
3d5898161d663eccad162269a5a6c102319077e22e1f2d89a8bfcab6926d29f6 selftest-harness.sh
cf6d4d8210e224a054d4ab693c28c83e7a9ddebda05da47d6ec311d825a606c0 selftest_statements.sh