coherence sweep wave 1 (pacta): the v0.11 era leaves ESTATE/llms/comments
Cross-repo audit findings 1-9,29: ESTATE snapshot to v0.15+DOI, suite
count 157, mermaid paper node, retired /paper/v0.x routes dropped from
the endpoint row, pasta row aligned to the subject repo's own claim
(field foundation proven, completion pending), llms.txt to v0.15+DOI,
paper/README supersession tail through v0.15, web.py route comment,
ltl.tex header comment no longer names the private reinvention outline
or the rejection (moat + zero-process in public files), litex-boards
dropped from the sources row (not in the pinned pool). Paper PDF bytes
untouched (comment-only tex change; v0.15 artifact stays byte-stable —
the committed PDF is the version-of-record built at v0.15 release).
2026-08-22 16:40:11 +00:00
% Reinvented August 2026 from the round-11 review of the prior draft;
% the full revision history lives in this folder's README.md.
2026-07-09 16:02:59 +00:00
\documentclass [11pt] { article}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\usepackage [a4paper,margin=1.02in] { geometry}
\usepackage { amsmath,amssymb,amsthm,mathtools}
\usepackage { booktabs,tabularx,array}
2026-07-09 16:02:59 +00:00
\usepackage { enumitem}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\usepackage { xcolor}
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
\usepackage { lmodern}
\usepackage { microtype}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\usepackage { listings}
2026-07-09 17:27:13 +00:00
\usepackage { tikz}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\usetikzlibrary { arrows.meta,positioning,fit,decorations.pathreplacing,calc}
\usepackage [colorlinks=true,linkcolor=blue!55!black,citecolor=blue!55!black,urlcolor=blue!55!black] { hyperref}
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
\hypersetup { pdftitle={ Accountable Distribution of Machine-Checked Correctness Evidence: A Transparency Model and the Lean Transparency Log} ,pdfauthor={ Olaf Horvath} ,pdfsubject={ Transparency distribution of formal-verification replay evidence} ,pdfkeywords={ formal verification, transparency log, Lean, Ed25519, SLH-DSA, FIPS 205, Merkle tree, attestation} }
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\lefthyphenmin =2 \righthyphenmin =3
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\newtheorem { definition} { Definition}
2026-07-09 16:02:59 +00:00
\newtheorem { theorem} { Theorem}
\newtheorem { lemma} { Lemma}
\newtheorem { proposition} { Proposition}
2026-07-09 17:27:13 +00:00
\newtheorem { corollary} { Corollary}
2026-07-09 16:02:59 +00:00
\theoremstyle { remark}
\newtheorem { remark} { Remark}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\newcommand { \Hh } { \mathsf { H} }
\newcommand { \hleaf } { \mathsf { h} _ { \rm leaf} }
\newcommand { \hnode } { \mathsf { h} _ { \rm node} }
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\hyphenation { time-stamp time-stamps}
2026-07-09 16:02:59 +00:00
\newcommand { \MTH } { \mathsf { MTH} }
\newcommand { \Root } { \mathsf { Root} }
\newcommand { \Path } { \mathsf { Path} }
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\newcommand { \ConsRec } { \mathsf { ConsRec} }
\newcommand { \Obs } { \mathsf { Obs} }
\newcommand { \Policy } { \mathsf { Policy} }
2026-07-09 16:02:59 +00:00
\newcommand { \Fp } { \mathbb { F} _ { 2^ { 255} -19} }
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\newcommand { \code } [1]{ \texttt { \detokenize { #1} } }
\definecolor { deepblue} { RGB} { 43,61,112}
\definecolor { deepgreen} { RGB} { 28,111,71}
\definecolor { softgray} { RGB} { 245,247,249}
2026-07-09 16:02:59 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\lstset { basicstyle=\ttfamily \small ,frame=single,rulecolor=\color { black!15} ,
backgroundcolor=\color { softgray} ,columns=fullflexible,keepspaces=true,
showstringspaces=false,breaklines=true,xleftmargin=.5em,xrightmargin=.5em}
\title { \textbf { Accountable Distribution of Machine-Checked Correctness Evidence} \\ [3pt]
\large A Transparency Model and the Lean Transparency Log}
2026-07-09 16:02:59 +00:00
\author { Olaf Horvath\\
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\small Olaf.Horvath@zkdefi.org \quad ORCID 0009-0004-8008-5805}
2026-08-17 11:40:39 +00:00
\date { July 2026 \\ { \normalsize Revised: August 2026 --- v0.15} }
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
\begin { document}
\maketitle
\begin { abstract}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Formal verification produces machine-checkable evidence, but consuming that
evidence usually requires the original prover, dependency graph, source
checkout, and substantial replay time. This paper studies a distinct
cryptographic problem: how can a lightweight consumer obtain precise and
accountable assurance about a deterministic proof replay without executing the
verifier and without reducing the result to an opaque provider label?
We define \emph { accountable replay attestation} . A specialized operator performs
an expensive replay once and publishes a structured observation through a
signed append-only log. Consumers verify a signed tree head and logarithmic
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
inclusion proof, pin history, and apply their own policy to the exact reported axiom-name sets
for each theorem. The construction does not prove that the operator's
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
observation is true. It makes the claim immutable within a signed view,
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
comparable across consumers, and attributable when incompatible signed views
are compared.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
We instantiate the model as the Lean Transparency Log (LTL), using Lean~4 replay
attestations and an RFC~9162 Merkle tree. We give explicit
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
collision-extracting arguments for inclusion and consistency, lift them to
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
scheme-level accountability games with a composition theorem, and evaluate a
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
live deployment over four production Ed25519 codebases and the verification
path of SLH-DSA (FIPS~205), the hash-based post-quantum signature standard.
The public log contains nineteen leaves, including a Lean mechanization of the
2026-07-17 20:20:42 +00:00
accumulator's own security arguments (61 human-reviewed certificates with one
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
project-specific uninterpreted SHA-256 boundary axiom) and, as its newest
entry, eleven certificates over the SLH-DSA-SHA2-128s verifier. Since tree
size 14 every signed head additionally carries a deterministic SLH-DSA
co-signature --- produced with the parameter set whose verification path the
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
log itself attests. The mechanization effort also exposed, via
differential testing, a nontrivial model/implementation divergence --- on
malformed size claims, the deployed iterative consistency verifier was not
extensionally equal to the recursive model proved in Lean (since closed;
this paper reports the pre-closure measurements) --- recorded explicitly
in the corresponding log entry. The contribution is a cryptographic distribution
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
model for machine-checked correctness evidence, with an end-to-end deployed
instantiation that carries scoped proofs about its own accountability
machinery.
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
\end { abstract}
2026-07-09 16:02:59 +00:00
\section { Introduction} \label { sec:intro}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Formal verification has made it possible to connect production cryptographic
software to machine-checked mathematics. Systems such as HACL*, EverCrypt,
Fiat-Crypto, and Aeneas demonstrate different routes from implementation to
proof~\cite { hacl,evercrypt,fiatcrypto,aeneas} . Yet the standard assurance story
quietly assumes a capable consumer: one that can retrieve the exact source,
reconstruct the verifier environment, resolve dependencies, and spend minutes
or hours replaying a corpus.
That assumption is often false. A package resolver selecting a cryptographic
backend, a deployment controller enforcing a proof requirement, or an
autonomous custody agent may have milliseconds and a small trusted computing
base, not a theorem prover and thirty minutes of kernel time per candidate.
This creates a problem that is logically downstream of proof construction:
\begin { quote}
\emph { How can a consumer that cannot execute the prover obtain precise,
accountable evidence about a proof replay, without collapsing the result into
2026-08-17 11:40:39 +00:00
an opaque provider label?}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\end { quote}
A detached signature on the word ``verified'' authenticates an issuer but does
not bind an ordered history, expose silent replacement, or give consumers a
compact state that can be pinned and required to grow. Shipping the complete
proof and checker preserves direct verification but may defeat the cost and
portability objective. Committees distribute trust but do not themselves fix
the semantics of the attested result. Succinct proofs of verifier execution
would provide validity rather than mere accountability, but require a circuit or
verified-VM representation of the prover and are not yet the deployment
2026-08-17 11:40:39 +00:00
assumption of the artifacts studied here. Each alternative thus fails on
one of two sides: the cost of checking stays with the consumer, or it
disappears because belief in a label is demanded. The primitive studied
here occupies the point between.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
We therefore study a narrower primitive: \emph { accountable delegation of
deterministic proof replay} . The operator still observes the replay. The
cryptographic layer does not make that observation true. Instead, it makes the
observation exact, persistent, attributable, and locally policy-checkable.
Independent replay remains the mechanism for challenging a fabricated
observation.
\paragraph { Central thesis.}
The contribution is not a new Merkle tree and not a new theorem prover. It is a
trust decomposition for distributing machine-checked correctness evidence:
\begin { center}
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\fbox { \parbox { 0.91\linewidth } { \raggedright \hyphenpenalty =10000\exhyphenpenalty =10000
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\textbf { Expensive deterministic verification produces an observation.
Transparency makes that observation accountable. Consumer-local policy decides
whether the observation is acceptable.} } }
\end { center}
The Lean Transparency Log (LTL)\footnote { The acronym collides with linear
temporal logic~\cite { pnueli} ; we note the collision once and rely on context.}
is the complete instantiation evaluated in this paper. Its subjects are four
Rust Ed25519 codebases with Lean~4~\cite { lean4} certificates against extracted
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
models. Leaf 12 --- its thirteenth entry --- attests the Lean corpus
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
that mechanizes the security arguments of the log's own Merkle accumulator
(the tree of \S \ref { sec:construction} together with its inclusion and
consistency verifiers). The paper's central
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
claim survives replacement of Lean, Ed25519, or RFC~9162 by other components;
what is essential is the distribution and accountability model.
\paragraph { Contributions.}
\begin { enumerate} [leftmargin=1.7em,itemsep=3pt]
\item \textbf { A distribution model for machine-checked evidence.}
We define replay attestations, distinguish observation from verdict, and state
what a lightweight consumer learns without executing Lean.
\item \textbf { A cryptographic accountability layer.}
Using the RFC~9162 tree unchanged, we define signed views, inclusion receipts,
local history pinning, and transferable same-size fork evidence. We give
explicit collision-extracting soundness arguments specialized to the consumer
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
algorithms, and lift them to scheme level: concrete games for position
binding, history binding, and fork evidence, discharged by explicit
reductions (\S \ref { sec:games} ).
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\item \textbf { Boundary-conformance policy.}
Each leaf records the exact axiom names reported by Lean. Consumers compare
those observations with their own policy; operator labels can veto but cannot
grant acceptance. We state clearly that axiom-name equality is not semantic
identity of theorem statements.
\item \textbf { A deployed cryptographic case study.}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The log contains nineteen leaves: three replay generations across the four
Ed25519 codebases (the newest at 44 certificates per fork; a \emph { certificate} throughout this paper is one theorem's kernel-checked proof together with its recorded axiom cone), two attestations
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
of the accumulator's own Lean corpus (leaf 12 carries an environment-derived
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
audit inventory of 222 compiled constants, 61 human-reviewed certificate
cones, and a single uninterpreted SHA-256 axiom; leaf 17 re-attests the
hardened state), and --- as leaf 18 --- the log's first post-quantum subject:
eleven certificates over the SLH-DSA-SHA2-128s verification path
(Appendix~\ref { app:slhtiers} ).
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\item \textbf { A negative deployment result.}
Differential testing found that the deployed iterative RFC-style consistency
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
verifier and the recursive model proved in Lean are not extensionally equal:
there are malformed size/root combinations accepted only by the deployed
verifier. We characterize 3,867 divergences in 73,573 pinned boundary tests
--- every one deployed-accepts-only --- and scope the public attestation
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
accordingly. (Subsequently closed: the divergence was traced to
2026-08-15 12:17:03 +00:00
the deployed verifier omitting RFC~9162 \S 2.1.4.2 Step~7's terminal
$ sn = 0 $ condition; restoring that one conjunct removes every divergence in the
pinned family, confirmed by a three-way regression against an independent
faithful RFC transliteration.)
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\end { enumerate}
\paragraph { Non-claims.}
LTL does not prove that the operator honestly reported a kernel run; independent
replay remains the way to detect a fabricated observation. It does not prove
binary correspondence, compiler correctness, extraction faithfulness,
side-channel resistance, SHA-512 correctness, or execution provenance of the
signing binary. The present leaf schema identifies theorem declarations by
repository commit and name, not by a canonical digest of their elaborated Lean
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
types. These are explicit boundaries, not hidden qualifications
(Appendix~\ref { app:matrix} tabulates every consumer-facing claim with its
establishing mechanism and remaining assumption).
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\section { The distribution problem} \label { sec:problem}
\subsection { Three evidence modes}
Let a subject repository at commit $ g $ contain theorem declarations
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
$ \Theta _ 1 , \dots , \Theta _ q $ . A deterministic verifier execution produces an observation
$ O _ g $ containing success/failure and the reported \emph { axiom cone} (synonymously, the observed axiom-name set) of each
$ \Theta _ i $ --- the set of axioms the checked proof of $ \Theta _ i $ ultimately rests on. There are three natural ways to consume this result.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { description} [leftmargin=1.5em,itemsep=4pt]
\item [Direct replay.] The consumer reconstructs the verifier environment and
checks $ O _ g $ itself. This gives the strongest provenance, but has high
operational cost.
\item [Detached attestation.] A provider signs $ O _ g $ . This is cheap to consume,
but provides no append-only history and no common value for clients to pin.
\item [Transparent attestation.] The provider signs a tree head committing
$ O _ g $ as one leaf among an ordered history. A consumer verifies inclusion and
persists a head. Incompatible views become attributable when compared.
\end { description}
The third mode is useful precisely when replay is expensive but the result is
stable and deterministic. It does not dominate direct replay: it replaces
local computation with a narrower trust in the replay provider.
\subsection { Why transparency rather than a signature database?}
Suppose an operator signs every replay result independently. Authenticity of
an individual record follows from signature verification, but four properties
are absent:
\begin { enumerate} [leftmargin=1.7em,itemsep=2pt]
\item no signed value commits to the ordered set of all records;
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
\item the signer commits to no complete ordered history, so omission or
replacement is not detectable by a fresh consumer and carries no compact
consistency proof;
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\item two consumers cannot compare a single compact view identifier;
\item a consumer cannot demand that its previously accepted history only grow.
2026-07-09 16:02:59 +00:00
\end { enumerate}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
An append-only Merkle tree supplies these missing interfaces. At the current
deployment size, logarithmic proof size is not the decisive benefit;
\emph { history binding} is.
\subsection { Design alternatives}
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
Table~\ref { tab:alternatives} places the construction among the natural
alternatives, read as a design taxonomy rather than an empirical comparison.
Local replay and proof transport keep semantic checking with the consumer at
high operational cost; detached signatures and committees lower consumer cost
but commit to no ordered history (a committee distributes trust in the
observation; it does not by itself make the record's history accountable);
succinct proofs of replay would upgrade accountability to validity at the
price of proving the prover. LTL occupies the low-consumer-cost point that
still binds an ordered, signed, pinnable history --- and deliberately does not
buy validity of the observation itself.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { table} [t]
\centering \small
2026-07-17 20:20:42 +00:00
\begin { tabularx} { \textwidth } { @{ } l>{ \raggedright \arraybackslash } X>{ \raggedright \arraybackslash } X>{ \raggedright \arraybackslash } X>{ \raggedright \arraybackslash } X@{ } }
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\toprule
Mechanism & Consumer cost & Semantic checker & History accountability & Main residual cost \\
\midrule
Local replay & high & consumer & local only & prover/toolchain deployment \\
Proof transport / PCC & medium--high & consumer checker & optional & proof/checker portability \\
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
Detached signed result & low & provider & statement-level only & replaceable history \\
Committee replay & low & committee & none without an additional log & membership trust \\
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Succinct proof of replay & low & circuit/VM verifier & optional & proving the prover \\
LTL & low & provider observes; consumer applies policy & signed append-only views & observation honesty \\
\bottomrule
\end { tabularx}
\caption { Evidence-distribution alternatives. LTL targets low-cost consumers
while retaining an attributable history; it does not remove trust in the
replay observation.}
\label { tab:alternatives}
\end { table}
\section { Model and trust decomposition} \label { sec:model}
\subsection { Roles and objects}
The system has three logical roles.
\begin { description} [leftmargin=1.5em,itemsep=4pt]
\item [Subject maintainer.] Publishes source and proof artifacts at a commit.
\item [Replay operator.] Executes the declared verifier procedure, constructs
an attestation, appends it to the log, and signs tree heads.
\item [Consumer.] Holds the log public key and a local policy; verifies receipts
and optionally persists a previous head.
\end { description}
2026-07-09 16:02:59 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
A replay attestation $ a $ contains at least
2026-07-09 16:02:59 +00:00
\[
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
(\textsf { repo} ,g,\textsf { toolchain} ,\textsf { environment} ,
[(N_ i,s_ i,A_ i)]_ { i=1} ^ { q} ),
2026-07-09 16:02:59 +00:00
\]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
where $ N _ i $ is a declaration name, $ s _ i $ is replay status, and $ A _ i $ is the
observed axiom-name set. The deployed schema additionally carries diagnostics,
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
resource controls, a machine-readable \emph { scope block} (the deployed
leaf-12 instance is quoted verbatim in Appendix~\ref { app:entry13} ), and exclusions.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { definition} [Attestation-transparency scheme]
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
An attestation-transparency scheme is a~\mbox { tuple}
2026-07-09 16:02:59 +00:00
\[
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\Pi =(\mathsf { KeyGen} ,\mathsf { Append} ,\mathsf { ProveIncl} ,
\mathsf { VerifyIncl} ,\mathsf { ProveCons} ,\mathsf { VerifyCons} ,\mathsf { Verdict} )
2026-07-09 16:02:59 +00:00
\]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
over a hash function and signature scheme. $ \mathsf { Append } $ commits the
canonical serialization of an attestation as the next leaf and returns a signed
tree head. $ \mathsf { Verdict } $ is parameterized by consumer-local policy and
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
does not consume an operator label as positive evidence.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\end { definition}
2026-07-09 16:02:59 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { definition} [Accountable replay distribution]
Fix an operator public key and a consumer that persists accepted signed heads.
A replay-distribution scheme is \emph { accountable} if the following hold:
2026-07-17 20:20:42 +00:00
(i) every accepted attestation has an authentic signed view and a uniquely
determined leaf value at its claimed position; (ii) a
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
consumer accepts a later view only as the same view or a verified extension;
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
(iii) two valid equal-size heads with unequal roots, in one log and protocol
context, form transferable evidence
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
that the key holder signed incompatible views, except under signature
forgery; and (iv) positive acceptance of
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
a theorem boundary is a function of recorded observations and consumer-local
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
policy, not of an operator label.
2026-07-09 17:27:13 +00:00
\end { definition}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The definition is intentionally an accountability property, not a validity
property. It says when conflicting claims become attributable; it does not
cryptographically prove that the replay observation was honestly produced.
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
Throughout, ``accountability'' means signed-view and history accountability;
observation validity remains external to the mechanism.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
Section~\ref { sec:games} states clauses (i)--(iv) as games and explicit
reductions and proves the construction satisfies them.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { figure} [t]
\centering
\begin { tikzpicture} [
node distance=8mm and 8mm,
b/.style={ draw,rounded corners=2pt,align=center,minimum height=10mm,minimum width=29mm,font=\small } ,
a/.style={ -{ Latex[length=2mm]} ,thick,draw=black!60}
]
\node [b,fill=blue!6] (subject) { subject source\\ and proof corpus} ;
\node [b,fill=green!7,right=of subject] (replay) { expensive\\ deterministic replay} ;
\node [b,fill=yellow!10,right=of replay] (att) { structured replay\\ observation} ;
\node [b,fill=blue!6,right=of att] (log) { signed append-only\\ view} ;
\node [b,fill=green!7,below=12mm of log] (consumer) { lightweight consumer\\ signature + hashes + policy} ;
\draw [a] (subject)--(replay);
\draw [a] (replay)--(att);
\draw [a] (att)--(log);
\draw [a] (log)--(consumer);
\draw [a,dashed] (consumer.west) -| node[pos=.25,below,font=\scriptsize ]{ targeted independent replay} (replay.south);
\end { tikzpicture}
\caption { Trust decomposition. The log authenticates and orders the replay
operator's observation; it does not replace the theorem prover or make the
observation true.}
\label { fig:decomposition}
\end { figure}
\subsection { What is and is not transferred}
A verified receipt establishes a statement of the form:
\begin { quote}
The holder of public key $ pk $ signed a tree head committing, at position $ m $ ,
to a leaf in which the operator reports that the named declarations at commit
$ g $ replayed with the recorded axiom-name sets.
\end { quote}
It does not establish that the operator's report is true. Nor does it identify
the semantics of a theorem from its name alone. This separation is central:
\begin { center} \small
\begin { tabular} { @{ } ll@{ } }
\toprule
Layer & What it contributes \\
\midrule
Lean kernel & validity of a checked term relative to declarations and axioms \\
Replay pipeline & binding of source, toolchain, theorem names, and observations \\
Attestation signature & attribution of one replay statement \\
Merkle log & position binding and append-only view commitments \\
Consumer policy & acceptability of the recorded boundary \\
Independent replay & detection of fabricated operator observations \\
\bottomrule
\end { tabular}
\end { center}
2026-07-09 16:02:59 +00:00
\subsection { Adversary model}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The network adversary may replay, delay, suppress, or substitute messages. The
operator may be malicious: it may construct arbitrary leaves, sign arbitrary
heads, label results arbitrarily, and present different signed views to
different consumers. We assume collision resistance of SHA-256 for the log,
EUF-CMA security of the head-signature scheme, and correct initial acquisition
of the operator public key.
The model deliberately does not cryptographically exclude fabricated kernel
2026-08-15 12:17:03 +00:00
observations; the same holds when the operator's replay harness is defective
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
rather than dishonest. Whether the kernel actually ran as claimed is a
fact about a physical execution on the operator's machine. The mechanism instead makes the claimed execution target precise
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
enough for a third party to replay.
\subsection { Consumer goals}
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
Each goal below is formalized as a game in Section~\ref { sec:games} .
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { description} [leftmargin=1.5em,itemsep=5pt]
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\item [G1: Authentic position binding.] If a consumer accepts leaf $ d $ at
index $ m $ under signed head $ ( n,r ) $ : the head was issued by the key holder
except under signature forgery, and no leaf distinct from $ d $ can also be
opened at position $ m $ under that head except under hash collision.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\item [G2: Local append-only history.] A consumer that persists $ ( n,r ) $ accepts
a later view only if it is the same view or a verified extension. Two valid
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
heads of equal size and unequal roots, in one log context, are transferable
evidence that the key holder signed incompatible views. Unequal-size forks
require retained history, gossip, or a witness. The transition discipline
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
itself is syntactic, enforced by the pin rule (\S 4.3) by construction; the semantic
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
content --- an opened position cannot change value across accepted views ---
is a theorem (\S \ref { sec:games} ).
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\item [G3: Policy separation.] The operator's positive label cannot make a
certificate acceptable. The consumer recomputes boundary conformance from
observations and local policy. Operator failure labels may be treated as a
conservative veto.
2026-07-09 16:02:59 +00:00
\end { description}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\subsection { Boundary conformance, not semantic identity}
For certificate $ c $ , let $ \Obs _ a ( c ) $ be the axiom-name set recorded in leaf
$ a $ , and let $ \Policy ( c ) $ be the consumer's allowed set. Define
2026-07-09 16:02:59 +00:00
\[
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\mathsf { boundary\_ ok} _ a(c) \iff \Obs _ a(c)=\Policy (c).
2026-07-09 16:02:59 +00:00
\]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Exact equality detects both additional assumptions and drift in the declared
assurance interface. A missing expected axiom is not automatically a logical
defect: it may indicate a strengthened theorem, a changed statement, a bypassed
abstraction boundary, or stale policy. The consumer therefore rejects or
requires review rather than interpreting the drift.
This predicate is intentionally narrower than ``the intended theorem was
proved.'' The deployed system identifies a declaration by repository commit
and name. A stronger future schema should include canonical digests of the
elaborated theorem type and of the types of declarations in its axiom cone.
\section { Construction} \label { sec:construction}
\subsection { RFC 9162 tree}
Let $ \Hh $ be SHA-256. For byte string $ d $ and 32-byte values $ x,y $ define
2026-07-09 16:02:59 +00:00
\[
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\hleaf (d)=\Hh (\mathtt { 0x00} \parallel d),\qquad
\hnode (x,y)=\Hh (\mathtt { 0x01} \parallel x\parallel y).
2026-07-09 16:02:59 +00:00
\]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
For leaf list $ D = [ d _ 0 , \ldots ,d _ { n - 1 } ] $ :
2026-07-09 16:02:59 +00:00
\[
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\MTH ([])=\Hh (\epsilon ),\qquad \MTH ([d])=\hleaf (d),
2026-07-09 16:02:59 +00:00
\]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
and for $ n> 1 $ ,
2026-07-09 17:27:13 +00:00
\[
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\MTH (D)=\hnode (\MTH (D[0{ :} k]),\MTH (D[k{ :} n])),
2026-07-09 17:27:13 +00:00
\]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
where $ k $ is the largest power of two strictly smaller than $ n $ . Inclusion and
consistency proofs are the RFC~9162 algorithms~\cite { ct2} .
\subsection { Signed tree heads}
A tree head contains schema-version and type tags, a log identifier, tree
size, root hash, timestamp, and hash-algorithm identifier. The canonical JSON serialization of
those fields is signed with Ed25519. The log identifier and version tag prevent
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
cross-log and cross-protocol replay. We call the leaf history a head
commits to a \emph { view} , and write \emph { signed view} for that history
as represented by its signed head.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
Since tree size 14, every head additionally carries a \emph { deterministic}
SLH-DSA-SHA2-128s (FIPS~205) signature over the same payload. The
co-signature is additive: the Ed25519 signature remains the one every
consumer must verify, and heads published before size 14 carry no
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
post-quantum signature --- the standalone verifier reports the co-signature as
absent on such heads rather than rejecting them: an append-only log
necessarily preserves the history of its own signature-scheme upgrades. Determinism is chosen as an audit primitive: a
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
deterministic re-sign of the same payload is byte-comparable, so ``same
input, same signature'' becomes a diff rather than an assurance. The
co-signature closes a further loop: its parameter set is exactly the one
whose verification path is attested at leaf 18
(\S \ref { sec:slhdsa} , Appendix~\ref { app:slhtiers} ).
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The current implementation records signing-backend provenance alongside the
signature, but that provenance is not execution attestation: an Ed25519
signature does not identify the program that produced it. The public system
therefore treats the claimed signing implementation as operator-reported
context, not as a property proved by the signature.
\subsection { Receipts and pinning}
A receipt contains the leaf index, sibling path, and signed head. A consumer
first verifies the head signature and then reconstructs the root. For history,
a local pin $ ( n _ { \rm pin } ,r _ { \rm pin } ) $ evolves as follows:
\begin { itemize} [leftmargin=1.6em,itemsep=2pt]
\item same size: accept iff roots match; otherwise retain both signed heads as
same-size fork evidence;
\item larger size: accept iff a consistency proof verifies, then update;
\item smaller size: reject as rollback.
2026-07-09 16:02:59 +00:00
\end { itemize}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
We call this transition discipline the \emph { pin rule} , and the persisted
pair $ ( n _ { \mathrm { pin } } ,r _ { \mathrm { pin } } ) $ the \emph { pin-store} .
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Freshness is an external availability policy. A persisted pin detects rollback
relative to local history; it does not prove that a client sees the globally
latest signed head.
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\paragraph { Notation summary.}
For reference across the security analysis:
\begin { center} \small
\begin { tabular} { @{ } ll@{ } }
\toprule
$ \Hh $ ;\ $ \hleaf ( d ) $ ;\ $ \hnode ( x,y ) $ & SHA-256; leaf hash $ \Hh ( \mathtt { 0 x 00 } \| d ) $ ; node hash $ \Hh ( \mathtt { 0 x 01 } \| x \| y ) $ \\
$ D $ , $ d $ , $ m $ , $ n $ & leaf list; leaf bytes; leaf index; tree size \\
$ \MTH ( D ) $ ;\ $ k $ & Merkle root; split point (largest power of two below $ n $ ) \\
$ \Path ( m,D ) $ ;\ $ \Root ( v,m,n,P ) $ & inclusion path (leaf to root); path refold \\
$ \mathsf { Open } ( d,m,n,P,r ) $ & accepting opening: $ m<n $ and $ \Root ( \hleaf ( d ) ,m,n,P ) = r $ \\
2026-08-17 10:54:08 +00:00
$ \ConsRec $ ;\ $ \mathsf { Ext } $ & recursive consistency verifier; pin-rule transition (\S \ref { sec:games} ) \\
$ C $ ;\ $ b $ & consistency proof; flag: old root is the pinned $ r _ 0 $ ($ \top $ ) vs read from $ C $ \\
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
$ \Obs _ a ( c ) $ ;\ $ \Policy ( c ) $ & axiom names recorded in leaf $ a $ ; consumer's allowed set \\
$ \chi _ { \rm enc } $ ;\ $ \chi = ( \chi _ { \rm enc } ,pk ) $ & payload-encoded head context; full context with the key \\
$ h = ( n,r,t; \sigma ) $ ;\ $ \mathsf { Vf } _ { pk } $ & signed head (size, root, timestamp); signature check \\
$ \mathsf { Ev } _ \chi $ & same-context, equal-size, unequal-root evidence pair \\
$ \mathcal { B } _ { \rm pb } , \mathcal { B } _ { \rm hist } , \mathcal { B } _ { \rm ha } , \mathcal { B } _ { \rm fr } $ & the named explicit reductions of \S \ref { sec:games} \\
$ Q $ ;\ $ \mathbf { Adv } $ & signing-oracle query set; winning probability (keyed games) \\
\bottomrule
\end { tabular}
\end { center}
2026-07-09 16:02:59 +00:00
\section { Security analysis} \label { sec:security}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
This section states the consumer-facing arguments in the form used by the Lean
mechanization. The proofs are elementary but explicit: successful false
openings yield concrete SHA-256 collisions rather than appealing to an informal
2026-07-17 07:42:45 +00:00
``Merkle trees are secure'' statement. The explicitness is load-bearing: over a
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
fixed-width hash, ``some collision exists'' is trivially true by counting;
each soundness statement therefore names an explicit extractor function,
and the corpus pins a machine-checked guard that each extractor's output
really is a collision (distinct preimages, equal digests).
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\subsection { Inclusion}
2026-07-09 16:02:59 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Let $ \Root ( v,m,n,P ) $ recursively fold value $ v $ at position $ m $ through proof
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
path $ P $ using the same largest-power-of-two decomposition as $ \MTH $ . Both
$ \Root $ and $ \ConsRec $ are partial (the mechanization's \code { Option} ):
malformed shapes return a distinguished rejection value, and an equation such
as $ \Root ( \cdot ) = \MTH ( D ) $ asserts acceptance with that output.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { lemma} [Domain separation]
For all byte strings $ d $ and 32-byte values $ x,y $ ,
$ \mathtt { 0 x 00 } \parallel d \neq \mathtt { 0 x 01 } \parallel x \parallel y $ .
2026-07-09 16:02:59 +00:00
\end { lemma}
\begin { proof}
The first byte differs.
\end { proof}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { theorem} [Inclusion completeness]
For every non-empty $ D $ , every $ m<|D| $ ,
2026-07-09 16:02:59 +00:00
\[
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\Root (\hleaf (D[m]),m,|D|,\Path (m,D))=\MTH (D).
2026-07-09 16:02:59 +00:00
\]
\end { theorem}
\begin { proof}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
By structural induction on $ |D| $ . The singleton case is immediate. For a split
$ D = L \| R $ , the honest path is the recursive path inside the side containing $ m $
followed by the other side's root. The induction hypothesis reconstructs the
selected child root, and the final node hash reconstructs $ \MTH ( D ) $ .
2026-07-09 16:02:59 +00:00
\end { proof}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { theorem} [Inclusion soundness: position binding]
There is an explicit extractor $ \mathcal { E } _ { \rm incl } $ such that, given $ D $ ,
$ m<|D| $ , $ d \neq D [ m ] $ , and a path $ P $ satisfying
\[
\Root (\hleaf (d),m,|D|,P)=\MTH (D),
\]
$ \mathcal { E } _ { \rm incl } ( D,m,d,P ) $ returns two distinct SHA-256 preimages with
the same digest.
2026-07-09 16:02:59 +00:00
\end { theorem}
\begin { proof}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Recompute the honest tree and replay the accepting reconstruction from the root
downward. At each visited internal node, compare the adversarial and honest
node preimages. If they differ while their digests agree, output the collision.
Otherwise both child values agree and descent continues along the path. At the
terminal leaf, equality of digests with $ d \neq D [ m ] $ yields a leaf-hash
collision. Domain separation rules out interpreting a leaf preimage as a node
preimage without already producing a collision.
2026-07-09 16:02:59 +00:00
\end { proof}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\subsection { Consistency}
2026-07-09 16:02:59 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The recursive verifier $ \ConsRec ( n _ 0 ,n _ 1 ,C,b,r _ 0 ) $ reconstructs an old and new
root from proof $ C $ , a flag $ b $ indicating whether the old root is implicit,
and pinned value $ r _ 0 $ . Malformed shapes return rejection.
\begin { theorem} [Consistency soundness of the recursive model]
There is an explicit extractor $ \mathcal { E } _ { \rm cons } $ such that, whenever
$ |D _ 0 | = n _ 0 \le n _ 1 = |D _ 1 | $ , $ D _ 0 \neq D _ 1 [ 0 { : } n _ 0 ] $ , and
\[
\ConsRec (n_ 0,n_ 1,C,\top ,\MTH (D_ 0))
=(\MTH (D_ 0),\MTH (D_ 1)),
\]
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
$ \mathcal { E } _ { \rm cons } ( D _ 0 ,D _ 1 ,C ) $ returns a SHA-256 collision. (The hypothesis supplies the honest
$ \MTH ( D _ 0 ) $ as the pinned value; \S 5.3 measures the deployed flow, which
has no such mechanized supplier.)
2026-07-09 16:02:59 +00:00
\end { theorem}
2026-07-09 17:27:13 +00:00
\begin { proof}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The new-root component is a hash fold over the shape of the $ n _ 1 $ tree. Compare
it with the honest $ D _ 1 $ tree. Either the first differing preimage gives a
collision, or every consumed proof node equals the corresponding honest node.
In the latter case, the old-root component is the canonical fold of the honest
prefix $ D _ 1 [ 0 { : } n _ 0 ] $ , so acceptance implies
$ \MTH ( D _ 0 ) = \MTH ( D _ 1 [ 0 { : } n _ 0 ] ) $ . The two equal-sized leaf lists differ; descend
through their identically shaped honest trees to extract the first hash
collision.
2026-07-09 16:02:59 +00:00
\end { proof}
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
The theorem's hypothesis pins the honest old root $ \MTH ( D _ 0 ) $ . The deployed
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
flow contains nothing mechanized that guarantees the pinned value is the
honest old root; the next subsection measures the iterative verifier's
behavior when only the claimed sizes constrain its reconstruction.
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { proposition} [Pin-store safety]
Assume EUF-CMA security of the head signature and collision resistance of
SHA-256. A consumer following the pin transition accepts only a nondecreasing
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
sequence of sizes; if leaf lists are exhibited for two accepted heads,
they are prefix-related except under collision (see the mapping paragraph
of \S \ref { sec:games} ). Two accepted
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
heads under the same key, in one log context, with equal size and unequal
roots are transferable evidence that the key holder signed incompatible
views.
2026-07-09 16:02:59 +00:00
\end { proposition}
\begin { proof}
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
Rollback is rejected syntactically. At equal size the transition is accepted
only with equal roots; if the two exhibited equal-length leaf lists differed,
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
whole-tree root binding (each root determines its committed leaf list up
to collision) would extract a SHA-256 collision, so under collision
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
resistance the lists are equal. A larger head is accepted only after a
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
consistency proof, so non-prefix acceptance yields a collision by the previous
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
theorem. Equal-size unequal roots in one log context, with valid signatures, are two
conflicting statements attributable to the key holder, except under signature
forgery.
2026-07-09 16:02:59 +00:00
\end { proof}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { proposition} [Policy separation]
For fixed local policy $ \Policy $ , the boundary-conformance result for every
certificate is a function only of $ \Obs _ a ( c ) $ and $ \Policy ( c ) $ . An operator
label cannot change a nonconforming observation into a conforming one.
2026-07-09 16:02:59 +00:00
\end { proposition}
\begin { proof}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The comparison is set equality and takes no positive operator label as input.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
A deployment may conservatively treat an operator failure label as a veto, but
a veto cannot grant acceptance.
2026-07-09 16:02:59 +00:00
\end { proof}
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\subsection { Scope of the deployed consistency claim} \label { sec:seamscope}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The Lean theorem covers the recursive predicate above. The deployed iterative
verifier follows the familiar RFC bit-navigation algorithm. Differential
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
testing discovered that the two verifiers are not extensionally equal on
malformed size claims, every observed divergence being accepted only by the
iterative verifier: for example, a valid proof for a $ 2 \to 3 $ transition can
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
be accepted under the false old-size claim $ 1 \to 3 $ when paired with the size-2
root. The mechanism is elementary: the iterative algorithm seeds its
reconstruction with the supplied old root and consults the size claims only as
bit-navigation state, so several distinct old-size claims navigate one proof
identically. In 73,573 lied-size boundary cases, 3,867 divergences were
observed; all were one-sided (deployed accepts, recursive model rejects).
2026-08-15 12:17:03 +00:00
The root cause was later identified and closed: the deployed loop omitted
RFC~9162 \S 2.1.4.2 Step~7's terminal $ sn = 0 $ condition; with the conjunct
restored the pinned family shows zero divergences (three-way regression:
deployed verifier, recursive model, independent RFC transliteration).
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The intended consumer flow binds $ ( n _ 0 ,r _ 0 ) $ in local persistent state and
binds $ ( n _ 1 ,r _ 1 ) $ together in a signed head. The present corpus does not prove
a refinement theorem from that operational invariant to the recursive
predicate. Consequently the public attestation says exactly this: the model is
proved; deployment correspondence is finite-tested and relies on an
unmechanized authentic-size/root invariant.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\subsection { Scheme-level games and a composition theorem} \label { sec:games}
The theorems above bind single artifacts to a reference leaf list. This
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
subsection lifts them to the scheme. Readers content with the component
theorems can skim the statements --- the four games,
Definition~\ref { def:formal} , Theorem~\ref { thm:main} --- and the closing
mapping paragraph; the proofs add explicit reductions but no new assumptions.
Fix once, for the entire subsection, an \emph { encoded context}
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
\[ \chi _ { \rm enc } = ( \text { log identifier } , \ \text { schema and type tags } , \
\text { hash-algorithm identifier} );\]
every head below is required to encode $ \chi _ { \rm enc } $ in its canonical
payload, matching the deployed head format of \S 4.2. The verification key is
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
deliberately \emph { not} part of the payload: it is the external verification
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
parameter, and we write $ \chi = ( \chi _ { \rm enc } ,pk ) $ for the full context once
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
a key exists --- the keyed games fix $ \chi _ { \rm enc } $ , run
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
$ \mathsf { KeyGen } $ , and then set $ \chi $ .
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
The results come in two levels. The theorems are unconditional: explicit
algorithms turn any winning transcript into a concrete SHA-256 collision,
and the signature reductions lose exactly one EUF-CMA forgery. Hardness
enters only at the end: SHA-256 is a fixed, unkeyed function, so following
the human-ignorance treatment~\cite { rogaway} , Corollary~\ref { cor:security}
states the constructive consequence --- an explicit winner yields an explicit
collision finder --- and labels the security reading as the engineering
judgment it is. (A keyed-family restatement is routine and omitted.)
The position-binding and history games are non-interactive: they are
universal statements over accepted transcripts, independent of how a
transcript was obtained, so adaptive interaction with a proof-issuing
service collapses into the adversary's final output. Signatures constrain
two other parties --- an outsider forging an ordinary head
($ \mathsf { HEAD } $ ), and a third party fabricating equivocation evidence
($ \mathsf { FORK } $ ); those games have a secret and a signing oracle, and their
advantage is the probability, over key generation and the adversary's coins,
2026-07-17 20:20:42 +00:00
of winning. The adversary may query the signing oracle adaptively on
context-valid payloads; $ Q $ denotes the set of exact queried payload bytes.
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\paragraph { The games at a glance.}
\begin { center} \footnotesize
\begin { tabular} { @{ } lllll@{ } }
\toprule
Game & Adversary & Secrets & Wins by exhibiting & Consequence \\
\midrule
$ \mathsf { PB } $ & operator (holds key) & none & two openings, one position, $ d \neq d' $ & collision (Thm.~\ref { thm:pb} ) \\
$ \mathsf { HIST } $ & operator & none & accepted chain, changed opened value & collision (Thm.~\ref { thm:hist} ) \\
$ \mathsf { HEAD } $ & outsider & signing oracle & valid head never issued & forgery (Thm.~\ref { thm:head} ) \\
$ \mathsf { FORK } $ & third party & signing oracle & evidence pair not fully issued & forgery (Thm.~\ref { thm:fork} ) \\
\bottomrule
\end { tabular}
\end { center}
\noindent Policy separation is deliberately not a game: it is a deterministic
property of the verdict algorithm (Lemma~\ref { lem:policy} ).
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\paragraph { Accepted-artifact syntax.}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
A head is $ h = ( n,r,t; \sigma ) $ , with $ t $ a timestamp; its canonical payload is
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
$ \mathsf { EncodeHead } _ { \chi _ { \rm enc } } ( n,r,t ) $ as in \S 4.2, and $ \mathsf { Vf } _ { pk } ( h ) = 1 $
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
iff its Ed25519 signature verifies. An \emph { opening}
of leaf $ d $ at index $ m $ under $ ( n,r ) $ is a path $ P $ with $ m<n $ and
$ \Root ( \hleaf ( d ) ,m,n,P ) = r $ (acceptance in the Option sense of \S 5.1); write
$ \mathsf { Open } ( d,m,n,P,r ) = 1 $ . An \emph { extension} from $ ( n _ 0 ,r _ 0 ) $ to
$ ( n _ 1 ,r _ 1 ) $ by proof $ C $ is exactly a pin-rule transition: either $ n _ 0 = n _ 1 $ ,
$ r _ 0 = r _ 1 $ , and $ C $ is empty, or $ n _ 0 <n _ 1 $ and
$ \ConsRec ( n _ 0 ,n _ 1 ,C, \top ,r _ 0 ) = ( r _ 0 ,r _ 1 ) $ ; write
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
$ \mathsf { Ext } ( n _ 0 ,r _ 0 ,n _ 1 ,r _ 1 ,C ) = 1 $ .
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\begin { lemma} [Monotone extensions]\label { lem:mono}
If $ \mathsf { Ext } ( n _ 0 ,r _ 0 ,n _ 1 ,r _ 1 ,C ) = 1 $ then $ n _ 0 \le n _ 1 $ ; accepted chains of
extensions have nondecreasing sizes.
\end { lemma}
\begin { proof}
Immediate from the two disjuncts of $ \mathsf { Ext } $ .
\end { proof}
\begin { lemma} [Payload injectivity]\label { lem:inj}
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
For fixed $ \chi _ { \rm enc } $ , $ \mathsf { EncodeHead } _ { \chi _ { \rm enc } } $ is
injective on $ ( n,r,t ) $ ; in particular, distinct $ ( n,r ) $ pairs yield distinct
payload byte strings.
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\end { lemma}
\begin { proof}
The canonical serialization emits a fixed set of keys in sorted order with
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
fixed separators; the size is a decimal integer, the root a fixed-length
lowercase hex string, and the timestamp a JSON string with injective
escaping, all under distinct fixed keys, so the encoding parses back
uniquely. This is injectivity of the specified serializer over the restricted
head schema, not a claim about arbitrary JSON.
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\end { proof}
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\paragraph { Game $ \mathsf { PB } $ (position binding).}
$ \mathcal { A } $ outputs $ ( n,r,m,d,P,d',P' ) $ and wins iff $ d \neq d' $ and
\[ \mathsf { Open } ( d,m,n,P,r ) = \mathsf { Open } ( d',m,n,P',r ) = 1 . \]
\begin { theorem} [Scheme position binding]\label { thm:pb}
There is an explicit algorithm $ \mathcal { B } _ { \rm pb } $ that, whenever
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
$ \mathcal { A } $ wins $ \mathsf { PB } $ , outputs two distinct byte strings with
equal SHA-256 digests, using at most the $ 2 ( \lceil \log _ 2 n \rceil { + } 1 ) $ hash
evaluations of replaying the two openings, with their intermediate values
retained.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { theorem}
\begin { proof}
Both accepting folds have the shape determined by $ ( m,n ) $ and output the same
root $ r $ . Walk from the root downward along the path of $ m $ , maintaining that
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
the two transcripts agree on the current node's value. At an internal node
the transcripts present preimages $ \mathtt { 0 x 01 } \| a \| b $ and
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
$ \mathtt { 0 x 01 } \| a' \| b' $ with equal digests; since child values have fixed
32-byte width, the argument pairs are recoverable from the preimages, so
unequal pairs are a collision and equal pairs propagate agreement one level
down. If no disagreement occurs, the leaf presents $ \mathtt { 0 x 00 } \| d $ and
$ \mathtt { 0 x 00 } \| d' $ with equal digests and $ d \neq d' $ --- a collision. Since
the shapes coincide, every comparison is leaf-to-leaf or node-to-node; domain
separation would in addition make any cross-type coincidence itself a
collision of distinct strings.
\end { proof}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\paragraph { The transport algorithm.}
For the history theorem we need to move an opening backward through an
accepted extension. Recall the recursive verifiers (\S 4.1, the mechanized
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
form; malformed shapes reject); Figure~\ref { fig:transport} shows the assembly in a
small instance. With $ k $ the largest power of two below $ n $ :
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\[
\Root (v,m,n,P)=
\begin { cases}
v & n=1,\ P\ \text { exhausted} \\
\hnode (\Root (v,m,k,P'),\, s) & m<k\\
\hnode (s,\, \Root (v,m{ -} k,n{ -} k,P')) & m\ge k,
\end { cases}
\]
where $ s $ is the sibling $ P $ supplies for the current level, and
\[
\ConsRec (n_ 0,n,C,b,r)=
\begin { cases}
(v,v),\ \ v=r\ \text { if} \ b\ \text { else the next value of} \ C & n_ 0=n\\
(x,\ \hnode (y,s)) & n_ 0\le k\\
(\hnode (s,x),\ \hnode (s,y)) & n_ 0>k,
\end { cases}
\]
where in the second branch $ ( x,y ) = \ConsRec ( n _ 0 ,k,C,b,r ) $ and $ s $ is the next
value of $ C $ , and in the third branch $ s $ is the next value of $ C $ and
$ ( x,y ) = \ConsRec ( n _ 0 { - } k,n { - } k,C, \bot ,r ) $ . Both recursions' shapes are
determined by their integer arguments, not by the adversary, so two
computations at the same arguments traverse the same nodes and there are no
mismatched stopping points.
2026-07-17 20:20:42 +00:00
\begin { figure} [htbp]
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\centering
\begin { tikzpicture} [
every node/.style={ font=\scriptsize } ,
lf/.style={ draw,minimum width=6.5mm,minimum height=5mm,inner sep=1pt} ,
nd/.style={ draw,rounded corners=1pt,minimum width=7.5mm,minimum height=4.5mm,inner sep=1pt,fill=white} ,
fr/.style={ nd,draw=blue!60!black,thick,fill=blue!8} ,
pn/.style={ nd,draw=black!55,dashed,fill=black!4} ,
sb/.style={ draw=orange!85!black,thick} ,
op/.style={ draw=red!70!black,very thick}
]
\foreach \i in { 0,...,7} \node [lf] (d\i ) at (0.95*\i ,0) { $ \i $ } ;
\node [nd,sb] (p01) at (0.475,0.95) { } ;
\node [nd,sb] (p23) at (2.375,0.95) { } ;
\node [fr] (p45) at (4.275,0.95) { $ B $ } ;
2026-07-17 20:20:42 +00:00
\node [pn] (p67) at (6.175,0.95) { $ s $ } ;
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\node [fr] (q03) at (1.425,1.9) { $ A $ } ;
2026-07-17 20:20:42 +00:00
\node [nd] (q47) at (5.225,1.9) { } ;
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\node [nd] (rt) at (3.325,2.85) { $ r _ 1 $ } ;
\foreach \a /\b in { d0/p01,d1/p01,d2/p23,d3/p23,d4/p45,d5/p45,d6/p67,d7/p67,p01/q03,p23/q03,p45/q47,p67/q47,q03/rt,q47/rt}
\draw (\a ) -- (\b );
\draw [op] (d1.north) -- (p01); \draw [op] (p01) -- (q03); \draw [op] (q03) -- (rt);
\draw [decorate,decoration={brace,mirror,raise=3pt},blue!60!black]
([xshift=-1pt]d0.south west) -- ([xshift=1pt]d3.south east)
node[midway,below=5pt]{ $ T ^ * $ (contains $ m { = } 1 $ )} ;
\draw [decorate,decoration={brace,mirror,raise=3pt},black!60]
([xshift=-1pt]d4.south west) -- ([xshift=1pt]d5.south east)
node[midway,below=5pt]{ $ [ 4 , 6 ) $ } ;
\node [nd,draw=blue!60!black,thick] (r0) at (7.8,2.6) { $ r _ 0 $ } ;
\node [align=left,anchor=north west] at (6.95,2.25)
{ $ r _ 0 = \hnode ( A,B ) $ \\ [1pt] $ P _ 0 = ( \, \text { siblings in } T ^ * \, ) \, \| \, [ B ] $ } ;
\end { tikzpicture}
\caption { Prefix transport in the $ 6 \to 8 $ instance, opening at index $ m = 1 $ .
The accepted consistency transcript pins the frontier values $ A,B $ covering
$ [ 0 , 6 ) $ (solid blue) and consumes the proof value $ s $ covering $ [ 6 , 8 ) $
(dashed). Comparing the opening's fold (red path) with the transcript fixes
the opening's value at the frontier subtree $ T ^ * $ containing $ m $ . Below
$ T ^ * $ the opening keeps its own siblings (orange); above it, the old-root
fold $ r _ 0 = \hnode ( A,B ) $ supplies the one remaining sibling $ B $ . The assembled
$ P _ 0 $ is the opening's inner path with the new tree's top sibling replaced
by $ B $ .}
\label { fig:transport}
\end { figure}
2026-07-17 20:20:42 +00:00
\begin { samepage}
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\begin { lemma} [Prefix transport]\label { lem:transport}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
Suppose $ m<n _ 0 \le n _ 1 $ and
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\[ \mathsf { Ext } ( n _ 0 ,r _ 0 ,n _ 1 ,r _ 1 ,C ) = 1 , \qquad \mathsf { Open } ( d,m,n _ 1 ,P,r _ 1 ) = 1 . \]
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
There is an explicit algorithm $ \mathsf { Transport } $ returning either two
distinct byte strings with equal SHA-256 digests, or a path $ P _ 0 $ with
$ \mathsf { Open } ( d,m,n _ 0 ,P _ 0 ,r _ 0 ) = 1 $ , using at most the hash evaluations of
replaying the two accepted transcripts.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { lemma}
2026-07-17 20:20:42 +00:00
\end { samepage}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\begin { proof}
If $ n _ 0 = n _ 1 $ then $ r _ 0 = r _ 1 $ and $ P _ 0 = P $ . Otherwise
$ \ConsRec ( n _ 0 ,n _ 1 ,C, \top ,r _ 0 ) = ( r _ 0 ,r _ 1 ) $ , and we prove the following claim by
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
strong induction on $ n $ --- both sub-calls strictly decrease it --- for every
sub-call arising in the accepted transcript:
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\emph { Claim.} If $ \ConsRec ( n _ 0 ',n,C',b, \cdot ) $ accepts with output $ ( x,y ) $ ,
and $ \mathsf { Open } ( d,m',n,P', \rho ) = 1 $ with $ m'<n _ 0 ' $ and $ \rho = y $ , then
either an explicit collision is output, or a path $ P _ 0 ' $ with
$ \mathsf { Open } ( d,m',n _ 0 ',P _ 0 ',x ) = 1 $ .
\emph { Base} ($ n _ 0 ' = n $ ): the transcript gives $ x = y = \rho $ , and $ P _ 0 ' = P' $ .
\emph { Case} $ n _ 0 ' \le k $ , $ k $ the split of $ n $ : the transcript's second
component is $ y = \hnode ( y _ L,s ) $ with $ ( x,y _ L ) $ the left sub-call's output.
Since $ m'<n _ 0 ' \le k $ , the opening's top step is
$ \rho = \hnode ( u,s _ P ) $ with $ u = \Root ( \hleaf ( d ) ,m',k, \cdot ) $ accepted on the
opening's remaining path. The two preimages of $ \rho = y $ are
$ \mathtt { 0 x 01 } \| y _ L \| s $ and $ \mathtt { 0 x 01 } \| u \| s _ P $ : if the pairs differ,
output the collision; otherwise $ u = y _ L $ , and the inductive hypothesis applied
to the left sub-call (output $ ( x,y _ L ) $ ) and the sub-opening (root value
$ u = y _ L $ ) yields a collision or $ P _ 0 ' $ with
$ \mathsf { Open } ( d,m',n _ 0 ',P _ 0 ',x ) = 1 $ , which is the claim since the first
component passes through this branch unchanged.
\emph { Case} $ n _ 0 '>k $ : the transcript consumed $ s $ and the right sub-call
returned $ ( x _ R,y _ R ) $ , so $ x = \hnode ( s,x _ R ) $ and $ y = \hnode ( s,y _ R ) $ . Because
$ k<n _ 0 ' \le n $ and $ k $ is the largest power of two below $ n $ , $ k $ is also the
largest power of two below $ n _ 0 ' $ (there is no power of two strictly between
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
$ k $ and $ n $ ; mechanized in the corpus as \code { kbelow_ prefix_ eq} ), so the $ n _ 0 ' $ -tree splits at $ k $ as well and
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
$ x = \hnode ( s,x _ R ) $ is precisely its root form.
\emph { If} $ m'<k $ : the opening's top step is $ \rho = \hnode ( u,s _ P ) $ with
$ u = \Root ( \hleaf ( d ) ,m',k, \cdot ) $ accepted on the remaining path
$ P' _ { \rm in } $ . Compare preimages of $ \rho = y $ : unequal pairs are a collision;
otherwise $ u = s $ and $ s _ P = y _ R $ , so the remaining path opens $ d $ at $ m' $ in the
left subtree with root value $ s $ , and
$ P _ 0 ' \coloneqq P' _ { \rm in } \, \| \, [ x _ R ] $ satisfies
$ \Root ( \hleaf ( d ) ,m',n _ 0 ',P _ 0 ' ) = \hnode ( s,x _ R ) = x $ : an accepting opening,
assembled from the opening's own inner path and the transcript's right
first-component. \emph { If} $ m' \ge k $ : the opening's top step is
$ \rho = \hnode ( s _ P,u ) $ with $ u $ accepted at $ m' - k $ in the right subtree;
comparing preimages of $ \rho = y $ either yields a collision or $ s _ P = s $ and
$ u = y _ R $ , and the inductive hypothesis on the right sub-call (output
$ ( x _ R,y _ R ) $ , sizes $ n _ 0 ' - k \le n - k $ , index $ m' - k<n _ 0 ' - k $ ) gives a collision or
$ P _ 0 '' $ opening $ d $ at $ m' - k $ under $ x _ R $ ; then
$ P _ 0 ' \coloneqq P _ 0 '' \, \| \, [ s ] $ opens $ d $ at $ m' $ under $ x = \hnode ( s,x _ R ) $ .
The top-level instance of the claim has $ \rho = r _ 1 = y $ and $ x = r _ 0 $ by
acceptance, which is the lemma. Every comparison is between two explicit
32-byte-child node preimages, so each disagreement is a concrete collision;
every assembled path entry is either an entry of $ P $ , an entry of $ C $ , or a
sub-call output value, all present in the replayed transcripts.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { proof}
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
In the smallest growth case $ 2 \to 3 $ --- the log's own transition in
\S \ref { sec:seamscope} --- $ n _ 0 $ is a power of two: the frontier is the whole
old tree and $ P _ 0 $ is simply the opening's within-prefix tail.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\paragraph { Game $ \mathsf { HIST } $ (local history binding).}
2026-08-17 10:54:08 +00:00
$ \mathcal { A } $ outputs a chain of head values $ h _ 0 , \dots ,h _ \ell $ , transition
proofs $ C _ 1 , \dots ,C _ \ell $ with $ \mathsf { Ext } ( n _ { i - 1 } ,r _ { i - 1 } ,n _ i,r _ i,C _ i ) = 1 $
for every $ 1 \le i \le \ell $ , indices $ 0 \le a<b \le \ell $ , an index $ m<n _ a $ , and
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
openings with
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
$ \mathsf { Open } ( d,m,n _ a,P,r _ a ) = \mathsf { Open } ( d',m,n _ b,P',r _ b ) = 1 $ and
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
$ d \neq d' $ . $ \mathcal { A } $ wins iff everything verifies. (The chain is the
Merkle-level state sequence a consumer's pin traverses; authentication is
$ \mathsf { HEAD } $ 's job, and the binding properties quantify over accepted
transcripts regardless of provenance.)
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\begin { theorem} [History binding]\label { thm:hist}
There is an explicit algorithm $ \mathcal { B } _ { \rm hist } $ that, whenever
$ \mathcal { A } $ wins $ \mathsf { HIST } $ , outputs a SHA-256 collision, using
2026-08-17 10:54:08 +00:00
$ O ( \ell \log n _ \ell ) $ hash evaluations.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { theorem}
\begin { proof}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
By Lemma~\ref { lem:mono} , $ m<n _ a \le n _ i $ for all $ i \ge a $ . Walk $ t $ from $ b $
down to $ a { + } 1 $ , maintaining an accepting opening of $ d' $ at $ m $ under
$ ( n _ t,r _ t ) $ . If $ n _ { t - 1 } = n _ t $ then $ \mathsf { Ext } $ forces $ r _ { t - 1 } = r _ t $ and
the opening carries over unchanged; if $ n _ { t - 1 } <n _ t $ , apply
Lemma~\ref { lem:transport} to $ C _ t $ and the current opening, obtaining a
collision (done) or an accepting opening under $ ( n _ { t - 1 } ,r _ { t - 1 } ) $ . Arriving
at $ h _ a $ yields two accepting openings of $ d \neq d' $ at $ m $ under
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
$ ( n _ a,r _ a ) $ , and Theorem~\ref { thm:pb} extracts the collision. Accepted
transcripts have their RFC-determined logarithmic length --- malformed
lengths reject --- so the walk costs at most the evaluations of replaying the
2026-08-17 10:54:08 +00:00
$ \ell $ transition transcripts and the two openings.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { proof}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\paragraph { Game $ \mathsf { HEAD } $ (head authenticity).}
A challenger runs $ \mathsf { KeyGen } $ and signs, on the operator's behalf, the
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
canonical payloads the operator issues in context $ \chi _ { \rm enc } $ (query
set $ Q $ ). The adversary, without the key, outputs a head $ h $ and wins iff
$ \mathsf { Vf } _ { pk } ( h ) = 1 $ , $ h $ encodes $ \chi _ { \rm enc } $ , and $ h $ 's payload is
not in $ Q $ .
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\begin { theorem} [Head authenticity]\label { thm:head}
For every $ \mathcal { A } $ there is an explicit $ \mathcal { B } _ { \rm ha } $ with
$ \mathbf { Adv } ^ { \mathsf { HEAD } } ( \mathcal { A } ) \le
\mathbf { Adv} ^ { \text { euf-cma} } (\mathcal { B} _ { \rm ha} )$ : a winning head's exact
payload bytes were never queried, so its valid signature is an existential
forgery, which $ \mathcal { B } _ { \rm ha } $ outputs.
\end { theorem}
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\paragraph { Game $ \mathsf { FORK } $ (fork evidence).}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
Define the context-scoped evidence predicate:
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
$ \mathsf { Ev } _ \chi ( h,h' ) = 1 $ iff both signatures verify under $ pk $ , both heads
encode the same $ \chi _ { \rm enc } $ , the tree sizes are equal, and the roots
differ. Heads of
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
different logs, schema versions, or hash algorithms never form evidence ---
one key legitimately operating two logs must not be classifiable as
equivocating. \emph { Completeness} is by construction: if the key holder signs
two equal-size, unequal-root heads in one context, the pair itself satisfies
$ \mathsf { Ev } _ \chi $ ; producing it requires retention and comparison, not
cooperation. \emph { Frame resistance} is the game: the challenger signs the
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
operator's issued payloads in $ \chi _ { \rm enc } $ (query set $ Q $ ); the
adversary, without the key, outputs $ ( h,h' ) $ and wins iff $ \mathsf { Ev } _ \chi ( h,h' ) = 1 $ and at
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
least one of the two payloads is not in $ Q $ . This is an
\emph { issued-message attribution} game: a valid evidence pair proves the key
holder signed both conflicting payloads, except with forgery probability.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\begin { theorem} [Frame resistance]\label { thm:fork}
For every $ \mathcal { A } $ there is an explicit $ \mathcal { B } _ { \rm fr } $ with
$ \mathbf { Adv } ^ { \mathsf { FORK } } ( \mathcal { A } ) \le
\mathbf { Adv} ^ { \text { euf-cma} } (\mathcal { B} _ { \rm fr} )$ .
\end { theorem}
\begin { proof}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
A winning pair contains a head whose exact canonical payload bytes were never
queried to the signing oracle; its valid signature is an existential forgery,
which $ \mathcal { B } _ { \rm fr } $ outputs.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { proof}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
\begin { lemma} [Policy separation --- Proposition~2 restated for the scheme package]\label { lem:policy}
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
For every leaf $ a $ and certificate $ c $ , the verdict computed by
$ \mathsf { Verdict } $ equals $ [ \Obs _ a ( c ) = \Policy ( c ) ] $ ; it reads no operator
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
label, and acceptance consults the operator's status only as a veto. This is
a deterministic property of the $ \mathsf { Verdict } $ algorithm, by construction
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
(\S \ref { sec:model} ); it is not a hardness statement.
\end { lemma}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\begin { definition} [Collision-extractable accountability]\label { def:formal}
A scheme with fixed context $ \chi $ is \emph { collision-extractably
accountable} if there are explicit algorithms, running in time polynomial in
the transcript size, that map every winning $ \mathsf { PB } $ or $ \mathsf { HIST } $
output to two distinct strings with equal hash digests; explicit reductions
bounding $ \mathbf { Adv } ^ { \mathsf { HEAD } } $ and $ \mathbf { Adv } ^ { \mathsf { FORK } } $
each by one EUF-CMA advantage; and a $ \mathsf { Verdict } $ satisfying policy
separation.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { definition}
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\begin { theorem} [Collision-extractable accountability of the construction]\label { thm:main}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The LTL construction with the recursive verifiers of \S \ref { sec:security}
--- the RFC~9162 tree, the canonical signed heads of \S 4.2 in their fixed context $ \chi $ , the pin rule of \S 4.3, and the policy
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
verdict of \S \ref { sec:model} --- is collision-extractably accountable, with
$ \mathcal { B } _ { \rm pb } $ ($ \le 2 ( \lceil \log _ 2 n \rceil { + } 1 ) $ hash evaluations),
2026-08-17 10:54:08 +00:00
$ \mathcal { B } _ { \rm hist } $ ($ O ( \ell \log n _ \ell ) $ ), and the one-forgery reductions
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
$ \mathcal { B } _ { \rm ha } , \mathcal { B } _ { \rm fr } $ of
Theorems~\ref { thm:pb} --\ref { thm:fork} .
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\end { theorem}
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
\begin { corollary} [Constructive security consequence]\label { cor:security}
For every explicitly given feasible adversary that wins $ \mathsf { PB } $ or
$ \mathsf { HIST } $ , the explicitly specified $ \mathcal { B } _ { \rm pb } $ and
2026-07-17 20:20:42 +00:00
$ \mathcal { B } _ { \rm hist } $ constitute an explicitly given SHA-256 collision
finder, feasible with the explicit overhead stated in
Theorems~\ref { thm:pb} and~\ref { thm:hist} . For every explicitly given
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
feasible $ \mathsf { HEAD } $ or $ \mathsf { FORK } $ adversary, the stated black-box
reductions give an Ed25519 EUF-CMA forger with no loss in success
probability, under correct initial acquisition of $ pk $ and the fixed context.
Under the human-ignorance reading of collision resistance~\cite { rogaway} ---
no feasible SHA-256 collision finder is presently known --- this yields the
intended security interpretation; that reading is an engineering judgment
stated as such, not a mathematical assumption discharged by this corollary.
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
\end { corollary}
\paragraph { What the games do and do not formalize.}
Against Definition~2: clause (i) is delivered as head authenticity
($ \mathsf { HEAD } $ ) plus opening \emph { uniqueness} ($ \mathsf { PB } $ ) --- no
distinct leaf can also be opened at an accepted position. Whether a root
moreover commits a complete published leaf list is a system property, not a
game property: the log publishes its leaves, and a consumer holding the
2026-07-17 20:20:42 +00:00
mirror checks membership against the actual list. In short,
$ \mathsf { PB } $ proves leaf-value binding; mirror recomputation proves
equality to the published list. Clause (ii) splits into a
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
syntactic part --- the pin rule accepts only same-view or verified-extension
transitions, by construction --- and the semantic part supplied by
$ \mathsf { HIST } $ : a position opened in two accepted views cannot change value
without a collision. Clause (iii) is $ \mathsf { FORK } $ completeness and frame
2026-07-17 20:20:42 +00:00
resistance, scoped to $ \chi $ . Clause (iv) is Lemma~\ref { lem:policy} . The games adapt the established
two-transcript secure-logging notions~\cite { dghs} to replay attestation ---
operator as first-class adversary, policy separation added.
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\begin { remark} [What is mechanized, what is not]\label { rem:gamescope}
The games are stated for the scheme's specified verifiers --- the recursive
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
model whose honest-reference specializations are kernel-checked in leaf~12
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
(the named extractors and per-step pin safety). The two-transcript
comparisons and the transport induction are paper-level proofs in the same
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
discipline --- the induction reuses the corpus's mechanized
\code { kbelow_ prefix_ eq} fact --- and are not part of the mechanized corpus;
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
$ \mathsf { HIST } $ supplies, at paper level, the multi-step closure the corpus
leaves external. Applying any of these statements to the deployed iterative
verifier inherits the refinement boundary of the previous subsection
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
unchanged.
\end { remark}
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
\section { Lean instantiation: Ed25519 and SLH-DSA} \label { sec:instantiation}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\subsection { Proof corpus}
The initial subjects are upstream \code { curve25519-dalek} /\code { ed25519-dalek}
2026-07-17 07:42:45 +00:00
(one implementation: the curve crate and the signature crate atop it) and
three deployed forks: Solana/Anza, RISC~Zero, and Betrusted --- all
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
implementations of Ed25519~\cite { eddsa,rfc8032} . Aeneas
provides a functional translation route from Rust to theorem-prover models;
its design uses Rust ownership information to avoid explicit memory reasoning
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
for a large class of safe Rust programs~\cite { aeneas} . A recent independent
experience report likewise applies a Rust-to-Lean pipeline to cryptographic
code~\cite { klaus2026} .
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
2026-08-15 12:17:03 +00:00
Each fork's corpus contained sixteen reviewed certificates at the
historical leaves studied here (the corpora have since grown to forty-four
per fork --- the log records both generations as separate leaves), covering:
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { itemize} [leftmargin=1.6em,itemsep=2pt]
\item five-limb field arithmetic over $ \Fp $ with value and bound preservation;
\item complete twisted-Edwards group operations~\cite { edwards,twisted} ;
\item scalar arithmetic modulo the Ed25519 group order;
\item encoding, decoding, and constructive point decompression;
\item a four-stage lifting ladder from byte-level verifier acceptance to a
mathematical point equation.
2026-07-09 16:02:59 +00:00
\end { itemize}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The signature apex is organized as four tiers T1--T4
(Appendix~\ref { app:tiers} ). Let $ c $ be the challenge scalar produced by an opaque SHA-512 boundary and let $ \bar R $ be the raw $ R $ bytes
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
from the signature. The corpus separates:
\begin { description} [leftmargin=1.5em,itemsep=2pt]
\item [T1:] acceptance iff the verifier's recomputed compressed bytes equal
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
$ \bar R $ ;
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\item [T2:] those recomputed bytes are the canonical encoding of
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
$ [ c ] ( - A ) + [ s ] B $ ;
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\item [T3:] canonical encoding is injective on valid curve points;
\item [T4:] acceptance iff constructive decompression of $ R $ yields
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
$ [ c ] ( - A ) + [ s ] B $ .
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\end { description}
The separation keeps residual assumptions visible. SHA-512 and selected
wire-format interfaces are opaque boundaries at the apex; lower arithmetic and
group certificates use the foundational Lean axioms observed in the corpus.
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
\subsection { A second instantiation: the SLH-DSA verify path} \label { sec:slhdsa}
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The second campaign extracts the verification path of SLH-DSA
(FIPS~205~\cite { fips205} ,
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
parameter set SHA2-128s) from a pinned pure-Rust implementation through the
same Charon/Aeneas route, starting from one monomorphic entry point with the
five hash primitives marked opaque at the extraction boundary. The corpus is
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
eleven certificates: ten \emph { loop-fidelity} theorems --- each stating
that an extracted loop computes the same value as a reference recursive
fold --- covering chain walking, WOTS recomputation and checksum, XMSS and
FORS Merkle ascent, hypertree layering, and digit/byte plumbing
(Appendix~\ref { app:slhtiers} lists each with its exact cone) and an acceptance characterization,
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
\code { slh_ verify_ 128s_ accepts_ iff} : for every message digest, signature, and
public key at these parameters, the extracted verifier accepts exactly when
the recomputed hypertree root byte-equals the public key's root --- no other
acceptance path exists.
The terrain differs from Ed25519 in one structural way, and the leaf says so.
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
For Ed25519, each theorem relates extracted code to an independent
mathematical semantics (arithmetic over $ \mathbb { Z } / p \mathbb { Z } $ ,
formalized with no reference to the extracted code); SLH-DSA verification
is hash chains and Merkle nodes all the way down, so its reference
specifications are folds over the same five uninterpreted hash oracles
(\code { h_ msg} , \code { f} , \code { h} , \code { t_ l} , \code { t_ len} , modeling
the SHA-256 instantiations --- uninterpreted function symbols in the
logic, not random oracles) that the extracted loops call --- there is no
independent second semantics to land in. Each loop certificate therefore makes the extracted
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
control flow \emph { visible} --- small, sequential, checkable against the
standard's algorithms --- while the reading of fold against FIPS~205 remains
a declared human step. The audit enforces every certificate's axiom set
exactly in both directions, and the cone \emph { grows} up the pyramid ---
pure bit arithmetic rests on the kernel alone; the apex carries all five
oracles (Appendix~\ref { app:slhtiers} ). Scope, stated in the leaf: the proved
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
subject is a monomorphic facade (the fixed-parameter entry point above)
whose bridge to the deployed generic verifier
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
is a 137-case differential test; one inner digit-extraction loop carries no
certificate; signing and key generation were never extracted.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\subsection { Replay attestation}
For every certificate the operator records:
\begin { lstlisting}
name
status
observed_ axioms
expected_ axioms # audit trail; consumer policy is local
axiom_ status
diagnostics
\end { lstlisting}
The attestation also records repository URL and commit, Lean and Lake versions,
replay diagnostics, and resource controls. Missing cones are
\code { unverifiable} ; they are never interpreted as empty.
\subsection { Operational self-reference}
The service reports that tree heads are generated using a binary built from the
same Ed25519 source family whose verification-path certificates appear in the
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
log. Before signing, the operator recomputes inclusion of the newest
signing-library leaf in the tree. This is useful operational coherence, but not proof
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
of execution provenance. The signature authenticates the tree-head payload; it
does not reveal the program that produced it. Reproducible builds or execution
attestation would be required to establish that stronger claim.
\section { Deployment and evaluation} \label { sec:deployment}
The evaluation asks four questions: (E1) can substantial proof-replay evidence
be consumed without deploying Lean; (E2) does the public history retain failed
and superseded observations rather than silently replacing them; (E3) can the
accumulator's own arguments be placed under the same attestation discipline;
and (E4) does mechanization expose mismatches between the proved model and the
deployed verifier?
\subsection { Public state}
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
As of 15 August 2026, the public log contains nineteen leaves and current root
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { center}
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
\path { 7ee239406890cf4ad59cc83ac3faa3d5cc48b29202159ee8c25bffd9737d32d8} .
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\end { center}
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
Every signed head issued since public mirroring began is retained --- twelve
heads, at tree sizes 8 through 19, dual-signed from size 14 on --- together
with every leaf and receipt, in an append-only Git mirror; a clone
re-verifies the entire log offline with the repository's standalone verifier.
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The first twelve leaves are three replay generations across the four
Ed25519 codebases. Leaves 0--3
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
record a failed audit run and remain permanently visible. Leaves 4--7 record a
clean replay. Leaves 8--11 re-attest rewritten repository histories rather
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
than replacing the old leaves. Leaf 12 attests the accumulator's own Lean
corpus (\S \ref { sec:deployment} , E3); leaves 13--16 re-attest the four
Ed25519 corpora at 44 certificates each; leaf 17 re-attests the accumulator
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
corpus at its hardened state (the same corpus after closure of external
review findings); and leaf 18 attests the SLH-DSA-SHA2-128s
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
verification path --- the log's first post-quantum subject, and the scheme
that has co-signed every head since size 14. A leaf whose pinned commit ceases to be
2026-07-17 07:42:45 +00:00
distributed decays from a replayable claim to a historical record; consumers
act only on attestations whose subjects they can retrieve.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\begin { samepage}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Leaf 12 (the thirteenth entry) attests the accumulator corpus at commit
\begin { center} \small \ttfamily
172a1d0653f489d5b7cb73ac7942a57cbb496532
\end { center}
paper v0.8: readability pass — reader aids + two graphic bugs, zero semantic change
Operator-ordered UX audit (full linear read + every page rendered and
visually inspected + both reviewers' 'visually clear' certifications
spot-checked). Scope: no theorem, proof, or scope sentence changed in
meaning.
BUGS FIXED (both missed by both round-12/13/14 reviewers):
- Deployment figure: leaf 11 was CLIPPED to 'clea' by the overlapping
1.3cm 'accumulator' box — box now standard width, label 'accum.'
Verified fixed by render.
- The sentence 'Leaf 12 attests the accumulator corpus at commit' was
split from its hash by a float/page break, stranding the bare commit
after the figure — now wrapped in samepage. Verified by render.
- 'signing- library' hyphenation artifact in §6.3.
READER AIDS (for adjacent-field experts; verifiability up, rigor
untouched):
- Notation summary table (12 rows) at the end of §4, right before the
security analysis that uses every symbol.
- NEW transport figure (now Fig. 2): the 6->8 instance with the opening
path (red), frontier values A,B (blue), consumed proof value (dashed),
kept siblings (orange), and the r0/P0 assembly inset — §5.4's five
pages previously had zero figures. Hand-verified by render;
referenced from the transport-algorithm paragraph.
- 'Games at a glance' table (game/adversary/secrets/wins-by/consequence)
after the §5.4 intro.
- One-sentence reading guide at the top of §5.4.
- 2->3 tie-in after the transport proof (the log's own transition as the
smallest growth case; seam subsection gains a label).
- 'assumption cone' defined at first use (§2.1).
DE-SEDIMENTATION (three review rounds of accreted hedges, reorganized
with all semantic content kept):
- §5.4 intro: one 14-line wall -> four short paragraphs (context /
two levels / non-interactivity), duplicated hardness sentence merged.
- HIST game: definition crisp, commentary moved to a parenthetical.
- Abstract: ~15% tighter (inventory numbers -> '61 human-reviewed
certificates over a single uninterpreted SHA-256 axiom'; run-on
split). All boundary/honesty sentences retained.
22 pages, 0 overfull, suite 115 green. Deployment figure renumbered
2->3 (no numeric figure cross-references existed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:23:08 +00:00
\end { samepage}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
It records 61/61 reviewed
certificates as proven with exact expected/observed cones. The corpus audit
also inventories 222 compiled environment constants and permits exactly one
boundary axiom, \code { LTLAcc.sha256} .
2026-07-09 17:27:13 +00:00
\begin { figure} [t]
\centering
\begin { tikzpicture} [
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
>=Latex,
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
box/.style={ draw,rounded corners=2pt,minimum width=.78cm,minimum height=.5cm,font=\tiny ,align=center,inner sep=1.5pt} ,
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
fail/.style={ box,fill=black!6,draw=black!45,text=black!60} ,
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
pq/.style={ box,fill=violet!8,draw=violet!60!black,text=violet!55!black} ,
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
ok/.style={ box,fill=green!7!white,draw=deepgreen,text=deepgreen!80!black} ,
acc/.style={ box,fill=blue!7!white,draw=deepblue,text=deepblue} ,
arrow/.style={ ->,draw=black!55}
]
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\foreach \i in { 0,...,3} { \node [fail] (l\i ) at (0.82*\i ,0) { \i \\ failed} ;}
\foreach \i in { 4,...,7} { \node [ok] (l\i ) at (0.82*\i ,0) { \i \\ clean} ;}
\foreach \i in { 8,...,11} { \node [ok] (l\i ) at (0.82*\i ,0) { \i \\ clean} ;}
\node [acc] (l12) at (0.82*12,0) { 12\\ accum.} ;
\foreach \i in { 13,...,16} { \node [ok] (l\i ) at (0.82*\i ,0) { \i \\ re-att.} ;}
\node [acc] (l17) at (0.82*17,0) { 17\\ accum.} ;
\node [pq] (l18) at (0.82*18,0) { 18\\ slh-dsa} ;
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\draw [decorate,decoration={brace,mirror,raise=5pt},black!45]
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
($ ( l 0 .south west ) + ( . 05 , 0 ) $ )--($ ( l 3 .south east ) + ( - . 05 , 0 ) $ )
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
node[midway,below=11pt,font=\scriptsize ]{ run 1} ;
\draw [decorate,decoration={brace,mirror,raise=5pt},deepgreen]
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
($ ( l 4 .south west ) + ( . 05 , 0 ) $ )--($ ( l 7 .south east ) + ( - . 05 , 0 ) $ )
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
node[midway,below=11pt,font=\scriptsize ]{ run 2} ;
\draw [decorate,decoration={brace,mirror,raise=5pt},deepgreen]
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
($ ( l 8 .south west ) + ( . 05 , 0 ) $ )--($ ( l 11 .south east ) + ( - . 05 , 0 ) $ )
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
node[midway,below=11pt,font=\scriptsize ]{ run 3} ;
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\draw [decorate,decoration={brace,mirror,raise=5pt},deepblue]
($ ( l 13 .south west ) + ( . 05 , 0 ) $ )--($ ( l 18 .south east ) + ( - . 05 , 0 ) $ )
node[midway,below=11pt,font=\scriptsize ]{ August 2026} ;
\node [draw,rounded corners,fill=softgray,minimum width=5.9cm,minimum height=.85cm,align=center,font=\small] (sth) at (7.4,1.75)
{ signed head: size 19, root \code { 7ee23940...} \\ dual-signed: Ed25519 $ + $ SLH-DSA} ;
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\draw [arrow] (l6.north) -- (sth.south west);
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\draw [arrow] (l18.north) -- (sth.south east);
2026-07-09 17:27:13 +00:00
\end { tikzpicture}
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\caption { The public nineteen-leaf deployment. Failure leaves are retained; leaf
12 (the thirteenth entry) attests the accumulator corpus itself, scoped to the
recursive model; leaves 13--16 re-attest the four forks at 44 certificates
each; leaf 17 the hardened accumulator corpus; leaf 18 the SLH-DSA verify
path. Heads are dual-signed from size 14 on.}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\label { fig:deployment}
2026-07-09 17:27:13 +00:00
\end { figure}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\subsection { Mechanization coverage}
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
Leaf 12 is not a claim that the whole service is formally verified. The Lean
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
corpus covers the recursive Merkle model, inclusion completeness and
collision-extracting soundness, the consistency extractor, and the Merkle-layer
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
share of pin-store safety. The folklore whole-tree root-binding property (a root determines its
committed leaf list up to SHA-256 collision) is
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
mechanized through the specializations needed by the extractors rather than as
one quantified hash-fold theorem. Signature unforgeability, execution
provenance, the full signed-head state machine, asymptotic cost, and the
refinement from the deployed iterative consistency verifier remain outside the
corpus.
\begin { center} \small
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\begin { tabularx} { \textwidth } { @{ } l>{ \raggedright \arraybackslash } X>{ \raggedright \arraybackslash } X@{ } }
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\toprule
Layer & Mechanized evidence & Explicit boundary \\
\midrule
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
Merkle definitions & $ \MTH $ , $ \Root $ , $ \Path $ , recursive $ \ConsRec $ & single SHA-256 boundary axiom \\
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Inclusion & completeness and named collision extractor & collision resistance interpreted externally \\
Consistency & recursive-model soundness and extractor & no general consistency-completeness theorem \\
Pinning & per-step monotonicity and prefix correctness & signature layer and multi-step closure external \\
Deployment refinement & finite differential harness & no theorem for iterative verifier under authentic-pair invariant \\
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
Policy separation & deterministic tooling logic and regression tests & not mechanized in the leaf-12 corpus \\
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
Scheme-level games (\S \ref { sec:games} ) & paper-level explicit reductions & two-transcript comparisons and prefix transport not mechanized \\
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\bottomrule
\end { tabularx}
\end { center}
\subsection { Cost and reproducibility}
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
A replay of one Ed25519 fork requires approximately 30 minutes of end-to-end
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
resource-guarded (memory- and time-capped) replay time under the pinned environment, a figure corroborated by the
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
inter-leaf issuance spacing visible in the published log. Receipt verification requires one Ed25519
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
signature and a logarithmic number of SHA-256 node computations (the
complete inclusion core is printed as Appendix~\ref { app:verifier} ). The
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
accumulator corpus is independently reviewable with a pinned public Lean
release; an environment-derived inventory fails closed on added, removed, or
axiom-smuggling declarations.
The fidelity harness compares the Lean-definition transliteration with the
deployed Python algorithms over pinned finite families:
\begin { center} \small
paper: Fable-5 rigor re-audit of the depth pass — fix 3 real defects
Re-auditing the prior (Opus-produced) depth pass adversarially found and
fixed three genuine issues:
1. OVERCLAIM (serious): §5.3 said the consistency verifier was
differential-tested 'on all (n0,n1) with n1<=256' but the script only
SAMPLED sizes (5,508 cases). Ran the genuinely exhaustive test — all
1<=n0<=n1<=256, honest + 4 mutations — 164,224 invocations, and the
inclusion verifier likewise (164,479). Paper now states the true scope
and counts; both are pinned in a new CI test (test_paper_verifiers.py,
104 tests) so the numbers cannot rot.
2. PROOF IMPRECISION: Lemma 2 (Root binding) was applied to ConsRec's
first component, which PASSES THROUGH (no hnode) at some levels and so
is not the hash-fold the lemma needs. Reworked: Lemma 2 now defined
over 'hash-folds' only; Theorem 3 restructured into 3 clean steps that
put only the full-hashing second component through the lemma, then
argue algebraically + one honest-tree collision. Also hoisted Lemma 2
above Theorem 2 and made Theorem 2 invoke it (was inlined), so the
'two theorems share the lemma' remark is now true; deduped the remark.
3. MISLABELED TABLE: Table 1's 'files vs upstream' column actually held
line-diffs against different baselines. Dropped it for clean comparable
columns (files / apex axioms / SHA-512 shape); the diff story stays in
the portability paragraph where each baseline is named.
17 pages, all refs resolve, 104 tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 17:46:11 +00:00
\begin { tabular} { @{ } lrrl@{ } }
2026-07-09 17:27:13 +00:00
\toprule
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Family & Cases & Divergences & Interpretation \\
2026-07-09 17:27:13 +00:00
\midrule
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Inclusion & 230,271 & 0 & baseline and out-of-range families \\
Consistency baseline & 230,016 & 0 & honest and mutation families \\
Lied-size consistency & 73,573 & 3,867 & all deployed-accepts-only \\
2026-07-09 17:27:13 +00:00
\bottomrule
\end { tabular}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\end { center}
Finite testing is not a proof of extensional equality. Here it served a more
valuable purpose: it falsified an overbroad equivalence claim and supplied a
stable regression boundary.
\begin { remark} [Model/deployment seam]
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
For malformed size claims, the deployed iterative verifier and the recursive
2026-08-15 12:17:03 +00:00
model are not extensionally equal (figures are the pre-closure measurement;
the $ sn = 0 $ restoration reduces the divergence count in this family to zero).
In all 3,867 divergences observed across
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
the pinned families the deployed verifier accepted and the model rejected; the
reverse direction was not observed, and no global inclusion relation between
the two acceptance sets is claimed.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The public attestation therefore scopes soundness to the recursive model and
states the additional operational assumption: roots and sizes must be bound by
the authenticated pin-store and signed-head flow. This invariant is not
mechanized in the present corpus.
\end { remark}
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
\subsection { Consumer prototypes and version exactness}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
The implemented internal consumer is a quorum-custody signing prototype: its
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
inbound boundary accepts a log-derived statement only when independently
attested verifier backends agree, and its policy consumes recorded
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
observations, never operator labels. Separately, an informal check found a
production codebase whose vendored Ed25519 dependency matches an attested
subject at family level but not at the attested version; the model treats a
family-level match as conferring nothing, because attestations are
version-exact by construction. Neither observation is an evaluation claim;
both indicate how the policy boundary is consumed in practice.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\subsection { Proof portability across forks}
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Pure mathematical lemmas are largely reusable, while extraction-facing scripts
diverge where code structure and generated names diverge. In the deployed
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
corpora, the RISC~Zero and Betrusted signature-layer proof files differ by 27
changed lines (tracking one fork's optimization barrier and the forks'
differing operation order), other extraction-facing files differ by tens to
hundreds of lines, and pure carry and field lemmas remain byte-identical. This supports a practical conclusion: verification is portable
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
above the representation boundary and target-specific where implementation
structure actually differs.
\section { Related work} \label { sec:related}
\paragraph { Transparency.}
Certificate Transparency introduced publicly auditable append-only logs for
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
certificate issuance~\cite { ct1,ct2} ; Crosby and Wallach built efficient
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
tamper-evident history trees~\cite { crosby} ; Dowling et al. formalized security
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
notions for secure logging and CT~\cite { dghs} --- the games of
\S \ref { sec:games} adapt that two-transcript style to replay attestation, with
the operator as first-class adversary and policy separation as a deterministic
functionality. CONIKS applies transparency to
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
key directories~\cite { coniks} . LTL reuses the authenticated data structure but
changes the payload and trust semantics: a leaf is an observation of a proof
replay, not an issuance event or key binding.
\paragraph { Software supply-chain attestations.}
In-toto expresses supply-chain steps and link metadata~\cite { intoto} . Sigstore
combines ephemeral signing, identity, and transparency to reduce software-
signing adoption barriers~\cite { sigstore} . LTL is complementary: it concerns
what a theorem prover reportedly accepted and which assumptions remained, not
who built or signed a binary. A complete assurance chain should eventually
combine both.
\paragraph { Proof transport and verified cryptography.}
Proof-carrying code ships a proof to a consumer-side checker~\cite { pcc} . LTL
serves consumers that cannot deploy that checker and therefore accepts a
different trust trade. HACL*, EverCrypt, and Fiat-Crypto demonstrate verified
cryptographic implementation pipelines~\cite { hacl,evercrypt,fiatcrypto} ;
Computer-aided frameworks such as EasyCrypt address scheme-level security
proofs~\cite { easycrypt} ; Aeneas targets functional verification of Rust
through translation~\cite { aeneas} .
LTL does not compete with those systems: it distributes accountable statements
about their replay.
\paragraph { Verification of transparency protocols.}
Cheval et al. mechanize transparency-protocol reasoning~\cite { cheval} .
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
The leaf-12 corpus approaches the composition from the opposite direction: it
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
mechanizes accumulator arguments and then logs that replay result. The
remaining refinement from the deployed state machine to the recursive model is
explicitly open.
\section { Limitations and research agenda} \label { sec:limitations}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The subject corpus maintains a numbered public file, \code { KNOWN-GAPS} ,
of fifteen gaps with their closure options (the scope block of
Appendix~\ref { app:entry13} cites its items 14 and 15); this section groups the load-bearing ones.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\paragraph { Operator observation trust.}
A malicious operator can fabricate a replay report. Signatures and Merkle
proofs make the lie attributable and persistent; they do not make it true.
Targeted independent replay is the corrective mechanism.
2026-08-15 12:17:03 +00:00
\paragraph { Replay-harness integrity.}
A wrong observation needs no malice: a defective replay harness --- a bug in
the audit driver, a fail-open guard, a truncated transcript --- produces the
same evidentiary damage as a dishonest operator, with the same accountability
answer (the record is attributable and persistent; independent replay corrects
it). The subject corpus's adversarial gate self-tests exist for exactly this
reason and reduce, but cannot eliminate, the exposure.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\paragraph { Theorem identity.}
2026-07-17 07:42:45 +00:00
Names and repository commits are not canonical semantic identifiers, and
commit identifiers are SHA-1-based --- a weaker binding than the log's own
SHA-256 tree. A future
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
schema should commit to elaborated theorem-type digests, axiom declaration-type
digests, and an environment or replay-manifest digest.
\paragraph { Source-to-binary gap.}
The evidence concerns source models at pinned commits. Reproducible builds,
compiler validation, binary measurement, and side-channel evidence are outside
the present result.
\paragraph { Witnessing and key distribution.}
The deployment has one operator and trust-on-first-use key distribution. A Git
mirror gives retaining observers a common public view, but does not force all
isolated clients to receive that view. Independent witnesses or gossip are the
natural next deployment step.
\paragraph { Consistency refinement.}
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
The recursive model is proved; the iterative deployment diverged from it on
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
malformed inputs, every observed divergence being deployed-accepts-only. The strongest closure is either to deploy
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
$ \ConsRec $ -equivalent semantics or to mechanize the signed-head and pin-store
flow and prove the authentic-pair refinement theorem.
\paragraph { Signed provenance.}
Signing-backend metadata is operator-provided context and should be committed
inside the signed tree-head payload. Even then it would remain an assertion,
not execution proof.
\paragraph { From accountable replay to cryptographic proof of replay.}
A longer-term direction is a succinct proof that a fixed proof-checker binary
accepted a fixed corpus. Such a system could reduce operator-observation trust,
but would introduce a new verified-execution stack. LTL supplies an
intermediate accountability layer and a public corpus against which that future
system can be evaluated.
\section { Conclusion}
Formal verification solves the production of correctness evidence; it does not
by itself solve distribution to consumers that cannot execute the verifier.
This paper isolates that second problem and gives a cryptographic answer based
on accountable replay attestation. The operator's observation remains trusted,
but its content is structured, its history is signed and append-only, its
assumption boundary is subject to consumer-local policy, and incompatible views
become attributable when compared.
The Lean Transparency Log demonstrates the complete construction. It amortizes
expensive replay over lightweight consumers, retains failed and superseded
observations, and carries a scoped attestation of the accumulator's own Lean
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
corpus as leaf 12. Just as importantly, the mechanization and differential
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
harness exposed a mismatch between the recursive model and the deployed
consistency verifier. Recording that mismatch in the public leaf is not a
failure of the method; it is evidence that the trust decomposition is doing
useful scientific work.
The next step is not to claim trustlessness. It is to close specific boundaries:
canonical theorem-type commitments, reproducible source-to-binary linkage,
independent witnesses, signed provenance commitments, and a proved refinement
between the deployed signed-head flow and the recursive model. Accountable
replay attestation provides an immediate infrastructure layer while those
stronger validity mechanisms are developed.
\section * { Artifact availability}
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
The live service is \url { https://ltl.zkdefi.org} . Leaf 12 (the log's thirteenth entry) has leaf hash
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { center} \small \ttfamily
8cb258d657f1fd00baaa9e0091e26c316cb69b591cb249a9543f51cade57c50a
\end { center}
and is included in the size-13 head with root
\begin { center} \small \ttfamily
3488a2d0ff9f00415bb561d61b01a420e3ca2e0f7b29351ec9ebb3f57319da0d
\end { center}
The public artifacts are available at:
\begin { itemize} [leftmargin=1.5em,itemsep=1pt]
\item append-only mirror: \href { https://github.com/saymrwulf/lean-transparency-log} { \texttt { saymrwulf/lean-transparency-log} } ;
\item accumulator mechanization: \href { https://github.com/saymrwulf/ltl-accumulator-verified} { \texttt { saymrwulf/ltl-accumulator-verified} } ;
\item provider and consumer tooling: \href { https://github.com/saymrwulf/proof-aware-crypto-tooling-agent} { \texttt { saymrwulf/proof-aware-crypto-tooling-agent} } .
\end { itemize}
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
A clone of the mirror re-verifies every numbered leaf, every published signed
head, and every published receipt offline via \code { python3 verify.py --all}
(Python standard library plus an \code { openssl} binary; the verifier fails
closed if signature checking is unavailable, and its adversarial self-test
ships beside it).
2026-07-09 16:02:59 +00:00
\section * { Acknowledgments}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
The author designed the system and is responsible for every claim. Claude
(Anthropic) and GPT (OpenAI) were used as critical assistants in proof-corpus,
tooling, and manuscript review. Their output was not accepted as evidence;
claims were retained only after human review or reproducible artifact checks.
2026-07-09 16:02:59 +00:00
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
\begin { thebibliography} { 23}
2026-07-09 16:02:59 +00:00
\itemsep 2pt
\bibitem { ct1} B. Laurie, A. Langley, E. K\" asper. Certificate Transparency.
RFC 6962, 2013.
\bibitem { ct2} B. Laurie, E. Messeri, R. Stradling. Certificate Transparency
Version 2.0. RFC 9162, 2021.
\bibitem { crosby} S. A. Crosby, D. S. Wallach. Efficient Data Structures for
audit v3: paper-reality congruence + external-pointer integrity (Fable-5 Socratic pass)
Two Fable-5 inventory agents cross-checked every empirical claim in the
paper against code/deployed log, and every external pointer against the
live internet. Fixes on both sides:
CODE (system brought up to the paper's claims):
- SECURITY: pin-store mutation (incl. permanent poisoning) was reachable
via receipts whose head signature FAILED verification in two of three
consumer paths (attestation.py, cli.py) - an unauthenticated forged
head at the pinned size could poison a consumer's pin forever and
pollute the equivocation-evidence pair with an unverifiable head,
contradicting SS5.4's 'validly signed' precondition and Prop 1.
Both paths now gate the store on a verified Ed25519 head signature
(logclient.py already did). Regression test added.
- Prop 2 made literally true: _normalize_certificate now derives the
cleanliness verdict purely from (observed cone, local allowed set) in
EVERY branch; the operator's axiom_status label is never copied (was
passed through for non-proven certs), missing cone => unverifiable
always. Labels can deny, never grant. Test added.
- webdocs: '/v1/sth-history: every head ever signed' -> 'the published
head history'.
PAPER (claims brought down to reality):
- 'every head ever signed' -> the signed head history since publication
began (heads for sizes 1-7 predate the mirror and were not retained).
- Run-3 bullet: 'independently checkable by diffing the two commit
trees' was no longer reproducible (pre-rewrite objects discarded);
now states the log-internal corroboration (identical cert lists and
cones across leaves 4-7 vs 8-11) and that tree diffs are not public.
- Appendix A leaf block now actually verbatim: scheme
openssl-ed25519, verified_backend serial/u64, real Lean version
(4.30.0-rc2) instead of 4.x.y placeholder, leaf's actual axiom order
(finalize/new/update), machine_protection note quoted, elisions
marked; preamble wording matches.
- Appendix C upstream boundary reordered to check.sh's verbatim order.
- '27 lines - all annotation' -> honest description (axiom-list entries
+ operation reordering from one fork's black_box barrier).
- Prop 2 proof + App A: status label consulted only negatively.
- SS7: provenance fields noted as outside the signed payload; consumer
chain relies on none of them.
- Bibliography: all 20 entries verified against DBLP/RFC-editor - zero
errors; added missing page numbers to 6 entries; thebibliography
width 19->20. All URLs verified public; no PlanetMacro leakage.
17 pages, 106 tests green, accumulator untouched (tree_size 12).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 19:33:28 +00:00
Tamper-Evident Logging. USENIX Security, pp. 317--334, 2009.
2026-07-09 16:02:59 +00:00
\bibitem { dghs} B. Dowling, F. G\" unther, U. Herath, D. Stebila. Secure
Logging Schemes and Certificate Transparency. ESORICS, LNCS 9879, pp.
140--158, 2016.
\bibitem { sigstore} Z. Newman, J. S. Meyers, S. Torres-Arias. Sigstore:
Software Signing for Everybody. ACM CCS, pp. 2353--2367, 2022.
\bibitem { intoto} S. Torres-Arias, H. Afzali, T. K. Kuppusamy, R. Curtmola,
J. Cappos. in-toto: Providing farm-to-table guarantees for bits and bytes.
audit v3: paper-reality congruence + external-pointer integrity (Fable-5 Socratic pass)
Two Fable-5 inventory agents cross-checked every empirical claim in the
paper against code/deployed log, and every external pointer against the
live internet. Fixes on both sides:
CODE (system brought up to the paper's claims):
- SECURITY: pin-store mutation (incl. permanent poisoning) was reachable
via receipts whose head signature FAILED verification in two of three
consumer paths (attestation.py, cli.py) - an unauthenticated forged
head at the pinned size could poison a consumer's pin forever and
pollute the equivocation-evidence pair with an unverifiable head,
contradicting SS5.4's 'validly signed' precondition and Prop 1.
Both paths now gate the store on a verified Ed25519 head signature
(logclient.py already did). Regression test added.
- Prop 2 made literally true: _normalize_certificate now derives the
cleanliness verdict purely from (observed cone, local allowed set) in
EVERY branch; the operator's axiom_status label is never copied (was
passed through for non-proven certs), missing cone => unverifiable
always. Labels can deny, never grant. Test added.
- webdocs: '/v1/sth-history: every head ever signed' -> 'the published
head history'.
PAPER (claims brought down to reality):
- 'every head ever signed' -> the signed head history since publication
began (heads for sizes 1-7 predate the mirror and were not retained).
- Run-3 bullet: 'independently checkable by diffing the two commit
trees' was no longer reproducible (pre-rewrite objects discarded);
now states the log-internal corroboration (identical cert lists and
cones across leaves 4-7 vs 8-11) and that tree diffs are not public.
- Appendix A leaf block now actually verbatim: scheme
openssl-ed25519, verified_backend serial/u64, real Lean version
(4.30.0-rc2) instead of 4.x.y placeholder, leaf's actual axiom order
(finalize/new/update), machine_protection note quoted, elisions
marked; preamble wording matches.
- Appendix C upstream boundary reordered to check.sh's verbatim order.
- '27 lines - all annotation' -> honest description (axiom-list entries
+ operation reordering from one fork's black_box barrier).
- Prop 2 proof + App A: status label consulted only negatively.
- SS7: provenance fields noted as outside the signed payload; consumer
chain relies on none of them.
- Bibliography: all 20 entries verified against DBLP/RFC-editor - zero
errors; added missing page numbers to 6 entries; thebibliography
width 19->20. All URLs verified public; no PlanetMacro leakage.
17 pages, 106 tests green, accumulator untouched (tree_size 12).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 19:33:28 +00:00
USENIX Security, pp. 1393--1410, 2019.
2026-07-09 16:02:59 +00:00
\bibitem { coniks} M. S. Melara, A. Blankstein, J. Bonneau, E. W. Felten,
M. J. Freedman. CONIKS: Bringing Key Transparency to End Users. USENIX
audit v3: paper-reality congruence + external-pointer integrity (Fable-5 Socratic pass)
Two Fable-5 inventory agents cross-checked every empirical claim in the
paper against code/deployed log, and every external pointer against the
live internet. Fixes on both sides:
CODE (system brought up to the paper's claims):
- SECURITY: pin-store mutation (incl. permanent poisoning) was reachable
via receipts whose head signature FAILED verification in two of three
consumer paths (attestation.py, cli.py) - an unauthenticated forged
head at the pinned size could poison a consumer's pin forever and
pollute the equivocation-evidence pair with an unverifiable head,
contradicting SS5.4's 'validly signed' precondition and Prop 1.
Both paths now gate the store on a verified Ed25519 head signature
(logclient.py already did). Regression test added.
- Prop 2 made literally true: _normalize_certificate now derives the
cleanliness verdict purely from (observed cone, local allowed set) in
EVERY branch; the operator's axiom_status label is never copied (was
passed through for non-proven certs), missing cone => unverifiable
always. Labels can deny, never grant. Test added.
- webdocs: '/v1/sth-history: every head ever signed' -> 'the published
head history'.
PAPER (claims brought down to reality):
- 'every head ever signed' -> the signed head history since publication
began (heads for sizes 1-7 predate the mirror and were not retained).
- Run-3 bullet: 'independently checkable by diffing the two commit
trees' was no longer reproducible (pre-rewrite objects discarded);
now states the log-internal corroboration (identical cert lists and
cones across leaves 4-7 vs 8-11) and that tree diffs are not public.
- Appendix A leaf block now actually verbatim: scheme
openssl-ed25519, verified_backend serial/u64, real Lean version
(4.30.0-rc2) instead of 4.x.y placeholder, leaf's actual axiom order
(finalize/new/update), machine_protection note quoted, elisions
marked; preamble wording matches.
- Appendix C upstream boundary reordered to check.sh's verbatim order.
- '27 lines - all annotation' -> honest description (axiom-list entries
+ operation reordering from one fork's black_box barrier).
- Prop 2 proof + App A: status label consulted only negatively.
- SS7: provenance fields noted as outside the signed payload; consumer
chain relies on none of them.
- Bibliography: all 20 entries verified against DBLP/RFC-editor - zero
errors; added missing page numbers to 6 entries; thebibliography
width 19->20. All URLs verified public; no PlanetMacro leakage.
17 pages, 106 tests green, accumulator untouched (tree_size 12).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 19:33:28 +00:00
Security, pp. 383--398, 2015.
2026-07-09 16:02:59 +00:00
\bibitem { pcc} G. C. Necula. Proof-Carrying Code. ACM POPL, pp. 106--119,
1997.
\bibitem { cheval} V. Cheval, J. Moreira, M. Ryan. Automatic verification of
audit v3: paper-reality congruence + external-pointer integrity (Fable-5 Socratic pass)
Two Fable-5 inventory agents cross-checked every empirical claim in the
paper against code/deployed log, and every external pointer against the
live internet. Fixes on both sides:
CODE (system brought up to the paper's claims):
- SECURITY: pin-store mutation (incl. permanent poisoning) was reachable
via receipts whose head signature FAILED verification in two of three
consumer paths (attestation.py, cli.py) - an unauthenticated forged
head at the pinned size could poison a consumer's pin forever and
pollute the equivocation-evidence pair with an unverifiable head,
contradicting SS5.4's 'validly signed' precondition and Prop 1.
Both paths now gate the store on a verified Ed25519 head signature
(logclient.py already did). Regression test added.
- Prop 2 made literally true: _normalize_certificate now derives the
cleanliness verdict purely from (observed cone, local allowed set) in
EVERY branch; the operator's axiom_status label is never copied (was
passed through for non-proven certs), missing cone => unverifiable
always. Labels can deny, never grant. Test added.
- webdocs: '/v1/sth-history: every head ever signed' -> 'the published
head history'.
PAPER (claims brought down to reality):
- 'every head ever signed' -> the signed head history since publication
began (heads for sizes 1-7 predate the mirror and were not retained).
- Run-3 bullet: 'independently checkable by diffing the two commit
trees' was no longer reproducible (pre-rewrite objects discarded);
now states the log-internal corroboration (identical cert lists and
cones across leaves 4-7 vs 8-11) and that tree diffs are not public.
- Appendix A leaf block now actually verbatim: scheme
openssl-ed25519, verified_backend serial/u64, real Lean version
(4.30.0-rc2) instead of 4.x.y placeholder, leaf's actual axiom order
(finalize/new/update), machine_protection note quoted, elisions
marked; preamble wording matches.
- Appendix C upstream boundary reordered to check.sh's verbatim order.
- '27 lines - all annotation' -> honest description (axiom-list entries
+ operation reordering from one fork's black_box barrier).
- Prop 2 proof + App A: status label consulted only negatively.
- SS7: provenance fields noted as outside the signed payload; consumer
chain relies on none of them.
- Bibliography: all 20 entries verified against DBLP/RFC-editor - zero
errors; added missing page numbers to 6 entries; thebibliography
width 19->20. All URLs verified public; no PlanetMacro leakage.
17 pages, 106 tests green, accumulator untouched (tree_size 12).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 19:33:28 +00:00
transparency protocols. IEEE EuroS\& P, pp. 107--121, 2023.
paper v4: merge of two independent hostile reviews (17->18 pages)
Review A (second Fable instance, delivered via USB, findings re-verified
by me against the tex before adoption; its frontier lemma re-derived from
scratch before applying):
- THE REAL FIX: Lemma 2's hash-fold definition did not cover its own two
uses (Root recomputes only along the leaf's root path; ConsRec bottoms
out at the [0,n0) decomposition and consumes the pinned root, which the
old Steps 1-2 never pinned - incl. the degenerate case where the first
component IS the pinned root alone). Now: folds shaped by a connected
sub-tree S containing the root, children outside S consumed as opaque
inputs, conclusion pins emitted values AND all consumed inputs; Thm 2
names its S; Thm 3 pins the consumed anchor and handles the degenerate
case; Lemma 1's role stated honestly.
- dangling R4/R5 taxonomy labels removed; G3/Prop 2 statements now match
their own veto-proof (deny-only, everywhere); Table 1 caption counts
boundary+standard-three; r1 defined as raw signature bytes (T1's whole
point); Contribution 4 'embedded in every signature' -> 'published
alongside'; Figure 1 redrawn in the exact RFC 9162 shape for n=12;
Solana error-type nit; App D namespace elision noted.
Review B (GPT-5.6, positions defended 2026-07-10, concessions adopted):
- abstract + G2 narrowed to what Prop 1 proves (same-size evidence +
monotonicity), unequal-size split views routed through the public leaf
mirror; residual-trust sentence stated at honest width (checkout, deps,
binding, parsing in the trusted observation pipeline); freshness
declared an availability policy (freeze attacks not prevented);
self-reference verb 'ensures' -> 'enforces and records' + signature
reveals nothing about the producing program; novelty softened to
'we are unaware of'; 25-line/150-line accounting in one breath;
missing-oracle-axiom = refuse-to-classify drift (keeping the oracle
argument); mechanization tone softened; head-encoding reality
documented (versioned canonical JSON w/ log id - system was ahead of
the paper); NEW claim-matrix table (Table 2) decomposing every consumer
conclusion into mechanism + residual assumption, incl. two deliberate
not-established rows.
Open questions from Review A resolved: black_box 27 lines are per-lemma
trusted-base bookkeeping (no published cone contains black_box -
verified); T4 x=0 edge case now stated precisely (roots coincide, set
sign bit rejected per RFC 8032, covered by the iff over extracted code;
Lean sqrt_core handles x=0 explicitly); Cheval pages (DBLP-verified)
restored alongside Review A's DOI.
18 pages, 106 tests green, accumulator untouched (12 leaves).
webdocs/llms.txt page counts updated.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-10 08:34:21 +00:00
doi:10.1109/EuroSP57164.2023.00016. arXiv:2303.04500.
2026-07-09 16:02:59 +00:00
\bibitem { easycrypt} G. Barthe, B. Gr\' egoire, S. Heraud, S. Zanella
B\' eguelin. Computer-Aided Security Proofs for the Working Cryptographer.
CRYPTO, LNCS 6841, pp. 71--90, 2011.
\bibitem { aeneas} S. Ho, J. Protzenko. Aeneas: Rust verification by
functional translation. Proc. ACM Program. Lang. 6 (ICFP): 711--741, 2022.
\bibitem { lean4} L. de Moura, S. Ullrich. The Lean 4 Theorem Prover and
Programming Language. CADE-28, LNCS 12699, pp. 625--635, 2021.
\bibitem { hacl} J.-K. Zinzindohou\' e, K. Bhargavan, J. Protzenko,
B. Beurdouche. HACL*: A Verified Modern Cryptographic Library. ACM CCS,
audit v3: paper-reality congruence + external-pointer integrity (Fable-5 Socratic pass)
Two Fable-5 inventory agents cross-checked every empirical claim in the
paper against code/deployed log, and every external pointer against the
live internet. Fixes on both sides:
CODE (system brought up to the paper's claims):
- SECURITY: pin-store mutation (incl. permanent poisoning) was reachable
via receipts whose head signature FAILED verification in two of three
consumer paths (attestation.py, cli.py) - an unauthenticated forged
head at the pinned size could poison a consumer's pin forever and
pollute the equivocation-evidence pair with an unverifiable head,
contradicting SS5.4's 'validly signed' precondition and Prop 1.
Both paths now gate the store on a verified Ed25519 head signature
(logclient.py already did). Regression test added.
- Prop 2 made literally true: _normalize_certificate now derives the
cleanliness verdict purely from (observed cone, local allowed set) in
EVERY branch; the operator's axiom_status label is never copied (was
passed through for non-proven certs), missing cone => unverifiable
always. Labels can deny, never grant. Test added.
- webdocs: '/v1/sth-history: every head ever signed' -> 'the published
head history'.
PAPER (claims brought down to reality):
- 'every head ever signed' -> the signed head history since publication
began (heads for sizes 1-7 predate the mirror and were not retained).
- Run-3 bullet: 'independently checkable by diffing the two commit
trees' was no longer reproducible (pre-rewrite objects discarded);
now states the log-internal corroboration (identical cert lists and
cones across leaves 4-7 vs 8-11) and that tree diffs are not public.
- Appendix A leaf block now actually verbatim: scheme
openssl-ed25519, verified_backend serial/u64, real Lean version
(4.30.0-rc2) instead of 4.x.y placeholder, leaf's actual axiom order
(finalize/new/update), machine_protection note quoted, elisions
marked; preamble wording matches.
- Appendix C upstream boundary reordered to check.sh's verbatim order.
- '27 lines - all annotation' -> honest description (axiom-list entries
+ operation reordering from one fork's black_box barrier).
- Prop 2 proof + App A: status label consulted only negatively.
- SS7: provenance fields noted as outside the signed payload; consumer
chain relies on none of them.
- Bibliography: all 20 entries verified against DBLP/RFC-editor - zero
errors; added missing page numbers to 6 entries; thebibliography
width 19->20. All URLs verified public; no PlanetMacro leakage.
17 pages, 106 tests green, accumulator untouched (tree_size 12).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 19:33:28 +00:00
pp. 1789--1806, 2017.
2026-07-09 16:02:59 +00:00
\bibitem { evercrypt} J. Protzenko et al. EverCrypt: A Fast, Verified,
audit v3: paper-reality congruence + external-pointer integrity (Fable-5 Socratic pass)
Two Fable-5 inventory agents cross-checked every empirical claim in the
paper against code/deployed log, and every external pointer against the
live internet. Fixes on both sides:
CODE (system brought up to the paper's claims):
- SECURITY: pin-store mutation (incl. permanent poisoning) was reachable
via receipts whose head signature FAILED verification in two of three
consumer paths (attestation.py, cli.py) - an unauthenticated forged
head at the pinned size could poison a consumer's pin forever and
pollute the equivocation-evidence pair with an unverifiable head,
contradicting SS5.4's 'validly signed' precondition and Prop 1.
Both paths now gate the store on a verified Ed25519 head signature
(logclient.py already did). Regression test added.
- Prop 2 made literally true: _normalize_certificate now derives the
cleanliness verdict purely from (observed cone, local allowed set) in
EVERY branch; the operator's axiom_status label is never copied (was
passed through for non-proven certs), missing cone => unverifiable
always. Labels can deny, never grant. Test added.
- webdocs: '/v1/sth-history: every head ever signed' -> 'the published
head history'.
PAPER (claims brought down to reality):
- 'every head ever signed' -> the signed head history since publication
began (heads for sizes 1-7 predate the mirror and were not retained).
- Run-3 bullet: 'independently checkable by diffing the two commit
trees' was no longer reproducible (pre-rewrite objects discarded);
now states the log-internal corroboration (identical cert lists and
cones across leaves 4-7 vs 8-11) and that tree diffs are not public.
- Appendix A leaf block now actually verbatim: scheme
openssl-ed25519, verified_backend serial/u64, real Lean version
(4.30.0-rc2) instead of 4.x.y placeholder, leaf's actual axiom order
(finalize/new/update), machine_protection note quoted, elisions
marked; preamble wording matches.
- Appendix C upstream boundary reordered to check.sh's verbatim order.
- '27 lines - all annotation' -> honest description (axiom-list entries
+ operation reordering from one fork's black_box barrier).
- Prop 2 proof + App A: status label consulted only negatively.
- SS7: provenance fields noted as outside the signed payload; consumer
chain relies on none of them.
- Bibliography: all 20 entries verified against DBLP/RFC-editor - zero
errors; added missing page numbers to 6 entries; thebibliography
width 19->20. All URLs verified public; no PlanetMacro leakage.
17 pages, 106 tests green, accumulator untouched (tree_size 12).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 19:33:28 +00:00
Cross-Platform Cryptographic Provider. IEEE S\& P, pp. 983--1002, 2020.
2026-07-09 16:02:59 +00:00
\bibitem { fiatcrypto} A. Erbsen, J. Philipoom, J. Gross, R. Sloan,
A. Chlipala. Simple High-Level Code for Cryptographic Arithmetic---With
Proofs, Without Compromises. IEEE S\& P, pp. 1202--1219, 2019.
\bibitem { eddsa} D. J. Bernstein, N. Duif, T. Lange, P. Schwabe, B.-Y. Yang.
High-speed high-security signatures. J. Cryptographic Engineering 2(2):
77--89, 2012.
\bibitem { rfc8032} S. Josefsson, I. Liusvaara. Edwards-Curve Digital
Signature Algorithm (EdDSA). RFC 8032, 2017.
\bibitem { edwards} D. J. Bernstein, T. Lange. Faster addition and doubling on
elliptic curves. ASIACRYPT, LNCS 4833, pp. 29--50, 2007.
\bibitem { twisted} D. J. Bernstein, P. Birkner, M. Joye, T. Lange,
C. Peters. Twisted Edwards curves. AFRICACRYPT, LNCS 5023, pp. 389--405,
2008.
\bibitem { pnueli} A. Pnueli. The temporal logic of programs. IEEE FOCS, pp.
46--57, 1977.
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
\bibitem { rogaway} P. Rogaway. Formalizing Human Ignorance:
Collision-Resistant Hashing without the Keys. VIETCRYPT, LNCS 4341, pp.
paper v0.6: round-13 fix batch — §5.4 rewritten; every verified finding closed
Reconciliation first: the two round-13 reviews CONTRADICT on FORK.
Opus (flagged mid-review as flipped, per operator): 'frame-resistance
unsound as stated' because payloads carry timestamps. GPT: 'the right
EUF-CMA form.' Independent re-derivation sides with GPT: a winning head
needs a VALID SIGNATURE on its never-queried exact payload bytes — a
forgery regardless of timestamp; Opus's no-forgery scenario never
produces the valid signature it presupposes, and its own fix paragraph
concedes the win condition already means exact-payload freshness. Its
real residue (the (n,r)-injectivity parenthetical was a red herring in
that proof) is adopted: the parenthetical is gone, injectivity is now
its own lemma where it belongs.
GPT findings, all verified then fixed:
- Theorem 5 formal error (CONFIRMED): the proof applied transport to
same-size transitions outside the lemma's n0<n1 hypothesis, and the
lemma's last line smuggled that case. Lemma restated for n0<=n1 with
the equal case explicit; HIST proof now case-splits (equal: Ext
forces equal roots, opening carries over; growth: transport).
- Prefix transport (CONFIRMED under-proved; Opus concurs): the frontier
narrative is replaced by a FULL induction over the ConsRec recursion,
with the verifier recursions displayed, the value-equality invariant
(rho = y) threaded exactly as the corpus's extractConsNode analysis
identified, explicit P0 assembly per branch, the no-mismatched-
stopping-points argument (shapes are integer-determined), and the
power-of-two split-stability step credited to the corpus's mechanized
kbelow lemma.
- FORK cross-log framing flaw (CONFIRMED): evidence predicate now
context-scoped — fixed chi = (log id, schema/type, hash-alg, pk)
declared once, encoded in every head; one key running two logs can no
longer be classified as equivocating. Prose corrected to
'issued-message attribution' (no more 'never equivocated' oracle
mismatch).
- HEAD-AUTH game added (CONFIRMED gap): outsider forging one ordinary
head reduces to EUF-CMA; G1's forgery leg is now discharged by an
actual game, closing the network-attacker hole.
- Two-level formalization (CONFIRMED): Definition 3 = collision-
extractable accountability (unconditional, explicit reductions with
stated costs); NEW security corollary = what human-ignorance CR +
EUF-CMA + correct key + fixed context then rule out. Extractability
no longer masquerades as hardness.
- Composition mapping made precise: G1 narrowed to authentic position
binding (HEAD + PB opening-uniqueness; full-list membership is a
system property of the published mirror, said so); G2 split into
syntactic pin rule vs semantic HIST content; monotone-extensions and
payload-injectivity as one-line lemmas; HIST game syntax lists C_i
and 0<=a<b<=k; Adv defined for the two keyed games; PB cost notes
retained intermediates; Rogaway bibitem gains the DOI (211-228
reconfirmed by GPT: Springer/DBLP vs the author's list-page typo).
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:01:45 +00:00
211--228, 2006. doi:10.1007/11958239\_ 14.
paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
accepting opening at m<n0 under the NEW head yields a collision or
an assembled accepting opening under the OLD head (frontier
comparison + old-root spine assembly; degenerate power-of-two case
handled).
- Game HIST (local history binding): pin-rule chains + contradictory
openings at any two accepted heads -> collision, by transport
induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
reduces to EUF-CMA. Win condition deliberately over canonical
PAYLOADS, not heads — a second signature on an already-signed
payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
suggestion), formal Definition 3, and Theorem 7: the construction
is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
221- typo): every hash statement is an explicit reduction, the
scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
signing key (no secrets, no oracles) — stated in the section,
mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
transcript comparisons and prefix transport are paper-level, not
mechanized); Definition 2 re-badged informal with pointer; DGHS
two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 11:31:51 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\bibitem { klaus2026} N. Klaus, J. Conejero, P. Tolmach. A Rust-to-Lean
Verification Pipeline with AI Provers: An Experience Report. arXiv:2605.30106,
2026.
2026-07-09 16:02:59 +00:00
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
\bibitem { fips205} National Institute of Standards and Technology.
Stateless Hash-Based Digital Signature Standard. FIPS 205, August 2024.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\end { thebibliography}
2026-07-09 16:02:59 +00:00
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
% Appendix policy (declared 2026-08-16): the appendix block starts on a
% fresh page and then flows continuously -- no page breaks between
% individual appendices. The claim matrix is one unbreakable tabularx.
\clearpage
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\appendix
2026-07-09 16:02:59 +00:00
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\section { End-to-end claim matrix} \label { app:matrix}
\begin { center} \small
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\begin { tabularx} { \textwidth } { @{ } >{ \raggedright \arraybackslash } X>{ \raggedright \arraybackslash } X>{ \raggedright \arraybackslash } X@{ } }
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\toprule
Consumer conclusion & Established by & Remaining assumption \\
\midrule
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
Leaf has an authentic opening with a position-bound leaf value at index $ m $ under head $ h $ & inclusion proof and signed head & \mbox { SHA-256} collision resistance; correct public key; \mbox { EUF-CMA} of the head signature \\
\addlinespace [3pt]
paper v0.7: round-14 fix batch — three GPT integration blockers closed; Opus concession recorded
Round-14 verdicts: the Claude reviewer CONCEDED its round-13 FORK
objection in writing ('I WAS WRONG', with the correct reasoning after
attempting the demanded counterexample) and passed everything
('nothing blocks x3') — but its 'chi genuinely encoded in the payload'
certification silently swapped pk out of the tuple, missing exactly
GPT's blocker 1. GPT verified the transport induction branch-by-branch
(sound) and found three real integration blockers, all independently
confirmed here before fixing:
- B1: chi contained pk and was claimed payload-encoded; the deployed
payload does NOT carry the key (it is an external verification
parameter) and the game fixed chi before KeyGen created pk. Now:
chi_enc = (log id, schema/type tags, hash-alg) is the encoded
context; chi = (chi_enc, pk) is set after KeyGen; all game texts
(syntax, injectivity lemma, HEAD, FORK/Ev) rescoped accordingly.
- B2: context scoping propagated to the three sites still stating the
cross-log-flawed form: Definition 2 clause (iii), Proposition 1
(statement + proof), and the Appendix A fork row — plus clause (i)
redefined as opening uniqueness under an authentic view (the
'position-bound' ambiguity), the App-A membership row aligned, and a
NEW App-A row for full-mirror recomputation (verify.py --all).
- B3: the security corollary no longer treats the epistemic
human-ignorance premise as a contradictable assumption. It is now
'Constructive security consequence': explicit feasible winner =>
explicitly given, equally feasible collision finder (stated costs);
HEAD/FORK => one EUF-CMA forgery, no loss; the human-ignorance
reading is an engineering judgment stated as such. Intro sentence
aligned.
Minor round-14 items adopted: kbelow citation corrected to the exact
corpus theorem kbelow_prefix_eq (Consistency.lean:48 — it EXISTS;
GPT's claim that no literally-named lemma exists was wrong, my memory
was right); payload-injectivity proof covers the timestamp string and
is scoped to the specified serializer; HIST chain re-termed
'head values, Merkle-level, authentication is HEAD's job'; transcript-
length cost sentence in Theorem 5; 'strong induction' clause;
DGHS-adaptation positioning sentence ('not a bespoke bar' — worded
'adapt', per GPT round 13's own caution against 'specialization').
21 pages, 0 overfull, suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 16:15:28 +00:00
Head root commits the published numbered leaf list & full-mirror recomputation (\code { verify.py --all} ) & mirror availability and retention \\
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\addlinespace [3pt]
Head was authorized by the log identity & Ed25519 verification & correct key acquisition; \mbox { EUF-CMA} \\
\addlinespace [3pt]
New pinned head extends old pinned head & consistency proof & \mbox { SHA-256} collision resistance; recursive-model soundness; authentic size/root pairing for deployment \\
\addlinespace [3pt]
Equal-size unequal roots in one log context conflict & two valid signatures & correct public key; \mbox { EUF-CMA} ; operationally, a retaining observer must compare the heads \\
\addlinespace [3pt]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Observed cone matches local boundary policy & exact set equality & semantic identity of named declarations \\
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\addlinespace [3pt]
Operator claims the kernel produced the observation & attestation signature and leaf inclusion & correct provider key; \mbox { EUF-CMA} \\
\addlinespace [3pt]
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
Kernel actually produced the recorded observation & not cryptographically established; independently checkable by replay & operator and replay-pipeline honesty, or faithful independent replay \\
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\addlinespace [3pt]
2026-08-15 12:17:03 +00:00
Recorded cone was produced by an audit that performed its checks & not established --- the audit driver is itself part of the replay pipeline & audit-gate integrity; adversarial gate self-tests reduce this exposure, they do not eliminate it \\
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\addlinespace [3pt]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Source corresponds to deployed binary & not established & reproducible build and compiler assurance \\
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
\addlinespace [3pt]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Claimed signer implementation produced STH & not established & execution provenance \\
\bottomrule
\end { tabularx}
\end { center}
2026-07-09 16:02:59 +00:00
paper v0.12 + estate: one numbering, everywhere — 0-based leaf indices
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
2026-08-16 18:04:44 +00:00
\section { Deployed leaf-12 scope} \label { app:entry13}
Leaf 12 contains the following deployment constraint,
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
quoted verbatim, in its machine-readable scope block:
\begin { quote} \small
Attestation scope: this corpus kernel-checks the listed theorems about the
mechanized recursive accumulator model. Correspondence with the deployed
inclusion verifier is supported by finite differential testing over the pinned
families. The deployed consistency verifier is not extensionally equal to the
model; applying the mechanized soundness result to the deployed consumer flow
additionally relies on an unmechanized authentic-size/root invariant
(KNOWN-GAPS 14/15).
2026-07-09 16:02:59 +00:00
\end { quote}
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Its exclusions name SHA-256 collision resistance, deployed-verifier extensional
equality, the signature/STH layer, and asymptotic cost claims.
\section { Compact receipt-verification core} \label { app:verifier}
The following code is only the Merkle inclusion core. A complete receipt
verifier must additionally validate the signed tree head, log identifier,
tree-size binding, public-key fingerprint or pinned key, leaf hash, and receipt
schema. The published log-repository verifier implements that full binding
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
list for every published receipt --- the binding fields are required, never
compare-if-present --- and fails closed when signature checking is
unavailable.
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { lstlisting} [language=Python]
import hashlib
def H(data):
return hashlib.sha256(data).digest()
def h_ leaf(data):
return H(b"\x 00" + data)
def h_ node(left, right):
return H(b"\x 01" + left + right)
def split_ below(n):
return 1 << ((n - 1).bit_ length() - 1)
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
def take(path, used):
if used >= len(path):
raise ValueError("proof exhausted")
return path[used]
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
def root(value, index, size, path, used=0):
if size == 1:
return value, used
k = split_ below(size)
if index < k:
left, used = root(value, index, k, path, used)
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
return h_ node(left, take(path, used)), used + 1
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
right, used = root(value, index-k, size-k, path, used)
paper v0.4: round-12 fix batch — both reviews absorbed, every blocker verified before fixing
All five GPT blockers, independently confirmed against source before
any edit, plus the real subset of the Opus findings:
- B1/M5: every strict-superset/strictly-more/larger-acceptance-set
claim (5 sites incl. two that wrap across source lines) replaced by
witnessed non-equivalence + pinned-family language; the Remark now
states explicitly that no global inclusion relation is claimed.
- B2: the optimistic-accountability/fraud-proof paragraph is REMOVED
(operator: bloat; GPT: technically wrong — consumers do not accept
by default, and a collision refutes the hash assumption rather than
attributing operator misconduct). The careful long-form analogy
stays in ltl-accumulator-verified/docs/optimistic-accountability.md.
- B3/M7: claim matrix — kernel-observation row split into operator-
CLAIMS (established) vs kernel-ACTUALLY-produced (not
cryptographically established); EUF-CMA/CR added where load-bearing.
- B4: artifact + Appendix C sentences now describe the upgraded
verifier (lean-transparency-log 52179bd: --all covers every
published receipt, binding fields required; 11-case adversarial
selftest GREEN).
- B5: pin-store sketch gains the equal-size/equal-root case via
whole-tree binding.
- M1 detached-signature honesty; M2 abstract axiom-name-sets +
compared-views narrowing; M3 kernel time -> end-to-end replay time;
M4+F4 consumers -> 'Consumer prototypes and version exactness'
(implemented prototype, informal check, explicit non-evaluation
disclaimer); M6 Appendix C listing fails closed on short proofs
(take() guard, verified empirically); M8-partial two alternatives-
table cells + design-taxonomy prose paragraph (also closes Opus F1
orphaned header); M9/F5 single experience report; M10 policy-
separation row in the coverage table; M11 27-line portability
number restored; F2 abstract 'via differential testing'; F3 linking
clause after the consistency theorem; Option-valued notation note
(both reviewers); GPT terminology sentence after Definition 2.
17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:19:46 +00:00
return h_ node(take(path, used), right), used + 1
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
def verify_ inclusion(leaf, index, size, path, expected_ root):
if size <= 0 or index < 0 or index >= size:
return False
try:
result, used = root(h_ leaf(leaf), index, size, path)
except ValueError:
return False
return used == len(path) and result == expected_ root
\end { lstlisting}
\section { Four Ed25519 verification tiers} \label { app:tiers}
2026-07-09 17:27:13 +00:00
\begin { center} \small
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
\begin { tabular} { @{ } lll@{ } }
2026-07-09 17:27:13 +00:00
\toprule
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
Tier & Meaning & Upstream Lean declaration \\
2026-07-09 17:27:13 +00:00
\midrule
paper v0.3: the reinvention — accountable distribution of machine-checked evidence
Executes the approved reinvention outline, using the round-11 GPT-5.6
draft as base material; the operator remains the author of record and
this pass is the authorial fact-check + completion of that draft. New
title: 'Accountable Distribution of Machine-Checked Correctness
Evidence: A Transparency Model and the Lean Transparency Log' (16 pp).
Old 19-page system report archived byte-identical as v0.2
(paper/ltl-v0.2.{tex,pdf}, served at /paper/v0.2; v0.1 unchanged).
Every factual claim in the draft was verified against the estate before
adoption: 222 inventoried constants + 61 reviewed cones (README:36),
all four fidelity counts, the gap-14 lied-size witness reproduced
empirically (deployed verify_consistency(1,3,R2,R3,P)=True while the
recursive model rejects; honest 2->3 True/True), all four apex theorem
names greped from the dalek repo, the entry-13 scope block now quoted
VERBATIM (was silently trimmed), the new klaus2026 citation confirmed
real via the arXiv API (author order corrected to Klaus, Conejero,
Tolmach), remaining 20 bibitems byte-identical to the F10-verified set.
Author corrections beyond the draft: 'opaque SHA-256 function' ->
uninterpreted/boundary AXIOM (matches axiom sha256 : List UInt8 -> Hash);
STH field list now matches the deployed head (adds type tag); lied-size
mechanism sentence from the gap ledger; six-published-heads (sizes 8-13)
mirror honesty; consumers subsection (warden + Swiss Post family-level
negative) per outline item 7; optimistic-accountability related-work
paragraph per outline item 8; fifteen-gap ledger pointer per outline
item 9; verify.py fail-closed tie-ins in artifact availability and
appendix C; wired the six uncited bibitems (lean4, pnueli, eddsa,
rfc8032, edwards+twisted, easycrypt); certificate listing gains the
deployed 'diagnostics' field. Build: 16 pages, 0 overfull, 0 undefined.
web.py: /paper/v0.2 route + loader. webdocs: paper card rewritten for
v0.3 with both archived versions linked. Suite 115 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 07:39:04 +00:00
T1 & byte-level acceptance equation & \code { verify_ accepts_ iff} \\
T2 & canonical encoding lift & \code { verify_ accepts_ iff_ point} \\
T3 & injectivity / point equation & \code { verify_ accepts_ iff_ point_ eq} \\
T4 & constructive decompression lift & \code { verify_ accepts_ iff_ decompress} \\
2026-07-09 17:27:13 +00:00
\bottomrule
\end { tabular}
\end { center}
2026-07-09 16:02:59 +00:00
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
All four tiers share one opaque boundary --- the SHA-512 challenge hash
and the selected wire-format interfaces (\S \ref { sec:instantiation} );
the arithmetic and group certificates beneath them rest on Lean's
foundational axioms alone.
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
\section { SLH-DSA verification certificates and their cones} \label { app:slhtiers}
Eleven certificates over the extracted SLH-DSA-SHA2-128s verify path
(leaf 18). Beyond Lean's three foundational axioms, each certificate's
exact axiom set consists of the uninterpreted hash oracles listed ---
enforced by the audit as set equality in both directions, so the table is
machine-checked, not documentation. The cone grows with the layer: pure
digit/byte arithmetic rests on the kernel alone; the apex carries all
five oracles.
\begin { center} \small
\begin { tabular} { @{ } lll@{ } }
\toprule
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
Layer & Lean declaration(s) & Oracles in the cone \\
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
\midrule
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
Digit/byte plumbing & \code { to_ int_ loop_ eq} , \code { to_ byte_ loop_ eq} & --- \\
& \code { wots_ csum_ loop_ eq} , \code { base2b_ outer_ loop_ eq} & \\
Chain walk & \code { chain_ free_ loop_ eq} & \code { f} \\
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
WOTS pk recomputation & \code { wots_ loop1_ eq} & \code { f} \\
XMSS Merkle ascent & \code { xmss_ loop_ eq} & \code { h} \\
FORS inner ascent & \code { fors_ inner_ loop_ eq} & \code { h} \\
FORS outer loop & \code { fors_ outer_ loop_ eq} & \code { f} , \code { h} \\
paper form round: every defect from the socratic inspection fixed + check-paper.sh gate
Triggered by the operator's hint (references flow into App A but a full
break sits between B and C). Full-document inspection found and fixed:
- ghost page 23 (~85% blank): the fossil \clearpage before Appendix C,
placed under an older pagination, removed; appendix policy now
DECLARED: the block starts on a fresh page, then flows with no
internal breaks
- claim matrix (the paper's honesty centerpiece): solid-set rows merged
visually and narrow justified columns gaped (badness-10000 in every
build log, never read) -- now ragged-right columns, 3pt row air,
EUF-CMA/SHA-256 unbreakable
- Figure 3 still drew the July 13-leaf snapshot in a v0.11 paper that
narrates 19 leaves -- extended: leaves 13-18, August-2026 brace,
dual-signed size-19 head box, pq-styled leaf 18
- ConsRec hyphenated as Con-sRec and set in serif vs sans elsewhere ->
math-face identifiers in the mechanization table
- 'tuple' stranded its last syllable as a whole line in Definition 1;
'timestamp' broke as times-tamp -> mbox + \hyphenation
- thesis box hyphenated its showcase slogan -> ragged-right no-hyphen
(first attempt justified+nohyphen was caught by the new gate itself)
- Appendix E header caps + layer-cell caps + continuation row cleanup;
related-work 3.4pt overfull removed
- NEW check-paper.sh: fails on overfull>10pt, any badness-10000, ghost
pages (<300 chars/page), missing version on title page, ?? refs;
4-check selftest; renders all pages for the mandatory eye pass
All 25 pages re-rendered and flipped by eye. Gate green. Tests green.
2026-08-16 13:27:56 +00:00
Hypertree walk & \code { ht_ loop_ eq} & \code { f} , \code { h} , \code { t_ l} \\
Acceptance characterization & \code { slh_ verify_ 128s_ accepts_ iff} & all five \\
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
\bottomrule
\end { tabular}
\end { center}
The oracles model the parameter set's SHA-256 hash-suite instantiations:
\code { h_ msg} (message digest), \code { f} (chain step and FORS leaf),
\code { h} (Merkle node), \code { t_ l} and \code { t_ len} (the WOTS and FORS
compressors --- two axioms over what is one Rust primitive, deliberately
conservative, with the source's naming inversion against the standard's
paper v0.13: the Green-persona approachability revision
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
2026-08-17 09:53:40 +00:00
$ T _ \ell $ /$ T _ k $ documented at the declarations). The acceptance characterization is proved directly from the verifier's
structure, not by composing the ten loop theorems --- it would remain
provable if any of the ten were deleted. Conversely, each loop
certificate carries assurance only insofar as a human has checked its
reference fold against the corresponding FIPS~205 algorithm.
paper v0.11: the paper catches up to the system it built
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
2026-08-16 11:14:57 +00:00
The LTL paper: 4-page arXiv draft, claim-disciplined
paper/ltl.tex + built PDF: "LTL: the Lean Transparency Log -
Distributing Machine-Checked Proof Evidence via an Authenticated Data
Structure Signed by Its Own Certified Artifact". Exactly four pages,
two-column, self-contained (embedded bibliography, TikZ figure of the
real 8-leaf log with the self-certifying signature loop).
Structure: intro (the consumption-economics argument), the LTL
(roles, replay-attestation leaves, boundary-exact auditing,
observation-not-verdict, pinning + git witness), the self-certifying
signature (with the honest verify-path/signing-path distinction),
deployment & evidence (the failure leaves as a feature; the full
assumption enumeration; the proof-portability observation with real
divergence numbers), related work (Rekor/CT/PCC/CONIKS/in-toto
engaged head-on; Cheval-Moreira-Ryan as the complementary direction -
"they verify the log; we log the verification"), limitations, and the
next-step agenda (Lean-verified RFC 9162 verifiers with SHA-256
collision resistance as a documented boundary axiom, certificates
entering the log they defend; EverCrypt/verified-Merkle prior art
credited).
Claim discipline verified on the rendered text: zero hype vocabulary,
explicit does-not-establish list, full trusted-base enumeration,
single-operator/TOFU/prototype-scale limitations stated, AI drafting
assistance acknowledged. References verified against the literature
(Sigstore CCS'22, Aeneas ICFP'22, HACL* CCS'17, Fiat-Crypto S&P'19,
EverCrypt S&P'20, in-toto USENIX'19, CONIKS USENIX'15, RFC
6962/9162/8032, Necula POPL'97, Lean 4 CADE-28, Bernstein et al.).
Footnote acknowledges the linear-temporal-logic acronym collision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:14:38 +00:00
\end { document}