From 5bea4c85cb1d961af76d3335e2731ade48cfd3c0 Mon Sep 17 00:00:00 2001 From: mrwulf Date: Sun, 16 Aug 2026 18:20:04 +0200 Subject: [PATCH] =?UTF-8?q?evidence:=20name=20the=20capture=20honestly=20?= =?UTF-8?q?=E2=80=94=20STH=20at=20capture=20time=20(size=208),=20pointer?= =?UTF-8?q?=20to=20today's=20live=20state?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- evidence/README.md | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/evidence/README.md b/evidence/README.md index b7d6c1a..764df3c 100644 --- a/evidence/README.md +++ b/evidence/README.md @@ -4,12 +4,17 @@ Signed, transparency-logged attestations from a REAL guarded replay of the four `saymrwulf/*-ed25519-verified` repositories (2026-07-06/07, ~30 min of Lean re-checking per fork under `lean-guard` memory caps). +This directory is a dated capture, kept byte-stable on purpose: every file +verifies against the head it cites. The live log has since grown (19 leaves, +dual-signed heads); `python3 verify.py --all` in the public mirror re-checks +today's full state. + | File | What it is | |---|---| | `-ed25519.attestation.yaml` | Signed proof-check attestation: repo commit, environment, machine-protection block, and all 16 certificates with their OBSERVED axiom cones (the four apex tiers carry the fork's exact documented boundary) | | `-ed25519.receipt.yaml` | RFC 9162-style inclusion receipt binding the attestation into the transparency log (tree size 8), with a consistency anchor | | `provider.ed25519.pub` | The provider's public key (the PRIVATE key never leaves `provider/state/`, which is gitignored) | -| `log-metadata.json`, `latest-sth.yaml` | Log identity and the latest Signed Tree Head | +| `log-metadata.json`, `latest-sth.yaml` | Log identity and the Signed Tree Head at capture time (tree size 8) | | `log-audit.txt` | Monitor self-check output (recomputed root matches the signed root) | The log holds EIGHT leaves: entries 0-3 are the first run's attestations,