mirror of
https://github.com/saymrwulf/proof-aware-crypto-tooling-agent.git
synced 2026-09-04 20:03:40 +00:00
site: the one-story card is gone; SHA-512 introduced where it first appears
The 'Paper and log, one story' card served OUR revision history, not the reader — removed without replacement. SHA-512 appeared unexplained; now its first mention says why it exists in assumption lists at all (the hash inside Ed25519, treated as an assumption, not as proven).
This commit is contained in:
parent
c5268ef46c
commit
6fcaaaee42
1 changed files with 3 additions and 12 deletions
|
|
@ -42,7 +42,6 @@ _STYLE = """
|
||||||
.sw{display:inline-block;width:.8rem;height:.8rem;border-radius:3px;vertical-align:-1px;margin-right:.3rem}
|
.sw{display:inline-block;width:.8rem;height:.8rem;border-radius:3px;vertical-align:-1px;margin-right:.3rem}
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
|
||||||
def _leaf_ok(entry: LogEntry) -> bool:
|
def _leaf_ok(entry: LogEntry) -> bool:
|
||||||
certificates = ((entry.leaf.get("attestation") or {}).get("certificates")) or []
|
certificates = ((entry.leaf.get("attestation") or {}).get("certificates")) or []
|
||||||
return bool(certificates) and all(
|
return bool(certificates) and all(
|
||||||
|
|
@ -50,14 +49,12 @@ def _leaf_ok(entry: LogEntry) -> bool:
|
||||||
for certificate in certificates
|
for certificate in certificates
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
def _leaf_short(component: str) -> str:
|
def _leaf_short(component: str) -> str:
|
||||||
"""Compact display name for a leaf box at small spans."""
|
"""Compact display name for a leaf box at small spans."""
|
||||||
return (component.replace("-ed25519-verified", "")
|
return (component.replace("-ed25519-verified", "")
|
||||||
.replace("ltl-accumulator-verified", "accum")
|
.replace("ltl-accumulator-verified", "accum")
|
||||||
.replace("fips205-slhdsa-verified", "slh-dsa"))
|
.replace("fips205-slhdsa-verified", "slh-dsa"))
|
||||||
|
|
||||||
|
|
||||||
def _svg_tree(entries: list[LogEntry], root_hex: str, signing_backend: str, head_label: str = "Ed25519") -> str:
|
def _svg_tree(entries: list[LogEntry], root_hex: str, signing_backend: str, head_label: str = "Ed25519") -> str:
|
||||||
"""The accumulator, drawn from its real leaves."""
|
"""The accumulator, drawn from its real leaves."""
|
||||||
if not entries:
|
if not entries:
|
||||||
|
|
@ -126,7 +123,6 @@ def _svg_tree(entries: list[LogEntry], root_hex: str, signing_backend: str, head
|
||||||
out.append("</svg>")
|
out.append("</svg>")
|
||||||
return "".join(out)
|
return "".join(out)
|
||||||
|
|
||||||
|
|
||||||
def _trust_anchor_html(log: TransparencyLog, metadata: dict[str, Any], base: str, mirror: str) -> str:
|
def _trust_anchor_html(log: TransparencyLog, metadata: dict[str, Any], base: str, mirror: str) -> str:
|
||||||
"""The provider public key, displayed in full on the front page. The key
|
"""The provider public key, displayed in full on the front page. The key
|
||||||
is the one thing a consumer takes on trust, once - hiding it behind a
|
is the one thing a consumer takes on trust, once - hiding it behind a
|
||||||
|
|
@ -176,7 +172,6 @@ verify against it.</p>
|
||||||
· <code>curl -s https://ltl.zkdefi.org/log-public-key</code></p>
|
· <code>curl -s https://ltl.zkdefi.org/log-public-key</code></p>
|
||||||
{slh_block}</div>"""
|
{slh_block}</div>"""
|
||||||
|
|
||||||
|
|
||||||
def render_docs(log: TransparencyLog, base_path: str) -> str:
|
def render_docs(log: TransparencyLog, base_path: str) -> str:
|
||||||
base = "/" + base_path.strip("/") if base_path.strip("/") else ""
|
base = "/" + base_path.strip("/") if base_path.strip("/") else ""
|
||||||
metadata = log.metadata()
|
metadata = log.metadata()
|
||||||
|
|
@ -374,7 +369,9 @@ is not something this site hands you at verification time — it is a
|
||||||
<strong>requirements card</strong> that lives in <em>your</em> tooling, on
|
<strong>requirements card</strong> that lives in <em>your</em> tooling, on
|
||||||
<em>your</em> disk, and that you can read in five minutes or rewrite from first
|
<em>your</em> disk, and that you can read in five minutes or rewrite from first
|
||||||
principles: Lean's three foundational axioms, plus — for the signature tiers only (the top proof layers, where full signature verification is proven) —
|
principles: Lean's three foundational axioms, plus — for the signature tiers only (the top proof layers, where full signature verification is proven) —
|
||||||
named placeholders for SHA-512 and the wire format. Your tooling ignores this
|
named placeholders for SHA-512 (the hash function Ed25519 uses internally —
|
||||||
|
the proofs treat it as an assumption, not as proven) and the byte-level wire
|
||||||
|
format. Your tooling ignores this
|
||||||
operator's pass/fail labels entirely and re-derives every verdict by comparing the
|
operator's pass/fail labels entirely and re-derives every verdict by comparing the
|
||||||
attestation's <em>observed</em> axiom list (its cone) against <em>your</em> card, name by name.
|
attestation's <em>observed</em> axiom list (its cone) against <em>your</em> card, name by name.
|
||||||
The operator is trusted to copy down what the proof kernel printed — never to
|
The operator is trusted to copy down what the proof kernel printed — never to
|
||||||
|
|
@ -408,12 +405,6 @@ instantiation section for the SLH-DSA (FIPS 205) verify path — eleven cer
|
||||||
five uninterpreted hash oracles, exact cones — and a certificate appendix mirroring the
|
five uninterpreted hash oracles, exact cones — and a certificate appendix mirroring the
|
||||||
Ed25519 tiers.</div>
|
Ed25519 tiers.</div>
|
||||||
|
|
||||||
<div class="card"><strong>Paper and log, one story.</strong> Since the August 2026 revisions the paper
|
|
||||||
describes this deployment as it runs — nineteen leaves, dual-signed heads, the
|
|
||||||
post-quantum verify path as leaf 18 with its own certificate appendix. The log is
|
|
||||||
append-only and keeps growing past any paper revision; every number the paper states
|
|
||||||
stays checkable against the retained history: the mirror clone from rung 1 of the
|
|
||||||
ladder re-verifies all of it, paper-era and after.</div>
|
|
||||||
|
|
||||||
<p class="muted">Log heads are signed offline; this service is read-only and holds no
|
<p class="muted">Log heads are signed offline; this service is read-only and holds no
|
||||||
key material. Provider tooling, agent tooling, and the full Jupyter course live in the
|
key material. Provider tooling, agent tooling, and the full Jupyter course live in the
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue