diff --git a/ESTATE.md b/ESTATE.md index cf9fb49..3aa6fe4 100644 --- a/ESTATE.md +++ b/ESTATE.md @@ -9,7 +9,7 @@ machinery hub and the only repo that changes freely. State snapshot (2026-07-22): log **13 leaves**, root `3488a2d0…`, key fingerprint `874c8a00…`, paper **v0.9 camera-ready (23 pp)**, five -attested components, one campaign open (SLH-DSA — **zero +attested components, one campaign open (SLH-DSA — **eleven certificates**), pacta suite 144 green. ```mermaid @@ -28,7 +28,7 @@ flowchart LR r["risc0-ed25519-verified
16 certs · leaf 10"] b["betrusted-ed25519-verified
16 certs · leaf 11"] p["pasta-pallas-verified
field layer only · NOT attested"] - f["fips205-slhdsa-verified
campaign in progress · 0 certs · NOT attested"] + f["fips205-slhdsa-verified
11 certs proven · reviewer attest-with-conditions · NOT in the log"] c["ltl-accumulator-verified
61 certs · entry-13 subject · frozen 172a1d0"] end subgraph M["MACHINERY — pacta + operator-held"] @@ -122,7 +122,7 @@ deployed verifier; see the corpus KNOWN-GAPS ledger). | `fips205-source` | upstream | verbatim snapshot of `integritychain/fips205` (pure-Rust FIPS 205 / SLH-DSA); upstream pin `30bac08`, snapshot head `5dca0db` — single deviation: upstream CI workflows stripped, documented in-commit | pinned; moves only for transparent, individually-justified Aeneas-compat patches (nothing proposed upstream) | | `dalek-` / `anza-` / `risc0-` / `betrusted-ed25519-verified` | subject | Rust source + Lean proofs; 16 certs each; attested (leaves 8–11, generations at 0–7) | frozen at attested commits; branch moves only for docs | | `pasta-pallas-verified` | subject | field layer proven; curve layer pending; **not attested** | changes freely | -| `fips205-slhdsa-verified` | subject | SLH-DSA (FIPS 205) verify-path campaign, parameter set SLH-DSA-SHA2-128s; **campaign in progress — zero certificates, `check.sh` non-green by design**; not attested | changes freely — campaign | +| `fips205-slhdsa-verified` | subject | SLH-DSA (FIPS 205) verify-path campaign, parameter set SLH-DSA-SHA2-128s; **11 certificates proven, `check.sh` green with an 18-attack self-test, outside-reviewer attest-with-conditions**; not appended to the log | changes freely — campaign | | `ltl-accumulator-verified` | subject | 61-cert corpus about the log's accumulator model; **entry-13 subject**, frozen `172a1d0` | frozen; doc-only commits allowed | | `proof-aware-crypto-tooling-agent` (this repo) | machinery | provider service, consumer library, warden (+ local read-only cockpit), dogfood signer, paper, course, tests | **changes freely — the hub** | | `lean-transparency-log` | published | the public mirror: leaves, heads, receipts, fail-closed `verify.py` + selftest | **generated by publish** — canonical files here, templates in pacta, CI-pinned | @@ -149,7 +149,7 @@ deployed verifier; see the corpus KNOWN-GAPS ledger). | provider write side (check / append / publish / sign) | **on demand** | operator machine | runs only during an append ceremony, minutes at a time; the signing key is offline otherwise | | warden (the financial agent) | **not running** | nowhere | implemented prototype: a wallet directory plus CLI/MCP/cockpit processes that exist only while explicitly started; no deployed instance, no funds watched | | custody cockpit | **on demand** | operator machine, localhost | `pacta wallet cockpit`, stops with Ctrl-C; read-only | -| SLH-DSA campaign (`fips205-source` + `fips205-slhdsa-verified`) | **no process** | — | static repos, **zero certificates yet**; extraction/proof sessions are episodic operator-machine runs under lean-guard | +| SLH-DSA campaign (`fips205-source` + `fips205-slhdsa-verified`) | **no process** | — | static repos, **11 certificates**; extraction/proof sessions are episodic operator-machine runs under lean-guard | | everything else (repos, paper, book, mirror, SD) | **no process** | — | static files; consumers and reviewers are external and episodic | The human-facing interactive rendering of this whole map, runtime