Two edits. (1) The alternatives paragraph of section 1 now states the
frame the site opens with, in paper register: each alternative fails on
one of two sides — checking cost stays with the consumer, or it
disappears because belief in a label is demanded — and the primitive
studied occupies the point between. (2) The introduction's italic
question said 'opaque provider verdict' where the abstract says
'label'; aligned to label, consistent with the v0.13 verdict/label
separation. Gate green, 25pp, page 2 eye-checked.
Operator order: every page of the PUBLISHED PDF inspected by eye, all
25. The flip surfaced two referee items the v0.13 batch had missed:
(1) the notation summary lacked rows for the consistency proof C and
the flag b (both load-bearing from Theorem 3 through Lemma 4) — added,
with Ext pointing at its defining subsection; the gate rejected the
first, too-wide row (130pt overfull) and the shortened one passed;
(2) the HIST chain length still shared the letter k with the Merkle
split point on facing pages — renamed to ell through the game,
Theorem 5, its proof, and Theorem 8's cost term. Gate green: v0.14,
25pp; pages 8 and 13 re-eyed; suite 156.
A referee persona (deep crypto, shallow Lean, no prior drafts) read the
whole paper; all findings applied, ~40 edits, none touching technical
content:
- house terms defined at first use: certificate (in contributions),
accumulator (= the log's Merkle tree + verifiers), signed view (4.2),
pin rule/pin-store (named at their definition, 4.3), axiom cone as the
one canonical synonym, loop-fidelity glossed, facade tied to its entry
point, scope block named in 3.1, oracles marked 'uninterpreted
function symbols, not random oracles'
- operator 'verdict' renamed label everywhere (Verdict stays the
consumer algorithm); fork disambiguated (codebases vs fork evidence)
- notation: declarations T_i -> Theta_i (tier collision), HIST chain
k kept but challenge scalar -> c and signature bytes -> R-bar
(k/r_1 overloads resolved); tiers T1-T4 introduced in 6.1 body
- theorem-statement sensitivity: Thm 8 scoped to the recursive
verifiers in the STATEMENT; Prop 1's 'exhibited' made conditional
with pointer; Thm 3 carries its honest-pin note; Def 2(iii) gets the
forgery caveat; Lemma 5 declared a restatement of Prop 2
- ghost references resolved (whole-tree root binding stated in place,
twice); revision residue purged (Post-submission -> Subsequently
closed; tense unified; hardened state, guarded replay, KNOWN-GAPS
explained); 6.2 retitled 'A second instantiation'
- six triple-read sentences rewritten per referee (them-sentence,
vacuous->trivially-by-counting with real non-vacuity guard wording,
pin supplier, physical-execution antecedent, bridges-land, App E
factorization)
- appendices A-D now each cited from the body; App D states its shared
opaque boundary; FIPS 205 added to the bibliography [23] and cited
- abstract divergence sentence rewritten (divergence not 'boundary',
past tense, closure named, 'the corresponding log entry')
Gate green: v0.13, 25pp; pages 1/16/25 eye-checked; suite 156.
Operator order: the leaf-index convention adopted this morning must be
global. Paper1 now says leaf 12 in every place that said entry 13
(intro, contributions, section 7.2, related work, conclusion, artifact
availability, Appendix B retitled 'Deployed leaf-12 scope'); the
ordinal 'thirteenth entry' survives only as a gloss. v0.12, 25pp, gate
green, Appendix B page eye-checked. Site card follows (v0.12; revision
prose de-versioned so it cannot churn), paper/README history extended,
top README says leaf 12/17/18. reinvention-outline moved to the private
control repo earlier this commit-series (moat doctrine).
The freeze rationale is gone (review concluded); v0.11 describes the
LIVE deployment instead of the July snapshot:
- abstract + contributions: nineteen leaves, four Ed25519 corpora at 44
certs, the accumulator's two attestations, leaf 18 = the SLH-DSA
verify path; heads dual-signed since size 14 with the parameter set
the log itself attests
- signed-tree-heads section: the additive deterministic SLH-DSA
co-signature, ABSENT-not-failed history honesty, determinism as an
audit primitive, the closed loop to leaf 18
- new instantiation subsection 'The SLH-DSA verify path: the method on
second terrain': 11 certificates, acceptance characterization, the
no-second-semantics honesty (visible-not-correct), exact cone
enforcement, scope (mono facade + 137-case bridge, base_2b, no
signing)
- deployment/public state: 15 August 2026, root 7ee23940, twelve heads
8-19, per-leaf narrative through 18
- NEW Appendix E: the eleven SLH-DSA certificates with their exact
oracle cones — the mirror of Appendix D's Ed25519 tiers
- title: v0.11; site card + snapshot note + paper/README updated
25pp, zero unresolved refs, Appendix E render-inspected by eye; full
test suite green
Operator finding 2026-08-15: the live site still said 'v0.9 — frozen
while under journal review' and advertised the superseded v0.1/v0.2
drafts. Fixed at the source:
- webdocs.py paper card: v0.10, revised August 2026 (version now also
printed on the PDF title page); the divergence description gains its
closure (the sn=0 conjunct, zero divergences, three-way regression);
the freeze-era reconciliation card shrunk to a tight snapshot-vs-today
paragraph; fragile '12 Jupyter lectures' count dropped
- web.py: /paper serves the current paper only; all old-variant routes
404 (git history retains the drafts); ltl-v0.1/v0.2 files removed from
the working tree, paper/README updated
- ltl.tex: title page now reads 'Revised: August 2026 — v0.10' (the
version travels IN the PDF, per operator order); rebuilt
- tests updated to ENFORCE the retirement (all old variants must 404);
full suite 152 passed
The review process concluded 2026-08 (operator released the hold). Folds
in exactly the staged erratum-queue + v0.10 items, nothing else:
- corpus count sentence made historical (sixteen at the studied leaves;
forty-four per fork since — the log records both generations)
- the 3,867/73,573 divergence finding gains its closure everywhere it
appears: root cause = deployed verifier omitted RFC 9162 S2.1.4.2
Step 7's terminal sn=0 condition (fixed in ddbb5a4); zero divergences
post-fix, three-way regression
- new limitations paragraph 'Replay-harness integrity' (a wrong
observation needs no malice)
- adversary model: defective-harness clause
- claim matrix: 'recorded cone was produced by an audit that performed
its checks — not established' row
- title page carries 'Revised: August 2026'; submitted v0.9 (7f140356)
preserved in git history; paper/README signpost updated
paper/README.md tells a visitor that ltl.pdf is the submitted version
frozen during review, that v0.1/v0.2 are superseded history, and that
v0.3-v0.9 live in git history. Also corrects the stale web.py comment
that labeled the live pdf 'v0.3 reinvention' (it is the v0.9 submitted
version). No served bytes change; the comment fix reaches the droplet
with the next routine app update.