All five GPT blockers, independently confirmed against source before any edit, plus the real subset of the Opus findings: - B1/M5: every strict-superset/strictly-more/larger-acceptance-set claim (5 sites incl. two that wrap across source lines) replaced by witnessed non-equivalence + pinned-family language; the Remark now states explicitly that no global inclusion relation is claimed. - B2: the optimistic-accountability/fraud-proof paragraph is REMOVED (operator: bloat; GPT: technically wrong — consumers do not accept by default, and a collision refutes the hash assumption rather than attributing operator misconduct). The careful long-form analogy stays in ltl-accumulator-verified/docs/optimistic-accountability.md. - B3/M7: claim matrix — kernel-observation row split into operator- CLAIMS (established) vs kernel-ACTUALLY-produced (not cryptographically established); EUF-CMA/CR added where load-bearing. - B4: artifact + Appendix C sentences now describe the upgraded verifier (lean-transparency-log 52179bd: --all covers every published receipt, binding fields required; 11-case adversarial selftest GREEN). - B5: pin-store sketch gains the equal-size/equal-root case via whole-tree binding. - M1 detached-signature honesty; M2 abstract axiom-name-sets + compared-views narrowing; M3 kernel time -> end-to-end replay time; M4+F4 consumers -> 'Consumer prototypes and version exactness' (implemented prototype, informal check, explicit non-evaluation disclaimer); M6 Appendix C listing fails closed on short proofs (take() guard, verified empirically); M8-partial two alternatives- table cells + design-taxonomy prose paragraph (also closes Opus F1 orphaned header); M9/F5 single experience report; M10 policy- separation row in the coverage table; M11 27-line portability number restored; F2 abstract 'via differential testing'; F3 linking clause after the consistency theorem; Option-valued notation note (both reviewers); GPT terminology sentence after Definition 2. 17 pages, 0 overfull, dead-phrase sweep clean. Suite 115 green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| src/pacta_provider | ||
| pyproject.toml | ||
| README.md | ||
PACTA Proof Check Provider
This nested project is a prototype third-party proof-checking service. It reuses host Lean/Aeneas infrastructure, runs portable PACTA replay/audit checks, and emits signed attestation certificates.
It does not modify anything outside this repository. It may read configured toolchains such as /Users/oho/GitClone/ClaudeCodeProjects/your-lean-project/aeneas-toolchain/env.sh.
It can also maintain a local transparency log. The log is an RFC 9162-style Merkle accumulator over signed attestations. It emits Signed Tree Heads with Ed25519 today and records an ML-DSA/FIPS 204 signature slot as unavailable unless a real backend is present. Agents that require both signatures must reject such receipts.
Commands
PYTHONPATH=src:provider/src python -m pacta_provider discover
PYTHONPATH=src:provider/src python -m pacta_provider init-key --key-dir provider/state/demo-provider
PYTHONPATH=src:provider/src python -m pacta_provider check \
--config examples/repos.yaml \
--repo-name dalek-ed25519-verified \
--repo repos/dalek-ed25519-verified \
--provider local-pacta-provider \
--private-key provider/state/demo-provider/provider.ed25519.key \
--public-key provider/state/demo-provider/provider.ed25519.pub \
--out provider/out/dalek.attestation.yaml
Transparency log:
PYTHONPATH=src:provider/src python -m pacta_provider log-init \
--log-dir provider/state/transparency-log \
--provider local-pacta-provider \
--public-key provider/state/demo-provider/provider.ed25519.pub
PYTHONPATH=src:provider/src python -m pacta_provider log-append \
--log-dir provider/state/transparency-log \
--attestation provider/out/dalek.attestation.yaml \
--private-key provider/state/demo-provider/provider.ed25519.key \
--public-key provider/state/demo-provider/provider.ed25519.pub \
--out provider/out/dalek.receipt.yaml
PYTHONPATH=src:provider/src python -m pacta_provider log-sth \
--log-dir provider/state/transparency-log \
--private-key provider/state/demo-provider/provider.ed25519.key \
--public-key provider/state/demo-provider/provider.ed25519.pub
The resulting certificate can be consumed by pacta with --attestation, --trust-attestation-provider, and --attestation-public-key.
The receipt can be consumed with --transparency-receipt, --transparency-log-public-key, and --require-transparency-receipt.
The private key must remain provider-side. Downstream agents only need the public key, the inclusion receipt, and a policy decision that the provider name/log key is trusted.