proof-aware-crypto-tooling-.../notebooks
mrwulf fbe40c3dfe The log goes public: git-published mirror, online service, witnesses
Three synchronized faces of one log - transport orthogonal to trust:

- PUBLISHED GIT MIRROR: log-publish exports the public face (one file
  per leaf so git history mirrors log history; the FULL STH history as
  the witness channel; per-component attestations + receipts; the
  provider public key; a standalone stdlib-only verify.py and customer
  README). Live at github.com/saymrwulf/lean-transparency-log (genesis:
  8 leaves incl. the honest failed-run entries, dogfood-signed head).
- ONLINE SERVICE (pacta_provider serve): read-only, zero-dependency
  HTTP with CT-style endpoints under a base path for
  zkdefi.org/lean-transparency-log - /v1/sth, /v1/sth-history,
  /v1/sth-consistency?first=N, /v1/proof, /v1/attestation, /v1/entries,
  /v1/metadata, /healthz - plus self-contained customer documentation
  at /docs (current state, attested components, API, the verify-
  without-trusting-this-site path, and the means/does-NOT-mean
  boundary). The process never loads private keys: heads are signed
  offline; a compromised server can withhold or replay (pinning +
  freshness detect both) but never forge. STH history now recorded
  append-only by the provider (with a backfill head signed for the
  existing log).
- AGENT ONLINE CLIENT: pacta log-fetch (download evidence; explicitly
  UNVERIFIED until receipt-verify runs - transport is not trust) and
  pacta sth-refresh (fetch head, verify signature, advance the pin via
  an online consistency proof from the pinned size; fail closed).
- WITNESSES: pacta witness-audit over a clone of the published mirror
  recomputes every prefix root from the public leaves and checks every
  historical head + signature - no consistency proofs needed when the
  leaves are public. Tampering one published entry trips both the
  leaf-hash check and the prefix-root check (tested). verify.py gives
  customers the same audit with zero installation.
- DEPLOY.md: the complete server-session checklist for zkdefi.org -
  reconstruct the servable log FROM the published mirror (the server
  stays in witness trust-position), hardened systemd unit, nginx/Caddy
  path routing, Forgejo mirror setup, the provider->world update
  cycle, and remote smoke tests.

Validated end-to-end on the REAL log: all 10 endpoints, online-fetched
proof re-verified locally through the dogfood verifier with pinning,
online pin refresh, publish + witness audit green, tamper caught,
standalone verify.py green in the published clone. 54/54 tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 16:05:20 +02:00
..
00_course_map.ipynb Mirrored lectures 6a/6b: the authenticated structure, drawn and domain-separated 2026-07-06 15:26:32 +02:00
01_threat_model_and_truth_boundary.ipynb Curriculum: the ratchet rule, the four-tier reality, and lecture 9 (dogfood) 2026-07-06 10:18:06 +02:00
02_claim_cards_and_risk_model.ipynb Curriculum: the ratchet rule, the four-tier reality, and lecture 9 (dogfood) 2026-07-06 10:18:06 +02:00
03_lean_replay_and_axiom_audit.ipynb add proof-aware crypto curriculum notebooks 2026-07-03 14:42:59 +02:00
04_proof_hygiene_and_boundaries.ipynb add proof-aware crypto curriculum notebooks 2026-07-03 14:42:59 +02:00
05_third_party_attestation_provider.ipynb REAL EVIDENCE: guarded replay of all four repos, attested, logged, dogfooded 2026-07-06 14:54:48 +02:00
06_merkle_transparency_logs.ipynb Mirrored lectures 6a/6b: the authenticated structure, drawn and domain-separated 2026-07-06 15:26:32 +02:00
06a_provider_build_the_log.ipynb Mirrored lectures 6a/6b: the authenticated structure, drawn and domain-separated 2026-07-06 15:26:32 +02:00
06b_agent_verify_inclusion.ipynb The log goes public: git-published mirror, online service, witnesses 2026-07-06 16:05:20 +02:00
07_agent_consequences.ipynb Curriculum: the ratchet rule, the four-tier reality, and lecture 9 (dogfood) 2026-07-06 10:18:06 +02:00
08_capstone_research_program.ipynb Curriculum: the ratchet rule, the four-tier reality, and lecture 9 (dogfood) 2026-07-06 10:18:06 +02:00
09_dogfood_verified_crypto.ipynb Lecture 9: dogfood now bidirectional (sign mode + provider self-inclusion); notebooks README course list updated 2026-07-06 15:27:16 +02:00
README.md Lecture 9: dogfood now bidirectional (sign mode + provider self-inclusion); notebooks README course list updated 2026-07-06 15:27:16 +02:00

PACTA Curriculum Notebooks

This directory contains a zero-to-hero teaching sequence for proof-aware cryptographic tooling.

Start with 00_course_map.ipynb, then proceed in order. The notebooks are intentionally output-free in git. Run them from the repository root or from this directory; each notebook locates the repo root and imports pacta from src/.

The course teaches:

  • theorem-boundary thinking,
  • claim cards and residual risk,
  • Lean replay and axiom audit concepts,
  • proof hygiene,
  • third-party proof-check provider trust,
  • RFC 9162-style Merkle transparency logs,
  • the mirrored provider/agent domain split (6a: one provider builds and dogfood-signs the log; 6b: many agents verify inclusion in ~25 lines, no Lean),
  • receipt-gated agent consequences (including the R4 wallet gate, now reachable),
  • split-view defense: STH pinning, consistency enforcement, freshness, monitoring,
  • dogfood verified cryptography and the honest hybrid post-quantum posture,
  • research roadmaps from R4 evidence toward R5 assurance.

This curriculum is not financial advice, not a trading bot, and not a wallet-building guide. It is a training path for engineers and researchers who need to evaluate formal-verification-enhanced cryptographic tooling without overclaiming.