Skip to content

Export and validate claim/evidence recurrence decisions - #5

Merged
aliengineering-byte merged 4 commits into
mainfrom
growth/portfolio-proof-20260902
Sep 2, 2026
Merged

aliengineering-byte merged 4 commits into
mainfrom
growth/portfolio-proof-20260902

Conversation

@aliengineering-byte

@aliengineering-byte aliengineering-byte commented Sep 2, 2026 •

Copy link
Copy Markdown
Owner

Outcome

VerifAxis 0.2.0 exports a complete claim/evidence recurrence artifact and validates it offline. The artifact binds the explicit claim, verifier packets, packet hashes, complete recurrence trace, derived evidence chain, and named stopping decision. Conflicting writes remain no-clobber.

The public verifier treats artifact files as untrusted strict UTF-8 JSON and now enforces a 1 MiB file limit, 32-level depth limit, 50,000-node limit, and 1,024-packet limit. Duplicate keys, malformed Unicode, digest tampering, trace-chain tampering, and conflicting summaries fail closed.

The OpenAI-compatible adapter refuses credential-like headers over remote plain HTTP, permits credentialed HTTP only for explicit loopback testing, rejects URL-embedded credentials, bounds/strictly parses response JSON, and redacts transport error details.

Research and security boundary

This remains an exploratory alpha runtime, not a truth machine, sandbox, hallucination eliminator, or evidence-authentication system. Evidence can contain prompts, candidates, verifier output, counterexamples, and timestamps and must be handled as sensitive data.

Validation

  • Ruff format/check: pass
  • strict mypy: pass
  • pytest: 76 passed; branch coverage observation 76%
  • Python 3.11/3.12/3.13 CI: pass
  • wheel and sdist build: pass
  • Twine/README rendering: pass
  • package metadata and contents inspected; License-Expression: Apache-2.0
  • clean wheel demo → export → offline verify: pass
  • tampered public artifact: rejected with exit 2
  • clean sdist installation and demo: pass
  • secret scans and git diff --check: pass

Publication is separate from this PR. PyPI currently has no verifaxis project, and no repository publisher credential or trusted-publisher configuration is available in this environment.

@aliengineering-byte
aliengineering-byte merged commit 24d6f27 into main Sep 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant