Repository navigation
Conversation
… set
verifierStatus "live" now means the oracle verifies the primitive at
/settle today, and the live ids are exactly the oracle's /settle verified
set (evidence #3195, agreed by the oracle #3274). Today that set is
{decl.self_attested}.
approval.payer, receipt.kernel_signed and confirm.execution_mode move to
"stub". Their machinery works outside /settle (the payer-approval route,
kernel signing, the mock gate), but /settle does not run their verifiers
yet. Marking them live let the oracle-enforcing eligibility path
(requireImplementedVerifier) count a tier as fundable on checks the
settlement path never makes.
The field is outside VOCAB_MANIFEST_HASH, so the vocabulary golden hash
does not move. New tests pin the live set, show that each flipped
primitive caps the tier that needs it under enforcement, and show that
decl.self_attested still carries tier 0. Four mutants (each flip reverted,
and decl demoted) are each killed by 2 tests.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0117ows6894R3n6YQXBCRahS
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
verifierStatus: "live"inpackages/spec/src/evidence/primitives.tsnow means the oracle verifies this primitive at/settletoday. The set of live ids is exactly the oracle's/settleverified set. This is the lockstep rule, proposed by evidence (bus #3195) and agreed by the oracle (bus #3274).Today that set is
{decl.self_attested}. Three primitives move fromlivetostub:approval.payer/settledoes not authenticate approvals yet (the oracle's O8d)receipt.kernel_signed/settledoes not verify kernel receipts yetconfirm.execution_mode/settledoes not run the execution-mode gate yetWhy
The oracle-enforcing eligibility path (
computeCsdEligibility(..., { requireImplementedVerifier: true })) treats a live primitive as able to carry a tier. #349's committed-program gate uses that path to decide whether a program is fundable at a tier. With these three marked live, it would count a tier as fundable on checks that the settlement path never makes. Now each one caps the tier that needs it, until/settleruns its verifier. The oracle flips a primitive back to live in the same change that makes/settlerun it. Per #3274, the next one isident.registered_key(#416's verifier), once the fundedsnapshotHashis transported.Safety
verifierStatusis outsideVOCAB_MANIFEST_HASH, so the vocabulary golden hash does not move.eligibility.ts, and only in enforcing mode. The gateway readsverifierStatusonly formachine.execution_log, which was already stub and is unchanged.Tests (DGX Spark)
packages/spec: 799/799 passed;tsc --noEmitis clean.evidence-primitives.test.ts: 43 tests, 2 of them new.{decl.self_attested}, and each of the three flipped primitives is asserted stub.decl.self_attestedstill carries tier 0.decl.self_attested.Draft. Merging is the operator's call. Needs a coord-watch review (it touches assurance).
🤖 Generated with Claude Code
https://claude.ai/code/session_0117ows6894R3n6YQXBCRahS