Skip to content

fix(spec): verifierStatus lockstep with the oracle's /settle verified set - #422

Draft
LamaSu wants to merge 1 commit into
masterfrom
fix/evidence-verifier-status-lockstep
Draft

LamaSu wants to merge 1 commit into
masterfrom
fix/evidence-verifier-status-lockstep

Conversation

@LamaSu

@LamaSu LamaSu commented Sep 24, 2026

Copy link
Copy Markdown
Owner

What

verifierStatus: "live" in packages/spec/src/evidence/primitives.ts now means the oracle verifies this primitive at /settle today. The set of live ids is exactly the oracle's /settle verified set. This is the lockstep rule, proposed by evidence (bus #3195) and agreed by the oracle (bus #3274).

Today that set is {decl.self_attested}. Three primitives move from live to stub:

Primitive Why it was live Why it is now stub
approval.payer the gateway's payer-approval route works /settle does not authenticate approvals yet (the oracle's O8d)
receipt.kernel_signed kernels sign receipts (emit side, 7 producers) /settle does not verify kernel receipts yet
confirm.execution_mode the mock/dry-run gate works /settle does not run the execution-mode gate yet

Why

The oracle-enforcing eligibility path (computeCsdEligibility(..., { requireImplementedVerifier: true })) treats a live primitive as able to carry a tier. #349's committed-program gate uses that path to decide whether a program is fundable at a tier. With these three marked live, it would count a tier as fundable on checks that the settlement path never makes. Now each one caps the tier that needs it, until /settle runs its verifier. The oracle flips a primitive back to live in the same change that makes /settle run it. Per #3274, the next one is ident.registered_key (#416's verifier), once the funded snapshotHash is transported.

Safety

Tests (DGX Spark)

  • packages/spec: 799/799 passed; tsc --noEmit is clean.
  • evidence-primitives.test.ts: 43 tests, 2 of them new.
    • The live set is pinned to {decl.self_attested}, and each of the three flipped primitives is asserted stub.
    • Under enforcement, a report-only tier-2 CSD built from those primitives caps at tier 0, with each primitive named as the reason.
    • decl.self_attested still carries tier 0.
  • Mutation check: 4 mutants, each killed by 2 tests. They revert each flip to live, and demote decl.self_attested.

Draft. Merging is the operator's call. Needs a coord-watch review (it touches assurance).

🤖 Generated with Claude Code

https://claude.ai/code/session_0117ows6894R3n6YQXBCRahS

… set

verifierStatus "live" now means the oracle verifies the primitive at
/settle today, and the live ids are exactly the oracle's /settle verified
set (evidence #3195, agreed by the oracle #3274). Today that set is
{decl.self_attested}.

approval.payer, receipt.kernel_signed and confirm.execution_mode move to
"stub". Their machinery works outside /settle (the payer-approval route,
kernel signing, the mock gate), but /settle does not run their verifiers
yet. Marking them live let the oracle-enforcing eligibility path
(requireImplementedVerifier) count a tier as fundable on checks the
settlement path never makes.

The field is outside VOCAB_MANIFEST_HASH, so the vocabulary golden hash
does not move. New tests pin the live set, show that each flipped
primitive caps the tier that needs it under enforcement, and show that
decl.self_attested still carries tier 0. Four mutants (each flip reverted,
and decl demoted) are each killed by 2 tests.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0117ows6894R3n6YQXBCRahS

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant