Skip to content

OrbitalProof · wireless, post-quantum and protocol bounds

w s enc ⁣:WorldwFins, readback ⁣:FinsFinwFin3.(wldc. readback(encwld)c=obswwldc)  2ws;at w=2 with member-path attribution: s32=9>22\forall w\ \forall s\ \forall\,\mathrm{enc}\colon \mathrm{World}\,w\to\mathrm{Fin}\,s,\ \mathrm{readback}\colon \mathrm{Fin}\,s\to\mathrm{Fin}\,w\to\mathrm{Fin}\,3.\quad \bigl(\forall \mathit{wld}\,c.\ \mathrm{readback}\,(\mathrm{enc}\,\mathit{wld})\,c=\mathrm{obs}\,w\,\mathit{wld}\,c\bigr)\ \Rightarrow\ 2^{w}\le s;\qquad \text{at } w=2 \text{ with member-path attribution: } s\ge 3^{2}=9>2^{2}

A duplicate-eliminating receiver that must answer, from its state alone, what it saw in each of w sequence-number slots needs at least 2^w states — for every window width, every encoder and every readback. At a two-slot window, a receiver that must also say which member path carried the first copy needs 9 states, strictly more than the 4 the bitmap in the standard describes.

Checked by the Lean kernel, statements read and not merely named.

receipt
path
f3/lean/frer_local_check.json
sha256
8ea778fd0c685dd2a32c737a28b9f08117da86654c9d21675a9b1437fcee937a
bytes
1280
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/lean/frer_local_check.json | shasum -a 256
open receipt

Every sentence of substance on this page ends in a receipt. Drop a certificate to check one yourself, offline.

Read what we got wrong — the overclaim confession, verbatim, and the candidates we killed at their own bar.

⊢ sealed bar
Graded against a bar sealed before the run · protocol-bench-sealed-model-run

Under a bar hashed into git before the model weights were fetched, a language model was scored on fifteen published IEEE 802.11 and 3GPP procedures and answered "safe" on every one: balanced accuracy 0.5, zero counterexamples produced and therefore zero replayed, and a raw accuracy of 0.8667 that is exactly the score of a constant that always says "safe". All three sealed predictions held, and the benchmark's replay requirement gave the model no credit for a detection it never made.

receipt
path
f3/artifacts/backends/protocol_bench_model_run.json
sha256
ca2f94aef3bdcd1fdb10266038d3a5fe52033b1eff65533753044a5dca59cda8
bytes
2728
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/protocol_bench_model_run.json | shasum -a 256
open receipt

Stranger Verifier

Drop a certificate. The check runs in this page, offline. Go offline first if you want to watch it not phone home.

runs in your browser · no networkformat certkit/farkas/v1 — a Farkas certificate bound by spec_fingerprint to the specification it was issued against (specs are certkit/spec/v1; atoms carry rational coefficients as [numerator, denominator] integer pairs). Also f2/decoder-audit/v2 — a certificate whose canonical body hashes to its own certificate_sha256, is signed Ed25519 over that canonical body, and commits to an outcome trace by a Merkle root (sha256, 0x00 leaf prefix, 0x01 node prefix, leaf hashes sorted, odd node promoted).source
receipt
path
f2/oss/stranger-verifier/verifier.html
sha256
e31466e52fa8c9859a21d7b02089d59b8fce754da9335368c1a3c1a9a2cabc9c
bytes
58220
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/oss/stranger-verifier/verifier.html | shasum -a 256
open receipt
Every step is a gate: the build refuses a sentence with no receipt, a receipt it does not serve, a hash that is not the served file's, and an instruction naming a file that is not there.
runs in your browser · no networkonline · format certkit/farkas/v1 — a Farkas certificate bound by spec_fingerprint to the specification it was issued against (specs are certkit/spec/v1; atoms carry rational coefficients as [numerator, denominator] integer pairs). Also f2/decoder-audit/v2 — a certificate whose canonical body hashes to its own certificate_sha256, is signed Ed25519 over that canonical body, and commits to an outcome trace by a Merkle root (sha256, 0x00 leaf prefix, 0x01 node prefix, leaf hashes sorted, odd node promoted).
Drop a certificate here
or . Accepted: .json, application/json. Nothing leaves this page.
network requests during check:

Theorems and Bounds

Each statement is rendered from its LaTeX, restated in plain English, and followed by what it forecloses. Private theorems are not on this page at all.

Third-party systems graded against a sealed bar

The bar was preregistered before the measurement. Both receipts are on each row; the preregistration comes first.

sealedrunmeasured
target systembar, sealed before the runmeasured
Qwen2.5-1.5B-Instruct, greedy decoding, one completion per task
Three predictions hashed into git before the weights were fetched: balanced accuracy in [0.40, 0.70]; at most one replayed counterexample; the KRACK trace must not replay.
receipt
path
f3/artifacts/prereg/protocol_bench_qwen_bar.json
sha256
ccc5e38a1ec1b03bb9f351a2447e2287c0d669987501be8bb92595287bad503e
bytes
3011
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/prereg/protocol_bench_qwen_bar.json | shasum -a 256
open receipt
All three held. Balanced accuracy 0.5, zero valid counterexamples, KRACK did not replay. The number the bar did not ask for is the sharp one: raw accuracy 0.8667 is exactly the trivial always-safe baseline, with recall 1.0 on safe procedures and 0.0 on violated ones. A fabricated-trace control was run first and scored zero.
receipt
path
f3/artifacts/backends/protocol_bench_model_run.json
sha256
ca2f94aef3bdcd1fdb10266038d3a5fe52033b1eff65533753044a5dca59cda8
bytes
2728
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/protocol_bench_model_run.json | shasum -a 256
open receipt
Seventeen published IEEE 802.11 and 3GPP procedures, modelled from their specifications
The expected classification of every procedure was written into the source before the search ran.
receipt
path
f3/telecom_formal/formal_models/published/__init__.py
sha256
7b56f8059889d7f45a9bc09e55f94842eda03b893fab943d3a4fb0ffeb2b8ae5
bytes
8648
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/telecom_formal/formal_models/published/__init__.py | shasum -a 256
open receipt
Zero classification mismatches across seventeen procedures. Three known counterexamples were re-derived, including KRACK; thirteen were proven safe over the modelled state space; one remains a candidate with no published citation found, and is published as an open question rather than a finding.
receipt
path
f3/telecom_formal/reports/published/counterexample_ledger.json
sha256
1f5b457d250b52eba08d68b5cb5d700479d16a5da4fd26c37f2d320132887671
bytes
6576
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/telecom_formal/reports/published/counterexample_ledger.json | shasum -a 256
open receipt
Eight sibling repositories in this estate, scanned for a committed result whose scope their own published command cannot produce
Sealed before any foreign tree was read, including a two-sided prediction that one named case would NOT be flagged. [Site-thread note: this preregistration is published as a path and a sha256, not as bytes. Its text records the absolute roots the scan walked, which names the machine that ran it, and that text sits inside the region the seal's own sha256 covers - redacting it would void the seal rather than protect anything. So the seal stays intact and the bytes stay off this site. A reader can check that the hash on the chip matches a copy obtained from the lane, and cannot read the bar here. That is a weaker offer than every other row on this page makes.]
receipt
path
f3/artifacts/prereg/s08_scope_defaults_estate.json
sha256
6488b42e97d388fc685500ee213dc86dc0d0df6a947ef00acfe23bd495184be7
bytes
3442
visibility
sealed

Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

The prediction held, and for a different reason than sealed: the producer joins a module constant rather than a literal. One finding survived verification. A second was refuted by its target and withdrawn, because the scanner had paired a producer with an artifact it only names. Three further flags were numeric co-occurrences and were refuted by hand before anything was sent to anyone.
receipt
path
f3/artifacts/backends/scope_defaults_estate.json
sha256
709067459433e3f62dec7aa41b89bf0c7e6446736631566819f9cc36ad70d480
bytes
27051
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/scope_defaults_estate.json | shasum -a 256
open receipt
Every MCP server in this estate, including this lane's own
Sealed before any server was read: the prediction was that most declare no capability annotations at all.
receipt
path
f3/artifacts/prereg/s08_capinfer_estate_servers.json
sha256
ad74f7264a4ea5965edaaf385e4bfbbaa075d8833ed2d234edbbd4e75cb17dc1
bytes
2297
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/prereg/s08_capinfer_estate_servers.json | shasum -a 256
open receipt
Ten server modules across eight repositories. Zero declare readOnlyHint, destructiveHint, idempotentHint or openWorldHint. The capability grader was 15 of 15 green in the same session, including a live sandbox run, so this is a property of the servers and not a broken tool. The observation half was not run, because with nothing declared there is nothing to contradict.
receipt
path
f3/artifacts/backends/mcp_annotation_census.json
sha256
e22788bbfd805b564abb71241877d5e0fab16901f286016abd70ae83a078a3df
bytes
5806
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/mcp_annotation_census.json | shasum -a 256
open receipt
Show the remaining 12 of 16 graded systems
target systembar, sealed before the runmeasured
The Linux kernel's eBPF verifier, given a monitor compiled from this repository's own proofs
Sealed before any load: accept or reject with the verifier's log captured verbatim, and a deliberately corrupted twin must be rejected differently. Both outcomes were declared publishable.
receipt
path
f3/artifacts/prereg/bpf_kernel_load_bar.json
sha256
a61c49b3b768bef3bdac080bd557243bf142335b508415ba4f4db043b93f997d
bytes
2491
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/prereg/bpf_kernel_load_bar.json | shasum -a 256
open receipt
Rejected under this lane's loader with 424 bytes of log. That result was then narrowed by us and overturned by measurement: the loader applies none of the object's twelve relocations, and under a relocating loader on another lane's kernel the same object is ACCEPTED at 182 instructions. The kernel never refused the monitor.
receipt
path
f3/monitorgen/artifacts/kernel_load.json
sha256
803e94bec7cac2694a0f356f72a9a087f7b5e628a81b36c0a55a609b0a61d5fc
bytes
1940
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/monitorgen/artifacts/kernel_load.json | shasum -a 256
open receipt
yosys, pono and eqy on a SKY130 gate-level netlist
Sealed before the run: all five acceptance fields true, and identity with the committed receipt outside a declared volatile set. The skip path was run first as the control and reproduced the stub.
receipt
path
f3/artifacts/prereg/asic_live_bar.json
sha256
ec5164cb543347182ffc460c05bbc2c6457875ed969ab8ba3b209fb9351563fa
bytes
2566
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/prereg/asic_live_bar.json | shasum -a 256
open receipt
Executed true, three modules re-proved by two hardware-model-checking engines, logical equivalence certified, and the receipt identical to the committed one outside the volatile fields.
receipt
path
f3/artifacts/asic_flow_v38.json
sha256
5d34c18b6b3eebc1d4f7afad605d7760e1a07819cbe0920fdf057dd44c0f028f
bytes
7450
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/artifacts/asic_flow_v38.json | shasum -a 256
open receipt
Composite ML-KEM (LAMPS draft), OpenPGP PQC (RFC 9980), CMS KEMRecipientInfo (RFC 9629), JOSE/COSE PQ-KEM (draft-ietf-jose-pqc-kem-05)
Each combiner is MAL-BIND-K-PK only if it binds every non-binding component's public key into the key derivation. The expectation column was written into the matrix before the prover ran, and all 38 prover verdicts were sealed before they were re-run, at commit 17e4fd3 2026-09-02. The DISCOVERY predates that seal and is therefore not blind: the seal fixes the verdict list and the blind re-derivation, not the finding.
receipt
path
f4/conformance/predictions/outward_provers.json
sha256
58a3e2a7d087676937782bf6a9366f34af680e517bda32843bb0f340e1bad21c
bytes
3831
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/outward_provers.json | shasum -a 256
open receipt
4 of 4 break the notion, as expected; five Tamarin models transcribed independently from the same standards' field lists reach the sealed verdict; the recipient public key is absent from the key derivation in all 4, confirmed against re-fetched normative text for the 2 published RFCs; and this lane's 3 attack flows all FAIL against a kill list written first. The other three artifacts behind this row are artifacts/native/outward_provers_ci.json, artifacts/native/pqc_keytransport_spec_evidence_ci.json and artifacts/native/pqc_keytransport_exploitability_ci.json.
receipt
path
f4/artifacts/native/kem_combiner_binding_audit_ci.json
sha256
458648980b4f8cabb77dfcfe1ca81d84d764247f44428c357359f8e069487493
bytes
9006
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/kem_combiner_binding_audit_ci.json | shasum -a 256
open receipt
pq-crystals/dilithium at commit d35ba3fe
Every front-page claim verdicted from a closed vocabulary, under a bar sealed at commit 0097cbe 2026-09-02 before the instrument knew a second target existed.
receipt
path
f4/conformance/predictions/claimbom_dilithium.json
sha256
a215a21f9c77fe3d930e2ccc6229e427be9eb4534825c3722a903dd86be1526b
bytes
2980
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/claimbom_dilithium.json | shasum -a 256
open receipt
13 rows; 1 of 9 material claims refuted; the reference signature vectors reproduce 5 of 5.
receipt
path
f4/artifacts/claimbom/pq-crystals-dilithium.bom.json
sha256
02a1c81115c6b9b0b764d1212d1830d512e0f5af92311543a0a25c1c5a1bcfea
bytes
364193
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/artifacts/claimbom/pq-crystals-dilithium.bom.json | shasum -a 256
open receipt
pq-code-package/mlkem-native at commit a1b94a1d
The same closed vocabulary and the same materiality rule, sealed at commit 870639c 2026-09-02 before the instrument knew a third target existed. If the findings track code quality the tally should look nothing like the first target's; if they track README age it should look the same.
receipt
path
f4/conformance/predictions/claimbom_mlkem_native.json
sha256
20246faf0010ac7c5463f1b24aa8c46a507aa43741a8e23830090fe0308d3f9b
bytes
2960
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/claimbom_mlkem_native.json | shasum -a 256
open receipt
11 rows; 0 of 7 material claims refuted. The instrument goes quiet exactly where the code is formally verified, which is the result.
receipt
path
f4/artifacts/claimbom/pq-code-package-mlkem-native.bom.json
sha256
601e9729579fb3f9466f832f3d7c6b7757072802bb7b76448aab867e6778e334
bytes
252610
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/artifacts/claimbom/pq-code-package-mlkem-native.bom.json | shasum -a 256
open receipt
7 deployed hybrid post-quantum protocols (IKEv2 multiple key exchanges, TLS 1.3 X25519MLKEM768, SSH post-quantum key exchange, Wi-Fi PQC SAE, MLS, EAP-TLS with ML-KEM, Signal PQXDH)
Each protocol's main model must RESIST and a named teeth model, written before the run, must BREAK. A family artifact binds every verdict to the digest of the model file it came from, so a citing lane's sentence fails loudly when a model moves. Sealed at commit 681d9ba 2026-09-02, RECORDED not blind and the seal says so; the citation object was sealed separately at 508f74b 2026-09-04 in conformance/predictions/hybrid_citation.json, and its result is artifacts/native/hybrid_downgrade_citation.json.
receipt
path
f4/conformance/predictions/hybrid_family_seven.json
sha256
af2dbfa3c33d43665fbb0e206c030d08f0fa87d811d9e18d818fd1036c766287
bytes
1647
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/hybrid_family_seven.json | shasum -a 256
open receipt
7 of 7 RESIST, 7 of 7 teeth BREAK. Appending one byte to any cited model makes verification exit non-zero and name that model. One row, opportunistic wireless encryption, BREAKs by design and any lane citing the family must carry it.
receipt
path
f4/artifacts/native/pqc_hybrid_downgrade_family_ci.json
sha256
5d65a8f8e9a7543a2411ebe4bc3fa3a34cb8f34d63619702881a14965fed1783
bytes
5868
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqc_hybrid_downgrade_family_ci.json | shasum -a 256
open receipt
OpenSSL 3.6.4 and liboqs 0.16.0, all three ML-KEM parameter sets
A contract sealed at commit a3194e4 2026-09-02 before either release was built into its scratch prefix, with a tampered-ciphertext control at every parameter set.
receipt
path
f4/conformance/predictions/interop_3p_contract.json
sha256
4b6d9a3082a551e83b70098e9cdbaa75c88bdfaaf80c7c645db75c026a7880ff
bytes
1675
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/interop_3p_contract.json | shasum -a 256
open receipt
24 of 24 checks pass. This row is here because an instrument that only ever reports failure is not an instrument: the third party passed its bar and the result is published at the same weight.
receipt
path
f4/artifacts/native/interop_3p_ci.json
sha256
6feca0be5f16c2754236770c129f84ae60232558ae277e2364457a6c2c87aa8d
bytes
2388
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/interop_3p_ci.json | shasum -a 256
open receipt
libxml2 xmlBuildQName (the shipped fix for CVE-2025-6021) and OpenSSL kek_unwrap_key (the shipped fix for CVE-2025-9230)
Fourteen boolean predictions about both guards, committed before the checker ran.
receipt
path
f2/artifacts/seals/cve_2025_guards_2026-09.seal.json
sha256
efb1af43fccd81d969e63fd3106dd3166d7ef41874105ba151a7103760c015c9
bytes
1526
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/artifacts/seals/cve_2025_guards_2026-09.seal.json | shasum -a 256
open receipt
Thirteen held. libxml2's guard is not sound unconditionally and is sound under a stated precondition, with a counterexample outside it; OpenSSL's fix is sound, tight, and provably the bounds predicate itself, while the check it replaced is unsound. The one miss was an in-run web call that came back rate-limited, not a proof key.
receipt
path
f2/out/seal_verify_cve_2025_guards_2026-09.txt
sha256
1ea397746f0a3d6065af7eaa34d1f54fb8e5077e0067019ef92c825b81324df6
bytes
1182
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_cve_2025_guards_2026-09.txt | shasum -a 256
open receipt
The Linux kernel's own BPF selftests, loaded into a live 6.8 kernel
Seven boolean predictions committed before the run, including that engine and kernel would disagree on no program.
receipt
path
f2/artifacts/seals/bpf_upstream_2026-09.seal.json
sha256
5e12f4e8231d560293fd06254ba7572a7cb9b0228c12ed04545a4033cfdacd47
bytes
744
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/artifacts/seals/bpf_upstream_2026-09.seal.json | shasum -a 256
open receipt
All seven held under a real verifier at log level two. An earlier predeclared bar on the same corpus was missed and published as missed rather than moved.
receipt
path
f2/out/seal_verify_bpf_upstream_2026-09.txt
sha256
6035a65a2c55f03559144f65de60fc2b95cf04470c8dec71fbf17eaf0026d0d7
bytes
505
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_bpf_upstream_2026-09.txt | shasum -a 256
open receipt
Cilium and Katran, at a newer upstream commit, on a live 6.8 kernel
Eight boolean predictions committed before the run.
receipt
path
f2/artifacts/seals/bpf_repin_2026-09.seal.json
sha256
b7d640911c6f21092fda8bf5c0a8e9750304dd2b780d9c014c045b1d54137f9e
bytes
1007
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/artifacts/seals/bpf_repin_2026-09.seal.json | shasum -a 256
open receipt
Seven held: every Cilium object built, the out-of-repo anchor accepted every published certificate, and the kernel's printed state agreed with the certificate on every property it measured. The miss was our own bar reading the wrong field of the pins block.
receipt
path
f2/out/seal_verify_bpf_repin_2026-09.txt
sha256
bf389e445dd1ae67d5dc429558f8ac20a7fa7d1b3792424bd7ba3e52ac09db0e
bytes
657
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_bpf_repin_2026-09.txt | shasum -a 256
open receipt
VTM, the VVC reference encoder
Three boolean predictions committed before a full re-run, including that the negative result would stand.
receipt
path
f2/artifacts/seals/real_vvc_inloop_2026-09.seal.json
sha256
dd74021c56e4efad8e021e388196615cc37adb0af26c08c21ad75eb43b158b47
bytes
583
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/artifacts/seals/real_vvc_inloop_2026-09.seal.json | shasum -a 256
open receipt
All three held: the in-loop kernel does not beat post-loop within a confidence interval that excludes zero. A kept negative on somebody else's reference software.
receipt
path
f2/out/seal_verify_real_vvc_inloop_2026-09.txt
sha256
08fb82b0184ac9893a05b4d12b247586b635aae654f2081b4782310b6ed9c5f5
bytes
269
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_real_vvc_inloop_2026-09.txt | shasum -a 256
open receipt
AOMedia AVM upstream (standing, not yet exercised)
Predictions committed in advance for the day upstream moves past the pinned commit.
receipt
path
f2/artifacts/seals/avm_drift_2026-09.seal.json
sha256
dd2d27b9db251e24f24dda872d382726cb543a9483f321c4bbdb91db769b6164
bytes
636
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/artifacts/seals/avm_drift_2026-09.seal.json | shasum -a 256
open receipt
Not exercised: upstream has not moved. The seal is armed and its outcome is not ours to choose.
receipt
path
f2/artifacts/avm-drift-check/drift.json
sha256
140fb291f8263c2559fef496194bc63dbbcf6149fc1853397fc8c8c453b38207
bytes
5911
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/artifacts/avm-drift-check/drift.json | shasum -a 256
open receipt
  1. w,s. (enc,readback. wldc. readback(encwld)c=obswwldc)2ws;s<32 ¬faithful at w=2\forall w,s.\ \bigl(\exists\,\mathrm{enc},\mathrm{readback}.\ \forall \mathit{wld}\,c.\ \mathrm{readback}\,(\mathrm{enc}\,\mathit{wld})\,c=\mathrm{obs}\,w\,\mathit{wld}\,c\bigr)\Rightarrow 2^{w}\le s;\quad s<3^{2}\Rightarrow\ \neg\,\text{faithful at } w=2

    Recovering what happened in each of w in-window sequence slots from state alone forces at least 2^w states, for every width. Adding member-path attribution forces 9 states at width two, against the 4 of a plain bitmap.

    forecloses Forecloses 'a cleverer encoding fits in the bitmap the standard already has': below the floor there is no encoding at all, not merely a worse one.

    receipt
    path
    f3/lean/frer_local_check.json
    sha256
    8ea778fd0c685dd2a32c737a28b9f08117da86654c9d21675a9b1437fcee937a
    bytes
    1280
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/lean/frer_local_check.json | shasum -a 256
    open receipt
  2. SNR(ϵ) rises 5.673 dB per decade of 1/ϵ;SNR(105)18.7858 dB, SNR(106)26.4421 dB\mathrm{SNR}^{*}(\epsilon)\ \text{rises } 5.673\ \text{dB per decade of } 1/\epsilon;\quad \mathrm{SNR}^{*}(10^{-5})\ge 18.7858\ \text{dB},\ \mathrm{SNR}^{*}(10^{-6})\ge 26.4421\ \text{dB}

    Each decade of reliability costs 5.673 dB in the declared Rician model, and one-in-a-million is unreachable below 26.4421 dB.

    forecloses Forecloses 'a better code closes the gap': a sphere-packing converse binds codes that have not been invented.

    receipt
    path
    f3/artifacts/wall_vs_reliability.json
    sha256
    b34d4478a431299dbf94d43192c84a0cf562b103f846486fdc91a404beda005d
    bytes
    45155
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/wall_vs_reliability.json | shasum -a 256
    open receipt
  3. logM(n)κϵn+o(n), κϵ=0.7090866971302584; n=409665.8856547523013 bits\log M^{*}(n)\le \kappa_{\epsilon}\sqrt{n}+o(\sqrt{n}),\ \kappa_{\epsilon}=0.7090866971302584;\ n=4096\Rightarrow \le 65.8856547523013\ \text{bits}

    Covert throughput against an optimal detector grows only as the square root of blocklength, so the per-use covert rate tends to zero.

    forecloses Forecloses 'more power or a better waveform buys a positive covert rate': the rate is zero in the limit regardless.

    receipt
    path
    f3/artifacts/covert_fbl_v98c.json
    sha256
    bc6a57509dbf7437687519e81b7640062d3b3d5eb40fe019fa4a3f901115e5dc
    bytes
    7320
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/covert_fbl_v98c.json | shasum -a 256
    open receipt
  4. I/O  3Nd words, for any algorithm, exact or approximate, on any hardware\text{I/O}\ \ge\ 3Nd\ \text{words, for any algorithm, exact or approximate, on any hardware}

    Any attention implementation must read every entry of Q, K and V at least once, so its memory traffic cannot fall below three times the input size.

    forecloses Forecloses 'an approximate kernel avoids the traffic': approximation does not exempt an algorithm from reading its input.

    receipt
    path
    f3/artifacts/attention_io_floor_v99.json
    sha256
    ef3cde4234d34e384cc9f440fbbe7e3e6bfb4eb611535c84ec61ac0c61b03a60
    bytes
    6610
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/attention_io_floor_v99.json | shasum -a 256
    open receipt
Show the remaining 30 of 34 theorems
  1. network words  383805.4537986715 at n=4096, M=1048576, against a single-device floor of 131072\text{network words}\ \ge\ 383805.4537986715\ \text{at } n=4096,\ M=1048576,\ \text{against a single-device floor of } 131072

    Splitting attention across devices adds a network-traffic floor of its own that no schedule beats, roughly three times the single-device input-scan floor at the pinned configuration.

    forecloses Forecloses 'sharding makes the I/O floor go away': it moves the cost onto the interconnect, where there is another floor.

    receipt
    path
    f3/artifacts/distributed_attention_floor_v101.json
    sha256
    42542a7f0ea4e7fd16d3f726254740254e97560e90ba26abb601c6113f60edcb
    bytes
    9114
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/distributed_attention_floor_v101.json | shasum -a 256
    open receipt
  2. T=0.17707148605111048 ms at 28GHz, v=10m/s, ϵ=105  (Jakes J0 principal-branch crossing)T^{*}=0.17707148605111048\ \text{ms at } 28\,\text{GHz},\ v=10\,\text{m/s},\ \epsilon=10^{-5}\ \ (\text{Jakes } J_{0}\ \text{principal-branch crossing})

    A beam or channel prediction becomes physically invalid 0.177 ms after it is made, in the declared isotropic-scattering model — a number derived from the Bessel correlation crossing, not tuned.

    forecloses Forecloses 'refresh cadence is an engineering preference': past this crossing the prediction is invalid regardless of the scheduler.

    receipt
    path
    f3/artifacts/staleness_floor_v93.json
    sha256
    f7425f7babd579ceece3f76cc44cb49d1f6313c607259b881bb4d143697b0cf9
    bytes
    11424
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/staleness_floor_v93.json | shasum -a 256
    open receipt
  3. EbN0min=10log10(ln2)=1.5917 dB (exact wideband converse)\frac{E_b}{N_0}\Big|_{\min}=10\log_{10}(\ln 2)=-1.5917\ \text{dB (exact wideband converse)}

    The wideband energy-per-bit converse sits at -1.5917 dB and no modulation reaches below it; the same kT ln 2 constant bounds the energy of erasing a bit.

    forecloses Forecloses 'a better waveform gets under the Shannon limit': the limit is a converse, and the Landauer twin applies only to irreversible computation, which the artifact states.

    receipt
    path
    f3/artifacts/energy_wall.json
    sha256
    09bcb8b72d7e41e65370d7c6f21f51924baff9b5ee5bb9ef2e1181706a067eda
    bytes
    2945
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/energy_wall.json | shasum -a 256
    open receipt
  4. rate  M^FMiscalibration300FactsPossible7n;monofact rate 0.2floor 0.189479\text{rate}\ \ge\ \hat{M}F-\text{Miscalibration}-300\tfrac{|\text{Facts}|}{|\text{Possible}|}-\tfrac{7}{\sqrt{n}};\quad \text{monofact rate } 0.2\Rightarrow \text{floor } 0.189479

    A model trained on facts that appear once in its corpus has a hallucination rate bounded below by the monofact rate, minus calibration and finite-sample terms: 0.189479 at a monofact rate of 0.2.

    forecloses Forecloses 'better training alone drives hallucination to zero': the floor is a property of the corpus, not the optimiser. A claimed rate of 0.0 is flagged by the artifact's own foil.

    receipt
    path
    f3/artifacts/hallucination_floor_v99h.json
    sha256
    6b02b6f94cbe9064435b2a908113b7f2e780464fe7064127d3470fa6641e87b2
    bytes
    4635
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/hallucination_floor_v99h.json | shasum -a 256
    open receipt
  5. captured share of converse-feasible savings=0.840000503469 (complex unconstrained); guard attains the policy optimum\text{captured share of converse-feasible savings}=0.840000503469\ \text{(complex unconstrained)};\ \text{guard attains the policy optimum}

    A tail-sum sphere-packing converse gives the physics floor on expected retransmission rounds, and the shipped guard captures 84.0% of the distance between the naive fixed policy and that floor.

    forecloses Forecloses 'a smarter stopping rule closes the remaining gap': the guard is already optimal among zero-false-ACK stopping rules under the four pinned assumptions.

    receipt
    path
    f3/artifacts/rounds_converse_v54.json
    sha256
    a2428baa4ebcc47fec016e51fab4d21016085ec60fb7b109738b66232d86029e
    bytes
    4555
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/rounds_converse_v54.json | shasum -a 256
    open receipt
  6. Over all 128 enumerated Boolean functions on the CEGIS observables: ngenuinely weaker and safe=0\text{Over all } 128 \text{ enumerated Boolean functions on the CEGIS observables: } n_{\text{genuinely weaker and safe}}=0

    Enumerating every Boolean function on the decision variables, none is both strictly weaker than the shipped guard and still safe.

    forecloses Forecloses 'a weaker guard would do': on those observables there is no weaker safe function, exhaustively.

    receipt
    path
    f3/artifacts/semantic_max_essentiality.json
    sha256
    01cfdb7e1ea8a39b80997bb01c4556dcbe1ccdeab635f973ba485de7ed58eac9
    bytes
    45044
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/semantic_max_essentiality.json | shasum -a 256
    open receipt
  7. Extending to 1-memory-bit Mealy automata: ngenuine weaker and safe survivors=0 at every hole\text{Extending to 1-memory-bit Mealy automata: } n_{\text{genuine weaker and safe survivors}}=0\ \text{at every hole}

    Giving the design-around a bit of memory does not help either: across thousands of automata per hole, none is weaker and safe.

    forecloses Forecloses 'add state and the ceiling lifts': one bit of memory does not lift it. Multi-bit memory is explicitly not claimed exhausted.

    receipt
    path
    f3/artifacts/automata_max_essentiality.json
    sha256
    88aa70a31d00f89c406a9f4dc16eb867690e02dc16d96973884ff94d50cbb446
    bytes
    6391
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/automata_max_essentiality.json | shasum -a 256
    open receipt
  8. No finite-memory, continuous, linear, randomized or deterministic-learned policy beats gmin\text{No finite-memory, continuous, linear, randomized or deterministic-learned policy beats } g_{\min}

    Four further policy families were closed by two QF_LRA unsatisfiability results and a kernel-checked refinement theorem: none of them beats the shipped guard.

    forecloses Forecloses 'the ceiling is an artefact of restricting to Boolean guards': it survives every family tested.

    receipt
    path
    f3/artifacts/mechanism_family_closure_v90.json
    sha256
    da5d5b0c6e5a0db062df149651a51e09c5bc675eec8f342cf3094aca6494d44e
    bytes
    20914
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/mechanism_family_closure_v90.json | shasum -a 256
    open receipt
  9. For 57 of 140 (pair, hazard) slots: no rule emitted by schema_to_rules can assign the field under ANY of 96×96=9216 trust assignments\text{For 57 of 140 (pair, hazard) slots: no rule emitted by } \mathrm{schema\_to\_rules}\ \text{can assign the field under ANY of } 96\times96=9216\ \text{trust assignments}

    For 57 informative composition slots, the hazard is unreachable for every trust model, checked exhaustively at 9,216 assignments per row by a structural route and confirmed by an independent z3 route.

    forecloses Forecloses 'you still need a runtime guard there': for those slots the hazard cannot arise under any trust assignment in the model.

    receipt
    path
    f3/artifacts/backends/impossibility.json
    sha256
    22f8d899c1f2a5126038e9b0e26a40979f995db373dc3869a9e5f8c97f6feece
    bytes
    188665
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/impossibility.json | shasum -a 256
    open receipt
  10. NsminB    NB/sminN\,s_{\min} \le B \;\Longrightarrow\; N \le \lfloor B / s_{\min} \rfloor

    For a memory budget B and a per-session floor s_min, no bounded-memory policy admits more than floor(B / s_min) unauthenticated sessions, and a quota of exactly that many attains B. Tight at all 5 concrete pairs.

    forecloses Any admission design that claims to bound memory and to seat more sessions than the floor allows. There is no third option: the quota is forced, not chosen.

    receipt
    path
    f4/artifacts/native/quota_curve_ci.json
    sha256
    f705b726e88606c1f1b1c1d823fc6b87eea197953989ed283d6d1f44845b4511
    bytes
    1776
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/quota_curve_ci.json | shasum -a 256
    open receipt
  11. log2k, and log2k suffices\ell \ge \lceil \log_2 k \rceil,\ \text{and}\ \lceil \log_2 k \rceil\ \text{suffices}

    k protocols on a shared base secret need at least ceil(log2 k) bits of separating domain label; the floor is attained. For k = 20 it is 5 bits.

    forecloses A domain-separation scheme shorter than the floor. It bounds length under exact comparison, not the content of the label, and a longer human-readable label meets it trivially.

    receipt
    path
    f4/artifacts/native/label_floor_ci.json
    sha256
    cf86d38e77da6c2f2a4eaec96bd6452b2ec46622dd0ddea28f7c5d3a32ea4558
    bytes
    2300
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/label_floor_ci.json | shasum -a 256
    open receipt
  12. ¬(bounded memoryno authentication before stateno refusal)\neg\big(\text{bounded memory} \wedge \text{no authentication before state} \wedge \text{no refusal}\big)

    A receiver cannot simultaneously bound its memory, create state before authenticating, and never refuse. Any two of the three are achievable; the three together are unsatisfiable.

    forecloses The design every deployment reaches for first: keep the memory bound, accept everyone, and never say no. One of the three has to go, and this says which choices remain.

    receipt
    path
    f4/artifacts/native/impossibility_filing_ci.json
    sha256
    4ec98413249bcdf10d86fec4a91889a0549a39b5a40f037947efe9f5a3ab64cc
    bytes
    1803
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/impossibility_filing_ci.json | shasum -a 256
    open receipt
  13. ¬(downgrade-resistanthybrid-capable¬cross-layer group binding)\neg\big(\text{downgrade-resistant} \wedge \text{hybrid-capable} \wedge \neg\,\text{cross-layer group binding}\big)

    A downgrade-resistant, hybrid-capable composition of an authentication exchange with a key handshake must bind the negotiated group across the layer boundary.

    forecloses Bolting a post-quantum exchange onto an existing handshake and leaving the group unbound across the seam, under an attacker who strips the post-quantum share.

    receipt
    path
    f4/artifacts/native/xlayer_impossibility_ci.json
    sha256
    282e58a7ce5cadb82e1454bdb86f0dcba8e5202b540e4bf033dbaf67b6f61103
    bytes
    1112
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/xlayer_impossibility_ci.json | shasum -a 256
    open receipt
  14. ¬(protocol isolationshared base secret¬domain label)\neg\big(\text{protocol isolation} \wedge \text{shared base secret} \wedge \neg\,\text{domain label}\big)

    Isolation between protocols derived from one base secret forces a domain label under a relay attacker. The label is not a convention; it is compelled.

    forecloses Reusing one post-quantum secret across protocols and arguing that context separation is implicit in the transcript.

    receipt
    path
    f4/artifacts/native/crossproto_impossibility_ci.json
    sha256
    5b068dd3a78a14815d47eaf9978cbf4135ba19740776b9a9a8539621e92daca3
    bytes
    1155
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/crossproto_impossibility_ci.json | shasum -a 256
    open receipt
  15. buffer(B)+[per-frame authentication]N  N\mathrm{buffer}(B) + [\text{per-frame authentication}]\cdot N \ \ge\ N

    A receiver reassembling a fragmented credential either buffers the fragments or authenticates each one. There is no third arrangement that covers the demand.

    forecloses A reassembly design that claims to avoid both the buffer and the per-fragment check. Machine-checked over the model, on top of a cited general bound.

    receipt
    path
    f4/artifacts/native/conservation_laws_ci.json
    sha256
    1f9e7bb5109c2ffe1c402669d3a773b11f44714d925623cce781fdcf156d9024
    bytes
    2024
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/conservation_laws_ci.json | shasum -a 256
    open receipt
  16. H(K)2k    Pr[deception]2kH(K) \ge 2k \;\Longrightarrow\; \Pr[\text{deception}] \le 2^{-k}

    Bounding an adversary's deception probability at 2^-k costs at least 2k bits of authentication key entropy. The cost is movable between mechanisms but cannot be removed.

    forecloses Claiming a deception bound while shrinking the key material that pays for it. The general form is cited, not ours; the deployed statement is machine-checked.

    receipt
    path
    f4/artifacts/native/conservation_laws_ci.json
    sha256
    1f9e7bb5109c2ffe1c402669d3a773b11f44714d925623cce781fdcf156d9024
    bytes
    2024
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/conservation_laws_ci.json | shasum -a 256
    open receipt
  17. evs: apTotal(run G CAP Rmin evs)G\forall\,\mathrm{evs}:\ \mathrm{apTotal}\big(\mathrm{run}\ G\ \mathrm{CAP}\ R_{\min}\ \mathrm{evs}\big) \le G

    Access-point-wide memory stays under its budget for every event sequence, with no hypothesis. Byte accounting seats eight half-filled sessions where the whole-window rule seats four, and refuses the ninth. 22 theorems, 12 audited for their kernel axioms.

    forecloses Per-session bounds presented as an access-point-wide guarantee. That conflation is retracted in this repository's own record, and this theorem is the unconditional replacement.

    receipt
    path
    f4/artifacts/native/lean_ap_bytes_ci.json
    sha256
    5434634fe6f1a7f75200464d1b87a1ce674d6910cecb74ff8e877b52ad6e86e2
    bytes
    3558
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/lean_ap_bytes_ci.json | shasum -a 256
    open receipt
  18. N=B/X=65536/12000=5N^{*} = \left\lfloor B / X \right\rfloor = \left\lfloor 65536 / 12000 \right\rfloor = 5

    A 65,536-byte access point carries at most 5 concurrent reassembly contexts before no per-session cap admits a 12,000-byte credential at all. The window closes.

    forecloses Sizing concurrency and credential size independently. Past the crossing point there is no cap to choose.

    receipt
    path
    f4/artifacts/native/reassembly_crossing_ci.json
    sha256
    014c5c33fef8a8b5100a5577614149818e242dcff45a53aeb2401b4b64345a6e
    bytes
    843
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/reassembly_crossing_ci.json | shasum -a 256
    open receipt
  19. AdvenvAdvCCA+AdvEUF+AdvCPAeph+AdvsepPRF,AdvCCA2qHAdvMLWE+δ+qdecδ\mathrm{Adv}_{\mathrm{env}} \le \mathrm{Adv}_{\mathrm{CCA}} + \mathrm{Adv}_{\mathrm{EUF}} + \mathrm{Adv}_{\mathrm{CPAeph}} + \mathrm{Adv}_{\mathrm{sepPRF}},\quad \mathrm{Adv}_{\mathrm{CCA}} \le 2 q_H \sqrt{\mathrm{Adv}_{\mathrm{MLWE}} + \delta} + q_{\mathrm{dec}}\delta

    The envelope's provable margin at a query budget of 2^64 hash queries is about 2^-16.5, not the 2^-164 correctness term it is often quoted as. The quantum-random-oracle transform loss is the dominant term and is now a number.

    forecloses Quoting a correctness parameter as a security margin. The signature term is left symbolic because no anchor for it exists here, and including it can only make the envelope larger.

    receipt
    path
    f4/artifacts/native/tightness_numeric_ci.json
    sha256
    91dea90bceecb0ce50c72e462474d1053bb3941921ded73920ca1e740dc88ba4
    bytes
    1348
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/tightness_numeric_ci.json | shasum -a 256
    open receipt
  20. Δair=ek+ct=1184+1088=2272 bytes\Delta_{\mathrm{air}} = |ek| + |ct| = 1184 + 1088 = 2272\ \text{bytes}

    ML-KEM-768 adds 2,272 bytes of key-exchange material per handshake in every deployed protocol that carries it, because the number is the algorithm's key and ciphertext size and not a property of the protocol.

    forecloses Protocol-specific optimism about the post-quantum handshake tax. It counts key-exchange bytes only; framing and retransmission are not included.

    receipt
    path
    f4/artifacts/native/pqc_handshake_onair_overhead_ci.json
    sha256
    85fcc9962fd2168c1c115b24c5a16c257040e155f0ea0dcf5f311e074bb9410b
    bytes
    2713
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqc_handshake_onair_overhead_ci.json | shasum -a 256
    open receipt
  21. Kfacet=26 (DRAT-checked, three solvers agreeing)K_{\mathrm{facet}} = 26\ \text{(DRAT-checked, three solvers agreeing)}

    The forced-gate lower bound over the frozen toggle vocabulary is 26, certified by a DRAT proof three solvers agree on. This lane's own record classifies the number as measured circularly over a vocabulary it also wrote.

    forecloses Nothing. It is listed so that a reader who finds the number elsewhere finds the retraction beside it, and so that no site thread promotes it.

    receipt
    path
    f4/artifacts/native/optimality_cert_ci.json
    sha256
    887300966344aacb6214c00fa1164bc3708f29b6241f1f13511a779d24db218e
    bytes
    7378
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/optimality_cert_ci.json | shasum -a 256
    open receipt
  22. Every subset-minimal dangerous composition of individually safe tools escaped the shipped policy; all were closed by further INSTANCES of the same gate types, none needed a new type.\text{Every subset-minimal dangerous composition of individually safe tools escaped the shipped policy; all were closed by further INSTANCES of the same gate types, none needed a new type.}

    Necessity is not sufficiency: the same five gate types, in the configuration we shipped, missed every minimal dangerous composition of tools that are each safe alone — and adding more instances of those same types caught all of them.

    forecloses Forecloses 'these gates are enough', including for us. We predicted this against our own interest and it held.

    receipt
    path
    f2/artifacts/crs/composition_overlap.json
    sha256
    3cde7c767c36099eaf1d61bcb8e3b06a254515906e28d328d4fd66542531f3d7
    bytes
    5972
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/composition_overlap.json | shasum -a 256
    open receipt
  23. No product domain iDi, at any precision, proves Pk for k2; the gap is zero at k=1 and positive from k=2.\text{No product domain }\textstyle\prod_i D_i\text{, at any precision, proves }P_k\text{ for }k\ge 2;\ \text{the gap is zero at }k=1\text{ and positive from }k=2.

    No verifier whose abstraction tracks each variable separately can prove the property our overlay certifies, however precise each component is made.

    forecloses Forecloses refining a non-relational analyser as a route to the same result.

    receipt
    path
    f2/artifacts/crs/relational_necessity.json
    sha256
    4be68bced6fef97e293be25eba6270166026e610f498add01b6ded4f24ad26ef
    bytes
    17616
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/relational_necessity.json | shasum -a 256
    open receipt
  24. Detecting the weakened guard requires Θ(1/ε) samples; the measured blind spot is a fixed fraction of the domain.\text{Detecting the weakened guard requires }\Theta(1/\varepsilon)\text{ samples; the measured blind spot is a fixed fraction of the domain.}

    The weakened patches sit in a region so small that random testing needs a number of draws proportional to its reciprocal to find them.

    forecloses Forecloses 'fuzzing would have caught it' for the patches this corpus contains.

    receipt
    path
    f2/artifacts/crs/impossibility_summary.json
    sha256
    7ac019714ee39192f1d9051119e0d1beaef12160191f9ca2bdf514b09eb5de4b
    bytes
    6317
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/impossibility_summary.json | shasum -a 256
    open receipt
  25. {x: g(x)¬s(x)} computed exactly for each gamed guard, every value positive.|\{x:\ g(x)\wedge\lnot s(x)\}|\ \text{computed exactly for each gamed guard, every value positive.}

    For a guard that passes its test battery we count exactly how many forbidden states it still admits — not an estimate, a count.

    forecloses Forecloses 'no failing test means no admitted state'.

    receipt
    path
    f2/artifacts/crs/gameability_measure.json
    sha256
    47913bfe2dcf249dfa6400706db20480bab005a1ad1c697c0f4abc1f7f322d08
    bytes
    13803
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/gameability_measure.json | shasum -a 256
    open receipt
  26. rounds  #{independently-necessary atoms}; tight on every class measured.\text{rounds}\ \ge\ \#\{\text{independently-necessary atoms}\};\ \text{tight on every class measured.}

    A counterexample-guided synthesiser needs at least one round per independently necessary atom, because each counterexample certifies at most one.

    forecloses Forecloses a sub-linear synthesis schedule on these classes. Its own artifact calls it a footnote, not a headline.

    receipt
    path
    f2/artifacts/crs/cegis_lower_bound.json
    sha256
    d727bdbd3181d283463dbb94c73eafc9b5b15e9d28f4d14e53c8fc8a7742b360
    bytes
    5349
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/cegis_lower_bound.json | shasum -a 256
    open receipt
  27. Exact enumeration of the product domain stops at the recorded cap; beyond it, counts are bracketed intervals rather than exact values.\text{Exact enumeration of the product domain stops at the recorded cap; beyond it, counts are bracketed intervals rather than exact values.}

    We state where exact counting stops on one machine, and past that point we publish an interval that brackets the truth instead of a number.

    forecloses Forecloses reading our exact counts as unbounded. This one bounds us rather than anyone else.

    receipt
    path
    f2/artifacts/crs/counting_scaling_wall.json
    sha256
    cd6caa94905d24b2377445eb35b1c8a0658d457e495eb02db2811d840f1cd448
    bytes
    7986
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/counting_scaling_wall.json | shasum -a 256
    open receipt
  28. False-discovery rate of proof-as-fitness=0; test-fitness admits false discoveries at a measured rate.\text{False-discovery rate of proof-as-fitness}=0;\ \text{test-fitness admits false discoveries at a measured rate.}

    A search whose fitness function is a proof cannot certify a false discovery; a search scored by a benchmark can, and we measured how often.

    forecloses Forecloses 'benchmark score is a discovery oracle' on the domain measured.

    receipt
    path
    f2/artifacts/crs/discovery_soundness.json
    sha256
    07f5c11cbbe236fed7abbda95bcae93abda20bec673285946dacf04c9bbec6c2
    bytes
    2506
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/discovery_soundness.json | shasum -a 256
    open receipt
  29. Q-infeasible with a Farkas certificateZ-infeasible; every class decided solver-free agrees with z3 across the semantic checks run.\text{Q-infeasible with a Farkas certificate}\Rightarrow\text{Z-infeasible};\ \text{every class decided solver-free agrees with z3 across the semantic checks run.}

    The decision procedure emits a certificate that replays by pure arithmetic, so no SMT solver sits inside the trusted base, and its verdicts agree with z3 wherever both were run.

    forecloses Forecloses 'you have to trust a solver to trust the verdict'.

    receipt
    path
    f2/artifacts/crs/decision_procedure_summary.json
    sha256
    fe0440fdac55b5fe9ac2c50b0bc407c00ce38d78c30feb7eb4914c8122e94b45
    bytes
    5828
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/decision_procedure_summary.json | shasum -a 256
    open receipt
  30. For the classes measured, the shipped upstream guard is sound only under a stated precondition, each with an explicit counterexample outside it.\text{For the classes measured, the shipped upstream guard is sound only under a stated precondition, each with an explicit counterexample outside it.}

    Several fixes that upstream shipped for real CVEs are sound only under a condition nobody wrote down, and we give the input that breaks each one outside that condition.

    forecloses Forecloses treating a shipped fix as a proof of the class it closes.

    receipt
    path
    f2/artifacts/crs/upstream_guard_2025/summary.json
    sha256
    22f6c29369c6a3ae125454d520e01315d9a168d1db6a5ab0ed019eb3dacdcea0
    bytes
    1518
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/upstream_guard_2025/summary.json | shasum -a 256
    open receipt

Artifacts, Datasets and Open Source

Status is literal: live means the link resolves today; planned means it does not exist yet and is not linked. A row is linked because its URL answered during this build.

Repositories · 26

  • minichecksha256 a635c5epushed this programUNKNOWN
    An explicit-state model checker in about 2,900 lines whose verdicts are three-valued: a truncated search reports undetermined, never proved.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  • protocol-benchsha256 23918adpushed this programUNKNOWN
    Ground-truth safety verdicts for fifteen published IEEE 802.11 and 3GPP procedures, where a claimed detection counts only if its counterexample replays.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  • failclosedsha256 84f92bapushed this programUNKNOWN
    Default-deny middleware: an endpoint returns 200 only on a machine-checked SAFE verdict, and unknown is refused rather than allowed.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  • polyfracsha256 8665b59pushed this programUNKNOWN
    Exact polynomial and rational arithmetic, so a bound is never lost to floating point.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  • specforgesha256 7e902c9pushed this programUNKNOWN
    A generated verification benchmark whose answer key is computed by an exhaustive model checker, so it cannot be memorised: change the seed and the set is new.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
Show the remaining 21 of 26
  • minicheck-mcpsha256 c8613a2pushed this programUNKNOWN
    The model checker as an MCP server, five tools. It declares no capability annotations, which our own checker reports as ungradable rather than clean.
    receipt
    path
    f3/artifacts/backends/mcp_annotation_census.json
    sha256
    e22788bbfd805b564abb71241877d5e0fab16901f286016abd70ae83a078a3df
    bytes
    5806
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/mcp_annotation_census.json | shasum -a 256
    open receipt
  • minicheck-actionsha256 91a5f78pushed this programUNKNOWN
    A GitHub Action wrapping the checker. Tag v1.0.1 carries the current code; the floating v1 is three commits behind and carries a real path-resolution bug, disclosed in the tag message.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  • protocol-bench-actionsha256 2d53f30liveUNKNOWN
    The benchmark as an Action. Unchanged this program: zero files differed from the published tree.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  • verification-docssha256 be5e25cliveUNKNOWN
    The documentation site for the tools above. Unchanged this program: zero files differed.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  • A Farkas certificate for a linear bound, re-checked by a C99 program with no solver and no network. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • The reassembly and admission bounds as Lean sources that compile with zero `sorry` and a kernel axiom audit. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • A bounded-memory reassembly demo beside the unbounded one that runs out of memory, on an embedded target. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • The admission gate in RTL with five Yosys formal proofs its own script re-runs. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • A GitHub Action that fails a build when a post-quantum credential no longer fits the budget it was sized for. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • A migration failure benchmark: scored cases where a post-quantum rollout breaks, with unrepaired controls. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • Six MCP tools that report post-quantum sizing and failure families to an agent. It reports; it returns no repairs. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • Sizes a post-quantum credential against a memory budget and a concurrency level, and exits non-zero when the window is empty. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • The sizing calculation in JavaScript, with the same vectors as the Python one. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • The documentation site tying the packages together, built with `--strict` so a broken link fails it. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • A corpus of formal-methods results over post-quantum protocols, queryable by polarity so the controls are addressable. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • certkitv0.4.1liveUNKNOWN
    The certificate format and an independent checker for it, with no solver and no search inside.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt
  • certkit-jsv0.1.1liveUNKNOWN
    The same checker in JavaScript with exact BigInt rational arithmetic, zero dependencies, and it runs in a browser.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt
  • certkit-actionliveUNKNOWN
    Re-check certificates in CI and fail the build when one does not check out.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt
  • soundnessbenchv0.3.1pushed this programUNKNOWN
    A benchmark where passing means never certifying a vulnerability as safe — and which now says on its own page that every leaderboard row is a baseline we wrote.
    receipt
    path
    f2/PUBLISHED_2026-09-04.md
    sha256
    37d17ffdf4e548b976916be1d7e477057c47b5f68ecf256c1021617a47e4c910
    bytes
    5368
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/PUBLISHED_2026-09-04.md | shasum -a 256
    open receipt
  • pytest-mutation-verifiedv0.1.1liveUNKNOWN
    Admits a test only once it has been observed to fail, so a test that cannot fail cannot pass.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt
  • The index of these artifacts, with a link checker that fails the build on a dead link.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt

PyPI packages · 9

  • minicheckv0.4.0liveUNKNOWN
    Published 2026-07-30, before this program. The tree holds a built and twine-clean 0.4.1; it is not uploaded, because uploads are blocked, so no README here quotes a version the index does not serve.
    receipt
    path
    f3/oss/OSS_RECONCILIATION.md
    sha256
    6e1418f58dc46ee0a0f7c534307f4578dc6f86de9f7b8e2fdd346a88b4ed7519
    bytes
    13133
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/OSS_RECONCILIATION.md | shasum -a 256
    open receipt

    pip install minicheckindex confirmed v0.4.0 on 2026-09-06pypi.org/project/minicheck/

  • protocol-benchv1.1.0liveUNKNOWN
    Published 2026-07-30, before this program. This is the version the offline check above pins, and the version whose output was verified against the dataset card.
    receipt
    path
    f3/oss/OSS_RECONCILIATION.md
    sha256
    6e1418f58dc46ee0a0f7c534307f4578dc6f86de9f7b8e2fdd346a88b4ed7519
    bytes
    13133
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/OSS_RECONCILIATION.md | shasum -a 256
    open receipt

    pip install protocol-benchindex confirmed v1.1.0 on 2026-09-06pypi.org/project/protocol-bench/

  • failclosedv0.2.0liveUNKNOWN
    Published 2026-07-30, before this program. A 0.2.1 is built and unpublished.
    receipt
    path
    f3/oss/OSS_RECONCILIATION.md
    sha256
    6e1418f58dc46ee0a0f7c534307f4578dc6f86de9f7b8e2fdd346a88b4ed7519
    bytes
    13133
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/OSS_RECONCILIATION.md | shasum -a 256
    open receipt

    pip install failclosedindex confirmed v0.2.0 on 2026-09-06pypi.org/project/failclosed/

  • polyfracv0.2.0liveUNKNOWN
    Published 2026-07-30, before this program. A 0.2.1 is built and unpublished.
    receipt
    path
    f3/oss/OSS_RECONCILIATION.md
    sha256
    6e1418f58dc46ee0a0f7c534307f4578dc6f86de9f7b8e2fdd346a88b4ed7519
    bytes
    13133
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/OSS_RECONCILIATION.md | shasum -a 256
    open receipt

    pip install polyfracindex confirmed v0.2.0 on 2026-09-06pypi.org/project/polyfrac/

  • pqc-mfbv0.1.0plannedUNKNOWN
    A migration failure benchmark: scored cases where a post-quantum rollout breaks, with unrepaired controls. The registry answered ABSENT for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
Show the remaining 4 of 9
  • pqc-migration-mcpv0.1.0plannedUNKNOWN
    Six MCP tools that report post-quantum sizing and failure families to an agent. It reports; it returns no repairs. The registry answered ABSENT for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • pqc-sizesv0.1.0plannedUNKNOWN
    Sizes a post-quantum credential against a memory budget and a concurrency level, and exits non-zero when the window is empty. The registry answered ABSENT for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • pcov0.1.0plannedUNKNOWN
    The name `pco` on PyPI belongs to a third party; this lane's proof-carrying optimiser is renamed `pco-certify` and is unpublished. The registry answered LIVE_NOT_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • certkit, exploit-counter, crs-mcp, soundnessbench, pytest-mutation-verifiedplannedUNKNOWN
    Five packages that build and pass twine check today; publishing waits on trusted publishing, which is not configured, and no token fallback was used.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt

Datasets · 8

  • nickh007/protocol-benchsha256 f74a58b4pushed this programUNKNOWN
    Fifteen procedures with computed verdicts. The card now carries the command that regenerates the file byte-for-byte, its sha256, and a control a reader can run in one line.
    receipt
    path
    f3/oss/protocol-bench/dataset/README.md
    sha256
    2415a3f1ba902109d80be883393a2322499fe75d15f774d2abecca4efb9070b2
    bytes
    8652
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/protocol-bench/dataset/README.md | shasum -a 256
    open receipt
  • nickh007/specforgesha256 b906f2a9pushed this programUNKNOWN
    Six hundred generated state machines across three difficulty configs, each answer computed by exhaustive checking. All three files regenerate byte-identically from the seed printed on the card.
    receipt
    path
    f3/oss/specforge/dataset/README.md
    sha256
    c437220b3bd01b713f5edf6f15c44e7369c37b1ffe945585ca5105bf243eb309
    bytes
    8853
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/specforge/dataset/README.md | shasum -a 256
    open receipt
  • The formal corpus as a dataset, with the source globs, the extraction rule and the sha256 of the rows it emits. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • nickh007/pqc-mfbliveUNKNOWN
    The migration failure benchmark as a dataset, with ten controls unrepaired by construction. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • pqc-claim-bomplannedUNKNOWN
    Built from artifacts and held locally; unpublished, because it has no organisation to be published under.
    receipt
    path
    f4/oss/outbox/pqc-claim-bom/data/claim_bom.jsonl
    sha256
    d2820a43fb8be8538462b4fc6633f6d7ca657c7ae456d803db5c7e88eeb9f61c
    bytes
    22419
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/outbox/pqc-claim-bom/data/claim_bom.jsonl | shasum -a 256
    open receipt
Show the remaining 3 of 8
  • pqc-hybrid-downgrade-familyplannedUNKNOWN
    Built from artifacts and held locally; unpublished, because it has no organisation to be published under.
    receipt
    path
    f4/oss/outbox/pqc-hybrid-downgrade-family/data/citation.json
    sha256
    34e52c3604235be5c3e712552962d28f45c1287ad9c6e29d4671fd4ef58f78ab
    bytes
    6906
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/outbox/pqc-hybrid-downgrade-family/data/citation.json | shasum -a 256
    open receipt
  • pqc-negative-resultsplannedUNKNOWN
    Built from artifacts and held locally; unpublished, because it has no organisation to be published under.
    receipt
    path
    f4/oss/outbox/pqc-negative-results/data/negative_results.jsonl
    sha256
    2ae1b99f63fc07e7ef58ec28220a4bb402e2b137b8f1ca41e5cc4cd5314c57b6
    bytes
    5513
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  • cve-proof-corpuspushed this programUNKNOWN
    Real vulnerability classes, each with a machine-checkable proof that the shipped fix eliminates it, and a card that now carries the file's hash and a negative control we ran rather than described.
    receipt
    path
    f2/oss/datasets/cve-proof-corpus/README.md
    sha256
    2645c73196f112c728dc3d61f854127cdaa1631ba87596fcca0393ed2f30c028
    bytes
    12241
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/oss/datasets/cve-proof-corpus/README.md | shasum -a 256
    open receipt

Spaces · 5

  • nickh007/protocol-bench-demosha256 9e8a27a1liveUNKNOWN
    A browser page that runs the real checker client-side under Pyodide. It still vendors both the published and the unpublished wheel, and was deliberately not rebuilt while the upload is blocked.
    receipt
    path
    f3/oss/PUBLISH.md
    sha256
    ed74998a2700ecf8f7c3c4da4a5bbc26d9a32c565fae209d5be2cd043421e95b
    bytes
    7386
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/PUBLISH.md | shasum -a 256
    open receipt
  • nickh007/specforge-leaderboardsha256 1af65224liveUNKNOWN
    The same shell over the generated benchmark. Not rebuilt this program, for the same reason.
    receipt
    path
    f3/oss/PUBLISH.md
    sha256
    ed74998a2700ecf8f7c3c4da4a5bbc26d9a32c565fae209d5be2cd043421e95b
    bytes
    7386
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/PUBLISH.md | shasum -a 256
    open receipt
  • A static explorer for the sizing calculation; the same arithmetic as the packages, in a page. The registry answered LIVE_AND_OURS for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • certkit-demopushed this programUNKNOWN
    Verify certificates in your browser under Pyodide — and the page now states that it fetches that runtime from a CDN at load, so it is not the zero-network verifier.
    receipt
    path
    f2/PUBLISHED_2026-09-04.md
    sha256
    37d17ffdf4e548b976916be1d7e477057c47b5f68ecf256c1021617a47e4c910
    bytes
    5368
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/PUBLISHED_2026-09-04.md | shasum -a 256
    open receipt
  • soundnessbench-leaderboardpushed this programUNKNOWN
    Score a soundness tool in your own browser, against a leaderboard that now says whose baselines it contains.
    receipt
    path
    f2/PUBLISHED_2026-09-04.md
    sha256
    37d17ffdf4e548b976916be1d7e477057c47b5f68ecf256c1021617a47e4c910
    bytes
    5368
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/PUBLISHED_2026-09-04.md | shasum -a 256
    open receipt

MCP servers · 3

  • minicheck-mcpsha256 c8613a2pushed this programUNKNOWN
    Five tools over the checker. Zero of them declare a capability hint, so our own capability grader reports it UNGRADABLE rather than clean — and so does every other MCP server in this estate.
    receipt
    path
    f3/artifacts/backends/mcp_annotation_census.json
    sha256
    e22788bbfd805b564abb71241877d5e0fab16901f286016abd70ae83a078a3df
    bytes
    5806
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/mcp_annotation_census.json | shasum -a 256
    open receipt
  • Six MCP tools that report post-quantum sizing and failure families to an agent. It reports; it returns no repairs.
    receipt
    path
    f4/oss/pqc-migration-mcp/src/pqc_migration_mcp/server.py
    sha256
    f632e9e68f260506f33b0e393232ef0edf1b36dd021e5354c5ab39915f0920e4
    bytes
    12428
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/pqc-migration-mcp/src/pqc_migration_mcp/server.py | shasum -a 256
    open receipt
  • crs-mcpv0.4.1pushed this programUNKNOWN
    A proof-backed verdict surface for AI coding agents, whose tools now declare their capability hints and whose closed-world claim is checked against every import rather than against its own prose.
    receipt
    path
    f2/PUBLISHED_2026-09-04.md
    sha256
    37d17ffdf4e548b976916be1d7e477057c47b5f68ecf256c1021617a47e4c910
    bytes
    5368
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/PUBLISHED_2026-09-04.md | shasum -a 256
    open receipt

Command-line tools · 8

  • minicheckv0.4.0liveUNKNOWN
    Exit code 3 means undetermined and is distinct from 0. A truncated search cannot be read as a proof.
    receipt
    path
    f3/oss/minicheck/README.md
    sha256
    0b5c2d30841beaaa0274d403ea522d4609e232ba63b814e84ee9a5d849142882
    bytes
    31947
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/minicheck/README.md | shasum -a 256
    open receipt
  • protocol-benchv1.1.0liveUNKNOWN
    run, score, prompts, score-completions. The scorer is the stranger check named in the verifier section.
    receipt
    path
    f3/oss/protocol-bench/src/protocol_bench/cli.py
    sha256
    21d89ed4e385e9c32290f7d57763e87e45f8716caeeb9addc2af7988ad72a2bc
    bytes
    4487
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/protocol-bench/src/protocol_bench/cli.py | shasum -a 256
    open receipt
  • specforgeplannedUNKNOWN
    generate, export, run, score. Installable from source today; its distribution name pcar-specforge is registered to nobody and is not uploaded, so no install line is given.
    receipt
    path
    f3/oss/specforge/README.md
    sha256
    618926dbf4dfd501e1f33526ba46350f3c28e1bc208b0982367e70c10f191cc1
    bytes
    19410
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/specforge/README.md | shasum -a 256
    open receipt
  • pqc-sizes-jsv0.1.0plannedUNKNOWN
    The sizing calculation in JavaScript, with the same vectors as the Python one. The registry answered ABSENT for this name on 2026-09-05T00:54:09Z.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  • pqc-sizesliveUNKNOWN
    Runs from a clone today; the README's first screen carries the command and a control that must fail. Not on any index.
    receipt
    path
    f4/oss/pqc-sizes/README.md
    sha256
    87973bcae438737d918602a182c72136d55662019325e7814946134e3e7ad447
    bytes
    14814
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/pqc-sizes/README.md | shasum -a 256
    open receipt
Show the remaining 3 of 8
  • pqc-mfbliveUNKNOWN
    Runs from a clone today; the README's first screen carries the command and a control that must fail. Not on any index.
    receipt
    path
    f4/oss/pqc-mfb/README.md
    sha256
    09889d63acb44e1529858c012602bc7b78ef1cae737bbef37810708d060b742d
    bytes
    17234
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/pqc-mfb/README.md | shasum -a 256
    open receipt
  • pqc-corpusliveUNKNOWN
    Runs from a clone today; the README's first screen carries the command and a control that must fail. Not on any index.
    receipt
    path
    f4/oss/datasets/pqc-formal-corpus/README.md
    sha256
    79bc9392e51bc0737aec004ab1193a72f92071cb4ec170bbaca4eaba80ad9f91
    bytes
    10896
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/datasets/pqc-formal-corpus/README.md | shasum -a 256
    open receipt
  • exploit-counterv0.4.0liveUNKNOWN
    Turns 'we found no escapes' into an exact integer: how many forbidden states a guard admits.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt

Certificate bundles · 3

  • PCAR/1 receipt bundle and its 49 conformance vectorsplannedUNKNOWN
    A stdlib-only offline verifier with exit codes 0 VERIFIED / 1 REFUSED / 2 usage / 3 INDETERMINATE, and 49 vectors across five families including deliberately undetectable ones. It is stronger than the check named above and it is NOT public; publishing it is an open question, not a claim.
    receipt
    path
    f3/pcar/vectors/INDEX.json
    sha256
    431036f904fe93b29560e7fb6879ca65350ad2c2bcce61b085d191f837c54c38
    bytes
    37299
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/pcar/vectors/INDEX.json | shasum -a 256
    open receipt
  • pqc-state-verifier-bundleplannedUNKNOWN
    The C-only Farkas checker with its six certificate vectors and the payload-kind spec. Built locally; it has no home yet, because the organisation it was built for does not exist.
    receipt
    path
    f4/oss/outbox/pqc-state-verifier-bundle/controls.tsv
    sha256
    0ccd20a08e90f4366dcd59ffe9a62b57ddc0941f1b9a801561c26b93f7a9f6bf
    bytes
    701
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/outbox/pqc-state-verifier-bundle/controls.tsv | shasum -a 256
    open receipt
  • decoder-audit certificate v2liveUNKNOWN
    A decoder audit bound to its own hash, an Ed25519 signature and a Merkle root over the outcome trace; seven forgeries of it are refused.
    receipt
    path
    f2/artifacts/decoder-audit/tamper_test.json
    sha256
    579afde57e96054fc785cc5408e9ad12e924506ac995880e06910c03625d436d
    bytes
    6549
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/decoder-audit/tamper_test.json | shasum -a 256
    open receipt

Models · 1

  • noneplannedUNKNOWN
    This lane trains no model. The HuggingFace model index returns an empty list for this author, and the site says so rather than leaving the section blank.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt

Notebooks · 1

  • noneplannedUNKNOWN
    No notebook is tracked. A runnable example here is a script, because a notebook adds a runtime a stranger must install before checking anything.
    receipt
    path
    f4/oss/OSS_RECONCILIATION.md
    sha256
    017920c47e388031e981950a90bc41cb28cd887f1134416dcb00d5fd5f5248d9
    bytes
    16895
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/OSS_RECONCILIATION.md | shasum -a 256
    open receipt

Intellectual Property

Status FILED rests on the owner's attestation. Application numbers are supplied by the owner and are never fetched from any registry.

genusclaimsstatusapplication numbersvalidation enginesreceipt

Operational Envelope and Known Limits

Limits as written by the lane, unsoftened. Then the lane's own overclaim confession, verbatim, and the candidates it killed at their own bar.

limits · 166

  1. 01
    All 16 graded rows on this page were audited against the receipts they cite, not sampled. Two of them cite a seal this lane adjudicated VIOLATED, and both are named in the row below and the one after it; the other 14 do not. VIOLATED here means at least one sealed key missed, not that the result is false, and the page no longer opens on either of them.
    receipt
    path
    site/SITE_CORRECTIONS_2026-09-04.md
    anchor
    L67-L96
    sha256
    528184611493ef729eab03a8a974f3e81e5c3e142a719998b531ef87437acacf
    bytes
    9140
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/site/SITE_CORRECTIONS_2026-09-04.md | shasum -a 256
    open receipt
  2. 02
    The CVE-guard row further down grades two shipped upstream fixes against a bar sealed before the run, and that seal is adjudicated VIOLATED: fourteen keys, thirteen held, and the miss is bar_both_fix_refs_verified_online, an in-run web call that came back rate-limited rather than a proof key. It was not re-sealed and not re-run. By this lane's own rule a git-prior seal with any missed key forfeits the third-party-with-a-bar label, which is why this result is no longer the headline.
    receipt
    path
    f2/out/seal_verify_cve_2025_guards_2026-09.txt
    sha256
    1ea397746f0a3d6065af7eaa34d1f54fb8e5077e0067019ef92c825b81324df6
    bytes
    1182
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_cve_2025_guards_2026-09.txt | shasum -a 256
    open receipt
  3. 03
    The Cilium and Katran re-pin row is graded against a seal that is also adjudicated VIOLATED: eight keys, seven held, and the miss was this lane's own bar reading the wrong field of the pins block rather than anything about the kernel.
    receipt
    path
    f2/out/seal_verify_bpf_repin_2026-09.txt
    sha256
    bf389e445dd1ae67d5dc429558f8ac20a7fa7d1b3792424bd7ba3e52ac09db0e
    bytes
    657
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_bpf_repin_2026-09.txt | shasum -a 256
    open receipt
  4. 04
    Two receipts on this page are published as a path and a sha256 with no bytes behind them, and both rows say so where the row is rather than in a footnote. One is a preregistration whose text sits inside the region its own seal covers. The other is f4's retraction ledger, cited by 57 rows here: it still quotes one absolute path naming the machine that produced a quarantined generator, so it is sealed until that lane redacts it as it already redacted the other. Fifty-seven rows therefore offer a hash where they used to offer bytes.
    receipt
    path
    site/SITE_CORRECTIONS_2026-09-04.md
    anchor
    L126-L141
    sha256
    528184611493ef729eab03a8a974f3e81e5c3e142a719998b531ef87437acacf
    bytes
    9140
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/site/SITE_CORRECTIONS_2026-09-04.md | shasum -a 256
    open receipt
Show the remaining 162 of 166 limits
  1. 05
    A forged copy of the sample certificate is served beside the sample, so a reader can watch this page reject one instead of taking our word for it. The printed instruction names it and this site serves it.
    receipt
    path
    f2/oss/certkit-js/examples/heartbleed.forged.json
    sha256
    6ccac39b555d979ad3d8318597656d6ff5ed924f2998686dbc77100a8e739ce7
    bytes
    224
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/oss/certkit-js/examples/heartbleed.forged.json | shasum -a 256
    open receipt
  2. 06
    The checker this page runs is served as one file, so a reader can hash the bytes the page carries rather than trust the page about them.
    receipt
    path
    f2/oss/stranger-verifier/verifier.bundle.mjs
    sha256
    c34ee499e014b75b44c3a3a9cd2a3d9ce62a084b231cd99b38e0d1edacd19af9
    bytes
    52033
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/oss/stranger-verifier/verifier.bundle.mjs | shasum -a 256
    open receipt
  3. 07
    The build manifest that records that bundle's sha256, its nine sources and their hashes is served beside it, which is what makes the hash comparison checkable rather than circular.
    receipt
    path
    f2/oss/stranger-verifier/manifest.json
    sha256
    bcd7dc40ee9ce77b34eaaa85df66f85672266a722cc20adf80f6cb76190effda
    bytes
    2264
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/oss/stranger-verifier/manifest.json | shasum -a 256
    open receipt
  4. 08
    The corpus runner is served too, so a reader can put every vector through the exact bytes this page carries, with an accept-everything and a reject-everything strategy scored beside them.
    receipt
    path
    f2/scripts/stranger_verifier_corpus.mjs
    sha256
    876fa4a1880e696c181679949262ea2df569539e2eb90862058de2f728c554a9
    bytes
    11223
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/scripts/stranger_verifier_corpus.mjs | shasum -a 256
    open receipt
  5. 09
    The repository behind every claim on this page is PRIVATE. An unauthenticated request returns 404, so a stranger can read this page and the public tools, and none of the register, the sealed bars or the corrections.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  6. 10
    Site-thread correction to the row above, which f3 wrote while its evidence was unreachable: this site publishes 46 of that repository's files as receipts, including the sealed bars under artifacts/prereg/ and the corrections in dataroom/STALE_CLAIMS.md. The repository itself is still private and still returns 404 to an unauthenticated request; what has changed is that the cited evidence is now readable here.
    receipt
    path
    site/SITE_CORRECTIONS_2026-09-04.md
    anchor
    L13-L23
    sha256
    528184611493ef729eab03a8a974f3e81e5c3e142a719998b531ef87437acacf
    bytes
    9140
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/site/SITE_CORRECTIONS_2026-09-04.md | shasum -a 256
    open receipt
  7. 11
    The published Merkle closure root no longer equals the root the live tree folds to. The binding check has been failing since it was written and has not been repaired, because repairing it means re-pinning the certificate, which is an owner decision.
    receipt
    path
    f3/dataroom/STALE_CLAIMS.md
    sha256
    5fa3b81b674ff926419358f3969da0d70e29b5f24438b0b8a118e26fd1610a0a
    bytes
    47301
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/dataroom/STALE_CLAIMS.md | shasum -a 256
    open receipt
  8. 12
    The pre-registration seal is tamper-evidence from the day it was sealed, not proof of priority: it entered git six days after the benchmark output it claims to precede.
    receipt
    path
    f3/dataroom/STALE_CLAIMS.md
    sha256
    5fa3b81b674ff926419358f3969da0d70e29b5f24438b0b8a118e26fd1610a0a
    bytes
    47301
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/dataroom/STALE_CLAIMS.md | shasum -a 256
    open receipt
  9. 13
    The radio work is mac80211_hwsim on a rented Linux host: a kernel simulator, RF-simulated, never over the air, and the hostapd version is pinned nowhere in the tree.
    receipt
    path
    f3/dataroom/STALE_CLAIMS.md
    sha256
    5fa3b81b674ff926419358f3969da0d70e29b5f24438b0b8a118e26fd1610a0a
    bytes
    47301
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/dataroom/STALE_CLAIMS.md | shasum -a 256
    open receipt
  10. 14
    Fifteen of seventeen radio runs are git-ignored and would not survive a clone. Only an index of them is tracked.
    receipt
    path
    f3/artifacts/backends/hostapd_runs_index.json
    sha256
    3ea393adbcdd5b8e9398c0a6d5788a60ea98f52203562b13f3d2b9da1f62429d
    bytes
    11133
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/hostapd_runs_index.json | shasum -a 256
    open receipt
  11. 15
    All 116 credited Lean theorems rest on a regex that finds the word theorem in a file. Only eleven statements have been read by the kernel; an axiom check alone credits a theorem whose statement is True and one that is a bare reflexivity, and our own control plants both and requires them reported vacuous.
    receipt
    path
    f3/artifacts/backends/lean_credit_audit.json
    sha256
    2a186ce4b1daa3693fd88e80007f4c4691ce3ce7bfe2afc029b554094256c4d6
    bytes
    6496
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/lean_credit_audit.json | shasum -a 256
    open receipt
  12. 16
    Eighty-nine Lean declarations are proved in this tree and credited in no pinned list. The count was 74 until a whole-tree census found three files the lane's own scanner never scanned.
    receipt
    path
    f3/artifacts/backends/lean_uncredited.json
    sha256
    45e1b089dc4c8359543ce1986cf0c991e31f4838b1467a599c5bfd145d8c2830
    bytes
    8150
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/lean_uncredited.json | shasum -a 256
    open receipt
  13. 17
    The general 3^w attribution floor is stated in the register and is not machine-checked. The kernel checked 2^w for every width and 3^w only at width two.
    receipt
    path
    f3/lean/TTEFrerRecoveryFoils.lean
    sha256
    f27a8ab614ca15c26fb8d01fd3113a547314ddd821d2be275e5ece75ea20083d
    bytes
    7643
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/lean/TTEFrerRecoveryFoils.lean | shasum -a 256
    open receipt
  14. 18
    Five hundred and eighty-nine tracked artifact-like files are named in no ranking document, 281 of them manifest leaves; thirty-three numeric bounds are asserted only in the test suite.
    receipt
    path
    f3/out/s03/unreferenced.tsv
    sha256
    db98e7a8f22aafb72b4f25c086fa7d241089950774af0206a0eafc3c7bcec239
    bytes
    27683
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/out/s03/unreferenced.tsv | shasum -a 256
    open receipt
  15. 19
    The impossibility producer's default command samples 400 assignments while the committed artifact records the full 9,216 per row. The register now publishes the non-default command; the default one writes a smaller experiment and exits 0.
    receipt
    path
    f3/artifacts/backends/scope_defaults_scan.json
    sha256
    a073778153b076b4e83bc0549055e93855eb359af758b29b12d4d3d772bf8bf9
    bytes
    2645
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/scope_defaults_scan.json | shasum -a 256
    open receipt
  16. 20
    Ten MCP servers ship across this estate and not one declares a capability hint, ours included. Reporting zero disagreements for any of them would be a green that means nothing, so the observation was not run.
    receipt
    path
    f3/artifacts/backends/mcp_annotation_census.json
    sha256
    e22788bbfd805b564abb71241877d5e0fab16901f286016abd70ae83a078a3df
    bytes
    5806
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/mcp_annotation_census.json | shasum -a 256
    open receipt
  17. 21
    The estate-wide scanner's precision was bought with recall: requiring a write context dropped its pairing coverage from 168 producer-artifact pairs to 11, so a producer that writes through a helper it cannot follow is now invisible to it.
    receipt
    path
    f3/artifacts/backends/scope_defaults_estate.json
    sha256
    709067459433e3f62dec7aa41b89bf0c7e6446736631566819f9cc36ad70d480
    bytes
    27051
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/artifacts/backends/scope_defaults_estate.json | shasum -a 256
    open receipt
  18. 22
    The kernel acceptance of our compiled monitor was measured by another lane on its hardware, not here. What this repository can regenerate is the rejection under its own non-relocating loader.
    receipt
    path
    f3/monitorgen/artifacts/kernel_load.json
    sha256
    803e94bec7cac2694a0f356f72a9a087f7b5e628a81b36c0a55a609b0a61d5fc
    bytes
    1940
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/monitorgen/artifacts/kernel_load.json | shasum -a 256
    open receipt
  19. 23
    A container kernel is not the kernel a deployment runs, and verifier acceptance is not semantic correctness.
    receipt
    path
    f3/monitorgen/artifacts/kernel_load.json
    sha256
    803e94bec7cac2694a0f356f72a9a087f7b5e628a81b36c0a55a609b0a61d5fc
    bytes
    1940
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/monitorgen/artifacts/kernel_load.json | shasum -a 256
    open receipt
  20. 24
    The closure verifier a stranger would run imports the builder that re-pins the certificate, so it is not standalone and is not offered as the offline check.
    receipt
    path
    f3/scripts/verify_closure.py
    sha256
    fa2e420b7d9f27f164e4040c5ac5c1d7345fcf08c34966bbbb1ea5d747fabce2
    bytes
    2015
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/scripts/verify_closure.py | shasum -a 256
    open receipt
  21. 25
    The twelve sealed bars record only the git commit at sealing time. Without an external time anchor a stranger cannot verify that a seal preceded its run; they can verify only that it has not been altered since.
    receipt
    path
    f3/artifacts/prereg/s08_scope_defaults_estate.json
    sha256
    6488b42e97d388fc685500ee213dc86dc0d0df6a947ef00acfe23bd495184be7
    bytes
    3442
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  22. 26
    Four PyPI packages sit one patch version behind the code in this tree. The newer distributions are built and pass twine check and are not uploaded.
    receipt
    path
    f3/oss/PUBLISH.md
    sha256
    ed74998a2700ecf8f7c3c4da4a5bbc26d9a32c565fae209d5be2cd043421e95b
    bytes
    7386
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/PUBLISH.md | shasum -a 256
    open receipt
  23. 27
    Two floating action tags point at commits three and two behind their repositories, and the older one carries a real path-resolution bug. They were not moved, because moving a published tag is a forced update.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  24. 28
    Both browser demos still vendor the older and the newer wheel at once, and were deliberately left alone while the index upload is blocked.
    receipt
    path
    f3/oss/PUBLISH.md
    sha256
    ed74998a2700ecf8f7c3c4da4a5bbc26d9a32c565fae209d5be2cd043421e95b
    bytes
    7386
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/PUBLISH.md | shasum -a 256
    open receipt
  25. 29
    One candidate's pass-fail bar was published in a plan and never sealed into the seal directory. It was not sealed retroactively, and the gap is recorded instead.
    receipt
    path
    f3/THREAD_LEDGER.md
    sha256
    6da6331b27d165c5442ed31e869dc09bfd45cb3550b6eb8927111263f7a5d580
    bytes
    90006
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  26. 30
    The lane's own closure certificate was called universal. Three lanes ship one and an independent check measured them disjoint. The name is dropped at the producer and on every live surface; the pinned artifact still carries the old string, because rewriting it is the re-pin.
    receipt
    path
    f3/dataroom/STALE_CLAIMS.md
    sha256
    5fa3b81b674ff926419358f3969da0d70e29b5f24438b0b8a118e26fd1610a0a
    bytes
    47301
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/dataroom/STALE_CLAIMS.md | shasum -a 256
    open receipt
  27. 31
    One register entry's cited artifact is a hand-authored reconciliation record that no command regenerates.
    receipt
    path
    f3/oss/OSS_RECONCILIATION.md
    sha256
    6e1418f58dc46ee0a0f7c534307f4578dc6f86de9f7b8e2fdd346a88b4ed7519
    bytes
    13133
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/oss/OSS_RECONCILIATION.md | shasum -a 256
    open receipt
  28. 32
    One producer exceeded a one-hour cap twice and its result is recorded as not run with the measured cost, rather than estimated.
    receipt
    path
    f3/NEGATIVE_RESULTS.md
    sha256
    6b19a644c2b10e8e8070f9af5f90ca609f5c902f20d2b6600012f999cd9f33ae
    bytes
    16360
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  29. 33
    Three checks in this repository are red right now and have been left red: the closure-root binding, an orphaned claim-trust guard, and one kit gate whose vocabulary contradicts four register rows.
    receipt
    path
    f3/OVERCLAIM_CONFESSION_2026-09.md
    anchor
    L162-L165
    sha256
    11a1eb0d3e6593b38eb5da611ac5970d463c9a03e285b18f116b6e0a569109a0
    bytes
    16560
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/OVERCLAIM_CONFESSION_2026-09.md | shasum -a 256
    open receipt
  30. 34
    There is no company, no domain and no organisation behind any of this. Nothing on this page is a product, a price, or an offer.
    receipt
    path
    f3/PUSH_LIST_S12.md
    sha256
    d6094b76d2a66533b60e6341ad2d1aa253426e733d6a56974c1ba3efbbd6325b
    bytes
    10568
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/PUSH_LIST_S12.md | shasum -a 256
    open receipt
  31. 35
    Site-thread correction to the row above, which f3 wrote before the domain existed: there is now a company name and a domain. This site is OrbitalProof at orbitalproof.com, registered 2026-09-04. The rest of f3's sentence still holds as measured: no organisation exists (github.com/orbitalproof and huggingface.co/orbitalproof both return 404), and nothing on this page is a product, a price, or an offer.
    receipt
    path
    site/SITE_CORRECTIONS_2026-09-04.md
    anchor
    L25-L36
    sha256
    528184611493ef729eab03a8a974f3e81e5c3e142a719998b531ef87437acacf
    bytes
    9140
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/site/SITE_CORRECTIONS_2026-09-04.md | shasum -a 256
    open receipt
  32. 36
    The covert-bits ceiling this lane published was wrong and was corrected upward, not down: a biased-quadrature estimator put it at 34.55 bits where the exact closed form gives roughly 65.9. The error was ours, found by recomputing our own flagship from scratch.
    receipt
    path
    f3/ARCHITECTURE.md
    sha256
    81ed2869740b12e0520f0ab379194a8b771902085c655850abe5b6944eb0b22b
    bytes
    209829
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  33. 37
    R1 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Unconditional `K ≥ 26`; "drat-trim 26/26" — 29 of 33 coverage cells are singletons by arithmetic; **genuinely discovered cells = 0 of 33**. The DRAT certificate is **14 bytes** and verifies a proof of `x ∧ ¬x` — it runs, and what it verifies is trivial. Use instead: `K_constr = 7`, unique over 245,157 subsets (top-20 entry 5)
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L103
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  34. 38
    R2 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: 1,095,743× DoS reduction as a *measurement* — Denominator is the committed cap **constant**, definitional, below page granularity; `bounded_measured_delta_bytes = 0`. n=1, does not reproduce (re-run gives 1,095,863). Use instead: The law: slope 1.0 vs slope 0.0, and **8,194× / 98,306×** two-endpoint (entry 9)
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L104
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  35. 39
    R3 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: 361,587× "directly measured" — Same defect; `dos_ratio_labels_ci.json` records `overstatement_factor = 2.2` Use instead: **164,358×** where one measured two-endpoint scalar is needed
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L105
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  36. 40
    R4 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: 1,379,333× — Never a measurement — a **projected** operating point (λ=100,000/s, T=30 s), always labelled as such Use instead: Do not promote it
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L106
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  37. 41
    R5 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: 2,146,200 evaluations — Asserted product of two config constants (1533 × 1400); no per-shard array, no raw log; illuminates 100 distinct niches Use instead: **Runnable floor: 5,600.** (Correction to the record: a `fleet-hunt` target *does* exist at `Makefile:1662` — the "no make target" half of the earlier objection was wrong; the reproducibility half stands)
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L107
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  38. 42
    R6 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "7/7 famous Wi-Fi CVEs reproduced and closed" — Only **3** are Wi-Fi CVE families — KRACK, FragAttacks, Dragonblood. Terrapin is SSH; oqs-provider and KyberSlash have no CVEs; "hostap has no PQC AKM" is a missing feature Use instead: **3 families**
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L108
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  39. 43
    R7 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: 5.10× decirc speedup — Re-measures at 4.81× under its own method. *The 3.02× retraction that preceded it was itself wrong and is withdrawn* — a retraction is a claim too Use instead: ~4.8× enumeration-only; end-to-end now **2.976×** (§A2)
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L109
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  40. 44
    R8 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "GitHub Actions billing is blocked account-wide" — **760** runs on this repo, not 200; 2,661 runs across 8 sampled repositories; ten siblings ran green on GitHub-**hosted** runners Use instead: CI runs on a self-hosted EC2 runner
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L110
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  41. 45
    R9 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "Six independent engines agree on K = 7" — **Four.** Bitmask and set-based enumeration are the same representation Use instead: Four engines
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L111
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  42. 46
    R10 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `K_constr = 6` — Corrected to **7** in eight documents (`724c979`) Use instead: 7
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L112
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  43. 47
    R11 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "16 KiB hard memory cap under DoS floods", read as an **AP-wide** sentence — Every proof leg was **per-session**. `Bound.lean`'s `gatedResident` is a single scalar and `n` counts admit attempts on **one** buffer; the Yosys/z3/Farkas legs prove the same scalar. `artifacts/native/threat_rung_ci.json` said so about itself — per-session bounding is "DEFINITIONALLY insufficient for a sum over N", and the cross-session quota was a **"candidate residual control"**, i.e. unbuilt. Measured: the per-session-cap-only arm reaches **66,060,288 B** at N=4096, **1,008×** the AP budget. Use instead: The AP-wide bound is now **earned, not narrowed**: **≤ 64 KiB across an unbounded number of concurrent sessions, N_max = 4** — proven (`ApBound.ap_bounded`, 0 hypotheses, 0 sorry, kernel-printed axioms), enforced (`lib/wifipqc/[filename withheld under I8: admission-mechanism source]`), measured (`make ap-quota`). State the per-session 16 KiB and the AP-wide 64 KiB **separately**; they are different quantities.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L113
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  44. 48
    R12 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: The 17.95 GB figure described as a **flood** — It is an **allocation-model** measurement: `pqc_state_dos_measure.c` does one `malloc` plus a page-touch loop driven by two integers — no packets, no handshake, no hostapd, no radio. Separately, its bounded arm allocated `SCRATCH_BYTES` = **4096** and never read it, while the artifact divided by **16384**. Built at both values, five trials each, ΔRSS is page-quantised noise with the *same* range at both settings (one run: 4096 → `32768, 49152, 0, 16384, 32768`; 16384 → `16384, 0, 32768, 32768, 16384`; page = 16,384 B). **The exact values differ run to run — that is the finding**: the arm retains nothing per session, so the constant does not drive the measurement. Use instead: "Allocation-model peak-RSS envelope", never "flood". **No ratio is publishable from that harness** — the denominator sits below its own noise floor. This *confirms* R2 rather than replacing it. → `make dos-scratch-reconcile`
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L114
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  45. 49
    R13 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `lean_proof_ci.json`'s `sorry_count` labelled **"(axiom-free)"** — It was a **source regex** for the token `sorry`, not an axiom check. Lean reports a `sorry` as a **warning** and exits 0, so `compiles` would not have caught one either; a theorem resting on a planted `axiom` or on `native_decide` (`ofReduceBool`) passed both checks. Three of the six breaks in `make lean-redgreen` are exactly those holes, and all three came back GREEN against the old driver's logic. Use instead: Axioms are now **printed by the kernel** (`#print axioms`) and parsed, against the allow-list `{propext, Classical.choice, Quot.sound}`. Both files verify at `{propext, Quot.sound}`. → `make lean-proof`, `make lean-redgreen`
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L115
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  46. 50
    R11 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "solver-free Farkas certificates in 123 lines of strict C99" — **Describes a file deleted for being unsound** — it answered VALID on `x ≤ 2^62 ⊨ x ≤ 1/4, λ=1` Use instead: **216 lines / 132 non-blank-non-comment**, and tell the deletion story (top-20 entry 3)
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L116
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  47. 51
    H1 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "5 Yosys formal proofs" — **RESOLVED 2026-08-18 — VERIFIED, T0.** The claim was always about the *external* repo `pqc-dos-gate-rtl`, whose source is vendored at `oss/pqc-dos-gate-rtl/`. `bash verify.sh` runs five proof scripts and all five produced their expected verdict on this host: `prove_gated`, `prove_fault_gated`, `prove_fault_unbounded` proven by unbounded k-induction; `prove_naive` and `prove_fault_admit` counterexample-found-as-expected. The figure is correct and may be used. (`rtl_gate_ci.json` records one k-induction result because it gates a *different* module, `bounded_reassembly.v` in this repo — that was the source of the confusion.)
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L124
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  48. 52
    H2 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "102.4 MB attack" — Stale phrasing, not a defect. The committed form is **102,400,000 bytes** / "a 200,000-fragment flood"
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L125
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  49. 53
    H3 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "α ≈ 1.00 byte/byte"; "the DoS gate ABSTAINs on 16 KiB-page hosts" — **NOT IN THE ARTIFACT.** `dos_memory_ci.json` has no `alpha` key and no ABSTAIN path. Use `naive_law.slope = 1.0000029340461285`
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L126
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  50. 54
    H4 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "180,794× median of paired ratios" — **MISDESCRIBED.** Occurs once, at `reports/state_exhaustion_dos_ci.md:45`, as a single sweep-table row (393,216 fragments). Not a median, not paired, never a headline
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L127
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  51. 55
    H5 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: On-air / CPU figures attributed to `cold_parity_ci.json` — **WRONG ARTIFACT.** `cold_parity_ci.json` is latency-only. Correct sources are `onair_resumption_ci.json` and `recurring_tax_ci.json` (top-20 entry 20)
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L128
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  52. 56
    H7 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "39/39 failure families closed" vs "35 real targeted" — Both code-derived, counting **different sets**. For filing and anything claim-shaped use **35 targeted / 34 in registry** — the stricter document
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L129
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  53. 57
    H8 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: The external portfolio audit's ten-item crown-jewel list (2026-07-30) — **STALE AS A WHOLE.** Still lists retracted 2.14M evals (R5), the deleted-file "123 lines" (R11), and "5 Yosys proofs" (H1); predates all nine new engines. **Do not hand it to anyone**
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L130
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  54. 58
    R14 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "the single equivalent mutant … 65/66" (sidecar rank 35, title + limits) — The count does not survive regeneration: committed `mutation_scale_ci.json` has `sweep_total 66, sweep_equivalent 1`; regenerating 2026-09-02 gave `68 / 3` (`out/mutation_scale_ci_regen_2026-09.json`), and the 08-26 excerpt already printed `equiv=3` beside a committed 1. The mutant set is not deterministic. Use instead: "Every non-equivalent mutant was killed on every run (kill_rate 1.0, zero survivors); the equivalent count is declared per run and moved 1/66 → 3/68."
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L374
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  55. 59
    R15 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "165 of 208 artifacts are unconfirmed" (sidecar rank 39 title) — Neither number is in `artifact_freshness_ci.json`, which records `n_artifacts 213, n_resolved 200, n_confirmed 30, n_unconfirmed 170`. Titles were outside the number gate's scan. Use instead: "170 of 200 resolvable artifacts (of 213) are unconfirmed."
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L375
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  56. 60
    R16 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "422 of 422 $equiv cells proved by induction, **mapped to real sky130 cells**" (rank 8) — Two facts compounded: `gates.formal_netlist_equivalence.method` = "equiv_make + equiv_induct + equiv_status -assert, **over yosys simcells models**"; the sky130 mapping is a separate gate in the same artifact. No yosys version is recorded. Use instead: "422/422 $equiv cells proved by induction over yosys simcell models; the same netlist is separately mapped to sky130_fd_sc_hd, WireLoad=none, no timing number."
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L376
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  57. 61
    R17 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "A gate fails the build if a withdrawn claim reappears **anywhere on the outward surface**" (rank 11) — NC9: `887/887`, `2,146,200` and `1,095,743×` planted in `README.md` → `make submission-status` exit 0, OK (`out/nc9_submission_status_2026-09.log`). The gate checks six declared standards-clause surfaces (`tools/check_submission_status.py:178-186`); README carries 887/887 once and `company/pitch_deck.md` five times today, and `artifacts/native/succinct_verdict_ci.json` still carries "887/887 PASS" as its `headline`. Use instead: "…if a retired mechanism reappears on any of the six declared standards-clause surfaces." The dead-number carriers in README, the pitch deck and `succinct_verdict_ci.json` are open items.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L377
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  58. 62
    R18 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "it refuted **three of their front-page claims**" (rank 13) — Of the three REFUTED rows in `artifacts/claimbom/pq-crystals-kyber.bom.json`, one ("the target controls every public-registry package name") is a claim the checker posed — the BOM's own `not_a_gate.the_claim_selection_is_an_input` says so — and one is refuted only under a stated reading. Use instead: "2 front-page sentences refuted under a stated reading, 1 checker-posed claim refuted, 4 reproduced, 1 corroborated, 3 unsupported, 1 unverifiable (12 rows)." Re-run live 2026-09-02: same three refutations; Q4 moved UNSUPPORTED → PARTIAL.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L378
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  59. 63
    R19 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "Six of thirty-two are NOT forced" (rank 36 scope) — `gate_forced_ci.json` classes five as `substitutable` (C, D, F, G, I) and one as `not_exercised` (E). An unexercised mechanism was rounded into a negative result. Use instead: "26 forced; 5 substitutable (C, D, F, G, I); 1 (E) not exercised."
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L379
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  60. 64
    R20 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `make silicon` as the regenerator of `arm_silicon_graviton.json` (rank 30 `reproduce_command`) — On every host it runs a TVLA experiment on six primitive ops, prints `SILICON: OK`, exits 0 and never writes the cited artifact (gate 4: `EXIT0_NO_TOUCH`, 08-26 and 09-02). The regenerator that exists, `tools/cloud/provision_aws_graviton.sh`, was uncited. Use instead: The sidecar now names the provisioner (t4g.medium, ~$0.10, not provisioned this pass). Provenance of the committed run: CloudTrail us-east-2, `RunInstances` 2026-07-04 09:54:55 −0700 / `TerminateInstances` 09:56:39 for the artifact's `instance_id`.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L380
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  61. 65
    R21 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Rank 31's excerpt displaying `reduction=6060.6x` — The entry's own limits retract that ratio (R-class D-6) while the generator still prints it and `embedded_dos_ci.json` still stores it as `reduction_factor`. Use instead: The excerpt now excludes that line; the number stays in the artifact and is recorded here rather than removed.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L381
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  62. 66
    R22 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "The main repository is still 15 commits unpushed" (rank 38 limits) — `main == origin/main` (2566b20) on 2026-09-02. A push count is a moving fact, not a limit. Use instead: "the push state moves; 15 were unpushed on 2026-08-20, 0 on 2026-09-02."
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L382
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  63. 67
    H9 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: §C/H3 above: "the DoS gate ABSTAINs on 16 KiB-page hosts is **not in the artifact**" — **H3 IS ITSELF STALE.** The ABSTAIN path is real and receipted twice (`out/run_receipts.json` 08-26 and `out/run_receipts_2026-09.json` rank 9: `RESULT: ABSTAIN (7 gates decided, 1 abstained)`, 93 s). H3's narrower point stands: the *committed* `dos_memory_ci.json` (231a634, 2026-06-25) predates the generator's abstain logic (edits 2026-07-26/30) and has no `abstain`/`page_size` key, so HEAD's generator cannot reproduce it on a 16 KiB-page host.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L388
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  64. 68
    H10 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: 14 sidecar entries whose `limits` said "Not re-run today" while tiered T0 (ranks 21, 23–27, 29, 31–36, 39) — **STALE PROSE, FIXED.** The prose was frozen before the 08-26 run; the tier moved and the prose did not. Removed 2026-09-02; `tools/check_top40_scope_flags.py` now fails on the pattern.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L389
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  65. 69
    H11 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `artifacts/native/interop_3p_ci.json` vendor string "OpenSSL 3.6.2" — **PER-HOST.** Regenerates as 3.6.3 on this host today; the rank-24 sentence names no version and is unaffected. Documents quoting "3.6.2" quote a host, not a result.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L390
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  66. 70
    H12 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `artifacts/native/eap_freeradius_ci.json` `ok: true` (uncited, triage T1) — **DOES NOT REGENERATE TODAY.** `make eap-sidecar` ran inside the local colima VM and wrote `ok:false, radius_eaptls_accept:false, downgrade_rejected:false` because `oqsprovider.so` is missing from the VM (the committed run built it under `/tmp`, which did not persist). Environmental, and I1 does not distinguish causes. Receipt `out/triage_regen_2026-09/`.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L391
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  67. 71
    H13 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `artifacts/native/pqm4_anchor_ci.json` (uncited, triage T5) — **STALE INPUT, VERDICT HOLDS.** Committed anchor used ML-KEM keygen 74,389 cycles; the committed Graviton artifact says 74,424. Regenerated: consistency 5/5 within band.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L392
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  68. 72
    H14 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `STALE_CLAIMS.md` §B carries **R11 twice** (the AP-wide bound row and the Farkas "123 lines" row) — **ID COLLISION, LEFT IN PLACE.** Renumbering would break external references; cite them as "R11 (AP-wide)" and "R11 (Farkas)". Nothing keys on the ids (`tools/check_stale_retractions.py` matches phrases).
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L393
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  69. 73
    H15 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Rank 2's evidence tier ("162 committed red/green breaks", T0) — **T0 FOR THE SUM ONLY.** `tools/verify_redgreen_total.py` re-reads ten committed artifacts (I1: transcription). The ten `make *-redgreen` harnesses were launched serially at 2026-09-02 15:27Z (`out/harnesses_2026-09.log`); per-harness outcomes are appended to this row as they complete.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L394
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  70. 74
    R23 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Rank 2's "162 committed red/green breaks: every check observed failing on its own mutation" read as a statement about today — Ten harnesses re-run serially 2026-09-02 (`out/harnesses_2026-09.log`): eight reproduce their committed counts (119 breaks); **dyncap** reproduces **4 of 19** (committed 19/19 — `out/harness_regen_2026-09/dyncap_redgreen.json` vs `artifacts/native/dyncap_redgreen.json`) because the dyncap gate itself is red today on `no-starvation` (`out/harness_regen_2026-09/dyncap_ci.json` FAIL 18/19 vs committed PASS 19/19); **modelrisk** reproduces **23 of 24** with `checker-is-independent` uncovered and `the-trusted-checker-spawns-a-process` red and green both FAIL 20/21 (`out/harness_regen_2026-09/modelrisk_redgreen.json`) Use instead: "162 breaks recorded; on 2026-09-02, 146 went red on their own check (8 harnesses at their committed counts, dyncap 4/19, modelrisk 23/24)." The committed artifacts are not regenerated to today's values; the difference is the finding.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L424
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  71. 75
    R24 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `artifacts/native/dyncap_ci.json` "PASS 19/19" as a current fact — `make dyncap-gate` today writes FAIL 18/19, `failures=['no-starvation']`, with the measured starvation events moving between runs (`out/churn_diff_s04_2026-09.txt`: `measured_starvation_events` 39→40) Use instead: "The conditional no-starvation theorem holds (modelrisk_ci.json checks[13]); the engine's no-starvation check is host-dependent and was red on 2026-09-02." Register entry `dyncap-adaptive-cap-guarantees` states both.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L425
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  72. 76
    R25 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `artifacts/native/cleanroom_dryrun.json` read as a passing "one-command neutral reproduction" — Committed artifact records `ok:false`, `root_match:false`, `stable_committed_match:false` (survey A row 29) Use instead: Do not claim a clean-room root match until the artifact says `root_match:true`.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L426
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  73. 77
    R26 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "STALE_CLAIMS §C V7: `origin/campaign/f4-2026-06-26` is the only unexamined ref" — `git log --oneline origin/campaign/f4-2026-06-26 ^main` → 0 commits; `git merge-base --is-ancestor origin/campaign/f4-2026-06-26 main` → true (`out/s04_search_2026-09.json → P7_git`) Use instead: V7 is CLOSED: the ref is a 2026-06-28 snapshot fully contained in `main`; nothing on it that `main` lacks.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L427
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  74. 78
    R27 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `tests/test_state_exhaustion_dos_ci.py:72` `assert recomputed >= 1_000_000` read as a measured floor — The value is `op["C"] * op["S_pq"] / K_AP` — the projected operating point R4 says must never be promoted; the test pins arithmetic, not a measurement Use instead: The test is internal consistency of the projection; it is not evidence for any ≥10⁶× sentence. Not edited (I11); recorded.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L428
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  75. 79
    R28 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Rank 9's "reduction @134 MB headline flood = 8,194× — corroborates ~8,194×" (`artifacts/native/dos_memory_ci.json → headline_reduction 8194.0`, darwin) read as a mechanism property — S06 row 4 re-ran `make dos-measure-ci` inside the 4 KiB-page colima VM (kernel 6.8.0-117-generic; `artifacts/native/dos_memory_ci_linux4k.json`, `out/dos_measure_linux4k_s06_2026-09.log`). The bounded arm's ΔRSS is **0 KiB at every one of the 15 flood sizes** (below even 4 KiB resolution), so the ratio has no denominator and the tool prints 41,469,269× (`headline_reduction`, = the naive arm's bytes over 1). On darwin the bounded arm resolved to exactly one 16 KiB page, and 134,217,728 / 16,384 = 8,192: the "8,194×" was the host's page size, not the mechanism. Gates `headline_corroborated` and `reduction_law_linear` FAIL on Linux; `naive_slope_is_one` also fails (slope 0.9546, CI [0.9402, 0.9690], intercept −48.5 MB). Use instead: "Under flood the naive arm's residency grows linearly (slope 1.000 on darwin, 0.955 on a 4 KiB-page Linux host) while the bounded arm stays flat at zero resolvable pages on both; the reduction *ratio* is page-size arithmetic on every host measured and is not quoted." The law survives; every ratio (8,194×, 98,306×, 41,469,269×) is retired.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L429
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  76. 80
    R29 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: "The claim checker refuted **3 of 8** material claims on the Kyber reference" — this lane's own falsification headline, carried into the S08 hand-off, the S11 plan and the orchestrator's S12 lane note, which asks for it in every card — Computed from the artifacts rather than transcribed (`artifacts/claimbom/*.bom.json`, rows filtered on `is_material_claim` and `verdict`): Kyber has **12** rows of which 8 are material, and **3** rows are REFUTED — but one of the three is `Q1-name-control-in-registries`, a diligence question the INSTRUMENT asks about package-registry names, not a claim the target made. The published figure took its numerator from all rows and its denominator from material claims alone. Q1 is REFUTED for all three targets, so it separates nothing. Use instead: "Material claims refuted: **2 of 8** on the Kyber reference, **1 of 9** on Dilithium, **0 of 7** on formally verified mlkem-native." Counting every row instead gives 3 of 12, 2 of 13, 1 of 11. Both readings are monotone in code quality, so the falsification argument stands unchanged; only the number was wrong.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L430
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  77. 81
    H16 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Rank 2 cites `artifacts/native/redgreen_total_ci.json` — **WAS UNTRACKED.** `git ls-files` returned nothing for it until commit `9840032`; a clean clone could not resolve a top-40 path and gate 1 passed on the working tree only. Now tracked.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L436
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  78. 82
    H17 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: §F's `KNOWN_FAILURES.jsonl` (38 rows) cited at `../_reconcile_20260813_s1147a223/05_registries/` — **WAS OUTSIDE THE TREE.** Copied verbatim to `conformance/known_failures.jsonl` (sha256 `150201d847a9…6a6002c`, commit `57ee041`) with `tests/test_known_failures.py` pinning 38 rows and the digest. §F's path now resolves in a clone.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L437
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  79. 83
    H18 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: liboqs version pin — **TWO VALUES.** `artifacts/native/verified_impl.json` and `artifacts/attestation/oqs_attestation.json` record `0.14.0` (and a `/Users/<redacted>/_oqs/` path — the account name is redacted because this row is served verbatim on a public page and the defect is the hard-coded home-rooted path, not the account that happened to own it); `ct_fullpath_ci.json`, `ct_mlkem_ci.json` and rank 26 record `0.15.0`. Nothing gates the disagreement; `make verified-impl` regeneration is the fix (S05).
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L438
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  80. 84
    H19 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Nine `artifacts/native/*.json` had no Makefile target (`guard_advertising_ci.json → n_scripts_invoked_only_by_an_unreachable_target 95`) — **FOUR NOW HAVE ONE** (`omnibus-coverage`, `stale-retractions`, `underclaim`, `evolve-fleet`, Makefile S04 block). Five remain cloud- or owner-only and are registered DEFER with the script path as command: `modal_hunt_local/modal`, `outward_hunt_ci`, `native_daemon_aws`, `pq_fabric_efa`, `pq_fabric_transport`, `state_exhaustion_dos_modal_probe`. `underclaim` stays RED (recall 1/3).
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L439
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  81. 85
    H20 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `frontier_redteam_ci.json ok:true` with `frontier_llm_ok:false`; `libjade_bench_ci.json ok:true` with `libjade_ran:false` — **GREEN WITH A DEAD HEADLINE LEG.** Both are honest about the leg but the top-level `ok` hides it; `tools/check_top40_scope_flags.py` flags `*_ran:false` the moment either enters a sidecar. Registered DEFER (`honest-skips-four-tools`).
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L440
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  82. 86
    H21 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `mechanism_search_ci.json K'=32` beside `k_floor_theorem_ci.json K_facet = 26` (over the frozen 32-toggle DSL, where it is measured circular; cf. `K_constr = 7`); `composite_kem_fix_cost_ci.json` 23,162 ns beside `pqc_binding_fix_cost_classwide_ci.json` 27,929 ns for the same ML-KEM-768 encap+decap — **TWO NUMBERS FOR ONE QUANTITY, TWICE.** K' is the unique minimal cover over the 34-term DSL vocabulary; K is the fooling-set floor over 32 mechanisms — different objects that will be read as one. The two timings are two hosts/runs. `tools/check_number_agreement.py` (commit `fd2abb1`) is the instrument to extend.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L441
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  83. 87
    H22 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `artifacts/supply_chain/sbom.cdx.json` — **UNLOCKED DECLARATIONS.** `liboqs-python` and `cryptography` carry `wifi-pqc:integrity = unlocked-declaration` (version ranges, no hashes). Uncited; fails most supply-chain reviews on sight.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L442
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  84. 88
    H24 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `make stale-retractions` after S02/S04 — **RED, CAUSED BY A RECEIPT.** `tools/check_stale_retractions.py` scans every tracked file for retracted phrases and found `blocked account-wide` in `out/guard_regen_2026-09/stale_retractions_ci.json:75` — the S02 receipt copy of the guard's own earlier output, which lists that retraction verbatim. The guard exempts its own `artifacts/native/` output but not a copy at another path. Not routed around (I11): the receipt stays, the guard stays red, and the choice (exempt receipt copies under `out/`, or stop copying guard outputs there) is the owner's. Receipt: this turn's run, `ACCEPTANCE: FAIL — red teeth ['no_live_stale_retraction']`.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L443
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  85. 89
    H25 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: `artifacts/native/cross_protocol_amplification.json` (20 protocols, amplification 6–148×, the only uncited artifact with a bar in `conformance/PREREG.json`) — **GENERATOR CRASHES AT HEAD.** `make cross-protocol-amplification` raises `KeyError: 'rdma_rocev2'` at `tools/hostapd_pqc/cross_protocol_amplification_ci.py:279` — the run banner says 23 protocols, three were added to the list without `SPEC_BUDGET` entries, so the committed 20-protocol artifact cannot be regenerated today (`out/run_receipts_register_2026-09.json` rank 8, exit 2). Registered DEFER with the bounded step (add the budgets with citations, re-run, re-seal `n_protocols_min`). Not repaired here.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L444
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  86. 90
    H26 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Two Farkas checker sources: `oss/farkas-check/src/farkas_check.c` (216 lines, added `36187b4` 2026-07-28, unchanged since) and `pqc-state-verifier-bundle/src/farkas_check.c` (234 lines, added `07bd03c` 2026-08-13, hardened `e7ff15d` 2026-08-14 with `strtoimax`/`ERANGE` integer reads and a trailing-input check) — **SETTLED FROM THE EVIDENCE (S06).** The gate `tools/check_farkas_certs.py:52` compiles the 216-line `oss/` copy; its docstring's "hardened sibling" (`:21`) contrasts it with the deleted 123-line fork, not with the bundle. The bundle copy is the newer, stricter file and the one the standalone bundle ships (`pqc-state-verifier-bundle/Makefile:8`). Canonical for any port or publication: **the bundle copy**; the `oss/` copy is behind by the 2026-08-14 hardening. Not edited here: aligning the two (or pointing the gate at the bundle) is an owner decision recorded as DEFER `farkas-two-sources`.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L445
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  87. 91
    H27 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: Rank 9 `dos-residency-law-two-endpoint`: the bounded arm "undecided on this host" (16 KiB darwin pages; `dos_measure_ci.py` abstains when page_size ≥ bounded_cap) — **DECIDED ON A 4 KiB HOST, AGAINST THE SEALED SLOPE (S06 row 4, NEGATIVE_RESULTS.md NR-2).** Seal `conformance/predictions/dos_law_linux4k.json` (5e0c893) predicted page 4096, 0 abstentions, headline decided, naive slope 1.00 ± 0.02, bounded slope CI ∋ 0, bounded ≤ cap. Measured (`artifacts/native/dos_memory_ci_linux4k.json`): page 4096 ✓, `abstained = []` ✓ (8 of 8 gates decided), headline decided ✓ (FALSE), bounded slope CI [0, 0] ✓, bounded ≤ cap ✓, **naive slope 0.9546 ✗**. The committed darwin artifact is unchanged; the Linux one sits beside it. Not repaired: the tool's ratio arithmetic and the naive-arm intercept (−48.5 MB, CI [−56.8, −40.2] MB) are recorded, not explained.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L446
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  88. 92
    H23 — CORRECTED and withdrawn. The claim, quoted here so the retraction is legible: The modelrisk harness `the-trusted-checker-spawns-a-process` break — **RED AND GREEN BOTH FAIL TODAY.** The restore leg does not return the gate to green in the harness run (`out/harness_modelrisk-redgreen_2026-09.log` lines 8-10) while `make modelrisk-gate` alone passes 21/21 (rank 14, `out/run_receipts_2026-09.json`). Cause not isolated; not repaired around.
    receipt
    path
    f4/STALE_CLAIMS.md
    anchor
    L447
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  89. 93
    Rank 1 (quota-curve-forced-minimum) — Model-relative to filing #12's abstraction (each session costs at least s_min; aggregate is the sum). It fixes how many sessions can be live, not which to refuse; the reservation interlock that enforces it is the rank-7 mechanism. Sealed 2026-09-02 (2f16fa8) before tools/check_quota_curve.py existed; the seal's BLIND item (whether z3 decides the symbolic implication) came back decided. A first checker version read the wrong key for the cross-check and failed the seal; the key was corrected and the seal untouched.
    receipt
    path
    f4/artifacts/native/quota_curve_ci.json
    sha256
    f705b726e88606c1f1b1c1d823fc6b87eea197953989ed283d6d1f44845b4511
    bytes
    1776
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/quota_curve_ci.json | shasum -a 256
    open receipt
  90. 94
    Rank 2 (dyncap-adaptive-cap-guarantees) — no_starvation holds under the hypothesis `sharedSum l + RESERVE * l.length <= cap`, which a cap DECREASE breaks; the unconditional reading is FALSE of the program and modelrisk_ci.json records that measurement. On this host today the gate is RED on no-starvation (18/19) and the harness accepts 4 of 19 breaks; both are findings, not repairs. Committed dyncap_ci.json says PASS 19/19; regenerated 2026-09-02 says FAIL 18/19 with failures=['no-starvation'] (out/harness_regen_2026-09/dyncap_ci.json). The harness's 15 BAD cases all redden no-starvation alongside their own check, so the count 19 that rank 2 sums is a committed count, not today's. The conditional theorem stands (modelrisk_ci.json checks[13]).
    receipt
    path
    f4/artifacts/native/dyncap_ci.json
    sha256
    8684e52a9e791ed80a0f669429981ebe5747ef0f1ba5d9e0c28dc73823e648ff
    bytes
    30335
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/dyncap_ci.json | shasum -a 256
    open receipt
  91. 95
    Rank 3 (identifier withheld under I8) — A statement about the modeled receiver state under the TTE spec in [filename withheld under I8: MECHANISM-PRIVATE floor family]; it says nothing about timing or content channels. The receipt file [filename withheld under I8: MECHANISM-PRIVATE floor family] records verdict EXACT and an axiom audit of 12 theorems; [filename withheld under I8: MECHANISM-PRIVATE floor family].json is the regenerable form. Axioms must stay within {propext, Classical.choice, Quot.sound}; anything else printed by the kernel fails the gate. Rank 6 cites the svirt engine side of the same result; this entry is the proof side, previously cited by no document.
    receipt
    path
    f4/lane_register.json
    sha256
    a95b6d9b5d2ad4b497dc151870ea2777ce6ae9aec105c13ea83bb1bd9e7ee3d0
    bytes
    149143
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  92. 96
    Rank 4 (kem-combiner-binding-audit-four-standards) — Held at RED candidate: human and counsel review, independent re-verification, never auto-promoted, no legal or FTO conclusion. S06 (2026-09-02): all 38 ProVerif verdicts were sealed in conformance/predictions/outward_provers.json (17e4fd3) before make outward-provers re-ran them; the fresh transcripts reproduce every sealed verdict and this artifact re-derives with no changed key (axis A). The Tamarin re-transcription is the companion entry tamarin-retranscription-[filename withheld under I8: public-key-binding hunt held pending counsel]-four-standards. The seal fixes the verdicts, not their exploitability: the exploitability companion (keytransport-exploit-killed-by-prereg) kills the estate's own exploit against these gaps, so the honest class is 'binding robustness gap', not 'break'. Re-running the same prover tests the prover; the independent leg is the Tamarin entry.
    receipt
    path
    f4/artifacts/native/kem_combiner_binding_audit_ci.json
    sha256
    458648980b4f8cabb77dfcfe1ca81d84d764247f44428c357359f8e069487493
    bytes
    9006
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/kem_combiner_binding_audit_ci.json | shasum -a 256
    open receipt
  93. 97
    Rank 5 (keytransport-spec-evidence-two-rfcs) — Two of the four are drafts whose text the artifact says to verify against the cited version; only the two RFCs are independently confirmed. This is a textual finding about what the standards say, not an exploit. Pair with keytransport-exploit-killed-by-prereg before quoting: the gap is real in the text and the exploit does not exist.
    receipt
    path
    f4/artifacts/native/pqc_keytransport_spec_evidence_ci.json
    sha256
    a2d96282adc6fc099b6668e01f7ff80bd7174a154054abf48eb2d9a42f7435d5
    bytes
    5193
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqc_keytransport_spec_evidence_ci.json | shasum -a 256
    open receipt
  94. 98
    Rank 6 (keytransport-exploit-killed-by-prereg) — A self-refutation about the estate's own finding; honest_residue names the one non-standard system where the gap would matter and why that is a misuse of the primitive. The kill list was written by the same team that found the gap; it is pre-written relative to the exploit attempt, not sealed against the finding (A-NOBAR).
    receipt
    path
    f4/artifacts/native/pqc_keytransport_exploitability_ci.json
    sha256
    eaef75060fdeb7594cf44a7417ef81cdf359d1f864ed7193a6e69df3dc5ae5ca
    bytes
    6422
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqc_keytransport_exploitability_ci.json | shasum -a 256
    open receipt
  95. 99
    Rank 7 (pqc-binding-conformance-kat) — An instrument: it grades combiners against a rule this repository wrote. The rule is stated before the vectors are generated; it is not an external bar. Offered as remediation tests; no standard body has run them (n_external_runs 0).
    receipt
    path
    f4/artifacts/native/pqc_binding_conformance_kat_ci.json
    sha256
    85a1ccbacb3e8f17d81f0f87a8eee43bd36fff5fbfbf3d0fc418ee26c7e7512b
    bytes
    1917
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqc_binding_conformance_kat_ci.json | shasum -a 256
    open receipt
  96. 100
    Rank 8 (hybrid-downgrade-family-seven-protocols) — Symbolic (ProVerif) models of the protocols, not their deployed code; RESIST is a statement about the model. The OWE row is an expected negative. The S06 seal (conformance/predictions/hybrid_family_seven.json, 681d9ba) is RECORDED, not blind: the four new verdicts were already in the day's outward_provers_ci.json; what it fixes is the family artifact's regeneration at 7/7. ProVerif must be on PATH; the artifact records prover='ProVerif (real binary)'.
    receipt
    path
    f4/artifacts/native/pqc_hybrid_downgrade_family_ci.json
    sha256
    5d65a8f8e9a7543a2411ebe4bc3fa3a34cb8f34d63619702881a14965fed1783
    bytes
    5868
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqc_hybrid_downgrade_family_ci.json | shasum -a 256
    open receipt
  97. 101
    Rank 9 (merkle-beacon-onair-13x) — Airtime is modeled from measured frame bytes; no radio. The CIs are bootstrap over 40 trials on this host. The on-air reduction (13.5509) and window optimum are byte-stable across runs; the CPU-reduction CIs move with host load (2026-09-02: AP sign 60.44 with CI95 [40.89, ...] vs committed 58.64 [42.91, 79.72]; out/register_regen_2026-09/merkle_beacon_onair_ci.json). STALE_CLAIMS H4/H5 already corrected earlier misattributions of these figures; quote this artifact only.
    receipt
    path
    f4/artifacts/native/merkle_beacon_onair_ci.json
    sha256
    6ddb01cefb34f63b49eb2f8e5d0608dad6364b16151094d073ec4f8a3ebf15c4
    bytes
    32166
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/merkle_beacon_onair_ci.json | shasum -a 256
    open receipt
  98. 102
    Rank 10 (ap-resource-gate-met-and-nogo) — Process tournament on localhost; the artifact's scope excludes hostapd, RF and enterprise-AP benchmarks. Three of five arms store 0 because they did not qualify at the minimum tested load, which metric_scope pre-declares. Regenerated 2026-09-02 on this host in 401 s with the same outcome (ENGINEERING_THRESHOLD_MET, ratio 1.24, NO-GO) while per-trial latencies moved with host load (out/churn_diff_s04b_2026-09.txt); the committed artifact is kept. Generator unresolvable by conformance/artifact_freshness_ledger.json (bash-driven). [filename withheld under I8: the AP resource-gate event stream].jsonl (70 MB) is its raw stream and stays out of any public surface.
    receipt
    path
    f4/artifacts/native/ap_resource_gate_ci.json
    sha256
    b6ca20514b3389487ae2faaad6292b2b4df4e8c03f4194719833aa5ad79e7647
    bytes
    258504
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/ap_resource_gate_ci.json | shasum -a 256
    open receipt
  99. 103
    Rank 11 (interop-kit-stdlib-verifier) — Designed to grade third parties; n_external_runs is 0 (artifacts/native/external_readiness_ledger_ci.json -> n_externally_validated=0). Publishing the three files is an S11 item; until then this is an instrument with no external receipt.
    receipt
    path
    f4/artifacts/native/interop_kit_ci.json
    sha256
    8e20b8d04bb5d73b301be79de50ee7e95fd7b008b680364978f205820f26404c
    bytes
    537
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/interop_kit_ci.json | shasum -a 256
    open receipt
  100. 104
    Rank 12 (three-impossibility-filings) — Tier-3, model-relative: impossibilities over the modeled abstraction, not theorems about deployed stacks or legal design-around conclusions. Rank 37 (dos-trichotomy-impossibility) is filing #12 of the same family; state all three with their z3 version.
    receipt
    path
    f4/artifacts/native/xlayer_impossibility_ci.json
    sha256
    282e58a7ce5cadb82e1454bdb86f0dcba8e5202b540e4bf033dbaf67b6f61103
    bytes
    1112
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/xlayer_impossibility_ci.json | shasum -a 256
    open receipt
  101. 105
    Rank 13 (rtl-fault-trusted-computing-base) — Fault injection at the RTL level under a symbolic model; no physical glitching. Yosys version is recorded in rtl_gate_ci.json, not here. Named only in reports/fault_model_ci.md before this entry.
    receipt
    path
    f4/artifacts/native/fault_model_ci.json
    sha256
    57c271f88e9e2f195046728934cea23cf07197f22dccd13c7b319727068388ba
    bytes
    1795
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/fault_model_ci.json | shasum -a 256
    open receipt
  102. 106
    Rank 14 (sealed-predictions-mechanism) — The mechanism, not any single result. Only 3 predictions are gate-verified today; 10 of the 12 files were cited by no document before this entry. A seal written after a result does not make it pre-registered; the S04 note records that the four standards findings are A-NOBAR for this reason.
    receipt
    path
    f4/artifacts/native/prereg_ci.json
    sha256
    e53535661e8bfdf95eac27f37bec99f9648428b67a3b89d147b1c666b655e1fc
    bytes
    10432
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/prereg_ci.json | shasum -a 256
    open receipt
  103. 107
    Rank 15 (optimality-cert-drat-three-solvers) — K_facet over the frozen 32-toggle DSL, where it is measured circular (STALE_CLAIMS R1); not the K_constr=7 result of rank 5, and never to be compared with it. The DRAT file itself is not shipped with the artifact; shipping it is the bounded step.
    receipt
    path
    f4/artifacts/native/optimality_cert_ci.json
    sha256
    887300966344aacb6214c00fa1164bc3708f29b6241f1f13511a779d24db218e
    bytes
    7378
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/optimality_cert_ci.json | shasum -a 256
    open receipt
  104. 108
    Rank 16 (conservation-laws-two-arbiters) — Laws over the modeled receiver; the Lean files are AuthEntropy.lean (deception floor, movable but irreducible) and ReassemblyFloor.lean (buffer-all or gate, no third option). The flagship theory object was cited by no prose before this entry.
    receipt
    path
    f4/artifacts/native/conservation_laws_ci.json
    sha256
    1f9e7bb5109c2ffe1c402669d3a773b11f44714d925623cce781fdcf156d9024
    bytes
    2024
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/conservation_laws_ci.json | shasum -a 256
    open receipt
  105. 109
    Rank 17 (tightness-bounds-four-term) — The bound is over the four envelope reductions of rank 22; the wider EasyCrypt trust base (31 of 56 axioms research-grade) is measured separately. Concrete in form; the advantage terms are named, not numerically bounded.
    receipt
    path
    f4/artifacts/native/tightness_bounds_ci.json
    sha256
    3a97e8186c07fdb087d6a4decf811ef5e09d9cb4b19129b17c9036e823058f32
    bytes
    1643
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/tightness_bounds_ci.json | shasum -a 256
    open receipt
  106. 110
    Rank 18 (pqc-handshake-onair-overhead-2272B) — Object sizes only; no framing, retransmission or fragmentation cost is included. The cleanest buyer sentence in the tree had no prose home before this entry.
    receipt
    path
    f4/artifacts/native/pqc_handshake_onair_overhead_ci.json
    sha256
    85fcc9962fd2168c1c115b24c5a16c257040e155f0ea0dcf5f311e074bb9410b
    bytes
    2713
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqc_handshake_onair_overhead_ci.json | shasum -a 256
    open receipt
  107. 111
    Rank 19 (designaround-boundaries-sig-exceeds-frame) — Cover sizes are model-relative over the declared vocabularies; the byte comparison is arithmetic over FIPS 204 and IEEE 802.11 constants. The 5 vs 13 cover sizes carry the same model-relativity as ranks 5 and 28.
    receipt
    path
    f4/artifacts/native/designaround_boundaries_ci.json
    sha256
    7137859aa1828ef0c090e1afb5875b98d59bfdfacc9b1f9286cbf23c7cb10309
    bytes
    2619
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/designaround_boundaries_ci.json | shasum -a 256
    open receipt
  108. 112
    Rank 20 (native-akm-inband-real-frames) — The driver builds and runs on this host (gate 4: BYTE_IDENTICAL, 1.6 s); the committed pcap under 07_hwsim_emulation/real/native_akm_inband/ is from a Linux hwsim run. The pcaps are evidence and stay private; only their hashes and counts appear in any public surface. The daemon-driven handshake is NOT claimed: native_daemon_aws.json records every rung false and native_daemon_ci.json records bind_active_default_off=true.
    receipt
    path
    f4/artifacts/native/native_akm_inband_ci.json
    sha256
    7835ffc23826212ae33f1d2f6b25099038166235f51db2ec5088a3e5a53068f3
    bytes
    998
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/native_akm_inband_ci.json | shasum -a 256
    open receipt
  109. 113
    Rank 21 (selfattestation-boundary-824-of-954) — A statement about the acceptance checker's own dependence on committed artifacts; it grades nothing external. Per-run: the committed artifact records 824/130 with 176 artifacts removed (954 criteria); regenerating on 2026-09-02 (602.8 s) gave 816 pass / 140 fail with 215 removed over 956 criteria (out/register_regen_2026-09/selfattestation_boundary.json), because 39 more artifacts now exist. Quote the committed run with its date. Cited nowhere before this entry; AUDIT.md gains the pointer in S04.
    receipt
    path
    f4/artifacts/native/selfattestation_boundary.json
    sha256
    97242f12e5b3aaf60a481c57b7c29608517e9508aa58d9e38ca5c7ff6118c78e
    bytes
    955
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/selfattestation_boundary.json | shasum -a 256
    open receipt
  110. 114
    Rank 22 (gate-genus-opentimestamps) — The 124 cells are the modeled genus; the .ots anchors when the prediction was sealed, not the correctness of the cells. `make gate-genus` (lib/wifipqc/gate_genus.py) writes only the markdown certificate; the JSON artifact is written by lib/wifipqc/gate_genus_smt.py, so the command here is `make gate-genus-smt` (added in S04 after gate 4 returned EXIT0_NO_TOUCH on the first command -- the D9 class, caught by running). Verifying the .ots against Bitcoin requires the ots client and network; not run here.
    receipt
    path
    f4/artifacts/native/gate_genus_ci.json
    sha256
    a8c30d7ddfee745afe166be8c527d7b168a295e47dbf623151387990f0879547
    bytes
    185
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/gate_genus_ci.json | shasum -a 256
    open receipt
  111. 115
    Rank 23 (pqxdh-reproduces-published-finding) — A model of PQXDH; the artifact states the result is NOT novel and cites the papers it reproduces. External validation here is agreement with published work, not a new indictment.
    receipt
    path
    f4/artifacts/native/pqxdh_ci.json
    sha256
    2afb28c5e88562694a3ebb6b0be6a05441e4bfde43e01bf6ec0aac11f52207f1
    bytes
    1927
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/pqxdh_ci.json | shasum -a 256
    open receipt
  112. 116
    Rank 24 (ikev2-rfc9370-resist-certificate) — Symbolic model of the deployed protocol; not the strongSwan code. Fills a gap the artifact attributes to Gazdag et al. ACSAC 2021; no WG has received it.
    receipt
    path
    f4/artifacts/native/ikev2_rfc9370_downgrade_ci.json
    sha256
    67b4407dba41055dba3473d1e8506fd1f1dfe744001009205dd90576185fe1b3
    bytes
    1670
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/ikev2_rfc9370_downgrade_ci.json | shasum -a 256
    open receipt
  113. 117
    Rank 25 (adversarial-gate-audit-26-of-26-bite) — Mutation of the gates, not of the mechanisms; a bite means the gate went red under its mutation. The 26 mutation diffs are not committed as patch files.
    receipt
    path
    f4/artifacts/native/adversarial_gate_audit_ci.json
    sha256
    a31b2768a4fc99f9fdd60c8198d6add7901384a7e0288ee8da33130eae6c269c
    bytes
    5315
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/adversarial_gate_audit_ci.json | shasum -a 256
    open receipt
  114. 118
    Rank 26 (wire-vocabulary-abstain-with-protocol) — Passive observation of committed real-radio captures; no detectability number is produced. The paired experiment is an S05 candidate ($0 on the hwsim runner).
    receipt
    path
    f4/lane_register.json
    sha256
    a95b6d9b5d2ad4b497dc151870ea2777ce6ae9aec105c13ea83bb1bd9e7ee3d0
    bytes
    149143
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  115. 119
    Rank 27 (detectability-4-of-32-observable) — Which mechanisms are observable is mechanism detail and is kept out of every public sentence (I8); only the counts are public. 20 skipped probes are a third of the surface; the artifact names them.
    receipt
    path
    f4/lane_register.json
    sha256
    a95b6d9b5d2ad4b497dc151870ea2777ce6ae9aec105c13ea83bb1bd9e7ee3d0
    bytes
    149143
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  116. 120
    Rank 28 (oss-verifiers-six) — Local verification of public trees; PyPI/npm publication state is separate (404 per oss/OSS_RECONCILIATION.md). Wraps the packages' own verifiers; counts are parsed from their output.
    receipt
    path
    f4/artifacts/native/oss_verifiers_ci.json
    sha256
    44adc20435e880863c1296a37e20921c3f9dc2123dc34e7bf23ba2dff2276f0c
    bytes
    4408
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  117. 121
    Rank 29 (ap-resource-hwsim-stock-hostapd) — The PQC work runs in an external RADIUS worker reached through hostapd's MAC-ACL path; hostapd is the harness, not the subject. One association per arm, no flood. Raw pcaps are private evidence (disclosure/GateOS_PQC_Standards_Safety_2026/PRIVATE_ARTIFACT_MANIFEST.md); only hashes and counts appear in public sentences. tools/run_ap_resource_hwsim.sh delegates into the local colima VM (Linux 6.8.0 aarch64); it is a local run, not the hwsim-yes runner. Reject-arm frame count moves between runs (268 committed, 279 today) while the semantics (0/0/8/0) do not; quote the semantics, not the count. Policy files and the artifact share a first commit (af3daf6), so the bar is same-commit, not prior. The committed evidence files are the 2026-07-16 run; the 2026-09-02 regeneration is kept under out/register_regen_2026-09/.
    receipt
    path
    f4/artifacts/native/ap_resource_hwsim_ci.json
    sha256
    ef4b7db56aadf3c55eb0e148b0406438079e0c02e2d8dd1d4435cedcfb8091a3
    bytes
    7543
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/ap_resource_hwsim_ci.json | shasum -a 256
    open receipt
  118. 122
    Rank 30 (identifier withheld under I8) — Same held-at-RED classification as the ProVerif entry: a documented LEAK/MAL-BIND-K-PK robustness gap, assessed not exploitable, not novel as a class; what is new is a pre-registered two-prover indictment of four named standards. Each Tamarin model is one rule with the KDF transcript as the standard lists it and an exists-trace lemma for two public keys deriving one KEK. Finding on the instrument: the harness's Tamarin branch never passed --prove (no .spthy existed before S06), so the first run classified all five INDETERMINATE (out/outward_provers_ci_s06_indeterminate_spthy.json); the invocation was repaired in tools/check_outward_provers.py, the seal untouched. A transcription error common to both provers would survive this test; the field lists are quoted verbatim in pqc_keytransport_spec_evidence_ci.json.
    receipt
    path
    f4/artifacts/native/outward_provers_ci.json
    sha256
    89d9cf507fdf1f77ed1b3290330c0912cccd735f99249e69866c6e5c93628fb2
    bytes
    16793
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/outward_provers_ci.json | shasum -a 256
    open receipt
  119. 123
    Rank 31 (label-floor-forced-minimum-bits) — Model-relative to filing #15's abstraction: the label is the only protocol-distinguishing field in the KDF transcript and labels compare exactly. It bounds label *length* in the information-theoretic sense (pairwise distinctness), not content; a longer human-readable label meets it trivially. The floor is a pigeonhole fact; z3 checks it, it does not discover it. Sealed 2026-09-02 (4b7c4bd) before tools/check_label_floor.py existed; the BLIND item (whether z3 decides the 20-in-16 pigeonhole instance without timeout) came back decided in milliseconds. The genus count 20 is crossproto.py's list, which cross_protocol_amplification.json also reports; the S05 plan's '23' was a misreading and is corrected here.
    receipt
    path
    f4/artifacts/native/label_floor_ci.json
    sha256
    cf86d38e77da6c2f2a4eaec96bd6452b2ec46622dd0ddea28f7c5d3a32ea4558
    bytes
    2300
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/label_floor_ci.json | shasum -a 256
    open receipt
  120. 124
    Rank 32 (reassembly-window-crossing-point) — Arithmetic on the floor's own cited constants; it says how many concurrent reassembly contexts a 64 KiB AP can carry before no per-session cap admits a level-5 credential, nothing about load or timing. Replaces check_reassembly_floor.py's N_MAX_AP = 4 modeled constant with the theorem's value for this check only; the floor check itself is not edited. Sealed 2026-09-02 (681d9ba) before the tool existed. The first version of the tool used Python `/` (a float) where z3 integer division was meant and failed the seal on its own bug; the operator was corrected, the seal untouched, both runs kept in the runlog.
    receipt
    path
    f4/artifacts/native/reassembly_crossing_ci.json
    sha256
    014c5c33fef8a8b5100a5577614149818e242dcff45a53aeb2401b4b64345a6e
    bytes
    843
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/reassembly_crossing_ci.json | shasum -a 256
    open receipt
  121. 125
    Rank 33 (ap-quota-byte-accounted-eight) — A model of admission over lists of per-session byte counts ([filename withheld under I8: admission-mechanism source] imports ApBound.lean's events and per-session gate). ap_bounded_bytes has no hypothesis; sessions are bounded by G / RMIN with RMIN = 7533, the estate's smallest reassembled credential. The engine arm is measured by the companion entry ap-quota-bytes-engine. Sealed 2026-09-02 (681d9ba) before [filename withheld under I8: admission-mechanism source] or the driver existed; the BLIND item (whether the invariant proofs close without Mathlib in one turn) came back closed at the first compile. Mechanism detail beyond this paragraph stays out of public surfaces as ordinary practice.
    receipt
    path
    f4/artifacts/native/lean_ap_bytes_ci.json
    sha256
    5434634fe6f1a7f75200464d1b87a1ce674d6910cecb74ff8e877b52ad6e86e2
    bytes
    3558
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/lean_ap_bytes_ci.json | shasum -a 256
    open receipt
  122. 126
    Rank 34 (interop-three-parameter-sets-new-releases) — Cross-vendor KEM interop (encap by A / decap by B and the reverse, secrets equal, sizes per FIPS 203) plus the interop-kit PTK oracle on a live secret; a statement about two libraries on this host, not about any AP. The releases were built from their upstream tarballs into scratch prefixes; nothing was upgraded system-wide. Sealed 2026-09-02 (a3194e4) before the builds and before the harness was parametrised. The version strings are RECORDED, not sealed: regenerating on a host with other libraries reproduces the contract against those libraries and the vendors / version fields move (the S02 finding on rank 26 applies). oqs-python 0.14.0 warns that liboqs 0.16.0 differs in minor version; the checks passed under that warning.
    receipt
    path
    f4/artifacts/native/interop_3p_ci.json
    sha256
    6feca0be5f16c2754236770c129f84ae60232558ae277e2364457a6c2c87aa8d
    bytes
    2388
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/interop_3p_ci.json | shasum -a 256
    open receipt
  123. 127
    Rank 35 (claimbom-second-target-dilithium) — One repository at one pinned commit, built on macOS arm64 only (the README's avx2/ tree and its Linux leg were not attempted); the four Q rows are the instrument's diligence questions, not the target's claims. Held to the same reading as the kyber BOM: nothing here is a criticism of authors who publish reference code for free. Sealed 2026-09-02 (0097cbe). Two instrument defects surfaced by the first two live passes are recorded in ip/notes/claimbom_dilithium.md and the ledger (harness failed to compile and read as REFUTED; materiality keyed on an id prefix); the third pass is the published one. The replay gate rebuilds the BOM from the capture with identical verdicts and derived fields; the committed BOM is the live one. Q2 is UNVERIFIABLE by its own rule (patent endpoints), as for kyber.
    receipt
    path
    f4/artifacts/claimbom/pq-crystals-dilithium.bom.json
    sha256
    02a1c81115c6b9b0b764d1212d1830d512e0f5af92311543a0a25c1c5a1bcfea
    bytes
    364193
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/claimbom/pq-crystals-dilithium.bom.json | shasum -a 256
    open receipt
  124. 128
    Rank 36 (ap-quota-bytes-engine) — Reference engine (Python) on localhost: retained bytes are exact, RSS deltas are page-quantised noise. The wire-level leg stays BLOCKED on this host as before. RMIN = 7533 is a deployment parameter like G and CAP. Sealed 2026-09-02 (870639c) before the policy existed. The first checker version read flood rows by a key they do not carry and crashed before writing; fixed, seal untouched. BLIND items recorded: on the overfill flood the arm settles at 4 live sessions (every admitted session fills to the cap) with slope 2.76 B per offered session.
    receipt
    path
    f4/artifacts/native/ap_quota_ci.json
    sha256
    8490a22a274cf3c51c932eecb702063a1ef4eeecf40714a7033928969c1701cb
    bytes
    25055
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/ap_quota_ci.json | shasum -a 256
    open receipt
  125. 129
    Rank 37 (tightness-numeric-four-term) — Arithmetic on the committed bound and its inputs; the O2H/FO form is the one MLKEM_IND_CCA.ec makes explicit. Not a new reduction: a tighter FO analysis would move the number and is not claimed. The signature term has no anchor and is left symbolic; adding it can only make the envelope larger. Sealed 2026-09-02 (99d7c98) before the tool existed. q_H, q_dec and the PRF assumption are sealed inputs, not measurements; a buyer with a different query budget recomputes with --q-h-log2.
    receipt
    path
    f4/artifacts/native/tightness_numeric_ci.json
    sha256
    91dea90bceecb0ce50c72e462474d1053bb3941921ded73920ca1e740dc88ba4
    bytes
    1348
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/tightness_numeric_ci.json | shasum -a 256
    open receipt
  126. 130
    Rank 38 (length-privacy-pareto-curve) — Exact over the declared three-class set with one object per class and no class weights; leakage is log2(distinct on-air shapes) under the estate's own _shape. A different population has a different curve. Sealed 2026-09-02 (e2ff326) before the tool existed; the seal's extractor was made to project the two sealed fields after the artifact gained a `targets` field (seal untouched).
    receipt
    path
    f4/artifacts/native/length_privacy_pareto_ci.json
    sha256
    89784b7db444b54392c3ebecda636b6ac4426a2fcfdb7fbb80fb36b93d780c83
    bytes
    1399
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/length_privacy_pareto_ci.json | shasum -a 256
    open receipt
  127. 131
    Rank 39 (claimbom-third-target-mlkem-native) — One repository at one pinned commit, built and tested on macOS arm64 (the README's Ubuntu quickstart passes here too); the formal-verification row records proof artefacts present and not re-run. The four Q rows are the instrument's questions. Nothing here is a criticism of authors who publish reference code for free. Sealed 2026-09-02 (870639c). Three live passes: the first died on GitHub's rate limit, the second on a harness that did not link and a badge extractor blind to GitHub's SVG; both instrument defects are repaired and recorded in ip/notes/claimbom_mlkem_native.md; the third pass is committed. Q2 is UNVERIFIABLE by its own rule, as for the other targets.
    receipt
    path
    f4/artifacts/claimbom/pq-code-package-mlkem-native.bom.json
    sha256
    601e9729579fb3f9466f832f3d7c6b7757072802bb7b76448aab867e6778e334
    bytes
    252610
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/claimbom/pq-code-package-mlkem-native.bom.json | shasum -a 256
    open receipt
  128. 132
    Rank 40 (hybrid-downgrade-citation) — A citation surface for the family already registered at rank 8, not a new measurement. RESIST remains a statement about symbolic models of simplified protocols under a classical Dolev-Yao attacker, teeth-verified; it is not a statement about deployed code. Any lane citing the family must carry the OWE row, which BREAKs by design. Sealed 2026-09-04 (508f74b) before the tool existed; RECORDED not blind, and the seal says so. The first version of the mutation control pointed --verify at an artifact that did not exist yet, so exit 1 came from a traceback rather than a mismatch, and it was fixed before the run.
    receipt
    path
    f4/artifacts/native/hybrid_downgrade_citation.json
    sha256
    54cfdd596e979604216b2746aac4900ab6cce534192bc9abba41bd4df63d2535
    bytes
    6907
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/hybrid_downgrade_citation.json | shasum -a 256
    open receipt
  129. 133
    Rank 41 (public-surfaces-estate) — Grades THE SURFACE, NOT THE SENTENCE: a row says what a registry answered on one date, and what that means for any lane's claim is that lane's to decide. LIVE_NOT_OURS means the registry payload declares no URL tying the name to this estate, not that anyone took it. Register text was the input list only. Three lanes claim a public OSS surface and name no name in the row, so those rows are not gradable by a stranger and are recorded as such. Sealed 2026-09-04 (508f74b) before the tool existed and before any registry was queried; the whole surface list is inside the seal, so the tool refuses to run if the list narrows. Every verdict was blind. A registry answer is a fact about one date: a name absent today can be taken tomorrow. Findings belong to the target lane to correct, per the orchestrator's assignment.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  130. 134
    Rank 42 (farkas-payload-kind-for-the-envelope) — The checker decides the three affine-Farkas conditions and nothing else: not premise feasibility (an infeasible premise makes the implication vacuously true), not the trusted root, and not that the modeled bound describes any deployed system. Its trusted base is a C99 compiler, POSIX shell and make. Sealed 2026-09-04 (508f74b) before spec/ existed. Nothing has been pushed: I7 makes the handover to f8 a push-list item and it is listed in CROSS_LANE_2026-09.md section C. The first version of the decided_by rule keyed on whether the exit code was a valid one rather than whether it was the expected one, which mislabelled the wrong-root vector as payload-decided; fixed before the run.
    receipt
    path
    f4/artifacts/native/farkas_payload_kind_ci.json
    sha256
    cb35b541c156aadf2d70d73683796f6cc780d2c1929027d0ab09c1fcb8f81a36
    bytes
    4121
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/farkas_payload_kind_ci.json | shasum -a 256
    open receipt
  131. 135
    The claim checker was pointed at pq-crystals/kyber at commit 3edd5af5 and verdicted 12 rows from a closed vocabulary: 2 of 8 material claims refuted under a stated reading, 3 of 12 rows refuted counting every row. THE BAR: there was none. This run predates the seal discipline in this repository, so no prediction was fixed before the target was read, and the claim list is an input the instrument chose rather than a list the target published as its claims. It is therefore a measurement and not an indictment, and it is recorded here rather than beside the rows that do carry a sealed bar. An earlier published version of this figure said 3 for kyber, counting a question the instrument itself poses about registry names against a material-claims-only denominator; that number is retracted in this repository's own record as R29. What would make it an indictment is stated with the other open questions: a claim list and a materiality rule sealed before the target is read.
    receipt
    path
    f4/artifacts/claimbom/pq-crystals-kyber.bom.json
    sha256
    7fbe34e3f8d88420338d25c4211c8835bd4a2929a4d88772d8b749cbb160b4f7
    bytes
    245167
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/claimbom/pq-crystals-kyber.bom.json | shasum -a 256
    open receipt
  132. 136
    The repository behind this page is private and unpushed: 97 commits sat above its own remote when this package was generated. A push count is a moving fact and not a limit -- this repository's own record says so -- so read it as the state on one date and not as a property. What does not move: nothing produced in this program is reachable by a reader, and the public surface is the eleven repositories and two datasets frozen on 2026-08-18.
    receipt
    path
    f4/STALE_CLAIMS.md
    sha256
    5ae644d67609e27d6fb8f2114b9244ececf64f3a8121515c9890a9ae20ae7f71
    bytes
    49292
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  133. 137
    Site-thread correction to the row above, which f4 wrote while its evidence was unreachable: "nothing produced in this program is reachable by a reader" is no longer true of the cited evidence. This site publishes 68 of that repository's files as receipts. The repository is still private and the eleven public repositories and two datasets are still the whole of its public surface elsewhere.
    receipt
    path
    site/SITE_CORRECTIONS_2026-09-04.md
    anchor
    L38-L47
    sha256
    528184611493ef729eab03a8a974f3e81e5c3e142a719998b531ef87437acacf
    bytes
    9140
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/site/SITE_CORRECTIONS_2026-09-04.md | shasum -a 256
    open receipt
  134. 138
    Nothing is installable. Four Python package names and one npm name are built and twine-clean and the indexes answered ABSENT on 2026-09-05T00:54:09Z; the name `pco` answered LIVE and is a third party's. No install line for any of them appears on this page.
    receipt
    path
    f4/artifacts/native/public_surfaces_ci.json
    sha256
    94c0f2ba4260f26f5808a7132551982a779da1df878f95c3c97f56cdde640ef2
    bytes
    42342
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/public_surfaces_ci.json | shasum -a 256
    open receipt
  135. 139
    No third party has run any instrument here: n_externally_validated = 0. Every claim graded against somebody else's work is graded by this lane's instrument against their published text.
    receipt
    path
    f4/artifacts/native/external_readiness_ledger_ci.json
    sha256
    c89c2361de164d2abad4d0e19fa751cdfd31c56ecdfd39ff2af00f016a898f85
    bytes
    957
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/external_readiness_ledger_ci.json | shasum -a 256
    open receipt
  136. 140
    5 of 12 research seals DIVERGED. Every one is written up as a negative result; a reader who counts before reading sees failures.
    receipt
    path
    f4/artifacts/native/research_seals_ci.json
    sha256
    ed0cfecc1644b6b3de27ced1d776c8bd6658f0837c68b360e0dd3cce0b4d2ee4
    bytes
    17023
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/research_seals_ci.json | shasum -a 256
    open receipt
  137. 141
    38 known failures are retained rather than closed, each with its disposition and verification tier.
    receipt
    path
    f4/conformance/known_failures.jsonl
    sha256
    150201d847a9f6c38ce722eff3f7a478d92d223500e2c397e8966836e6a6002c
    bytes
    18750
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/conformance/known_failures.jsonl | shasum -a 256
    open receipt
  138. 142
    One gate is red today by design: `make dyncap-gate` fails 18 of 19 on `no-starvation`, while the committed artifact records 19 of 19. The committed count is historical, not current.
    receipt
    path
    f4/artifacts/native/dyncap_ci.json
    sha256
    8684e52a9e791ed80a0f669429981ebe5747ef0f1ba5d9e0c28dc73823e648ff
    bytes
    30335
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/artifacts/native/dyncap_ci.json | shasum -a 256
    open receipt
  139. 143
    One surface check has a documented false positive that is deliberately not fixed: check 4 flags a quoted diff line recording a dead registry link being removed. Fixing it means editing a check, so it is carried as a finding.
    receipt
    path
    f4/oss/OSS_RECONCILIATION.md
    sha256
    017920c47e388031e981950a90bc41cb28cd887f1134416dcb00d5fd5f5248d9
    bytes
    16895
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/oss/OSS_RECONCILIATION.md | shasum -a 256
    open receipt
  140. 144
    The raw evidence is private: thirteen packet captures, a 70 MB event stream and the mechanism-detail artifacts stay out of every public surface. Only hashes, counts and semantics are published, so several numbers here cannot be recomputed from what is published.
    receipt
    path
    f4/oss/tools/check_surface.py
    sha256
    3f9083a96b54472566703d81cb1b78a0553c02664687fa2a0025810d10c6c580
    bytes
    17401
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  141. 145
    The byte-exact interoperability spec and the KEM-combiner public-key-binding hunt models are held: the first is mechanism detail, the second waits on counsel review. Neither is on any public surface.
    receipt
    path
    f4/lane_register.json
    sha256
    a95b6d9b5d2ad4b497dc151870ea2777ce6ae9aec105c13ea83bb1bd9e7ee3d0
    bytes
    149143
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  142. 146
    10 filenames were withheld from the statements above under I8, across 6 rows. The limitation each names is stated in full; only the private artifact's name is withheld, and the count is published here rather than left to be noticed.
    receipt
    path
    f4/oss/tools/check_surface.py
    sha256
    3f9083a96b54472566703d81cb1b78a0553c02664687fa2a0025810d10c6c580
    bytes
    17401
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  143. 147
    Until 2026-09-02 no pre-registered bar in this repository was committed before the result it graded; the three that existed were added in the same commit as their artifact, and one seal file disclaimed itself in its own text. Every bar cited on this site postdates that finding.
    receipt
    path
    f2/STALE_CLAIMS.md
    sha256
    229bf88c7ebc98f9efb2bb914180c2a6da7464d649a5e47e58adf70d9fe26a72
    bytes
    32776
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  144. 148
    Six sealed predictions have been missed and each is published with its receipt, including one where we predicted against the easy answer and lost, and one where a key held only vacuously and is flagged as such rather than counted.
    receipt
    path
    f2/NEGATIVE_RESULTS.md
    sha256
    e1b89f42dc09bb0da5694c6c584db8d6e173e00b40e7f089ccb8cdf5254ebd28
    bytes
    14757
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  145. 149
    Several results are live derivations only under docker: the eBPF corpus work, the repair engine and the proof-carrying checker. With the daemon stopped they refuse rather than pass — the control was run with docker down and the commands exited non-zero.
    receipt
    path
    f2/out/negative_controls_2026-09-02.txt
    sha256
    32f5d431659798df6a73a8863ead342d86e03c61a4ae98a035c2d0f253709903
    bytes
    1171
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  146. 150
    The kernel verifier logs behind those results live outside this repository by decision; what is committed is a manifest of their names, sizes and hashes.
    receipt
    path
    f2/artifacts/crs/bpf_kernel_logs_manifest.json
    sha256
    4502bb089d18df0ac2aa5dfa6b98504b3fdac0d3f496f58cf998ad88cedc2468
    bytes
    8242
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/bpf_kernel_logs_manifest.json | shasum -a 256
    open receipt
  147. 151
    One paid measurement has never run: the provider account returns insufficient balance, most recently on 2026-09-04. It is recorded as not run rather than quietly dropped, and its seal stays armed.
    receipt
    path
    f2/NEGATIVE_RESULTS.md
    sha256
    e1b89f42dc09bb0da5694c6c584db8d6e173e00b40e7f089ccb8cdf5254ebd28
    bytes
    14757
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  148. 152
    The browser verifier does not re-derive the probe-set Merkle root or the decoder binary hash — both need the generator and the binary — and reports them as unchecked rather than as passing. Its Ed25519 leg needs a browser whose WebCrypto implements Ed25519.
    receipt
    path
    f2/artifacts/browser-verifier/stranger_corpus_bundle.json
    sha256
    d9f3ca4ab9f6907c38c9c60df3ea0b3bc97034412ea6339dc8b093932eeabc03
    bytes
    17278
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/browser-verifier/stranger_corpus_bundle.json | shasum -a 256
    open receipt
  149. 153
    Certificates produced with integer tightening are certificates for the tightened system; the small standalone anchor does not yet replay that form, so the witness there is the decision procedure's own replay.
    receipt
    path
    f2/artifacts/crs/inference_floor_glm_tightened.json
    sha256
    96d23ba8ae8aef20496acb96d1c4e48b841840a78b4a9927f66598e7d78567e1
    bytes
    7532
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/inference_floor_glm_tightened.json | shasum -a 256
    open receipt
  150. 154
    We predict our own verifier will score zero on the estate's shared conformance corpus until the shared envelope registers our certificate kind, for the same reason two other lanes' verifiers scored zero: it does not speak that format. The prediction is sealed and untested.
    receipt
    path
    f2/artifacts/seals/atlas_when_staged_2026-09.seal.json
    sha256
    5ccf038875b5995bb43862420aff1b0f520ec08fa81d0b5762cab30e23678f9e
    bytes
    1137
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/seals/atlas_when_staged_2026-09.seal.json | shasum -a 256
    open receipt
  151. 155
    The certkit demo page fetches a pinned Pyodide runtime from a CDN when it loads. Nothing you type is uploaded, and it is not the zero-network verifier described above.
    receipt
    path
    f2/oss/spaces/certkit-demo/README.md
    sha256
    449b896a6c4fde87512c21083012dab38dd7eb638e50f833ea12b923c09e9c19
    bytes
    7664
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/oss/spaces/certkit-demo/README.md | shasum -a 256
    open receipt
  152. 156
    Every row of our soundness leaderboard is a baseline we wrote, scored against ground truth we computed. It demonstrates that the gate bites; it does not rank the field.
    receipt
    path
    f2/oss/soundnessbench/README.md
    sha256
    f1d0a9f68ee00d206ae9ab629d43ca0b2f3221ea4d18686a8ae1166093108e2e
    bytes
    16672
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/oss/soundnessbench/README.md | shasum -a 256
    open receipt
  153. 157
    Comparison against the Hugging Face hub is by file name and byte size, not by hash, because the hub's API exposes no object id. A same-size edit would not be detected.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt
  154. 158
    The multiview result's 'views' are temporally adjacent frames of a single clip; the real-camera number on genuine stereo pairs is roughly one sixth of it and is published beside it.
    receipt
    path
    f2/artifacts/multiview-stereo/summary.json
    sha256
    d4790aeb92bab354214a26db8e75ab3d4f3233416ca81c77a77c89b39568d99e
    bytes
    11172
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/multiview-stereo/summary.json | shasum -a 256
    open receipt
  155. 159
    The in-loop codec result is a negative and is kept as one; the restoration and HDR results are on a proxy codec and are labelled PROXY.
    receipt
    path
    f2/artifacts/real-vvc-inloop/summary.json
    sha256
    67433fb41b5b947c4df90a08f37d2e949915dd3e19665b2e9c3949560a46387c
    bytes
    16451
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/real-vvc-inloop/summary.json | shasum -a 256
    open receipt
  156. 160
    The decision procedure is sound but conservative over the rationals: it refuses a number of guards that are true only over the integers. The count is measured and published.
    receipt
    path
    f2/artifacts/crs/mutation_campaign_summary.json
    sha256
    095ca5b107e99fea1cb13cc54ab4dbf15023a15b577b987fb913c8856d8798d5
    bytes
    4245
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/crs/mutation_campaign_summary.json | shasum -a 256
    open receipt
  157. 161
    A shared gate in the audit kit reports INCONCLUSIVE on this repository because it cannot follow python -m recipes; that is a property of the gate and the waivers carry their own receipts.
    receipt
    path
    f2/reaudit_explained.json
    sha256
    a06b0a050a286f55dd966620a7ef6c5fe6b1708c4f825cc3cebf5303d1dc0b42
    bytes
    5386
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/reaudit_explained.json | shasum -a 256
    open receipt
  158. 162
    Two test assertions in an older working-set document have been failing since before this program began. They are left failing rather than edited, and they are the only red in the suite.
    receipt
    path
    f2/CROWN_JEWELS_WORKING_SET.md
    sha256
    707907d91add36c5b90e39290bba4cc27e44d08dc6748227cb1408bd6bb97a42
    bytes
    274903
    visibility
    sealed

    Sealed: the bytes are not published. The hash commits to them; the file is available under NDA and can be checked against this hash.

  159. 163
    Some committed artifacts still contain absolute home-directory paths from the machine that generated them. None is on a public surface; the publish preflight scans for exactly that and reports clear.
    receipt
    path
    f2/artifacts/oss/reconciliation.json
    sha256
    6b747996d9f15d91a62b6f70c4901b86e0bb559ddd6ed77e0e7b10ddacc795a4
    bytes
    7489
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/oss/reconciliation.json | shasum -a 256
    open receipt
  160. 164
    The rendering check for our two hosted demo pages could not run here: it needs a browser that is not installed. It is recorded as not run rather than as a pass.
    receipt
    path
    f2/PUBLISHED_2026-09-04.md
    sha256
    37d17ffdf4e548b976916be1d7e477057c47b5f68ecf256c1021617a47e4c910
    bytes
    5368
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/PUBLISHED_2026-09-04.md | shasum -a 256
    open receipt
  161. 165
    The checker this page runs is f2's browser verifier. Its home is the holding company, not this site: five sites embed the same implementation, so it is not owned by any one of them, and this site claims no credit for it. Its repository does not exist yet, so no link to it is offered here.
    receipt
    path
    site/SITE_CORRECTIONS_2026-09-04.md
    anchor
    L49-L56
    sha256
    528184611493ef729eab03a8a974f3e81e5c3e142a719998b531ef87437acacf
    bytes
    9140
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/site/SITE_CORRECTIONS_2026-09-04.md | shasum -a 256
    open receipt
  162. 166
    Two rows in the artifacts section, f3's protocol-bench command-line tool and its PCAR/1 bundle, describe themselves against "the verifier section" and "the check named above", meaning f3's own scorer. On this merged page the verifier section carries f2's checker instead, so those two sentences point at the wrong check. The prose is f3's and is rendered unedited; the mismatch is recorded here and routed to the lane.
    receipt
    path
    site/SITE_CORRECTIONS_2026-09-04.md
    anchor
    L58-L65
    sha256
    528184611493ef729eab03a8a974f3e81e5c3e142a719998b531ef87437acacf
    bytes
    9140
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/site/SITE_CORRECTIONS_2026-09-04.md | shasum -a 256
    open receipt

overclaim confessions · verbatim · 3 lanes

This site merges 3 lanes. Each lane's confession is below as that lane wrote it, with its own receipt and its own hash: check any one of them without reading the others.

lane f3sha256 11a1eb0d3e6593b38eb5da611ac5970d463c9a03e285b18f116b6e0a569109a0
# What this lane got wrong, and what stopped it Written 2026-09-04, the last step of this lane's work. Rendered on the site verbatim. Every claim below carries the path of the receipt that settles it. Nothing here was volunteered by a reviewer or found in review: each item was found by something running and failing. Where a number is given, it was measured this turn, not recalled. Read this before the theorems. If it is not the most useful page here, the rest is not worth much. --- ## 1. Nine claims that would have shipped, and the check that stopped each This is the part that matters, because in every case the wrong version was already written down. **A hero sentence citing a number its own receipt does not contain.** The first draft of the site package said the covert-bits ceiling was "corrected upward from 34.55", with `artifacts/covert_fbl_v98c.json` as its receipt. That artifact holds the corrected figure and not the retracted one; 34.55 lives in the dossiers. **Stopped by:** `scripts/site_package_check.py`, the rule that every load-bearing number in a claim must appear in that claim's own receipt. The claim was changed, not the check, and the retracted figure moved to a row whose receipt does hold it. **A theorem stated more generally than it was proved.** The register says a duplicate-eliminating receiver "must distinguish 3^w states". The Lean kernel checks `2^w ≤ s` for **every** width and the sharper `3^w` bound **only at width two**. The general case was stated and never machine-checked, and it would have gone onto the site as the hero. **Stopped by:** reading the elaborated statements in `artifacts/backends/lean_credit_audit.json` rather than the theorem names — which is precisely what this lane built that audit to do, and it caught this lane. `dataroom/STALE_CLAIMS.md` S29. **A headline that the Linux kernel refuses our compiled monitor.** It does not. Our loader applied none of the object's twelve relocations, so the kernel read through a literal zero we handed it. **Stopped by:** `llvm-readelf -r` on our own object, run because the result looked too good. We retracted it from a relocation table before anyone checked; another lane then measured the same object accepted at 182 instructions under a relocating loader. Our controls had proved the verifier was *reached* and never that the loader was *faithful*. `monitorgen/artifacts/kernel_load.json`, `NEGATIVE_RESULTS.md` §S06-6. **The acceptance figure is not ours to receipt:** `182` appears nowhere in this repository (`grep 182 monitorgen/artifacts/kernel_load.json` returns nothing). It was measured by another lane on its own hardware and recorded outside this tree. What this repository can regenerate is the rejection under its own loader — and a number whose receipt we do not hold is a number a reader should discount accordingly. **A defect reported against another repository that was not one.** Our scanner paired a producer with an artifact it merely *names* as a baseline witness and never opens. **Stopped by:** the target lane checking before acting on it. Two further notes against us: the reason we were given for the refutation was itself wrong (that script does carry the option it was said to lack), and we said so rather than accepting the tidier story. **Three flags out of five sent to other lanes as findings.** Two were real. Three were numeric co-occurrences between an option and a field sharing no name — 24 rows from 3 seeds is not a defect. **Stopped by:** hand-checking every flag against the producer's source before anything was addressed to anyone, and then a confidence tier that separates a name-matched pairing from a coincidence. **A public test-count badge derived from a broken collection.** The tool ran `pytest --collect-only` under an interpreter that cannot import the packages. pytest said `14 tests collected, 2 errors`; the regex took the 14 and returned it as authoritative, for a suite of 67. **Stopped by:** comparing the tool's output against the suites we had just run by hand. The badge said 849. It is **817**. **A self-test that destroyed the artifact it was testing.** The `--control` leg pointed the census at an absent directory, and the skip branch wrote its stub over the real result. **Stopped by:** `git status` showing a tracked artifact modified after a control run. This is the same defect this lane had fixed in a different file three steps earlier, reappearing inside the instrument meant to catch it. **Six `pyproject.toml` files broken by our own fix.** A regex insertion leaked a backslash escape and TOML stopped parsing on every interpreter. **Stopped by:** the Python 3.9/3.10 import control we had just written and run, within a minute of making the mistake. **A paper edit that would have shipped stale.** `oss/README.md` declares `paper/` a copy of `protocol-bench/paper/`; the edit went into the copy. **Stopped by:** a file-by-file blob comparison against the live repositories before pushing. A declared-copy guard now blocks staging while the two differ, and it was proved to fire by planting a drift. --- ## 2. Three filters we wrote that hide true things, with the cost as a number A filter that only removes noise is a filter nobody has measured. **The estate scanner's write-context rule costs 93 percent of its reach.** After the refutation above we required a producer to be shown *writing* an artifact before pairing with it. Precision went to 1 finding out of 1 verified. Recall collapsed. Across the nine repositories the scanner walks **14,386 JSON files** and now examines **11 producer–artifact pairs** — down from 168 under the broadest pairing and 59 under the version that was sealed before any foreign tree was read. A producer that writes through a helper function this cannot follow is invisible to it. Four of the nine repositories yield zero pairs — f2, f6, lattice and vllm — and that is a property of our scanner, not of those repositories. `artifacts/backends/scope_defaults_estate.json`. **Our own package checker verifies 5 percent of the numbers on the page.** It compares a number to its receipt only for decimals or integers of four digits or more, and only inside six named fields. The package contains **242 numeric literals**. **12** are compared against a receipt. **1** is exempted by name with a stated reason. **229 are never compared to anything.** The rule that makes the check meaningful is also what makes its coverage small, and a reader should assume any two- or three-digit number on the page is unchecked by machine. Measured with `scripts/site_package_check.py`'s own regex against `site-program/package.json`. **The MCP census refuses more than it counts.** To stop counting audit scripts that merely quote `@mcp.tool` in a comment, decorators must appear at the start of a line; to stop the scanner counting itself, its own file is excluded by path. Both rules are right and both discard true mentions. The census reports **10 servers, 0 declaring a hint**, and it reached that number only after **four** detector blind spots were caught by a leg that requires it to find every server already known to exist — the first version reported zero servers for three repositories that each ship one. `artifacts/backends/mcp_annotation_census.json`. --- ## 3. The numbers on that page we are least sure of, and what would settle each **The 3^w attribution floor.** We state it for every width and the kernel has it at width two. What would settle it: prove `attribution_floor_at_width_w` for general `w` in Lean, or withdraw the general form. Until then the site says what the kernel read. **5.673 dB per decade, and the 18.7858 / 26.4421 dB walls.** Exact inside a declared model — Rician K = 10 dB, no diversity, rate 1/2, CSIR, no CSIT — and that model is a choice. What would settle its relevance: a measured link at 28 GHz with a real front end, which this lane has never had. Nothing here is over the air. `artifacts/wall_vs_reliability.json`. **T\* = 0.17707 ms.** A Bessel correlation crossing against a chosen minimum usable correlation. The crossing is exact; the threshold is a modelling decision, and a different one moves the number. What would settle it: a paired over-the-air experiment at 28 GHz and 10 m/s. `artifacts/staleness_floor_v93.json`. **57 informative impossibility slots.** 62 are impossible and 5 of those sit on compositions with no modelled behaviour, so we quote 57. That split is our own judgement about which wins are vacuous. What would settle it: an independent reviewer re-deriving the degenerate set from the artifact. `artifacts/backends/impossibility.json`. **0.840000503469 as "84.0% of the feasible savings".** The artifact holds three variants — 0.8459, 0.8415 and this one — and we quote the complex-unconstrained figure. The number is not wrong; the choice of which of three to lead with is ours. `artifacts/rounds_converse_v54.json`. **"All nine public repositories have green CI."** True when measured on 2026-09-04 at the commits named. CI state is not a property of a commit alone; a dependency change turns it red without anyone touching the code. Assume it decays. **The 383,805-word distributed I/O floor.** A model composed with a published single-device theorem that is not ours, validated against brute-force minima at pinned configurations. It has never been compared against a measured interconnect. `artifacts/distributed_attention_floor_v101.json`. --- ## 4. What a buyer's engineer finds in the first hour that we did not put on the page **The file the page invites them to check is not there.** The verifier section names `oss/protocol-bench/examples/bfs_submission.json` as the sample certificate to drop in. It was created at the last step, committed to the private repository, and never pushed. Fetching it from the public repository returns **HTTP 404**. The invitation is addressed to a reader who cannot accept it. We found this in the last hour of the last step, added a check for it, and left that check **red** rather than quietly pushing the file — nothing was permitted to leave the repository in this step. One line on the next push list fixes it. `scripts/site_package_check.py`, the reachability leg. **The first command they type fails.** Clone `minicheck` and run `python3 -m pytest tests -q`, which is what anyone does: **9 errors during collection**. The suite needs an editable install first, the README's own test line says so, and the badge says 275 tests pass. Both are true and the first impression is a broken repository. **The version in the source is not the version on the index.** `pyproject.toml` says `0.4.1`; PyPI serves `0.4.0`. The README correctly says 0.4.0 — a test enforces it — but a reader who trusts the source tree will install something that does not exist. **Three checks in this repository are red and stay red.** The published Merkle closure root no longer equals what the live tree folds to; a claim-trust guard is orphaned; one gate's vocabulary contradicts four register rows. Each is disclosed, none is repaired, and repairing the first means re-pinning a certificate, which is not ours to do. **Most of the evidence does not survive a clone.** 15 of 17 radio runs are git-ignored. 589 tracked artifact-like files are named in no ranking document. The manifest pins 385 leaves; the repository holds far more than that. **The benchmark is small and one of the datasets is synthetic.** protocol-bench is 15 tasks, of which 2 are violations. specforge is generated, so its difficulty is a property of our generator. Neither is a corpus, and a system tuned on either will overfit within a week. **There is nothing to buy.** No customer, no revenue, no pilot, no third-party audit, no over-the-air measurement, no silicon. The two domains bought on 2026-09-04 are domains, not products. --- ## 5. The program that grades us made the same class of error, and that belongs here too An estate that publishes only its own errors is curating. These were made by the orchestrator of this program, and two of them touched this lane directly. A census of which of the estate's packages are on PyPI was answered **from thirteen recalled names instead of an enumeration of the trees**, and both halves of the answer were wrong. The true count, enumerated and probed: nine packages, eight predating this program — four of them this lane's, all published 2026-07-30 — and one published by it. That is the rule this program enforces on every lane, broken by the instrument that enforces it. A lane caught it. A concurrency fix was declared done and was not: making each write atomic does not make a read-modify-write atomic. Seven lanes' state records were silently erased and four turns died after running and being paid for. A lost update announces nothing, which is why it needed a control that reproduces it — 1 of 7 records survive under the old pattern, 7 of 7 under the new. Three smaller ones that reached this lane: a branch was asserted never to have been pushed when it was pushed on eight of nine lanes, and we read the remote ourselves and reported the contradiction; a ruling required `url: null` for artifacts under a nonexistent organisation, which cannot validate because the schema types that field as a string; and a stranger-verifier claim was validated from a developer's environment with the tools already on the path. --- ## 6. This file was checked twice, and the second pass changed it This estate's record is that one pass was never enough, so this program did not assume two were. The second pass re-read every sentence above against its receipt rather than against memory, and it found five things — two of them errors in the first draft of this very file. **It said two of the nine repositories yield zero pairs. It is four** (f2, f6, lattice, vllm), read back from `artifacts/backends/scope_defaults_estate.json`. The sentence understated the reach this lane's own filter gave up, in the section whose entire purpose is to state that cost. **It said "twelve sealed bars", and there are eleven files**, of which nine were sealed during this program and two predate it (`ls artifacts/prereg/`). That figure had been repeated across several of this lane's own step records before anyone counted the directory. A recall figure quoted from an earlier step was incomplete: the write-context filter was described as taking pairing from 168 to 11, which is true of the broadest pairing but omits that the **sealed** version examined 59, and both belong in the sentence. A "first hour" item asserting that bare `pytest` fails was written from expectation and then actually run against a fresh clone, which is where the exact figure of 9 collection errors comes from. And the reachability of the sample certificate had not been checked at all until the second pass asked how a stranger would obtain it — which is how the 404 above was found, at the last possible moment, in the deliverable of the previous step. Three of those five are counting errors in a document about counting errors. That is the honest rate, and it is why the number of passes is written down. The second pass is why this file names a defect in the step that produced the page it accompanies. --- ## 7. What is still not true Nothing of this lane's evidence is public. The repository is private and returns 404 to a stranger, so the register, the sealed bars and every correction above are visible to nobody outside. What is public is tooling and two small benchmarks. Four packages sit one patch version behind the code in this tree, because uploads are blocked and we will not publish a README quoting a version the index does not serve. Two floating action tags point at commits three and two behind, the older carrying a real path-resolution bug, and we did not move them because moving a published tag is a forced update. Both browser demos still vendor the old and new wheel at once. The strongest offline verifier this lane has — 49 conformance vectors, stdlib only, exit codes that distinguish refused from undetermined — is not published, and whether it should be is an open question rather than a claim. `artifacts/prereg/` holds **11** seal files, of which **9** were sealed during this program; the other two predate it. Each records only the git commit at sealing time. A stranger can verify that a seal has not been altered. Without an external time anchor they cannot verify that it preceded its run, and we have not anchored them.
receipt
path
f3/OVERCLAIM_CONFESSION_2026-09.md
sha256
11a1eb0d3e6593b38eb5da611ac5970d463c9a03e285b18f116b6e0a569109a0
bytes
16560
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f3/OVERCLAIM_CONFESSION_2026-09.md | shasum -a 256
open receipt
lane f4sha256 90e1914f5cc4d6c9f3c3b7b02b056c9db52d2f93a4ac060fbc6d64d1f68ce7e1
# Overclaim confession — lane f4 (wifi-pqc failure lab), site-program 2026-09 Written 2026-09-04, at the close of the lane. Every item is measured and carries the path that settles it. Nothing here is softened, and nothing is included because it is flattering: the estate's whole argument is that a stranger can check us, and this file is the part of that argument that costs something. Read it before anything we claim. --- ## I. The two things that were only found because a check was made to fail first **1. The guard I added to catch my own retracted number would have reported clean over it.** A number this lane published — "the claim checker refuted **3 of 8** material claims on the Kyber reference" — was wrong. The figures are **2 of 8** on that reference, 1 of 9 on its sibling and 0 of 7 on the formally verified implementation, and the fix was to add an entry to the repository's retraction guard so the wording could never come back. The rule of this program is to watch a new check fire before trusting it. It did not fire where it mattered. With the guard's global correcting-context list the entry **saw 7 occurrences and reported 2**, and the three it missed were the only three that were live: `tools/lane_register.py:404`, `lane_register.json:1112`, `LANE_REGISTER_2026-09.md:95`. The reason is worth stating exactly, because it generalises. The guard treats a retracted phrase as harmless when a *correcting marker* appears within 700 characters — that is how a retraction ledger can quote the thing it retracts. One of those markers is the word `REFUTED`. The register row that carried the defect is a claim-checker row, and its own tally reads `REPRODUCED 5, PARTIAL 4, REFUTED 1`. **The defect contained the word that means "this text is a correction", so the defect was read as its own correction.** This is the second time this exact hole has been found in that one file. Its docstring already records that `is measured` was removed from the marker list because the stale sentence it was meant to correct *began* "Binding is measured". A correcting-context rule is a hole generator. Entries may now carry their own markers, chosen so none can occur in that entry's defect, and both runs are kept: `out/s14_stale_globalcorr.txt` is the run that missed it, `out/s14_stale_perentry.txt` the run that caught it, and `tests/test_stale_retraction_kyber.py` plants both directions. **Had the order been "fix, then add the check", the check would have passed, the number would have been fixed in one place, and the guard would have reported a clean tree over the two copies still carrying it.** **2. Making a checker RUN the printed recipe found that the recipe did not run.** The content package prints a verification recipe for a stranger: `make clean && make check` inside the certificate bundle. The package's own check does not read that string, it executes it, from a fresh copy, negative controls first. It exited **2**: ``` cc -std=c99 -Wall -Wextra -Werror -pedantic -O2 src/farkas_check.c -o bin/farkas_check ./verify.sh make: ./verify.sh: Permission denied ``` The outbox builder wrote bytes and dropped the file mode. Three shipped executables — `verify.sh` and `pce` in the verifier bundle, `bin/pco` in the renamed proof-carrying optimiser — were written **100644 out of 100755 sources**. The bundles were byte-identical to the working originals, they passed every content check, they were on the approved push list, and the first command a stranger would run died on all three. The previous step had verified `verify.sh` and reported it green. It ran it **in the source tree**, where the executable bit was set — not in the bundle it had just built. **Content equality is not equality, and a verification of the wrong copy is not a verification.** Fixed at the builder; both re-verified from fresh copies (6 of 6 controls, acceptance count 1 of 6; `./bin/pco version` exits 0). --- ## II. Every place in this thread where a check stopped an overclaim, naming the check | # | what would have shipped | what stopped it | |---|---|---| | 1 | "3 of 8 material claims refuted on Kyber", in every dataset card and on the site | Rebuilding the claim-BOM card **from** `artifacts/claimbom/*.bom.json` instead of transcribing the sentence. The correct figures are 2 of 8, 1 of 9, 0 of 7. | | 2 | A retraction guard reporting a clean tree over three live copies of that number | The rule that a new check must be **watched failing** before it is trusted (section I.1) | | 3 | A certificate bundle whose first command dies with "Permission denied" | `tools/check_site_package.py` check 7, *the printed recipe was followed*, which runs the recipe rather than printing it (section I.2) | | 4 | The operator's home directory path, `/Users/<redacted>/...`, inside a public dataset of prover transcripts. **The account name is redacted here, and the redaction is itself part of the confession**: this file is rendered verbatim on a public page, and an estate does not publish the owner's home directory in order to prove that it once published the owner's home directory. What leaked was a machine path, and that is the whole fact — which account the laptop had adds nothing a reader needs and hands over something they should not have. | `oss/tools/check_surface.py` check 8, *no internal leaks* | | 5 | An internal client name in the open-source reconciliation report | `oss/tools/check_surface.py` check 8, *no internal leaks* | | 6 | Mechanism-private artifacts inside a published bundle | `oss/tools/check_surface.py` check 9, *no private paths, digests or names* — which refused this lane's **own** verifier bundle on its first run | | 7 | **This confession naming two private paths.** The first version of this file cited a patent-shape working note and a private specification by path, inside the file that gets published verbatim | `tools/check_site_package.py` check 4, *I8 by content* — which scans every string in the package whether or not it is flagged public | | 8 | **This confession restating "3 of 8"** with no correction adjacent to it — **twice, in both versions of this file**, the second time on the last build of the lane | `tools/check_site_package.py` check 8, *no retracted phrase restated* | | 9 | **The ledger entry describing the fix** restating "kyber 3 of 8" with no correction adjacent — the entry now reads 2 of 8 — found today, at the last gate run of the lane | `tools/check_stale_retractions.py`, on its own | | 10 | A package that does not validate, because a ruling said `url: null` and the schema types `url` as a string | Testing the ruling against the validator instead of implementing it. Absence is an absent key. | | 11 | "`pqc-sizes window` exits 0 on an empty window" | Re-measuring the exit code **without a pipe**. Through a pipe, `$?` is the pipe's. It exits 1. | | 12 | A mutation control that "passed" because the tool crashed with a traceback, exit 1, rather than because it detected the mutation | Printing the raw exit block before recording the verdict | | 13 | A payload-verifier boundary mislabelled, because the rule keyed on whether an exit code was *valid* rather than whether it was the *expected* one | The same raw-block discipline; it would have hidden the exact boundary the contribution exists to state | | 14 | Six of ten sealed predictions recorded as target failures when they were bugs in **my own tools** — a key read at the wrong depth, a prover flag never passed, float division where integer division was meant, a harness that failed to compile with exit 127 read as a refutation | The rule that a divergence is a finding about the instrument until proven otherwise | | 15 | A commit count published as a property of the work rather than as a fact about one minute | Rebuilding twice and watching the number move (85, then 87). This repository's own record, R22, says a push count is a moving fact and not a limit. | **Item 16 has no check in the right-hand column, and that is the point.** While writing section III of this file I measured the coverage of my own number-pinning check and found it exempted **49 of the 64 figures** in the package's graded sentences — including the `2` and the `8` of "2 of 8 material claims", the exact number this lane got wrong. A pin that skips the figure the whole retraction was about is not a pin. Nothing caught this. It was caught by the requirement to state a filter's recall cost **as a number**, which is a different instrument from a check, and a better one on this occasion. The exemption is now 23 tokens instead of 42, coverage is **59 of 64 figures**, and the tightening produced **zero** new failures — meaning every figure the wide set was hiding had been in its receipt all along, and the width bought nothing but a weaker check. **Item 17, same class.** The generator read one figure as `ip3.get("n_checks") or ... or 24`. The fallback never fired, and it was still the defect the generator exists to prevent: a typed number waiting for the day a key moves, which would then be silently wrong and would still pass the pin, because the number it invented would be the number it checked. It now raises instead. --- ## III. Every filter I wrote that suppressed signal along with noise, with the cost as a number | filter | why it exists | recall cost, measured | |---|---|---| | `GENERIC_BASENAMES` in the surface denylist | The literal-name leg fired on the words `SPEC.md` and `vectors.json` and refused this lane's own bundle | **2 of 11** private artifacts lose the literal-name leg (a private specification and its vector file, both generically named). They keep the path leg and the byte-digest leg, and a planted control proves the digest leg still refuses that specification's bytes under any filename. A published file that names it *in prose* is no longer caught. | | Per-entry correcting markers on the retraction entry | The global markers include the word inside the defect (section I.1) | This entry recognises **5** markers where the global list has **20**. A genuine correction phrased in any of the other 15 idioms will be reported as a live defect. I chose a false-positive risk over a false-negative one; that is a judgement, not a measurement. | | Splitting the file denylist for prose | Applying it whole would refuse the seal paths that the receipt rule *requires* beside every graded claim | **2 of 10** rules are not enforced on the package's text. Measured against the finished package, the excluded rules would have flagged **17** occurrences, all of one admission-engine name that the register's own limits carry and the envelope must publish unsoftened. The engine source is not published; the two file-name rules for it stay enforced. Both exclusions are printed inside the checker beside the reason. | | The number-pin exemption | Dates and standard identifiers are not measurements | Was **49 of 64** figures unchecked (23% pinned). Now **5 of 64** (92% pinned). See item 16 above. | | The `out/` carve-out in the retraction test | The guard reads its own transcripts of a defect as the defect | Of **69** live rows today, **4** are in source files and **65** are inside receipts of runs that *caught* something. The test asserts only that no source file restates the figure. The 65 are not asserted about at all. | | Withholding private filenames from copied register cells | A limitation may be published; the private artifact's name may not | **7** filenames withheld across **6** of 108 envelope rows. Every limitation is stated in full, only the filename is withheld, and the count is published inside the envelope itself rather than left to be noticed. | **The `out/` carve-out has a second cost that is mine.** The retraction guard's live count went from **13 to 69** in one step, because the previous step committed four transcripts of the guard's own runs into the tree the guard scans. Every future run inflates it further. That is the documented behaviour of this class (a guard's record of a defect read as the defect), amplified by my own decision to keep the receipts. Keeping them is right — the first wrong run's receipt is evidence — and the growth is a real defect in how this guard and its receipts coexist. It is recorded, not fixed, because fixing it means changing what the guard scans, and a check is not edited to make a number look better. --- ## IV. The numbers in the content package I am least sure of, and the exact experiment that settles each | number | why I doubt it | the experiment that settles it | |---|---|---| | The adaptive-cap gate's "19 of 19 breaks" | The committed artifact says 19 of 19; running it today says **18 of 19**, red on no-starvation. The harness's 15 bad cases all redden no-starvation alongside their own check, so the committed count may be a sum over co-reddening cases rather than 19 independent ones. | Run each of the 19 breaks **in isolation** and record which redden no-starvation on their own. If fewer than 19 do, the committed count was never 19 independent breaks and the register title is wrong, not merely stale. | | Self-attestation, 824 of 954 criteria | Regenerating gives 816 of 956, because 39 more artifacts exist than when it was committed. Both runs are honest; neither is stable. | Pin the artifact set by checking out a named commit into a clean tree, run the boundary tool twice, and publish the pair with that commit. A floor that moves with the tree is a floor for one tree. | | "2 of 8 material claims refuted" on the Kyber reference | It is corrected, but it is still **unsealed**: the run predates the seal discipline here, and the claim list is an input the instrument chose. The package says so in the row rather than dressing it up. | Freeze a claim list and a materiality rule in a sealed prediction **before** the target repository is read, then re-run. Until that exists this row is a demonstration, not an indictment. | | The envelope's provable margin, about 2^-16.5 | The hash-query budget and the pseudorandom-function assumption are **sealed inputs, not measurements**. The signature term is symbolic because no anchor for it exists in this tree. | Recompute with the buyer's own query budget through the tool's `--q-h-log2` flag, and add a core-SVP anchor for the signature scheme. Adding it can only make the envelope larger, never smaller. | | Every live-or-absent status in the artifacts section | A registry answer is a fact about one date. **This changed under me during this lane**: the networks domain was unregistered when I inventoried it and is registered now. | Re-run the surface instrument. It carries the timestamp of the run the package used, and every row states the date it was true on. | | The beacon on-air reduction, 13.55x | The on-air byte reduction is stable across runs; the CPU intervals beside it move with host load. | Quote the on-air figure only, from its own artifact. The CPU figures need a quiet host and a stated load, and this lane has neither. | | "24 of 24 interoperability checks pass" | The library versions are **recorded, not sealed**: on a host with different libraries the contract reproduces against *those* libraries and the version strings move. | Re-run on a second host with pinned upstream tarballs and compare the version fields, not just the pass count. | --- ## V. The errors this program's own orchestrator made, which belong in the estate's record and not only in mine These are not mine and I did not catch most of them. They are here because an honesty section that only confesses downward is an advertisement. 1. **A census answered from thirteen recalled names instead of an enumeration of the trees**, and reported as "zero publishes in this program" and "one package on the index". Both halves were wrong. The enumeration found **nine** of the estate's packages published, eight predating this program and one published by it. This is the "do the whole list, never a sample" rule, violated by the instrument that grades the lanes on that rule. A lane caught it. **My own instrument can corroborate only 2 of the 9 and is blind to the other 7**, because its list holds 45 named surfaces and the enumeration walked 94. A sample that agrees with a census is not a census, and mine is a sample. 2. **A concurrency fix declared done that was not.** Making each write atomic did not make a read-modify-write atomic. Seven lanes' state records were silently erased and four turns died after running and being paid for. A lost update announces nothing; that is what makes it the worst class. The control now reproduces it: 1 of 7 survive under the old pattern, 7 of 7 under the new. 3. **A ruling that could not validate.** Artifacts under an organisation that does not exist were to carry a null address; the schema types that field as a string, so the ruling made the package invalid. Two lanes measured it and omitted the key instead. The ruling was wrong and the lanes were right. 4. **Four smaller ones that touched this lane**: telling a lane its publish guard was fixed when it was not; asserting a branch had never been pushed when it was pushed on eight of nine lanes, which this lane disproved by reading its own remote; propagating this lane's "3 of 8" into 28 note files; and validating a stranger-verifier claim from a developer's environment with the tools already on the interpreter's path — which is the same defect as running a reproduce command that reads a file we wrote. --- ## VI. What a buyer's engineer finds in the first hour that we did not mention 1. **The repository is private, and nothing in this program is reachable.** The public surface is eleven repositories and two datasets frozen on 2026-08-18. Everything built since sits on an unpushed branch. 2. **Nothing is installable.** Four Python names and one JavaScript name are built, package-checked and **absent from both indexes**; a sixth name is a third party's. No page prints an install line for any of them, which is honest and also means there is no fast path to trying the work. The organisation the bundles were built for **still does not exist on either index today**, measured this afternoon, even though the domain was bought this morning. 3. **No third party has run any of it.** The externally-validated count is **zero**. The conformance kit, the remediation test vectors and the protocol certificates have been offered to no working group and executed by nobody outside this estate. Every "graded" claim here is graded by *our* instrument against *their* published text. 4. **One gate is red today and one check has a false positive nobody fixed.** The adaptive-cap gate fails 18 of 19. A surface check flags a quoted line in a diff that records a dead link being *removed*. Neither is hidden; the second is not fixed because fixing it means editing a check. 5. **Five of twelve research seals diverged.** Every one is written up as a negative result with the bar it missed, but a reader who counts before reading sees five failures, and should. 6. **A gate outside this lane's own set fails.** The kit's status-versus-receipts gate reports **5 contradictions and 13 unreceipted claims** against this register — identically before and after the last two steps, so it is nobody's regression, and it is also nobody's fix. It says some rows claim to have run while their own stored receipt says the command failed. 7. **The formal results are model-relative, everywhere, and say so.** A symbolic prover's RESIST is a statement about a model of a simplified protocol, not about deployed code. The machine-checked bounds are over modelled event lists. The impossibility results are over declared abstractions. An engineer looking for a claim about a specific access point's source code will not find one here. 8. **The raw evidence is private.** Thirteen packet captures, a 70-megabyte event stream and the mechanism-detail artifacts stay out. Only hashes, counts and semantics are published. That is deliberate, and it means several numbers on the page cannot be recomputed from what is published — only checked for internal consistency. 9. **The largest single claim on the page is the smallest one.** The hero is an inequality between two published constants: a signature is 3,309 bytes, a management frame carries 2,304. It needs none of the above to be true. Everything else does. --- ## VII. Two self-check passes The instruction was two passes minimum, on the grounds that this estate's record says one was never enough. It did not assume two are either, and neither do I: both passes found something, which is evidence that a third would too. **Pass one, against the requirements.** Checked this file against what it was asked to contain, item by item. It found section II item 16 — that the number-pinning check exempted 49 of 64 figures — which existed only because the instruction demanded a *number* for each filter's recall cost, and the number had never been computed. Tightened to 59 of 64, measured, zero new failures. **Pass two, against the tree.** Re-ran every gate and re-read every claim in this file against its receipt. It found four things. The generator's `or 24` fallback (item 17), now a hard failure. A statement in the previous version of this file that the networks domain was **unregistered**, which was true when written and is false now: the domain resolves today, the two organisations still do not, and I re-probed all three rather than trust either version. The claim "8 of 9 surface checks" needed the ninth named, not counted. And the retraction guard fired on the ledger entry describing the fix, which is item 9 in section II and was found by the gate run, not by me. **What a third pass would look for, since I am asserting two is not obviously enough.** Every number in this file that I copied from an earlier step rather than recomputing this turn; the 65 unasserted retraction rows inside receipts; and whether the checks I wrote this week have controls that would still fire if the thing they check were rewritten rather than deleted.
receipt
path
f4/OVERCLAIM_CONFESSION_2026-09.md
sha256
90e1914f5cc4d6c9f3c3b7b02b056c9db52d2f93a4ac060fbc6d64d1f68ce7e1
bytes
22204
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f4/OVERCLAIM_CONFESSION_2026-09.md | shasum -a 256
open receipt
lane f2sha256 8efd0c254c1de04ccb5919c70c73705840b650b5209f8278c757884238039657
# What this lane got wrong, and what it would have claimed if nobody had stopped it Written 2026-09-04, at the end of the program. Every item is drawn from `STALE_CLAIMS.md` §H-1…H-15, `NEGATIVE_RESULTS.md`, and this thread's own record, all of which are in this repository and predate this page. Nothing here is softened for the site. Every result we publish is either a measurement with a command that regenerates it, or it is nothing. That standard is only worth anything if it is applied hardest to the results that came out badly, so those are collected here rather than in a footnote. If something on our public surfaces contradicts this file, the file is right, and we want to know. --- ## 1. Predictions we sealed before running, and then lost We commit the bar before the measurement so a result cannot be reshaped afterwards. **Six of those bars have been missed.** A miss is published with the same receipt as a hit, and the bar is never moved. **Two of those six are missing from this page, and their absence is the most recent thing we got wrong.** Both were predictions we sealed about objects belonging to *other lanes*, run on our hardware. The results, and the receipts that evidence them, are those lanes' to publish — not ours. We had marked the work private in one place and then cited its receipt paths in four others: a negative result, an envelope receipt, and twice in this confession. A downstream consumer found that; our own checks passed it. So the two entries are gone rather than reworded, because the rule that governs everything else here governs them too: **a claim with no citable receipt does not appear on this page.** One of them was the single most useful thing in this document — a sealed prediction we lost outright, against our own interest — and losing it from the page is the correct price of having leaked its receipt. We are not going to describe a result while pointing at somebody else's evidence for it. **The four we can evidence, each with its miss named.** - **The inference floor on 24 real vendor-model guards** — six keys, one missed. The Farkas witness rejected 3 of 14 *sound* guards: strict-inequality guards equivalent to the safety property only over the integers, which rational Fourier-Motzkin cannot see. Sound but conservative, caught before we could describe it as a clean separation. `out/seal_verify_glm_inference_floor_2026-09.txt`. - **The browser verifier's first seal** — missed on the mutants key, because six of our own "corruptions" were `index_swap` on certificates whose two multipliers are equal, producing a byte-identical certificate. The verifier was right to accept them; our mutant generator was the defect. `out/seal_verify_browser_verifier_2026-09.txt`. - **Re-pinning the overlay to a newer upstream** — 7 of 8. The miss was our own bar reading `pins.pinned` where the pipeline records `pinned: true, checked: false`. Two earlier runs of the same seal reached no kernel at all, because a disk was full. `out/seal_verify_bpf_repin_2026-09.txt`. - **Two 2025 CVE fixes** — 13 of 14. Every prediction about the two guards held; the miss was `bar_both_fix_refs_verified_online`, an in-run web call that came back rate-limited. We had bundled a network receipt in with the proof keys. `out/seal_verify_cve_2025_guards_2026-09.txt`. --- ## 2. What we would have claimed if nothing had stopped us This is the section that matters. Each of these was a sentence we were ready to write. - **"A stranger can check our certificates in one file, offline."** The first build of that file **failed on its very first certificate**. Concatenating the modules strips their imports, which silently deleted the binding created by `import { fingerprint as specFingerprint }` — a name no file declares. The page would have refused every certificate handed to it. We found it only because we run the *shipped bundle* through the same vectors as the sources instead of assuming the build preserved behaviour. Had we shipped the artifact and tested the sources, the claim would have been false on the live page and true in our receipts. `scripts/build_stranger_verifier.py`. - **"And you can verify the page is what it says."** The footer tells a reader to hash the bytes between two markers and compare them to the manifest. That recipe was **off by one newline** and would have failed for anyone who followed it. It surfaced only when we changed `--check` to *follow* the recipe instead of printing it. A recipe that is printed and never followed is the same defect class as a reproduce command that reads a file we wrote. `oss/stranger-verifier/manifest.json`. - **"Our published surface is in sync, measured by hash."** Our own reconciliation tool queried the Hugging Face API without `?blobs=true`, which returns `size: null` for every file, so every comparison was `None != <int>`. The register said "local ahead in five"; **only two were real**. We found it because we read the push back and four files verified byte-identical while the tool still said they differed. `STALE_CLAIMS.md` §H-15. - **"Our content package cannot leak private material."** The first version of that gate let a planted `patent/` reference through in an envelope statement, because the check only scanned objects carrying an explicit `public: true` — and the envelope, hero, artifact one-liners and open questions carry no such flag. We found it by planting six defects and watching one survive. If we had planted five, we would have shipped a gate with a hole and called it a gate. `scripts/build_site_package.py`. - **"Our content package carries nothing that belongs to another lane."** We marked one row private and believed that settled it. The receipt paths on that row had already been copied into an envelope receipt, two negative results and two sentences of this confession, none of which carried a flag — so the private work's receipts were on the page four times over. Our own leak check passed it, because the check we wrote after the *last* version of this mistake still only looked at objects carrying a flag. We learned in September that a flag protects the object it sits on and nothing else, wrote that lesson down, and then did not finish applying it. A downstream consumer ran its own scan and found it. `scripts/build_site_package.py`. - **"562 tests, and the count is checked by one of them."** We doubted this number and set out to correct it, because it would not reproduce in our environment. It reproduced fine once the package was on the path: 562 collected, 561 passed, 1 skipped, and the self-checking test is real. **The number survived and our doubt was the error** — worth recording, because a confession that only ever confirms suspicion is not measuring anything either. --- ## 3. Filters we wrote that suppressed signal along with noise Every one of these is a deliberate choice that makes a check weaker than it sounds. - **The package gate's number allowlist.** It exempts the digits 0 through 8 — not 9, which is an accident of how the list was written rather than a decision — and a handful of small counts, from the requirement that every number in a public sentence appear in its receipt. That is most of the small numbers in ordinary prose, so the check is strong on figures like `182` or `65,536` and nearly silent on "three of five". An allowlist that grows is a gate going soft, and this one starts non-empty. - **The same gate exempts the confession itself** from the private-path scan, because it is rendered verbatim and it names the files it is confessing about — including this sentence. Its only check is byte-equality with this file. - **The mutant generator refuses to emit an identity mutant** and falls back to a value perturbation, flagging that it did. That fixed a real defect, but it means the six `index_swap` cases are never actually exercised as `index_swap` on those certificates; a different corruption is tested instead. - **The kernel-probe classifier decides ACCEPTED / REJECTED / LOAD-ERROR from marker strings** in the verifier's output. It got the cases we ran right, and the classes are declared before each run — but an unusual log is classified by pattern, not by understanding. - **Hub comparison is by file name and byte size**, because the Hugging Face API exposes no object id. A same-size edit to a published file would not be detected. - **The prose-versus-receipt gate scans headline, claim and title only.** Numbers in `status_note`, `limits` and `scope` — where most of our caveats live — are not bound to anything. - **Sixteen entries are waived out of the command/artifact gate**, each with a written reason and a gate-4 receipt. They are honest waivers and they still remove sixteen entries from an automatic check; the gate now reports INCONCLUSIVE at 79.3% coverage rather than passing, which is the correct outcome and not a pass. `reaudit_explained.json`. - **The regenerate-from-absence probe covers thirteen entries**, not the register. - **The new private-set check is a string scan over the package, and only over the package.** It reads every string in the document — receipts, prose, the confession, and rows flagged non-public — with no exemptions, which is what the previous version lacked. It does not open the files those strings point at. A public receipt whose *contents* name a private path would not be caught by it, and we know of at least one such file in this repository: our own negative-results record, which describes the removed entries in full. That record is not published as a page; it is a repository file. We are stating the gap rather than implying the check is total. --- ## 4. The numbers in our content package we are least sure of - **"55 of 55 vectors."** Three of those vectors are other projects' certificates that live *outside this repository*, in the orchestrator's directory. **On a stranger's clone the same command reports 52 of 52, and the foreign-refusal count is 0 of 0** — measured, not inferred. The sealed key `bar_three_foreign_certificates_all_refused` would read false for anyone but us. The REFUSE verdict is our hero sentence, and its strongest evidence is the part a stranger cannot reproduce. *What would settle it:* vendor three foreign certificates into the repository with their provenance, or have the lanes that own them publish them so the vectors can be fetched. - **`implementation: exists_wasm`.** The verifier contains **no WebAssembly at all** — it is plain JavaScript. The schema's enum had no value for that, and the program decided plain JS qualifies. A reader who takes the field literally will be wrong, and we would rather say so than let the field carry it. *What would settle it:* a value that means "runs in a browser with no runtime download". - **"Detection 1.0, valid-acceptance 1.0."** Over our own corpus, built from our own vectors. Both degenerate strategies score zero on the same rule, which is the property that makes the number mean anything — but it is our corpus grading our verifier. *What would settle it:* the estate's shared conformance corpus, which now finally can register our certificate kind. We have a sealed, untested prediction that we will score **0.00** on it before that registration takes effect, for the same reason two other lanes' verifiers scored zero: not speaking the format. That seal is armed and we did not score it in this turn. - **"Thirteen of fourteen."** The fourteenth was a rate-limited web call, not a proof. We say so in the sentence, and it still flatters us: a bar we designed included a key that could fail for reasons that have nothing to do with whether we were right. - **"Eleven artifacts, eleven in sync."** Eight are compared exactly, by git blob hash. Three are compared by name and byte size only. --- ## 5. What a buyer's engineer finds in the first hour that we did not mention We went looking for these deliberately. All were measured today. - **`git clone` pulls about 2.06 GiB** and the working tree is roughly 15 GB. Nothing in our register or package prepares anyone for that. - **`pip install certkit` fails.** So does every one of our five package names: none is on PyPI, and `certkit`, `exploit-counter` and `crs-mcp` all return 404. Our READMEs use the `git+https` install form, so they are honest — but the obvious command a reader types does not work, and the reason is that trusted publishing is not configured. - **We have never opened our own verifier page in a browser.** The corpus test runs the bundle under Node. `oss/stranger-verifier/verifier.html` has no rendering test at all; the drag-and-drop wiring, the file input and the verdict rendering have never executed anywhere. The hero sentence of this site is about a page whose page-ness is untested. - **A rendering check that exists did not run.** `oss/portfolio/check_spaces.py` needs a Playwright browser that is not installed here, so it did not execute. It is recorded as **not run**, not as a pass. An unrun check is not a green one, and the two hosted demo pages are unverified by us today. - **`make verify-all` — this repository's own "the ONE command before any push" — was never run in this program.** Not once across every turn. We ran a large set of narrower gates instead and reported those; we did not run the one the Makefile calls the single source of truth. - **Two entries carry non-clean run verdicts** in the receipts file: one `TIMEOUT` and one `EXIT0_NO_TOUCH`, the latter being a producer that exits successfully without touching its artifact — the exact defect class this estate names as its signature failure, still present in our own register. - **Two commit messages in `git log` read `/bin/zsh spent`**, where `$0 spent` was meant. A shell expansion in the message itself. We do not rewrite history to tidy an embarrassment, so they stand. - **Some committed artifacts contain absolute home-directory paths** from the machine that generated them. None is on a public surface — the publish preflight scans for exactly that and reports clear — but they are visible to anyone reading the JSON. --- ## 6. Claims that were wrong on our own public surfaces, and how long they survived - **A live public page said it made no network requests while fetching a runtime from a CDN at load.** The certkit demo Space executes Python under Pyodide, downloaded from `cdn.jsdelivr.net` when the page opens. Its old wording — "nothing is installed at page load" — was true of *packages* and read as a claim about the page. It is corrected, and it now also says it is not the verifier our seal covers. - **An MCP server declared zero capability hints.** Five tools, no `readOnlyHint`, no `openWorldHint`, nothing for a client deciding whether to prompt a user. Ten server modules across eight lanes had the same gap; ours is fixed, and the closed-world claim is now checked against every import rather than against its own prose. - **We called our own benchmark third-party graded.** Every row of the soundness leaderboard, including the "exhaustive" oracle, is a baseline we wrote scored against ground truth we computed. Both the README and the public Space now say so. - **A stale headline outlived its own correction in four places** — a privacy figure corrected in the claim and the measurements while the headline kept the old value, rendering in three documents and expected at the old value by a test binding. The audit target was red on the default branch and nothing reported it. - **Twenty-one entries said "not re-run this pass" beside their own receipt saying they had run.** - **No pre-registered bar in this repository was committed before its result** until 2026-09-02. The three that existed were added in the same commit as the artifact they graded, and one seal file disclaimed itself in its own text. Every "graded against a prior bar" label we carry dates from after that finding. - **A register we generated mislabelled 36 rows**, reading axis and site from a file that never carries them, so every row printed the same default regardless of what it was. - **A commit message claimed a seal was verified before its receipt had been read**; the receipt showed two keys violated for that run. History is not rewritten; the receipt is authoritative. - **Four claims were narrowed to what the code does**: a "proposer is an untrusted model" that was synthesised presets; a "no human in the loop" resting on a replayed transcript; a linter described in one entry while a different tool's artifact was cited; a "verifier imports nothing from this repository" that imports our own published package. --- ## 7. An incident on a public surface On 2026-08-01 a publish script was invoked as `publish_oss.sh --dry-run` in the belief that it supported that flag. It did not: the argument was the commit message. **Two public repositories carry commits whose message is the literal string `--dry-run`.** They are still there. The script now implements a real dry run and refuses a flag-shaped commit message. ## 8. On intellectual property This program never classified any of it. Every row of our content package carries `ip_class: UNKNOWN` and the IP ledger is empty by design, to be filled at the site phase from the owner's own attestation. No number in it is taken from this tree. We mention it only so that an empty section is not read as an omission. --- ## What we would say to someone auditing this Read `NEGATIVE_RESULTS.md` and `STALE_CLAIMS.md` rather than this summary of them. Every number elsewhere on this site carries the path of the file that produced it; run the command yourself. If a receipt does not resolve, that is a defect and it is ours.
receipt
path
f2/OVERCLAIM_CONFESSION_2026-09.md
sha256
8efd0c254c1de04ccb5919c70c73705840b650b5209f8278c757884238039657
bytes
17944
visibility
public

The file is served from this site. Run this and compare it with the hash above:

curl -sS https://orbitalproof.com/receipts/f2/OVERCLAIM_CONFESSION_2026-09.md | shasum -a 256
open receipt

negative results · killed at their own preregistered bar · 18

  • A seventh third-party MCP server was predicted to contradict its own declared hints, the prediction was sealed, and the candidate was NOT RUN because its kill criterion fired on the second clause: the sandbox seeds text files only and cannot build the git repository the server needs. The seal predates any observation, so the prediction survives intact for whenever a seed hook lands.
    receipt
    path
    f3/NEGATIVE_RESULTS.md
    sha256
    6b19a644c2b10e8e8070f9af5f90ca609f5c902f20d2b6600012f999cd9f33ae
    bytes
    16360
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  • The kernel-verifier candidate's sealed FAIL branch was published, and then the finding itself was withdrawn: the rejection was an artefact of our own non-relocating loader, and another lane's relocating loader had the same kernel accept the object.
    receipt
    path
    f3/NEGATIVE_RESULTS.md
    sha256
    6b19a644c2b10e8e8070f9af5f90ca609f5c902f20d2b6600012f999cd9f33ae
    bytes
    16360
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  • The capability observation over the estate's own MCP servers was not run, and the reason is the result: not one of the ten declares a hint, so a clean artifact would have established nothing.
    receipt
    path
    f3/NEGATIVE_RESULTS.md
    sha256
    6b19a644c2b10e8e8070f9af5f90ca609f5c902f20d2b6600012f999cd9f33ae
    bytes
    16360
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
Show the remaining 15 of 18 killed candidates
  • The estate scanner's sealed prediction that one named case would not be flagged held, but for a different reason than sealed, and that is published rather than smoothed: the producer joins a module constant, which the sealed pairing cannot anchor.
    receipt
    path
    f3/NEGATIVE_RESULTS.md
    sha256
    6b19a644c2b10e8e8070f9af5f90ca609f5c902f20d2b6600012f999cd9f33ae
    bytes
    16360
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  • Four of twelve breakthrough candidates were never reached inside the budget and are recorded with what each would have cost, rather than described as future work.
    receipt
    path
    f3/NEGATIVE_RESULTS.md
    sha256
    6b19a644c2b10e8e8070f9af5f90ca609f5c902f20d2b6600012f999cd9f33ae
    bytes
    16360
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  • A gate that was asked to pass on a second sidecar does not pass, because that sidecar carries no cross-references and the gate's anti-vacuity refusal correctly fires. Making it pass would have meant weakening the refusal.
    receipt
    path
    f3/NEGATIVE_RESULTS.md
    sha256
    6b19a644c2b10e8e8070f9af5f90ca609f5c902f20d2b6600012f999cd9f33ae
    bytes
    16360
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f3/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  • NR-1 — Tail latency of legitimate clients per admission arm (row 3). The bar, sealed before the run: `accept_all_p95_under_threshold_at_every_load` = `false`. Measured: `true`. The header's own 25,000 µs legitimate-p95 bar does not separate the arms: all five (accept_all, class_fair_share, constitution, station_quota, token_bucket) keep legitimate p95 under it at every one of the 14 loads. The constitution arm's worst p95 is 485 µs against accept_all's 7,303 µs (15×), but the *sealed* claim, that accept-all misses the bar, is false on this dataset. The eight RECORDED keys (row counts, arm/load/seed counts, threshold, constitution verdict) all matched. Result artifacts: artifacts/native/ap_resource_tail_latency_ci.json, artifacts/native/research_seals_ci.json.
    receipt
    path
    f4/conformance/predictions/ap_resource_tail_latency.json
    sha256
    3bd7239172939b20d449a6d24ff196c4c713c907394480d90d0f28d39df51426
    bytes
    1803
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/ap_resource_tail_latency.json | shasum -a 256
    open receipt
  • NR-2 — Rank 9's DoS residency law decided in the 4 KiB-page VM (row 4). The bar, sealed before the run: `naive_slope` = `1.0 ± 0.02`. Measured: `0.9546` (95% CI [0.9402, 0.9690]). On the 4 KiB host every one of the 8 gates decides (no abstention, as sealed) and the bounded arm is flat with a slope CI of exactly [0, 0], as sealed; but the naive arm grows at 0.955 resident bytes per attacker byte with a −48.5 MB intercept, not 1.000 as on darwin. The tool's own gates `naive_slope_is_one`, `headline_corroborated` and `reduction_law_linear` FAIL: the bounded arm's ΔRSS is 0 KiB at all 15 flood sizes, so the "reduction" has no denominator (printed 41,469,269×), and the darwin 8,194× is shown to be flood ÷ 16 KiB page (134,217,728 / 16,384 = 8,192). Result artifacts: artifacts/native/dos_memory_ci_linux4k.json, out/dos_measure_linux4k_s06_2026-09.log, artifacts/native/research_seals_ci.json.
    receipt
    path
    f4/conformance/predictions/dos_law_linux4k.json
    sha256
    6d63c5423f0dc013af6aca95069d1afc417d122f26e09732b159ec04349a5c32
    bytes
    1550
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/dos_law_linux4k.json | shasum -a 256
    open receipt
  • NR-3 — Cross-protocol budgets restored (queue row 16). The bar, sealed before the run: `n_protocols`, `n_budgets_without_protocol` = `19`, `3`. Measured: `22`, `0`. The seal miscounted the genus: the generator adds three protocols (eaptls, radsec, pqxdh) to the library's twenty through `_extra_protocols`, which I read as orphaned budgets. The repair itself works as sealed on its other keys: rdma_rocev2 gets 1024 B (IBTA), cxl gets 42 B (DSP0274 MinDataTransferSize), uec is excluded with its reason, and the generator no longer crashes (H25). But the generator's own gate `naive_breaks_every_protocol` FAILS on the new member rdma_rocev2 (`naive_break_canon` and `naive_break_spec` both false at 1024 B), so the regenerated artifact is RESULT: FAIL by the tool's own standard and does not replace the committed 20-protocol artifact. Result artifacts: out/cross_protocol_amplification_s06c_2026-09.json, out/crossproto_regen_s06c_2026-09.log, artifacts/native/prereg_ci.json.
    receipt
    path
    f4/conformance/predictions/crossproto_budgets_restored.json
    sha256
    71d6913b671477fefdc8ce7462d3e1158ac2370264fc882a6f43eb47df99c08d
    bytes
    1773
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/crossproto_budgets_restored.json | shasum -a 256
    open receipt
  • NR-4 — Stock-AP swap: hostapd 2.11 in the same hwsim harness (queue row 13). The bar, sealed before the run: `status`, `all_checks_true` = `PASS`, `true`. Measured: `FAIL`, 4 of 8 false. The sealed recipe ("built from the w1.fi hostap_2_11 tag with the stock defconfig") produces a hostapd without SAE: the AP refused its own configuration (`Line 7: invalid key_mgmt 'SAE'`, `unknown configuration item 'sae_password'`, `Failed to initialize interface`) and no station could associate, so the four accept-side and reject-pcap checks are false. The distro's 2.10 build has `CONFIG_SAE` compiled in; the stock `defconfig` does not. Nothing here is a finding about hostapd 2.11's RADIUS or ACL behaviour, which was never reached. Result artifacts: out/ap_resource_hwsim_ci_hostapd_2_11_FAIL_s06c_2026-09.json, out/hostapd_2_11_accept_hostapd_s06c_2026-09.log, out/hwsim_hostapd_2_11_s06c_2026-09.log.
    receipt
    path
    f4/conformance/predictions/hostapd_2_11_swap.json
    sha256
    db4308e906aa29a01a9af4eff73b1311cabc43a91f8799f4833618a53d61921e
    bytes
    1685
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/hostapd_2_11_swap.json | shasum -a 256
    open receipt
  • NR-5 — FreeRADIUS + oqs-provider rebuilt on a persistent path (queue row 17). The bar, sealed before the run: `downgrade_rejected`, `radius_eaptls_accept`, `ok` = `true`, `true`, `true`. Measured: `false`, `false`, `false`. The provider now builds and lives on a persistent path (`/home/<redacted>/eap_pqc/oqs-provider/_build/lib/oqsprovider.so` — account name redacted, because this row is served verbatim and what matters is that the provider is on a persistent path rather than in a temporary directory, not whose account the CI runner used, `oqs_provider_path_persistent` true) and the standalone PQC TLS 1.3 handshake passes (`tls_pqc_handshake` true, X25519MLKEM768 / mldsa65), but FreeRADIUS's OpenSSL loads providers from the system module directory, where `/usr/lib/aarch64-linux-gnu/ossl-modules/oqsprovider.so` still points at the July run's `/tmp` path (`dlfcn_load: could not load the shared library`, `provider_init ... name=oqsprovider`, `cert chain FAILED`), so the EAP-TLS leg never reached Access-Accept and the downgrade leg could not be exercised. The committed artifact is restored; the run's artifact and log are under `out/`. Result artifacts: out/eap_freeradius_ci_persistent_FAIL_s06c_2026-09.json, out/eap_freeradius_run_s06c_2026-09.log, out/eap_freeradius_persistent_s06c_2026-09.log, artifacts/native/research_seals_ci.json.
    receipt
    path
    f4/conformance/predictions/eap_freeradius_persistent.json
    sha256
    9665edcf657b5331aa8fa1c624c9eb6c7beb5a1e805a15b5ffe8497cfd664af8
    bytes
    1625
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f4/conformance/predictions/eap_freeradius_persistent.json | shasum -a 256
    open receipt
  • The inference floor's first seal was violated because the witness refused sound guards that are true only over the integers — the instrument's documented conservativeness, caught by a bar we wrote before seeing the result.
    receipt
    path
    f2/out/seal_verify_glm_inference_floor_2026-09.txt
    sha256
    2a8d62dc14a39f56e278fcefc73d14cbe9f7d83338627d94b5247a927fdf3e7c
    bytes
    517
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_glm_inference_floor_2026-09.txt | shasum -a 256
    open receipt
  • The browser verifier's first seal was violated by our own mutant generator, which emitted corruptions that were byte-identical to the original certificate. The verifier was right to accept them.
    receipt
    path
    f2/out/seal_verify_browser_verifier_2026-09.txt
    sha256
    dc20e0b81555ee2c7e01421f7887d063d4d5c690bb3fdd2b049f795dc3d58606
    bytes
    530
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_browser_verifier_2026-09.txt | shasum -a 256
    open receipt
  • Re-pinning the overlay to a newer upstream missed one sealed key because our bar read the wrong field of the pins block; two earlier runs reached no kernel at all because a disk was full.
    receipt
    path
    f2/out/seal_verify_bpf_repin_2026-09.txt
    sha256
    bf389e445dd1ae67d5dc429558f8ac20a7fa7d1b3792424bd7ba3e52ac09db0e
    bytes
    657
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_bpf_repin_2026-09.txt | shasum -a 256
    open receipt
  • The 2025 CVE work missed one sealed key: an in-run web call to confirm a fix reference came back rate-limited. We had bundled a network receipt in with the proof keys.
    receipt
    path
    f2/out/seal_verify_cve_2025_guards_2026-09.txt
    sha256
    1ea397746f0a3d6065af7eaa34d1f54fb8e5077e0067019ef92c825b81324df6
    bytes
    1182
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/out/seal_verify_cve_2025_guards_2026-09.txt | shasum -a 256
    open receipt
  • A paid measurement has never run: the provider returns insufficient balance. Recorded as not run, with the money unspent and the seal armed.
    receipt
    path
    f2/NEGATIVE_RESULTS.md
    sha256
    e1b89f42dc09bb0da5694c6c584db8d6e173e00b40e7f089ccb8cdf5254ebd28
    bytes
    14757
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/NEGATIVE_RESULTS.md | shasum -a 256
    open receipt
  • The negative controls for the multiview result behaved as a control should: uncorrelated views make the coding result worse than the baseline, and disabling the disparity search collapses it.
    receipt
    path
    f2/artifacts/multiview-syntax/negative_control.json
    sha256
    4567ee94d4c95eca5b53099d374eb7824471c6fb1c3a31d2d01bfdbdda3294c8
    bytes
    5256
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/artifacts/multiview-syntax/negative_control.json | shasum -a 256
    open receipt
  • Two further results belong on this list and are not on it. Both were sealed predictions this lane lost on objects owned by other lanes, and their receipts are those lanes' to publish, not ours to cite. Rather than describe a loss we cannot evidence here, we record that the entries were removed and why. The rule that removed them is the same one that governs everything else on this page: a claim without a citable receipt does not appear.
    receipt
    path
    f2/OVERCLAIM_CONFESSION_2026-09.md
    sha256
    8efd0c254c1de04ccb5919c70c73705840b650b5209f8278c757884238039657
    bytes
    17944
    visibility
    public

    The file is served from this site. Run this and compare it with the hash above:

    curl -sS https://orbitalproof.com/receipts/f2/OVERCLAIM_CONFESSION_2026-09.md | shasum -a 256
    open receipt

open questions · 20

Questions, not claims; they carry no receipt.

  • [f3] Whether the seventeen-days-red confession may open the page above the pre-registered indictment. The ruling is that it may not, and it sits immediately below the hero instead; the lane would have put it first.
  • [f3] Whether to publish the PCAR/1 offline verifier with its 49 conformance vectors. It is stdlib-only, exits 0/1/2/3, and refuses a planted tamper; it is stronger than the check this page names and it is not public.
  • [f3] Whether to upload the four built and twine-clean patch releases, which would let the browser demos drop their older vendored wheels and let four READMEs quote the version they were written for.
  • [f3] Whether to re-point the two floating action tags, which today hand a reader a commit three behind carrying a real bug, against a rule that forbids moving a published tag.
Show the remaining 16 of 20 open questions
  • [f3] Whether to anchor the twelve sealed bars to an external time source, without which a stranger can verify only that a seal is unaltered, not that it preceded its run.
  • [f3] Whether the owner re-pins the closure certificate so its schema string stops saying universal, a word an independent check showed is earned by none of the three closure certificates in this estate.
  • [f3] Whether a prediction this lane sealed about another lane's compiled object, and which was graded correct on both halves, may be cited here when the grading record lives outside this repository.
  • [f3] Who else writes to this repository's remote: two branches appeared during the last step that this lane did not push.
  • [f4] The confession rendered here is the provisional first version written in S14; S15 revises it after two self-check passes and the package is regenerated. Render the S15 version.
  • [f4] The verifier is C99 only, so `implementation` reads `needs_port`. A WebAssembly port of the 234-line checker is roughly one turn of work; the site thread decides whether it wants one or embeds the browser verifier another lane owns.
  • [f4] The certificate envelope is f8's, not this lane's. This lane owns the payload kind the envelope carries for linear bounds. Any page sentence must point at f8 for the envelope and must not describe it as ours.
  • [f4] The envelope section may be truncated for length by the site thread. It may not be rephrased: every statement is a cell copied from the retraction ledger or the register, and paraphrase is how the estate has previously lost the qualification while keeping the claim.
  • [f4] The schema types `url` as a string, so an absent URL is an absent key: `url: null` is rejected by the validator. Every surface that is not live today therefore carries no `url` field at all.
  • [f4] The organisation this lane's unpublished packages were built for does not exist on either index, and the domain is unregistered. No name and no URL for it appears anywhere in this package; the site thread binds names later.
  • [f4] The opening result's discovery predates its seal and the row says so. If the site thread wants an opener that is blind end to end, the two sealed claim-checker targets are the alternative, at the cost of a weaker sentence.
  • [f2] Four rows in this lane's register carry a HoldCo site (the trusted-bit floor, the inference floor, the forced-gates result and the adversarial-impossibility zone). By the rule that a shared method belongs to HoldCo and a domain result to the subsidiary, they are HoldCo's; they appear here as theorems because they are this lane's receipts. The site thread decides where they render, and the answer must be the same in both packages.
  • [f2] The stranger verifier's repository does not exist, so no URL is claimed for it. When the HoldCo organisation is created, the artifact row and this site's verifier section both need that URL, and the index page's link checker must pass before either is added.
  • [f2] Every receipt path here is a path in this repository at commit 9f24e9e3 on branch site-program/2026-09, which has an open pull request and is not yet merged. The site should bind to a commit, not to a branch name.
  • [f2] This package names two other lanes' objects only as work this lane's instrument was used on, marked not public. If the site wants to tell that story it has to come from those lanes, not from here.
  • [f2] The IP ledger is empty by design: it is emitted at the site phase from an owner-supplied attestation, and no number is scraped from this tree.