{
  "checks": [
    {
      "detail": "`tools/claimbom/checker.py` over the published BOM: **VERIFIED**. The checker re-derives every derived field from the raw ones and re-applies every verdict rule; it agrees with all 12 published verdicts",
      "name": "bom-verifies-under-the-trusted-checker",
      "status": "PASS"
    },
    {
      "detail": "the committed capture, replayed through the same connector parsers, rebuilds the published BOM. The ONLY field permitted to differ is `mode` ('live' published, 'replayed-from-capture' on replay), because the published artifact is the live run's own output and this rebuild is not. Every other byte matches",
      "name": "replaying-the-capture-rebuilds-the-published-bom",
      "status": "PASS"
    },
    {
      "detail": "the DoD names GitHub, cloud logs, datasets, notebooks, CI, registries, patents and regulatory docs. All eight ran against the target and each carries provenance (url + response digest): `github`=OK(n=6), `cloud_logs`=OK(n=5), `datasets`=EMPTY_UPSTREAM(n=3), `notebooks`=NOT_APPLICABLE(n=100), `ci`=EMPTY_UPSTREAM(n=4), `registries`=OK(n=12), `patents`=OK(n=3), `regulatory_docs`=OK(n=2)",
      "name": "the-dod-names-eight-connectors-and-eight-ran",
      "status": "PASS"
    },
    {
      "detail": "every connector that reports a positive, empty or not-applicable result publishes how much it examined, and none of them examined nothing (github:6, cloud_logs:5, datasets:3, notebooks:100, ci:4, registries:12, patents:3, regulatory_docs:2). THE DISTINCTION IS THE POINT: `datasets` is EMPTY_UPSTREAM over 3 answered queries and `notebooks` is NOT_APPLICABLE over 100 files walked -- neither is 'nothing found' and neither is 'did not run'",
      "name": "no-connector-reports-a-finding-having-counted-nothing",
      "status": "PASS"
    },
    {
      "detail": "8 material claims, 0 without a recorded attempt. The attempt log holds 10 runs and every one carries an exit code read from the process -- none missing. The exit codes themselves: `A1_documented_make`=2, `A2_deviated_make`=2, `A2_make_clean`=0, `A3_test_kyber768`=0, `A4_test_vectors768_run_a`=0, `A4_test_vectors768_run_b`=0, `A5_compile_counterfactual`=0, `A5_compile_shipped`=0, `clone.checkout`=0, `clone.clone`=0",
      "name": "every-material-claim-has-an-independent-reproduction-attempt",
      "status": "PASS"
    },
    {
      "detail": "of 8 material claims: **2 REFUTED** (C2-round-3-identification, C5-build-procedure), **2 UNSUPPORTED** (C3-build-status-badge, C4-coverage-badge), 4 borne out (C1-official-reference-implementation, C6-selftest-contract, C7-deterministic-vectors, C8-maintenance-disclosure). A diligence run in which everything reproduced would be evidence about the run and not about the target; so would one in which nothing did. BOTH DIRECTIONS ARE REQUIRED HERE",
      "name": "the-answer-is-not-yes",
      "status": "PASS"
    },
    {
      "detail": "NIST's own published ML-KEM-768 keyGen vectors, run through the TARGET's own `crypto_kem_keypair_derand`: **5/5** encapsulation and decapsulation keys reproduce byte-for-byte. THE OTHER SIDE IS WHAT MAKES IT A MEASUREMENT: the same comparison against a copy of the target's source with FIPS 203's `d || k` domain separation reverted to the round-3 formula -- ONE LINE, nothing else touched -- matches **0/5**. Without the counterfactual, 5/5 would be a coincidence nobody had ruled out",
      "name": "the-identification-finding-is-two-sided",
      "status": "PASS"
    },
    {
      "detail": "the target's key and ciphertext sizes are {'ct': 1088, 'pk': 1184, 'sk': 2400, 'ss': 32}, and NIST's ML-KEM-768 vectors carry ek=1184, dk=2400 -- IDENTICAL. Round-3 Kyber and ML-KEM have the same object sizes, so the size table a buyer would check passes for both and establishes nothing. The README's ML-KEM mentions are 3 in number and False of them identify THIS code: every one recommends a different project. THAT is why the verdict is REFUTED and why it took running the standard's vectors to get it",
      "name": "object-sizes-cannot-tell-the-two-apart",
      "status": "PASS"
    },
    {
      "detail": "the patent row is **UNVERIFIABLE**, never 'no patents found'. 2 of 3 endpoints are blind: `patentsview-legacy` HTTP 200 -> WRONG_PAYLOAD; `uspto-open-data` HTTP 401 -> UNAUTHORIZED; `google-patents-xhr` HTTP 200 -> OK. A diligence report that renders a credential wall as a clean freedom-to-operate answer is worse than one that omits the question",
      "name": "absence-of-evidence-is-recorded-as-unverifiable",
      "status": "PASS"
    },
    {
      "detail": "`api.patentsview.org` answers a patent query with HTTP **200** and a body of content-type 'text/html' where its documentation promises JSON. It is classified WRONG_PAYLOAD, which is one of the three BLIND statuses and can never become OK. A connector that read the status code alone would have recorded a successful patent search returning zero patents -- the exact shape of a search that examined nothing publishing the number of one that examined everything",
      "name": "two-hundred-is-not-success",
      "status": "PASS"
    },
    {
      "detail": "both README badges are pinned to `?branch=master`, and `git ls-remote --heads` reports ['cm4', 'deterministic_api', 'highfailure', 'main', 'mkem-bench', 'round2', 'round3', 'standard'] -- no `master`. The coverage badge still renders **93%** from a record calculated at 2021-02-09T11:57:38Z, **2001 days** before this run. Asking the same API about `main` returns HTTP 200 carrying `\"branch\":\"master\"` -- THE SAME STALE ROW. The connector records what it asked for and what came back, and they disagree; the badge for the branch that does exist reads 'unknown'",
      "name": "an-answer-about-another-branch-is-not-an-answer",
      "status": "PASS"
    },
    {
      "detail": "the guard is RUN, not asserted. Fed two runs of zero bytes it reports `digests_equal=True` -- they agree on `e3b0c44298fc1c14...`, the digest of nothing -- and `deterministic=False`, verdict UNSUPPORTED. THIS IS NOT HYPOTHETICAL: it is what this item's own reconnaissance produced when the binary had not been built and `cmp` called two empty files identical. The real C7 measurement has both runs non-empty and byte-identical over 10000 vector sets",
      "name": "two-empty-outputs-do-not-prove-determinism",
      "status": "PASS"
    },
    {
      "detail": "**30/30** forged BOMs refused, each naming the checker rule it was built to violate, and 3/3 honest BOMs still VERIFY -- a checker that refuses everything is not a checker. The forgeries that matter: a REFUTED build procedure relabelled REPRODUCED with every measurement left in place; a blind patent connector published as `no third-party patent reads on the algorithm`; a search with n_examined zeroed still reporting; and the counterfactual deleted while the match is still claimed",
      "name": "every-forged-bom-is-refused-on-the-rule-it-targets",
      "status": "PASS"
    },
    {
      "detail": "28 rules in the trusted checker, 28 with a forgery aimed at them. A rule with no forgery is a rule nobody has shown can fire -- and requiring each forgery to NAME its rule is what found that `determinism-requires-nonempty-runs` and `branch-echo-recorded` were UNREACHABLE: the structural checks sat after a `continue` taken whenever the re-derivation raised, which is exactly the input those rules describe",
      "name": "every-checker-rule-has-a-forgery-aimed-at-it",
      "status": "PASS"
    },
    {
      "detail": "`checker.py` imports only `json`, `os`, `re`, `sys` and the SPECIFICATION (`model`). It cannot import the producer, the connectors, the reproduction runner, or anything that reaches a network or spawns a process -- so its agreement is a second opinion and not the same opinion twice. Scanned for: producer, connectors, reproduce, urllib, socket, subprocess, requests, http; it imports ['__future__', 'json', 'model', 'os', 're', 'sys']",
      "name": "the-checker-cannot-re-run-the-producer",
      "status": "PASS"
    },
    {
      "detail": "asked in replay mode for a URL that was never captured, the connector layer RAISES. It does not return an empty record. This is the failure mode the whole vocabulary is built around: a measurement that did not happen must never be indistinguishable from a measurement that found nothing",
      "name": "a-missing-capture-is-not-an-empty-result",
      "status": "PASS"
    },
    {
      "detail": "37 capture files, 34 of them HTTP responses, each recording its URL, final URL, status, content type, byte count and SHA-256. NIST's ML-KEM keyGen vector file is committed as the 5 ML-KEM-768 cases used plus the digest and length of the whole 558841-byte upstream file (`d7a62a2c3476957f...`), which is what a third party re-derives with one `curl`",
      "name": "every-captured-response-carries-its-own-digest",
      "status": "PASS"
    },
    {
      "detail": "the published BOM declares `mode=live` at 2026-08-04T00:18:27Z, against `pq-crystals/kyber` at commit `3edd5af59919` -- a 40-hex object id, not a branch name. Host: Darwin arm64, Apple clang version 17.0.0 (clang-1700.3.19.1). C5's refutation is scoped to THAT platform and the row says so; nothing here was run on Linux and no claim is made about Linux",
      "name": "the-run-is-pinned-and-its-platform-recorded",
      "status": "PASS"
    },
    {
      "detail": "the notebooks connector reports NOT_APPLICABLE over 100 files walked at the pinned commit -- the target has no notebooks. A connector whose code path never executes is not a connector, so its output-fidelity parser is exercised on a fixture with one agreeing and one disagreeing cell: 2 cells, 1 agreed, 1 disagreed",
      "name": "the-not-applicable-connector-is-not-vapour",
      "status": "PASS"
    },
    {
      "detail": "6 names across 2 public registries, 6 of which resolve to a real package and **0** of which declare any URL pointing at the target: kyber-crystals@npm, kyber-py@pypi, kyber@npm, kyber@pypi, pqc-kyber@npm, pykyber@pypi. Control is decided from each package's OWN declared project URLs, not from the name looking plausible",
      "name": "the-supply-chain-row-is-a-count-not-an-impression",
      "status": "PASS"
    },
    {
      "detail": "the target's README at the pinned commit is fetched by the github connector (102 lines, digest in the capture) and every one of the 8 quoted claims is recovered from EXACTLY the lines it cites, under the single normalisation declared in `model.normalise` -- links to their labels, fence delimiters dropped, whitespace collapsed, no word added or reordered. FOUR OF THE EIGHT CITATIONS WERE WRONG when this item was first written and nothing noticed: C1 pointed at a blank line, C2 at an unrelated sentence about AVX2, C5 at a range beginning blank and ending inside C6's text, and C6 at a range that EXCLUDED the sentence it quotes. An item about whether a target's claims survive checking had misquoted where the target makes them",
      "name": "every-quote-is-at-the-line-it-cites",
      "status": "PASS"
    },
    {
      "detail": "`ld: unknown options: -z` is quoted as the target's linker's own words in the report, the Makefile and the commit message, so it is BOUND: the recorded stderr of the documented build must contain it (True). Likewise `removing one flag`: the deviation is `-z noexecstack` and the CFLAGS actually passed are the target's own minus that one option, read out of its Makefile (`-Wall -Wextra -Wpedantic -Wmissing-prototypes -Wredundant-decls -Wshadow -Wpointer-arith -O3 -fomit-frame-pointer`). AN EARLIER REVISION PASSED A THREE-FLAG CFLAGS that silently removed SEVEN of the target's options while every publication point said one. And the counterfactual build's object sizes are measured, not assumed (True), so `identical either way` is a measurement on both sides",
      "name": "the-quoted-evidence-is-in-the-recorded-output",
      "status": "PASS"
    },
    {
      "detail": "eleven limits are published in the BOM itself: that the GATE REPLAYS and the live run is `make claimbom-live`; that the checker verifies INFERENCE and not OBSERVATION; that C5 is scoped to Darwin/arm64; that nothing here says the target's cryptography is wrong -- C2's measurement runs in its favour and the finding is about a sentence; that the eight claims are a SELECTION and no check can validate it; and that C2 rests on ML-KEM keyGen only, encapsulation having not been run; that C1, C6 and C7 were measured on binaries the DOCUMENTED command did not produce; that only `ref/` was built; that C7's SHAKE128 mechanism was NOT tested, only byte-identity; that `cloud_logs` reads hosted quality RECORDS and not build logs, there being none; and that the blind-connector override changed no verdict in this run, Q2 having reached UNVERIFIABLE by its own rule from probe-level blindness",
      "name": "the-limits-are-in-the-artifact-not-only-in-the-commit-message",
      "status": "PASS"
    }
  ],
  "connectors": {
    "ci": {
      "n_examined": 4,
      "status": "EMPTY_UPSTREAM"
    },
    "cloud_logs": {
      "n_examined": 5,
      "status": "OK"
    },
    "datasets": {
      "n_examined": 3,
      "status": "EMPTY_UPSTREAM"
    },
    "github": {
      "n_examined": 6,
      "status": "OK"
    },
    "notebooks": {
      "n_examined": 100,
      "status": "NOT_APPLICABLE"
    },
    "patents": {
      "n_examined": 3,
      "status": "OK"
    },
    "registries": {
      "n_examined": 12,
      "status": "OK"
    },
    "regulatory_docs": {
      "n_examined": 2,
      "status": "OK"
    }
  },
  "determinism_guard": {
    "derived": {
      "both_runs_nonempty": false,
      "deterministic": false,
      "digests_equal": true,
      "n_vector_sets": 0,
      "n_vector_sets_as_claimed": false
    },
    "raw": {
      "n_vector_sets": 0,
      "n_vector_sets_claimed": 10000,
      "run_a": {
        "bytes": 0,
        "exit_code": 127,
        "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
      },
      "run_b": {
        "bytes": 0,
        "exit_code": 127,
        "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
      }
    },
    "reason": "at least one run produced no bytes, so the comparison that found them equal compared nothing",
    "sha256_of_empty": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
    "verdict": "UNSUPPORTED",
    "why": "two runs of a binary that does not exist produce two empty files, and `cmp` calls them identical. The digests DO agree -- on the digest of nothing. `deterministic` is false only because `both_runs_nonempty` is checked first."
  },
  "failures": [],
  "forgeries": {
    "n": 30,
    "n_must_verify": 3,
    "rules": [
      "schema-version",
      "spec-digest",
      "row-set-complete",
      "problem-digest-binds-the-row",
      "verdict-in-vocabulary",
      "derived-recomputed-agrees",
      "verdict-follows-from-derived",
      "connector-kinds-complete",
      "connector-status-in-vocabulary",
      "counted-nothing-is-not-a-finding",
      "blind-connector-forces-unverifiable",
      "provenance-present",
      "acvp-bytes-well-formed",
      "counterfactual-required-for-a-match-claim",
      "determinism-requires-nonempty-runs",
      "branch-echo-recorded",
      "payload-classification-consistent",
      "target-commit-is-a-sha",
      "attempts-carry-exit-codes",
      "host-recorded",
      "reason-follows-from-derived",
      "row-declaration-matches-the-register",
      "no-duplicate-rows",
      "tally-recomputed",
      "no-unknown-top-level-keys",
      "connector-kind-is-known",
      "exit-codes-are-integers",
      "a-row-that-examined-nothing-is-not-a-finding"
    ],
    "rules_with_no_forgery": []
  },
  "gate": "claimbom",
  "honest_scope": {
    "cloud_logs_read_records_not_logs": "The `cloud_logs` connector fetches badge images and the coverage records underneath them. It fetches no build-log body, because this target has none: it has never run a hosted CI job. The DoD's `cloud logs` kind is satisfied by the hosted quality records that exist, and the distinction is stated rather than glossed.",
    "encapsulation_was_not_tested": "C2's measurement is ML-KEM keyGen only. NIST publishes encapDecap vectors too and they were not run, so the identification finding rests on key generation and on one reverted line, not on the whole KEM.",
    "no_claim_about_the_targets_correctness": "Nothing in this BOM says the target's cryptography is wrong. C2 is about an IDENTIFICATION on a front page, and the measurement runs in the target's favour: its key generation reproduces NIST's ML-KEM-768 vectors exactly. The finding is that the sentence a buyer would read says something else.",
    "only_ref_was_built": "C5's sentence names `ref/` OR `avx2/` and only `ref/` was attempted, so the nine executables counted are one directory's. The README's Prerequisites section (lines 31-47) tells macOS users to export CFLAGS for OpenSSL; that is not a workaround for this failure -- the target's Makefile uses `CFLAGS +=`, so an exported CFLAGS still inherits `-z noexecstack` -- but it was not quoted and a reader should know it exists.",
    "shake128_was_not_tested": "C7's quoted claim says the deterministic bytes come from SHAKE128 on empty input. What was measured is that two runs are byte-identical and that 10000 vector sets appear. Any seeded PRNG passes that; the SHAKE128 mechanism is NOT tested here.",
    "the_blind_override_did_not_fire_in_this_run": "Rule 5 -- a blind connector forces UNVERIFIABLE -- is applied to every row and changed no verdict here, because every connector had at least one probe that answered. Q2 is UNVERIFIABLE by its OWN rule, from probe-level blindness (a 401 and a 200-with-HTML among three endpoints), not by the override. Each connector publishes `n_blind_probes` so the aggregation is visible.",
    "the_checker_verifies_inference_not_observation": "The checker re-derives every derived field from the raw fields and re-applies every verdict rule. It catches a verdict that does not follow from the measurements. It cannot catch a producer that lies about what it observed, and nothing here claims otherwise.",
    "the_claim_set_is_a_selection": "Eight material claims were taken from the target's README. They are the ones a buyer prices -- identification, build, self-test, determinism, CI, coverage, maintenance -- and they are not everything the repository asserts. The selection is an input to this BOM and nothing in the checker can validate it.",
    "the_gate_replays": "`make claimbom-gate` reaches no network and runs no compiler. It replays the committed capture through the same connector parsers, rebuilds the BOM, requires it to be byte-identical to the published one, and runs the trusted checker over it and over a corpus of forgeries. The live run is `make claimbom-live`; the capture is its evidence. What a third party re-derives independently is the upstream SHA-256s, the pinned target commit, and a re-run.",
    "the_platform_findings_are_platform_findings": "C5 is REFUTED on Darwin/arm64 with Apple clang and says so in the row: `-z noexecstack` is a GNU-ld option and `test/cpucycles.h` is x86 inline assembly. The README names macOS explicitly, which is what makes this a refutation rather than a portability note, but nothing here was run on Linux and no claim is made about Linux.",
    "the_self_test_ran_on_a_build_the_readme_does_not_document": "C1, C6 and C7 are measured on binaries the DOCUMENTED command did not produce. It produced none: the documented `make` exits 2 on this platform. The measurements come from the deviated build -- the target's own CFLAGS with `-z noexecstack` removed and nothing else -- and every one of those three rows is a statement about that build, not about the one the README describes."
  },
  "item": "F4-08 Claim BOM -- deep-tech acquisition diligence",
  "n_checks": 23,
  "n_passed": 23,
  "not_a_gate": {
    "mode_is_self_declared": "`mode: live` in the committed artifact is a string the producer wrote. This gate replays, so it cannot distinguish a live run from a replay that claims to be one, and it does not pretend to: the field's VOCABULARY is checked and its truth is not. The committed artifact is the live run's own output; what makes that checkable by someone else is `make claimbom-live` and the upstream digests, not a check in here.",
    "the_capture_could_be_fabricated": "Nothing in this gate proves the recorded HTTP responses or exit codes were ever produced by a real run. Replay is replay. The gate's subject is the INFERENCE from measurement to verdict, plus the presence of every measurement a verdict depends on. What is checkable by a third party is the upstream SHA-256s, the pinned commit, and re-running `make claimbom-live`.",
    "the_claim_selection_is_an_input": "`the-answer-is-not-yes` requires refutations to exist, which is a property of THIS claim set on THIS target. It is evidence that the machinery can produce a negative verdict; it is not evidence that the eight claims are the right eight. That judgement is an input and no check here validates it.",
    "the_determinism_probes_digests_agree_by_construction": "`prove_the_guard` writes the same literal digest into both runs, so `digests_equal: true` is guaranteed and is not evidence. The discriminating conjunct is `deterministic: false`; the equal digests are there to show WHY the trap is a trap.",
    "the_scope_check_measures_length_not_content": "`the-limits-are-in-the-artifact` requires each of the eleven scope entries to exceed 80 characters. It cannot tell a limit from eighty-one characters of anything; what it prevents is a limit being quietly emptied."
  },
  "status": "PASS",
  "tally": {
    "CORROBORATED": 1,
    "REFUTED": 3,
    "REPRODUCED": 4,
    "UNSUPPORTED": 3,
    "UNVERIFIABLE": 1
  },
  "target": {
    "commit": "3edd5af5991927164edd4aacebfcbee00b8064e7",
    "default_branch": "main",
    "id": "pq-crystals-kyber",
    "name": "pq-crystals/kyber",
    "url": "https://github.com/pq-crystals/kyber",
    "why_this_target": "A real repository outside this portfolio, in this portfolio's own subject matter, whose front page makes claims of exactly the kinds an acquirer has to price: an identification of the algorithm, a build procedure, a build-status badge, a coverage number and a maintenance disclosure. Nothing here is a criticism of its authors, who publish reference code for free; it is a demonstration that the claims a buyer would read off a front page can be checked mechanically, and that several of these do not survive it."
  },
  "verdicts": {
    "C1-official-reference-implementation": "REPRODUCED",
    "C2-round-3-identification": "REFUTED",
    "C3-build-status-badge": "UNSUPPORTED",
    "C4-coverage-badge": "UNSUPPORTED",
    "C5-build-procedure": "REFUTED",
    "C6-selftest-contract": "REPRODUCED",
    "C7-deterministic-vectors": "REPRODUCED",
    "C8-maintenance-disclosure": "CORROBORATED",
    "Q1-name-control-in-registries": "REFUTED",
    "Q2-patent-exposure": "UNVERIFIABLE",
    "Q3-notebook-output-fidelity": "REPRODUCED",
    "Q4-dataset-substantiation": "UNSUPPORTED"
  }
}
