{
  "_doc": "One result, read from the codebase’s own files at the commit named here. Every value is that file’s own, copied verbatim; nothing here is written by hand. A value replaced by {withheld: true, sha256_of_value, bytes} is committed by its sha256 instead of published, for the reason it states, and is never edited. Each whole source file is committed by sha256 below, and its bytes are published only where its visibility says so. The codebase is named by the public subject its files are published under.",
  "lane": "wireless-pqc",
  "repository": "wireless-pqc",
  "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
  "portfolio_id": "wireless-pqc:rust-python-102-verdicts",
  "id": "rust-python-102-verdicts",
  "attestation_row": {
    "attested_at": "2026-09-13",
    "attestor": "03-wifipqc",
    "repository": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "6f37ed958c37482bf7ee04acba61df04492fe3186c1ba6c10b77519cd450c69f",
      "bytes": 7
    },
    "source_doc": "CROWN_JEWELS_RESOLVED.md",
    "source_doc_sha256": "6958cd834026328936c2fbfb51a8b00a4dd5ec6cb65b1d0d8960bcfe0b9e2418",
    "state": "attested",
    "top_n": 26,
    "note_sha256": "c1af3e3220ffc4290cc975a79bf85d216638fd8abd3f4d8e7e67f6f5af0aff3b",
    "ids_in_row": 26,
    "file": "dataroom/TOP_N_ATTESTATION.jsonl",
    "line": 1
  },
  "claim_source": {
    "receipt": "wireless-pqc/dataroom/top40.json",
    "sha256": "6076db4027d7499ac53b5cf15f9a07bb7e41c38f56fb0f469a62353e10e65353",
    "field": "entries[31].claim",
    "file": "dataroom/top40.json"
  },
  "top40_entry": {
    "id": "rust-python-102-verdicts",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "d2940dc4c5ef73e739e28e0d692599d10df0e07d7c6a217f94bd5ef01428af1b",
      "bytes": 32
    },
    "rank": 32,
    "native_rank": 27,
    "title": "An independent Rust re-implementation agrees with the Python arbiter on every verdict in the decision surface",
    "claim": "An independent Rust re-implementation agrees with the Python arbiter on every verdict across the whole decision surface, including the deliberately re-opened configurations.",
    "scope": "The Rust kernel is trusted ONLY because it equals the arbiter; the Python frozen verifier remains the sole arbiter. It ports the invariant DECISION layer, not a Rust-native handshake simulation.",
    "artifact_path": "artifacts/native/cross_impl_equiv_ci.json",
    "witness_command": "python3 tools/cross_impl_equiv_ci.py",
    "witness_result": {
      "status": "RAN",
      "exit": 0,
      "line": "wrote artifacts/native/cross_impl_equiv_ci.json",
      "seconds": 1.4,
      "run_at": "2026-09-13T02:34:39Z",
      "owner_gated": false,
      "reason": null,
      "run_of_record": "clean clone at HEAD (S03, dataroom/witness_quality_20260913/clean_clone_baseline.json)"
    },
    "third_party_axis": "—",
    "facts": {
      "ran_with_receipt": true,
      "third_party_graded": false,
      "negative_control_stated": false,
      "ip_class_known": false,
      "reproduce_command": true,
      "regenerates": false
    },
    "fact_count": 2,
    "repro_command": "python3 tools/cross_impl_equiv_ci.py",
    "ip_class": null,
    "ip_class_basis": "no source in this repository states an IP class for this entry; never guessed"
  },
  "witness_quality_entry": {
    "id": "rust-python-102-verdicts",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "d2940dc4c5ef73e739e28e0d692599d10df0e07d7c6a217f94bd5ef01428af1b",
      "bytes": 32
    },
    "title": "An independent Rust re-implementation agrees with the Python arbiter on every verdict in the decision surface",
    "claim": "An independent Rust re-implementation agrees with the Python arbiter on every verdict across the whole decision surface, including the deliberately re-opened configurations.",
    "class": "ASSERTING",
    "why": "clean-clone exit 0; every decisive planted defect went red: [0] invert the Python arbiter's no_key_reinstall invariant (nonce_resets == 0 -> != 0): Python and Rust now disagree wherever a KRACK reinstall occurs -> exit 1",
    "witness_command": "python3 tools/cross_impl_equiv_ci.py",
    "clean_clone": {
      "exit": 0,
      "status": "RAN",
      "seconds": 1.4,
      "first_line": "liboqs-python faulthandler is disabled",
      "last_line": "wrote artifacts/native/cross_impl_equiv_ci.json",
      "artifact_rewritten": false,
      "dirtied": [],
      "run_at": "2026-09-13T02:34:39Z",
      "reason": null
    },
    "planted_defects": [
      {
        "index": 0,
        "what": "invert the Python arbiter's no_key_reinstall invariant (nonce_resets == 0 -> != 0): Python and Rust now disagree wherever a KRACK reinstall occurs",
        "falsifies": "property: agreement on every verdict",
        "decisive": true,
        "planted": [
          {
            "path": "lib/wifipqc/attacks.py",
            "diff": "'    held = (r.nonce_resets == 0)\\n    return held, (\"no reinstall\" if held' -> '    held = (r.nonce_resets != 0)\\n    return held, (\"no reinstall\" if held' (x1 of 1)"
          }
        ],
        "exit": 1,
        "seconds": 1,
        "last_line": "wrote artifacts/native/cross_impl_equiv_ci.json",
        "failure_moved_by": null
      }
    ],
    "measured": true,
    "stale_claims_ref": null
  },
  "packet": null,
  "measured": {
    "measured": true,
    "basis": "planted_defects[].exit = 1",
    "exit": 1,
    "defect_rejected": true
  },
  "register": {
    "truth_state": "attested",
    "truth_line": 131,
    "measured_per_register": true,
    "witness_class_per_register": "ASSERTING",
    "ip_class_public": "unknown",
    "ip_class_sha256": "b23a6a8439c0dde5515893e7c90c1e3233b8616e634470f20dc4928bcf3609bc",
    "ip_class_source": "TOP_N_CROWN_JEWELS.md:72 @ 102044d55aab",
    "receipt": "register/CROWN_JEWELS_TRUTH.md",
    "receipt_sha256": "bde06cf0d3e99644522d18e79b6bd5d84ed4f5c86e315a48fef207e9e49c5022",
    "ip_class_receipt": "register/ip_class.jsonl",
    "ip_class_receipt_sha256": "b1e8f97aa6779e0fefed2f7a7726e1a03563b536b497392401b49bb8ef84d4ca"
  },
  "withheld_fields": [
    {
      "field": "top40.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "witness_quality.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "attestation_row.repository",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    }
  ],
  "sources": {
    "attestation": {
      "receipt": "wireless-pqc/dataroom/TOP_N_ATTESTATION.jsonl",
      "source": "dataroom/TOP_N_ATTESTATION.jsonl",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "9bf48d398fc36b52f21264edc3a04b8e2c3cd7da3c53f24ec80636897997097e",
      "bytes": 3364,
      "visibility": "sealed"
    },
    "top40": {
      "receipt": "wireless-pqc/dataroom/top40.json",
      "source": "dataroom/top40.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "6076db4027d7499ac53b5cf15f9a07bb7e41c38f56fb0f469a62353e10e65353",
      "bytes": 167747,
      "visibility": "sealed"
    },
    "witness_quality": {
      "receipt": "wireless-pqc/dataroom/witness_quality.json",
      "source": "dataroom/witness_quality.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "5d379a10112d400163b35100a423124c28e8bfbbdbe4378b71840eda85f75cfe",
      "bytes": 143046,
      "visibility": "sealed"
    },
    "repro_index": {
      "receipt": "wireless-pqc/repro/INDEX.json",
      "source": "repro/INDEX.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "378fd4a3ce4f44403b7c9ca6a3f19c11895831f892736376c90cf9423037f9eb",
      "bytes": 26512,
      "visibility": "sealed"
    }
  }
}
