{
  "_doc": "One result, read from the codebase’s own files at the commit named here. Every value is that file’s own, copied verbatim; nothing here is written by hand. A value replaced by {withheld: true, sha256_of_value, bytes} is committed by its sha256 instead of published, for the reason it states, and is never edited. Each whole source file is committed by sha256 below, and its bytes are published only where its visibility says so. The codebase is named by the public subject its files are published under.",
  "lane": "wireless-reliability",
  "repository": "wireless-reliability",
  "commit": "1cb3c54d9de8629abdd214911bfef7a7244ec4ff",
  "portfolio_id": "wireless-reliability:provenance-lint",
  "id": "provenance-lint",
  "attestation_row": {
    "attested_at": "2026-09-19",
    "attestor": "02-wireless",
    "repository": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "62a01cc8ef60803479267f32d6c312ef0eb75baeb9e054d8b1cac54bf9f40a33",
      "bytes": 7
    },
    "source_doc": "CROWN_JEWELS_RESOLVED.md",
    "source_doc_sha256": "0e41e33d018b8df50fc37e9a1ee7fb393ef434e338776bb04f71e8e15cf440e8",
    "state": "attested",
    "top_n": 17,
    "note_sha256": "e7b0dcf1a32532b1bd0eb9b3d22caa8772768191e022000636b87cd28b1536b0",
    "ids_in_row": 17,
    "file": "05_wireless_reliability_fallback_lab/dataroom/TOP_N_ATTESTATION.jsonl",
    "line": 1
  },
  "claim_source": {
    "receipt": "wireless-reliability/dataroom/top40.json",
    "sha256": "94bf9dc5735a54020b7052fde3da5f062e760f2cb351babab0fcd6f1b52c7be5",
    "field": "entries[22].claim",
    "file": "05_wireless_reliability_fallback_lab/dataroom/top40.json"
  },
  "top40_entry": {
    "id": "provenance-lint",
    "rank": 23,
    "title": "`provenance/lint.py` — the portfolio's immune system (jewel 39)",
    "claim": "A stdlib-only AST linter, verified runnable under `python3 -I -S`, that enforces five provenance rules plus a vacuity guard **against repositories nobody here owns** — no install, no network, no CI.",
    "scope": "CORRECTED S02, 2026-09-02: the committed verdict covers THIS repository only (the artifact's own honest_scope: 'over this repository'); no run against a foreign repository is receipted anywhere in this tree, so 'runs against repositories nobody here owns' is a capability, not a result. A stdlib-only AST linter, verified runnable under python3 -I -S. It shipped with THREE vacuous-pass defects of its own, found by attacking it. Exit 3 is not exit 0: a repository that declared nothing has been SKIPPED, not checked.",
    "limits": "Two, both self-inflicted and both disclosed.",
    "artifact_path": "artifacts/backends/provenance_lint.json",
    "witness_command": "python3 scripts/check_provenance_lint.py",
    "witness_result": "exit=0 · 0.9s · -> artifacts/backends/provenance_lint.json",
    "witness_class": "ASSERTING",
    "witness_class_basis": "`dataroom/witness_quality.json` id `provenance-lint` — class ASSERTING; clean-clone exit 0; planted defect(s) D19",
    "clean_clone_exit": 0,
    "third_party_axis": "—",
    "third_party_basis": "`out/s02/verdicts.json` rank 23 axis `SELF`",
    "facts": {
      "ran_with_receipt": true,
      "third_party_graded": false,
      "negative_control_stated": false,
      "ip_class_known": false,
      "reproduce_command": true,
      "regenerates": true
    },
    "facts_count": 3,
    "repro_command": "python3 scripts/check_provenance_lint.py",
    "reproduce_command": "python3 scripts/check_provenance_lint.py",
    "ip_class": null,
    "ip_class_basis": "LANE_REGISTER_2026-09.md: '`ip_class` is UNKNOWN for every row by instruction' — unassessed, therefore null, never inferred",
    "evidence_tier": "TOOL",
    "run_status": "RAN",
    "output_excerpt": "exit=0",
    "attestation_rank": 26
  },
  "witness_quality_entry": {
    "id": "provenance-lint",
    "claim": "A stdlib-only AST linter, verified runnable under `python3 -I -S`, that enforces five provenance rules plus a vacuity guard **against repositories nobody here owns** — no install, no network, no CI.",
    "class": "ASSERTING",
    "why": "`n_rules` is read from `provenance.lint.RULES` (five: PROV-001..005), not from the payload, so a rule that stopped reporting cannot make the run look clean. The vacuity guard is the claim's own second half and it is enforced before the verdict.",
    "clean_clone": {
      "artifact_skip_markers": null,
      "exit": 0,
      "receipt": "out/s02_witness_quality/clean_clone_receipts_2026-09-12.json#23:provenance-lint",
      "seconds": 0.2,
      "skip_reason": null,
      "skipped": null
    },
    "planted_defects": [
      {
        "demo": "D19",
        "exit_after_restore": 0,
        "exit_before": 0,
        "exit_with_defect": 1,
        "expectation": "nonzero",
        "expectation_met": true,
        "file_restored_byte_identical": true,
        "mutation": {
          "from": "hero      = 18.7858",
          "to": "hero      = 18.9999"
        },
        "needle": null,
        "needle_in_baseline": false,
        "needle_with_defect": false,
        "planted": "the ledger's hero value for the 1e-5 reliability wall is moved off the artifact it names. The linter re-reads the artifact and is supposed to fail on drift, so a clean report here would mean the five rules do not bind",
        "ran_at": "2026-09-19T00:37:43+00:00",
        "receipt_file": "out/s02_witness_quality/planted_defects_2026-09-19.json",
        "verdict": "ASSERTING — the planted defect turned the witness red"
      }
    ],
    "asserts": [
      {
        "asserts": "the linter must report clean with zero findings",
        "file": "scripts/check_provenance_lint.py",
        "lines": [
          106
        ],
        "needle": "return 0 if ok else 1",
        "source": "return 0 if ok else 1"
      },
      {
        "asserts": "the vacuity guard runs FIRST and a rule that can no longer fire is MISCONFIGURED (exit 3), never clean",
        "file": "provenance/lint.py",
        "lines": [
          479
        ],
        "needle": "vacuous = vacuity_problems(cfg)",
        "source": "vacuous = vacuity_problems(cfg)"
      }
    ],
    "stale_claims_ref": null
  },
  "packet": null,
  "measured": {
    "measured": true,
    "basis": "planted_defects[].exit_with_defect = 1",
    "exit": 1,
    "defect_rejected": true
  },
  "register": {
    "truth_state": "attested",
    "truth_line": 99,
    "measured_per_register": false,
    "witness_class_per_register": "ASSERTING",
    "ip_class_public": "unknown",
    "ip_class_sha256": "b23a6a8439c0dde5515893e7c90c1e3233b8616e634470f20dc4928bcf3609bc",
    "ip_class_source": "05_wireless_reliability_fallback_lab/LANE_REGISTER_2026-09.md:7 @ 3871d59d4db8",
    "receipt": "register/CROWN_JEWELS_TRUTH.md",
    "receipt_sha256": "bde06cf0d3e99644522d18e79b6bd5d84ed4f5c86e315a48fef207e9e49c5022",
    "ip_class_receipt": "register/ip_class.jsonl",
    "ip_class_receipt_sha256": "b1e8f97aa6779e0fefed2f7a7726e1a03563b536b497392401b49bb8ef84d4ca"
  },
  "withheld_fields": [
    {
      "field": "attestation_row.repository",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    }
  ],
  "sources": {
    "attestation": {
      "receipt": "wireless-reliability/dataroom/TOP_N_ATTESTATION.jsonl",
      "source": "05_wireless_reliability_fallback_lab/dataroom/TOP_N_ATTESTATION.jsonl",
      "commit": "1cb3c54d9de8629abdd214911bfef7a7244ec4ff",
      "sha256": "0a32ca5be37efe69c4770cfdc34075f6101dfd530f8f64349812f119f1dc256f",
      "bytes": 3470,
      "visibility": "sealed"
    },
    "top40": {
      "receipt": "wireless-reliability/dataroom/top40.json",
      "source": "05_wireless_reliability_fallback_lab/dataroom/top40.json",
      "commit": "1cb3c54d9de8629abdd214911bfef7a7244ec4ff",
      "sha256": "94bf9dc5735a54020b7052fde3da5f062e760f2cb351babab0fcd6f1b52c7be5",
      "bytes": 163338,
      "visibility": "sealed"
    },
    "witness_quality": {
      "receipt": "wireless-reliability/dataroom/witness_quality.json",
      "source": "05_wireless_reliability_fallback_lab/dataroom/witness_quality.json",
      "commit": "1cb3c54d9de8629abdd214911bfef7a7244ec4ff",
      "sha256": "d54d7585c2c9014d607f3a27518062eea78a5e1ac86733df5c69067c25f5f365",
      "bytes": 135112,
      "visibility": "sealed"
    },
    "repro_index": {
      "receipt": "wireless-reliability/_root/repro/INDEX.json",
      "source": "repro/INDEX.json",
      "commit": "1cb3c54d9de8629abdd214911bfef7a7244ec4ff",
      "sha256": "0bff5030dca36a8e129e242975c67c75d1b983c670458420bee8b943429ac3ee",
      "bytes": 24483,
      "visibility": "sealed"
    }
  }
}
