Skip to content

Draft evidence integrity design#23

Merged
SSBrouhard merged 1 commit into
mainfrom
codex/evidence-integrity-design
Jun 10, 2026
Merged

Draft evidence integrity design#23
SSBrouhard merged 1 commit into
mainfrom
codex/evidence-integrity-design

Conversation

@SSBrouhard

Copy link
Copy Markdown
Owner

Summary

  • add a design doc for issue Add tamper-evident evidence ledger and verification command #2 before implementing tamper-evident evidence
  • define the Tier 1 HMAC-chain boundary, including the compromised-broker residual
  • specify MAC commitment, canonicalization, expected-head handling for tail truncation, three verifier states, legacy evidence compatibility, key rotation, and write-path concurrency/crash behavior
  • link the draft from the evidence notes while preserving the current append-only/advisory claim

Validation

  • .venv/bin/python scripts/vmga_release_check.py
  • git diff --check
  • claim-hygiene grep for tamper-proof/hash-chained/cannot_verify/expected-head boundary language

Closes no implementation issue yet; this is the design gate for #2.

@SSBrouhard SSBrouhard force-pushed the codex/evidence-integrity-design branch from 5387652 to 3600452 Compare June 10, 2026 08:38
@SSBrouhard SSBrouhard merged commit ce422a4 into main Jun 10, 2026
5 checks passed
@SSBrouhard SSBrouhard deleted the codex/evidence-integrity-design branch June 10, 2026 08:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant