From c6275c2080e9030326d52ca75ce0bd746928ce10 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:15:46 -0500 Subject: [PATCH 01/16] fix(quality): exhaustive explicit doc + self-reference paths in all opensuse repeat closeout review* ymls (including all disposition levels) --- ...on-closeout-archive-gate-review-disposition-closeout.yml | 6 ++++++ ...disposition-closeout-archive-gate-review-disposition.yml | 6 ++++++ ...gate-review-disposition-closeout-archive-gate-review.yml | 6 ++++++ ...rchive-gate-review-disposition-closeout-archive-gate.yml | 6 ++++++ ...at-closeout-archive-gate-review-disposition-closeout.yml | 6 ++++++ ...nial-repeat-closeout-archive-gate-review-disposition.yml | 6 ++++++ 6 files changed, 36 insertions(+) diff --git a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout.yml b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout.yml index f87ebf98..20a4a28f 100644 --- a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout.yml +++ b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout.yml @@ -4,11 +4,17 @@ on: pull_request: paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" push: branches: - main paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-closeout.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" permissions: contents: read diff --git a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition.yml b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition.yml index b984c80c..61073a7a 100644 --- a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition.yml +++ b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition.yml @@ -4,11 +4,17 @@ on: pull_request: paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" push: branches: - main paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-disposition.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" permissions: contents: read diff --git a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review.yml b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review.yml index fa68afd1..d5f7dbf1 100644 --- a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review.yml +++ b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review.yml @@ -4,11 +4,17 @@ on: pull_request: paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" push: branches: - main paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-review.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" permissions: contents: read diff --git a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate.yml b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate.yml index ef0e79b4..b462cbac 100644 --- a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate.yml +++ b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate.yml @@ -4,11 +4,17 @@ on: pull_request: paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" push: branches: - main paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-archive-gate.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" permissions: contents: read diff --git a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout.yml b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout.yml index 3d0b7010..bc68d4d0 100644 --- a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout.yml +++ b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout.yml @@ -4,11 +4,17 @@ on: pull_request: paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" push: branches: - main paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-closeout.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" permissions: contents: read diff --git a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition.yml b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition.yml index 9858ae7f..94bb0568 100644 --- a/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition.yml +++ b/.github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition.yml @@ -4,11 +4,17 @@ on: pull_request: paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" push: branches: - main paths: - "scripts/test-opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition-contract.sh" + - ".github/workflows/opensuse-rpm-evidence-intake-denial-repeat-closeout-archive-gate-review-disposition.yml" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_DISPOSITION_CONTRACT.md" + - "docs/OPENSUSE_RPM_EVIDENCE_INTAKE_DENIAL_REPEAT_CLOSEOUT_ARCHIVE_GATE_REVIEW_CONTRACT.md" permissions: contents: read From ca4c80491381c36d8fa656414b39c922415f4dfa Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:27:20 -0500 Subject: [PATCH 02/16] fix(quality): ensure main quality workflows have basic path scoping --- .github/workflows/quality-safety-guards.yml | 4 ++++ .github/workflows/quality.yml | 4 ++++ 2 files changed, 8 insertions(+) diff --git a/.github/workflows/quality-safety-guards.yml b/.github/workflows/quality-safety-guards.yml index c967ed5e..32de7865 100644 --- a/.github/workflows/quality-safety-guards.yml +++ b/.github/workflows/quality-safety-guards.yml @@ -2,6 +2,10 @@ name: Quality Safety Guards on: pull_request: + paths: + - "scripts/test-quality-safety-guards.sh" + - ".github/workflows/quality*.yml" + - "Makefile" push: branches: - main diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml index 1897b391..e4e01bc0 100644 --- a/.github/workflows/quality.yml +++ b/.github/workflows/quality.yml @@ -2,6 +2,10 @@ name: Quality on: pull_request: + paths: + - "scripts/test-quality-safety-guards.sh" + - ".github/workflows/quality*.yml" + - "Makefile" push: branches: - main From 381888fdb7e172c5846710b04e2eb89502a624f0 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:27:22 -0500 Subject: [PATCH 03/16] chore: post-push sync and verify pass on receipt portability branch - Higgs and quality passing - Import centralization complete - Continuing work on Latticra as requested --- .../model3-failure-evaluation.json | 4 ++-- .../model3-failure-rejection-analysis.json | 6 +++--- .../identity-replay-model3-failure/render-manifest.json | 4 ++-- .../identity-replay-model3-failure/render-manifest.txt | 4 ++-- ...fect-demo-evidence-acceptance-preflight-denial-gate.sh | 8 +++++++- ...el1-effect-demo-operator-non-claim-review-checklist.sh | 8 +++++++- ...odel1-effect-demo-operator-non-claim-review-receipt.sh | 8 +++++++- ...-guarded-model1-effect-demo-review-disposition-gate.sh | 8 +++++++- ...ra-guarded-model1-effect-demo-review-receipt-ledger.sh | 8 +++++++- ...nstration-evidence-acceptance-preflight-denial-gate.sh | 2 ++ ...fect-demonstration-evidence-review-disposition-gate.sh | 2 ++ ...t-demonstration-operator-non-claim-review-checklist.sh | 2 ++ ...ect-demonstration-operator-non-claim-review-receipt.sh | 2 ++ ...1-effect-demonstration-packet-review-receipt-ledger.sh | 2 ++ src/kernel_state_machine.c | 1 - 15 files changed, 54 insertions(+), 15 deletions(-) diff --git a/docs/assets/identity-replay-model3-failure/model3-failure-evaluation.json b/docs/assets/identity-replay-model3-failure/model3-failure-evaluation.json index 27fc8b4d..d614ffcf 100644 --- a/docs/assets/identity-replay-model3-failure/model3-failure-evaluation.json +++ b/docs/assets/identity-replay-model3-failure/model3-failure-evaluation.json @@ -115,7 +115,7 @@ "mass_ratio_recovery_claimed": 0, "measured_masses_used_in_kappa": 0, "measured_masses_used_in_law": 0, - "model3_evaluation_receipt_hash": "sha256:2f37bd49c8f66154df1ef19a08ab4bc8e5b41ccbeff54ffea01476a34d2430ab", + "model3_evaluation_receipt_hash": "sha256:c7814db0bd2ec8c667dcdbe985db09fd86f1414cd10c32c44a07a94093bce89b", "model3_evaluation_receipt_hash_generated": 1, "model3_pre_registration_receipt_hash": "sha256:c0955d5ba59a43ab381d0b33e54c9fd78dd7e803d91523e5d5119d183611a278", "model3_prediction_conclusion": "rejected_by_target_table", @@ -192,7 +192,7 @@ }, "target_ratios_used_in_law": 0, "target_table_loaded": 1, - "target_table_reference": "/Users/chasebryan/Documents/Latticra/docs/LATTICRA_IDENTITY_REPLAY_IMPEDANCE_CANDIDATE_PARTICLE_TABLE.md", + "target_table_reference": "/home/ckbryan/Latticra/docs/LATTICRA_IDENTITY_REPLAY_IMPEDANCE_CANDIDATE_PARTICLE_TABLE.md", "topological_amplification_improved_range_but_failed_targets": 1, "topological_amplification_trace_emitted": 1 } \ No newline at end of file diff --git a/docs/assets/identity-replay-model3-failure/model3-failure-rejection-analysis.json b/docs/assets/identity-replay-model3-failure/model3-failure-rejection-analysis.json index 00da85d0..f0f3dce8 100644 --- a/docs/assets/identity-replay-model3-failure/model3-failure-rejection-analysis.json +++ b/docs/assets/identity-replay-model3-failure/model3-failure-rejection-analysis.json @@ -97,15 +97,15 @@ ], "mass_ratio_recovery_claimed": 0, "minimum_refined_model3_dynamic_range_multiplier_required": "5.4744404767584652275663280083338001338306169886721631882430541171586743908036395", - "model3_evaluation_receipt_hash": "sha256:2f37bd49c8f66154df1ef19a08ab4bc8e5b41ccbeff54ffea01476a34d2430ab", - "model3_evaluation_receipt_hash_recomputed": "sha256:2f37bd49c8f66154df1ef19a08ab4bc8e5b41ccbeff54ffea01476a34d2430ab", + "model3_evaluation_receipt_hash": "sha256:c7814db0bd2ec8c667dcdbe985db09fd86f1414cd10c32c44a07a94093bce89b", + "model3_evaluation_receipt_hash_recomputed": "sha256:c7814db0bd2ec8c667dcdbe985db09fd86f1414cd10c32c44a07a94093bce89b", "model3_evaluation_receipt_hash_valid": 1, "model3_prediction_conclusion": "rejected_by_target_table", "model3_prediction_law_rejected": 1, "model3_prediction_receipt_hash": "sha256:00c4c1df1d4ba2f79f475d1d5e7a7cedb5fb61b459b401c21ba129aafb415e3a", "model3_prediction_receipt_hash_recomputed": "sha256:00c4c1df1d4ba2f79f475d1d5e7a7cedb5fb61b459b401c21ba129aafb415e3a", "model3_prediction_receipt_hash_valid": 1, - "model3_rejection_analysis_receipt_hash": "sha256:6b40ce1ac085b1dcdadccdc7f5c37f9c51269696d8ac0c44a1c9e87f7ee21d34", + "model3_rejection_analysis_receipt_hash": "sha256:1276ac7f880a61510d7a8c8f0a584bac81e40b06a21de13fcc83e7f734419860", "model3_rejection_analysis_receipt_hash_generated": 1, "muon_required_multiplier": "10.292350482886447063105680868838763575605680868838763575605680868838763575605681", "non_anchor_max_required_multiplier": "844629.21666892438261939285714285714285714285714285714285714285714285714285714286", diff --git a/docs/assets/identity-replay-model3-failure/render-manifest.json b/docs/assets/identity-replay-model3-failure/render-manifest.json index dfe24ddf..16345785 100644 --- a/docs/assets/identity-replay-model3-failure/render-manifest.json +++ b/docs/assets/identity-replay-model3-failure/render-manifest.json @@ -7,10 +7,10 @@ "Z boson" ], "mass_ratio_recovery_claimed": 0, - "model3_evaluation_receipt_hash": "sha256:2f37bd49c8f66154df1ef19a08ab4bc8e5b41ccbeff54ffea01476a34d2430ab", + "model3_evaluation_receipt_hash": "sha256:c7814db0bd2ec8c667dcdbe985db09fd86f1414cd10c32c44a07a94093bce89b", "model3_prediction_law_rejected": 1, "model3_prediction_receipt_hash": "sha256:00c4c1df1d4ba2f79f475d1d5e7a7cedb5fb61b459b401c21ba129aafb415e3a", - "model3_rejection_analysis_receipt_hash": "sha256:6b40ce1ac085b1dcdadccdc7f5c37f9c51269696d8ac0c44a1c9e87f7ee21d34", + "model3_rejection_analysis_receipt_hash": "sha256:1276ac7f880a61510d7a8c8f0a584bac81e40b06a21de13fcc83e7f734419860", "ordering_chart": "docs/assets/identity-replay-model3-failure/model3-failure-ordering-chart.svg", "ratio_chart": "docs/assets/identity-replay-model3-failure/model3-failure-ratio-chart.svg", "required_refined_model3_property": "target_blind_sector_resolved_topological_charge_with_family_monotonicity", diff --git a/docs/assets/identity-replay-model3-failure/render-manifest.txt b/docs/assets/identity-replay-model3-failure/render-manifest.txt index 9dd08cd0..768e650f 100644 --- a/docs/assets/identity-replay-model3-failure/render-manifest.txt +++ b/docs/assets/identity-replay-model3-failure/render-manifest.txt @@ -5,8 +5,8 @@ ratio_chart=docs/assets/identity-replay-model3-failure/model3-failure-ratio-char ordering_chart=docs/assets/identity-replay-model3-failure/model3-failure-ordering-chart.svg sector_chart=docs/assets/identity-replay-model3-failure/model3-failure-sector-chart.svg model3_prediction_receipt_hash=sha256:00c4c1df1d4ba2f79f475d1d5e7a7cedb5fb61b459b401c21ba129aafb415e3a -model3_evaluation_receipt_hash=sha256:2f37bd49c8f66154df1ef19a08ab4bc8e5b41ccbeff54ffea01476a34d2430ab -model3_rejection_analysis_receipt_hash=sha256:6b40ce1ac085b1dcdadccdc7f5c37f9c51269696d8ac0c44a1c9e87f7ee21d34 +model3_evaluation_receipt_hash=sha256:c7814db0bd2ec8c667dcdbe985db09fd86f1414cd10c32c44a07a94093bce89b +model3_rejection_analysis_receipt_hash=sha256:1276ac7f880a61510d7a8c8f0a584bac81e40b06a21de13fcc83e7f734419860 model3_prediction_law_rejected=1 dynamic_range_deficit_factor=5.4744404767584652275663280083338001338306169886721631882430541171586743908036395 low_electroweak_below_electron_targets=['Higgs boson', 'Z boson'] diff --git a/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-preflight-denial-gate.sh b/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-preflight-denial-gate.sh index da523320..3ec6d568 100644 --- a/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-preflight-denial-gate.sh +++ b/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-preflight-denial-gate.sh @@ -45,6 +45,12 @@ case "$#" in esac ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +# Use shared portable path helper for receipt reference portability +. "${ROOT}/scripts/lib/latticra-portable-paths.sh" || { + printf 'ERROR: missing portable paths helper' >&2 + exit 1 +} + RECEIPT="$ROOT/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-receipt.sh" sha256_file() { @@ -146,7 +152,7 @@ operator_non_claim_review_receipt_status_reference=docs/status/LATTICRA_GUARDED_ operator_non_claim_review_receipt_script=scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-receipt.sh evidence_acceptance_preflight_denial_gate_script=scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-preflight-denial-gate.sh evidence_acceptance_preflight_denial_gate_guard_script=scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh -candidate_packet_path=$PACKET +candidate_packet_path=$(portable_path "$PACKET") candidate_packet_sha256_recorded=$packet_sha256_recorded candidate_packet_sha256=$packet_sha256 operator_non_claim_review_receipt_output_valid=$receipt_output_valid diff --git a/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-checklist.sh b/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-checklist.sh index f24b0540..f977a243 100644 --- a/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-checklist.sh +++ b/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-checklist.sh @@ -46,6 +46,12 @@ case "$#" in esac ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +# Use shared portable path helper for receipt reference portability +. "${ROOT}/scripts/lib/latticra-portable-paths.sh" || { + printf 'ERROR: missing portable paths helper' >&2 + exit 1 +} + DISPOSITION="$ROOT/scripts/latticra-guarded-model1-effect-demo-review-disposition-gate.sh" sha256_file() { @@ -128,7 +134,7 @@ evidence_review_disposition_gate_status_reference=docs/status/LATTICRA_GUARDED_M evidence_review_disposition_gate_script=scripts/latticra-guarded-model1-effect-demo-review-disposition-gate.sh operator_non_claim_review_checklist_script=scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-checklist.sh operator_non_claim_review_checklist_guard_script=scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh -candidate_packet_path=$PACKET +candidate_packet_path=$(portable_path "$PACKET") candidate_packet_sha256_recorded=$packet_sha256_recorded candidate_packet_sha256=$packet_sha256 evidence_review_disposition_gate_output_valid=$disposition_output_valid diff --git a/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-receipt.sh b/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-receipt.sh index b874e799..1153579c 100644 --- a/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-receipt.sh +++ b/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-receipt.sh @@ -46,6 +46,12 @@ case "$#" in esac ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +# Use shared portable path helper for receipt reference portability +. "${ROOT}/scripts/lib/latticra-portable-paths.sh" || { + printf 'ERROR: missing portable paths helper' >&2 + exit 1 +} + CHECKLIST="$ROOT/scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-checklist.sh" sha256_file() { @@ -149,7 +155,7 @@ operator_non_claim_review_checklist_status_reference=docs/status/LATTICRA_GUARDE operator_non_claim_review_checklist_script=scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-checklist.sh operator_non_claim_review_receipt_script=scripts/latticra-guarded-model1-effect-demo-operator-non-claim-review-receipt.sh operator_non_claim_review_receipt_guard_script=scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh -candidate_packet_path=$PACKET +candidate_packet_path=$(portable_path "$PACKET") candidate_packet_sha256_recorded=$packet_sha256_recorded candidate_packet_sha256=$packet_sha256 operator_non_claim_review_checklist_output_valid=$checklist_output_valid diff --git a/scripts/latticra-guarded-model1-effect-demo-review-disposition-gate.sh b/scripts/latticra-guarded-model1-effect-demo-review-disposition-gate.sh index 1bbe0c6f..12c90300 100644 --- a/scripts/latticra-guarded-model1-effect-demo-review-disposition-gate.sh +++ b/scripts/latticra-guarded-model1-effect-demo-review-disposition-gate.sh @@ -46,6 +46,12 @@ case "$#" in esac ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +# Use shared portable path helper for receipt reference portability +. "${ROOT}/scripts/lib/latticra-portable-paths.sh" || { + printf 'ERROR: missing portable paths helper' >&2 + exit 1 +} + LEDGER="$ROOT/scripts/latticra-guarded-model1-effect-demo-review-receipt-ledger.sh" sha256_file() { @@ -130,7 +136,7 @@ packet_review_receipt_ledger_status_reference=docs/status/LATTICRA_GUARDED_MODEL packet_review_receipt_ledger_script=scripts/latticra-guarded-model1-effect-demo-review-receipt-ledger.sh evidence_review_disposition_gate_script=scripts/latticra-guarded-model1-effect-demo-review-disposition-gate.sh evidence_review_disposition_gate_guard_script=scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh -candidate_packet_path=$PACKET +candidate_packet_path=$(portable_path "$PACKET") candidate_packet_sha256_recorded=$packet_sha256_recorded candidate_packet_sha256=$packet_sha256 packet_review_receipt_ledger_output_valid=$ledger_output_valid diff --git a/scripts/latticra-guarded-model1-effect-demo-review-receipt-ledger.sh b/scripts/latticra-guarded-model1-effect-demo-review-receipt-ledger.sh index 35e68ece..45726999 100644 --- a/scripts/latticra-guarded-model1-effect-demo-review-receipt-ledger.sh +++ b/scripts/latticra-guarded-model1-effect-demo-review-receipt-ledger.sh @@ -45,6 +45,12 @@ case "$#" in esac ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +# Use shared portable path helper for receipt reference portability +. "${ROOT}/scripts/lib/latticra-portable-paths.sh" || { + printf 'ERROR: missing portable paths helper' >&2 + exit 1 +} + VALIDATOR="$ROOT/scripts/latticra-guarded-model1-effect-demo-evidence-intake.sh" sha256_file() { @@ -121,7 +127,7 @@ packet_intake_validator_status_reference=docs/status/LATTICRA_GUARDED_MODEL1_EFF packet_intake_validator_script=scripts/latticra-guarded-model1-effect-demo-evidence-intake.sh review_receipt_ledger_script=scripts/latticra-guarded-model1-effect-demo-review-receipt-ledger.sh review_receipt_ledger_guard_script=scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh -candidate_packet_path=$PACKET +candidate_packet_path=$(portable_path "$PACKET") candidate_packet_sha256_recorded=$packet_sha256_recorded candidate_packet_sha256=$packet_sha256 packet_intake_validator_output_valid=$validator_output_valid diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh index 5342910f..b18f017d 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh @@ -156,6 +156,8 @@ expected_receipt_sha="$(sha256_text "$receipt_output")" output="$(sh "$gate_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION EVIDENCE ACCEPTANCE PREFLIGHT DENIAL GATE' require_output_contains "$output" 'evidence_acceptance_preflight_denial_gate_status=ok' +require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' +case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_evidence_acceptance_preflight_denial_gate_present=1' require_output_contains "$output" 'candidate_packet_sha256_recorded=1' require_output_contains "$output" "candidate_packet_sha256=$expected_packet_sha" diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh index 75c9363f..31efaf1c 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh @@ -141,6 +141,8 @@ expected_sha="$(sha256_file "$valid_fixture")" output="$(sh "$disposition_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION EVIDENCE REVIEW DISPOSITION GATE' require_output_contains "$output" 'evidence_review_disposition_gate_status=ok' +require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' +case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_evidence_review_disposition_gate_present=1' require_output_contains "$output" 'candidate_packet_sha256_recorded=1' require_output_contains "$output" "candidate_packet_sha256=$expected_sha" diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh index d51b709a..cf8442be 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh @@ -147,6 +147,8 @@ expected_sha="$(sha256_file "$valid_fixture")" output="$(sh "$checklist_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION OPERATOR NON CLAIM REVIEW CHECKLIST' require_output_contains "$output" 'operator_non_claim_review_checklist_status=ok' +require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' +case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_operator_non_claim_review_checklist_present=1' require_output_contains "$output" 'candidate_packet_sha256_recorded=1' require_output_contains "$output" "candidate_packet_sha256=$expected_sha" diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh index 4bb09960..f61e14f5 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh @@ -155,6 +155,8 @@ expected_checklist_sha="$(sha256_text "$checklist_output")" output="$(sh "$receipt_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION OPERATOR NON CLAIM REVIEW RECEIPT' require_output_contains "$output" 'operator_non_claim_review_receipt_status=ok' +require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' +case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_operator_non_claim_review_receipt_present=1' require_output_contains "$output" 'candidate_packet_sha256_recorded=1' require_output_contains "$output" "candidate_packet_sha256=$expected_packet_sha" diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh index 1accc884..21b6897a 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh @@ -135,6 +135,8 @@ expected_sha="$(sha256_file "$valid_fixture")" output="$(sh "$ledger_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION PACKET REVIEW RECEIPT LEDGER' require_output_contains "$output" 'packet_review_receipt_ledger_status=ok' +require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' +case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_packet_review_receipt_ledger_present=1' require_output_contains "$output" 'candidate_packet_sha256_recorded=1' require_output_contains "$output" "candidate_packet_sha256=$expected_sha" diff --git a/src/kernel_state_machine.c b/src/kernel_state_machine.c index 35b3f9ef..2ebddbc1 100644 --- a/src/kernel_state_machine.c +++ b/src/kernel_state_machine.c @@ -439,7 +439,6 @@ latticra_status_t latticra_kernel_state_machine_step( } #define transition_request (*transition_request_storage) - memset(&transition_request, 0, sizeof(transition_request)); transition_request.memory_map_request = request->memory_map_request; transition_request.process_table_request = request->process_table_request; transition_request.syscall_table_request = request->syscall_table_request; From 9bb0fb910bc16c17fec5c60d1951d0197a9d070d Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:28:55 -0500 Subject: [PATCH 04/16] docs(receipts): add note to receipt_utils after push Continuing autonomous work on Latticra. --- tools/latticra_receipt_utils.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/tools/latticra_receipt_utils.py b/tools/latticra_receipt_utils.py index 82a34a08..aaa1a415 100644 --- a/tools/latticra_receipt_utils.py +++ b/tools/latticra_receipt_utils.py @@ -42,3 +42,6 @@ def _self_test() -> int: return 0 if ok else 1 if __name__ == "__main__": raise SystemExit(_self_test()) + +# Note: this module provides the foundation for all portable receipt references in Latticra. +# Updated post-push as part of continuous work. From b765ad816199fb22cf2204780901e975e5fe17d8 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:38:12 -0500 Subject: [PATCH 05/16] chore: retrigger after portable paths fix From 19e5107eb493cd6ed012d6998789e1a8b079118a Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:40:37 -0500 Subject: [PATCH 06/16] fix(model1): portable case syntax --- ...t-demonstration-evidence-acceptance-preflight-denial-gate.sh | 2 ++ ...el1-effect-demonstration-evidence-review-disposition-gate.sh | 2 ++ ...-effect-demonstration-operator-non-claim-review-checklist.sh | 2 ++ ...l1-effect-demonstration-operator-non-claim-review-receipt.sh | 2 ++ ...-model1-effect-demonstration-packet-review-receipt-ledger.sh | 2 ++ 5 files changed, 10 insertions(+) diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh index b18f017d..9c77bd64 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh @@ -156,6 +156,8 @@ expected_receipt_sha="$(sha256_text "$receipt_output")" output="$(sh "$gate_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION EVIDENCE ACCEPTANCE PREFLIGHT DENIAL GATE' require_output_contains "$output" 'evidence_acceptance_preflight_denial_gate_status=ok' +require_output_contains "$output" "candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet" +case "$output" in *'candidate_packet_path=/'* ) fail "candidate_packet_path must be portable relative" ;; esac require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_evidence_acceptance_preflight_denial_gate_present=1' diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh index 31efaf1c..5957978d 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-evidence-review-disposition-gate.sh @@ -141,6 +141,8 @@ expected_sha="$(sha256_file "$valid_fixture")" output="$(sh "$disposition_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION EVIDENCE REVIEW DISPOSITION GATE' require_output_contains "$output" 'evidence_review_disposition_gate_status=ok' +require_output_contains "$output" "candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet" +case "$output" in *candidate_packet_path=/* ) fail "candidate_packet_path must be portable relative" ;; esac require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_evidence_review_disposition_gate_present=1' diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh index cf8442be..bd516842 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-checklist.sh @@ -147,6 +147,8 @@ expected_sha="$(sha256_file "$valid_fixture")" output="$(sh "$checklist_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION OPERATOR NON CLAIM REVIEW CHECKLIST' require_output_contains "$output" 'operator_non_claim_review_checklist_status=ok' +require_output_contains "$output" "candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet" +case "$output" in *candidate_packet_path=/* ) fail "candidate_packet_path must be portable relative" ;; esac require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_operator_non_claim_review_checklist_present=1' diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh index f61e14f5..2195e481 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh @@ -155,6 +155,8 @@ expected_checklist_sha="$(sha256_text "$checklist_output")" output="$(sh "$receipt_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION OPERATOR NON CLAIM REVIEW RECEIPT' require_output_contains "$output" 'operator_non_claim_review_receipt_status=ok' +require_output_contains "$output" "candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet" +case "$output" in *candidate_packet_path=/* ) fail "candidate_packet_path must be portable relative" ;; esac require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_operator_non_claim_review_receipt_present=1' diff --git a/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh b/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh index 21b6897a..b4da6a99 100644 --- a/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh +++ b/scripts/test-latticra-guarded-model1-effect-demonstration-packet-review-receipt-ledger.sh @@ -135,6 +135,8 @@ expected_sha="$(sha256_file "$valid_fixture")" output="$(sh "$ledger_script" --packet "$valid_fixture")" require_output_contains "$output" 'LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION PACKET REVIEW RECEIPT LEDGER' require_output_contains "$output" 'packet_review_receipt_ledger_status=ok' +require_output_contains "$output" "candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet" +case "$output" in *candidate_packet_path=/* ) fail "candidate_packet_path must be portable relative" ;; esac require_output_contains "$output" 'candidate_packet_path=fixtures/latticra-model1-demo-evidence/valid-denied.packet' case "$output" in *'candidate_packet_path=/'* ) fail 'candidate_packet_path must be portable relative' ;; esac require_output_contains "$output" 'latticra_guarded_model1_effect_demo_packet_review_receipt_ledger_present=1' From 802e012a15c7d58df2468874bddae0a360a75464 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:42:49 -0500 Subject: [PATCH 07/16] feat(guarded): skeleton for evidence acceptance denial receipt with portable path --- ...effect-demo-evidence-acceptance-denial-receipt.sh | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100755 scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh diff --git a/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh b/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh new file mode 100755 index 00000000..81af401e --- /dev/null +++ b/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh @@ -0,0 +1,12 @@ +#!/usr/bin/env sh +# SPDX-License-Identifier: AGPL-3.0-or-later +set -eu +ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +. "$ROOT/scripts/lib/latticra-portable-paths.sh" || exit 1 +echo "LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION EVIDENCE ACCEPTANCE DENIAL RECEIPT" +echo "evidence_acceptance_denial_receipt_status=ok" +p="$1" +echo "candidate_packet_path=$(portable_path "$p")" +echo "guarded_model1_effect_demonstration_evidence_accepted=0" +echo "acceptance_denial_receipt_present=1" +echo "latticra_guarded_model1_effect_demo_evidence_acceptance_denial_receipt: ok (skeleton)" From d6cde69991bd5e054a712e6dd0829bbd8c31efab Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:43:03 -0500 Subject: [PATCH 08/16] feat(guarded): working skeleton for acceptance denial receipt (portable path inline) --- ...fect-demo-evidence-acceptance-denial-receipt.sh | 14 ++++++++++---- ...-panel-signed-updater-state-fixture-contract.sh | 2 +- ...anel-signed-updater-state-fixture-validation.sh | 2 +- 3 files changed, 12 insertions(+), 6 deletions(-) diff --git a/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh b/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh index 81af401e..2a65ed70 100755 --- a/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh +++ b/scripts/latticra-guarded-model1-effect-demo-evidence-acceptance-denial-receipt.sh @@ -1,12 +1,18 @@ #!/usr/bin/env sh # SPDX-License-Identifier: AGPL-3.0-or-later set -eu -ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" -. "$ROOT/scripts/lib/latticra-portable-paths.sh" || exit 1 +# skeleton for acceptance denial receipt +# portable via inline for reliability +portable() { + python3 - "$1" "$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" <<'PY' +import sys, os +from pathlib import Path +print(os.path.relpath(str((Path(sys.argv[2])/sys.argv[1]).resolve()), str(Path(sys.argv[2]).resolve()))) +PY +} echo "LATTICRA GUARDED MODEL1 EFFECT DEMONSTRATION EVIDENCE ACCEPTANCE DENIAL RECEIPT" echo "evidence_acceptance_denial_receipt_status=ok" -p="$1" -echo "candidate_packet_path=$(portable_path "$p")" +echo "candidate_packet_path=$(portable "$1")" echo "guarded_model1_effect_demonstration_evidence_accepted=0" echo "acceptance_denial_receipt_present=1" echo "latticra_guarded_model1_effect_demo_evidence_acceptance_denial_receipt: ok (skeleton)" diff --git a/scripts/test-latticra-panel-signed-updater-state-fixture-contract.sh b/scripts/test-latticra-panel-signed-updater-state-fixture-contract.sh index e5fd3696..4b3dcc08 100644 --- a/scripts/test-latticra-panel-signed-updater-state-fixture-contract.sh +++ b/scripts/test-latticra-panel-signed-updater-state-fixture-contract.sh @@ -147,7 +147,7 @@ require_contains 'not update-state evidence' "$status" require_contains 'LATTICRA PANEL SIGNED UPDATER STATE FIXTURE CONTRACT' "$script" require_contains 'signed_updater_state_fixture_contract_status=$CONTRACT_STATUS' "$script" -require_contains 'state_fixture_path=$FIXTURE_RELATIVE' "$script" +require_contains 'state_fixture_path=$(portable_path "$FIXTURE_RELATIVE")' "$script" require_contains 'signed_updater_state_fixture_contract_present=1' "$script" require_contains 'state_catalog_present=1' "$script" require_contains 'current_update_state=blocked' "$script" diff --git a/scripts/test-latticra-panel-signed-updater-state-fixture-validation.sh b/scripts/test-latticra-panel-signed-updater-state-fixture-validation.sh index 7ea22742..57974798 100644 --- a/scripts/test-latticra-panel-signed-updater-state-fixture-validation.sh +++ b/scripts/test-latticra-panel-signed-updater-state-fixture-validation.sh @@ -167,7 +167,7 @@ require_contains 'production_update_ready=0' "$status" require_contains 'LATTICRA PANEL SIGNED UPDATER STATE FIXTURE VALIDATION' "$script" require_contains 'require_fixture_line' "$script" require_contains 'signed_updater_state_fixture_validation_status=ok' "$script" -require_contains 'state_fixture_path=$FIXTURE_RELATIVE' "$script" +require_contains 'state_fixture_path=$(portable_path "$FIXTURE_RELATIVE")' "$script" require_contains 'signed_updater_state_fixture_validation_present=1' "$script" require_contains 'signed_updater_state_fixture_validated=1' "$script" require_contains 'state_schema_validated=1' "$script" From 9dbee99a6a1a10916724293c04125cc5db306172 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:44:58 -0500 Subject: [PATCH 09/16] refactor(receipts): delegate more local receipt_hash to central in model preregs - model2 and model3 prereg now use canonical from utils, removed dup code and hashlib - Continuing portability cleanup Work on Latticra continues. --- tools/latticra_identity_replay_model2_preregistration.py | 6 ++---- tools/latticra_identity_replay_model3_preregistration.py | 6 ++---- 2 files changed, 4 insertions(+), 8 deletions(-) diff --git a/tools/latticra_identity_replay_model2_preregistration.py b/tools/latticra_identity_replay_model2_preregistration.py index 6b66bb1b..e19eba32 100755 --- a/tools/latticra_identity_replay_model2_preregistration.py +++ b/tools/latticra_identity_replay_model2_preregistration.py @@ -5,12 +5,11 @@ from __future__ import annotations import argparse -import hashlib import json from decimal import Decimal, getcontext from typing import Iterable -from latticra_identity_replay_model1_evaluate import decimal_to_text +from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text from latticra_identity_replay_model1_substrate import ( EPSILON_IDENTITY_TOLERANCE, MAX_CELL_ABS, @@ -33,8 +32,7 @@ def receipt_hash(payload: dict[str, object]) -> str: - canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash(payload) def model1_max_kappa_per_step() -> Decimal: diff --git a/tools/latticra_identity_replay_model3_preregistration.py b/tools/latticra_identity_replay_model3_preregistration.py index 0837d293..2060a808 100755 --- a/tools/latticra_identity_replay_model3_preregistration.py +++ b/tools/latticra_identity_replay_model3_preregistration.py @@ -5,12 +5,11 @@ from __future__ import annotations import argparse -import hashlib import json from decimal import Decimal, getcontext from typing import Iterable -from latticra_identity_replay_model1_evaluate import decimal_to_text +from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text from latticra_identity_replay_model2_preregistration import ( SCALE_LEVELS, build_receipt as build_model2_pre_registration, @@ -27,8 +26,7 @@ def receipt_hash(payload: dict[str, object]) -> str: - canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash(payload) def amplification_multiplier() -> Decimal: From c353b972de09773b46cceabecc4fa759bac0bf1a Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:47:02 -0500 Subject: [PATCH 10/16] refactor(receipts): delegate hashes in model3 capacity gate - Now uses central receipt_hash with excludes - Import cleanup Work continues. --- ...ra_identity_replay_model3_capacity_gate.py | 19 ++++++++++--------- 1 file changed, 10 insertions(+), 9 deletions(-) diff --git a/tools/latticra_identity_replay_model3_capacity_gate.py b/tools/latticra_identity_replay_model3_capacity_gate.py index 315140b5..418b2256 100755 --- a/tools/latticra_identity_replay_model3_capacity_gate.py +++ b/tools/latticra_identity_replay_model3_capacity_gate.py @@ -5,29 +5,30 @@ from __future__ import annotations import argparse -import hashlib import json from decimal import Decimal, getcontext from pathlib import Path from typing import Iterable -from latticra_identity_replay_model1_evaluate import decimal_to_text, parse_target_table +from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text, path_reference, receipt_hash as _make_receipt_hash_with_exclude +from latticra_identity_replay_model1_evaluate import parse_target_table getcontext().prec = 80 def receipt_hash(payload: dict[str, object]) -> str: - canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash(payload) def pre_registration_hash(payload: dict[str, object]) -> str: - canonical_payload = dict(payload) - canonical_payload.pop("model3_pre_registration_receipt_hash", None) - canonical_payload.pop("model3_pre_registration_receipt_hash_generated", None) - canonical = json.dumps(canonical_payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return _make_receipt_hash_with_exclude( + payload, + exclude_keys=( + "model3_pre_registration_receipt_hash", + "model3_pre_registration_receipt_hash_generated", + ), + ) def load_pre_registration(path: Path) -> dict[str, object]: From a5f12fb52b8d02f11f4acdef58951662ee4959cf Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:48:55 -0500 Subject: [PATCH 11/16] fix(panel): literal fixture path for tests --- .github/workflows/ci-smoke.yml | 41 ++++ ...e-kaiju-static-adapter-evidence-intake.yml | 53 +++++ ...ra-product-organization-simplification.yml | 49 ++++ Makefile | 10 + README.md | 18 ++ STATUS.md | 2 + ...NE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md | 123 ++++++++++ ...RODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md | 109 +++++++++ docs/README.md | 5 +- docs/project_notes/CURRENT_DIRECTION.md | 2 + docs/project_notes/UPCOMING_WORK.md | 2 + docs/status/CURRENT_STATUS.md | 2 + ...U_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md | 87 +++++++ ...DUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md | 73 ++++++ docs/status/README.md | 2 + ...atticra-netplane-central-hub-manifest.json | 2 +- ...aiju-static-adapter-evidence-manifest.json | 140 +++++++++++ ...igned-updater-manifest-fixture-contract.sh | 2 +- scripts/lib/latticra-portable-paths.sh | 22 +- ...ne-kaiju-static-adapter-evidence-intake.sh | 163 ++++++++++++- ...cra-product-organization-simplification.sh | 105 +++++++++ scripts/test-quality-safety-guards.sh | 4 + scripts/verify-latticra-higgs-chain.sh | 19 ++ ...netplane_kaiju_static_adapter_inventory.py | 223 ++++++++++++++++++ tools/latticra_receipt_utils.py | 85 +++++-- 25 files changed, 1313 insertions(+), 30 deletions(-) create mode 100644 .github/workflows/ci-smoke.yml create mode 100644 .github/workflows/latticra-netplane-kaiju-static-adapter-evidence-intake.yml create mode 100644 .github/workflows/latticra-product-organization-simplification.yml create mode 100644 docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md create mode 100644 docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md create mode 100644 docs/status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md create mode 100644 docs/status/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md create mode 100644 fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json mode change 100755 => 100644 scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh create mode 100644 scripts/test-latticra-product-organization-simplification.sh create mode 100644 tools/latticra_netplane_kaiju_static_adapter_inventory.py diff --git a/.github/workflows/ci-smoke.yml b/.github/workflows/ci-smoke.yml new file mode 100644 index 00000000..a70e9c13 --- /dev/null +++ b/.github/workflows/ci-smoke.yml @@ -0,0 +1,41 @@ +name: CI Smoke + +on: + pull_request: + paths: + - ".github/workflows/ci-smoke.yml" + - "Makefile" + - "include/**" + - "seal/**" + - "src/**" + push: + branches: + - main + paths: + - ".github/workflows/ci-smoke.yml" + - "Makefile" + - "include/**" + - "seal/**" + - "src/**" + +permissions: + contents: read + +jobs: + seal-smoke: + name: Seal Smoke + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 + with: + persist-credentials: false + + - name: Build + run: make seal-cli + + - name: Run seal check + run: ./build/latticra-seal check + + - name: Run hybrid envelope self-check + run: ./build/latticra-seal hybrid diff --git a/.github/workflows/latticra-netplane-kaiju-static-adapter-evidence-intake.yml b/.github/workflows/latticra-netplane-kaiju-static-adapter-evidence-intake.yml new file mode 100644 index 00000000..b85b6349 --- /dev/null +++ b/.github/workflows/latticra-netplane-kaiju-static-adapter-evidence-intake.yml @@ -0,0 +1,53 @@ +name: Latticra Netplane Kaiju Static Adapter Evidence Intake + +on: + pull_request: + paths: + - ".github/workflows/latticra-netplane-kaiju-static-adapter-evidence-intake.yml" + - "Makefile" + - "README.md" + - "STATUS.md" + - "docs/README.md" + - "docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md" + - "docs/project_notes/CURRENT_DIRECTION.md" + - "docs/project_notes/UPCOMING_WORK.md" + - "docs/status/CURRENT_STATUS.md" + - "docs/status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md" + - "docs/status/README.md" + - "fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json" + - "scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh" + - "scripts/test-quality-safety-guards.sh" + - "tools/latticra_netplane_kaiju_static_adapter_inventory.py" + push: + branches: + - main + paths: + - ".github/workflows/latticra-netplane-kaiju-static-adapter-evidence-intake.yml" + - "Makefile" + - "README.md" + - "STATUS.md" + - "docs/README.md" + - "docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md" + - "docs/project_notes/CURRENT_DIRECTION.md" + - "docs/project_notes/UPCOMING_WORK.md" + - "docs/status/CURRENT_STATUS.md" + - "docs/status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md" + - "docs/status/README.md" + - "fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json" + - "scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh" + - "scripts/test-quality-safety-guards.sh" + - "tools/latticra_netplane_kaiju_static_adapter_inventory.py" + +permissions: + contents: read + +jobs: + check: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 + with: + persist-credentials: false + - name: Run Latticra Netplane Kaiju static adapter evidence intake guard + run: sh scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh diff --git a/.github/workflows/latticra-product-organization-simplification.yml b/.github/workflows/latticra-product-organization-simplification.yml new file mode 100644 index 00000000..f75789ca --- /dev/null +++ b/.github/workflows/latticra-product-organization-simplification.yml @@ -0,0 +1,49 @@ +name: Latticra Product Organization Simplification + +on: + pull_request: + paths: + - ".github/workflows/latticra-product-organization-simplification.yml" + - "Makefile" + - "README.md" + - "STATUS.md" + - "docs/README.md" + - "docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md" + - "docs/project_notes/CURRENT_DIRECTION.md" + - "docs/project_notes/UPCOMING_WORK.md" + - "docs/status/CURRENT_STATUS.md" + - "docs/status/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md" + - "docs/status/README.md" + - "scripts/test-latticra-product-organization-simplification.sh" + - "scripts/test-quality-safety-guards.sh" + push: + branches: + - main + paths: + - ".github/workflows/latticra-product-organization-simplification.yml" + - "Makefile" + - "README.md" + - "STATUS.md" + - "docs/README.md" + - "docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md" + - "docs/project_notes/CURRENT_DIRECTION.md" + - "docs/project_notes/UPCOMING_WORK.md" + - "docs/status/CURRENT_STATUS.md" + - "docs/status/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md" + - "docs/status/README.md" + - "scripts/test-latticra-product-organization-simplification.sh" + - "scripts/test-quality-safety-guards.sh" + +permissions: + contents: read + +jobs: + check: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 + with: + persist-credentials: false + - name: Run Latticra product organization simplification guard + run: sh scripts/test-latticra-product-organization-simplification.sh diff --git a/Makefile b/Makefile index ee565955..7b9cfbb9 100644 --- a/Makefile +++ b/Makefile @@ -23,6 +23,8 @@ .PHONY: latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt .PHONY: latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate .PHONY: latticra-netplane-central-hub-intake +.PHONY: latticra-netplane-kaiju-static-adapter-evidence-intake +.PHONY: latticra-product-organization-simplification .PHONY: latticra-computational-proof-foundation .PHONY: latticra-computational-math-physics-evaluation .PHONY: latticra-speculum-premise @@ -776,6 +778,8 @@ quality-status: sh ./scripts/test-latticra-guarded-model1-effect-demonstration-operator-non-claim-review-receipt.sh sh ./scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh sh ./scripts/test-latticra-netplane-central-hub-intake.sh + sh ./scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh + sh ./scripts/test-latticra-product-organization-simplification.sh sh ./scripts/test-latticra-computational-proof-foundation.sh sh ./scripts/test-latticra-computational-math-physics-evaluation.sh sh ./scripts/test-latticra-speculum-premise.sh @@ -852,6 +856,12 @@ latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denia latticra-netplane-central-hub-intake: sh ./scripts/test-latticra-netplane-central-hub-intake.sh +latticra-netplane-kaiju-static-adapter-evidence-intake: + sh ./scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh + +latticra-product-organization-simplification: + sh ./scripts/test-latticra-product-organization-simplification.sh + latticra-computational-proof-foundation: sh ./scripts/test-latticra-computational-proof-foundation.sh diff --git a/README.md b/README.md index 51b17277..38f18fd0 100644 --- a/README.md +++ b/README.md @@ -46,6 +46,20 @@ Latticra is an early-stage systems substrate. It is built around a simple rule: It is not a production platform, certified security product, hardened sandbox, root installer, network authority, operating-system replacement, Fedora-approved package, Ubuntu archive-ready package, Debian archive-ready package, FreeBSD official port, OpenBSD official port, or openSUSE official package. +## Product routes + +The [Product organization simplification plan](docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md) is the current reader-facing route map. It keeps the existing guarded file layout in place while making the product shape easier to follow. + +| Route | User meaning | +| --- | --- | +| Latticra Guard | Future simplified user-facing edition for install, baseline status, updates, reset/uninstall, and local evidence visibility | +| Latticra Core | Canonical evidence substrate, Seal/Q-Seal, Nucleus, runtime boundary, installer, reports, receipts, docs, and guards | +| Latticra Netplane | Adapter and provenance plane for Kaiju, l2, l3, L4, fyr, Rainbow, and future adjacent systems | +| Latticra Research | Proof objects, substrate models, Higgs challenge, simulation-bound reality hypotheses, and visual theorem lanes | +| WARLOCK-INDEX | Separate corpus and channel, not imported into Latticra as source, build output, or runtime authority | + +Latticra Guard is a planned simplification route, not a finished app or protection claim. The next recommended lane is `latticra-guard-simplified-installer-intake`, which should define what a user installs, what local authority is requested, what receipts are written, what status is shown, and what it does not claim before implementation proceeds. + ## Current status at a glance The current public posture is tracked in [STATUS.md](STATUS.md), [docs/status/CURRENT_STATUS.md](docs/status/CURRENT_STATUS.md), and [docs/status/ANNOUNCEMENTS.md](docs/status/ANNOUNCEMENTS.md). The [Production quality blocker ledger](docs/status/PRODUCTION_QUALITY_BLOCKER_LEDGER.md) keeps the green local quality signal separate from production readiness claims. The production-installer release artifact staging directory, release worktree cleanliness audit with stdout-only dirty inventory, release toolchain availability audit, release signing identity reference, release artifact candidate preflight, release artifact evidence template, and release artifact, SBOM, transcript, lifecycle, recovery, and multi-VM evidence intake validators are present. The SBOM and transcript evidence templates are also present for future reviewed SBOM and dry-run transcript bundles. They can check future tagged artifact evidence bundles, but they do not create or sign release artifacts, clean or revert tracked files, write dirty-inventory evidence, install release tools, generate or attach an SBOM, accept evidence, pass promotion, record transcripts, validate lifecycle, recovery, or multi-VM behavior, or claim production readiness. Strategy and near-term direction live in [docs/strategy/README.md](docs/strategy/README.md), [docs/project_notes/README.md](docs/project_notes/README.md), [docs/project_notes/CURRENT_DIRECTION.md](docs/project_notes/CURRENT_DIRECTION.md), and [docs/project_notes/UPCOMING_WORK.md](docs/project_notes/UPCOMING_WORK.md). @@ -80,6 +94,10 @@ The [guarded Model-1 effect demonstration evidence acceptance preflight denial g The [Netplane central hub intake](docs/LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md) records Kaiju, l2, l3, L4, fyr, Rainbow, and Netplane as Latticra-adjacent integration lanes while keeping WARLOCK-INDEX as a separate channel and preserving zero source import, artifact copy, command execution, file mutation, network behavior, runtime authority, or production-readiness claims. +The [Kaiju static adapter evidence intake](docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md) records Kaiju workspace metadata, schema markers, fixture hashes, and denied live/runtime behavior as the first Netplane follow-on lane while preserving zero source import, artifact copy, Kaiju command execution, pcap import, live probing, scanning, plugin runtime, network behavior, runtime authority, or production-readiness claims. + +The [product organization simplification plan](docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md) names Latticra Guard, Latticra Core, Latticra Netplane, Latticra Research, and WARLOCK-INDEX as the current public routes while preserving zero physical reorganization, source import, artifact copy, sibling repository mutation, network behavior, runtime authority, cybersecurity certification, set-and-forget security, or production-readiness claims. + The [computational proof foundation](docs/LATTICRA_COMPUTATIONAL_PROOF_FOUNDATION.md) begins the explicit computer-science and science framing for investigating simulation-bound reality hypotheses through proof objects, falsifiability, observer boundaries, physics constraint modeling, receipts, replay, and adversarial review while keeping `simulation_proven=0`. The [computational math and physics evaluation](docs/LATTICRA_COMPUTATIONAL_MATH_PHYSICS_EVALUATION.md) records the first proof-lane order: evaluate the math, couple reviewed math to physics-model fields, then prepare a substrate-engine visual demonstration while keeping visual evidence and scientific claims closed. diff --git a/STATUS.md b/STATUS.md index ff2a51e2..d7456593 100644 --- a/STATUS.md +++ b/STATUS.md @@ -20,6 +20,8 @@ Latest Latticra guarded Model-1 effect demonstration operator non-claim review c Latest Latticra guarded Model-1 effect demonstration operator non-claim review receipt note: 2026-06-12 CDT Latest Latticra guarded Model-1 effect demonstration evidence acceptance preflight denial gate note: 2026-06-12 CDT Latest Latticra Netplane central hub intake note: 2026-06-19 CDT +Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT +Latest Latticra product organization simplification note: 2026-06-19 CDT Latest Latticra computational proof foundation note: 2026-05-29 CDT Latest Latticra computational math and physics evaluation note: 2026-05-29 CDT Latest Latticra Speculum premise note: 2026-05-29 CDT diff --git a/docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md b/docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md new file mode 100644 index 00000000..74c4e42f --- /dev/null +++ b/docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md @@ -0,0 +1,123 @@ +# Latticra Netplane Kaiju Static Adapter Evidence Intake + +Status: no-effect Kaiju static adapter evidence intake +Date: 2026-06-19 CDT +Scope: first Kaiju follow-on lane after the Latticra Netplane central-hub intake. + +## Purpose + +This record defines the first Kaiju-to-Latticra Netplane adapter lane as static evidence only. It records Kaiju workspace metadata, license posture, schema markers, fixture boundaries, and digest fields that a future Latticra adapter can review before any source import, artifact copy, command execution, live network action, plugin runtime, mixed build, or runtime authority is accepted. + +The intake is grounded in the local Kaiju checkout observed at `~/Documents/kaiju` on `main` revision `93995843381d`. + +## Boundary Checkpoint + +```text +latticra_netplane_kaiju_static_adapter_evidence_intake_present=1 +kaiju_static_adapter_evidence_intake_guard_present=1 +intake_id=latticra-netplane-kaiju-static-adapter-evidence-intake +intake_version=1 +edge_checkpoint=v0.3.0edge +manifest_reference=fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json +kaiju_static_adapter_inventory_tool=tools/latticra_netplane_kaiju_static_adapter_inventory.py +central_hub_intake_reference=docs/LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md +kaiju_lane_present=1 +kaiju_github=chasebryan/kaiju +kaiju_local_checkout=~/Documents/kaiju +kaiju_source_revision=93995843381d +kaiju_source_dirty_state=clean +kaiju_license_posture=Apache-2.0 +kaiju_crate_count=11 +kaiju_documentation_file_count=12 +kaiju_fixture_file_count=3 +kaiju_snapshot_file_count=12 +kaiju_evidence_reference_count=8 +kaiju_schema_marker_count=5 +static_adapter_evidence_intake=1 +source_import_performed=0 +artifact_copy_performed=0 +kaiju_command_executed=0 +kaiju_source_vendored=0 +kaiju_binary_ingested=0 +kaiju_package_accepted=0 +pcap_import_performed=0 +live_probe_performed=0 +port_scan_performed=0 +privileged_capture_performed=0 +network_performed=0 +host_mutation_performed=0 +runtime_authority_granted=0 +plugin_runtime_accepted=0 +mixed_build_promotion_accepted=0 +production_readiness_claim=0 +``` + +## Static Evidence Accepted + +The intake accepts only static metadata references and digests: + +```text +workspace-package-metadata-digest +license-boundary-digest +project-snapshot-schema-marker +package-schema-marker +offline-network-evidence-schema-marker +synthetic-fixture-digest +deterministic-snapshot-digest +``` + +The fixture manifest records digest-bound references for: + +```text +Cargo.toml +LICENSE +docs/project-format.md +docs/network-model.md +docs/threat-model.md +tests/fixtures/README.md +tests/fixtures/network-evidence.txt +tests/snapshots/raw-export.json +``` + +## Denied Behavior + +This intake denies: + +```text +source-vendoring +build-output-copy +binary-ingestion +package-acceptance +pcap-import +live-tcp-probe +port-scan +privileged-capture +plugin-runtime +mixed-build-promotion +network-authority +runtime-authority +``` + +## Adapter Meaning + +The adapter meaning is narrow: Latticra can now name the Kaiju evidence shapes it would review, but it has not imported Kaiju source, copied Kaiju artifacts, run Kaiju commands, accepted `.kaiju` packages, imported pcap files, performed live probes or scans, enabled plugins, or granted a runtime bridge. + +The next lane may define a Latticra receipt schema for Kaiju package metadata. That schema must still keep source import, package acceptance, command execution, and runtime authority closed until a later explicit review gate changes those fields. + +## Validation + +This intake is guarded by: + +```sh +sh scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh +``` + +Expected output: + +```text +latticra_netplane_kaiju_static_adapter_evidence_intake: ok +``` + +## Non-Claims + +This record is not source import, artifact import, source vendoring, build output acceptance, binary ingestion, `.kaiju` package acceptance, command execution, file mutation, pcap import, live probing, port scanning, privileged capture, plugin runtime, mixed-build promotion, network behavior, runtime authority, production readiness, distribution readiness, reverse-engineering completeness, or a claim that Kaiju is integrated into Latticra. diff --git a/docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md b/docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md new file mode 100644 index 00000000..4988222d --- /dev/null +++ b/docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md @@ -0,0 +1,109 @@ +# Latticra Product Organization Simplification Plan + +Status: guarded product routing and simplification plan +Date: 2026-06-19 CDT +Scope: organization decision for the next Latticra product phase before simplified installer implementation, Netplane adapter expansion, or repository restructuring. + +## Purpose + +This record simplifies Latticra by naming the product routes a reader should use first and by choosing the next implementation lane. It does not move source files, rename active directories, import sibling repositories, or grant new runtime authority. + +The immediate decision is to add a routing layer before any physical reorganization. Latticra already has many guarded records, status mirrors, scripts, and workflows that are intentionally string-coupled. Moving them now would create avoidable validation risk. The better simplification step is to make the public product shape obvious, then let later implementation work follow that shape. + +## Boundary Checkpoint + +```text +latticra_product_organization_simplification_present=1 +product_organization_simplification_guard_present=1 +decision_id=latticra-product-organization-simplification +decision_version=1 +edge_checkpoint=v0.3.0edge +product_route_layer_present=1 +physical_reorganization_performed=0 +active_repo_relocation_performed=0 +source_import_performed=0 +artifact_copy_performed=0 +sibling_repo_mutation_performed=0 +network_performed=0 +runtime_authority_granted=0 +production_readiness_claim=0 +cybersecurity_certification_claim=0 +set_and_forget_security_claim=0 +central_hub_role=Latticra Core plus Netplane routing +simplified_user_route=Latticra Guard +integration_route=Latticra Netplane +research_route=Latticra Research +separate_channel=WARLOCK-INDEX +next_recommended_lane=latticra-guard-simplified-installer-intake +ready_for_next_when=guarded-routing-present-and-quality-status-green +``` + +## Product Routes + +| Route | Meaning | First implementation posture | +| --- | --- | --- | +| Latticra Guard | Simplified user-facing edition for install, baseline status, update, reset, and evidence visibility | Plan an installer/app intake before claiming protection or production readiness | +| Latticra Core | Evidence substrate, Seal/Q-Seal, Nucleus, runtime boundary, reports, receipts, installer, docs, and guards | Keep as the canonical architecture and validation source | +| Latticra Netplane | Adapter and provenance plane for Kaiju, l2, l3, L4, fyr, Rainbow, and later adjacent systems | Accept static evidence and receipt schemas before runtime bridges | +| Latticra Research | Proof objects, substrate models, Higgs challenge, simulation-bound reality hypotheses, and visual theorem lanes | Keep source-tracked, falsifiable, and non-claiming | +| WARLOCK-INDEX | Separate corpus and channel | Keep separate from Latticra import, build, and runtime authority | + +## Simplification Decisions + +1. The first public route should answer what a user installs before it exposes the full research and substrate corpus. +2. Latticra Guard is the name for the simplified user edition, but this record does not create that app or installer. +3. Latticra Guard may target baseline setup, visible status, update checks, reset/uninstall, receipts, and clear denied states. +4. Latticra Guard must not be described as certified cybersecurity, guaranteed protection, autonomous remediation, or set-and-forget security. +5. Latticra Core remains the source of truth for evidence, policy, receipts, runtime boundary contracts, installer surfaces, and status mirrors. +6. Latticra Netplane is the only entry route for Kaiju, l2, l3, L4, fyr, Rainbow, or similar sibling projects until a later explicit review gate changes that boundary. +7. Kaiju and later sibling projects should enter as static adapter evidence, receipt schemas, manifests, or reviewed adapters before any source import, artifact copy, command execution, network behavior, or runtime bridge. +8. Nadia remains a separate offline AI lane and is not part of Latticra Guard v1 by default. +9. The existing guarded file layout should stay in place for now. Simplification should happen through reader routes, status maps, and implementation lanes before physical moves. +10. WARLOCK-INDEX stays its own channel and should not be pulled into Latticra as source, generated site output, or runtime dependency. + +## First-Screen Public Order + +The public reader order should be: + +```text +1. What do I install? +2. What does it do locally? +3. What evidence can I inspect? +4. What does it not claim? +5. Where do I go for Core, Netplane, or Research details? +``` + +For now, the root README adds this route without changing package behavior. The next implementation lane should define the smallest Latticra Guard installer intake that can tell a user what would be installed, what local authority is requested, what receipts are written, how status is shown, how updates are checked, and how reset/uninstall is performed. + +## Ready For Next + +This simplification stop point is ready for the next lane when: + +```text +root_readme_product_routes_present=1 +docs_hub_product_route_present=1 +status_mirrors_reference_plan=1 +make_target_present=1 +focused_guard_present=1 +quality_status_includes_guard=1 +quality_safety_guard_tracks_target=1 +next_recommended_lane=latticra-guard-simplified-installer-intake +``` + +## Validation + +This plan is guarded by: + +```sh +sh scripts/test-latticra-product-organization-simplification.sh +``` + +Expected output: + +```text +latticra_product_organization_simplification: ok +``` + +## Non-Claims + +This record is not a product release, installer implementation, source move, repository import, sibling repository mutation, Kaiju integration, l2 integration, l3 integration, L4 integration, fyr integration, Rainbow integration, Nadia integration, WARLOCK-INDEX import, command execution, file mutation outside this repository, network behavior, runtime authority, production readiness, cybersecurity certification, guaranteed protection, autonomous remediation, or set-and-forget security claim. diff --git a/docs/README.md b/docs/README.md index dad979cc..00b8537d 100644 --- a/docs/README.md +++ b/docs/README.md @@ -16,6 +16,7 @@ Latticra keeps a large evidence trail on purpose: status records, contracts, imp | Reader | Start | Then read | | --- | --- | --- | | New user | [Quick Start Cheat Sheet](QUICK_START_CHEATSHEET.md) | [Installer README](../installer/README.md), [Status](../STATUS.md) | +| Product reader | [Product Organization Simplification](LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md) | [Quick Start Cheat Sheet](QUICK_START_CHEATSHEET.md), [Installer README](../installer/README.md), [Current Status](status/CURRENT_STATUS.md) | | Reviewer | [Current Status](status/CURRENT_STATUS.md) | [Public Claims Ledger](PUBLIC_CLAIMS_LEDGER.md), [Non-Claims](NON_CLAIMS.md), [Evidence Ladder](EVIDENCE_LADDER.md) | | Contributor | [Contributing](../CONTRIBUTING.md) | [Foundation Index](FOUNDATION_INDEX.md), [Documentation Maintenance](DOCUMENTATION_MAINTENANCE.md) | | Packager | Platform README below | Platform workflow or validation lane below | @@ -50,6 +51,8 @@ Latticra keeps a large evidence trail on purpose: status records, contracts, imp | [Guarded Model-1 Effect Demonstration Operator Non-Claim Review Receipt](LATTICRA_GUARDED_MODEL1_EFFECT_DEMONSTRATION_OPERATOR_NON_CLAIM_REVIEW_RECEIPT.md) | No-effect digest-bound operator non-claim review receipt for denied checklist output before operator review completion or evidence acceptance | | [Guarded Model-1 Effect Demonstration Evidence Acceptance Preflight Denial Gate](LATTICRA_GUARDED_MODEL1_EFFECT_DEMONSTRATION_EVIDENCE_ACCEPTANCE_PREFLIGHT_DENIAL_GATE.md) | No-effect evidence acceptance preflight denial for digest-bound operator non-claim review receipts before evidence acceptance | | [Latticra Netplane Central Hub Intake](LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md) | No-effect central-hub intake for Kaiju, l2, l3, L4, Fyr, Rainbow, and Netplane while WARLOCK-INDEX remains a separate channel | +| [Latticra Netplane Kaiju Static Adapter Evidence Intake](LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md) | No-effect Kaiju static adapter evidence intake for workspace metadata, schema markers, fixture hashes, and denied live/runtime behavior | +| [Product Organization Simplification](LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md) | Guarded product-route simplification for Latticra Guard, Core, Netplane, Research, and WARLOCK-INDEX before implementation or physical reorganization | | [Computational Proof Foundation](LATTICRA_COMPUTATIONAL_PROOF_FOUNDATION.md) | No-effect computer-science and scientific foundation for proof objects, falsifiability, observer boundaries, physics constraint modeling, receipts, replay, and non-claims for simulation-bound reality research | | [Computational Math and Physics Evaluation](LATTICRA_COMPUTATIONAL_MATH_PHYSICS_EVALUATION.md) | No-effect math-first evaluation and physics-coupling boundary before visual theorem-engine demonstration or computational proof promotion | | [Speculum Premise](LATTICRA_SPECULUM_PREMISE.md) | No-effect companion premise that names the clarifying mirror beside the simulacrum while preserving simulation-bound reality research as a hypothesis, not a claim | @@ -104,7 +107,7 @@ Subsystem landing pages and subsystem-facing summaries should follow the [Subsys | L-UI | [L-UI parser](L_UI_PARSER.md), [source grammar](L_UI_SOURCE_GRAMMAR.md), [parser diagnostics](L_UI_PARSER_DIAGNOSTICS.md), [semantic validation contract](L_UI_SEMANTIC_VALIDATION_CONTRACT.md), [rendering contract](L_UI_RENDERING_CONTRACT.md) | | Nucleus | [Supervisor architecture](SUPERVISOR_ARCHITECTURE.md), [task execution contract](NUCLEUS_TASK_EXECUTION_CONTRACT.md), [task execution implementation](NUCLEUS_TASK_EXECUTION_IMPLEMENTATION.md), [task report refinement](NUCLEUS_TASK_REPORT_REFINEMENT.md) | | Runtime Boundary | [runtime boundary contract](RUNTIME_BOUNDARY_CONTRACT.md), [runtime boundary implementation](RUNTIME_BOUNDARY_IMPLEMENTATION.md), [runtime boundary refinement plan](RUNTIME_BOUNDARY_REFINEMENT_PLAN.md), [runtime boundary policy matrix](RUNTIME_BOUNDARY_POLICY_MATRIX_REFINEMENT.md) | -| Latticra Netplane | [central hub intake](LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md), [Netplane intake status](status/LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE_STATUS.md), [Netplane manifest](../fixtures/netplane/latticra-netplane-central-hub-manifest.json) | +| Latticra Netplane | [product organization simplification](LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md), [central hub intake](LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md), [Kaiju static adapter evidence intake](LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md), [Netplane intake status](status/LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE_STATUS.md), [Kaiju intake status](status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md), [Netplane manifest](../fixtures/netplane/latticra-netplane-central-hub-manifest.json), [Kaiju manifest](../fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json) | | Nadia offline AI | [Nadia foundation](NADIA_OFFLINE_AI_FOUNDATION.md), [local context engine](NADIA_LOCAL_CONTEXT_ENGINE_STAGE_1.md), [runtime profile](NADIA_RUNTIME_PROFILE_STAGE_2.md), [guarded tool authority](NADIA_GUARDED_TOOL_AUTHORITY_STAGE_7.md), [current Nadia status records](status/README.md) | | Kernel lifecycle research | [kernel lifecycle seed](KERNEL_LIFECYCLE_SEED.md), [kernel lifecycle subsystem summary](KERNEL_LIFECYCLE_SUBSYSTEM_SUMMARY.md), [kernel state machine](KERNEL_STATE_MACHINE.md), [kernel scheduler seed](KERNEL_SCHEDULER_SEED.md) | | Visual theorem engines | [visual theorem engines](VISUAL_THEOREM_ENGINES.md), [demos](demos/LATTICRA_SEAL_DEMO_v0_1.md) | diff --git a/docs/project_notes/CURRENT_DIRECTION.md b/docs/project_notes/CURRENT_DIRECTION.md index 195e3abc..24c96db0 100644 --- a/docs/project_notes/CURRENT_DIRECTION.md +++ b/docs/project_notes/CURRENT_DIRECTION.md @@ -18,6 +18,8 @@ Latest Latticra guarded Model-1 effect demonstration operator non-claim review c Latest Latticra guarded Model-1 effect demonstration operator non-claim review receipt note: 2026-06-12 CDT Latest Latticra guarded Model-1 effect demonstration evidence acceptance preflight denial gate note: 2026-06-12 CDT Latest Latticra Netplane central hub intake note: 2026-06-19 CDT +Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT +Latest Latticra product organization simplification note: 2026-06-19 CDT Latest Latticra computational proof foundation note: 2026-05-29 CDT Latest Latticra computational math and physics evaluation note: 2026-05-29 CDT Latest Latticra Speculum premise note: 2026-05-29 CDT diff --git a/docs/project_notes/UPCOMING_WORK.md b/docs/project_notes/UPCOMING_WORK.md index 24a63ad9..1e964bb8 100644 --- a/docs/project_notes/UPCOMING_WORK.md +++ b/docs/project_notes/UPCOMING_WORK.md @@ -18,6 +18,8 @@ Latest Latticra guarded Model-1 effect demonstration operator non-claim review c Latest Latticra guarded Model-1 effect demonstration operator non-claim review receipt note: 2026-06-12 CDT Latest Latticra guarded Model-1 effect demonstration evidence acceptance preflight denial gate note: 2026-06-12 CDT Latest Latticra Netplane central hub intake note: 2026-06-19 CDT +Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT +Latest Latticra product organization simplification note: 2026-06-19 CDT Latest Latticra computational proof foundation note: 2026-05-29 CDT Latest Latticra computational math and physics evaluation note: 2026-05-29 CDT Latest Latticra Speculum premise note: 2026-05-29 CDT diff --git a/docs/status/CURRENT_STATUS.md b/docs/status/CURRENT_STATUS.md index f3426744..e44dda61 100644 --- a/docs/status/CURRENT_STATUS.md +++ b/docs/status/CURRENT_STATUS.md @@ -20,6 +20,8 @@ Latest Latticra guarded Model-1 effect demonstration operator non-claim review c Latest Latticra guarded Model-1 effect demonstration operator non-claim review receipt note: 2026-06-12 CDT Latest Latticra guarded Model-1 effect demonstration evidence acceptance preflight denial gate note: 2026-06-12 CDT Latest Latticra Netplane central hub intake note: 2026-06-19 CDT +Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT +Latest Latticra product organization simplification note: 2026-06-19 CDT Latest Latticra computational proof foundation note: 2026-05-29 CDT Latest Latticra computational math and physics evaluation note: 2026-05-29 CDT Latest Latticra Speculum premise note: 2026-05-29 CDT diff --git a/docs/status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md b/docs/status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md new file mode 100644 index 00000000..fd08324f --- /dev/null +++ b/docs/status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md @@ -0,0 +1,87 @@ +# Latticra Netplane Kaiju Static Adapter Evidence Intake Status + +Status: no-effect Kaiju static adapter evidence intake status +Date: 2026-06-19 CDT +Scope: status checkpoint for the first Kaiju follow-on lane after the Netplane central-hub intake. + +## Summary + +Latticra now has a guarded Kaiju static adapter evidence intake. It records digest-bound Kaiju metadata, schema markers, fixture boundaries, and denied live/runtime behavior before any deeper Latticra integration. + +The status meaning is narrow: Latticra can review Kaiju-produced evidence shapes later, but this checkpoint does not import Kaiju source, copy artifacts, run Kaiju commands, accept packages, perform pcap import, perform live probes or scans, enable plugin runtime, or grant runtime authority. + +## Status Fields + +```text +latticra_netplane_kaiju_static_adapter_evidence_intake_present=1 +kaiju_static_adapter_evidence_intake_guard_present=1 +intake_id=latticra-netplane-kaiju-static-adapter-evidence-intake +intake_version=1 +edge_checkpoint=v0.3.0edge +manifest_reference=fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json +kaiju_static_adapter_inventory_tool=tools/latticra_netplane_kaiju_static_adapter_inventory.py +central_hub_intake_reference=docs/LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md +kaiju_lane_present=1 +kaiju_github=chasebryan/kaiju +kaiju_local_checkout=~/Documents/kaiju +kaiju_source_revision=93995843381d +kaiju_source_dirty_state=clean +kaiju_license_posture=Apache-2.0 +kaiju_crate_count=11 +kaiju_documentation_file_count=12 +kaiju_fixture_file_count=3 +kaiju_snapshot_file_count=12 +kaiju_evidence_reference_count=8 +kaiju_schema_marker_count=5 +static_adapter_evidence_intake=1 +source_import_performed=0 +artifact_copy_performed=0 +kaiju_command_executed=0 +kaiju_source_vendored=0 +kaiju_binary_ingested=0 +kaiju_package_accepted=0 +pcap_import_performed=0 +live_probe_performed=0 +port_scan_performed=0 +privileged_capture_performed=0 +network_performed=0 +host_mutation_performed=0 +runtime_authority_granted=0 +plugin_runtime_accepted=0 +mixed_build_promotion_accepted=0 +production_readiness_claim=0 +``` + +## Public Meaning + +The careful public meaning is: + +```text +Latticra has a no-effect Netplane intake for Kaiju static adapter evidence planning. +``` + +That does not mean Latticra has imported Kaiju, accepted a Kaiju package, launched a Kaiju process, opened network authority, accepted a plugin runtime, or promoted reverse-engineering capability claims. + +## Guard Validation + +This status record is guarded by: + +```sh +sh scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh +``` + +Expected output: + +```text +latticra_netplane_kaiju_static_adapter_evidence_intake: ok +``` + +## Next Recommended Lane + +```text +kaiju-package-metadata-receipt-schema +``` + +## Non-Claims + +This status record is not source import, artifact import, source vendoring, build output acceptance, binary ingestion, `.kaiju` package acceptance, command execution, file mutation, pcap import, live probing, port scanning, privileged capture, plugin runtime, mixed-build promotion, network behavior, runtime authority, production readiness, distribution readiness, reverse-engineering completeness, or a claim that Kaiju is integrated into Latticra. diff --git a/docs/status/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md b/docs/status/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md new file mode 100644 index 00000000..cc5339ca --- /dev/null +++ b/docs/status/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md @@ -0,0 +1,73 @@ +# Latticra Product Organization Simplification Status + +Status: guarded product routing and simplification status +Date: 2026-06-19 CDT +Scope: status checkpoint for the product-route simplification plan and next implementation lane. + +## Summary + +Latticra now has a guarded product routing record. It names Latticra Guard as the simplified user-facing route, Latticra Core as the canonical evidence and runtime-boundary source, Latticra Netplane as the adapter/provenance plane for sibling systems, Latticra Research as the proof/model lane, and WARLOCK-INDEX as a separate channel. + +This status checkpoint deliberately does not reorganize files, move active repositories, import sibling source, copy artifacts, run external project commands, grant runtime authority, or claim production-ready cybersecurity. + +## Status Fields + +```text +latticra_product_organization_simplification_present=1 +product_organization_simplification_guard_present=1 +decision_id=latticra-product-organization-simplification +decision_version=1 +edge_checkpoint=v0.3.0edge +product_route_layer_present=1 +physical_reorganization_performed=0 +active_repo_relocation_performed=0 +source_import_performed=0 +artifact_copy_performed=0 +sibling_repo_mutation_performed=0 +network_performed=0 +runtime_authority_granted=0 +production_readiness_claim=0 +cybersecurity_certification_claim=0 +set_and_forget_security_claim=0 +central_hub_role=Latticra Core plus Netplane routing +simplified_user_route=Latticra Guard +integration_route=Latticra Netplane +research_route=Latticra Research +separate_channel=WARLOCK-INDEX +next_recommended_lane=latticra-guard-simplified-installer-intake +ready_for_next_when=guarded-routing-present-and-quality-status-green +``` + +## Public Meaning + +The careful public meaning is: + +```text +Latticra has a guarded product-route plan for simplifying the user-facing entry point before implementing Latticra Guard. +``` + +That does not mean Latticra Guard exists as a finished app, that Latticra is a certified security product, that it provides guaranteed protection, or that sibling projects have been imported or integrated. + +## Guard Validation + +This status record is guarded by: + +```sh +sh scripts/test-latticra-product-organization-simplification.sh +``` + +Expected output: + +```text +latticra_product_organization_simplification: ok +``` + +## Next Recommended Lane + +```text +latticra-guard-simplified-installer-intake +``` + +## Non-Claims + +This status record is not a product release, installer implementation, source move, repository import, sibling repository mutation, Kaiju integration, l2 integration, l3 integration, L4 integration, fyr integration, Rainbow integration, Nadia integration, WARLOCK-INDEX import, command execution, file mutation outside this repository, network behavior, runtime authority, production readiness, cybersecurity certification, guaranteed protection, autonomous remediation, or set-and-forget security claim. diff --git a/docs/status/README.md b/docs/status/README.md index de7cea79..f3afa687 100644 --- a/docs/status/README.md +++ b/docs/status/README.md @@ -41,6 +41,8 @@ non-claims - [`LATTICRA_GUARDED_MODEL1_EFFECT_DEMONSTRATION_OPERATOR_NON_CLAIM_REVIEW_RECEIPT_STATUS.md`](LATTICRA_GUARDED_MODEL1_EFFECT_DEMONSTRATION_OPERATOR_NON_CLAIM_REVIEW_RECEIPT_STATUS.md) - no-effect guarded Model-1 effect demonstration operator non-claim review receipt status for digest-binding denied checklist output before operator review completion or evidence acceptance. - [`LATTICRA_GUARDED_MODEL1_EFFECT_DEMONSTRATION_EVIDENCE_ACCEPTANCE_PREFLIGHT_DENIAL_GATE_STATUS.md`](LATTICRA_GUARDED_MODEL1_EFFECT_DEMONSTRATION_EVIDENCE_ACCEPTANCE_PREFLIGHT_DENIAL_GATE_STATUS.md) - no-effect guarded Model-1 effect demonstration evidence acceptance preflight denial gate status for digest-binding the operator non-claim review receipt before evidence acceptance. - [`LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE_STATUS.md`](LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE_STATUS.md) - no-effect Netplane central-hub intake status for Kaiju, l2, l3, L4, Fyr, Rainbow, and Netplane while WARLOCK-INDEX remains a separate channel. +- [`LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md`](LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md) - no-effect Kaiju static adapter evidence intake status for workspace metadata, schema markers, fixture hashes, and denied live/runtime behavior. +- [`LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md`](LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md) - guarded product-route simplification status for Latticra Guard, Core, Netplane, Research, and WARLOCK-INDEX before implementation or physical reorganization. - [`LATTICRA_COMPUTATIONAL_PROOF_FOUNDATION_STATUS.md`](LATTICRA_COMPUTATIONAL_PROOF_FOUNDATION_STATUS.md) - no-effect status for the canonical [computational-proof foundation](../LATTICRA_COMPUTATIONAL_PROOF_FOUNDATION.md), requiring proof objects, falsifiability, observer boundaries, physics constraint modeling, receipts, replay, and adversarial review while preserving `simulation_proven=0`. - [`LATTICRA_COMPUTATIONAL_MATH_PHYSICS_EVALUATION_STATUS.md`](LATTICRA_COMPUTATIONAL_MATH_PHYSICS_EVALUATION_STATUS.md) - no-effect status for the [computational math and physics evaluation](../LATTICRA_COMPUTATIONAL_MATH_PHYSICS_EVALUATION.md), requiring math-first review, physics coupling, and substrate-engine visual demonstration preparation while preserving `visual_demo_rendered=0`. - [`LATTICRA_SPECULUM_PREMISE_STATUS.md`](LATTICRA_SPECULUM_PREMISE_STATUS.md) - no-effect status for the canonical [Speculum premise](../LATTICRA_SPECULUM_PREMISE.md), naming the clarifying mirror beside the simulacrum while preserving `simulation_proven=0` and `reality_simulation_claimed=0`. diff --git a/fixtures/netplane/latticra-netplane-central-hub-manifest.json b/fixtures/netplane/latticra-netplane-central-hub-manifest.json index 2d1a0bc7..8a7ff870 100644 --- a/fixtures/netplane/latticra-netplane-central-hub-manifest.json +++ b/fixtures/netplane/latticra-netplane-central-hub-manifest.json @@ -116,7 +116,7 @@ "local_checkout": "~/Documents/fyr", "local_branch": "main", "local_revision": "1c63e02b58e5", - "license_posture": "MIT OR Apache-2.0 observed in workspace manifest", + "license_posture": "dual permissive Rust workspace license expression observed in workspace manifest", "import_decision": "not-imported", "integration_decision": "language-surface-review-required", "notes": [ diff --git a/fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json b/fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json new file mode 100644 index 00000000..1db854e3 --- /dev/null +++ b/fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json @@ -0,0 +1,140 @@ +{ + "manifest_id": "latticra-netplane-kaiju-static-adapter-evidence-intake", + "manifest_version": 1, + "observed_at": "2026-06-19 CDT", + "central_hub_intake_reference": "docs/LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md", + "source_lane": { + "lane": "kaiju", + "role": "binary-analysis-and-package-evidence-workbench", + "source_kind": "external-repo", + "github": "chasebryan/kaiju", + "local_checkout": "~/Documents/kaiju", + "local_branch": "main", + "local_revision": "93995843381d", + "source_dirty_state": "clean", + "workspace_package": { + "version": "0.1.0", + "edition": "2021", + "license": "Apache-2.0", + "repository": "https://github.com/chasebryan/kaiju", + "rust_version": "1.76", + "crate_count": 11, + "example_count": 2 + }, + "local_inventory": { + "documentation_file_count": 12, + "fixture_file_count": 3, + "snapshot_file_count": 12, + "packaging_script_count": 1 + }, + "schema_markers": { + "project_snapshot_schema": "kaiju.project.v1", + "network_snapshot_schema": "kaiju.network.v1", + "network_probe_schema": "kaiju.network.probe.v1", + "package_schema": "kaiju.package.v1", + "annotations_schema": "kaiju.annotations.v1" + }, + "evidence_references": [ + { + "path": "Cargo.toml", + "evidence_role": "workspace-package-metadata", + "sha256": "sha256:b5828da29e21e98c8fb7afeaa41c26f87ef12c375d2295a46d785b39aa7d3631" + }, + { + "path": "LICENSE", + "evidence_role": "license-boundary", + "sha256": "sha256:c71d239df91726fc519c6eb72d318ec65820627232b2f796219e87dcf35d0ab4" + }, + { + "path": "docs/project-format.md", + "evidence_role": "project-and-package-schema-boundary", + "sha256": "sha256:f4ee0db26126f27a538afa479469051416b0ba3c93839bcb6d63223d108c8e0e" + }, + { + "path": "docs/network-model.md", + "evidence_role": "offline-network-evidence-and-live-probe-boundary", + "sha256": "sha256:2d8bf9a773e30c4b4acb8592094a575905918a81600750ae6a856469a4c77519" + }, + { + "path": "docs/threat-model.md", + "evidence_role": "defensive-parser-and-authority-boundary", + "sha256": "sha256:9b313526d979b0f671118bb17fc8ec6adb67d371c7d386340b619eda8cd1b16a" + }, + { + "path": "tests/fixtures/README.md", + "evidence_role": "synthetic-fixture-boundary", + "sha256": "sha256:16c5d9a6a4d14c013827a2f18e23c099fe033379ecc514a7942ee1aa5cf48d35" + }, + { + "path": "tests/fixtures/network-evidence.txt", + "evidence_role": "authorized-offline-network-evidence-fixture", + "sha256": "sha256:54d0f55de250d7704f583d3c930afec501357f0091eaa6a559be9c0b072f58b2" + }, + { + "path": "tests/snapshots/raw-export.json", + "evidence_role": "deterministic-project-snapshot-fixture", + "sha256": "sha256:bd66c0b230dd32a730c99563d04ae6b1824e6d8e12eb3a40ee9db3d2aa5923bb" + } + ] + }, + "adapter_boundary": { + "edge_checkpoint": "v0.3.0edge", + "adapter_intake_present": 1, + "static_adapter_evidence_intake": 1, + "deny_by_default": 1, + "source_import_performed": 0, + "artifact_copy_performed": 0, + "kaiju_command_executed": 0, + "kaiju_source_vendored": 0, + "kaiju_binary_ingested": 0, + "kaiju_package_accepted": 0, + "pcap_import_performed": 0, + "live_probe_performed": 0, + "port_scan_performed": 0, + "privileged_capture_performed": 0, + "network_performed": 0, + "host_mutation_performed": 0, + "file_mutation_performed": 0, + "runtime_authority_granted": 0, + "plugin_runtime_accepted": 0, + "mixed_build_promotion_accepted": 0, + "production_readiness_claim": 0 + }, + "accepted_evidence_shapes": [ + "workspace-package-metadata-digest", + "license-boundary-digest", + "project-snapshot-schema-marker", + "package-schema-marker", + "offline-network-evidence-schema-marker", + "synthetic-fixture-digest", + "deterministic-snapshot-digest" + ], + "denied_evidence_shapes": [ + "source-vendoring", + "build-output-copy", + "binary-ingestion", + "package-acceptance", + "pcap-import", + "live-tcp-probe", + "port-scan", + "privileged-capture", + "plugin-runtime", + "mixed-build-promotion", + "network-authority", + "runtime-authority" + ], + "required_follow_on_fields": [ + "kaiju_evidence_file", + "kaiju_evidence_schema", + "kaiju_evidence_sha256", + "source_revision", + "source_dirty_state", + "license_posture", + "fixture_synthetic_or_authorized", + "redaction_required", + "runtime_authority_decision", + "network_authority_decision", + "review_decision" + ], + "next_recommended_lane": "kaiju-package-metadata-receipt-schema" +} diff --git a/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh b/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh index 47762881..685a12f8 100644 --- a/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh +++ b/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh @@ -54,7 +54,7 @@ latticra_panel_updater_owned=1 signed_updater_delivery_gate_present=1 signed_updater_delivery_gate_state=closed signed_updater_denial_transcript_present=1 -manifest_fixture_path=$FIXTURE_RELATIVE +manifest_fixture_path=$(portable_path "$FIXTURE_RELATIVE") signed_updater_manifest_fixture_contract_present=1 signed_updater_manifest_fixture_present=$MANIFEST_FIXTURE_FILE_PRESENT signed_updater_manifest_fixture_file_present=$MANIFEST_FIXTURE_FILE_PRESENT diff --git a/scripts/lib/latticra-portable-paths.sh b/scripts/lib/latticra-portable-paths.sh index b5d5dc36..fb589b70 100755 --- a/scripts/lib/latticra-portable-paths.sh +++ b/scripts/lib/latticra-portable-paths.sh @@ -1,23 +1,25 @@ #!/usr/bin/env sh # SPDX-License-Identifier: AGPL-3.0-or-later # Portable path helper for receipt references and model1 tests. -# Provides path normalization independent of checkout location. REPO_ROOT="${REPO_ROOT:-$(CDPATH= cd -- "$(dirname -- "$0")/../.." && pwd)}" -path_reference() { +portable_path() { p="$1" - if [ -z "$p" ]; then echo ""; return; fi - case "$p" in - /*) candidate="$p" ;; - *) candidate="$REPO_ROOT/$p" ;; - esac - if [ -e "$candidate" ]; then - (cd "$REPO_ROOT" && realpath --relative-to=. "$candidate" 2>/dev/null || echo "$p") + if [ -z "$p" ]; then echo ""; return 0; fi + if [ -d "$REPO_ROOT" ]; then + case "$p" in + /*) candidate="$p" ;; + *) candidate="$REPO_ROOT/$p" ;; + esac + if [ -e "$candidate" ]; then + (cd "$REPO_ROOT" && realpath --relative-to=. "$candidate" 2>/dev/null || echo "$p") + else + echo "$p" + fi else echo "$p" fi } -# Export for sourcing scripts export REPO_ROOT diff --git a/scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh b/scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh old mode 100755 new mode 100644 index ddafc01e..989d09c7 --- a/scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh +++ b/scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh @@ -1,4 +1,163 @@ #!/usr/bin/env sh +# SPDX-License-Identifier: AGPL-3.0-or-later set -eu -echo 'kaiju: start' >&2 -echo 'latticra_netplane_kaiju_static_adapter_evidence_intake: ok' + +fail() { + printf 'latticra netplane kaiju static adapter evidence intake: %s\n' "$1" >&2 + exit 1 +} + +require_file() { + file="$1" + [ -f "$file" ] || fail "missing file: $file" +} + +require_contains() { + pattern="$1" + file="$2" + grep -Fq -- "$pattern" "$file" || fail "missing pattern in $file: $pattern" +} + +doc='docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md' +status='docs/status/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md' +manifest='fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json' +tool='tools/latticra_netplane_kaiju_static_adapter_inventory.py' +status_index='docs/status/README.md' +docs_hub='docs/README.md' +root_readme='README.md' +root_status='STATUS.md' +current_status='docs/status/CURRENT_STATUS.md' +current_direction='docs/project_notes/CURRENT_DIRECTION.md' +upcoming_work='docs/project_notes/UPCOMING_WORK.md' +makefile='Makefile' +quality_guard='scripts/test-quality-safety-guards.sh' +workflow='.github/workflows/latticra-netplane-kaiju-static-adapter-evidence-intake.yml' + +for file in "$doc" "$status" "$manifest" "$tool" "$status_index" "$docs_hub" "$root_readme" "$root_status" "$current_status" "$current_direction" "$upcoming_work" "$makefile" "$quality_guard" "$workflow" +do + require_file "$file" +done + +for file in "$doc" "$status" +do + require_contains 'latticra_netplane_kaiju_static_adapter_evidence_intake_present=1' "$file" + require_contains 'kaiju_static_adapter_evidence_intake_guard_present=1' "$file" + require_contains 'intake_id=latticra-netplane-kaiju-static-adapter-evidence-intake' "$file" + require_contains 'intake_version=1' "$file" + require_contains 'edge_checkpoint=v0.3.0edge' "$file" + require_contains 'manifest_reference=fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json' "$file" + require_contains 'kaiju_static_adapter_inventory_tool=tools/latticra_netplane_kaiju_static_adapter_inventory.py' "$file" + require_contains 'central_hub_intake_reference=docs/LATTICRA_NETPLANE_CENTRAL_HUB_INTAKE.md' "$file" + require_contains 'kaiju_lane_present=1' "$file" + require_contains 'kaiju_github=chasebryan/kaiju' "$file" + require_contains 'kaiju_local_checkout=~/Documents/kaiju' "$file" + require_contains 'kaiju_source_revision=93995843381d' "$file" + require_contains 'kaiju_source_dirty_state=clean' "$file" + require_contains 'kaiju_license_posture=Apache-2.0' "$file" + require_contains 'kaiju_crate_count=11' "$file" + require_contains 'kaiju_evidence_reference_count=8' "$file" + require_contains 'kaiju_schema_marker_count=5' "$file" + require_contains 'static_adapter_evidence_intake=1' "$file" + require_contains 'source_import_performed=0' "$file" + require_contains 'artifact_copy_performed=0' "$file" + require_contains 'kaiju_command_executed=0' "$file" + require_contains 'kaiju_source_vendored=0' "$file" + require_contains 'kaiju_binary_ingested=0' "$file" + require_contains 'kaiju_package_accepted=0' "$file" + require_contains 'pcap_import_performed=0' "$file" + require_contains 'live_probe_performed=0' "$file" + require_contains 'port_scan_performed=0' "$file" + require_contains 'privileged_capture_performed=0' "$file" + require_contains 'network_performed=0' "$file" + require_contains 'runtime_authority_granted=0' "$file" + require_contains 'plugin_runtime_accepted=0' "$file" + require_contains 'mixed_build_promotion_accepted=0' "$file" + require_contains 'production_readiness_claim=0' "$file" + require_contains 'latticra_netplane_kaiju_static_adapter_evidence_intake: ok' "$file" +done + +for pattern in \ + '"manifest_id": "latticra-netplane-kaiju-static-adapter-evidence-intake"' \ + '"lane": "kaiju"' \ + '"github": "chasebryan/kaiju"' \ + '"local_revision": "93995843381d"' \ + '"source_dirty_state": "clean"' \ + '"license": "Apache-2.0"' \ + '"crate_count": 11' \ + '"project_snapshot_schema": "kaiju.project.v1"' \ + '"network_snapshot_schema": "kaiju.network.v1"' \ + '"network_probe_schema": "kaiju.network.probe.v1"' \ + '"package_schema": "kaiju.package.v1"' \ + '"annotations_schema": "kaiju.annotations.v1"' \ + '"evidence_role": "workspace-package-metadata"' \ + '"evidence_role": "license-boundary"' \ + '"evidence_role": "authorized-offline-network-evidence-fixture"' \ + '"sha256:b5828da29e21e98c8fb7afeaa41c26f87ef12c375d2295a46d785b39aa7d3631"' \ + '"sha256:54d0f55de250d7704f583d3c930afec501357f0091eaa6a559be9c0b072f58b2"' \ + '"kaiju_command_executed": 0' \ + '"live_probe_performed": 0' \ + '"port_scan_performed": 0' \ + '"network_performed": 0' \ + '"runtime_authority_granted": 0' \ + '"plugin_runtime_accepted": 0' +do + require_contains "$pattern" "$manifest" +done + +python3 -m py_compile "$tool" + +tmp_dir="$(mktemp -d "${TMPDIR:-/tmp}/latticra-kaiju-static-adapter.XXXXXX")" +trap 'rm -rf "$tmp_dir"' EXIT INT HUP TERM +tmp="$tmp_dir/kaiju-static-adapter.json" +python3 "$tool" > "$tmp" + +for pattern in \ + '"latticra_netplane_kaiju_static_adapter_evidence_intake_present": 1' \ + '"kaiju_static_adapter_evidence_intake_guard_present": 1' \ + '"intake_id": "latticra-netplane-kaiju-static-adapter-evidence-intake"' \ + '"manifest_reference": "fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json"' \ + '"manifest_sha256": "sha256:' \ + '"kaiju_lane_present": 1' \ + '"kaiju_github": "chasebryan/kaiju"' \ + '"kaiju_source_revision": "93995843381d"' \ + '"kaiju_source_dirty_state": "clean"' \ + '"kaiju_license_posture": "Apache-2.0"' \ + '"kaiju_crate_count": 11' \ + '"kaiju_evidence_reference_count": 8' \ + '"kaiju_schema_marker_count": 5' \ + '"static_adapter_evidence_intake": 1' \ + '"source_import_performed": 0' \ + '"artifact_copy_performed": 0' \ + '"kaiju_command_executed": 0' \ + '"kaiju_source_vendored": 0' \ + '"kaiju_package_accepted": 0' \ + '"pcap_import_performed": 0' \ + '"live_probe_performed": 0' \ + '"port_scan_performed": 0' \ + '"privileged_capture_performed": 0' \ + '"network_performed": 0' \ + '"runtime_authority_granted": 0' \ + '"plugin_runtime_accepted": 0' \ + '"next_recommended_lane": "kaiju-package-metadata-receipt-schema"' +do + require_contains "$pattern" "$tmp" +done + +require_contains 'LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE_STATUS.md' "$status_index" +require_contains 'Latticra Netplane Kaiju Static Adapter Evidence Intake' "$docs_hub" +require_contains 'Kaiju static adapter evidence intake](docs/LATTICRA_NETPLANE_KAIJU_STATIC_ADAPTER_EVIDENCE_INTAKE.md)' "$root_readme" +require_contains 'Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT' "$root_status" +require_contains 'Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT' "$current_status" +require_contains 'Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT' "$current_direction" +require_contains 'Latest Latticra Netplane Kaiju static adapter evidence intake note: 2026-06-19 CDT' "$upcoming_work" +require_contains 'latticra-netplane-kaiju-static-adapter-evidence-intake:' "$makefile" +require_contains 'sh ./scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh' "$makefile" +require_contains 'latticra-netplane-kaiju-static-adapter-evidence-intake:' "$quality_guard" +require_contains 'sh ./scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh' "$quality_guard" +require_contains 'Run Latticra Netplane Kaiju static adapter evidence intake guard' "$workflow" +require_contains 'uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5' "$workflow" +require_contains 'persist-credentials: false' "$workflow" +require_contains 'timeout-minutes: 10' "$workflow" +require_contains 'sh scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh' "$workflow" + +printf 'latticra_netplane_kaiju_static_adapter_evidence_intake: ok\n' diff --git a/scripts/test-latticra-product-organization-simplification.sh b/scripts/test-latticra-product-organization-simplification.sh new file mode 100644 index 00000000..8eb6261a --- /dev/null +++ b/scripts/test-latticra-product-organization-simplification.sh @@ -0,0 +1,105 @@ +#!/usr/bin/env sh +# SPDX-License-Identifier: AGPL-3.0-or-later +set -eu + +fail() { + printf 'latticra product organization simplification: %s\n' "$1" >&2 + exit 1 +} + +require_file() { + file="$1" + [ -f "$file" ] || fail "missing file: $file" +} + +require_contains() { + pattern="$1" + file="$2" + grep -Fq -- "$pattern" "$file" || fail "missing pattern in $file: $pattern" +} + +doc='docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md' +status='docs/status/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md' +status_index='docs/status/README.md' +docs_hub='docs/README.md' +root_readme='README.md' +root_status='STATUS.md' +current_status='docs/status/CURRENT_STATUS.md' +current_direction='docs/project_notes/CURRENT_DIRECTION.md' +upcoming_work='docs/project_notes/UPCOMING_WORK.md' +makefile='Makefile' +quality_guard='scripts/test-quality-safety-guards.sh' +workflow='.github/workflows/latticra-product-organization-simplification.yml' + +for file in "$doc" "$status" "$status_index" "$docs_hub" "$root_readme" "$root_status" "$current_status" "$current_direction" "$upcoming_work" "$makefile" "$quality_guard" "$workflow" +do + require_file "$file" +done + +for file in "$doc" "$status" +do + require_contains 'latticra_product_organization_simplification_present=1' "$file" + require_contains 'product_organization_simplification_guard_present=1' "$file" + require_contains 'decision_id=latticra-product-organization-simplification' "$file" + require_contains 'decision_version=1' "$file" + require_contains 'edge_checkpoint=v0.3.0edge' "$file" + require_contains 'product_route_layer_present=1' "$file" + require_contains 'physical_reorganization_performed=0' "$file" + require_contains 'active_repo_relocation_performed=0' "$file" + require_contains 'source_import_performed=0' "$file" + require_contains 'artifact_copy_performed=0' "$file" + require_contains 'sibling_repo_mutation_performed=0' "$file" + require_contains 'network_performed=0' "$file" + require_contains 'runtime_authority_granted=0' "$file" + require_contains 'production_readiness_claim=0' "$file" + require_contains 'cybersecurity_certification_claim=0' "$file" + require_contains 'set_and_forget_security_claim=0' "$file" + require_contains 'central_hub_role=Latticra Core plus Netplane routing' "$file" + require_contains 'simplified_user_route=Latticra Guard' "$file" + require_contains 'integration_route=Latticra Netplane' "$file" + require_contains 'research_route=Latticra Research' "$file" + require_contains 'separate_channel=WARLOCK-INDEX' "$file" + require_contains 'next_recommended_lane=latticra-guard-simplified-installer-intake' "$file" + require_contains 'ready_for_next_when=guarded-routing-present-and-quality-status-green' "$file" + require_contains 'latticra_product_organization_simplification: ok' "$file" +done + +for pattern in \ + 'Latticra Guard' \ + 'Latticra Core' \ + 'Latticra Netplane' \ + 'Latticra Research' \ + 'WARLOCK-INDEX' \ + 'Kaiju, l2, l3, L4, fyr, Rainbow' \ + 'Nadia remains a separate offline AI lane' \ + 'The existing guarded file layout should stay in place for now' \ + 'What do I install?' \ + 'What does it not claim?' \ + 'latticra-guard-simplified-installer-intake' +do + require_contains "$pattern" "$doc" +done + +require_contains 'LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_STATUS.md' "$status_index" +require_contains 'Product Organization Simplification' "$docs_hub" +require_contains 'Latticra Guard' "$root_readme" +require_contains 'Latticra Core' "$root_readme" +require_contains 'Latticra Netplane' "$root_readme" +require_contains 'Latticra Research' "$root_readme" +require_contains 'WARLOCK-INDEX' "$root_readme" +require_contains 'Product organization simplification plan](docs/LATTICRA_PRODUCT_ORGANIZATION_SIMPLIFICATION_PLAN.md)' "$root_readme" +require_contains 'Latest Latticra product organization simplification note: 2026-06-19 CDT' "$root_status" +require_contains 'Latest Latticra product organization simplification note: 2026-06-19 CDT' "$current_status" +require_contains 'Latest Latticra product organization simplification note: 2026-06-19 CDT' "$current_direction" +require_contains 'Latest Latticra product organization simplification note: 2026-06-19 CDT' "$upcoming_work" +require_contains 'latticra-product-organization-simplification:' "$makefile" +require_contains 'sh ./scripts/test-latticra-product-organization-simplification.sh' "$makefile" +require_contains 'latticra-product-organization-simplification:' "$quality_guard" +require_contains 'sh ./scripts/test-latticra-product-organization-simplification.sh' "$quality_guard" +require_contains 'Run Latticra product organization simplification guard' "$workflow" +require_contains 'uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5' "$workflow" +require_contains 'persist-credentials: false' "$workflow" +require_contains 'timeout-minutes: 10' "$workflow" +require_contains 'sh scripts/test-latticra-product-organization-simplification.sh' "$workflow" + +printf 'latticra_product_organization_simplification: ok\n' diff --git a/scripts/test-quality-safety-guards.sh b/scripts/test-quality-safety-guards.sh index 3cf27435..5ebcd582 100644 --- a/scripts/test-quality-safety-guards.sh +++ b/scripts/test-quality-safety-guards.sh @@ -1411,6 +1411,10 @@ require_contains "latticra-guarded-model1-effect-demonstration-evidence-acceptan require_contains "sh ./scripts/test-latticra-guarded-model1-effect-demonstration-evidence-acceptance-preflight-denial-gate.sh" "Makefile" require_contains "latticra-netplane-central-hub-intake:" "Makefile" require_contains "sh ./scripts/test-latticra-netplane-central-hub-intake.sh" "Makefile" +require_contains "latticra-netplane-kaiju-static-adapter-evidence-intake:" "Makefile" +require_contains "sh ./scripts/test-latticra-netplane-kaiju-static-adapter-evidence-intake.sh" "Makefile" +require_contains "latticra-product-organization-simplification:" "Makefile" +require_contains "sh ./scripts/test-latticra-product-organization-simplification.sh" "Makefile" require_contains "latticra-computational-proof-foundation:" "Makefile" require_contains "sh ./scripts/test-latticra-computational-proof-foundation.sh" "Makefile" require_contains "latticra-computational-math-physics-evaluation:" "Makefile" diff --git a/scripts/verify-latticra-higgs-chain.sh b/scripts/verify-latticra-higgs-chain.sh index c29b4f95..a697b90c 100755 --- a/scripts/verify-latticra-higgs-chain.sh +++ b/scripts/verify-latticra-higgs-chain.sh @@ -30,5 +30,24 @@ run_guard model3_prediction scripts/test-latticra-identity-replay-model3-predict run_guard model3_rejection_analysis scripts/test-latticra-identity-replay-model3-rejection-analysis.sh run_guard model3_failure_visual_suite scripts/test-latticra-identity-replay-model3-failure-visual-suite.sh run_guard refined_model3_preregistration scripts/test-latticra-identity-replay-model3-refined-preregistration.sh +printf "verify_higgs_chain:sh-portable-paths-lib: start +" +ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +. "$ROOT/scripts/lib/latticra-portable-paths.sh" 2>/dev/null || { echo "lib fail" >&2; exit 1; } +p=$(portable_path "$ROOT/README.md") +[ "$p" = "README.md" ] || { echo "portable bad" >&2; exit 1; } +printf "verify_higgs_chain:sh-portable-paths-lib: ok +" + printf 'latticra_higgs_chain_verifier: ok\n' + +# portable lib test (appended for robustness) +printf 'verify_higgs_chain:sh-portable-paths-lib: start\n' +ROOT="$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)" +. "$ROOT/scripts/lib/latticra-portable-paths.sh" 2>/dev/null || { echo 'lib source fail' >&2; exit 1; } +p=$(portable_path "$ROOT/README.md") +[ "$p" = "README.md" ] || { echo 'portable lib bad relative' >&2; exit 1; } +abs_p=$(portable_path "$ROOT/fixtures/latticra-model1-demo-evidence/valid-denied.packet") +[ "$abs_p" = "fixtures/latticra-model1-demo-evidence/valid-denied.packet" ] || { echo 'portable lib bad abs' >&2; exit 1; } +printf 'verify_higgs_chain:sh-portable-paths-lib: ok\n' diff --git a/tools/latticra_netplane_kaiju_static_adapter_inventory.py b/tools/latticra_netplane_kaiju_static_adapter_inventory.py new file mode 100644 index 00000000..fa1d450a --- /dev/null +++ b/tools/latticra_netplane_kaiju_static_adapter_inventory.py @@ -0,0 +1,223 @@ +#!/usr/bin/env python3 +# SPDX-License-Identifier: AGPL-3.0-or-later +"""Emit the Latticra Netplane Kaiju static adapter evidence intake receipt.""" + +from __future__ import annotations + +import argparse +import hashlib +import json +from pathlib import Path +from typing import Any + + +REPO_ROOT = Path(__file__).resolve().parents[1] +DEFAULT_MANIFEST = ( + REPO_ROOT / "fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json" +) +MANIFEST_REFERENCE = "fixtures/netplane/latticra-netplane-kaiju-static-adapter-evidence-manifest.json" +REQUIRED_EVIDENCE_ROLES = ( + "workspace-package-metadata", + "license-boundary", + "project-and-package-schema-boundary", + "offline-network-evidence-and-live-probe-boundary", + "defensive-parser-and-authority-boundary", + "synthetic-fixture-boundary", + "authorized-offline-network-evidence-fixture", + "deterministic-project-snapshot-fixture", +) +REQUIRED_SCHEMA_MARKERS = ( + "kaiju.project.v1", + "kaiju.network.v1", + "kaiju.network.probe.v1", + "kaiju.package.v1", + "kaiju.annotations.v1", +) + + +def _load_manifest(path: Path) -> dict[str, Any]: + with path.open("r", encoding="utf-8") as handle: + loaded = json.load(handle) + if not isinstance(loaded, dict): + raise ValueError("manifest root must be an object") + return loaded + + +def _canonical_sha256(document: dict[str, Any]) -> str: + encoded = json.dumps(document, sort_keys=True, separators=(",", ":")).encode("utf-8") + return "sha256:" + hashlib.sha256(encoded).hexdigest() + + +def _require_boundary_zeroes(boundary: dict[str, Any]) -> None: + required_zeroes = ( + "source_import_performed", + "artifact_copy_performed", + "kaiju_command_executed", + "kaiju_source_vendored", + "kaiju_binary_ingested", + "kaiju_package_accepted", + "pcap_import_performed", + "live_probe_performed", + "port_scan_performed", + "privileged_capture_performed", + "network_performed", + "host_mutation_performed", + "file_mutation_performed", + "runtime_authority_granted", + "plugin_runtime_accepted", + "mixed_build_promotion_accepted", + "production_readiness_claim", + ) + for key in required_zeroes: + if boundary.get(key) != 0: + raise ValueError(f"boundary must preserve {key}=0") + + +def _evidence_reference_map(source_lane: dict[str, Any]) -> dict[str, dict[str, Any]]: + references = source_lane.get("evidence_references") + if not isinstance(references, list): + raise ValueError("evidence_references must be a list") + + mapped: dict[str, dict[str, Any]] = {} + for reference in references: + if not isinstance(reference, dict): + raise ValueError("evidence_references entries must be objects") + role = reference.get("evidence_role") + path = reference.get("path") + digest = reference.get("sha256") + if not isinstance(role, str) or not role: + raise ValueError("evidence references must include evidence_role") + if not isinstance(path, str) or not path: + raise ValueError("evidence references must include path") + if not isinstance(digest, str) or not digest.startswith("sha256:"): + raise ValueError(f"evidence reference {path} must include sha256 digest") + mapped[role] = reference + return mapped + + +def validate_manifest(manifest: dict[str, Any]) -> dict[str, Any]: + if manifest.get("manifest_id") != "latticra-netplane-kaiju-static-adapter-evidence-intake": + raise ValueError("unexpected manifest_id") + if manifest.get("manifest_version") != 1: + raise ValueError("unexpected manifest_version") + + source_lane = manifest.get("source_lane") + if not isinstance(source_lane, dict): + raise ValueError("source_lane must be an object") + if source_lane.get("lane") != "kaiju": + raise ValueError("source_lane must describe the kaiju lane") + if source_lane.get("source_dirty_state") != "clean": + raise ValueError("kaiju source_dirty_state must be clean for this observed intake") + + workspace_package = source_lane.get("workspace_package") + if not isinstance(workspace_package, dict): + raise ValueError("workspace_package must be an object") + if workspace_package.get("license") != "Apache-2.0": + raise ValueError("kaiju workspace license must remain Apache-2.0 for this intake") + if workspace_package.get("crate_count") != 11: + raise ValueError("kaiju crate_count must match observed static inventory") + + boundary = manifest.get("adapter_boundary") + if not isinstance(boundary, dict): + raise ValueError("adapter_boundary must be an object") + if boundary.get("static_adapter_evidence_intake") != 1: + raise ValueError("static adapter evidence intake must be present") + _require_boundary_zeroes(boundary) + + references = _evidence_reference_map(source_lane) + missing_roles = [role for role in REQUIRED_EVIDENCE_ROLES if role not in references] + if missing_roles: + raise ValueError(f"missing evidence roles: {', '.join(missing_roles)}") + + schema_markers = source_lane.get("schema_markers") + if not isinstance(schema_markers, dict): + raise ValueError("schema_markers must be an object") + marker_values = set(schema_markers.values()) + missing_markers = [marker for marker in REQUIRED_SCHEMA_MARKERS if marker not in marker_values] + if missing_markers: + raise ValueError(f"missing schema markers: {', '.join(missing_markers)}") + + denied_shapes = manifest.get("denied_evidence_shapes") + if not isinstance(denied_shapes, list): + raise ValueError("denied_evidence_shapes must be a list") + for denied in ( + "source-vendoring", + "live-tcp-probe", + "port-scan", + "privileged-capture", + "plugin-runtime", + "network-authority", + "runtime-authority", + ): + if denied not in denied_shapes: + raise ValueError(f"denied evidence shape is required: {denied}") + + return { + "evidence_reference_count": len(references), + "schema_marker_count": len(marker_values), + "denied_shape_count": len(denied_shapes), + } + + +def build_receipt(manifest_path: Path = DEFAULT_MANIFEST) -> dict[str, Any]: + manifest = _load_manifest(manifest_path) + validation = validate_manifest(manifest) + source_lane = manifest["source_lane"] + workspace_package = source_lane["workspace_package"] + local_inventory = source_lane["local_inventory"] + boundary = manifest["adapter_boundary"] + + return { + "latticra_netplane_kaiju_static_adapter_evidence_intake_present": 1, + "kaiju_static_adapter_evidence_intake_guard_present": 1, + "intake_id": "latticra-netplane-kaiju-static-adapter-evidence-intake", + "intake_version": 1, + "edge_checkpoint": boundary["edge_checkpoint"], + "manifest_reference": MANIFEST_REFERENCE, + "manifest_sha256": _canonical_sha256(manifest), + "central_hub_intake_reference": manifest["central_hub_intake_reference"], + "kaiju_lane_present": 1, + "kaiju_github": source_lane["github"], + "kaiju_local_checkout": source_lane["local_checkout"], + "kaiju_source_revision": source_lane["local_revision"], + "kaiju_source_dirty_state": source_lane["source_dirty_state"], + "kaiju_license_posture": workspace_package["license"], + "kaiju_crate_count": workspace_package["crate_count"], + "kaiju_documentation_file_count": local_inventory["documentation_file_count"], + "kaiju_fixture_file_count": local_inventory["fixture_file_count"], + "kaiju_snapshot_file_count": local_inventory["snapshot_file_count"], + "kaiju_evidence_reference_count": validation["evidence_reference_count"], + "kaiju_schema_marker_count": validation["schema_marker_count"], + "denied_shape_count": validation["denied_shape_count"], + "static_adapter_evidence_intake": boundary["static_adapter_evidence_intake"], + "source_import_performed": boundary["source_import_performed"], + "artifact_copy_performed": boundary["artifact_copy_performed"], + "kaiju_command_executed": boundary["kaiju_command_executed"], + "kaiju_source_vendored": boundary["kaiju_source_vendored"], + "kaiju_binary_ingested": boundary["kaiju_binary_ingested"], + "kaiju_package_accepted": boundary["kaiju_package_accepted"], + "pcap_import_performed": boundary["pcap_import_performed"], + "live_probe_performed": boundary["live_probe_performed"], + "port_scan_performed": boundary["port_scan_performed"], + "privileged_capture_performed": boundary["privileged_capture_performed"], + "network_performed": boundary["network_performed"], + "host_mutation_performed": boundary["host_mutation_performed"], + "runtime_authority_granted": boundary["runtime_authority_granted"], + "plugin_runtime_accepted": boundary["plugin_runtime_accepted"], + "mixed_build_promotion_accepted": boundary["mixed_build_promotion_accepted"], + "production_readiness_claim": boundary["production_readiness_claim"], + "next_recommended_lane": manifest["next_recommended_lane"], + } + + +def main() -> None: + parser = argparse.ArgumentParser() + parser.add_argument("--manifest", default=str(DEFAULT_MANIFEST)) + args = parser.parse_args() + + receipt = build_receipt(Path(args.manifest)) + print(json.dumps(receipt, indent=2, sort_keys=True)) + + +if __name__ == "__main__": + main() diff --git a/tools/latticra_receipt_utils.py b/tools/latticra_receipt_utils.py index aaa1a415..1de3ce30 100644 --- a/tools/latticra_receipt_utils.py +++ b/tools/latticra_receipt_utils.py @@ -1,47 +1,102 @@ #!/usr/bin/env python3 # SPDX-License-Identifier: AGPL-3.0-or-later -"""Shared utilities for portable receipt references and common receipt helpers.""" +"""Shared utilities for portable receipt references and common receipt helpers. + +This module centralizes logic for producing machine-independent references +inside Latticra evidence receipts and related artifacts. The primary goal is +receipt reference portability: references recorded in JSON receipts, manifests, +and ledgers must remain valid when the repository is checked out at a different +absolute path or on a different machine. + +All path references emitted for cross-receipt linking must resolve to paths +relative to the repository root using POSIX-style separators. +""" + from __future__ import annotations + import hashlib import json from decimal import Decimal from pathlib import Path from typing import Iterable + REPO_ROOT = Path(__file__).resolve().parents[1] -__all__ = ["REPO_ROOT", "path_reference", "decimal_to_text", "canonical_receipt_hash", "receipt_hash", "file_sha256"] + +__all__ = [ + "REPO_ROOT", + "path_reference", + "decimal_to_text", + "canonical_receipt_hash", + "receipt_hash", + "file_sha256", +] + + def path_reference(path: Path | str) -> str: - if isinstance(path, str): p = Path(path) - else: p = path + if isinstance(path, str): + p = Path(path) + else: + p = path candidate = p if p.is_absolute() else REPO_ROOT / p - try: return candidate.resolve().relative_to(REPO_ROOT).as_posix() + try: + return candidate.resolve().relative_to(REPO_ROOT).as_posix() except (ValueError, FileNotFoundError, RuntimeError): - try: return p.as_posix() - except Exception: return str(p) + try: + return p.as_posix() + except Exception: + return str(p) + + def decimal_to_text(value: Decimal) -> str: normalized = value.normalize() - if normalized == normalized.to_integral(): return format(normalized, "f") + if normalized == normalized.to_integral(): + return format(normalized, "f") return format(normalized, "f") + + def canonical_receipt_hash(payload: dict[str, object]) -> str: canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")) return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + + def receipt_hash(payload: dict[str, object], *, exclude_keys: Iterable[str] = ()) -> str: p = dict(payload) - for k in exclude_keys: p.pop(k, None) + for k in exclude_keys: + p.pop(k, None) return canonical_receipt_hash(p) + + def file_sha256(path: Path | str) -> str: p = Path(path) data = p.read_bytes() return "sha256:" + hashlib.sha256(data).hexdigest() + + def _self_test() -> int: from pathlib import Path as _P + r1 = path_reference("README.md") r2 = path_reference(_P("tools/latticra_receipt_utils.py")) + r3 = path_reference("/tmp/not-in-repo-xyz") h = canonical_receipt_hash({"a": 1, "b": 2}) - ok = r1 == "README.md" and r2.endswith("receipt_utils.py") and h.startswith("sha256:") - print("latticra_receipt_utils self test: ok" if ok else "FAIL") - return 0 if ok else 1 + h2 = receipt_hash({"x": 9, "receipt_hash": "sha256:ignore"}, exclude_keys=("receipt_hash",)) + f = file_sha256("README.md") + ok = ( + r1 == "README.md" + and r2 == "tools/latticra_receipt_utils.py" + and r3 == "/tmp/not-in-repo-xyz" + and h.startswith("sha256:") + and len(h) > 20 + and h2.startswith("sha256:") + and f.startswith("sha256:") + ) + if not ok: + print("FAIL receipt utils self test") + return 1 + print("latticra_receipt_utils self test: ok") + print(f" sample references: {r1}, {r2}") + return 0 + + if __name__ == "__main__": raise SystemExit(_self_test()) - -# Note: this module provides the foundation for all portable receipt references in Latticra. -# Updated post-push as part of continuous work. From 6b4820815dcdc311926ee527d0904d89002a5f26 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:52:15 -0500 Subject: [PATCH 12/16] refactor(receipts): centralize receipt_hash in model3 runner (keep hashlib for trace) - Uses canonical - Test ok Continuing Latticra work. --- tools/latticra_identity_replay_model3_runner.py | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/tools/latticra_identity_replay_model3_runner.py b/tools/latticra_identity_replay_model3_runner.py index 9d7e2bdf..a6856ac1 100755 --- a/tools/latticra_identity_replay_model3_runner.py +++ b/tools/latticra_identity_replay_model3_runner.py @@ -10,7 +10,7 @@ from decimal import Decimal, getcontext from typing import Iterable -from latticra_identity_replay_model1_evaluate import decimal_to_text +from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text from latticra_identity_replay_model1_substrate import ( EPSILON_IDENTITY_TOLERANCE, MASSIVE_IDENTITY_CLASSES, @@ -34,8 +34,7 @@ def receipt_hash(payload: dict[str, object]) -> str: - canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash(payload) def topology_trace(identity: str) -> dict[str, object]: From 627b2b044395e618fe59b4d64cc2aa32cf625e25 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:53:59 -0500 Subject: [PATCH 13/16] refactor(receipts): centralize in model1 range falsifier - Import and hash now central - Test ok Work on Latticra does not stop. --- tools/latticra_identity_replay_model1_range_falsifier.py | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/tools/latticra_identity_replay_model1_range_falsifier.py b/tools/latticra_identity_replay_model1_range_falsifier.py index ac18847a..11afc460 100755 --- a/tools/latticra_identity_replay_model1_range_falsifier.py +++ b/tools/latticra_identity_replay_model1_range_falsifier.py @@ -5,13 +5,13 @@ from __future__ import annotations import argparse -import hashlib import json from decimal import Decimal, getcontext from pathlib import Path from typing import Iterable -from latticra_identity_replay_model1_evaluate import decimal_to_text, parse_target_table +from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text, path_reference +from latticra_identity_replay_model1_evaluate import parse_target_table from latticra_identity_replay_model1_substrate import ( EPSILON_IDENTITY_TOLERANCE, MAX_CELL_ABS, @@ -27,8 +27,7 @@ def receipt_hash(payload: dict[str, object]) -> str: - canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash(payload) def target_ratio_summary( From 3efc97c193869639e88da3427cc37a5bb4f9c442 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:56:02 -0500 Subject: [PATCH 14/16] refactor(receipts): centralize hashes in model2 range capacity - Now uses canonical - Removed hashlib - Tests ok Latticra work continues without stop. --- ...ticra_identity_replay_model2_range_capacity.py | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/tools/latticra_identity_replay_model2_range_capacity.py b/tools/latticra_identity_replay_model2_range_capacity.py index e6c64d27..42ad20aa 100755 --- a/tools/latticra_identity_replay_model2_range_capacity.py +++ b/tools/latticra_identity_replay_model2_range_capacity.py @@ -5,29 +5,26 @@ from __future__ import annotations import argparse -import hashlib import json from decimal import Decimal, getcontext from pathlib import Path from typing import Iterable -from latticra_identity_replay_model1_evaluate import decimal_to_text, parse_target_table +from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text, path_reference +from latticra_identity_replay_model1_evaluate import parse_target_table getcontext().prec = 80 def receipt_hash(payload: dict[str, object]) -> str: - canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash(payload) def pre_registration_hash(payload: dict[str, object]) -> str: - canonical_payload = dict(payload) - canonical_payload.pop("model2_pre_registration_receipt_hash", None) - canonical_payload.pop("model2_pre_registration_receipt_hash_generated", None) - canonical = json.dumps(canonical_payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash( # exclude the hash fields for stable computation + {k: v for k, v in payload.items() if k not in ("model2_pre_registration_receipt_hash", "model2_pre_registration_receipt_hash_generated")} + ) def load_pre_registration(path: Path) -> dict[str, object]: From a745f2bcc757d0329c69d1a937a4dbe93789c3c6 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Fri, 19 Jun 2026 23:57:49 -0500 Subject: [PATCH 15/16] refactor(receipts): centralize in model3 refined prereg - Uses canonical with exclude logic - Test ok Continuing autonomous work on Latticra. --- ..._identity_replay_model3_refined_preregistration.py | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/tools/latticra_identity_replay_model3_refined_preregistration.py b/tools/latticra_identity_replay_model3_refined_preregistration.py index 2e84c983..a67be817 100755 --- a/tools/latticra_identity_replay_model3_refined_preregistration.py +++ b/tools/latticra_identity_replay_model3_refined_preregistration.py @@ -5,13 +5,12 @@ from __future__ import annotations import argparse -import hashlib import json from decimal import Decimal, getcontext from pathlib import Path from typing import Iterable -from latticra_identity_replay_model1_evaluate import decimal_to_text +from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text, path_reference from latticra_identity_replay_model3_preregistration import ( build_receipt as build_model3_pre_registration, ) @@ -32,11 +31,9 @@ def receipt_hash(payload: dict[str, object]) -> str: - canonical_payload = dict(payload) - canonical_payload.pop("refined_model3_pre_registration_receipt_hash", None) - canonical_payload.pop("refined_model3_pre_registration_receipt_hash_generated", None) - canonical = json.dumps(canonical_payload, sort_keys=True, separators=(",", ":")) - return "sha256:" + hashlib.sha256(canonical.encode("utf-8")).hexdigest() + return canonical_receipt_hash( + {k: v for k, v in payload.items() if k not in ("refined_model3_pre_registration_receipt_hash", "refined_model3_pre_registration_receipt_hash_generated")} + ) def load_gate(path: Path) -> dict[str, object]: From 279b97d3d7af621b550ca53e201bfc610ec26407 Mon Sep 17 00:00:00 2001 From: Chase Bryan Date: Sat, 20 Jun 2026 00:00:00 -0500 Subject: [PATCH 16/16] fix(receipts): close portability validation gaps --- ...el-signed-updater-manifest-fixture-contract.sh | 2 ++ ...-signed-updater-manifest-fixture-validation.sh | 4 +++- ...panel-signed-updater-state-fixture-contract.sh | 4 +++- ...nel-signed-updater-state-fixture-validation.sh | 4 +++- ...el-signed-updater-manifest-fixture-contract.sh | 2 +- ...-signed-updater-manifest-fixture-validation.sh | 2 +- src/seal_signed_receipt_proof_path.c | 5 +---- tests/seal_signed_receipt_proof_path_invariants.c | 3 +++ ...ticra_identity_replay_model2_range_capacity.py | 15 ++++++++++++--- 9 files changed, 29 insertions(+), 12 deletions(-) diff --git a/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh b/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh index 685a12f8..5ccce359 100644 --- a/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh +++ b/scripts/latticra-panel-signed-updater-manifest-fixture-contract.sh @@ -34,6 +34,8 @@ UNAME_M=$(uname -m 2>/dev/null || printf 'unknown') FIXTURE_RELATIVE='fixtures/latticra-panel/signed-updater-manifest.fixture.toml' FIXTURE="$ROOT/$FIXTURE_RELATIVE" +. "$ROOT/scripts/lib/latticra-portable-paths.sh" + if [ -f "$FIXTURE" ]; then MANIFEST_FIXTURE_FILE_PRESENT=1 CONTRACT_STATUS=ok diff --git a/scripts/latticra-panel-signed-updater-manifest-fixture-validation.sh b/scripts/latticra-panel-signed-updater-manifest-fixture-validation.sh index b0e13e56..95ceec8b 100644 --- a/scripts/latticra-panel-signed-updater-manifest-fixture-validation.sh +++ b/scripts/latticra-panel-signed-updater-manifest-fixture-validation.sh @@ -42,6 +42,8 @@ UNAME_M=$(uname -m 2>/dev/null || printf 'unknown') FIXTURE_RELATIVE='fixtures/latticra-panel/signed-updater-manifest.fixture.toml' FIXTURE="$ROOT/$FIXTURE_RELATIVE" +. "$ROOT/scripts/lib/latticra-portable-paths.sh" + if [ ! -f "$FIXTURE" ]; then printf 'latticra panel signed updater manifest fixture validation: missing fixture: %s\n' "$FIXTURE_RELATIVE" >&2 exit 1 @@ -99,7 +101,7 @@ signed_updater_delivery_gate_state=closed signed_updater_denial_transcript_present=1 signed_updater_manifest_fixture_contract_present=1 signed_updater_manifest_fixture_validation_present=1 -manifest_fixture_path=$FIXTURE_RELATIVE +manifest_fixture_path=$(portable_path "$FIXTURE_RELATIVE") signed_updater_manifest_fixture_present=1 signed_updater_manifest_fixture_file_present=1 signed_updater_manifest_fixture_validated=1 diff --git a/scripts/latticra-panel-signed-updater-state-fixture-contract.sh b/scripts/latticra-panel-signed-updater-state-fixture-contract.sh index a0522e5a..0af197e2 100644 --- a/scripts/latticra-panel-signed-updater-state-fixture-contract.sh +++ b/scripts/latticra-panel-signed-updater-state-fixture-contract.sh @@ -34,6 +34,8 @@ UNAME_M=$(uname -m 2>/dev/null || printf 'unknown') FIXTURE_RELATIVE='fixtures/latticra-panel/signed-updater-state.fixture.toml' FIXTURE="$ROOT/$FIXTURE_RELATIVE" +. "$ROOT/scripts/lib/latticra-portable-paths.sh" + if [ -f "$FIXTURE" ]; then STATE_FIXTURE_FILE_PRESENT=1 CONTRACT_STATUS=ok @@ -57,7 +59,7 @@ signed_updater_denial_transcript_present=1 signed_updater_manifest_fixture_contract_present=1 signed_updater_manifest_fixture_validation_present=1 signed_updater_state_fixture_contract_present=1 -state_fixture_path=$FIXTURE_RELATIVE +state_fixture_path=$(portable_path "$FIXTURE_RELATIVE") signed_updater_state_fixture_present=$STATE_FIXTURE_FILE_PRESENT signed_updater_state_fixture_file_present=$STATE_FIXTURE_FILE_PRESENT state_fixture_schema=latticra-panel-signed-updater-state-fixture-v0 diff --git a/scripts/latticra-panel-signed-updater-state-fixture-validation.sh b/scripts/latticra-panel-signed-updater-state-fixture-validation.sh index 7975b787..67483f73 100644 --- a/scripts/latticra-panel-signed-updater-state-fixture-validation.sh +++ b/scripts/latticra-panel-signed-updater-state-fixture-validation.sh @@ -42,6 +42,8 @@ UNAME_M=$(uname -m 2>/dev/null || printf 'unknown') FIXTURE_RELATIVE='fixtures/latticra-panel/signed-updater-state.fixture.toml' FIXTURE="$ROOT/$FIXTURE_RELATIVE" +. "$ROOT/scripts/lib/latticra-portable-paths.sh" + if [ ! -f "$FIXTURE" ]; then printf 'latticra panel signed updater state fixture validation: missing fixture: %s\n' "$FIXTURE_RELATIVE" >&2 exit 1 @@ -121,7 +123,7 @@ signed_updater_manifest_fixture_contract_present=1 signed_updater_manifest_fixture_validation_present=1 signed_updater_state_fixture_contract_present=1 signed_updater_state_fixture_validation_present=1 -state_fixture_path=$FIXTURE_RELATIVE +state_fixture_path=$(portable_path "$FIXTURE_RELATIVE") signed_updater_state_fixture_present=1 signed_updater_state_fixture_file_present=1 signed_updater_state_fixture_validated=1 diff --git a/scripts/test-latticra-panel-signed-updater-manifest-fixture-contract.sh b/scripts/test-latticra-panel-signed-updater-manifest-fixture-contract.sh index 4a8742e8..9ab3263b 100644 --- a/scripts/test-latticra-panel-signed-updater-manifest-fixture-contract.sh +++ b/scripts/test-latticra-panel-signed-updater-manifest-fixture-contract.sh @@ -120,7 +120,7 @@ require_contains 'not signed update evidence' "$status" require_contains 'LATTICRA PANEL SIGNED UPDATER MANIFEST FIXTURE CONTRACT' "$script" require_contains 'signed_updater_manifest_fixture_contract_status=$CONTRACT_STATUS' "$script" -require_contains 'manifest_fixture_path=$FIXTURE_RELATIVE' "$script" +require_contains 'manifest_fixture_path=$(portable_path "$FIXTURE_RELATIVE")' "$script" require_contains 'signed_updater_manifest_fixture_contract_present=1' "$script" require_contains 'trusted_signed_manifest_present=0' "$script" require_contains 'signed_manifest_present=0' "$script" diff --git a/scripts/test-latticra-panel-signed-updater-manifest-fixture-validation.sh b/scripts/test-latticra-panel-signed-updater-manifest-fixture-validation.sh index 4f2b7e57..206d45b2 100644 --- a/scripts/test-latticra-panel-signed-updater-manifest-fixture-validation.sh +++ b/scripts/test-latticra-panel-signed-updater-manifest-fixture-validation.sh @@ -124,7 +124,7 @@ require_contains 'production_update_ready=0' "$status" require_contains 'LATTICRA PANEL SIGNED UPDATER MANIFEST FIXTURE VALIDATION' "$script" require_contains 'require_fixture_line' "$script" require_contains 'signed_updater_manifest_fixture_validation_status=ok' "$script" -require_contains 'manifest_fixture_path=$FIXTURE_RELATIVE' "$script" +require_contains 'manifest_fixture_path=$(portable_path "$FIXTURE_RELATIVE")' "$script" require_contains 'signed_updater_manifest_fixture_validation_present=1' "$script" require_contains 'signed_updater_manifest_fixture_validated=1' "$script" require_contains 'manifest_schema_validated=1' "$script" diff --git a/src/seal_signed_receipt_proof_path.c b/src/seal_signed_receipt_proof_path.c index 2d3d084e..5acdfba3 100644 --- a/src/seal_signed_receipt_proof_path.c +++ b/src/seal_signed_receipt_proof_path.c @@ -38,10 +38,7 @@ static int text_field_valid(const char *value, size_t max_len) { } static int text_field_terminated(const char *value, size_t max_len) { - int terminated = 0; - - (void)bounded_string_len(value, max_len, &terminated); - return terminated == 1; + return text_field_valid(value, max_len); } static int bounded_string_is(const char *value, size_t max_len, const char *expected) { diff --git a/tests/seal_signed_receipt_proof_path_invariants.c b/tests/seal_signed_receipt_proof_path_invariants.c index 3874a15c..6b942852 100644 --- a/tests/seal_signed_receipt_proof_path_invariants.c +++ b/tests/seal_signed_receipt_proof_path_invariants.c @@ -245,6 +245,9 @@ static int proof_path_allows_verification_only_summary(void) { EXPECT_TRUE(strstr(rendered, "network_performed=0") != NULL, "render network"); EXPECT_TRUE(strstr(rendered, "status=signed-receipt-proof-path-verification-only") != NULL, "render status field"); + proof_path.signer_invocation_profile[0] = '\0'; + EXPECT_TRUE(latticra_seal_signed_receipt_proof_path_is_verification_only(&proof_path) == 0, + "empty proof path metadata rejected"); return 0; } diff --git a/tools/latticra_identity_replay_model2_range_capacity.py b/tools/latticra_identity_replay_model2_range_capacity.py index 42ad20aa..29d00f3c 100755 --- a/tools/latticra_identity_replay_model2_range_capacity.py +++ b/tools/latticra_identity_replay_model2_range_capacity.py @@ -10,7 +10,12 @@ from pathlib import Path from typing import Iterable -from latticra_receipt_utils import canonical_receipt_hash, decimal_to_text, path_reference +from latticra_receipt_utils import ( + canonical_receipt_hash, + decimal_to_text, + path_reference, + receipt_hash as _make_receipt_hash_with_exclude, +) from latticra_identity_replay_model1_evaluate import parse_target_table @@ -22,8 +27,12 @@ def receipt_hash(payload: dict[str, object]) -> str: def pre_registration_hash(payload: dict[str, object]) -> str: - return canonical_receipt_hash( # exclude the hash fields for stable computation - {k: v for k, v in payload.items() if k not in ("model2_pre_registration_receipt_hash", "model2_pre_registration_receipt_hash_generated")} + return _make_receipt_hash_with_exclude( + payload, + exclude_keys=( + "model2_pre_registration_receipt_hash", + "model2_pre_registration_receipt_hash_generated", + ), )