Rendered from CHANGELOG.md at build time without changing its status. The repository source controls if this presentation differs.
Changelog#
Acronyms: artificial intelligence (AI); Advanced Micro Devices (AMD); application programming interface (API); Amazon Web Services (AWS); Concise Binary Object Representation (CBOR); continuous integration (CI); command-line interface (CLI); conjunctive normal form (CNF); CBOR Object Signing and Encryption (COSE); grounded decision certificate (GDC); Hypertext Transfer Protocol Secure (HTTPS); Internet Engineering Task Force (IETF); JavaScript Object Notation (JSON); nondeterministic polynomial time (NP); reduced instruction set computer (RISC); Boolean satisfiability problem (SAT); Secure Hash Algorithm 256-bit (SHA-256); Secure Hash Algorithm 3 256-bit (SHA3-256); Supply Chain Integrity, Transparency, and Trust (SCITT); Secure Shell (SSH); Coordinated Universal Time (UTC); Verifier Standard (VSTD); ZIP archive format (ZIP); zero-identity/zero-knowledge (ZIZK).
1.2.0 - 2026-09-01#
Public surface and integrations#
- Restructure the public first-view path around one bounded project description, one deterministic demonstration, one canonical maturity table, skeptical claim limits, contributor routes, and release/citation boundaries; align Pages and package metadata without changing normative or serialized-receipt semantics.
- Normalize the public architecture as a verification complex of named closure coordinates and cumulative numbered profiles; reserve VSTD-4 rung, candidate depth, verification order, compatibility level, and checker-cost tier for their distinct uses.
- Add experimental workflow profile 0.1 with deterministic canonicalization, strict validation, bounded work-allocation records, additive amendments and challenges, explicit unresolved horizons, and verdict-neutral platform events.
- Add a normalized GitHub adapter for issues, commits, workflow runs, artifacts, and pull requests. Successful workflows and merges retain
verification_effect = NONEunless a separate native result is explicitly mapped through a bound VSTD receipt. - Add
vstd experiment validateandvstd experiment github-eventsas offline, verdict-neutral entry points. Repository artifacts are explicitlyNOT_CHECKEDwith exit code 2 unless their root is supplied. - Add a machine-readable schema, checked-in verdict-neutral specimen, generated experiment index, adversarial tests, and a runnable offline example.
- Add a generated CLI/API reference page and presentation gates that reject stale reference or experiment-index content.
- Clarify VSTD's role as a verification-domain language and interchange layer that preserves, rather than replaces or strengthens, native verifier results.
- Add the experimental SCITT adapter, rerunnable real-COSE specimen with ephemeral keys, explicit semantic boundary, and adversarial composition tests without claiming IETF review or payload truth from registration.
- Surface zero-identity/zero-knowledge (ZIZK) artifact-first TRUST as governing architecture, publish the bounded RISC Zero reference mechanism and exact recorded public proof artifacts, and keep only unfinished mechanisms experimental while preserving unresolved horizons and native-system authority.
- Bind the recorded RISC Zero proof to the image produced from the tracked guest and locked toolchain in the governed offline verifier, rather than accepting source/proof correspondence from a neighboring historical image identifier.
- Formally distinguish TRUST as mechanism-earned forward artifact support, ROT as typed time-indexed degradation of current admissibility, and RUST as an inverse-TRUST memetic causal backtrace toward recorded ancestor states. None is actor-tied trust or a scalar; reachability alone never infers guilt, responsibility, or causal localization.
- Present current reports, schemas, module descriptions, and examples under the full VSTD-1 and VSTD-2 numbered-profile identifiers; remove retired partial-profile object identifiers from active readers and add a regression preventing their return.
- Add normative artifact-control mechanism version 1 with exact-byte file/directory freezing, SHA-256 plus SHA3-256 artifact-derived identities, observable read-only guards, readable finite self-closing Ed25519 seals, external anchor checks, and copy-on-write thaw descendants. Sealing is not encryption and supplies no actor trust, semantic correctness, trusted time, or numbered VSTD profile result.
- Document multi-temporal realms, discrete and continuous coexistence, causal and problem-space partial orders, atemporal versus temporal capsules, explicit cross-realm mappings, and future constrained language-model transition verification without claiming continuous mediation, inference-law implementation, or textual truth.
Claim boundaries and validation#
- Require
thawed_artifact_statusandvstd artifact statusto verify an actual supplied, cleanly sealed parent and every recorded parent coordinate before returningTHAWED_CLEANorTHAWED_DIRTY. Sidecar-only agreement is nowNOT_ESTABLISHED; even a verified current match does not authenticate the historical copy operation or external parent continuity. - Preserve final filesystem-entry identity during artifact creation: freeze refuses symbolic-link sources, and bundle, thaw-descendant, and sidecar outputs refuse every preexisting lexical entry, including dangling symbolic links, without claiming universal race-free filesystem security.
- Require authoritative freeze-manifest, payload, seals-container, and seal-envelope members to have ordinary lexical types; linked external or in-bundle targets cannot lend bytes to bundle closure, while verified outer read aliases and ordinary hard-link byte-and-path semantics remain explicitly distinct.
- Remove the live SimulacraBench rehearsal and its front-door promotion; the repository never contained or reproduced the submission, hosted image, hardware, or protected evaluation identified by that name.
- Correct generic-run wording: digest validation is an integrity check, external references remain unattested until dereferenced and verified, same-path output extraction is not independent verification, and unverified determinism is
UNKNOWN. - Publish a Pages guide index and enforce language, title, viewport, main-region, skip-link, image-alt, labelled-navigation, generated-reference, and local-link checks in CI.
- Preserve explicit ordered-list starting numbers in generated Pages so procedures split by code blocks retain their source step numbers instead of restarting at one.
- Require CodeQL security-extended Python analysis in the protected repository-check aggregate with only read access to content and write access to security results.
- Fail closed on malformed generic-run receipts, publish their exact schema, and dispatch
VSTD-1by its required receipt profile. - Package every normative specification, verify byte identity, and smoke-test the built wheel outside the source checkout so installed specification bindings cannot silently become unavailable.
- Bind the bundled checker to VSTD-1, record actor and execution separation explicitly, and never infer independent actors from a historical field name, repeated runs, or matching results.
- Reject self-promoted independence even when every supplied status and digest agrees; the generic-run compatibility path never derives
EVIDENCEDfrom serialized references. The distinct VSTD-5 path reruns all seven separation propositions and does not upgrade the legacy generic-run fields. - Require the real optional SCITT/COSE cryptographic example in the protected repository-check aggregate rather than allowing its dependency-gated tests to disappear from the base matrix.
- Close generic-run control structures while retaining the released refutation-extension map, make common receipt commands honor
--json, and lockvalidateas an integrity/profile check rather than a claim verifier.
Graph and conformance semantics#
- Add a zero-dependency evidence execution core that resolves and rehashes exact evidence bytes, pins a registered mechanism implementation digest, enforces byte/item bounds, reruns the mechanism, and preserves
PASS,FAIL, orUNKNOWNunder explicit trust roots. - Add an evidence-bound VSTD-4 path and replayable receipt form. Compatibility
vstd4_depthremains aNOT_ESTABLISHEDcandidate; only exact passing VSTD-1/2/3 and fourteen-rung mechanisms plus an accepted kernel witness admit VSTD-5. - Implement the VSTD-5 reference mechanism and receipt: seven evidence-bound separation dimensions, duplicate-witness/evidence refusal, exact admitted-certificate and corroboration binding, typed binding/identity/separation/corroboration errors, disagreement preservation, embedded evidence, and offline result recheck. Independence fails closed on any identity or separation defect without parsing error-message text. Witness identities and assertions serialize separately and in order, so duplicate, orphan, missing, and reused-identity error inputs remain replayable instead of collapsing during receipt construction. Keep permissive malformed-input assessment distinct from portable receipt admission: the builder now raises unless the strict schema and complete verdict-material evidence coverage hold, and the rechecker applies the same zero-dependency gate before replay. The rechecker also compares the complete carried VSTD-4 entry, and
corroboration_classis mechanism-bound rather than relabelable metadata. This does not claim a real external witness or independent implementation; a positive observation with unresolved independence is overallUNKNOWN. - Add evidence-bound Graph profile computation and replay. The compatibility
graph_levelpath remains caller-supplied; the new path reruns every member, ancestor, and reached-edge rating mechanism bound to the exact Graph, members, collection, and claim before profile 1–5 can reportESTABLISHED. Profile zero remainsNOT_ESTABLISHED. - Add
VSTD-GRAPH-ASSURANCE-1andAssuranceLedgerfor hash-chained edge-local TRUST, ROT, RUST, challenge-ledger projection, additive conflict declaration/resolution, structural RUST concentration, explicit causal localization, and bounded artifact-relative BLAME/GUILT propositions. Each TRUST event binds one exact transformation, its inputs/output, the historical Graph, and prerequisite TRUST events; current eligibility recursively fails closed when any bound dependency degrades or conflicts. Duplicate paths remain set-valued, historical graph bytes remain immutable, and topology alone earns no causal or moral conclusion. BLAME establishes bounded responsibility or material contribution. GUILT is not BLAME in the opposite direction: it composes separately bound responsibility, exact scoped-obligation applicability, and same-obligation violation components, then binds their exact event digests. One compound mechanism may emit all three component evaluations in one invocation; an opaque combined pass or decorative obligation string remainsNOT_ESTABLISHED. Localization binds one exact passing RUST event and descendant-deviation proposition. Neither result establishes actor morality, reputation, automatic legal liability, innocence, exoneration, obligation satisfaction, or absence of hidden contributors. Status-conflict resolution projects the selected state into current admissibility; arbitrary resolved predicates remain blocked. The current runtime has no general non-status admissibility-effect mechanism. RUST follows historically recorded contributing ancestry even when current lifecycle state excludes a route from TRUST. New construction, evidence-bound Graph establishment, and assurance propagation require globally disjoint artifact/transformation identifiers so an untypedsubject_idcannot ambiguously name both; the frozenVSTD-DATA-0.1reader retains its original two namespaces. Add complete offline event replay, current TRUST filtering, and deduplicated descendant reassessment discovery.
- Preserve incompatible Graph assertions as evidence-linked conflict records and label rating-derived Graph profile numbers as
CALLER_SUPPLIEDcandidates with conformanceNOT_ESTABLISHED. - Classify the current VSTD-4 candidate-depth calculation as a structural result over caller-supplied rung references with conformance
NOT_ESTABLISHED; reject that candidate at the VSTD-5 entry gate even when its candidate depth is 14. - Label compatibility Graph 2–5 candidates consistently while separately presenting the implemented evidence-bound reference paths. Bind complete challenge-ledger state into an additive current Graph view without mutating history.
Release and maintainer controls#
- Mark 1.2.0 metadata as an unreleased release candidate, omit any fabricated release date, and require the exact tagged checkout to have
TIME.mdset toStatus: CLEAR. - Move the immutable-release setting check before tag creation in the documented release sequence and enforce it again in the tag workflow, so a disabled setting stops publication rather than producing a mutable release.
- Make package/reference status identify VSTD-5 as the highest exposed project specification with an evidence-bound reference mechanism, without claiming a real independent witness, and require finalized release metadata in the tag workflow.
- Publish the architecture ownership map linking normative documents, runtime validators, schemas, and conformance tests.
- Document the five-As human traversal over existing receipt, Graph, hardware, certificate, reproduction, and SCITT machinery without adding a serialized receipt format; reject duplicate Graph identifiers and reproduction-fidelity states inferred from declarations, matching verdicts, or mismatching runs.
- Restore the three non-overlapping operating controls:
AGENTS.mdfor automated work,HUMANS.mdfor human five-As reasoning, andTIME.mdfor current repository contradictions. Development may recordOPEN; the exact tagged checkout must beCLEARbefore publication. - Replace the developmental profile-numbered generic-run container with required neutral
assessment_context; preserve its mechanism, bound, commitment, and refutation coordinates without carrying a VSTD-4 conformance field.
1.1.3 - 2026-08-22#
- Canonicalize source ZIP timestamps in UTC and remove host ZIP metadata, so the same Git coordinate produces byte-identical source archives on Windows and Linux.
- Canonicalize generated wheel and source-distribution newlines, archive member order, modes, timestamps, and ownership. Rebuild wheel
RECORDafter normalization and use compression-independent ZIP members plus a stableustar/gzip container. - Normalize common HTTPS and SSH spellings of the Git origin before recording the public repository coordinate in a release manifest.
- Require CI to build the complete release artifact set independently on Windows and Linux and fail the conformance gate unless every resulting byte is identical.
- Record that
v1.1.2remained a signed, tested, and attested GitHub-only release: its protected PyPI deployment was cancelled after cross-platform build differences were detected, before any Python distribution was uploaded.
1.1.2 - 2026-08-22#
- Rename the import package
verifiabletoverifierand the distributionverifiable-standardtoverifier-standard, so no published name reuses the ordinary-English adjective or the maintainer's former project name. Thevstd,verifier, andverifiablecommand names all continue to work;verifiableis a command name only and no longer names an import package. - Derive the release source-archive name from the manifest during verification, so manifests published through
v1.1.1that bindverifiable-standard-<release>.zipremain verifiable without republishing. - Record the import-package, distribution, and archive renames in
WIRE_IDENTIFIERS.md. No receipt serialized receipt identifier, schema$id, or canonical digest changes. - Attribute the specifications, distribution metadata, and governance decision rights to
TimeLordRaps. The legal name remains the copyright holder inNOTICE. - Add a normalized, byte-reproducible Python source distribution beside the reproducible wheel; verify their name, version, import package, and frozen console-script set before release.
- Publish only the tested wheel and source distribution through PyPI Trusted Publishing after explicit approval in the protected
pypienvironment. The GitHub release keeps the full source ZIP and external byte manifest as the public provenance coordinate. - Document that the unrelated PyPI project named
verifiershares the same import name and must not be co-installed; this is an ecosystem collision boundary, not a claim to that distribution coordinate.
- Rename the VSTD-2 section 7 lifecycle term
VERIFIABLEtoGEOMETRY_INSPECTABLEand record inWIRE_IDENTIFIERS.mdthat the section 7 vocabulary is prose-only, so no status token reuses the maintainer's name and no serialized receipt value changes. - Label the reference emulator's synthetic accelerator descriptor
vendorasEMULATEDinstead of the maintainer's name, so fabricated hardware evidence cannot read as maintainer attestation. - Remove maintainer-scoped phrasing from normative specification prose: conformance is defined by the documents, and the independent auditor role is named by the standard rather than by the maintainer.
- Correct the SimulacraBench synthetic specimen additively: unobserved private artifacts now remain
IDENTIFIED, and the public challenge stops atCHALLENGEDwithout a maintainer-authored adjudication. - Require content-bound observed bytes before deriving
AVAILABLEorPORTABLE; locator and retention declarations alone no longer elevate availability. - Expand the public presentation gate to reject drive-qualified paths, private locator schemes, deployment fields, local model artifact filenames, business operations identifiers, common secret shapes, and email addresses.
1.1.1 - 2026-08-22#
- Replace the overview's generic maturity badges with the exact status of every object and Graph numbered profile, so the presentation cannot imply evidence or implementation maturity that the specifications do not establish.
- Enforce those visual labels in the presentation gate and publish canonical receipt schemas at their declared GitHub Pages
$idroutes. - Add contributor guardrails for the live schema routes, the Python 3.10 floor, and the immediate-publication consequences of edits to Pages content.
1.1.0 - 2026-08-22#
- Add
vstd demo, a deterministic four-scenario adversarial demonstration that rejects a proof grounded to the wrong artifact, preserves a checkedUNKNOWN, rejects verification-cost inflation, and exposes a revoked transitive ancestor. - Publish the replayable demo specimens, a newcomer quickstart, a public technical roadmap, an ecosystem boundary map, and a focused project overview site.
- Make
vstdthe canonical cross-platform command while retainingverifierandverifiableas compatibility aliases. This avoids collision with Windows Driver Verifier without breaking previously issued command references. - Replace the unused adopter-migration document name with an implementation compatibility note; no external adoption or adopter migration is implied.
- Add automated checks for documentation links, version agreement, public-boundary language, packaged demo behavior, and checked-in specimen determinism.
- Add repository-level instructions that keep automated contributors inside VSTD's fail-closed claim, dependency, compatibility, and public/private boundaries.
1.0.1 - 2026-08-22#
- State explicitly that each VSTD closure coordinate requires its own evidence: Refutability does not supply, entail, upgrade, or repair prerequisite coordinates.
- Replace unsupported Tarski, generic NP-certificate, CNF-equals-3-SAT, and physical-world co-NP claims with bounded statements tied to implemented formal languages and declared observation surfaces.
- Replace adopter-migration framing with an exact current wire-dispatch registry; no external adoption is claimed.
- Generate source releases from exact public Git objects and publish a separate manifest binding the resolvable ref, commit, archive digest, file set, and member bytes. Line-ending equivalence is not accepted as byte identity.
- Add a side-effect-free manifest plan command and make unsandboxed execution visible at the CLI and README boundary without pretending declared-path checks sandbox the subprocess.
- Test the advertised Python 3.10 through 3.13 range, add release-integrity and installed-wheel jobs, and expose one required conformance gate for branch protection.
- Add an owner-dispatched release workflow for an existing tag that refuses a non-default-branch dispatch or a tag outside protected history, requires the protected conformance check and an owner-confirmed immutable-release preflight, rebuilds and smoke-tests exact artifacts, records tag signature status without relabeling it, and creates GitHub/Sigstore attestations for every uploaded asset.
- Add structured ambiguity, counterexample, and implementation feedback surfaces plus public conduct and pull-request consequence checks.
1.0.0 - 2026-08-22#
- Redesign specification numbers as cumulative numbered profiles: VSTD-1 through VSTD-5 on the object axis and VSTD-Graph-1 through VSTD-Graph-5 on the collection axis.
- Establish integer numbered-profile specification paths while release history remains available in the corresponding Git tags.
- Add the fourteen-rung VSTD-4 structural calculation and compute its candidate depth by iterated satisfiability rather than copying a declared depth. Version 1.2.0 clarifies that its caller-supplied references do not establish VSTD-4 conformance.
- Add the
VSTD4-GDC-1grounded decision-certificate format, independent bounded checker, Horn/unit-propagation tier, width-bounded and general-resolution tiers, and evidence-bearingUNKNOWNresults on exhaustion. - Add machine-readable refutation surfaces, precommitment envelopes, availability assessment, append-only challenge adjudication, monotonic degradation, and refutability closure.
- Preserve the historical
graph_levelcompatibility calculation from membership, provenance closure, status, and caller-supplied edge ratings, with a certificate explaining the next unreachable candidate Graph profile. Version 1.2.0 labels conformanceNOT_ESTABLISHED. - Replace fabricated conflict evidence, literal trust-boundary claims, and decorative policy certificates with checked evidence and fail-closed divergence.
- Publish a draft VSTD-5 witness-corroboration interface. No independent witness implementation or interoperability claim is included.
- Move profile-specific documentation under
docs/and publish schemas with stable compatibility filenames and paths.
0.2.0 - 2026-08-21#
- Implement VSTD-3.0 Universal Accelerator Accountability without changing earlier receipt semantics.
- Add strict deterministic VSTD 3 types and JSON Schemas, plus a data-driven registry covering 37 accelerator/supporting-device profiles.
- Add the virtual firmware accountability state machine, nonce-bound test attestation, typed compute accounting, authenticated continuity, reset epochs, and local/file anchor interfaces.
- Add partition/topology and enrolled-fleet verification with physical/logical double-counting protection.
- Add generic, NVIDIA, AMD, Intel, and Google/AWS/Microsoft provider fixture boundaries. Opaque vendor evidence is preserved without invented verification.
- Compose device, firmware, execution, accounting, continuity, and provider evidence into the existing provenance hypergraph and blast-radius implementation.
- Add
hardware,continuity,fleet,evidence, andclaimsCLI command families with JSON and explicitPASS/FAIL/UNKNOWN/UNSUPPORTEDresults. - Add adversarial, epistemic, canonicalization, schema, provenance, adapter, CLI, and backward-compatibility tests.
- Publish a VSTD 3 threat model, vendor integration kit, migration guide, primary-source references, and claim-by-claim plain-language translations.
0.1.0 - 2026-08-21#
- Publish the initial claim-mechanics, provenance-graph, and experimental verification-geometry surfaces.
- Publish zero-required-dependency receipt, provenance, geometry, and policy primitives.
- Publish an optional logits-level constraint kernel with atomic dependency profiles.
- Add a target-neutral public CLI for generic-run and stored VSTD-DATA receipts.
- Fail closed on malformed provenance graphs, inflated coverage metrics, dangling references, and omitted artifact status.
- Clarify that digest, license, and policy fields bind recorded declarations rather than proving real-world truth or complete lineage.
- Add a non-normative predictive-AI and competition-evaluation integration profile.
- Add a plain-language claim translation guide stating why each bounded claim can or cannot be made and what evidence it requires.
- Explicitly exclude private operational material and target-specific adapters.
- Release the specification, documentation, and reference implementation under the Apache License 2.0 with a repository
NOTICEfile.