Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
116 commits
Select commit Hold shift + click to select a range
da407e7
Fix CRLF-dependent research book manifest hash
SHi-ON Sep 7, 2026
dff341b
Add integration contracts, hashing primitives, and package skeletons
SHi-ON Sep 7, 2026
680a7c0
Implement Phase B runtime packages: hashing chain, evidence writer, m…
SHi-ON Sep 7, 2026
5ed51da
Tighten shared contracts after Phase B integration
SHi-ON Sep 7, 2026
25d4c0c
Implement Phase C: checkpoint service, Base anchor publisher, indepen…
SHi-ON Sep 7, 2026
ff96ed2
Integrate Phase C: stream-aware chain links, evaluationTurns passthro…
SHi-ON Sep 7, 2026
ae1aa52
Implement Phase D-1: statistics toolkit, DTSF twin routes, orchestrat…
SHi-ON Sep 7, 2026
6d7aa35
Verifier: read an absent auxiliary tree as the empty tree for consist…
SHi-ON Sep 7, 2026
33fa5d9
Add production runtime wiring, E03/E11 qualification harnesses, repor…
SHi-ON Sep 7, 2026
217e4d0
Harden anchor publisher and checkpoint scheduler per adversarial review
SHi-ON Sep 7, 2026
a20275d
Harden the independent verifier per adversarial review
SHi-ON Sep 7, 2026
488bc06
Harden Phase B packages per adversarial review; withhold randomSeed f…
SHi-ON Sep 7, 2026
b64d08d
Harden the Nursery runtime per adversarial review
SHi-ON Sep 7, 2026
11d8387
Raise vitest timeouts for the heavy end-to-end runtime tests
SHi-ON Sep 7, 2026
117dcfd
Learners: recovery-safe ledger bookkeeping and checkpointed registries
SHi-ON Sep 7, 2026
d91ddba
Harden twin routes per adversarial review
SHi-ON Sep 7, 2026
e9a8abe
Learners: tolerate any legal message length, idempotent per-turn call…
SHi-ON Sep 7, 2026
6bbe22c
Add first qualification report, project status, and backlog verificat…
SHi-ON Sep 7, 2026
fcef18f
Extend shared contracts for Phase E: intervention plans, pre-registra…
SHi-ON Sep 8, 2026
3157d4f
feat: recover Phase E protocol foundations
SHi-ON Sep 8, 2026
8dec6dc
feat: gate run creation on scenario quarantine
SHi-ON Sep 8, 2026
cc2f885
feat: execute pre-registered curriculum stages
SHi-ON Sep 8, 2026
dca8b94
feat: execute verifier-bound causal probes
SHi-ON Sep 8, 2026
3ce7c66
feat: execute bounded repair turns
SHi-ON Sep 8, 2026
e69180b
test: verify retention enforcement end to end
SHi-ON Sep 8, 2026
e961e19
feat: enforce research-grade container isolation
SHi-ON Sep 9, 2026
6631b10
feat: run active side-channel attacks
SHi-ON Sep 9, 2026
fba46a6
fix: witness intervention evidence in checkpoints
SHi-ON Sep 9, 2026
b64c13f
feat: bind analysis attachments to run evidence
SHi-ON Sep 9, 2026
582a39f
test: synchronize shutdown snapshot signal
SHi-ON Sep 9, 2026
7837a65
feat: instrument ephemeral encoding research
SHi-ON Sep 9, 2026
5566470
feat: interpret delayed human audit ledgers
SHi-ON Sep 9, 2026
b10ddd1
feat: evaluate alternate-carrier leakage
SHi-ON Sep 9, 2026
707b2ed
feat: attest scratch learner initialization
SHi-ON Sep 9, 2026
48c51f3
feat: verify derived run lineage
SHi-ON Sep 9, 2026
0e2b1ae
fix: audit blocked observations
SHi-ON Sep 9, 2026
21914ba
test: enforce side-channel route contracts
SHi-ON Sep 9, 2026
6cf4ab4
feat: witness model and claim provenance
SHi-ON Sep 9, 2026
b284313
feat: attest self-supervised update contract
SHi-ON Sep 9, 2026
9265e60
feat: qualify semantic leakage claims
SHi-ON Sep 9, 2026
44a2701
test: prove Mode R training isolation
SHi-ON Sep 9, 2026
c231d04
feat: add the Research Console
SHi-ON Sep 9, 2026
bbd67aa
feat: bind operational integrity records
SHi-ON Sep 9, 2026
0a4ba4d
feat: enforce experiment readiness gates
SHi-ON Sep 9, 2026
5f22202
ci: consolidate release readiness checks
SHi-ON Sep 9, 2026
429f64f
docs: record hosted integrity evidence
SHi-ON Sep 9, 2026
a2a1145
test: eliminate cryptographic substring flakes
SHi-ON Sep 9, 2026
2a2deb2
docs: plan research execution readiness
SHi-ON Sep 9, 2026
340b829
ci: enforce dependency integrity
SHi-ON Sep 9, 2026
46df2d4
feat: make E03 design reproducible
SHi-ON Sep 9, 2026
2e5fa9a
feat: compile E03 registration artifacts
SHi-ON Sep 9, 2026
d2a5286
feat: fail closed before confirmatory runs
SHi-ON Sep 9, 2026
132d6c5
feat: qualify real frozen models
SHi-ON Sep 9, 2026
84c94b9
fix: bind real model provenance in conformance
SHi-ON Sep 9, 2026
1389e53
fix: support live llama qualification
SHi-ON Sep 9, 2026
443e66e
fix: keep tool constraints interoperable
SHi-ON Sep 9, 2026
494d666
docs: retain real frozen-model qualification
SHi-ON Sep 9, 2026
d1b4eab
feat: complete research execution readiness
SHi-ON Sep 9, 2026
355391f
build: migrate workspace validation to pnpm
SHi-ON Sep 11, 2026
559436f
docs: establish research evidence baseline
SHi-ON Sep 11, 2026
ca7a188
feat: generate requirement conformance matrix
SHi-ON Sep 11, 2026
433b1d2
docs: seal frozen validation receipt
SHi-ON Sep 11, 2026
745f9ab
feat: add independent integrity auditor
SHi-ON Sep 11, 2026
f7df56a
docs: record integrity challenge results
SHi-ON Sep 11, 2026
97a33be
feat: qualify full Mode R topology
SHi-ON Sep 11, 2026
afb130b
docs: seal Mode R topology receipt
SHi-ON Sep 11, 2026
6871f8d
feat: add matched recurrent scientific baselines
SHi-ON Sep 11, 2026
2595b51
docs: seal recurrent baseline qualification
SHi-ON Sep 11, 2026
886dd53
feat: teach learners generative carrier forms
SHi-ON Sep 11, 2026
e4332af
docs: seal generative carrier qualification
SHi-ON Sep 11, 2026
d6d98df
feat: attest frozen model execution
SHi-ON Sep 11, 2026
9530c85
docs: seal frozen model qualification
SHi-ON Sep 11, 2026
48f6082
feat: qualify study control lifecycle
SHi-ON Sep 11, 2026
39a6e45
fix: audit derived policy references
SHi-ON Sep 11, 2026
b2b119c
docs: record study control qualification
SHi-ON Sep 11, 2026
ccf455b
docs: freeze integrated software candidate
SHi-ON Sep 11, 2026
9aac5f3
docs: audit sources and challenge novelty
SHi-ON Sep 11, 2026
52046d6
docs: freeze research questions and estimands
SHi-ON Sep 11, 2026
8b2f364
fix: lock leakage-safe scenario splits
SHi-ON Sep 11, 2026
ca5871c
fix: validate statistical decision rules
SHi-ON Sep 11, 2026
934d7a8
fix: freeze causal and leakage decisions
SHi-ON Sep 11, 2026
a450329
feat: freeze seed and resource allocation
SHi-ON Sep 11, 2026
2bad1b6
feat: gate campaign registration readiness
SHi-ON Sep 11, 2026
1994593
feat: inventory evidence claim boundaries
SHi-ON Sep 11, 2026
5cecfcf
feat: benchmark local audit cost and utility
SHi-ON Sep 11, 2026
61bed99
feat: add prospective causal comparator pipeline
SHi-ON Sep 11, 2026
541142d
fix: make clean checks build before audits
SHi-ON Sep 11, 2026
45e8907
test: qualify causal prediction comparators
SHi-ON Sep 11, 2026
1be279e
feat: enforce canonical registration packet completeness
SHi-ON Sep 11, 2026
645a529
feat: add carrier perception diagnostics
SHi-ON Sep 11, 2026
27f4dad
test: qualify carrier perception diagnostics
SHi-ON Sep 11, 2026
62e3ae1
feat: add carrier side-feature attacks
SHi-ON Sep 11, 2026
42dc839
test: qualify carrier side-feature defenses
SHi-ON Sep 11, 2026
3c7f6a0
feat: bind causal predictions before receiver outcomes
SHi-ON Sep 11, 2026
82b65c6
test: qualify causal prediction runtime evidence
SHi-ON Sep 11, 2026
a8370bc
docs: complete manuscript readiness review
SHi-ON Sep 11, 2026
0dc16bd
docs: make external prerequisites auditable
SHi-ON Sep 11, 2026
7c30018
docs: bind current upstream workflow state
SHi-ON Sep 11, 2026
a6b500b
docs: record Fort-backed qualification
SHi-ON Sep 12, 2026
ae47054
feat: adopt simulation-funded research profile
SHi-ON Sep 12, 2026
c37e375
feat: enable repository-native research registration
SHi-ON Sep 12, 2026
59cd60d
feat: preregister E00 integrity qualification
SHi-ON Sep 12, 2026
996b437
fix: remove E00 registration commit cycle
SHi-ON Sep 12, 2026
cdd8dff
feat: activate E00 simulated registration
SHi-ON Sep 12, 2026
6ac2b19
feat: implement registered E00 challenge
SHi-ON Sep 12, 2026
81fd043
fix: close Rust inclusion-proof coverage
SHi-ON Sep 12, 2026
4426162
feat: activate repaired E00 registration
SHi-ON Sep 12, 2026
60cc54d
feat: preregister cycle-free E00 qualification
SHi-ON Sep 12, 2026
4897ad0
feat: activate E00 local commitment
SHi-ON Sep 12, 2026
8cef99c
fix: close E00 anchor-class coverage
SHi-ON Sep 12, 2026
6a3faa8
feat: activate repaired E00 v5
SHi-ON Sep 12, 2026
68c9d57
feat: record qualified E00 v5 result
SHi-ON Sep 12, 2026
156fb3e
feat: add registered E01 topology runner
SHi-ON Sep 12, 2026
62dfd93
research: register the E01 isolation protocol
SHi-ON Sep 12, 2026
8d3a9f6
research: activate the E01 simulated commitment
SHi-ON Sep 12, 2026
5b14be1
research: preserve and audit the E01 v1 result
SHi-ON Sep 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
7 changes: 7 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
node_modules
.git
evidence
reports
**/dist
**/*.tsbuildinfo
*.sqlite*
6 changes: 2 additions & 4 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,5 @@ ALD_DATABASE_PATH=./evidence/ald.sqlite
ALD_LOG_LEVEL=info
ALD_BASE_NETWORK=base-sepolia

# Paths and endpoints are intentionally blank.
ALD_KEY_DIR=
ALD_BASE_RPC_URL=
ALD_ANCHOR_KEY_FILE=
# Secret values and secret file paths are injected only by `si fort run`.
# They are intentionally absent from this file.
86 changes: 58 additions & 28 deletions .github/workflows/book-integrity.yml
Original file line number Diff line number Diff line change
@@ -1,47 +1,77 @@
name: Research book integrity
name: Consolidated integrity suite

on:
pull_request:
paths:
- RESEARCH.md
- research-book.html
- book/**
- scripts/build-research-book.mjs
- scripts/research-book-entry.js
- package.json
- package-lock.json
- vitest.config.ts
push:
branches:
- main
paths:
- RESEARCH.md
- research-book.html
- book/**
- scripts/build-research-book.mjs
- scripts/research-book-entry.js
- package.json
- package-lock.json
- vitest.config.ts

permissions:
contents: read

jobs:
verify-book:
consolidated-suite:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4
uses: actions/checkout@v7

- name: Set up Node.js
uses: actions/setup-node@v4
- name: Set up Homebrew
uses: Homebrew/actions/setup-homebrew@49d03f1bf5d455a413dfbdf99e6718054a4cd975

- name: Install Node.js and pnpm with Homebrew
run: |
brew install node@24 pnpm
echo "$(brew --prefix node@24)/bin" >> "$GITHUB_PATH"

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Audit dependency graph
run: |
mkdir -p artifacts
pnpm audit --audit-level=high --json > artifacts/pnpm-audit.json

- name: Run consolidated suite with timing
run: |
mkdir -p artifacts
/usr/bin/time -v pnpm run check:ci 2> artifacts/consolidated-runtime.txt

- name: Upload test and runtime evidence
if: always()
uses: actions/upload-artifact@v7
with:
node-version: 22.13.0
cache: npm
name: consolidated-suite-evidence
path: artifacts/
retention-days: 30

mode-r:
runs-on: ubuntu-latest
needs: consolidated-suite
steps:
- name: Check out repository
uses: actions/checkout@v7

- name: Set up Homebrew
uses: Homebrew/actions/setup-homebrew@49d03f1bf5d455a413dfbdf99e6718054a4cd975

- name: Install Node.js and pnpm with Homebrew
run: |
brew install node@24 pnpm
echo "$(brew --prefix node@24)/bin" >> "$GITHUB_PATH"

- name: Install dependencies
run: npm ci
run: pnpm install --frozen-lockfile

- name: Run real-container Mode R suite with timing
run: |
mkdir -p artifacts
/usr/bin/time -v pnpm run test:mode-r 2> artifacts/mode-r-runtime.txt

- name: Verify manuscript and book assets
run: npm test
- name: Upload Mode R runtime evidence
if: always()
uses: actions/upload-artifact@v7
with:
name: mode-r-suite-evidence
path: artifacts/
retention-days: 30
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
node_modules/
dist/
coverage/
.artifacts/
*.tsbuildinfo
.env
.env.*
Expand Down
552 changes: 323 additions & 229 deletions BACKLOG.md

Large diffs are not rendered by default.

49 changes: 34 additions & 15 deletions CONFIGURATION.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
# Configuration

Runtime configuration is loaded through `@ald/config`. Environment variables contain
only operational values and paths. Private key material and API tokens must never be
stored directly in environment files committed to this repository.
only non-secret operational values or short-lived file paths materialized by `si fort`.
Private key material, signer seeds, RPC credentials, and API tokens must never be
stored directly in environment variables or repository files.

## Variables

Expand All @@ -13,32 +14,50 @@ stored directly in environment files committed to this repository.
| `ALD_DEPLOYMENT_MODE` | `prototype` or `research-grade` | `prototype` | No |
| `ALD_EVIDENCE_DIR` | Path | `./evidence` | No |
| `ALD_DATABASE_PATH` | Path | `<evidence>/ald.sqlite` | No |
| `ALD_KEY_DIR` | Path | `<evidence>/keys` | Yes in research-grade mode |
| `ALD_RUN_SIGNER_SEEDS_JSON_FILE` | Fort-materialized path | None | Yes in research-grade mode |
| `ALD_LOG_LEVEL` | `debug`, `info`, `warn`, or `error` | `info` | No |
| `ALD_ANCHOR_CLASS` | `simulated` or `public-chain` | `simulated` | No |
| `ALD_BASE_NETWORK` | `base-sepolia` or `base-mainnet` | `base-sepolia` | No |
| `ALD_BASE_RPC_URL` | URL | None | Required only when anchoring is enabled |
| `ALD_ANCHOR_KEY_FILE` | Path | None | Required only when anchoring is enabled |
| `ALD_BASE_RPC_URL_FILE` | Fort-materialized path | None | Required only for an amended `public-chain` profile |
| `ALD_ANCHOR_KEY_FILE` | Fort-materialized path | None | Required only for an amended `public-chain` profile |
| `ALD_ALLOW_MAINNET_ANCHORING` | `true` or unset | unset | Must be `true` (together with an explicit publisher opt-in) before any Base mainnet transaction is submitted |

## Secret Handling

- Store private keys in files outside the repository and provide only their paths.
- Store all secret values only in the encrypted `safe` repository and access them
through `si fort`; do not create ad-hoc secret files.
- Do not commit `.env` files. The repository ignores `.env` and `.env.*`.
- Use a dedicated, low-balance anchor wallet.
- Run `npm run scan:secrets` before committing.
- Research-grade mode fails fast unless `ALD_KEY_DIR` is explicitly configured.
- The approved research `RunConfig` defaults to `anchorClass: "simulated"` and uses
no wallet, RPC credential, faucet, token, or fee.
- If a future amendment permits `anchorClass: "public-chain"`, use a dedicated,
low-balance anchor wallet and independent verification endpoint.
- Run `pnpm run scan:secrets` before committing.
- Research-grade mode fails fast unless Fort materializes
`ALD_RUN_SIGNER_SEEDS_JSON_FILE` in files mode.
- Mainnet anchoring is double opt-in: the anchor publisher must be constructed with `allowMainnet: true` and `ALD_ALLOW_MAINNET_ANCHORING=true` must be set. The current governance policy separately prohibits all public-chain research transactions.
- The signer material is a versioned JSON envelope containing an exact run-id map
and all six Ed25519 signer domains. The Nursery reads its mode-0600 regular file
once; the path is then removed from the child environment. Learner containers
never receive the path or file mount. Seeds never enter the evidence store or a
bundle.

## Examples

Prototype defaults require no environment variables:

```powershell
npm run build
pnpm run build
```

Research-grade mode requires an explicit isolated key directory:
Research-grade Mode R uses Fort file materialization:

```powershell
$env:ALD_DEPLOYMENT_MODE = 'research-grade'
$env:ALD_KEY_DIR = 'C:\ald-secrets\keys'
npm run build
```sh
si fort run --repo agentic-language-development --env dev \
--keys ALD_RUN_SIGNER_SEEDS_JSON --mode files -- \
pnpm run test:mode-r-study
```

The encrypted value must authorize each exact study run id. The qualification
command can run without credentials using ephemeral in-memory signers, but that
path is explicitly non-confirmatory. Simulated funding removes the wallet/RPC
dependency; it does not remove the persistent per-run signer or registration gates.
Loading