An AlgoVoi original. This directory implements the six executed assurance phases
P1-P6 of kaf/DESIGN.md, the design of record. The phase numbering here is the
source of truth: it matches the sealed receipts in receipts/ (v3p1a .. v3p5a,
sealed under P6).
The corpus stops being "a list of vectors" and becomes a measured system on four axes: agreement (independent implementations in byte-exact consensus), strata (generated coverage of the input space), cells (runtime environments the verdicts hold in), and seal (signed, hash-chained, offline-verifiable evidence).
A cell is (language, runtime version, libc variant), pinned in
cells.json and resolved to an exact image digest per run
(cells.lock.json). The contract:
- Provisioning runs with network ON as a recorded exception
(
provision_cell.sh): interpreter dependencies land on a volume, the outcome (pip freeze, any per-package failure) is written toprovision.jsonand embedded in the receipt. - Execution runs with
--network=none(cell_exec.shviarun_cell.sh): the corpus is mounted read-only, a network canary (a real program file) must prove the network unreachable, and every suite runs as a real module. The real-module rule is absolute: nothing executes via-e/-c/REPL contexts, which inject globals that mask environment defects (the Node 18crypto.subtlelesson). - Suites per cell: the L1 composition checks (
verify_corpus,first_principles,adversarial_jcs,mutation_fuzz) on python cells, and the single-language per-set matrix (run_matrix_lang.sh) everywhere.
Run on the host (VM2):
bash kaf/orchestrate_p1.sh <run_id> [cell_id ...]
The remaining runtime phases execute under the same cell contract, and each seals its own receipt:
- P2, published-package cells. The conformance run executed against the published PyPI/npm packages rather than local source, catalog-anchored with an in-cell canary.
- P3, differential rejection consensus. Ten independent JCS implementations must agree on every adversarial rejection (full 10-way consensus) before any input shape reaches a signing preimage.
- P4, strata blast. Seeded mutation-forgery generators fire across the corpus; zero escapes, plan reproducible from the seed.
- P5, L1-L4 composition chains plus the junction / splice attack gauntlets.
seal.py turns a green run into a sealed receipt:
- The receipt body is JCS-canonicalized with algovoi-substrate and must byte-match the independent rfc8785 implementation (a differential check inside the sealer).
- The seal is an RFC 9421 + RFC 9530 signature over a synthetic HTTP
message carrying those bytes, produced by the published
algovoi-rfc9421-signer. - The envelope file IS its canonical bytes; its sha256 is the chain link.
Each receipt names its predecessor's digest; the first is anchored to
the P0 snapshot MANIFEST, committed here as
kaf/MANIFEST.txt(sha256e5282959...). History cannot be reordered or backdated.
kaf_verify.py re-proves all of it offline with the published
algovoi-rfc9421-verifier against the pinned key in
keys/kaf-seal.pub.json:
python kaf/kaf_verify.py --receipts-dir kaf/receipts \
--pub-file kaf/keys/kaf-seal.pub.json \
--genesis-anchor kaf/MANIFEST.txt --expect-count 18
The framework certifies itself with the primitives it certifies. That is the stamp.
keys/kaf-seal.pub.json pins the seal public key and keyid. The private
seed lives outside every repository and is never printed, logged, or
transmitted.
- A skipped anything is named and counted, never silent
(
provision_failed_specs, theexecution_ref_v1[node]optional-dep skip). seal.pyrefuses to seal a run that is not fully green.- A receipt that fails any check is a hard failure, not a warning.