Skip to content

Commit 7962e84

Browse files
committed
docs(security): record source-bound validation evidence
1 parent 47f1c9c commit 7962e84

4 files changed

Lines changed: 142 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ are not validation certificates. See [the current assessment](docs/security/NIST
1111

1212
| Version | Supported |
1313
| ------- | ------------------ |
14+
| 4.x.x | :white_check_mark: (current development line) |
1415
| 3.x.x | :white_check_mark: |
1516
| 2.x.x | :white_check_mark: (security fixes only) |
1617
| 1.x.x | :x: |

docs/security/NIST_READINESS.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -51,6 +51,9 @@ The implementation correspondence audit passed all seven groups (12,641 finite
5151
checks). Lean rebuilt 47 theorems, audited their dependencies, and rejected three
5252
false fixtures. These counts describe different kinds of evidence and are not
5353
added together into a security score.
54+
The [validation receipt](evidence/validation-20260918.json) records the source
55+
commit and hashes; [the correspondence receipt](evidence/runtime-contracts-20260918.json)
56+
records each group. Subsequent changes must be assessed against their own commits.
5457
Tests of insecure mocks establish protocol mechanics only. Native backend smoke
5558
tests require an actual library, exact ML-KEM-768/ML-DSA-65 algorithm availability,
5659
round trips and rejection of altered signature messages.
Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
{
2+
"schema": "scbe-lean-correspondence/v1",
3+
"repository": "SCBE-AETHERMOORE",
4+
"head": "47f1c9c836fd50aac271b7fc38f52a662e4b125c",
5+
"scope": "Finite implementation checks, not whole-program verification or security assurance",
6+
"sources": {
7+
"codec": {
8+
"path": "src/crypto/sacred_tongues.py",
9+
"sha256": "322b72e5147aae80f63bbb1ba1148af71e97252f287894ee99198c527bc74863"
10+
},
11+
"cfi": {
12+
"path": "src/symphonic_cipher/topological_cfi.py",
13+
"sha256": "51dce525b504e491143bc2486ab9b4656f37722c824b6ad8dc6074057ecb0ddd"
14+
},
15+
"layers": {
16+
"path": "src/symphonic_cipher/scbe_aethermoore/layers/fourteen_layer_pipeline.py",
17+
"sha256": "3ee7e8c78fa6d1b4272751cf13a0c77c008c31fdb8c4197490452263c5a381df"
18+
},
19+
"full": {
20+
"path": "src/symphonic_cipher/scbe_aethermoore/full_system.py",
21+
"sha256": "f338ee728feb29d92f1ff027611fa20ac23b150cafab2b40321ed5a831b3b106"
22+
}
23+
},
24+
"checks": [
25+
{
26+
"contract": "six_codec_tables",
27+
"status": "PASS",
28+
"cases": 10758
29+
},
30+
{
31+
"contract": "L12_exact_formula_samples",
32+
"status": "PASS",
33+
"cases": 35
34+
},
35+
{
36+
"contract": "L12_invalid_domain_rejection",
37+
"status": "PASS",
38+
"cases": 5
39+
},
40+
{
41+
"contract": "L5_interior_geometry_samples",
42+
"status": "PASS",
43+
"cases": 192
44+
},
45+
{
46+
"contract": "frozen_directed_CFI",
47+
"status": "PASS",
48+
"cases": 1604
49+
},
50+
{
51+
"contract": "full_system_refusal_precedence",
52+
"status": "PASS",
53+
"cases": 32
54+
},
55+
{
56+
"contract": "L6_positive_deformation_contract",
57+
"status": "PASS",
58+
"cases": 15
59+
}
60+
],
61+
"passed": true
62+
}
Lines changed: 76 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,76 @@
1+
{
2+
"schema": "scbe-security-validation/v1",
3+
"source_commit": "47f1c9c836fd50aac271b7fc38f52a662e4b125c",
4+
"scope": "Selected code contracts, not whole-system security, accuracy benchmarking or certification",
5+
"python": {
6+
"tests": 482,
7+
"failures": 0,
8+
"errors": 0,
9+
"junit_sha256": "6fbbdaba83bf76669b3402c1d5c0b19c4bf3ed249a4898bdeb9fe9c7c1216956"
10+
},
11+
"typescript": {
12+
"tests": 105,
13+
"failures": 0,
14+
"files": 4
15+
},
16+
"lean": {
17+
"theorems": 47,
18+
"negative_fixtures_rejected": 3,
19+
"receipt_sha256": "1e60db1b698f0a113a7b329f890558d601ba1319254c6cd061d110120a8bb722"
20+
},
21+
"source_hashes": {
22+
".github/workflows/lean-contracts.yml": "95b7ed714371895a4bf3040b1554dda0b2aefdb4393a6a58a6ea9ccb6ad08984",
23+
".github/workflows/pqc-native-liboqs.yml": "ce25aef547855e54aba10e16926ca448c09b2af59a72d8f842623b2dc6d320c0",
24+
"examples/SCBEAgent/uv.lock": "5b9052592c63d9d806ab25e8a12f6667cd3038dd1b974d3ec61239f3d9bf2539",
25+
"formal/lean/.gitattributes": "92cdfb8257b339f97ac1bb86f4675d626f6079a9995535705a4819ab3f4dfb1e",
26+
"formal/lean/.gitignore": "cfc7ea47af89556b09b27ecb4e4e542a0549f1e9c852b327edbda5b274ea6f15",
27+
"formal/lean/SCBE.lean": "9a10a28d8cb462c080adec55b808c5b8608bc3b68b16d7a8b2e02755b791f9b0",
28+
"formal/lean/SCBE/Codecs.lean": "f7e328e43700b6a254bd2d2277e39ab69b421a1a26337866875f8be6acaf1119",
29+
"formal/lean/SCBE/Composition.lean": "3556677efe539e19f09fb817eb5df04cb3634e7bb87e55436cddc576b00f033e",
30+
"formal/lean/SCBE/Geometry.lean": "2721a4697ffdf85832fc448c63727e94ad087e7ac9336e98291ec569c4f58950",
31+
"formal/lean/SCBE/Harmonic.lean": "d2bac727431ac343e584ea9a5bfc97e1ef3f3118bee5d83431fa73ac5d0ae637",
32+
"formal/lean/SCBE/Routing.lean": "09eb37e33bdca162872dc3168f259f68d46e939baa400572bb5a6eaf7d993591",
33+
"formal/lean/SCBE/Vocabulary.lean": "43c19230fb85703343def772aab3b06648ccdce8158509fc3cba1e1f2bcd4219",
34+
"formal/lean/audit_implementation.py": "1680811f3026f218093e96904359726c17f43f12ac93e7dbf7fa9e52fd5eb7e6",
35+
"formal/lean/evidence/proof-20260918.json": "7a4b22d27a713f8e47bca894dc10ac3ca6f2bd53ca4a2347ce896e348c5e6889",
36+
"formal/lean/evidence/proof-portable-20260918.json": "7cc674cce36aa2d877655b3e6f56ea8649673894ed4bc7baeee4a4e5f0c76b5d",
37+
"formal/lean/export_vocabulary.py": "a77f2a0d657c273334ac83aa3eb3071d5a549f59cca9b90c4b2d7ed4c091a301",
38+
"formal/lean/lake-manifest.json": "b32a7bfac961bdbac326e97b578e38d966a89e1f31551e208aef783c92b4a86c",
39+
"formal/lean/lakefile.toml": "705aa586642f5133d36551e3c34620d472553799a09c2418346a99b3cec4b604",
40+
"formal/lean/lean-toolchain": "55e97be96000b5e9e290c9e74482e5e317861499a5540353ce845471bded8cea",
41+
"formal/lean/verify.py": "5040aa95b297a2229b6e8c9265cc3eabc9045ec5fba1156f29cab6d1baa2de26",
42+
"packages/kernel/src/hamiltonianCFI.ts": "159ab531cd9b16cd66e7aea12acadb2bc0f16195d16c9d7509a52ed2e26d5269",
43+
"packages/kernel/src/hyperbolic.ts": "fcc969bec83ef69f6cf95b068ee568e0cb78545557a5c056e4efba0fac1f5bd6",
44+
"scripts/security/native_liboqs_smoke.py": "4bd40be74c8ce2e7cc1073affc30e2a96acf52eb56db1314089a8296a6b499e8",
45+
"scripts/system/run_core_python_checks.py": "8d879af8b47ddd8a7cf3794c755eddbcf44d267277feb24a8ab95bb6106ac759",
46+
"src/governance/runtime_gate.py": "9570ba5f2d97de318168ef80ec086b6e1e491323f38409f1b2ca2fc7fd1871f3",
47+
"src/harmonic/hyperbolic.ts": "ebf34e0a45fb5b6ec42e0950788a8559862741c5beadf5d08148ed10ef2e4340",
48+
"src/symphonic_cipher/scbe_aethermoore/axiom_grouped/causality_axiom.py": "d0027fdad9ea012adec44089fdb9d000e71ce6b2c31ed65f4c103d3684cfa03e",
49+
"src/symphonic_cipher/scbe_aethermoore/constants.py": "377af9f0c1226b45acdabd93096d166b465cb218d8679985b5ad7f5a2e1d17d3",
50+
"src/symphonic_cipher/scbe_aethermoore/dual_lattice.py": "7869a92e26788b263a8dbbe163e650b32b98f253871e0e2fea003285f627e0ec",
51+
"src/symphonic_cipher/scbe_aethermoore/full_system.py": "f338ee728feb29d92f1ff027611fa20ac23b150cafab2b40321ed5a831b3b106",
52+
"src/symphonic_cipher/scbe_aethermoore/layers/fourteen_layer_pipeline.py": "3ee7e8c78fa6d1b4272751cf13a0c77c008c31fdb8c4197490452263c5a381df",
53+
"src/symphonic_cipher/scbe_aethermoore/pqc/__init__.py": "0895cedecdd264213cd785189c33110fc46d0c8d9d2ad871166f8dade4e8dbdc",
54+
"src/symphonic_cipher/scbe_aethermoore/pqc/pqc_core.py": "c05a5f8d085d5a21d48901b018afb19bf799fc4766598af7cf484bef50b3a9a1",
55+
"src/symphonic_cipher/tests/test_fourteen_layer.py": "40d763ade9c588b598d8235d84203bcb77b81830e7173c0d851f7935696a3e98",
56+
"src/symphonic_cipher/topological_cfi.py": "51dce525b504e491143bc2486ab9b4656f37722c824b6ad8dc6074057ecb0ddd",
57+
"symphonic_cipher/scbe_aethermoore/axiom_grouped/causality_axiom.py": "d27d2e34ed9afc656bb1e0f852fdc0ef02103da8ebabf9bb453082e446ad76b9",
58+
"symphonic_cipher/scbe_aethermoore/constants.py": "e80b29dec6d92acdd797b8cf9c3d6941e535f6feedd805284cb1691d94a265e8",
59+
"symphonic_cipher/scbe_aethermoore/dual_lattice.py": "be08a4aeb7ebbdb6dcc9e4c77c3f1dc62831f8b8ca33efcb19572844b26a3967",
60+
"symphonic_cipher/scbe_aethermoore/full_system.py": "a60c2f50e7944e0374fae7476570cfd75c7e0dab7065ffb5df4e02a887fde7a0",
61+
"symphonic_cipher/scbe_aethermoore/layers/fourteen_layer_pipeline.py": "083f1fc279c01eca6aedd09bc4261ba8b30dfbab8c62778bb3252b6b8120125e",
62+
"symphonic_cipher/scbe_aethermoore/pqc/__init__.py": "0895cedecdd264213cd785189c33110fc46d0c8d9d2ad871166f8dade4e8dbdc",
63+
"symphonic_cipher/scbe_aethermoore/pqc/pqc_core.py": "b174093e1a4506f6cec71d192813f5271f49280e9bfd2e7733e613690fc49ce2",
64+
"symphonic_cipher/tests/test_fourteen_layer.py": "abbe800df35976d0c1d3b26b28ef0fb2e6bbf01ff6a5ba77f42930907a61ad47",
65+
"symphonic_cipher/topological_cfi.py": "861039adb101f766830124a21daa7e0e75644f6a009912485f56d172df137fd9",
66+
"tests/governance/test_full_system_decision_precedence.py": "26172fea3afdfb5b8fea485508b7f1c2c0d64310aa09f6d6a8c58bcc665d3fe2",
67+
"tests/governance/test_patent_decision_repairs.py": "653a3207a94ae1010126615de48339807539b04f5f2235e18cbc9e480a329ed1",
68+
"tests/harmonic/breathing.security.test.ts": "5d38aefb8042c2b241d16eb8c9ffd808c1fdfdf90bbff908193d6b39bef16203",
69+
"tests/harmonic/hamiltonianCFI.security.test.ts": "c7af48af92d54286bfd6e9401f5cfe1553dc9cc07609f7aabdb35524ec880a3b",
70+
"tests/security/test_breathing_and_backend_contracts.py": "8f641d51374c216525f9d38d24c5a821aa7d4fb8651e1c6b0e8a6d3a8d31b892",
71+
"tests/test_patent_security_regressions.py": "2a9b1668d483d9878117e8db1f1b56fced4c98610eda7a75590cae609b5d273a",
72+
"tests/test_pqc.py": "624dfe98aec3f89bcca543cd8c11527307fa3b349498b990615f844f3a494e90",
73+
"tests/test_runtime_gate.py": "b874211ab2b32c1c02050adbfd44ceb719372eeeaac353a949660e2010476c2c",
74+
"tests/test_runtime_gate_hybrid_monotonic.py": "0abf66020cf86b7af6562b21a0224bc210a74902c79eb469bdfdf0876dd21426"
75+
}
76+
}

0 commit comments

Comments
 (0)