Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 18 additions & 14 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,18 +22,21 @@ same exact release bytes.

## Spacecraft finite-burn certificate

**Commit-scoped status:** this source snapshot was prepared as the **v1.7.5
corrective release candidate** before publication. A tag or source snapshot does
not itself establish current GitHub publication state; consult the
[releases index](https://github.com/AnubisQuantumCipher/jackal/releases) and
the postpublication readback on `master`. The v1.7.5 tag page exists only after
publication. At this candidate commit, the
historical v1.7.4 release remained published and its 11 public assets had passed
download readback, but **v1.7.4 should not be used as the publication-grade
verifier bundle**. Its tag full-certificate campaign was cancelled at the
60-minute ceiling. The v1.7.5 candidate was prepared to close gaps in the
structured verdict, claim surfaces, executable archive, verification
instructions, and tag campaign before independent review and publication.
**Published state:** [JACKAL v1.7.5](https://github.com/AnubisQuantumCipher/jackal/releases/tag/v1.7.5)
is the observed public **Latest** release and is neither a draft nor a
prerelease. Its qualified verdict is **CERTIFIED SAFE under the stated
finite-burn ODE model, supplied input bounds, and machine-checked
interval-certificate assumptions**. Fresh downloads reproduced all 12 uploaded
release asset byte identities and all 11 `SHA256SUMS` payload rows; the committed
[v1.7.5 readback receipt](release/evidence/spacecraft_burn_release_readback_v175.json)
binds the PR, merge, annotated tag, release metadata, asset sizes and hashes,
proof/checker/source/request/witness/review identities, hosted checks, plugin
identity, protected checkout, and explicit non-claims.

The v1.7.4 release, tag, assets, and
[historical readback](release/evidence/spacecraft_burn_release_readback_v174.json)
remain immutable historical evidence. v1.7.4 is not the publication-grade
verifier bundle; v1.7.5 is the corrective published epoch.

The published historical [v1.7.4 release](https://github.com/AnubisQuantumCipher/jackal/releases/tag/v1.7.4)
added a repository/release formal certificate for the spacecraft finite-burn
Expand All @@ -52,8 +55,9 @@ request, model, epoch, nonce, and receipt. See
assurance boundary and physical-model non-claims.

This lane does not add an MCP command. The ordered agent catalog remains 41
tools; use the repo-local CLI now, and use v1.7.5 release assets only after the
fresh public-download readback is committed.
tools. Use either the repo-local CLI or the exact published v1.7.5 assets; the
[public-download readback](release/evidence/spacecraft_burn_release_readback_v175.json)
binds the release bytes without changing the plugin surface.

JACKAL is written in **Anubis Safe mode**. It does not try to win by adding another wall of
buttons. It treats a serious calculation as a bounded scientific claim: value, units,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -939,38 +939,75 @@ binds its live Python/Git runtime to the proof identity, builds a deterministic
safe-entry archive, and reproduces the checker and outer-verifier procedure.
The v1.7.4 packager remains byte-for-byte unchanged.

- [ ] **Step 4: Complete a new independent review**
- [x] **Step 4: Complete a new independent review**

Review the exact v1.7.5 candidate, including the Picard enclosure producer,
formal checker, source binding, structured claims, and executable package.
Record an internal independent-review report and clearance with zero unresolved
release blockers; do not call it external peer review.

- [ ] **Step 5: Run every full release gate on the final reviewed candidate**
Completion evidence: reviewed commit
`54c9af66405c445d17735c92ee177cd652fc34b9` received 37 independent-review
passes; 17 findings were resolved, 1 was classified invalid, and 0 unresolved
release blockers remained. The review report and clearance bind the exact
reviewed candidate and preserve the internal-review/non-peer-review boundary.

- [x] **Step 5: Run every full release gate on the final reviewed candidate**

Run the full Lean build, axiom and admission audit, evidence reproduction,
checker/verifier replay, mutation campaign, claim gate, package extraction
replay, capability drift, all 41-tool plugin checks, skill validation,
repository tests, and clean-diff checks from fresh state.

- [ ] **Step 6: Commit, push, review, merge, and verify the merge SHA**
Completion evidence: the full Lean build, admission/axiom audit, proof identity,
checker and outer-verifier replay, evidence reproduction, mutation campaign,
claim gate, capability/plugin checks, repository tests, and clean extraction
replay passed. Two complete campaigns were byte-identical across the five
decisive outputs; two deterministic package builds matched as 12-asset
directories, and `SHA256SUMS` verified all 11 payload rows.

- [x] **Step 6: Commit, push, review, merge, and verify the merge SHA**

Push the corrective branch, open a PR with exact proof and non-claim evidence,
wait for every required check and review disposition, merge through repository
convention, and then require every relevant workflow to pass on the exact
remote `master` merge commit.

- [ ] **Step 7: Tag and publish v1.7.5 from the verified merge**
Completion evidence: PR
[17](https://github.com/AnubisQuantumCipher/jackal/pull/17) bound head
`eb69713918798f5828950d92f1003c66d2eb26ca` and merged as
`9a49f70b65b20907df40be99ee83e61e18adc7c5`. The required PR workflows and
the exact-merge `master` workflows completed successfully.

- [x] **Step 7: Tag and publish v1.7.5 from the verified merge**

Build and compare the release assets from the exact merge commit, create and
push an annotated v1.7.5 tag, wait for all tag-triggered workflows, validate a
draft with the explicit asset roster and checksums, and publish it as Latest
only after every gate is green.

- [ ] **Step 8: Read back the public release and merge the closure receipt**
Completion evidence: annotated tag object
`1369dacf60101c2d196d577b0319b6d5c0a72aa8` peels to merge
`9a49f70b65b20907df40be99ee83e61e18adc7c5`; all three tag-triggered
workflows completed successfully. Public release
[377032844](https://github.com/AnubisQuantumCipher/jackal/releases/tag/v1.7.5)
was published as Latest with 12 uploaded release assets and is neither a draft
nor a prerelease.

- [x] **Step 8: Read back the public release and merge the closure receipt**

Download every public asset into fresh storage, verify the tag target, sizes,
hashes, `SHA256SUMS`, metadata, and the extracted verification procedure.
Commit the v1.7.5 publication-readback receipt and final README state in a
separate closure PR, merge it, and audit remote refs, plugin identity, and the
untouched protected checkout one final time.

Completion evidence: fresh public downloads reproduced all 12 uploaded release
asset sizes and SHA-256 identities, all 11 `SHA256SUMS` rows, the canonical
checker `ACCEPT`, the authoritative outer-verifier `ACCEPT`, and the public
Latest metadata. The
new `release/evidence/spacecraft_burn_release_readback_v175.json` records those
observations, the unchanged plugin/protected-checkout identities, and the
explicit non-claims. The closure commit containing that receipt and this final
prose is landed through this closure PR before terminal declaration; no PR
number is invented here.
Loading
Loading