Weave: preserved architecture, switchable implementation and provisional answers - #62
erinepshovel-code wants to merge 31 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 66f0690db4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| For each arity level `a_i`: | ||
|
|
||
| 1. partition the working bit sequence into `a_i` ordered sections; | ||
| 2. apply `I` independently to every section; | ||
| 3. preserve all bits exactly once. | ||
|
|
||
| After all declared arity levels, apply `I` once to the entire working sequence. |
There was a problem hiding this comment.
Resolve the stage input before defining the transform
When implementing this section, “working bit sequence” and the later “resulting complete bit sequence” define each level as consuming the preceding level's output, but lines 119–120 explicitly leave open whether levels instead repartition the original input, while lines 111–113 require implementations to refuse unresolved choices. Consequently, one implementation can build the sequential pipeline and claim conformance while another must fail closed; make the skeleton neutral or resolve the stage-input rule before treating it as declared.
AGENTS.md reference: AGENTS.md:L26-L30
Useful? React with 👍 / 👎.
| "source_repository": "The-Interdependency/stack", | ||
| "source_commit": "01f340ba5b4c5f107703233750768e201a41da68", | ||
| "canon_path": null, | ||
| "authority": "stack-local specification and research for Erin Spencer's intended multi-arity interleaving encryption construction", |
There was a problem hiding this comment.
Pin the evidence that defines the preserved mechanism
The pinned Stack commit contains only generic references to an intended multi-arity construction; it does not contain the newly attributed (5,7,3) schedule, last/first interleave order, minimum level count, or final whole-sequence operation. A consumer resolving this BASE therefore cannot recover the evidence behind claims attributed to Erin or distinguish it from a new interpretation. Record an exact source artifact/path and identity for that discussion, or scope the attribution to what this commit actually establishes.
AGENTS.md reference: AGENTS.md:L11-L12
Useful? React with 👍 / 👎.
|
|
||
| - **bit conservation** — no bit is added, removed, duplicated, or changed by the core | ||
| interleaving transform; | ||
| - **order-sensitive arity schedule** — changing arity order is a different transform; |
There was a problem hiding this comment.
Allow schedule collisions in the invariant
The required order-sensitivity is impossible for some schedules that otherwise satisfy this specification: for a six-bit input, (2,3,6) and (2,6,3) both have three levels and even partitions, but the arity-6 stage operates on singleton sections and is therefore the identity, so both schedules produce the same permutation under the declared sequential skeleton. Section 5 also explicitly asks implementations to detect schedule collisions, leaving a conforming implementation unable to report such evidence without violating this invariant. Define sensitivity in terms of retained schedule metadata, constrain the admissible schedules, or permit equivalent permutations.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 247af26527
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| │ ├── edcm/ # current EDCM measurement research + BASE.json | ||
| │ ├── pcea/ # current PCEA research + BASE.json | ||
| │ ├── urpcs/ # RETIRED: substituted GPT-produced codec; historical evidence only | ||
| │ ├── interlace-encryption/ # intended multi-arity interleaving encryption research |
There was a problem hiding this comment.
Point the directory tree at the Weave workspace
At this commit, a full tree search shows research/weave/ but no research/interlace-encryption/, so anyone using the root directory map is sent to a nonexistent workspace. The description also reduces the participant to interleaving even though the other authority projections define Weave as the full multi-layer system; update this entry to the actual name and scope.
AGENTS.md reference: AGENTS.md:L26-L26
Useful? React with 👍 / 👎.
| - order sensitivity of the declared arity schedule; | ||
| - level-count sensitivity; | ||
| - dependence on the declared thread relation; | ||
| - dependence on the declared corpus/material relation if that layer is enabled; |
There was a problem hiding this comment.
Require corpus dependence for complete profiles
When evaluating a profile as complete, this condition permits disabling the corpus/material layer and still satisfying the listed invariants, despite thread-associated material being a required preserved layer of Weave. Make corpus/material dependence unconditional for complete profiles; profiles that exclude it can remain explicitly classified as layer tests.
AGENTS.md reference: AGENTS.md:L26-L26
Useful? React with 👍 / 👎.
| "URPCS is retired historical evidence after GPT-assisted implementation diverged from Erin Spencer's intended multi-arity interleaving specification; why the substitution occurred remains unresolved", | ||
| "skill-lib remains a special operational snapshot at stack root rather than following the libs/research pair" | ||
| "skill-lib remains a special operational snapshot at stack root rather than following the libs/research pair", | ||
| "Weave preserves the intended multi-arity interleaving mechanism, while uneven partitioning, stage-input composition, schedule encoding, thread/corpus binding, hyperspace/gonol binding, authentication/state, and threat model remain unresolved" |
There was a problem hiding this comment.
Record unresolved asymmetric derivation in the manifest
For consumers that use the machine manifest as the work-graph boundary, this hmmm list omits public/private key derivation and the source of asymmetry, although SPECIFICATION.md:173 explicitly leaves them unresolved and asymmetry is a required Weave layer. This can make coordination treat the key relation as settled while the workspace must still fail closed on it; carry that unresolved boundary here and in the matching human projections.
AGENTS.md reference: AGENTS.md:L26-L26
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2f1a70948f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| for name, expected in r["source_inputs"]["local_sha256"].items(): | ||
| must(hashlib.sha256((root/name).read_bytes()).hexdigest() == expected, | ||
| f"source mismatch: {name}") |
There was a problem hiding this comment.
Require the complete source hash set
When verify.py is run on an edited or externally supplied receipt, this loop trusts the receipt itself to specify which sources require verification. Setting source_inputs.local_sha256 to {} therefore performs no source checks, yet the script still exits successfully with SURVIVED_SECOND_IMPLEMENTATION; the claimed Stack and UCHC source identities are likewise unchecked. Require the exact expected source keys and provenance identities, or bind verification to the published receipt digest, before reporting success.
Useful? React with 👍 / 👎.
…side proposed answers Add separate stage modules, forward/inverse orchestration, public/private API boundaries, and phone-sized switches. Preserve source-native missing operators as blocked rather than substitute implementations. Local assembly tests: 19 methods and all 512 switch configurations; not whole-system encryption evidence. No participant, source pin, lifecycle or upstream authority changes.
|
Added switchable whole-scope assembly at Standing: assembly implemented; complete encryption not implemented. Local validation: 19 assembly tests passed. The complete 512-switch set contains 320 compatible wiring-fixture configurations and 192 explicitly incompatible configurations under the proposed binding dependency. These are wiring tests, not Weave cryptographic results. Default full-scope execution correctly remains BLOCKED at six missing native inputs/operators: key, gonol, binding, split, corpus, join. The two literal bit stages reuse the prior source-verified Read back and matched all stage-module blobs, the assembly runner, test module and assembly document against the locally tested copies. No participant, source pin, |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 200032dba6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if self.switches['key'] and (context is None or context.public_key is None): | ||
| problems.append('key: Q2/Q7/Q8, native public/private relation/key input missing') | ||
| if type(context) is PrivateContext and self.switches['key'] and context.private_key is None: |
There was a problem hiding this comment.
Require a provenance-bound key relation
When all required operators are supplied, enabling key only requires arbitrary non-None objects in the public/private contexts; stages.key.keygen is never wired into Pipeline, and its law_identity is absent from the recipe. A caller can therefore pass object() as both key sides and receive FULL_PROFILE_EXPERIMENT even though no asymmetric key relation was constructed. Require a validated KeyPair or otherwise bind the key law identity into the pipeline before treating the key layer as present.
AGENTS.md reference: AGENTS.md:L26-L26
Useful? React with 👍 / 👎.
| if encrypted.recipe != self.recipe(): | ||
| raise ValueError('inverse profile/operator identities differ from forward lab recipe') |
There was a problem hiding this comment.
Bind transform parameters into the inverse profile
When the recipient supplies different parameters from those used for encryption, this recipe comparison still passes because the recipe contains only switches and operator identities. For example, encrypting six bits with interleave partition (2,2,2) and decrypting with (1,1,4) returns a different payload without an error, despite the API claiming to enforce the same selected profile. Bind the effective transform-plan identity to the run or explicitly validate an independently derived inverse plan before executing it.
AGENTS.md reference: AGENTS.md:L26-L26
Useful? React with 👍 / 👎.
…ive adapter Implement available provisional answers as separate split, corpus traversal, arity and join modules, preserving whole interleave and the default full-native refusal boundary. Add explicit transport scope, exact inverse composition, file CLI, strict profile/record validation, native UCHC word reader, source-bound tests, and Q1-Q10 proposed answers. Native whole-message, key/private-gonol binding and corpus/thread geometry remain unimplemented rather than substituted. Local verification: 43 test methods, zero failures/errors/skips; 8191 exhaustive binary messages; 512 assembly masks and 32 transport masks; 64KiB roundtrip; fresh-process recovery after input deletion. Code/profile source digest 15ecd585290b2adf6d827d55606fe62189493423ad26b1036ea8f8514a8d534c. 24 remote source/document Git blobs match locally checked files. Fixed-map recovery succeeds against this explicit transport candidate; not a whole-Weave security result. No producer or libs/lifecycle changes.
Creates
research/weave/after URPCS retirement and preserves the full intended construction: native hyperspace/gonol plaintext, private-gonol recovery, related threads, corpus/material participation, multi-arity last/first interleaves, and a native asymmetric relation.Implemented at 5dd67de
Read IMPLEMENTED.md and QUESTIONS.md.
File plan and risks
stages/{split,corpus,inter,join}.py: implement explicit reversible candidates; risk is mistaken promotion to native laws; transport scope and tests prevent automatic promotion.stages/gonol.py: consume exact native source/word object; risk is unverified source or missing database; source identity and read-only boundaries tested, successful corpus replay unexecuted.stages/api.py,assembly.py: preserve switches, reverse order, context separation and evidence classification.transport.py,lab.py,run.py,profiles/transport.json: explicit experiment profile and phone-sized file commands, no overwrite or network; lab format is not production encryption.tests/test_transport.py,test.py,evidence/transport-v1.json: exact-source replay with failures/skips/changed scope rejected.IMPLEMENTATION_PLAN.json,IMPLEMENTED.md,QUESTIONS.md: source plan, usage, rollout/rollback, unresolved questions and probable answers..github/workflows/weave.yml: path-scoped read-only exact-head testing.Executed local evidence
43 test methods; zero failures/errors/skips. Includes 8191 exhaustive binary messages, all 512 assembly switch masks, 32 transport masks (28 executable/four incompatible), 64KiB roundtrip, fresh-process recovery after original input deletion, malformed-input and actual-corpus tests. 24 uploaded source/document blobs verified equal to locally checked files.
Code/profile source SHA-256:
15ecd585290b2adf6d827d55606fe62189493423ad26b1036ea8f8514a8d534c.The attack witness recovers this fixed transport map at 137 bits in eight chosen-input queries; wrong material can return incorrect bytes without authentication. These results concern the explicit transport candidate, not the full native design. No independent researcher review or Android execution is claimed.
Dependency and standing
Base remains
retire-urpcs-spec-divergence; retirement must land before this replacement. No libs, upstream producer or root lifecycle change. No confidentiality or production-security claim. Hosted checks must be read separately from local evidence.