proofabstraction

package
v0.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 8 Imported by: 0

Documentation

Overview

Package proofabstraction implements the experimental exact proof-projection relation described by PPA-V0. It proves only non-strengthening relative to a supplied source envelope; it does not establish source truth.

Index

Constants

View Source
const (
	EnvelopeProfile    = "corvint-proof-state/0-experimental"
	RequestProfile     = "corvint-proof-preserving-abstraction-request/0-experimental"
	CertificateProfile = "corvint-proof-preserving-abstraction-certificate/0-experimental"
	AlgorithmProfile   = "corvint-exact-proof-projection/0"
	CertificateClaim   = "RELATIVE_NON_STRENGTHENING"

	MaxArtifactBytes = 4 << 20
	MaxClaims        = 2_048
	MaxEvidence      = 4_096
	MaxFrontier      = 4_096
	MaxClaimEvidence = 64
	MaxTokenBytes    = 256
)

Variables

This section is empty.

Functions

func Compile

func Compile(source Envelope, request Request) (Envelope, Certificate, error)

Compile builds a destination projection and certificate, then verifies the non-strengthening relation before returning either artifact.

func MarshalCertificate

func MarshalCertificate(value Certificate) ([]byte, error)

MarshalCertificate emits one deterministic, newline-free certificate.

func MarshalEnvelope

func MarshalEnvelope(value Envelope) ([]byte, error)

MarshalEnvelope emits one deterministic, newline-free wire object.

func MarshalRequest

func MarshalRequest(value Request) ([]byte, error)

MarshalRequest emits one deterministic, newline-free request.

func Verify

func Verify(source Envelope, request Request, destination Envelope, certificate Certificate) error

Verify independently checks that destination is no stronger than source and that certificate accounts for the exact requested transformation.

Types

type Action

type Action struct {
	ClaimID string     `json:"claimId"`
	Action  ActionKind `json:"action"`
	Reason  *Reason    `json:"reason"`
}

type ActionKind

type ActionKind string
const (
	ActionRetain          ActionKind = "RETAIN"
	ActionDemoteToUnknown ActionKind = "DEMOTE_TO_UNKNOWN"
	ActionOmit            ActionKind = "OMIT"
)

type AuthorityClass

type AuthorityClass string
const (
	AuthorityRepositoryAccepted AuthorityClass = "REPOSITORY_ACCEPTED"
	AuthorityOwningVerifier     AuthorityClass = "OWNING_VERIFIER"
	AuthorityProviderQualified  AuthorityClass = "PROVIDER_QUALIFIED"
	AuthorityAdapterQualified   AuthorityClass = "ADAPTER_QUALIFIED"
	AuthorityCallerReported     AuthorityClass = "CALLER_REPORTED"
	AuthorityAdvisory           AuthorityClass = "ADVISORY"
	AuthorityNone               AuthorityClass = "NONE"
)

type Certificate

type Certificate struct {
	Profile               string               `json:"profile"`
	Algorithm             string               `json:"algorithm"`
	Claim                 string               `json:"claim"`
	SourceEnvelopeID      string               `json:"sourceEnvelopeId"`
	DestinationEnvelopeID string               `json:"destinationEnvelopeId"`
	RequestSHA256         string               `json:"requestSha256"`
	Repository            Repository           `json:"repository"`
	PolicySHA256          string               `json:"policySha256"`
	PurposeSHA256         string               `json:"purposeSha256"`
	CompletenessRelation  CompletenessRelation `json:"completenessRelation"`
	ClaimRelations        []ClaimRelation      `json:"claimRelations"`
	OmittedClaims         []OmittedClaim       `json:"omittedClaims"`
	EvidenceAccounting    []EvidenceAccounting `json:"evidenceAccounting"`
	FrontierAccounting    FrontierAccounting   `json:"frontierAccounting"`
	CertificateID         string               `json:"certificateId,omitempty"`
}

func DecodeCertificate

func DecodeCertificate(raw []byte) (Certificate, error)

DecodeCertificate accepts only the exact canonical encoding.

type Claim

type Claim struct {
	ID              string          `json:"id,omitempty"`
	StatementSHA256 string          `json:"statementSha256"`
	ScopeSHA256     string          `json:"scopeSha256"`
	Critical        bool            `json:"critical"`
	Verdict         Verdict         `json:"verdict"`
	AuthorityClass  AuthorityClass  `json:"authorityClass"`
	EvidenceClasses []EvidenceClass `json:"evidenceClasses"`
	Evidence        []string        `json:"evidence"`
	CounterEvidence []string        `json:"counterEvidence"`
	UnknownReasons  []string        `json:"unknownReasons"`
}

func BindClaim

func BindClaim(value Claim) (Claim, error)

BindClaim validates and content-addresses one claim atom. Envelope binding later verifies that every evidence reference resolves.

type ClaimRelation

type ClaimRelation struct {
	SourceClaimID      string   `json:"sourceClaimId"`
	DestinationClaimID string   `json:"destinationClaimId"`
	Relation           Relation `json:"relation"`
	Reason             *Reason  `json:"reason"`
}

type Code

type Code string

Code is a stable verifier failure classification.

const (
	Noncanonical             Code = "NONCANONICAL"
	LimitExceeded            Code = "LIMIT_EXCEEDED"
	SourceIDMismatch         Code = "SOURCE_ID_MISMATCH"
	SnapshotChanged          Code = "SNAPSHOT_CHANGED"
	PolicyChanged            Code = "POLICY_CHANGED"
	ClaimAdded               Code = "CLAIM_ADDED"
	ClaimIdentityChanged     Code = "CLAIM_IDENTITY_CHANGED"
	VerdictStrengthened      Code = "VERDICT_STRENGTHENED"
	AuthorityChanged         Code = "AUTHORITY_CHANGED"
	CriticalClaimWeakened    Code = "CRITICAL_CLAIM_WEAKENED"
	ConflictHidden           Code = "CONFLICT_HIDDEN"
	UnknownHidden            Code = "UNKNOWN_HIDDEN"
	EvidenceAdded            Code = "EVIDENCE_ADDED"
	EvidenceMutated          Code = "EVIDENCE_MUTATED"
	FrontierRemoved          Code = "FRONTIER_REMOVED"
	OmissionUnaccounted      Code = "OMISSION_UNACCOUNTED"
	CompletenessStrengthened Code = "COMPLETENESS_STRENGTHENED"
	CertificateMismatch      Code = "CERTIFICATE_MISMATCH"
)

func ErrorCode

func ErrorCode(err error) (Code, bool)

ErrorCode returns a stable failure code and false for unrelated errors.

type Completeness

type Completeness string
const (
	CompletenessComplete Completeness = "COMPLETE"
	CompletenessPartial  Completeness = "PARTIAL"
	CompletenessUnknown  Completeness = "UNKNOWN"
)

type CompletenessRelation

type CompletenessRelation string
const (
	CompletenessEqual             CompletenessRelation = "EQUAL"
	CompletenessWeakenedToPartial CompletenessRelation = "WEAKENED_TO_PARTIAL"
)

type Envelope

type Envelope struct {
	Profile       string       `json:"profile"`
	Repository    Repository   `json:"repository"`
	PolicySHA256  string       `json:"policySha256"`
	PurposeSHA256 string       `json:"purposeSha256"`
	Completeness  Completeness `json:"completeness"`
	Claims        []Claim      `json:"claims"`
	Evidence      []Evidence   `json:"evidence"`
	Frontier      []Frontier   `json:"frontier"`
	EnvelopeID    string       `json:"envelopeId,omitempty"`
}

func BindEnvelope

func BindEnvelope(value Envelope) (Envelope, error)

BindEnvelope validates and content-addresses a complete canonical envelope.

func DecodeEnvelope

func DecodeEnvelope(raw []byte) (Envelope, error)

DecodeEnvelope accepts only the exact canonical encoding.

type Error

type Error struct {
	Code Code
}

Error reports one fail-closed protocol or non-strengthening violation.

func (*Error) Error

func (e *Error) Error() string

type Evidence

type Evidence struct {
	ID            string `json:"id,omitempty"`
	SourceProfile string `json:"sourceProfile"`
	ExternalID    string `json:"externalId"`
	ContentSHA256 string `json:"contentSha256"`
}

func BindEvidence

func BindEvidence(value Evidence) (Evidence, error)

BindEvidence validates and content-addresses one evidence wrapper.

type EvidenceAccounting

type EvidenceAccounting struct {
	EvidenceID     string        `json:"evidenceId"`
	State          EvidenceState `json:"state"`
	SourceClaimIDs []string      `json:"sourceClaimIds"`
}

type EvidenceClass

type EvidenceClass string
const (
	EvidenceDeclared    EvidenceClass = "DECLARED"
	EvidenceImplemented EvidenceClass = "IMPLEMENTED"
	EvidenceVerified    EvidenceClass = "VERIFIED"
	EvidenceObserved    EvidenceClass = "OBSERVED"
	EvidenceInferred    EvidenceClass = "INFERRED"
)

type EvidenceState

type EvidenceState string
const (
	EvidencePreserved EvidenceState = "PRESERVED"
	EvidenceOmitted   EvidenceState = "OMITTED"
)

type Frontier

type Frontier struct {
	ID               string       `json:"id,omitempty"`
	ClaimID          string       `json:"claimId"`
	Kind             FrontierKind `json:"kind"`
	Reason           string       `json:"reason"`
	SourceEnvelopeID *string      `json:"sourceEnvelopeId"`
	Recovery         Recovery     `json:"recovery"`
}

func BindFrontier

func BindFrontier(value Frontier) (Frontier, error)

BindFrontier validates and content-addresses one frontier atom. Envelope binding later verifies whether its claim is present or intentionally absent.

type FrontierAccounting

type FrontierAccounting struct {
	Preserved []string `json:"preserved"`
	Added     []string `json:"added"`
}

type FrontierKind

type FrontierKind string
const (
	FrontierSourceUnknown   FrontierKind = "SOURCE_UNKNOWN"
	FrontierSourceConflict  FrontierKind = "SOURCE_CONFLICT"
	FrontierSourceExclusion FrontierKind = "SOURCE_EXCLUSION"
	FrontierAbstractedClaim FrontierKind = "ABSTRACTED_CLAIM"
)

type OmittedClaim

type OmittedClaim struct {
	SourceClaimID string  `json:"sourceClaimId"`
	SourceVerdict Verdict `json:"sourceVerdict"`
	Reason        Reason  `json:"reason"`
	FrontierID    string  `json:"frontierId"`
}

type Reason

type Reason string
const (
	ReasonAudience Reason = "AUDIENCE"
	ReasonBudget   Reason = "BUDGET"
)

type Recovery

type Recovery string
const (
	RecoverySourceVerifier     Recovery = "SOURCE_VERIFIER"
	RecoveryLoadSourceEnvelope Recovery = "LOAD_SOURCE_ENVELOPE"
)

type Relation

type Relation string
const (
	RelationIdentical        Relation = "IDENTICAL"
	RelationDemotedToUnknown Relation = "DEMOTED_TO_UNKNOWN"
)

type Repository

type Repository struct {
	ObjectFormat string `json:"objectFormat"`
	Revision     string `json:"revision"`
	Tree         string `json:"tree"`
}

type Request

type Request struct {
	Profile          string   `json:"profile"`
	SourceEnvelopeID string   `json:"sourceEnvelopeId"`
	PurposeSHA256    string   `json:"purposeSha256"`
	Actions          []Action `json:"actions"`
}

func DecodeRequest

func DecodeRequest(raw []byte) (Request, error)

DecodeRequest accepts only the exact canonical encoding.

type Verdict

type Verdict string
const (
	VerdictProved     Verdict = "PROVED"
	VerdictRefuted    Verdict = "REFUTED"
	VerdictConflicted Verdict = "CONFLICTED"
	VerdictUnknown    Verdict = "UNKNOWN"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL