{
  "record": "R-Series Reference Core \u2014 internal assurance evidence",
  "record_version": "3.0",
  "supersedes": [
    {
      "frozen_tag": "audit-tob-v1.1.0",
      "commit": "697f339",
      "reproduced_utc": "2026-07-27",
      "status": "SUPERSEDED \u2014 retained as dated historical evidence, not current"
    },
    {
      "identifier": "internal-assurance-c2.6",
      "status": "SUPERSEDED \u2014 never published; Gate A closed on C2.9, not C2.6"
    }
  ],
  "identifier": "internal-assurance-c2.9",
  "identifier_note": "Deliberately unambiguous and internal. The previous public tag 'audit-tob-v1.1.0' is withdrawn from new evidence: 'ToB' can reasonably be read as Trail of Bits, and NO Trail of Bits audit \u2014 and no professional external audit of any kind \u2014 has occurred.",
  "candidate": {
    "id": "CORE-AUDIT-C2.9",
    "date": "2026-08-18",
    "root_digest_sha256": "391159c8fceb7f8fb4696c679ae9da896d89189626bed5b70595bec03a63ef45",
    "archive": "DCS_RSeries_V2_CORE_AUDIT_C2_9_2026-08-18.zip",
    "archive_sha256": "123f3d8ff7d0b0c595198ba3d9da4780ca4584865807833e8d083ec634b0aa5e",
    "manifest_entries": 23676,
    "files_in_archive": 23678,
    "identity_rule": "files_in_extracted_archive == manifest_entries + 2",
    "symlinks": 0,
    "generated_artifacts_inside_candidate": 0
  },
  "measured": {
    "reference_suite": {
      "command": "npm test",
      "suites": 14,
      "checks_executed": 404208,
      "failed": 0
    },
    "conformance": {
      "command": "npm run conformance",
      "vectors": "1.1.0-draft1",
      "checks": 55,
      "passed": 55,
      "failed": 0,
      "declared_skips": 2
    },
    "assurance_runner": {
      "command": "npm run assurance",
      "suites": 15,
      "checks_executed": 404263,
      "verdict": "ALL-SUITES-GREEN"
    },
    "composition_never_conflated": {
      "conventional_assertions": 255,
      "randomized_property_checks": 404008,
      "total": 404263,
      "note": "Two different kinds of work are never added into one headline. test_H1_fuzz.mjs contributes 404,000 randomized adversarial ML-DSA cases, independently reproduced at Gate A."
    },
    "execution_ledger": {
      "inventory_reconciled_against_disk": true,
      "counts": {
        "pass": 15,
        "fail": 0,
        "error": 0,
        "timeout": 0
      },
      "states_never_conflated": [
        "PASS",
        "FAIL",
        "ERROR",
        "TIMEOUT",
        "SKIP",
        "NOT-EXERCISED"
      ],
      "greenness_rule": "ALL-SUITES-GREEN is computed only from structured per-suite records. It is never derived from scraped stdout."
    },
    "platform_reproduction": {
      "macos_arm64": "writable and read-only extraction, identical: post-run file delta 0, 0 bytecode, root unchanged",
      "linux_x86_64": "read-only extraction as unprivileged owner on node 20 / 22.16 / 22.23 \u2014 all meta-controls exit 0",
      "h1_timing_measured": {
        "macos_arm_native_s": 72,
        "gate_a_verifier_s": 145,
        "qemu_x86_on_arm_s": 2249
      }
    },
    "regression_inventory": {
      "authority": "C29_SUITE_INVENTORY.json (exact membership, not counts)",
      "total": 37,
      "cold": 23,
      "integration": 10,
      "meta_control": 4,
      "rule": "declared_set == on_disk_set; missing, unexpected, rename, duplicate, overlap and class-move each turn the gate RED"
    }
  },
  "post_quantum": {
    "signature_leg": "real ML-DSA-65",
    "library": "@noble/post-quantum 0.6.1",
    "statement": "The current R-Series hybrid signature profile uses real ML-DSA-65 for the post-quantum signature leg alongside the classical signature leg. Production hardware-backed/HSM/KMS key custody is a separate deployment-control layer and is not implied by this statement.",
    "withdrawn_statement": "'The Post-Quantum (PQ) leg currently utilizes size-conformant ground stand-ins' \u2014 stale for the R-Series core and withdrawn from R-Series records."
  },
  "r4_ceremony": {
    "original_circuit": {
      "phase2_ceremony": "COMPLETED",
      "when": "May 2026",
      "contributors": 5,
      "finalisation": "Bitcoin block-hash beacon"
    },
    "repaired_circuit": {
      "phase2_ceremony": "PENDING"
    },
    "statement": "A five-contributor Phase-2 trusted-setup ceremony was completed in May 2026 for the original R+4 circuit. Following subsequent security-audit-driven circuit changes, a new production Phase-2 ceremony for the repaired circuit remains pending.",
    "on_chain_verifier": "No repaired-circuit on-chain verifier is deployed. The published Solidity verifier embeds no verifying key; earlier exports that did embed one were built from the pre-repair (C0) zkeys and are archived."
  },
  "posture": {
    "assurance_level": "INTERNAL-VERIFIED",
    "externally_audited": false,
    "externally_certified": false,
    "penetration_tested": false,
    "statement": "Gate A is GO/CLOSED on this candidate by independent internal verification. Gate B (public-claim reconciliation) remains OPEN, and the blind Audit B remains NOT AUTHORIZED until Gate B closes.",
    "preserved_scope_claims": [
      "distinct KEY ID (never distinct principal or custody domain)",
      "R+4 repaired-circuit production multi-party Phase-2 ceremony = PENDING",
      "R+3<->R+4 tree equality = issuer-committed, publicly auditable, classically recomputed \u2014 NOT proven in-circuit"
    ]
  },
  "does_not_prove": [
    "Any external audit, certification or formal validation",
    "FIPS validation of any DCS implementation",
    "A production trusted setup for the repaired R+4 circuit",
    "Hardware-backed key custody",
    "Live production deployment behaviour \u2014 these are reference-implementation results"
  ],
  "gate_a": {
    "status": "GO / CLOSED",
    "closed_utc": "2026-08-18",
    "verified_by": "independent internal AI-assisted verification (GPT), Linux x86-64 \u00b7 Node v22.16.0",
    "boundary": "Internal independent verification. NOT an external professional audit or certification.",
    "independently_reproduced": [
      "archive SHA-256 and sidecar",
      "manifest and root digest",
      "23,678 = 23,676 + 2 \u00b7 0 symlinks",
      "R+4 VERIFIED \u00b7 repaired-circuit Phase-2 ceremony PENDING",
      "R2 conformance 55/0/2 skipped",
      "exact regression inventory 19/0 with same-count-replacement, rename and class-move mutations RED",
      "DB 0/1/2 exit contract 28/0",
      "candidate immutability 13/0 writable AND 13/0 genuinely read-only as unprivileged owner",
      "H-1 adversarial fuzz 404,000 cases, run standalone from a fresh extraction (~145 s) — the '0 failures' reported here is WITHDRAWN; see h1_erratum",
      "post-run: files unchanged, 0 bytecode, manifest PASS, root unchanged"
    ]
  },
  "h1_erratum": {
    "dated": "2026-08-28",
    "applies_to": [
      "composition_never_conflated.note",
      "gate_a.independently_reproduced[] — the H-1 entry"
    ],
    "population": "404,000 adversarial cases (signature malleability / downgrade / Merkle forgery)",
    "withdrawn_claim": "0 failures / 0 succeeded",
    "corrected_result_against_frozen_tag_audit_tob_v1_1_0": "309 slips out of 404,000",
    "corrected_result_against_repaired_implementation": "0 slips",
    "repair_commits": ["85e3d09", "c66e25d"],
    "detail": "The original oracle could not detect the relabel-to-legacy downgrade attack it enumerated: it counted a slip only when the receipt was not flagged as downgraded, while that attack sets the flag. Both the oracle and the two affected verifier surfaces were repaired on 2026-08-28. The repair is NOT present in the published audit-tob-v1.1.0 tag, so any figure in this record that is scoped to that tag predates it. No other figure in this record is changed.",
    "figures_deliberately_unchanged": [404263, 404208, 255, 404008, 55, 195, 13, 14]
  }
}
