{"artifacts":{"draft-saha-stage-receipts":{"note":"-00 posted 2026-09-08 (datatracker.ietf.org/doc/draft-saha-stage-receipts); an Internet-Draft, not a standard; second and last Internet-Draft under the two-draft cap","state":"shipped","target":"2026-09-08"},"reference-sdk":{"note":"release condition: battery results attached uncurated","state":"not-started","target":"2026-10"},"reference-verifier":{"note":"preview implementation published in samples/verify.py","state":"specified","target":"2026-10"},"validation-battery":{"note":"published before the code it will judge","state":"specified","target":"2026-09-11"}},"as_of":"2026-09-14T00:00:00+02:00","battery_rings":[{"name":"Pathology zoo","note":"fixtures written before the code; each names the incident that motivated it","ring":"1","state":"specified"},{"name":"Golden conformance vectors","note":"ship inside the draft; ten rejection vectors published in the preview","ring":"2","state":"specified"},{"name":"Framework matrix","note":"one verifier, four frameworks, blind; the verifier must not be able to tell which produced a record","ring":"3","state":"not-started"},{"name":"Dogfood","note":"the forensic pipeline's own records re-expressed through the SDK","ring":"4","state":"not-started"}],"commitments":["The format, the SDK and the verifier are open and free, permanently.","The reference implementation ships with battery results attached uncurated, failures included.","No conforming verifier may require a key, an account, a network call, or a live third party.","We will not operate a certificate authority, a key escrow, or any service on which a record's checkability depends.","Any published third-party battery run will be linked from here, passing or failing, including runs that fail against our own implementation."],"format":"oneproof-status/0.0-preview","note":"Machine-readable state of every open requirement and every battery ring. Watch this file; diff it. States: not-started | specified | implemented | tested | shipped. Nothing marked shipped is a promise; everything else is.","requirements":[{"battery_coverage":"testable","id":"1","name":"Merkle corpus manifest","note":"inclusion proofs and a tampered-member rejection vector","state":"not-started"},{"battery_coverage":"partial","id":"2","name":"Epoch anchoring","note":"LOAD-BEARING, first in importance. Directed into the Moment 2 scope by the owner, 2026-09-01; priced at the design note. The battery can test that a record declares its anchor, cadence and unanchored state; it cannot test that an anchor is unrewritable. Tamper-evidence is measurable; tamper-resistance is not. If the mechanism is not battery-clean by the SDK release, the declaration ships first and the mechanism follows - testing masters the schedule.","state":"not-started"},{"battery_coverage":"partial","id":"3","name":"Tenant isolation","note":"format-level separation testable; deployment isolation is not","state":"not-started"},{"battery_coverage":"not-yet","id":"4","name":"Signature envelope","note":"sequenced behind actor identity; vectors reserved, not written","state":"not-started"},{"battery_coverage":"testable","id":"5","name":"Per-receipt dependency record","note":"CycloneDX-aligned; network access as a declared, counted class. Motivating case raised by a reader: agreement between two tools corroborates only if they fail independently, and two wrappers over one extraction backend read identically to real corroboration - so the record must say what sits under the tool, not only which tool ran. A dependency record alone does not reach the harder case: two independent engines reading the same broken text layer agree because what they share is the document's own encoding, not a library.","state":"not-started"},{"battery_coverage":"not-yet","id":"6","name":"Signing-key lifecycle","note":"follows #4; vector reserved for a record signed by a since-revoked key","state":"not-started"},{"battery_coverage":"not-yet","id":"7","name":"Receipt topology / DAG","note":"LOAD-BEARING and the battery's largest hole. Fan-out, fan-in, retries as distinct attempts, branches, loops, compensation, exactly-once vs at-least-once, out-of-order arrival, and an ordering model for disagreeing clocks. Raised by an independent reviewer, accepted, unsolved. Comparison is the harder half: \"first difference\" presumes a sequence, so two runs of differing shape need a stable per-stage role identity to align on, and the closed verdict set has no word for present-in-one-absent-in-the-other. Ordering should derive from causal linkage - a receipt citing its predecessor's digest - rather than from clocks.","state":"not-started"},{"battery_coverage":"partial","id":"8","name":"Disclosure layer","note":"a record checkable without being fully read","state":"not-started"},{"battery_coverage":"testable","id":"9","name":"Coverage attestation and causal completeness","note":"declared expected topology, emitting stages, boundary declarations, INCOMPLETE as a first-class state. Independently identified by two reviewers as the central missing control. Includes conformance of an executed run against a declared plan: the plan's digest declares the intended topology, the receipts form the actual one, and a deviation between them is then mechanical to find.","state":"not-started"},{"battery_coverage":"testable","id":"10","name":"Content trust class","note":"operator-authored / model-generated / externally-sourced; present in the preview samples","state":"specified"},{"battery_coverage":"testable","id":"11","name":"Emission failure semantics","note":"declared fail-open or fail-closed; the resulting absence recorded as a declared gap. A declared gap must be counted and carry a reason code, or \"declared gap\" becomes an unfalsifiable excuse.","state":"specified"},{"battery_coverage":"testable","id":"12","name":"Schema evolution and version negotiation","note":"what a current verifier concludes from an earlier-version record","state":"not-started"},{"battery_coverage":"testable","id":"13","name":"External effect records","note":"attempted / returned-a-response / confirmed-by-the-external-system; a verifier may not read the first as the third","state":"not-started"}],"states":["not-started","specified","implemented","tested","shipped"]}