{
  "_doc": "One result, read from the codebase’s own files at the commit named here. Every value is that file’s own, copied verbatim; nothing here is written by hand. A value replaced by {withheld: true, sha256_of_value, bytes} is committed by its sha256 instead of published, for the reason it states, and is never edited. Each whole source file is committed by sha256 below, and its bytes are published only where its visibility says so. The codebase is named by the public subject its files are published under.",
  "lane": "inference-limits",
  "repository": "inference-limits",
  "commit": "eb76dce3f6dc0889d822db1c7a5af76dc876d2db",
  "portfolio_id": "inference-limits:claim-control-plane",
  "id": "claim-control-plane",
  "attestation_row": {
    "attested_at": "2026-09-12",
    "attestor": "04-aiscaleout",
    "repository": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "dc9a8056162a9f8af22c3358adefec1007380f73db3ac6575018b9f67cec86a6",
      "bytes": 7
    },
    "source_doc": "TOP_N_CROWN_JEWELS.md",
    "source_doc_sha256": "15a64fb189e85a28a6fee2c09ec72d602dd019272769f54e167d6cc5bf3c425a",
    "state": "attested",
    "top_n": 11,
    "note_sha256": "cda096249bc344dc78f7c156eaaaaa4915f346127e628cf67243910f731d04df",
    "ids_in_row": 11,
    "file": "dataroom/TOP_N_ATTESTATION.jsonl",
    "line": 1
  },
  "claim_source": {
    "receipt": "inference-limits/top40.json",
    "sha256": "5d74491a747c903d407b42abbeececaf6268df57216a1fac67aa795bc4092b6e",
    "field": "entries[16].claim",
    "file": "top40.json"
  },
  "top40_entry": {
    "id": "claim-control-plane",
    "rank": 17,
    "native_rank": 1,
    "title": "Claim-control plane that can veto its own headline",
    "claim": {
      "withheld": true,
      "why": "uses a word the published record keeps for its own process (S3.1-DIALECT)",
      "sha256_of_value": "4a1024ccf5065b5651ffaf1a2555d3c9f1e14fc1527898bca7c07437c4f0e2ee",
      "bytes": 343
    },
    "scope": "23 registered headlines in dd_audit/headline_registry.json, each {cert,json_path,render,forbidden[],documents[]}; three checks over the documents each entry names. Governs prose in the scanned globs only — it cannot force an unscanned surface to obey it, and CHECK 2 is report-only by design.",
    "limits": {
      "withheld": true,
      "why": "uses a word the published record keeps for its own process (S3.1-DIALECT)",
      "sha256_of_value": "571e515cf3ff64ec4542dc33dd0f8f9829214ca215aa1012e5166fda01dcc8cf",
      "bytes": 898
    },
    "artifact_path": "dd_audit/headline_registry.json",
    "witness_command": "python3 scripts/audit_cert_prose_consistency.py --strict",
    "witness_result": "exit=0 | CERT-PROSE CONSISTENCY AUDIT",
    "witness_class": "ASSERTING",
    "third_party_axis": "—",
    "facts": {
      "ran_with_receipt": true,
      "third_party_graded": false,
      "negative_control_stated": false,
      "ip_class_known": false,
      "reproduce_command": true,
      "regenerates_not_verifies": false
    },
    "fact_count": 2,
    "repro_command": "python3 scripts/audit_cert_prose_consistency.py --strict",
    "ip_class": null,
    "ip_class_basis": {
      "withheld": true,
      "why": "a note on the entry's intellectual-property class, which this site does not publish; a hash of the note is kept",
      "sha256_of_value": "1fa3b0de2499ff0cae5431ddd894e54301c85cc39df867e9e43b4552d055cba7",
      "bytes": 265
    },
    "negative_control": null
  },
  "witness_quality_entry": {
    "id": "claim-control-plane",
    "claim": {
      "withheld": true,
      "why": "uses a word the published record keeps for its own process (S3.1-DIALECT)",
      "sha256_of_value": "4a1024ccf5065b5651ffaf1a2555d3c9f1e14fc1527898bca7c07437c4f0e2ee",
      "bytes": 343
    },
    "class": "ASSERTING",
    "why": "S01 ran the same checker WITHOUT --strict, where a mismatched headline is report-only (audit_cert_prose_consistency.py:395). Planted defect: editing the certificate field a registered headline is bound to makes --strict exit 1.",
    "witness_command": "python3 scripts/audit_cert_prose_consistency.py --strict",
    "defect_demonstration": {
      "id": "claim-control-plane",
      "target": "results/data/statefabric/gpu/timing_oracle_batching.json",
      "defect": "the certificate field a registered headline is bound to (runs[0].arms.unsalted.cached_median_hit) is edited, so the prose that quotes it no longer matches its certificate",
      "witness_command": "python3 scripts/audit_cert_prose_consistency.py --strict",
      "recorded_exit": 0,
      "recorded_assertion": "OK — every registered headline in every listed document matches its certificate",
      "mutation": "replaced 6 of 6 occurrences of '\"cached_median_hit\": 2848' with '\"cached_median_hit\": 2849'",
      "mutated_exit": 1,
      "mutated_first_line": "CERT-PROSE CONSISTENCY AUDIT",
      "assertion_present_under_defect": false,
      "witness_rejects_the_defect": true,
      "tree_clean_after_restore": true,
      "restored_exit": 0,
      "restored_assertion_present": true
    },
    "asserts": "with --strict, every one of the 23 registered headlines is re-read from its named certificate at its named json_path and compared to the prose of every document the registry binds it to; CHECK 0 additionally re-derives the derivable certificates. The asserted line is CHECK 1's verdict.",
    "stale_claims_ref": null,
    "attested": true
  },
  "packet": null,
  "measured": {
    "measured": true,
    "basis": "defect_demonstration.mutated_exit = 1",
    "exit": 1,
    "defect_rejected": true
  },
  "register": {
    "truth_state": "attested",
    "truth_line": 143,
    "measured_per_register": true,
    "witness_class_per_register": "ASSERTING",
    "ip_class_public": "unknown",
    "ip_class_sha256": "b23a6a8439c0dde5515893e7c90c1e3233b8616e634470f20dc4928bcf3609bc",
    "ip_class_source": "reports/TOP_N_CROWN_JEWELS.md:27 @ 7eff877f38ed",
    "receipt": "register/CROWN_JEWELS_TRUTH.md",
    "receipt_sha256": "bde06cf0d3e99644522d18e79b6bd5d84ed4f5c86e315a48fef207e9e49c5022",
    "ip_class_receipt": "register/ip_class.jsonl",
    "ip_class_receipt_sha256": "b1e8f97aa6779e0fefed2f7a7726e1a03563b536b497392401b49bb8ef84d4ca"
  },
  "withheld_fields": [
    {
      "field": "top40.claim",
      "codes": [
        "PROCESS_NARRATION"
      ]
    },
    {
      "field": "top40.limits",
      "codes": [
        "PROCESS_NARRATION"
      ]
    },
    {
      "field": "witness_quality.claim",
      "codes": [
        "PROCESS_NARRATION"
      ]
    },
    {
      "field": "attestation_row.repository",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    }
  ],
  "sources": {
    "attestation": {
      "receipt": "inference-limits/dataroom/TOP_N_ATTESTATION.jsonl",
      "source": "dataroom/TOP_N_ATTESTATION.jsonl",
      "commit": "eb76dce3f6dc0889d822db1c7a5af76dc876d2db",
      "sha256": "a674007bd1bcc71c72d9033d28bbf3c0fe0f19bff407993b2a71aacfa57fca6f",
      "bytes": 1701,
      "visibility": "sealed"
    },
    "top40": {
      "receipt": "inference-limits/top40.json",
      "source": "top40.json",
      "commit": "eb76dce3f6dc0889d822db1c7a5af76dc876d2db",
      "sha256": "5d74491a747c903d407b42abbeececaf6268df57216a1fac67aa795bc4092b6e",
      "bytes": 246151,
      "visibility": "sealed"
    },
    "witness_quality": {
      "receipt": "inference-limits/dataroom/witness_quality.json",
      "source": "dataroom/witness_quality.json",
      "commit": "eb76dce3f6dc0889d822db1c7a5af76dc876d2db",
      "sha256": "2d25181a8dde236a009eb4264e63f129382d7641862180d6001c0be2856f9049",
      "bytes": 82971,
      "visibility": "sealed"
    },
    "repro_index": {
      "receipt": "inference-limits/repro/INDEX.json",
      "source": "repro/INDEX.json",
      "commit": "eb76dce3f6dc0889d822db1c7a5af76dc876d2db",
      "sha256": "80ed62f5df6a95c42aa44f13ab11a287c303acf258caf8ff2bd72439f5fc0bf0",
      "bytes": 46450,
      "visibility": "sealed"
    }
  }
}
