{
  "_doc": "One result, read from the codebase’s own files at the commit named here. Every value is that file’s own, copied verbatim; nothing here is written by hand. A value replaced by {withheld: true, sha256_of_value, bytes} is committed by its sha256 instead of published, for the reason it states, and is never edited. Each whole source file is committed by sha256 below, and its bytes are published only where its visibility says so. The codebase is named by the public subject its files are published under.",
  "lane": "wireless-pqc",
  "repository": "wireless-pqc",
  "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
  "portfolio_id": "wireless-pqc:ap-wide-memory-bound",
  "id": "ap-wide-memory-bound",
  "attestation_row": {
    "attested_at": "2026-09-13",
    "attestor": "03-wifipqc",
    "repository": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "6f37ed958c37482bf7ee04acba61df04492fe3186c1ba6c10b77519cd450c69f",
      "bytes": 7
    },
    "source_doc": "CROWN_JEWELS_RESOLVED.md",
    "source_doc_sha256": "6958cd834026328936c2fbfb51a8b00a4dd5ec6cb65b1d0d8960bcfe0b9e2418",
    "state": "attested",
    "top_n": 26,
    "note_sha256": "c1af3e3220ffc4290cc975a79bf85d216638fd8abd3f4d8e7e67f6f5af0aff3b",
    "ids_in_row": 26,
    "file": "dataroom/TOP_N_ATTESTATION.jsonl",
    "line": 1
  },
  "claim_source": {
    "receipt": "wireless-pqc/dataroom/top40.json",
    "sha256": "6076db4027d7499ac53b5cf15f9a07bb7e41c38f56fb0f469a62353e10e65353",
    "field": "entries[13].claim",
    "file": "dataroom/top40.json"
  },
  "top40_entry": {
    "id": "ap-wide-memory-bound",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "0334c9fca89f3e3a3da95d992993f4f9fb6650a4e3fc6c5a705ee22005b96169",
      "bytes": 28
    },
    "rank": 14,
    "native_rank": 7,
    "title": "Lean 4 proves the AP-wide memory bound holds across an UNBOUNDED number of concurrent sessions — and that the per-session cap alone does not",
    "claim": "Under an adversary-chosen schedule over an unbounded number of concurrent sessions, the AP's total pre-authentication reassembly residency never exceeds 64 KiB, with at most 4 live contexts.",
    "scope": "Holds for an AP running lib/wifipqc/ap_admission.ApAdmissionControl -- NOT for the 32-mechanism envelope as shipped; statemachine.py, repairs.py and attacks.py do not import it. Measured on the Python reference path; no 802.11 frame crosses a radio. N_max is DERIVED from two deployment parameters.",
    "artifact_path": "artifacts/native/lean_proof_ci.json",
    "witness_command": "make lean-proof && make ap-quota",
    "witness_result": {
      "status": "RAN",
      "exit": 0,
      "line": "  wire-level leg: BLOCKED (this host is Darwin; missing: linux, hostapd, wpa_supplicant, modprobe, mac80211_hwsim. mac80211_hwsim is Linux-only and the repo's own hwsim workflow (.github/workflows/hwsim.yml) requires a self-hosted runner labelled `hwsim-yes`. No wire-level number is published from t",
      "seconds": 6.2,
      "run_at": "2026-09-13T02:31:58Z",
      "owner_gated": false,
      "reason": null,
      "run_of_record": "clean clone at HEAD (S03, dataroom/witness_quality_20260913/clean_clone_baseline.json)"
    },
    "third_party_axis": "B",
    "facts": {
      "ran_with_receipt": true,
      "third_party_graded": true,
      "negative_control_stated": false,
      "ip_class_known": false,
      "reproduce_command": true,
      "regenerates": false
    },
    "fact_count": 3,
    "repro_command": "make lean-proof && make ap-quota",
    "ip_class": null,
    "ip_class_basis": "no source in this repository states an IP class for this entry; never guessed"
  },
  "witness_quality_entry": {
    "id": "ap-wide-memory-bound",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "0334c9fca89f3e3a3da95d992993f4f9fb6650a4e3fc6c5a705ee22005b96169",
      "bytes": 28
    },
    "title": "Lean 4 proves the AP-wide memory bound holds across an UNBOUNDED number of concurrent sessions — and that the per-session cap alone does not",
    "claim": "Under an adversary-chosen schedule over an unbounded number of concurrent sessions, the AP's total pre-authentication reassembly residency never exceeds 64 KiB, with at most 4 live contexts.",
    "class": "ASSERTING",
    "why": "clean-clone exit 0; every decisive planted defect went red: [0] double the per-session buffer in the Python engine (16 KiB -> 32 KiB): n_max becomes 2 while the Lean proof still says 4 -> exit 2; [1] plant a sorry in the AP-wide invariant preservation theorem: the Lean proof is no longer a proof -> exit 2",
    "witness_command": "make lean-proof && make ap-quota",
    "clean_clone": {
      "withheld": true,
      "why": "the operator's account name (R8); a macOS private temporary path on the machine that produced the file (R8); an agent scratch directory (R8); an agent build root, which carries the operator uid and home directory in slugged form (R8); a home directory in slugged form (R8)",
      "sha256_of_value": "481fb832957ec9f302312912b86165d22e64f75ac2dc83b0a4e71cb0bb64304e",
      "bytes": 688
    },
    "planted_defects": [
      {
        "index": 0,
        "what": "double the per-session buffer in the Python engine (16 KiB -> 32 KiB): n_max becomes 2 while the Lean proof still says 4",
        "falsifies": "property: proof and code agree on 64 KiB / 4 contexts",
        "decisive": true,
        "planted": [
          {
            "path": "lib/wifipqc/incremental_auth.py",
            "diff": "'DEFAULT_MAX_BUFFER_BYTES = 16 * 1024' -> 'DEFAULT_MAX_BUFFER_BYTES = 32 * 1024' (x1 of 1)"
          }
        ],
        "exit": 2,
        "seconds": 8.1,
        "last_line": "make: *** [ap-quota] Error 1",
        "failure_moved_by": null
      },
      {
        "index": 1,
        "what": "plant a sorry in the AP-wide invariant preservation theorem: the Lean proof is no longer a proof",
        "falsifies": "property: proved in Lean (0 sorry)",
        "decisive": true,
        "planted": [
          {
            "path": "06_formal_models/lean/ApBound.lean",
            "diff": "'theorem step_preserves (G CAP : Nat) (st : List Nat) (e : Ev) (h : Inv G CAP st)' -> 'theorem step_preserves (G CAP : Nat) (st : List Nat) (e : Ev) (h : Inv G CAP st)' (x1 of 1)"
          }
        ],
        "exit": 2,
        "seconds": 0.9,
        "last_line": "make: *** [lean-proof] Error 1",
        "failure_moved_by": null
      }
    ],
    "measured": true,
    "stale_claims_ref": null
  },
  "packet": null,
  "measured": {
    "measured": true,
    "basis": "planted_defects[].exit = 2",
    "exit": 2,
    "defect_rejected": true
  },
  "register": {
    "truth_state": "attested",
    "truth_line": 112,
    "measured_per_register": true,
    "witness_class_per_register": "ASSERTING",
    "ip_class_public": "unknown",
    "ip_class_sha256": "b23a6a8439c0dde5515893e7c90c1e3233b8616e634470f20dc4928bcf3609bc",
    "ip_class_source": "TOP_N_CROWN_JEWELS.md:72 @ 102044d55aab",
    "receipt": "register/CROWN_JEWELS_TRUTH.md",
    "receipt_sha256": "bde06cf0d3e99644522d18e79b6bd5d84ed4f5c86e315a48fef207e9e49c5022",
    "ip_class_receipt": "register/ip_class.jsonl",
    "ip_class_receipt_sha256": "b1e8f97aa6779e0fefed2f7a7726e1a03563b536b497392401b49bb8ef84d4ca"
  },
  "withheld_fields": [
    {
      "field": "top40.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "witness_quality.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "witness_quality.clean_clone",
      "codes": [
        "OPERATOR_ACCOUNT",
        "PRIVATE_TMP_PATH",
        "AGENT_BUILD_ROOT",
        "SLUGGED_HOME"
      ]
    },
    {
      "field": "attestation_row.repository",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    }
  ],
  "sources": {
    "attestation": {
      "receipt": "wireless-pqc/dataroom/TOP_N_ATTESTATION.jsonl",
      "source": "dataroom/TOP_N_ATTESTATION.jsonl",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "9bf48d398fc36b52f21264edc3a04b8e2c3cd7da3c53f24ec80636897997097e",
      "bytes": 3364,
      "visibility": "sealed"
    },
    "top40": {
      "receipt": "wireless-pqc/dataroom/top40.json",
      "source": "dataroom/top40.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "6076db4027d7499ac53b5cf15f9a07bb7e41c38f56fb0f469a62353e10e65353",
      "bytes": 167747,
      "visibility": "sealed"
    },
    "witness_quality": {
      "receipt": "wireless-pqc/dataroom/witness_quality.json",
      "source": "dataroom/witness_quality.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "5d379a10112d400163b35100a423124c28e8bfbbdbe4378b71840eda85f75cfe",
      "bytes": 143046,
      "visibility": "sealed"
    },
    "repro_index": {
      "receipt": "wireless-pqc/repro/INDEX.json",
      "source": "repro/INDEX.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "378fd4a3ce4f44403b7c9ca6a3f19c11895831f892736376c90cf9423037f9eb",
      "bytes": 26512,
      "visibility": "sealed"
    }
  }
}
