{
  "_doc": "One result, read from the codebase’s own files at the commit named here. Every value is that file’s own, copied verbatim; nothing here is written by hand. A value replaced by {withheld: true, sha256_of_value, bytes} is committed by its sha256 instead of published, for the reason it states, and is never edited. Each whole source file is committed by sha256 below, and its bytes are published only where its visibility says so. The codebase is named by the public subject its files are published under.",
  "lane": "wireless-pqc",
  "repository": "wireless-pqc",
  "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
  "portfolio_id": "wireless-pqc:cbmc-bounded-decision-contracts",
  "id": "cbmc-bounded-decision-contracts",
  "attestation_row": {
    "attested_at": "2026-09-13",
    "attestor": "03-wifipqc",
    "repository": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "6f37ed958c37482bf7ee04acba61df04492fe3186c1ba6c10b77519cd450c69f",
      "bytes": 7
    },
    "source_doc": "CROWN_JEWELS_RESOLVED.md",
    "source_doc_sha256": "6958cd834026328936c2fbfb51a8b00a4dd5ec6cb65b1d0d8960bcfe0b9e2418",
    "state": "attested",
    "top_n": 26,
    "note_sha256": "c1af3e3220ffc4290cc975a79bf85d216638fd8abd3f4d8e7e67f6f5af0aff3b",
    "ids_in_row": 26,
    "file": "dataroom/TOP_N_ATTESTATION.jsonl",
    "line": 1
  },
  "claim_source": {
    "receipt": "wireless-pqc/dataroom/top40.json",
    "sha256": "6076db4027d7499ac53b5cf15f9a07bb7e41c38f56fb0f469a62353e10e65353",
    "field": "entries[1].claim",
    "file": "dataroom/top40.json"
  },
  "top40_entry": {
    "id": "cbmc-bounded-decision-contracts",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "d190ac73d6d1430716375dff63491c2887e66679d5122f0d2ee0d8cb86e6b56e",
      "bytes": 39
    },
    "rank": 2,
    "native_rank": 21,
    "title": "CBMC proves the deployable-glue decision contracts for every bounded input, and a deliberately broken compare fails verification",
    "claim": "CBMC proves the deployable-glue decision contracts for every bounded input, and a deliberately broken compare fails verification.",
    "scope": "Bounded model checking within its unwinding bound; it abstracts HMAC. This is the glue DECISION LOGIC -- full hostapd-daemon integration is a documented residual.",
    "artifact_path": "artifacts/native/cbmc_equiv_ci.json",
    "witness_command": "make code-equiv-cbmc",
    "witness_result": {
      "status": "RAN",
      "exit": 0,
      "line": "ACCEPTANCE: ALL PASS",
      "seconds": 5.2,
      "run_at": "2026-09-13T02:34:20Z",
      "owner_gated": false,
      "reason": null,
      "run_of_record": "clean clone at HEAD (S03, dataroom/witness_quality_20260913/clean_clone_baseline.json)"
    },
    "third_party_axis": "B",
    "facts": {
      "ran_with_receipt": true,
      "third_party_graded": true,
      "negative_control_stated": true,
      "ip_class_known": false,
      "reproduce_command": true,
      "regenerates": false
    },
    "fact_count": 4,
    "repro_command": "make code-equiv-cbmc",
    "ip_class": null,
    "ip_class_basis": "no source in this repository states an IP class for this entry; never guessed"
  },
  "witness_quality_entry": {
    "id": "cbmc-bounded-decision-contracts",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "d190ac73d6d1430716375dff63491c2887e66679d5122f0d2ee0d8cb86e6b56e",
      "bytes": 39
    },
    "title": "CBMC proves the deployable-glue decision contracts for every bounded input, and a deliberately broken compare fails verification",
    "claim": "CBMC proves the deployable-glue decision contracts for every bounded input, and a deliberately broken compare fails verification.",
    "class": "ASSERTING",
    "why": "clean-clone exit 0; every decisive planted defect went red: [0] the constant-time compare under proof checks only the first byte -> exit 2",
    "witness_command": "make code-equiv-cbmc",
    "clean_clone": {
      "exit": 0,
      "status": "RAN",
      "seconds": 5.2,
      "first_line": "cbmc-equiv: 4/4 harnesses verified; teeth=True; ok=True",
      "last_line": "ACCEPTANCE: ALL PASS",
      "artifact_rewritten": false,
      "dirtied": [],
      "run_at": "2026-09-13T02:34:20Z",
      "reason": null
    },
    "planted_defects": [
      {
        "index": 0,
        "what": "the constant-time compare under proof checks only the first byte",
        "falsifies": "property: ct_eq == spec_eq for every bounded input",
        "decisive": true,
        "planted": [
          {
            "path": "tools/hostapd_pqc/cbmc_glue_harness.c",
            "diff": "'    for (size_t i = 0; i < n; i++) d |= (uint8_t)(a[i] ^ b[i]);' -> '    for (size_t i = 0; i < 1; i++) d |= (uint8_t)(a[i] ^ b[i]);' (x1 of 1)"
          }
        ],
        "exit": 2,
        "seconds": 5.5,
        "last_line": "make: *** [code-equiv-cbmc] Error 1",
        "failure_moved_by": null
      }
    ],
    "measured": true,
    "stale_claims_ref": null
  },
  "packet": {
    "id": "cbmc-bounded-decision-contracts",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "d190ac73d6d1430716375dff63491c2887e66679d5122f0d2ee0d8cb86e6b56e",
      "bytes": 39
    },
    "witness_command": "make code-equiv-cbmc",
    "checker_witness": "make code-equiv-cbmc",
    "path": "repro/cbmc-bounded-decision-contracts/",
    "inputs": 3,
    "grade": "ASSERTING",
    "facts_count": 4,
    "env_guard": {
      "tool": "cbmc",
      "exit": 69
    },
    "kit2": {
      "grade": "ASSERTING",
      "graded_commit": "ecb2234212c70992465532494a378f97faffa959",
      "lane_head_at_grading": "cece072121bfd611fff9d7bf30acd649b8e55b40",
      "graded_utc": "2026-09-17T16:25:33Z",
      "reasons": [],
      "semantic_mutations": {
        "claim_moving": 3,
        "repro_red": 3,
        "witness_runs": 7,
        "tiers": {
          "claim_values": {
            "candidates": 0,
            "claim_moving": 0,
            "witness_runs": 0
          },
          "listed": {
            "candidates": 65,
            "claim_moving": 3,
            "witness_runs": 7
          },
          "traced": {
            "candidates": 0,
            "claim_moving": 0,
            "witness_runs": 0
          }
        }
      },
      "neutral_mutations": {
        "drawn": 10,
        "repro_red": 0,
        "coverage": {
          "listed_inputs_with_edits": 2,
          "runs": 10
        }
      },
      "inputs_graded": 3,
      "kit_pins_sha256": "af52c51b8b736c1930e0f36a27ce273f13cf86c8b4b88b703df44e80d5b25553"
    }
  },
  "measured": {
    "measured": true,
    "basis": "planted_defects[].exit = 2",
    "exit": 2,
    "defect_rejected": true
  },
  "register": {
    "truth_state": "attested",
    "truth_line": 114,
    "measured_per_register": true,
    "witness_class_per_register": "ASSERTING",
    "ip_class_public": "unknown",
    "ip_class_sha256": "b23a6a8439c0dde5515893e7c90c1e3233b8616e634470f20dc4928bcf3609bc",
    "ip_class_source": "TOP_N_CROWN_JEWELS.md:72 @ 102044d55aab",
    "receipt": "register/CROWN_JEWELS_TRUTH.md",
    "receipt_sha256": "bde06cf0d3e99644522d18e79b6bd5d84ed4f5c86e315a48fef207e9e49c5022",
    "ip_class_receipt": "register/ip_class.jsonl",
    "ip_class_receipt_sha256": "b1e8f97aa6779e0fefed2f7a7726e1a03563b536b497392401b49bb8ef84d4ca"
  },
  "withheld_fields": [
    {
      "field": "top40.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "witness_quality.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "packet.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "attestation_row.repository",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    }
  ],
  "sources": {
    "attestation": {
      "receipt": "wireless-pqc/dataroom/TOP_N_ATTESTATION.jsonl",
      "source": "dataroom/TOP_N_ATTESTATION.jsonl",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "9bf48d398fc36b52f21264edc3a04b8e2c3cd7da3c53f24ec80636897997097e",
      "bytes": 3364,
      "visibility": "sealed"
    },
    "top40": {
      "receipt": "wireless-pqc/dataroom/top40.json",
      "source": "dataroom/top40.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "6076db4027d7499ac53b5cf15f9a07bb7e41c38f56fb0f469a62353e10e65353",
      "bytes": 167747,
      "visibility": "sealed"
    },
    "witness_quality": {
      "receipt": "wireless-pqc/dataroom/witness_quality.json",
      "source": "dataroom/witness_quality.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "5d379a10112d400163b35100a423124c28e8bfbbdbe4378b71840eda85f75cfe",
      "bytes": 143046,
      "visibility": "sealed"
    },
    "repro_index": {
      "receipt": "wireless-pqc/repro/INDEX.json",
      "source": "repro/INDEX.json",
      "commit": "709160c57c9eb875e239acdf1eb3d0c4462e4c29",
      "sha256": "378fd4a3ce4f44403b7c9ca6a3f19c11895831f892736376c90cf9423037f9eb",
      "bytes": 26512,
      "visibility": "sealed"
    }
  }
}
