feat(verified): evidence chain -- change, run and evidence identities - #6693
Merged
Merged
Conversation
specs/verified/evidence_chain.t27: chain() checks that a run names its change, the evidence names its run, outputs/tests/logs are referenced and the seal matched, and returns the first broken link. Ids are prefixes of existing hashes and numbers (0 = not recorded); no hash is computed here. 9 tests, 10/10 mutants killed, sealed. Closes #6692 Refs #6655 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
This was referenced Oct 6, 2026
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #6692
Refs #6655 (Phase D: change identity, run identity, evidence record)
Adds
specs/verified/evidence_chain.t27.chain(change, run_change, run, ev_run, has_outputs, has_tests, has_logs, seal)checks the links in order and returns LINKED or the first broken one:A record that points at another change or run is a different chain, so it proves nothing about this one. Missing is never linked. Ids are 64-bit prefixes of existing hashes and numbers, so no hash is computed and no new store is added.
Evidence (Railway lab, master t27c, zig 0.16.0):
t27c seal --verify: all hashes MATCH (spec_hash sha256:661844eb...)🤖 Generated with Claude Code