Kernel
Typed definitions, gate semantics, threat model, and a falsifiable spectral hypothesis kept apart from the gate.
Proposal
Let S_d be the typed state space for domain d. A proposal is x = (s_before, a, s_proposed, d, t_v, t_r). Here a is the proposed action, t_v is valid time and t_r is record time. A domain adapter declares how these fields are observed. It cannot confer authority.
Gate
P_v: a versioned policy, retrievable by content hash.I_v : S_d → V_I: a declared invariant measurement, with comparisonD_Iand registered toleranceε_I.E_x: typed evidence bindings. Each has a subject, source, hash, provenance, capture time, availability interval and verification result.A_x: an authority chain, verified against declared trust roots independently of the proposer.
An invariant may be an authorisation scope, resource bound, schema constraint, conservation quantity or other domain-defined property. If eigenvectors genuinely matter, the adapter must name the operator L, its domain and basis, and a registered comparison. An example is the distance between spectral projectors, ‖P_before − P_after‖ ≤ ε. The kernel contains no “eigenvalue equality between a transition and an invariant”.
Determination semantics
- Every check returns PASS, FAIL, UNAVAILABLE or UNMEASURABLE. Only all-PASS checks permit EXECUTE. The site’s original browser gate still returns HOLD; its EXECUTE path is untested. A separate experimental verifier and browser evaluator address one test-domain EXECUTE under a declared test root. They do not exercise the original browser gate.
UNMEASURABLEandUNAVAILABLEnever become PASS, by default or by display.- Specification: the gate issues a hash-bound (and, where key custody exists, signed) receipt before any authorised effect, and execution and observed consequence get separate receipts. This site executes no effects, so only the determination receipt exists here.
- A reassessment is a new determination that references the earlier receipt. The earlier determination is not modified, and its
receipt_refcommits to its content. - A verified signature establishes who signed some bytes. It cannot turn a failed binding, policy or invariant check into PASS. Signature verification and authority verification are reported separately.
INPUT_BINDING_FAILED: the recomputedinputs_hash(or policy hash or evaluation time) differs from the value in the signed verdict.REPLAY_FAILEDis reserved for a replay comparison that was actually run and failed. The site’s replay recomputes its own determination. It is not an independent replay of a source gate’s decision.- A trust root declared inside a demo is illustrative and never establishes independent authority.
Epistemixer: declared measurements PROPOSED
The Epistemixer evaluates three named, domain-specific functions: 𝓔_d(x) = (R_d(x), G_d(x), K_d(x)). It does not apply vector calculus to arbitrary syscalls or organisations.
| Output | Meaning | Required declaration |
|---|---|---|
R_d relevance | Does the evidence bear on this proposed action and purpose? | Evidence-to-claim test, scope, threshold |
G_d generativity | What additional reachable or testable states does the transition create? | State model, horizon, baseline, threshold |
K_d circulation / instability | Does a feedback cycle amplify unresolved discrepancy? | Cycle model, measurement, bound |
Each function returns PASS, FAIL or UNMEASURABLE, together with its inputs, method version and uncertainty. These outputs inform a named policy. Positive generativity is not a universal condition for permission. A research fixture may define a smooth manifold, a differentiable φ and a vector field 𝐅, and then measure directional derivative, divergence and curl. A discrete graph fixture may use incidence operators with explicitly chosen cycles. Those operators belong only to fixtures that supply the geometry. No Epistemixer function is implemented on this site.
Threat model (current scope)
| Threat | Handled by | Status |
|---|---|---|
| Altered fixture or verdict bytes | Manifest SHA-256 per file; domain-separated SHA-256; Ed25519 over domain ‖ bytes | tested |
| Non-canonical encodings smuggling alternate meanings | Strict CBOR decoders, 79 rejection vectors | tested |
| Valid signature over a verdict about different inputs | binding.inputs_hash check → INPUT_BINDING_FAILED | tested |
| Self-asserted signer authority | Trust roots declared independently of the proposer | tested (as a rejection) |
| Hostile host serving consistent fake files and manifest | Not handled. The manifest comes from the same origin. | UNAVAILABLE |
| Key custody, time source integrity, durable append-only ledger | Not implemented | UNAVAILABLE |
Spectral hypothesis PROPOSED
Spectral structure is an optional hypothesis, separate from the production gate. Take a declared finite transition graph G with a specified graph operator L_G. Project a typed transition encoding v_x onto the eigenspaces of L_G. Any run must publish the encoding, normalisation, graph construction, spectrum and stability checks.
Zeta zeros may serve as an experimental reference sequence in a preregistered comparison against controls: matched random spectra and other fixed sequences. The observable, loss function, held-out fixtures and criterion for added value are fixed before the run. If the zeta sequence performs no better than controls, that result is reported and the zeta claim is removed from any product description.
Background, not a result of this programme: no established operator is known whose spectrum is the Riemann zeta zeros. The Hilbert–Pólya approach remains a proposed route, tied to the open Riemann hypothesis (see P. Sarnak’s account in the Clay Mathematics Institute 2004 annual report). No spectral output is a gate input, and research endpoints never return a warrant.