The self-auditing benchmark¶
"The project rigorously verifies its output and never verifies its self-description."
—
oracles.audit.structure_wiresmodule docstring
Every check described on this page is implemented in python/oracles/audit/
and oracles.trust_ledger. Rather than re-narrate what those modules already
document — the kind of restatement that is exactly how the drift this page
exists to close first happened — this page renders their own docstrings and
adds only the connective prose needed to read them in order.
Numerical wires: W1, W2a–W2d, W3–W11¶
oracles.audit.wires verifies that the numbers the benchmark reports are
true — synthetic-data invariants, metric identities recomputed from raw
arrays, results round-tripping through the frozen contract, Jacobian
conditioning, and more. Each wire_w* function returns one or more
WireResult records with a "pass" / "warn" / "fail" / "skipped" /
"gap" status; a missing input is reported as "skipped" or "gap", never
silently upgraded to a pass. The full function-by-function listing (every
wire_w1.. wire_w11) lives on
Python: benchmark harness —
this page renders only the module's own framing of that discipline:
oracles.audit.wires
¶
One function per wire. Each returns a list of WireResult records.
W1/W3/W4/W6 read the pytest lastfailed cache for their status via a TRI-STATE
helper: an absent cache means the test never ran, so the wire reports "skipped"
(no pass-by-absence) rather than inflating the rung with an unbacked "pass".
W2a/W2b/W2c accept an optional audit_records parameter; when present they
RECOMPUTE from the full undecimated arrays in the audit.json sidecar instead of
relying on a stale cache entry. When audit_records is None they return
"skipped" so the rung is not inflated.
Note
_SUBJECT_BACKEND (used by W2c) names the subject under test in the
benchmark harness — the backend whose \(\kappa(J)\) capability W2c verifies.
Oracle backends (lmfit, jax) that do not expose \(\kappa\) are a disclosed
per-backend limitation, not a capability gap in the subject.
W8, the external-replication gate, is its own module because it re-runs real NIST StRD certified-value datasets rather than checking an internal invariant:
oracles.audit.nist
¶
NIST StRD certified-value validation emitter (wire W8 evidence).
Re-runs 22 of NIST's 27 StRD nonlinear-regression datasets — Gauss1, Gauss2,
Gauss3, Lanczos1, Lanczos2, Lanczos3, BoxBOD, Misra1a, Misra1b, MGH17,
Bennett5, MGH09, Eckerle4, Roszman1, DanWood, Kirby2, Hahn1, Thurber, Rat42,
Rat43, Chwirut1, Chwirut2 — and returns a structured
:class:~oracles.trust_ledger.NistValidation. The original ten also have a
dedicated scenario test apiece under tests/scenario/nist_strd/; the
remaining twelve are exercised here and via kernel-correctness numpy-oracle
tests only. Each fit starts from NIST's published START2 guess, recovers the
parameters via spectrafit's LM solver, projects them back to the NIST
parameterization, and records the significant-figure agreement against the
certified values.
The fits are tiny (\(\leq\) 250 points, ~0.4 s total) and deterministic; this is the cheap, independent external-replication oracle that earns the honest RUNG_5.
The build/project recipes intentionally mirror the scenario tests' _build_graph
/ _project_to_nist helpers verbatim (same parameterization mapping, same
START2 guess) so this emitter and the green scenario tests assert the same fit.
Bennett5 note: Bennett5 is NIST "Higher" difficulty and may not converge to
the certified values from START2 via the LM solver. Its _NistRecipe entry
is included for completeness; if it does not pass the sig-fig threshold the
NistDataset.passed flag will be False for that entry. NistValidation.passed
is a strict all() over every recipe dataset with no exclusion in this
production path — a Bennett5 regression fails the overall validation and caps
the W8 wire (and therefore the RUNG_5 unlock) exactly like any other dataset
would. The unit test suite (tests/audit/test_nist_validation.py) separately
tracks a narrower _OPTIONAL_DATASETS subset for its own "mandatory datasets
pass" assertion, but that exclusion is local to the test and is never applied
to the value this module (or the W8 wire) actually returns.
MGH09 note: MGH09 is also NIST "Higher" difficulty (Kowalik–Osborne rational
function). It is included for kernel-correctness evidence (the MGH09_RATIONAL
kernel and parity oracle are verified), but LM-solver convergence to the certified
values is not guaranteed from either NIST start. Like Bennett5, it is in the test
suite's _OPTIONAL_DATASETS set, not excluded from this module's own
NistValidation.passed.
Threshold & denominator: NIST_SIGFIG_THRESHOLD (4.0) is the minimum
significant-figure agreement required for a dataset to "pass". The scenario
tests assert 1e-3 relative (~3 sig figs) on parameters; this emitter holds
to the stricter \(\ge\)4 sig figs (1e-4 relative) that the RSS/\(\chi^2\)
assertions use, which the actual fits clear by ~6 figures of headroom.
NIST_STRD_TOTAL (27) is the size of the external NIST StRD
nonlinear-regression universe (Lower/Average/Higher difficulty) — the
canonical denominator for "N of M datasets reproduced"
(https://www.itl.nist.gov/div898/strd/nls/nls_main.shtml). It lives here
(the validation source of truth) and is emitted on the contract so the UI
never hardcodes it.
See NIST StRD Validation for what that dataset-by-dataset agreement means and NIST StRD reference for the generated agreement table itself.
Structural wires: the S1–S5 taxonomy¶
The W-wires above only ever check numbers. A different defect class needs its
own guard: claims the repository makes about its own structure — a hook's
cited "source of truth" file, an
enforcement anchor's trigger, a doc's ownership claim, an FFI (Foreign
Function Interface) stub's completeness, a hand-maintained model list —
silently drifting from the structure itself. oracles.audit.structure_wires
closes that gap with the same idiom as the numerical wires: each
S-prefixed wire below returns a
WireResult, so a drifted comment or a stale doc now fails a wire exactly
the way a wrong \(r^2\) does, and both land in the same TrustBlock.
oracles.audit.structure_wires
¶
Structure wires — the self-description trust ledger (S-wires).
The W1..W11 wires in :mod:oracles.audit.wires verify that the numbers this
project reports are true (\(r^2\), \(\chi^2_{\mathrm{red}}\), pulls, NIST agreement). They are the reason
the dashboard can put a credibility rung on the science.
A repository can accumulate claims about its own structure that silently drift from the structure itself — all instances of the same defect class, and none of them numerical:
- a hook's "source of truth" comment points at a file that does not exist
anywhere under web/, so the guard is dead code.
- a pre-merge-*.sh hook is declared as an INDEX.yaml stream anchor but is
wired to NO trigger (0 refs in settings.json / CI / poe).
- a doc names oracles/contract.py as "the frozen BenchReport contract"
when the real BenchReport lives elsewhere.
- _core.pyi omits a real runtime PyO3 symbol.
- PeakModel.spectrafit_type is a bare str resolved by getattr at fit
time — a hand-maintained model list with no compile/import binding.
These are all the same bug: a claim the repository makes about its own structure that has silently drifted from the structure. The project rigorously verifies its output and never verifies its self-description. So a contributor reads a comment, an anchor, a doc, a stub — and is led somewhere that no longer exists.
This module closes that gap with the project's own idiom. Each S-wire returns a
:class:~oracles.trust_ledger.WireResult (same record the numerical wires emit),
so structural truth and numerical truth land in one TrustBlock and surface
on the same credibility rung. A drifted comment, a dead anchor, a stale doc, a
phantom stub symbol, or an un-bound model list now fails a wire — the same
way a wrong \(r^2\) does.
Wire-ids are the S series so they never collide with W1..W11:
S1 hook-reference liveness — every path a hook calls a "source of truth"
actually exists on the tree.
S2 anchor-trigger liveness — every INDEX.yaml stream anchor that *looks*
like an enforced hook is reachable from a real
trigger (settings.json / CI / poe).
S3 doc-owner truth — when a doc says "X is the frozen BenchReport
contract", class BenchReport is actually
defined in X.
S4 FFI-stub completeness — _core.pyi's top-level defs == the runtime
PyO3 capability set.
S5 model-list parity — Rust ModelTypeStr::ALL == Python ModelType
members == every PeakModel.spectrafit_type
registration, all three the same set, so a
hand-maintained model list can no longer
drift silently.
Each wire is pure (filesystem read only), returns skipped rather than inflating
a pass when its inputs are absent, and never raises — a structural verifier that
crashes is just another broken claim.
s1_hook_reference_liveness(root=None)
¶
S1: every source-of-truth path a hook cites must exist on the tree.
A hook whose REQUIRED_* comment / guard names a file that does not exist is dead code lying about its own scope.
Note
_PATH_TOKEN matches path-shaped tokens a hook cites as authority
(e.g. frontend/render_report.tsx, web/src/panels/registry.tsx,
python/oracles/contract.py). It has no leading \b: a leading "." (e.g.
.claude/settings.json) is a non-word char, so \b would
anchor on the first word char and silently drop the dot, turning
a real path into a phantom claude/settings.json. An optional
leading "." captures dotfiles/dot-dirs whole.
_PATH_IGNORE excludes tokens that are obviously not repo paths
(urls, globs, std headers) or are runtime-generated artifacts that
legitimately do not exist at rest (a benchmark baseline the hook
itself writes/reads, not a source-of-truth that must pre-exist).
_ILLUSTRATIVE excludes lines that cite a path illustratively, not
as a source-of-truth claim: a shellcheck source= directive (the
real source is the adjacent live source line, resolved relative
to the hook dir) and example/usage blocks. A cited path is
considered live if it resolves from the repo root OR from the
hook's own directory ($SCRIPT_DIR-relative sources, e.g.
lib/git-hygiene.sh sitting in .claude/hooks/lib/).
s2_anchor_trigger_liveness(root=None)
¶
S2: every INDEX.yaml *.sh anchor must be reachable from a real trigger.
Only DEPLOYED hooks (the .sh exists on disk) count as advertised
enforcement — a name that appears only in a planning comment (e.g. the
to_hooks: relocation list) with no file yet is a TODO, not a false
promise of automation.
s3_doc_owner_truth(root=None, *, symbol='BenchReport', docs=('CLAUDE.md',))
¶
S3: a doc that names the symbol owner must point where it is defined.
Note
_OWNER_CLAIM captures a path token on the same line as the
phrase "frozen BenchReport contract" in either order — e.g.
CLAUDE.md:231 reads python/oracles/contract.py` (the frozen
`BenchReport` contract), i.e. the path PRECEDES "frozen ...
BenchReport contract".
Doc text has its whitespace (incl. newlines) collapsed before
matching, so a claim that wraps across lines in the markdown still
matches — the bounded [^\n] windows in _OWNER_CLAIM
otherwise cannot span the line break between "...frozen" and
"BenchReport".
s4_ffi_stub_completeness(root=None)
¶
S4: _core.pyi's top-level defs must equal the runtime PyO3 surface.
The hand-kept _core.pyi must enumerate exactly the runtime PyO3
capability set; a missing symbol (e.g. model_type_wire_strings)
blinds the type checker to the canonical model enumerator.
Note
The source of truth for the runtime surface is the
wrap_pyfunction! registrations in the PyO3 module init. This
wire reads the .rs source rather than importing the compiled
extension so it can run with no build step.
s5_model_list_parity(root=None)
¶
S5: Rust ModelTypeStr == Python ModelType == every spectrafit_type name.
Rust ModelTypeStr::ALL must equal the Python ModelType members,
which must equal every PeakModel.spectrafit_type registration — the
third list (spectrafit_type) is the one ARCH-02 flags as un-bound;
this wire binds all three into one set.
run_structure_wires(root=None)
¶
Run every S-wire, never raising — a crashing verifier is a broken claim.
main()
¶
CLI: print each S-wire and exit non-zero on any structural drift.
Structure wires are deliberately non-capping on the credibility rung in both directions — see Credibility-rung derivation below for why.
Claim registry and value provenance¶
Two smaller registries back the taxonomy above with what is being audited, as opposed to whether each check passed:
oracles.audit.claims
¶
Claim registry. Claims register themselves; the runner discovers them.
Vista-trap preemption: the audit harness never references claims by name. Adding
the 101st claim is a single class definition; the runner picks it up from
CLAIM_REGISTRY. Mirrors MODEL_REGISTRY in oracles.models.
Note
The NIST StRD external-replication claims (nist.*, backed by W8):
each dataset's recovery of NIST's certified values is a distinct claim.
They are audited only when W8 passes (all four datasets reproduce the
certified values to \(\ge\) the sig-fig threshold), which is also what
unlocks RUNG_5.
NON_PATH_SOURCE_FIELDS = frozenset({'results.json', '/api/*', 'scipy.least_squares'})
module-attribute
¶
Source-field sentinels that are NOT JSON paths into the payload (external oracle / file / API references). The runtime + test L3 resolvers skip these.
Claim
¶
Abstract claim. Subclasses set the four class attributes.
resolve_source_field(payload, path)
¶
Return True iff path resolves to \(\geq 1\) non-null value in payload.
Minimal JSON-path resolver shared by the data-level L3 test and the runtime
L3 guard in :func:oracles.audit.runner.run_audit. Syntax:
register_claim(cls)
¶
Decorator: add a Claim subclass to the registry.
audited_count(wire_status)
¶
Count claims whose backing verification wire passed.
A claim is audited only when its declared wire_id maps to "pass" in
wire_status. A failing/skipped wire (e.g. W2c \(\kappa(J)\)) leaves its claims
un-audited, so audited_count truthfully falls below the registered total
instead of vacuously equalling it.
oracles.audit.provenance
¶
Value-provenance spine — Invariant V, the single declarative source of truth.
Every numerical value the dashboard renders gets exactly one ValueProvenance
record here: where it is produced, the contract field that carries it, the
independent oracle that checks it, the panel that renders it, and — crucially —
whether it is real or a proxy (and if a proxy, the tracked task to make
it real). The claim ledger, the proxy register, and contract-coverage all
derive from this registry, so a value's provenance can never drift across two
code paths.
Invariant V — End-to-end Value Provenance:
- V1 produced for real at the source (not a proxy) —
status. - V2 a first-class contract field that resolves non-null —
contract_field. - V3 checked against an independent oracle within a declared tolerance —
oracle. - V4 no silent skip —
skip_policysays what a missing check means. - V5 no silent proxy —
status == "proxy"requires aproxy_task(enforced structurally at construction; the best enforcement tier).
Vista-trap preemption (evolutionary-platform-thinking): adding the next metric
is a single record, not new gate code. The registry mirrors CLAIM_REGISTRY
in :mod:oracles.audit.claims and MODEL_REGISTRY in :mod:oracles.models.
Note
Audited-claim values maintain parity with CLAIM_REGISTRY: a
record's id equals the claim's claim_id, contract_field
equals claim.source_field, and oracle.wire_id equals
claim.wire_id.
convergence.theta_distance is now REAL (it was previously a
\(\chi^2\)-floor proxy): per-iteration \(\theta\) is recorded by the faer
LM driver (FitResult.params_history), the engine computes
\(d_k = \|(\theta_k - \theta_{\mathrm{true}})/s\|_2\) into the contract
field, and the web renders it directly. Its oracle is the ground-truth
V&V test.
ProvenanceStatus = Literal['real', 'proxy', 'deferred']
module-attribute
¶
real — computed for real + oracle-checked. proxy — a stand-in for an
unimplemented quantity (must be declared). deferred — a contract field that
exists but no panel renders yet.
SkipPolicy = Literal['caps_rung', 'gap']
module-attribute
¶
What a missing oracle check means (V4). caps_rung — a skip is a real
coverage hole that must cap the credibility rung (never a silent pass).
gap — a disclosed capability absence (e.g. \(\kappa(J)\) not exposed) that does not
cap the rung but is reported honestly.
OracleRef
pydantic-model
¶
Bases: BaseModel
The independent oracle that verifies a value, and its declared tolerance.
Show JSON schema:
{
"additionalProperties": false,
"description": "The independent oracle that verifies a value, and its declared tolerance.",
"properties": {
"wire_id": {
"title": "Wire Id",
"type": "string"
},
"reference": {
"title": "Reference",
"type": "string"
},
"tolerance": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"title": "Tolerance"
}
},
"required": [
"wire_id",
"reference"
],
"title": "OracleRef",
"type": "object"
}
Config:
extra:forbidfrozen:True
Fields:
wire_id
pydantic-field
¶
The verification wire that performs the check (W1..W8, W2d).
reference
pydantic-field
¶
Human-readable name of the independent reference the value is checked against.
tolerance = None
pydantic-field
¶
Declared numeric tolerance for the check; None for non-numeric / band /
finite-only / bitwise-exact checks (described in reference).
ValueProvenance
pydantic-model
¶
Bases: BaseModel
One rendered numerical value, traced source → contract → oracle → render.
Show JSON schema:
{
"$defs": {
"OracleRef": {
"additionalProperties": false,
"description": "The independent oracle that verifies a value, and its declared tolerance.",
"properties": {
"wire_id": {
"title": "Wire Id",
"type": "string"
},
"reference": {
"title": "Reference",
"type": "string"
},
"tolerance": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"title": "Tolerance"
}
},
"required": [
"wire_id",
"reference"
],
"title": "OracleRef",
"type": "object"
}
},
"additionalProperties": false,
"description": "One rendered numerical value, traced source \u2192 contract \u2192 oracle \u2192 render.",
"properties": {
"id": {
"title": "Id",
"type": "string"
},
"source": {
"title": "Source",
"type": "string"
},
"contract_field": {
"title": "Contract Field",
"type": "string"
},
"oracle": {
"anyOf": [
{
"$ref": "#/$defs/OracleRef"
},
{
"type": "null"
}
],
"default": null
},
"panel_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Panel Id"
},
"status": {
"default": "real",
"enum": [
"real",
"proxy",
"deferred"
],
"title": "Status",
"type": "string"
},
"proxy_task": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Proxy Task"
},
"skip_policy": {
"default": "caps_rung",
"enum": [
"caps_rung",
"gap"
],
"title": "Skip Policy",
"type": "string"
}
},
"required": [
"id",
"source",
"contract_field"
],
"title": "ValueProvenance",
"type": "object"
}
Config:
extra:forbidfrozen:True
Fields:
-
id(str) -
source(str) -
contract_field(str) -
oracle(OracleRef | None) -
panel_id(str | None) -
status(ProvenanceStatus) -
proxy_task(str | None) -
skip_policy(SkipPolicy)
Validators:
-
_structural_invariants
id
pydantic-field
¶
Dotted namespace, e.g. "convergence.theta_distance". Equals the
claim_id for values that are also audited claims.
source
pydantic-field
¶
The symbol / pipeline that produces the value (Rust fn, Python fn).
contract_field
pydantic-field
¶
JSON-path leaf into the serialised BenchReport payload.
oracle = None
pydantic-field
¶
The independent oracle + tolerance (V3). None means no oracle yet —
valid only for proxy / deferred values awaiting implementation.
panel_id = None
pydantic-field
¶
The web panel that renders this value, or None if deferred / not rendered.
proxy_task = None
pydantic-field
¶
Tracked task to implement the real metric; required iff status == "proxy".
Credibility-rung derivation¶
oracles.audit.runner walks every wire and produces the TrustBlock that
gets persisted as trust.json and inlined into results.json:
oracles.audit.runner
¶
Audit runner — walks the wire list, computes the credibility rung.
Persists trust.json next to manifest.json, and inlines the TrustBlock into results.json.
The mapping from wire statuses to a CredibilityRung — which statuses cap
the rung, which are non-capping, and what unlocks the reserved top rung — is
itself substantial enough to read as primary source rather than summary:
oracles.audit.runner._compute_rung(wires)
¶
Map wire statuses to a credibility rung.
Only a genuine fail caps the rung at RUNG_2. A gap (a disclosed
capability absence, e.g. \(\kappa(J)\) not exposed) and a skipped (test never ran)
are NON-CAPPING: they neither earn a rung nor cap it, so the earned rung is
whatever the passing wires support.
The core wires (everything except W8, W10, W11) earn RUNG_2..RUNG_4. RUNG_5
— reserved for "independent differential validation + external replication +
inferential checks" — is unlocked only when W8 (NIST StRD certified-value
validation) \(\land\) W10 (\(\sigma\)-calibration) \(\land\) W11 (speed inference) all pass AND the
core wires already clear RUNG_4. Any of the three top-rung gates absent or
skipped → the rung honestly caps at RUNG_4; a lower-rung fail still caps
at RUNG_2 regardless of W8/W10/W11.
Two tiers of "unverified value wire" capping (EF-PY-13):
-
Soft-cap wires (W2a/W2b/W2c):
skippedmeans the audit sidecar was absent so the recompute could not run — a graceful degradation.warnmeans the recompute DID run and found a value outside its target band (e.g. W2b's \(\sigma\)-coverage falling outside [0.5, 0.85]) — a real, disclosed numerical concern, not a hard failure. Bothskippedandwarnon any of these caps the rung at RUNG_3 (V4 guard) — a "warn" must not be silently invisible to the rung the way an unrecognised status would be. -
Hard-cap value-oracle wires (W2d):
skippedmeans the pytestlastfailedcache was absent (UNKNOWN state on a fresh checkout). An absent cache is indistinguishable from "never verified"; the solver-output oracle claim must not be silently passed.skippedon W2d caps the rung at RUNG_2, exactly like a genuinefail.
Note
Structure (S-prefixed) wires are non-capping for now: they verify
the repo's self-description, not a run's numbers, and some
confirmed structural items are pending triage. They ride in
TrustBlock.wires for visibility but are excluded from rung
capping — in BOTH directions — so structural drift can't conflate
with "the science is unverified" (RUNG_2's meaning) AND structural
passes can't inflate a rung the numerical evidence doesn't support.
Promote them once the structural backlog clears.
W8/W10/W11 are top-rung gates: they earn RUNG_5 but must not
inflate the core-wire pass count that earns RUNG_2..RUNG_4, so all
three are excluded from the core ladder and their votes only count
at the RUNG_5 gate. Structure (S-prefixed) wires are excluded from
the core ladder for the same reason they're excluded above — a
passing structure wire must not count toward pass_count either,
or structural checks alone could lift the rung (SL-11: previously
only excluded from the fail-floor check, not from the core-ladder
pass-count too).
W8 is also excluded from the soft-cap check below: its skip is
already handled by the w8_passed gate — an absent W8 honestly
caps at the core ladder (RUNG_4) and does not undermine core value
verification. A skip on the visible/render lane (W5) is
conservative-by-design, not a value hole.
TrustBlock: the provenance contract¶
oracles.trust_ledger defines the typed records every wire above ultimately
produces or feeds — WireResult, NistParam/NistDataset/NistValidation
(the W8 evidence block), TrustBlock, and the persisted TrustLedger — plus
the CredibilityRung enum _compute_rung returns:
oracles.trust_ledger
¶
Trust-ledger contract — single source of truth for what was audited.
The TrustBlock is embedded in BenchReport (optional, additive). It maps each
audited claim to a wire-id, the evidence sentence, and a pass/warn/fail status,
plus an aggregate credibility rung. The block is written to disk as
trust.json next to manifest.json AND inlined into results.json so a
single payload carries its own provenance.
CredibilityRung
¶
Bases: IntEnum
V&V maturity ladder (inspired by ASME V&V credibility levels).
The live wire set earns RUNG_2..RUNG_4. RUNG_1 / RUNG_5 are reserved end-stops (see the per-member comments), part of the public contract and pinned by an enum-value test — reserved, not dead.
WireResult
pydantic-model
¶
Bases: _Contract
One verification wire's outcome.
Note
status="gap" is distinct from "fail": it means the property
could not be verified because the backend does NOT expose the input
(a disclosed CAPABILITY gap, e.g. \(\kappa(J)\) is not surfaced by
spectrafit/lmfit/jax), not because a computed value was wrong. Like
"skipped", a "gap" does not cap the credibility rung; only a
genuine "fail" does (see runner._compute_rung).
Show JSON schema:
{
"additionalProperties": false,
"description": "One verification wire's outcome.\n\nNote:\n ``status=\"gap\"`` is distinct from ``\"fail\"``: it means the property\n could not be verified because the backend does NOT expose the input\n (a disclosed CAPABILITY gap, e.g. $\\kappa(J)$ is not surfaced by\n spectrafit/lmfit/jax), not because a computed value was wrong. Like\n ``\"skipped\"``, a ``\"gap\"`` does not cap the credibility rung; only a\n genuine ``\"fail\"`` does (see ``runner._compute_rung``).",
"properties": {
"wireId": {
"description": "Audit wire id: W1, W2a-W2d, or W3..W11 from the value-stream diagram.",
"title": "Wireid",
"type": "string"
},
"name": {
"description": "Short machine-readable wire name (e.g. `synth_invariants`).",
"title": "Name",
"type": "string"
},
"status": {
"description": "Wire outcome: `pass`, `warn`, or `fail` for a computed verdict; `skipped` when the underlying test never ran; `gap` for a disclosed capability gap (see the class Note).",
"enum": [
"pass",
"warn",
"fail",
"skipped",
"gap"
],
"title": "Status",
"type": "string"
},
"evidence": {
"description": "One-line evidence statement.",
"title": "Evidence",
"type": "string"
},
"details": {
"additionalProperties": {
"anyOf": [
{
"type": "number"
},
{
"type": "integer"
},
{
"type": "string"
},
{
"type": "boolean"
},
{
"type": "null"
}
]
},
"description": "Optional structured detail (counts, thresholds, sample sizes, ...) supporting `evidence`; empty when the one-line statement is self-sufficient.",
"title": "Details",
"type": "object"
}
},
"required": [
"wireId",
"name",
"status",
"evidence"
],
"title": "WireResult",
"type": "object"
}
Config:
extra:forbidalias_generator:to_camelpopulate_by_name:True
Fields:
-
wire_id(str) -
name(str) -
status(WireStatus) -
evidence(str) -
details(dict[str, float | int | str | bool | None])
wire_id
pydantic-field
¶
Audit wire id: W1, W2a-W2d, or W3..W11 from the value-stream diagram.
name
pydantic-field
¶
Short machine-readable wire name (e.g. synth_invariants).
status
pydantic-field
¶
Wire outcome: pass, warn, or fail for a computed verdict; skipped when the underlying test never ran; gap for a disclosed capability gap (see the class Note).
evidence
pydantic-field
¶
One-line evidence statement.
details
pydantic-field
¶
Optional structured detail (counts, thresholds, sample sizes, ...) supporting evidence; empty when the one-line statement is self-sufficient.
NistParam
pydantic-model
¶
Bases: _Contract
One parameter's certified-vs-fitted agreement for a NIST StRD dataset.
Show JSON schema:
{
"additionalProperties": false,
"description": "One parameter's certified-vs-fitted agreement for a NIST StRD dataset.",
"properties": {
"name": {
"description": "NIST parameter name, e.g. 'b1'.",
"title": "Name",
"type": "string"
},
"certified": {
"description": "NIST certified value (10+ sig figs).",
"title": "Certified",
"type": "number"
},
"fitted": {
"description": "Spectrafit recovered value.",
"title": "Fitted",
"type": "number"
},
"sigFigsAgreed": {
"description": "$-\\log_{10}\\left(|\\mathrm{fitted}-\\mathrm{certified}|/|\\mathrm{certified}|\\right)$; $\\infty$-capped for exact agreement.",
"title": "Sigfigsagreed",
"type": "number"
}
},
"required": [
"name",
"certified",
"fitted",
"sigFigsAgreed"
],
"title": "NistParam",
"type": "object"
}
Fields:
-
name(str) -
certified(float) -
fitted(float) -
sig_figs_agreed(float)
name
pydantic-field
¶
NIST parameter name, e.g. 'b1'.
certified
pydantic-field
¶
NIST certified value (10+ sig figs).
fitted
pydantic-field
¶
Spectrafit recovered value.
sig_figs_agreed
pydantic-field
¶
\(-\log_{10}\left(|\mathrm{fitted}-\mathrm{certified}|/|\mathrm{certified}|\right)\); \(\infty\)-capped for exact agreement.
NistDataset
pydantic-model
¶
Bases: _Contract
Per-dataset NIST StRD certified-value validation result.
Show JSON schema:
{
"$defs": {
"NistParam": {
"additionalProperties": false,
"description": "One parameter's certified-vs-fitted agreement for a NIST StRD dataset.",
"properties": {
"name": {
"description": "NIST parameter name, e.g. 'b1'.",
"title": "Name",
"type": "string"
},
"certified": {
"description": "NIST certified value (10+ sig figs).",
"title": "Certified",
"type": "number"
},
"fitted": {
"description": "Spectrafit recovered value.",
"title": "Fitted",
"type": "number"
},
"sigFigsAgreed": {
"description": "$-\\log_{10}\\left(|\\mathrm{fitted}-\\mathrm{certified}|/|\\mathrm{certified}|\\right)$; $\\infty$-capped for exact agreement.",
"title": "Sigfigsagreed",
"type": "number"
}
},
"required": [
"name",
"certified",
"fitted",
"sigFigsAgreed"
],
"title": "NistParam",
"type": "object"
}
},
"additionalProperties": false,
"description": "Per-dataset NIST StRD certified-value validation result.",
"properties": {
"name": {
"description": "StRD problem name, e.g. 'Gauss1'.",
"title": "Name",
"type": "string"
},
"model": {
"description": "Human-readable model description.",
"title": "Model",
"type": "string"
},
"nParams": {
"title": "Nparams",
"type": "integer"
},
"params": {
"items": {
"$ref": "#/$defs/NistParam"
},
"title": "Params",
"type": "array"
},
"minSigFigs": {
"description": "Worst (minimum) per-parameter sig-fig agreement.",
"title": "Minsigfigs",
"type": "number"
},
"passed": {
"description": "True iff min_sig_figs $\\ge$ the validation threshold.",
"title": "Passed",
"type": "boolean"
}
},
"required": [
"name",
"model",
"nParams",
"params",
"minSigFigs",
"passed"
],
"title": "NistDataset",
"type": "object"
}
Fields:
-
name(str) -
model(str) -
n_params(int) -
params(list[NistParam]) -
min_sig_figs(float) -
passed(bool)
NistValidation
pydantic-model
¶
Bases: _Contract
Aggregate NIST StRD certified-value validation (the W8 evidence block).
Independent external replication against NIST's extended-precision certified values — the evidence RUNG_5 was reserved for. Additive on TrustBlock.
Show JSON schema:
{
"$defs": {
"NistDataset": {
"additionalProperties": false,
"description": "Per-dataset NIST StRD certified-value validation result.",
"properties": {
"name": {
"description": "StRD problem name, e.g. 'Gauss1'.",
"title": "Name",
"type": "string"
},
"model": {
"description": "Human-readable model description.",
"title": "Model",
"type": "string"
},
"nParams": {
"title": "Nparams",
"type": "integer"
},
"params": {
"items": {
"$ref": "#/$defs/NistParam"
},
"title": "Params",
"type": "array"
},
"minSigFigs": {
"description": "Worst (minimum) per-parameter sig-fig agreement.",
"title": "Minsigfigs",
"type": "number"
},
"passed": {
"description": "True iff min_sig_figs $\\ge$ the validation threshold.",
"title": "Passed",
"type": "boolean"
}
},
"required": [
"name",
"model",
"nParams",
"params",
"minSigFigs",
"passed"
],
"title": "NistDataset",
"type": "object"
},
"NistParam": {
"additionalProperties": false,
"description": "One parameter's certified-vs-fitted agreement for a NIST StRD dataset.",
"properties": {
"name": {
"description": "NIST parameter name, e.g. 'b1'.",
"title": "Name",
"type": "string"
},
"certified": {
"description": "NIST certified value (10+ sig figs).",
"title": "Certified",
"type": "number"
},
"fitted": {
"description": "Spectrafit recovered value.",
"title": "Fitted",
"type": "number"
},
"sigFigsAgreed": {
"description": "$-\\log_{10}\\left(|\\mathrm{fitted}-\\mathrm{certified}|/|\\mathrm{certified}|\\right)$; $\\infty$-capped for exact agreement.",
"title": "Sigfigsagreed",
"type": "number"
}
},
"required": [
"name",
"certified",
"fitted",
"sigFigsAgreed"
],
"title": "NistParam",
"type": "object"
}
},
"additionalProperties": false,
"description": "Aggregate NIST StRD certified-value validation (the W8 evidence block).\n\nIndependent external replication against NIST's extended-precision certified\nvalues \u2014 the evidence RUNG_5 was reserved for. Additive on TrustBlock.",
"properties": {
"thresholdSigFigs": {
"description": "Required minimum significant-figure agreement.",
"title": "Thresholdsigfigs",
"type": "number"
},
"datasets": {
"items": {
"$ref": "#/$defs/NistDataset"
},
"title": "Datasets",
"type": "array"
},
"minSigFigs": {
"description": "Worst min_sig_figs across all datasets.",
"title": "Minsigfigs",
"type": "number"
},
"passed": {
"description": "True iff every dataset agrees to $\\ge$ threshold sig figs.",
"title": "Passed",
"type": "boolean"
},
"totalAvailable": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Size of the external NIST StRD nonlinear-regression universe (the denominator for 'N of M' coverage). Emitted by the validation builder so the UI never hardcodes the total. Additive \u2014 None for payloads written before this field existed.",
"title": "Totalavailable"
}
},
"required": [
"thresholdSigFigs",
"datasets",
"minSigFigs",
"passed"
],
"title": "NistValidation",
"type": "object"
}
Fields:
-
threshold_sig_figs(float) -
datasets(list[NistDataset]) -
min_sig_figs(float) -
passed(bool) -
total_available(int | None)
threshold_sig_figs
pydantic-field
¶
Required minimum significant-figure agreement.
min_sig_figs
pydantic-field
¶
Worst min_sig_figs across all datasets.
passed
pydantic-field
¶
True iff every dataset agrees to \(\ge\) threshold sig figs.
total_available = None
pydantic-field
¶
Size of the external NIST StRD nonlinear-regression universe (the denominator for 'N of M' coverage). Emitted by the validation builder so the UI never hardcodes the total. Additive — None for payloads written before this field existed.
TrustBlock
pydantic-model
¶
Bases: _Contract
Aggregate trust evidence attached to a BenchReport.
Show JSON schema:
{
"$defs": {
"CredibilityRung": {
"description": "V&V maturity ladder (inspired by ASME V&V credibility levels).\n\nThe live wire set earns RUNG_2..RUNG_4. RUNG_1 / RUNG_5 are reserved\nend-stops (see the per-member comments), part of the public contract and\npinned by an enum-value test \u2014 reserved, not dead.",
"enum": [
1,
2,
3,
4,
5
],
"title": "CredibilityRung",
"type": "integer"
},
"NistDataset": {
"additionalProperties": false,
"description": "Per-dataset NIST StRD certified-value validation result.",
"properties": {
"name": {
"description": "StRD problem name, e.g. 'Gauss1'.",
"title": "Name",
"type": "string"
},
"model": {
"description": "Human-readable model description.",
"title": "Model",
"type": "string"
},
"nParams": {
"title": "Nparams",
"type": "integer"
},
"params": {
"items": {
"$ref": "#/$defs/NistParam"
},
"title": "Params",
"type": "array"
},
"minSigFigs": {
"description": "Worst (minimum) per-parameter sig-fig agreement.",
"title": "Minsigfigs",
"type": "number"
},
"passed": {
"description": "True iff min_sig_figs $\\ge$ the validation threshold.",
"title": "Passed",
"type": "boolean"
}
},
"required": [
"name",
"model",
"nParams",
"params",
"minSigFigs",
"passed"
],
"title": "NistDataset",
"type": "object"
},
"NistParam": {
"additionalProperties": false,
"description": "One parameter's certified-vs-fitted agreement for a NIST StRD dataset.",
"properties": {
"name": {
"description": "NIST parameter name, e.g. 'b1'.",
"title": "Name",
"type": "string"
},
"certified": {
"description": "NIST certified value (10+ sig figs).",
"title": "Certified",
"type": "number"
},
"fitted": {
"description": "Spectrafit recovered value.",
"title": "Fitted",
"type": "number"
},
"sigFigsAgreed": {
"description": "$-\\log_{10}\\left(|\\mathrm{fitted}-\\mathrm{certified}|/|\\mathrm{certified}|\\right)$; $\\infty$-capped for exact agreement.",
"title": "Sigfigsagreed",
"type": "number"
}
},
"required": [
"name",
"certified",
"fitted",
"sigFigsAgreed"
],
"title": "NistParam",
"type": "object"
},
"NistValidation": {
"additionalProperties": false,
"description": "Aggregate NIST StRD certified-value validation (the W8 evidence block).\n\nIndependent external replication against NIST's extended-precision certified\nvalues \u2014 the evidence RUNG_5 was reserved for. Additive on TrustBlock.",
"properties": {
"thresholdSigFigs": {
"description": "Required minimum significant-figure agreement.",
"title": "Thresholdsigfigs",
"type": "number"
},
"datasets": {
"items": {
"$ref": "#/$defs/NistDataset"
},
"title": "Datasets",
"type": "array"
},
"minSigFigs": {
"description": "Worst min_sig_figs across all datasets.",
"title": "Minsigfigs",
"type": "number"
},
"passed": {
"description": "True iff every dataset agrees to $\\ge$ threshold sig figs.",
"title": "Passed",
"type": "boolean"
},
"totalAvailable": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Size of the external NIST StRD nonlinear-regression universe (the denominator for 'N of M' coverage). Emitted by the validation builder so the UI never hardcodes the total. Additive \u2014 None for payloads written before this field existed.",
"title": "Totalavailable"
}
},
"required": [
"thresholdSigFigs",
"datasets",
"minSigFigs",
"passed"
],
"title": "NistValidation",
"type": "object"
},
"WireResult": {
"additionalProperties": false,
"description": "One verification wire's outcome.\n\nNote:\n ``status=\"gap\"`` is distinct from ``\"fail\"``: it means the property\n could not be verified because the backend does NOT expose the input\n (a disclosed CAPABILITY gap, e.g. $\\kappa(J)$ is not surfaced by\n spectrafit/lmfit/jax), not because a computed value was wrong. Like\n ``\"skipped\"``, a ``\"gap\"`` does not cap the credibility rung; only a\n genuine ``\"fail\"`` does (see ``runner._compute_rung``).",
"properties": {
"wireId": {
"description": "Audit wire id: W1, W2a-W2d, or W3..W11 from the value-stream diagram.",
"title": "Wireid",
"type": "string"
},
"name": {
"description": "Short machine-readable wire name (e.g. `synth_invariants`).",
"title": "Name",
"type": "string"
},
"status": {
"description": "Wire outcome: `pass`, `warn`, or `fail` for a computed verdict; `skipped` when the underlying test never ran; `gap` for a disclosed capability gap (see the class Note).",
"enum": [
"pass",
"warn",
"fail",
"skipped",
"gap"
],
"title": "Status",
"type": "string"
},
"evidence": {
"description": "One-line evidence statement.",
"title": "Evidence",
"type": "string"
},
"details": {
"additionalProperties": {
"anyOf": [
{
"type": "number"
},
{
"type": "integer"
},
{
"type": "string"
},
{
"type": "boolean"
},
{
"type": "null"
}
]
},
"description": "Optional structured detail (counts, thresholds, sample sizes, ...) supporting `evidence`; empty when the one-line statement is self-sufficient.",
"title": "Details",
"type": "object"
}
},
"required": [
"wireId",
"name",
"status",
"evidence"
],
"title": "WireResult",
"type": "object"
}
},
"additionalProperties": false,
"description": "Aggregate trust evidence attached to a BenchReport.",
"properties": {
"rung": {
"$ref": "#/$defs/CredibilityRung",
"description": "Aggregate V&V credibility rung (see `CredibilityRung`), capped by the worst genuine `fail` among `wires` \u2014 a `gap` or `skipped` wire never lowers it."
},
"wires": {
"description": "Every verification wire's outcome making up this ledger.",
"items": {
"$ref": "#/$defs/WireResult"
},
"title": "Wires",
"type": "array"
},
"nClaimsAudited": {
"description": "Number of report claims this audit run actually checked.",
"title": "Nclaimsaudited",
"type": "integer"
},
"nClaimsTotal": {
"description": "Total number of claims the report makes, whether or not they were audited this run.",
"title": "Nclaimstotal",
"type": "integer"
},
"nistValidation": {
"anyOf": [
{
"$ref": "#/$defs/NistValidation"
},
{
"type": "null"
}
],
"default": null,
"description": "NIST StRD certified-value validation (W8). Additive \u2014 Pydantic fills None for payloads that predate the A7 external-validation wire."
}
},
"required": [
"rung",
"wires",
"nClaimsAudited",
"nClaimsTotal"
],
"title": "TrustBlock",
"type": "object"
}
Fields:
-
rung(CredibilityRung) -
wires(list[WireResult]) -
n_claims_audited(int) -
n_claims_total(int) -
nist_validation(NistValidation | None)
Validators:
-
_rung5_requires_nist_and_inference
rung
pydantic-field
¶
Aggregate V&V credibility rung (see CredibilityRung), capped by the worst genuine fail among wires — a gap or skipped wire never lowers it.
wires
pydantic-field
¶
Every verification wire's outcome making up this ledger.
n_claims_audited
pydantic-field
¶
Number of report claims this audit run actually checked.
n_claims_total
pydantic-field
¶
Total number of claims the report makes, whether or not they were audited this run.
nist_validation = None
pydantic-field
¶
NIST StRD certified-value validation (W8). Additive — Pydantic fills None for payloads that predate the A7 external-validation wire.
TrustLedger
pydantic-model
¶
Bases: BaseModel
Persisted ledger written to trust.json.
Show JSON schema:
{
"$defs": {
"CredibilityRung": {
"description": "V&V maturity ladder (inspired by ASME V&V credibility levels).\n\nThe live wire set earns RUNG_2..RUNG_4. RUNG_1 / RUNG_5 are reserved\nend-stops (see the per-member comments), part of the public contract and\npinned by an enum-value test \u2014 reserved, not dead.",
"enum": [
1,
2,
3,
4,
5
],
"title": "CredibilityRung",
"type": "integer"
},
"NistDataset": {
"additionalProperties": false,
"description": "Per-dataset NIST StRD certified-value validation result.",
"properties": {
"name": {
"description": "StRD problem name, e.g. 'Gauss1'.",
"title": "Name",
"type": "string"
},
"model": {
"description": "Human-readable model description.",
"title": "Model",
"type": "string"
},
"nParams": {
"title": "Nparams",
"type": "integer"
},
"params": {
"items": {
"$ref": "#/$defs/NistParam"
},
"title": "Params",
"type": "array"
},
"minSigFigs": {
"description": "Worst (minimum) per-parameter sig-fig agreement.",
"title": "Minsigfigs",
"type": "number"
},
"passed": {
"description": "True iff min_sig_figs $\\ge$ the validation threshold.",
"title": "Passed",
"type": "boolean"
}
},
"required": [
"name",
"model",
"nParams",
"params",
"minSigFigs",
"passed"
],
"title": "NistDataset",
"type": "object"
},
"NistParam": {
"additionalProperties": false,
"description": "One parameter's certified-vs-fitted agreement for a NIST StRD dataset.",
"properties": {
"name": {
"description": "NIST parameter name, e.g. 'b1'.",
"title": "Name",
"type": "string"
},
"certified": {
"description": "NIST certified value (10+ sig figs).",
"title": "Certified",
"type": "number"
},
"fitted": {
"description": "Spectrafit recovered value.",
"title": "Fitted",
"type": "number"
},
"sigFigsAgreed": {
"description": "$-\\log_{10}\\left(|\\mathrm{fitted}-\\mathrm{certified}|/|\\mathrm{certified}|\\right)$; $\\infty$-capped for exact agreement.",
"title": "Sigfigsagreed",
"type": "number"
}
},
"required": [
"name",
"certified",
"fitted",
"sigFigsAgreed"
],
"title": "NistParam",
"type": "object"
},
"NistValidation": {
"additionalProperties": false,
"description": "Aggregate NIST StRD certified-value validation (the W8 evidence block).\n\nIndependent external replication against NIST's extended-precision certified\nvalues \u2014 the evidence RUNG_5 was reserved for. Additive on TrustBlock.",
"properties": {
"thresholdSigFigs": {
"description": "Required minimum significant-figure agreement.",
"title": "Thresholdsigfigs",
"type": "number"
},
"datasets": {
"items": {
"$ref": "#/$defs/NistDataset"
},
"title": "Datasets",
"type": "array"
},
"minSigFigs": {
"description": "Worst min_sig_figs across all datasets.",
"title": "Minsigfigs",
"type": "number"
},
"passed": {
"description": "True iff every dataset agrees to $\\ge$ threshold sig figs.",
"title": "Passed",
"type": "boolean"
},
"totalAvailable": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Size of the external NIST StRD nonlinear-regression universe (the denominator for 'N of M' coverage). Emitted by the validation builder so the UI never hardcodes the total. Additive \u2014 None for payloads written before this field existed.",
"title": "Totalavailable"
}
},
"required": [
"thresholdSigFigs",
"datasets",
"minSigFigs",
"passed"
],
"title": "NistValidation",
"type": "object"
},
"TrustBlock": {
"additionalProperties": false,
"description": "Aggregate trust evidence attached to a BenchReport.",
"properties": {
"rung": {
"$ref": "#/$defs/CredibilityRung",
"description": "Aggregate V&V credibility rung (see `CredibilityRung`), capped by the worst genuine `fail` among `wires` \u2014 a `gap` or `skipped` wire never lowers it."
},
"wires": {
"description": "Every verification wire's outcome making up this ledger.",
"items": {
"$ref": "#/$defs/WireResult"
},
"title": "Wires",
"type": "array"
},
"nClaimsAudited": {
"description": "Number of report claims this audit run actually checked.",
"title": "Nclaimsaudited",
"type": "integer"
},
"nClaimsTotal": {
"description": "Total number of claims the report makes, whether or not they were audited this run.",
"title": "Nclaimstotal",
"type": "integer"
},
"nistValidation": {
"anyOf": [
{
"$ref": "#/$defs/NistValidation"
},
{
"type": "null"
}
],
"default": null,
"description": "NIST StRD certified-value validation (W8). Additive \u2014 Pydantic fills None for payloads that predate the A7 external-validation wire."
}
},
"required": [
"rung",
"wires",
"nClaimsAudited",
"nClaimsTotal"
],
"title": "TrustBlock",
"type": "object"
},
"WireResult": {
"additionalProperties": false,
"description": "One verification wire's outcome.\n\nNote:\n ``status=\"gap\"`` is distinct from ``\"fail\"``: it means the property\n could not be verified because the backend does NOT expose the input\n (a disclosed CAPABILITY gap, e.g. $\\kappa(J)$ is not surfaced by\n spectrafit/lmfit/jax), not because a computed value was wrong. Like\n ``\"skipped\"``, a ``\"gap\"`` does not cap the credibility rung; only a\n genuine ``\"fail\"`` does (see ``runner._compute_rung``).",
"properties": {
"wireId": {
"description": "Audit wire id: W1, W2a-W2d, or W3..W11 from the value-stream diagram.",
"title": "Wireid",
"type": "string"
},
"name": {
"description": "Short machine-readable wire name (e.g. `synth_invariants`).",
"title": "Name",
"type": "string"
},
"status": {
"description": "Wire outcome: `pass`, `warn`, or `fail` for a computed verdict; `skipped` when the underlying test never ran; `gap` for a disclosed capability gap (see the class Note).",
"enum": [
"pass",
"warn",
"fail",
"skipped",
"gap"
],
"title": "Status",
"type": "string"
},
"evidence": {
"description": "One-line evidence statement.",
"title": "Evidence",
"type": "string"
},
"details": {
"additionalProperties": {
"anyOf": [
{
"type": "number"
},
{
"type": "integer"
},
{
"type": "string"
},
{
"type": "boolean"
},
{
"type": "null"
}
]
},
"description": "Optional structured detail (counts, thresholds, sample sizes, ...) supporting `evidence`; empty when the one-line statement is self-sufficient.",
"title": "Details",
"type": "object"
}
},
"required": [
"wireId",
"name",
"status",
"evidence"
],
"title": "WireResult",
"type": "object"
}
},
"additionalProperties": false,
"description": "Persisted ledger written to ``trust.json``.",
"properties": {
"schema_version": {
"default": "1.0",
"description": "Ledger schema version, independent of the BenchReport schema.",
"title": "Schema Version",
"type": "string"
},
"run_id": {
"description": "The benchmark run id this ledger belongs to.",
"title": "Run Id",
"type": "string"
},
"block": {
"$ref": "#/$defs/TrustBlock",
"description": "The aggregate trust evidence itself."
}
},
"required": [
"run_id",
"block"
],
"title": "TrustLedger",
"type": "object"
}
Config:
extra:forbid
Fields:
-
schema_version(str) -
run_id(str) -
block(TrustBlock)
See also¶
- Related explanation: NIST StRD Validation — what W8 checks.
- Reference: Python: benchmark harness —
the full internal API surface, including every W-wire signature this page
only frames. NIST StRD reference — its full
agreement table. Python: benchmark API —
the
/api/v1/trustendpoint that serves a run'sTrustBlockto the web UI. - Glossary: Glossary — definitions for this page's
project-specific terms (
StRD,NIST,Jacobian).