Skip to content

Commit b42ca64

Browse files
docs: Proven/Witnessed/Trusted ladder; correct believe_me and annotation claims (#344)
## Summary Adds a Proven / Witnessed / Trusted ladder to the README and site, and corrects safety claims that the code does not back: "zero believe_me" (the enforced budget is 4 sanctioned axioms), "formally verified coordination ABI", and four tool annotations. The ladder also says plainly that the Idris core does not typecheck today, because of a duplicate `allTake` and a CI job that never reaches Idris. That is tracked in #343, which this PR does **not** fix. ## Type of change - [x] Documentation - [x] Small code change: four MCP tool annotation values in `mcp-bridge/lib/tools.js` ## 📌 New pins Head SHA: **e7474849e54da49f64b02131c42968e49416b2cd**. No action, lockfile, container or `actions.lock` pins are added or changed. ## Changes - **README.adoc + regenerated README.md:** new "What is proven" section with the three-column ladder. The Features and Security bullets are rescoped (it is a safety and dispatch ABI model, not a "coordination ABI"). The PROOF-NEEDS link now points at the `.adoc`. - **site/index.html:** the "Verified" card becomes a compact ladder that links to the README section. - **About 20 docs, Justfile comments, `.claude/CLAUDE.md`:** "zero believe_me" and "5 axioms" become 4 sanctioned axioms in `SafetyLemmas.idr`. Rules for cartridge authors ("your ABI must have zero believe_me") are unchanged. - **PROOF-NEEDS.adoc:** the count history now reads 5 → 4 (2026-06-24), broken `docs/proof-debt.md` links are fixed, and a new "Model-to-code obligations" section covers restoring the proof gate, the 13 unimplemented `libbozsafety` bindings, and effect-typed manifests. - **verification/proofs/README.adoc:** 5 → 4 axioms, and `charEqSym` is marked as discharged. - **src/abi/Boj/SafeHTTP.idr:** a comment only. "Zero believe_me" becomes "none in this module; relies on the 4 SafetyLemmas axioms". - **mcp-bridge/lib/tools.js:** - `boj_browser_read_page` and `boj_browser_screenshot` are now `readOnlyHint:false`, a conservative label until effect-typed manifests land; - `boj_github_graphql` (accepts mutations) and `boj_cartridge_invoke` (reaches any cartridge) are now `destructiveHint:true`. ## RSR Quality Checklist ### Required - [x] Tests pass: `bun test mcp-bridge/tests/` reported 52 pass, 0 fail. - [ ] Code is formatted: not applicable. The only code change is four boolean literals plus two description strings, in the file's existing style. - [x] Linter is clean: no new code paths. The repo's pre-commit hooks passed on commit. - [x] No banned language patterns: no new files in any language. - [x] No `unsafe` blocks without `// SAFETY:` comments: none touched. - [x] No banned functions: none added. Text that mentions `believe_me` documents the existing 4 axioms. `bash scripts/check-trusted-base.sh` reported "OK … 4 sanctioned class-(J) axioms". - [x] SPDX license headers present: no new files, and existing headers are unchanged. - [x] No secrets, credentials or `.env` files included. ### As Applicable - [ ] `.machine_readable/*.a2ml`: deliberately not touched. `0-AI-MANIFEST.a2ml` and `META.a2ml` also say "zero believe_me" and are left for the owner's decision. - [x] Documentation updated for user-facing changes. - [ ] `TOPOLOGY.md`: not applicable, no architecture change. - [ ] CHANGELOG: not updated; docs-only, no release. - [ ] New dependencies: none. - [ ] ABI/FFI changes validated: not applicable, no ABI or FFI change (one `.idr` comment only). ## Testing - `bun test mcp-bridge/tests/` reported 52 pass, 0 fail. - README derivation was reproduced locally with the pinned toolchain (pandoc 3.10, asciidoctor 2.0.26). As a control, it first reproduced the committed `README.md` on `main` byte-for-byte after normalisation. Then the regenerated file was committed. `readme-vocab-gate.sh` (standards@84355587) reported 98.7% at a 98% floor; the base was 98.4%. - `bash scripts/check-trusted-base.sh` reported OK with 4 axioms. - `cd src/abi && idris2 --typecheck boj.ipkg` **fails**, and fails the same way on `main`: `allTake is already defined`. The `.idr` change is a comment. See #343. ### Red check deferral - `Idris2 type-check (core + all cartridge ABIs)` is expected to be red: this PR touches `src/abi/` and `verification/`, which triggers the job, and the job fails on `main` too (empty asdf version, duplicate `allTake`). It is not a required check. Deferred to #343. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01Ge6k9wanwVdYJWBrnwjPxf --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
1 parent d836a63 commit b42ca64

21 files changed

Lines changed: 166 additions & 50 deletions

‎.claude/CLAUDE.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ exceptions:
3535

3636
| Layer | Language | Role |
3737
|---|---|---|
38-
| **ABI** | **Idris2** | Formally verified contract — dependent-type proofs, state machine or exposure-gate invariants, `%default total`, zero `believe_me`/`postulate`/`assert_total` in the trusted core. |
38+
| **ABI** | **Idris2** | Formally verified contract — dependent-type proofs, state machine or exposure-gate invariants, `%default total`, no `postulate`/`assert_total`, and `believe_me` only in the 4 documented `SafetyLemmas` axioms (core) — zero in cartridge ABIs. |
3939
| **FFI** | **Zig** | C-ABI implementation (ADR-0006 five-symbol pattern: `boj_cartridge_{init,deinit,name,version,invoke}`). |
4040
| **Adapter** | **Zig** | The base-level API/service surface — see below. |
4141

‎Justfile‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -415,7 +415,7 @@ fmt-check:
415415
@echo "Checking Zig formatting..."
416416
find ffi/ -name '*.zig' -exec zig fmt --check {} +
417417

418-
# Lint — verify zero believe_me + type-check all ABI files
418+
# Lint — trusted-base audit (only the 4 sanctioned axioms) + type-check all ABI files
419419
lint: verify-no-believe-me typecheck
420420
@echo "Lint passed!"
421421

@@ -434,15 +434,15 @@ typecheck:
434434
# Verify the trusted base: no unsound constructs beyond the sanctioned axioms.
435435
#
436436
# The estate trusted-base reduction policy (hyperpolymath/standards#203) sanctions
437-
# EXACTLY the 5 class-(J) axioms in src/abi/Boj/SafetyLemmas.idr — opaque Char/String
437+
# EXACTLY the 4 class-(J) axioms in src/abi/Boj/SafetyLemmas.idr — opaque Char/String
438438
# primitives, %unsafe-tagged and externally validated (see PROOF-NEEDS.md and
439439
# docs/proof-debt.md). Everything else must be a genuine constructive proof.
440440
# This recipe fails on any believe_me/assert_* outside that module, and also
441441
# fails if the audited axiom count drifts from 5 (keep the docs in sync).
442442
verify-no-believe-me:
443443
bash scripts/check-trusted-base.sh
444444

445-
# Full verification suite: type-check + zero believe_me + build + test
445+
# Full verification suite: type-check + trusted-base audit + build + test
446446
verify: typecheck verify-no-believe-me build test
447447
@echo "Full verification passed!"
448448

@@ -616,7 +616,7 @@ deps-audit:
616616
echo "Running Zig build + test audit on catalogue..."
617617
cd ffi/zig && zig build test
618618
cd "$OLDPWD"
619-
# Verify zero believe_me (formal verification soundness audit)
619+
# Trusted-base audit (formal verification soundness audit)
620620
just verify-no-believe-me
621621
# Supplementary scanners (if available)
622622
if command -v panic-attack >/dev/null 2>&1; then
@@ -1410,7 +1410,7 @@ tour:
14101410
echo "Quick commands:"
14111411
echo " just run Start server (REST 7700, gRPC 7701, GraphQL 7702)"
14121412
echo " just test Run all FFI tests"
1413-
echo " just verify Full verification (typecheck + zero believe_me)"
1413+
echo " just verify Full verification (typecheck + trusted-base audit)"
14141414
echo " just matrix Show cartridge capability matrix"
14151415
echo " just test-smoke Quick smoke test"
14161416
echo ""
@@ -1449,7 +1449,7 @@ help-me:
14491449
echo " just readiness Component Readiness Grade tests"
14501450
echo " just bench Run benchmarks"
14511451
echo " just integration End-to-end integration tests"
1452-
echo " just verify Full verification (typecheck + zero believe_me + build + test)"
1452+
echo " just verify Full verification (typecheck + trusted-base audit + build + test)"
14531453
echo " just typecheck Type-check all Idris2 ABIs"
14541454
echo " just verify-no-believe-me Scan for unsound constructs"
14551455
echo ""

‎PROOF-NEEDS.adoc‎

Lines changed: 27 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
== PROOF-NEEDS.md — boj-server
22

33
____
4-
*See also*: link:docs/proof-debt.md[`+docs/proof-debt.md+`] is the
4+
*See also*: link:docs/proof-debt.adoc[`+docs/proof-debt.adoc+`] is the
55
schema-conformant per-repo index under the estate
66
https://github.com/hyperpolymath/standards/blob/main/docs/TRUSTED-BASE-REDUCTION-POLICY.adoc[Trusted-Base
77
Reduction Policy] (standards#203, enforcement standards#211).
88
PROOF-NEEDS.md is the _strategic-goals_ narrative — full audit table,
99
classification rationale, and external-validation pointers.
10-
`+docs/proof-debt.md+` is the _machine-checked_ index that
10+
`+docs/proof-debt.adoc+` is the _machine-checked_ index that
1111
`+scripts/check-trusted-base.sh+` greps. Keep both in sync when the
1212
marker count in `+src/abi/Boj/SafetyLemmas.idr+` changes.
1313
____
@@ -51,7 +51,7 @@ run over nothing.
5151
*exactly 4* sanctioned class-(J) axioms in `+SafetyLemmas.idr+`, zero
5252
undocumented unsound constructs. (`+charEqSym+` was discharged
5353
2026-06-24, taking the count 5 → 4; `+EXPECTED_AXIOMS=4+` in the
54-
enforcing script is the source of truth, and `+docs/proof-debt.md+`
54+
enforcing script is the source of truth, and `+docs/proof-debt.adoc+`
5555
agrees.) Independently corroborated by a `+panic-attack assail+` scan
5656
(MPL-2.0, built from source), which flags the same `+believe_me+` sites
5757
as `+ProofDrift+` and nothing else proof-shaped.
@@ -114,7 +114,7 @@ historically.
114114
are documentation/comment mentions of the word (1 in SafeHTTP.idr line
115115
15, 1 in SafetyLemmas.idr line 9, 2 in
116116
cartridges/fleet-mcp/abi/FleetMcp/SafeFleet.idr lines 14 & 34) and are
117-
*not* axiom uses. The audited true count is 5.
117+
*not* axiom uses. The audited true count was 5; it is 4 since 2026-06-24.
118118
* *LOC*: ~5,400 (Elixir + Idris2)
119119
* *ABI layer*: Comprehensive dependent-type ABI
120120

@@ -323,3 +323,26 @@ validating `+prim__eqChar+` / `+prim__strToCharList+` /
323323
then citing that evidence here. This is a backend-assurance task, not a
324324
proof obligation — keep it tracked but do not expect a constructive
325325
proof.
326+
327+
=== Model-to-code obligations (added 2026-10-06)
328+
329+
The proofs above are about the Idris model. These obligations connect the
330+
model to the running server; README "What is proven" summarises where each
331+
claim sits today.
332+
333+
. *Restore the proof gate.* `idris2 --typecheck boj.ipkg` fails because
334+
`allTake` is defined twice in `SafetyLemmas.idr`; the `proofs.yml`
335+
typecheck job fails at `asdf install idris2 ""` and is path-skipped on
336+
most PRs. Delete the duplicate, pin the Idris2 version, remove the skip.
337+
. *Every bound foreign symbol exists (Obligation B).* Each
338+
`%foreign "C:<sym>,<lib>"` in `src/abi/Boj/` resolves to a symbol in a
339+
library `ffi/zig/build.zig` builds. Today 13 of the 17
340+
`boj_safety_*` bindings to `libbozsafety` have no implementation and the
341+
library is not a build target. Add a CI check (`nm` over the built
342+
artefact, with a planted-positive control) and implement or delete each
343+
binding.
344+
. *Effect-typed tool manifests (Obligation C).* Declare each MCP tool's
345+
effect once (`Read | Write | Delete | Exec`) in Idris, generate the
346+
`mcp-bridge/lib/tools.js` annotations from it with a CI drift check,
347+
have the dispatcher enforce it, and prove that a `Read` tool's dispatch
348+
targets contain no mutating action, with no new axioms.

‎README.adoc‎

Lines changed: 34 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@ ____
3434
* link:#transports[Transports]
3535
* link:#configuration[Configuration]
3636
* link:#security[Security]
37+
* link:#what-is-proven[What is proven]
3738
* link:#license[License]
3839
* link:++#contributing--links++[Contributing & links]
3940

@@ -49,7 +50,7 @@ ____
4950
* *Inspectable offline* — `boj++_++health`, `boj++_++menu`, `boj++_++cartridges`, and `boj++_++cartridge++_++info` answer from an offline manifest so clients can introspect the server without any backend running.
5051
* *MCP resources & prompts* — 7 `boj://` resources and reusable prompts (`audit-repo`, `convene-cluster`, `deploy-with-dns-ssl`, `summarize-channel`, `triage-issues`, `proof-status`).
5152
* *Hardened* — per-call rate limiting, size caps, prompt-injection detection with Unicode-confusable normalisation, and error sanitisation (paths, stack traces, and env vars stripped from responses).
52-
* *Formally verified core* — the coordination ABI is written in Idris2 with discharged proof obligations; remaining axioms are documented, not hidden.
53+
* *Formally verified ABI model* — an Idris2 safety and dispatch ABI (HTTP, CORS, API keys, WebSocket lifecycle, prompt injection, catalogue, dispatch, credential isolation), `%default total`, with four documented axioms and nothing else unsound. Proofs are about the Idris model; see link:#what-is-proven[What is proven] for where they stop.
5354

5455
'''''
5556

@@ -258,7 +259,7 @@ Key environment variables (full schema in link:glama.json[`glama.json`]):
258259
* *Error sanitisation* — responses strip filesystem paths, stack traces, and environment variables before they reach the client.
259260
* *HTTP safety* — `BOJ++_++HTTP++_++AUTH=none` is refused on any non-loopback bind; bearer auth is required for remote exposure.
260261
* *Credential isolation* — cartridge credentials are supplied per-cartridge (env vars or the `vault-mcp` broker), never embedded in tool definitions.
261-
* *Formal verification* — the coordination ABI safety layer is written in Idris2 with discharged proof obligations; remaining `believe++_++me` sites are isolated, documented axioms over the compiler's opaque `Char`/`String` primitives, tracked in link:PROOF-NEEDS.md[`PROOF-NEEDS.md`].
262+
* *Formal verification* — the Idris2 ABI safety layer has discharged proof obligations; the only `believe++_++me` sites are four documented axioms over the compiler's opaque `Char`/`String` primitives, tracked in link:PROOF-NEEDS.adoc[`PROOF-NEEDS.adoc`]. See link:#what-is-proven[What is proven] for the Proven / Witnessed / Trusted breakdown.
262263
* *Supply chain* — SHA-pinned GitHub Actions; coherence tests assert the advertised tool list matches the cartridge manifest so nothing is advertised-but-undispatched.
263264

264265
Run the coherence tests:
@@ -272,6 +273,37 @@ Report vulnerabilities per link:SECURITY.md[`SECURITY.md`].
272273

273274
'''''
274275

276+
== What is proven
277+
278+
Every safety claim BoJ makes sits in one of three bins. "Proven" always means _proven about a model_, so the claim is only as good as the match between that model and the running code. That is why the Witnessed column matters.
279+
280+
[cols="1,1,1",options="header"]
281+
|===
282+
|Proven — the compiler checks it |Witnessed — an artefact backs it |Trusted — relied on from outside
283+
284+
a|
285+
* *Status (2026-10-06): the core does not currently typecheck.* `SafetyLemmas.idr` defines `allTake` twice, and the CI typecheck job has not completed since at least 2026-09-21 (it fails while installing Idris2, and is path-skipped on most PRs). Tracked in link:https://github.com/hyperpolymath/boj-server/issues/343[#343]. Until that is fixed, read this column as "proven when last green", not "proven now".
286+
* The Idris2 ABI in `src/abi/Boj/` (17 modules, all `%default total`) covers catalogue and dispatch, HTTP/CORS/API-key/WebSocket/prompt-injection safety predicates, and the credential-isolation model.
287+
* `believe++_++me` appears only in *four* documented axioms over opaque `Char`/`String` primitives (`SafetyLemmas.idr`); CI (`scripts/check-trusted-base.sh`) pins that count and greps the rest of the Idris tree for `believe++_++me`, `assert++_++total`, `assert++_++smaller` and `idris++_++crash`. The grep has known gaps (a use followed by a `--` comment is skipped; `partial`, `covering` and holes are not scanned) and the job is path-filtered, so it does not run on every PR.
288+
* *Limit:* these proofs are about the Idris model. The model is only ever typechecked, never compiled or linked into the running server, and 13 of the 17 C safety checks it binds (`libbozsafety`) are not yet implemented.
289+
a|
290+
* Property tests (Elixir StreamData, `elixir/test/backend_assurance/`) of the behaviour each of the four axioms assumes, run against Elixir analogues of the Chez primitives (not the compiled Idris code); last executed and green 2026-10-06.
291+
* Zig FFI enum constants checked at compile time against a hand-kept mirror of the Idris values (the Idris side itself is not compared).
292+
* TLA+ specs of the JS worker, worker pool and invoker (`specs/elixir-harness/`), model-checked with TLC by hand (results recorded in its README), not in CI.
293+
* npm package published with provenance; SLSA level 3 provenance on release tarballs; container build attestation.
294+
* Coherence tests: the advertised tool list matches the dispatch table.
295+
a|
296+
* The JavaScript bridge (`mcp-bridge/`) and the Zig FFI: the proofs cover the model, not this code.
297+
* Tool annotations (`readOnlyHint`, `destructiveHint`, …): hand-written labels, not derived from types and not enforced at dispatch.
298+
* Postgres, Docker, cloud and forge APIs behaving as documented; cartridge backends you run yourself.
299+
* The Idris2 compiler, Zig, the Node/Deno/Bun runtime and the operating system.
300+
* The AI choosing the right tool. Prompt injection is limited by input hardening, not proven away.
301+
|===
302+
303+
Planned next steps that move items left (Trusted → Witnessed → Proven) are tracked in link:PROOF-NEEDS.adoc[`PROOF-NEEDS.adoc`]: link every bound C symbol and gate CI on it, and derive tool annotations from a typed effect declaration that the dispatcher enforces.
304+
305+
'''''
306+
275307
== License
276308

277309
* *Code* — link:LICENSE[MPL-2.0] (Mozilla Public License 2.0) — the license published to npm and detected by GitHub.

‎README.md‎

Lines changed: 49 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,8 @@
3131

3232
- [Security](#security)
3333

34+
- [What is proven](#what-is-proven)
35+
3436
- [License](#license)
3537

3638
- [Contributing & links](#contributing--links)
@@ -53,7 +55,7 @@
5355

5456
- **Hardened** — per-call rate limiting, size caps, prompt-injection detection with Unicode-confusable normalisation, and error sanitisation (paths, stack traces, and env vars stripped from responses).
5557

56-
- **Formally verified core** — the coordination ABI is written in Idris2 with discharged proof obligations; remaining axioms are documented, not hidden.
58+
- **Formally verified ABI model** — an Idris2 safety and dispatch ABI (HTTP, CORS, API keys, WebSocket lifecycle, prompt injection, catalogue, dispatch, credential isolation), `%default total`, with four documented axioms and nothing else unsound. Proofs are about the Idris model; see [What is proven](#what-is-proven) for where they stop.
5759

5860
# Install
5961

@@ -242,7 +244,7 @@ Key environment variables (full schema in [`glama.json`](glama.json)):
242244

243245
- **Credential isolation** — cartridge credentials are supplied per-cartridge (env vars or the `vault-mcp` broker), never embedded in tool definitions.
244246

245-
- **Formal verification** — the coordination ABI safety layer is written in Idris2 with discharged proof obligations; remaining `believe_me` sites are isolated, documented axioms over the compiler’s opaque `Char`/`String` primitives, tracked in [`PROOF-NEEDS.md`](PROOF-NEEDS.md).
247+
- **Formal verification** — the Idris2 ABI safety layer has discharged proof obligations; the only `believe_me` sites are four documented axioms over the compiler’s opaque `Char`/`String` primitives, tracked in [`PROOF-NEEDS.adoc`](PROOF-NEEDS.adoc). See [What is proven](#what-is-proven) for the Proven / Witnessed / Trusted breakdown.
246248

247249
- **Supply chain** — SHA-pinned GitHub Actions; coherence tests assert the advertised tool list matches the cartridge manifest so nothing is advertised-but-undispatched.
248250

@@ -254,6 +256,51 @@ node --test mcp-bridge/tests/
254256

255257
Report vulnerabilities per [`SECURITY.md`](SECURITY.md).
256258

259+
# What is proven
260+
261+
Every safety claim BoJ makes sits in one of three bins. "Proven" always means *proven about a model*, so the claim is only as good as the match between that model and the running code. That is why the Witnessed column matters.
262+
263+
<table>
264+
<colgroup>
265+
<col style="width: 33%" />
266+
<col style="width: 33%" />
267+
<col style="width: 33%" />
268+
</colgroup>
269+
<thead>
270+
<tr>
271+
<th style="text-align: left;">Proven — the compiler checks it</th>
272+
<th style="text-align: left;">Witnessed — an artefact backs it</th>
273+
<th style="text-align: left;">Trusted — relied on from outside</th>
274+
</tr>
275+
</thead>
276+
<tbody>
277+
<tr>
278+
<td style="text-align: left;"><ul>
279+
<li><p><strong>Status (2026-10-06): the core does not currently typecheck.</strong> <code>SafetyLemmas.idr</code> defines <code>allTake</code> twice, and the CI typecheck job has not completed since at least 2026-09-21 (it fails while installing Idris2, and is path-skipped on most PRs). Tracked in <a href="https://github.com/hyperpolymath/boj-server/issues/343">#343</a>. Until that is fixed, read this column as "proven when last green", not "proven now".</p></li>
280+
<li><p>The Idris2 ABI in <code>src/abi/Boj/</code> (17 modules, all <code>%default total</code>) covers catalogue and dispatch, HTTP/CORS/API-key/WebSocket/prompt-injection safety predicates, and the credential-isolation model.</p></li>
281+
<li><p><code>believe_me</code> appears only in <strong>four</strong> documented axioms over opaque <code>Char</code>/<code>String</code> primitives (<code>SafetyLemmas.idr</code>); CI (<code>scripts/check-trusted-base.sh</code>) pins that count and greps the rest of the Idris tree for <code>believe_me</code>, <code>assert_total</code>, <code>assert_smaller</code> and <code>idris_crash</code>. The grep has known gaps (a use followed by a <code>--</code> comment is skipped; <code>partial</code>, <code>covering</code> and holes are not scanned) and the job is path-filtered, so it does not run on every PR.</p></li>
282+
<li><p><strong>Limit:</strong> these proofs are about the Idris model. The model is only ever typechecked, never compiled or linked into the running server, and 13 of the 17 C safety checks it binds (<code>libbozsafety</code>) are not yet implemented.</p></li>
283+
</ul></td>
284+
<td style="text-align: left;"><ul>
285+
<li><p>Property tests (Elixir StreamData, <code>elixir/test/backend_assurance/</code>) of the behaviour each of the four axioms assumes, run against Elixir analogues of the Chez primitives (not the compiled Idris code); last executed and green 2026-10-06.</p></li>
286+
<li><p>Zig FFI enum constants checked at compile time against a hand-kept mirror of the Idris values (the Idris side itself is not compared).</p></li>
287+
<li><p>TLA+ specs of the JS worker, worker pool and invoker (<code>specs/elixir-harness/</code>), model-checked with TLC by hand (results recorded in its README), not in CI.</p></li>
288+
<li><p>npm package published with provenance; SLSA level 3 provenance on release tarballs; container build attestation.</p></li>
289+
<li><p>Coherence tests: the advertised tool list matches the dispatch table.</p></li>
290+
</ul></td>
291+
<td style="text-align: left;"><ul>
292+
<li><p>The JavaScript bridge (<code>mcp-bridge/</code>) and the Zig FFI: the proofs cover the model, not this code.</p></li>
293+
<li><p>Tool annotations (<code>readOnlyHint</code>, <code>destructiveHint</code>, …): hand-written labels, not derived from types and not enforced at dispatch.</p></li>
294+
<li><p>Postgres, Docker, cloud and forge APIs behaving as documented; cartridge backends you run yourself.</p></li>
295+
<li><p>The Idris2 compiler, Zig, the Node/Deno/Bun runtime and the operating system.</p></li>
296+
<li><p>The AI choosing the right tool. Prompt injection is limited by input hardening, not proven away.</p></li>
297+
</ul></td>
298+
</tr>
299+
</tbody>
300+
</table>
301+
302+
Planned next steps that move items left (Trusted → Witnessed → Proven) are tracked in [`PROOF-NEEDS.adoc`](PROOF-NEEDS.adoc): link every bound C symbol and gate CI on it, and derive tool annotations from a typed effect declaration that the dispatcher enforces.
303+
257304
# License
258305

259306
- **Code** — [MPL-2.0](LICENSE) (Mozilla Public License 2.0) — the license published to npm and detected by GitHub.

‎docs/RSR_OUTLINE.adoc‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ just typecheck
3838
# Run tests
3939
just test
4040
41-
# Full verification (zero believe_me + type-check + tests)
41+
# Full verification (trusted-base audit + type-check + tests)
4242
just verify
4343
----
4444

@@ -52,7 +52,7 @@ Every cartridge follows the ABI/FFI universal standard:
5252

5353
|**ABI**
5454
|Idris2
55-
|Formal proofs, `%default total`, zero `believe_me`
55+
|Formal proofs, `%default total`, `believe_me` only in 4 documented axioms
5656

5757
|**FFI**
5858
|Zig

‎docs/developer/README.adoc‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88

99
A cartridge is a swappable, formally verified capability module. It occupies one or more cells in the 2D matrix (protocol x domain) and follows the three-layer stack:
1010

11-
. *Idris2 ABI* — Type-safe interface with `%default total` and zero `believe_me`
11+
. *Idris2 ABI* — Type-safe interface with `%default total`; `believe_me` only in 4 documented core axioms
1212
. *Zig FFI* — C-compatible native execution
1313
. *zig Adapter* — REST + gRPC + GraphQL endpoints
1414

0 commit comments

Comments
 (0)