Grant Stellmacher
RegistryAEF

Attested Execution Framework

Where the series stands

Every number on this page is derived at build time from the repository's artifacts: the coverage declaration, the challenge record, the threat model source, and the version registry. Nothing here is hand-edited. Where this page and an artifact disagree, the artifact is authoritative and this page is a build defect.

Documents

10 published documents. Superseded versions stay live at permanent paths for citation.

Published AEF documents with current version and date
No.TitleVersionDateSuperseded
1000Charterv0.311 August 20262 kept
1001Terminologyv0.111 August 2026
1100Threat modelv0.211 August 20261 kept
1101The trust basev0.214 August 20261 kept
1200Verifier requirementsv0.214 August 20261 kept
1201Conformance and self-testv0.114 August 2026
1300Record structure and scope declarationv0.214 August 20261 kept
1301Approval and signature semanticsv0.114 August 2026
1400Sealing, time, and re-verificationv0.114 August 2026
1900Provenance findingsv0.114 August 2026

Verifier and suite

The reference verifier is aef-reference-verifier 0.4.0, written against 1200/0.2 with 1300/0.2, 1300/0.1, 1201/0.1, 1301/0.1, 1400/0.1 also applied. The suite version under AEF 1201 C10 is the digest of the coverage declaration as served:

sha-256:f851528b8d6e7e3acbaf8a711b9e20450ae38c0534136bd4f786265797ac07b9

Suite composition
Entries5133 pinned fixtures, 18 generated tests; under C5 only the pinned entries are fixtures
Required to fail24entries whose expected outcome is a failure
Checks2216 have a failing fixture counting all entries
Fatal-capable1515 have an isolating entry
Retired5expectations superseded by later rulings, each retired with its reason under C12

Coverage of AEF 1200 v0.2's 54 requirements, entry by entry, is in the browsable coverage declaration.

Threat dispositions

AEF 1100 v0.2 enumerates 23 threats. The dispositions below are parsed from the document's own text, concessions first, because the concessions are the content:

Threat counts by disposition
Conceded11no defense exists or is claimed
Conditional9defended only if a named mechanism exists
Out of scope2delegated to parties better placed
In scope1defended by the record as specified

AEF 1400 section 16 records 5 disposition changes as candidates for AEF 1100 v0.3. They are recorded, not applied, and this page reports them the same way:

Candidate disposition changes, recorded and not applied
ThreatNowCandidate
10.3 operator clockCONDITIONAL, unrealizableCONDITIONAL, realizable in part
10.4 seal-time delayCONCEDEDCONDITIONAL
7.3 scope amendmentCONDITIONAL, unrealizableCONDITIONAL, realizable
10.1 backward reachCONDITIONAL, half-unrealizableCONDITIONAL, realizable
R14 ordering (1300 §12)No observerCandidate observer

Open failures against AEF 1201

The coverage declaration records where the reference implementation currently fails the conformance document's own requirements. This list shrinks by fixing, never by rewording:

Reference implementation failures against AEF 1201
Req.Failure, as recorded
C518 of 51 entries regenerate their inputs each time the suite executes; the 33 pinned entries' options still include the wall clock, and two of the run-0001 entries consume the live repository as artifact root
C6five entries pin complete qualification sets; the remaining 46 do not
C7counting generated tests, 5 of 22 checks have no failing entry, two by design (anchor-ordering and algorithm-standing report and decide nothing); counting fixtures under C5, 12 of 22 have no failing fixture
C8counting all entries, every one of the 15 fatal-capable checks has an isolating entry; counting fixtures under C5, 7 of 15 lack an isolating fixture, all seven pre-dating AEF 1301
C10this file's binding of run-0001 pinned inputs remains incomplete: the artifact-root documents are bound only transitively through aer.json, and the trust base statement and options are not bound
C19the verifier carries no fixture subset and runs no self-test
C20no self-test failure behavior exists
C21verification results record no self-test digest or outcome

Challenge record

4 challenges filed, 4 resolved, none unresolved. Rulings: challenge-0001 adopted in part; challenge-0002 adopted; challenge-0003 adopted; challenge-0004 adopted. The full record, with each challenge's claim, observation, and ruling, is browsable here and served raw at challenge-record.json.

What blocks the first conformance claim

The coverage declaration states the claim's standing plainly:

None exists and none can honestly be made. AEF 1201 C1 requires a suite version, and this suite does not yet satisfy the requirements that make its version meaningful. AEF 1201 section 12 states this.

The blocking list is the failure list above, in requirement order. Each item is discharged by making the artifact satisfy the requirement, at which point it leaves this page by derivation:

  1. C5. 18 of 51 entries regenerate their inputs each time the suite executes; the 33 pinned entries' options still include the wall clock, and two of the run-0001 entries consume the live repository as artifact root
  2. C6. five entries pin complete qualification sets; the remaining 46 do not
  3. C7. counting generated tests, 5 of 22 checks have no failing entry, two by design (anchor-ordering and algorithm-standing report and decide nothing); counting fixtures under C5, 12 of 22 have no failing fixture
  4. C8. counting all entries, every one of the 15 fatal-capable checks has an isolating entry; counting fixtures under C5, 7 of 15 lack an isolating fixture, all seven pre-dating AEF 1301
  5. C10. this file's binding of run-0001 pinned inputs remains incomplete: the artifact-root documents are bound only transitively through aer.json, and the trust base statement and options are not bound
  6. C19. the verifier carries no fixture subset and runs no self-test
  7. C20. no self-test failure behavior exists
  8. C21. verification results record no self-test digest or outcome