Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,10 @@ jobs:
run: node --test interop/aae-psea-gate/verify.test.mjs interop/aae-psea-gate/reperform.test.mjs
- name: Verify the public verifier-forgery corpus (node:test)
run: node --test tests/verifier-forgery/forgery.test.mjs
- name: Verify executable AIPS-1 P3 public-comment lab
run: |
node --test standards/aips-1/p3-evidence-source-evaluation-v0/evaluate.selftest.mjs
node standards/aips-1/p3-evidence-source-evaluation-v0/generate-report.mjs --check
- name: Verify every remaining package suite (discovered, not listed)
# The step above still enumerates packages. That is the bug pattern that
# dropped 8 of 11 verify suites until 2026-07-02 and left eight whole
Expand Down
6 changes: 3 additions & 3 deletions AI_CONTEXT.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

> EMILIA is the authority control plane for autonomous work. The plain-language operating picture is a customer-owned authority toll booth at a configured protected boundary, where a human or institution defines a finite operating mandate and agents work unattended inside it. EMILIA Gate verifies the authority and evidence the owner requires for the exact action, reserves accepted authority before provider entry, admits or refuses the crossing, preserves executed or indeterminate outcomes, refuses blind replay, and returns an action-bound receipt packet. EMILIA Host is the private local deployment form of Gate for activated covered HTTP and MCP paths at a credential-owning provider boundary; the current surface is an HTTP local service alpha, HTTP and MCP SDK protection, and governed pilots. Native mandates and credentials from A2A, AP2, OAuth, and hardware-backed approval systems remain attributable to their issuers. EMILIA Protocol is the open Action Receipt Contract underneath Gate; EMILIA Approver captures device-bound exact-action human decisions when the mandate or local policy requires fresh human authority; EMILIA Assurance Plane defines scoped verification, re-performance, conformance-report, and deployment-evidence procedures without acting as an auditor or accredited certifier. The toll-booth metaphor describes the intended cross-stack contract, not current coverage or operation of a central global network.

Generated from repository evidence. Evidence snapshot: 2026-09-01T09:44:11.545Z. Input digest: sha256:58ef6ac4a77b5d5dbc19181b45e6f796b0a54a61aace98f77114fa91bcd7a2a8.
Generated from repository evidence. Evidence snapshot: 2026-09-02T00:56:07.055Z. Input digest: sha256:3e8f027d79f489d7ee1accb3695b6901b33f0f9a533299e8f457f17726c4a0c6.
Do not edit this file directly. Source: [docs/ai/context-source.v1.json](docs/ai/context-source.v1.json). Freshness check: `npm run check:llm-context`.

## Read This First
Expand All @@ -15,10 +15,10 @@ When this file conflicts with a quantitative claim elsewhere, use the machine-re

## Current Evidence Snapshot

- Automated tests: 10,609 cases across 658 files; all platform-applicable cases must pass; platform-specific cases may skip.
- Automated tests: 10,622 cases across 661 files; all platform-applicable cases must pass; platform-specific cases may skip.
- Cross-language conformance: 21 suites, 332 current vectors, 3 same-team ports (JavaScript, Python, Go). This is consistency evidence, not implementation independence.
- External Rust interoperability: pass on the time-pinned 164-vector set evaluated 2026-07-11; the current bundle has 332. The same pinned implementation passes 359 hostility cases. Strict clean-room construction acceptance: false.
- Security case: 35 executable claims, 259 evidence files, execution passed; bundle sha256:947a0f8612dcc9a67520637a100d9ca3137193d5db78b882e3bbf98b82528880.
- Security case: 35 executable claims, 259 evidence files, execution passed; bundle sha256:66c3b1d0a7bcde8d1aa627c75c0e1b735480973758f9ee196ece8f1de63bb58e.
- Core formal inventory: 26 TLA+ invariants, 35 Alloy facts, 32 Alloy assertions. The selected-scenario models are reported separately below; formal scope and exclusions remain claim-specific.
- Selected model/runtime scenario conformance: 78 content-addressed scenarios across 14 bounded models and 21 public claims; 51 negative controls pair a formal counterexample with a safe-runtime refusal. They do not mutate the runtime implementation. Boundary: selected model/runtime scenarios under explicit projection relations; not a mechanized implementation refinement proof.
- Formal evidence taxonomy: 2 claims with verified formal obligations; 21 with bounded runtime-traced evidence; 1 with bounded formal evidence but no governed runtime bridge; 0 with partial symbolic coverage; 11 with executable or operational evidence only.
Expand Down
8 changes: 4 additions & 4 deletions lib/proof-stats.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
{
"generatedAt": "2026-09-01T09:44:11.545Z",
"generatedAt": "2026-09-02T00:56:07.055Z",
"tests": {
"total": 10609,
"files": 658,
"total": 10622,
"files": 661,
"policy": "all platform-applicable cases must pass; platform-specific cases may skip"
},
"tla": {
Expand Down Expand Up @@ -105,7 +105,7 @@
"status": "passed",
"claims": 35,
"evidenceFiles": 259,
"evidenceBundleSha256": "947a0f8612dcc9a67520637a100d9ca3137193d5db78b882e3bbf98b82528880"
"evidenceBundleSha256": "66c3b1d0a7bcde8d1aa627c75c0e1b735480973758f9ee196ece8f1de63bb58e"
},
"conformance": {
"suites": 21,
Expand Down
14 changes: 7 additions & 7 deletions public/.well-known/emilia-context.json
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
{
"@version": "EMILIA-REPO-CONTEXT-v1",
"evidence_snapshot_at": "2026-09-01T09:44:11.545Z",
"evidence_snapshot_at": "2026-09-02T00:56:07.055Z",
"provenance": {
"generator": "scripts/generate-llm-context.mts",
"input_digest_sha256": "58ef6ac4a77b5d5dbc19181b45e6f796b0a54a61aace98f77114fa91bcd7a2a8",
"input_digest_sha256": "3e8f027d79f489d7ee1accb3695b6901b33f0f9a533299e8f457f17726c4a0c6",
"generated_from": [
{
"path": "docs/ai/context-source.v1.json",
Expand All @@ -17,7 +17,7 @@
},
{
"path": "lib/proof-stats.json",
"sha256": "cab74e79ac95cff9d2747e038ba4d65fc7a9340dbab3e1dd24852592030c063e",
"sha256": "944ebd9a99a59e77ed8d7892affc0f91feaa93550b98868594250d1613747416",
"bytes": 4299
},
{
Expand All @@ -37,7 +37,7 @@
},
{
"path": "security/security-case.json",
"sha256": "c068ea00b3d264f6d2d9cdc7883c7f9302c4008529c2d1190cfabafd5c1ee455",
"sha256": "da6a51f0253eaf494785b3f1eeef778da75f5e1793b50d80d145ae60242bbe57",
"bytes": 386020
},
{
Expand Down Expand Up @@ -307,8 +307,8 @@
],
"current_evidence": {
"automated_tests": {
"total": 10609,
"files": 658,
"total": 10622,
"files": 661,
"policy": "all platform-applicable cases must pass; platform-specific cases may skip"
},
"cross_language_conformance": {
Expand Down Expand Up @@ -419,7 +419,7 @@
"status": "passed",
"claims": 35,
"evidence_files": 259,
"evidence_bundle_sha256": "947a0f8612dcc9a67520637a100d9ca3137193d5db78b882e3bbf98b82528880"
"evidence_bundle_sha256": "66c3b1d0a7bcde8d1aa627c75c0e1b735480973758f9ee196ece8f1de63bb58e"
},
"caid": {
"core_vectors": 48,
Expand Down
6 changes: 3 additions & 3 deletions public/llms-full.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

> EMILIA is the authority control plane for autonomous work. The plain-language operating picture is a customer-owned authority toll booth at a configured protected boundary, where a human or institution defines a finite operating mandate and agents work unattended inside it. EMILIA Gate verifies the authority and evidence the owner requires for the exact action, reserves accepted authority before provider entry, admits or refuses the crossing, preserves executed or indeterminate outcomes, refuses blind replay, and returns an action-bound receipt packet. EMILIA Host is the private local deployment form of Gate for activated covered HTTP and MCP paths at a credential-owning provider boundary; the current surface is an HTTP local service alpha, HTTP and MCP SDK protection, and governed pilots. Native mandates and credentials from A2A, AP2, OAuth, and hardware-backed approval systems remain attributable to their issuers. EMILIA Protocol is the open Action Receipt Contract underneath Gate; EMILIA Approver captures device-bound exact-action human decisions when the mandate or local policy requires fresh human authority; EMILIA Assurance Plane defines scoped verification, re-performance, conformance-report, and deployment-evidence procedures without acting as an auditor or accredited certifier. The toll-booth metaphor describes the intended cross-stack contract, not current coverage or operation of a central global network.

Generated from repository evidence. Evidence snapshot: 2026-09-01T09:44:11.545Z. Input digest: sha256:58ef6ac4a77b5d5dbc19181b45e6f796b0a54a61aace98f77114fa91bcd7a2a8.
Generated from repository evidence. Evidence snapshot: 2026-09-02T00:56:07.055Z. Input digest: sha256:3e8f027d79f489d7ee1accb3695b6901b33f0f9a533299e8f457f17726c4a0c6.
Do not edit this file directly. Source: [docs/ai/context-source.v1.json](https://github.com/emiliaprotocol/emilia-protocol/blob/main/docs/ai/context-source.v1.json). Freshness check: `npm run check:llm-context`.

## Read This First
Expand All @@ -15,10 +15,10 @@ When this file conflicts with a quantitative claim elsewhere, use the machine-re

## Current Evidence Snapshot

- Automated tests: 10,609 cases across 658 files; all platform-applicable cases must pass; platform-specific cases may skip.
- Automated tests: 10,622 cases across 661 files; all platform-applicable cases must pass; platform-specific cases may skip.
- Cross-language conformance: 21 suites, 332 current vectors, 3 same-team ports (JavaScript, Python, Go). This is consistency evidence, not implementation independence.
- External Rust interoperability: pass on the time-pinned 164-vector set evaluated 2026-07-11; the current bundle has 332. The same pinned implementation passes 359 hostility cases. Strict clean-room construction acceptance: false.
- Security case: 35 executable claims, 259 evidence files, execution passed; bundle sha256:947a0f8612dcc9a67520637a100d9ca3137193d5db78b882e3bbf98b82528880.
- Security case: 35 executable claims, 259 evidence files, execution passed; bundle sha256:66c3b1d0a7bcde8d1aa627c75c0e1b735480973758f9ee196ece8f1de63bb58e.
- Core formal inventory: 26 TLA+ invariants, 35 Alloy facts, 32 Alloy assertions. The selected-scenario models are reported separately below; formal scope and exclusions remain claim-specific.
- Selected model/runtime scenario conformance: 78 content-addressed scenarios across 14 bounded models and 21 public claims; 51 negative controls pair a formal counterexample with a safe-runtime refusal. They do not mutate the runtime implementation. Boundary: selected model/runtime scenarios under explicit projection relations; not a mechanized implementation refinement proof.
- Formal evidence taxonomy: 2 claims with verified formal obligations; 21 with bounded runtime-traced evidence; 1 with bounded formal evidence but no governed runtime bridge; 0 with partial symbolic coverage; 11 with executable or operational evidence only.
Expand Down
4 changes: 2 additions & 2 deletions public/llms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,13 @@

> EMILIA is the authority control plane for autonomous work. The plain-language operating picture is a customer-owned authority toll booth at a configured protected boundary, where a human or institution defines a finite operating mandate and agents work unattended inside it. EMILIA Gate verifies the authority and evidence the owner requires for the exact action, reserves accepted authority before provider entry, admits or refuses the crossing, preserves executed or indeterminate outcomes, refuses blind replay, and returns an action-bound receipt packet. EMILIA Host is the private local deployment form of Gate for activated covered HTTP and MCP paths at a credential-owning provider boundary; the current surface is an HTTP local service alpha, HTTP and MCP SDK protection, and governed pilots. Native mandates and credentials from A2A, AP2, OAuth, and hardware-backed approval systems remain attributable to their issuers. EMILIA Protocol is the open Action Receipt Contract underneath Gate; EMILIA Approver captures device-bound exact-action human decisions when the mandate or local policy requires fresh human authority; EMILIA Assurance Plane defines scoped verification, re-performance, conformance-report, and deployment-evidence procedures without acting as an auditor or accredited certifier. The toll-booth metaphor describes the intended cross-stack contract, not current coverage or operation of a central global network.

This is a generated discovery index following the llms.txt proposal. Evidence snapshot: 2026-09-01T09:44:11.545Z. For substantive analysis, load the full or machine-readable context below before drawing conclusions from individual repository files.
This is a generated discovery index following the llms.txt proposal. Evidence snapshot: 2026-09-02T00:56:07.055Z. For substantive analysis, load the full or machine-readable context below before drawing conclusions from individual repository files.

Prevention boundary: Gate prevents only on action paths under complete mediation. It does not constrain a path that bypasses the deployed enforcement point.

## Engineering Evidence

EMILIA is implemented security infrastructure, not architecture-only: 10,609 automated tests across 658 files; 35 executable security claims over 259 hashed evidence files; 20 verified obligations across 2 composed Tamarin models, with 8 deliberately weakened variants producing concrete attack traces; and 78 content-addressed selected model/runtime scenarios across 14 bounded models and 21 claims, including 51 paired formal-counterexample/runtime-refusal controls.
EMILIA is implemented security infrastructure, not architecture-only: 10,622 automated tests across 661 files; 35 executable security claims over 259 hashed evidence files; 20 verified obligations across 2 composed Tamarin models, with 8 deliberately weakened variants producing concrete attack traces; and 78 content-addressed selected model/runtime scenarios across 14 bounded models and 21 claims, including 51 paired formal-counterexample/runtime-refusal controls.

Interoperability evidence: 21 conformance suites and 332 current vectors across three same-team ports; external Rust evidence covers a time-pinned 164-vector set plus 359 hostility cases. Strict clean-room construction acceptance remains false.

Expand Down
Loading
Loading