Skip to content

docs: publish the tenant verification contract — claim, artifact, trust assumption#9258

Merged
loopover-orb[bot] merged 1 commit into
mainfrom
docs/verification-contract-eval-interface
Jul 27, 2026
Merged

docs: publish the tenant verification contract — claim, artifact, trust assumption#9258
loopover-orb[bot] merged 1 commit into
mainfrom
docs/verification-contract-eval-interface

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

Summary

Publishes the verification matrix decided on #9186 as a tenant-facing docs page, /docs/what-you-can-verify — a sibling to verify-this-review (which stays the how-to walkthrough; this is the what-can-I-check contract).

Five rows, each stating claim → artifact → endpoint/CLI → who can run it → trust assumption: gate-decision integrity (hash-chained ledger), decision-record authenticity (digest + published record), published accuracy numbers (corpus export + replay), attested execution (envelope + offline verifier CLI), and what the record's digests do and do not commit to.

The boundaries are stated as plainly as the guarantees:

Closes #9186. The decision record resolving all four numbered requirements is on the issue.

Test plan

  • npx vitest run src/components/site/docs-nav.test.tsx — 4/4 passing (the bidirectional nav drift guard: every content/docs/*.mdx has a nav entry, no entry points at an unpublished page)
  • npm run docs:drift-check — clean
  • npm run ui:lint — 0 errors
  • npm run ui:build — builds clean
  • Verified the documented endpoint live: GET /v1/public/decision-ledger/verify returns HTTP 200 unauthenticated with exactly the documented shape ({ok, checked, nextAfterSeq, tipSeq, tipHash, totalCount})
  • Corrected the API origin to the real api.loopover.ai (matches DEFAULT_API_ORIGIN)

…st assumption (#9186)

Adds "What you can verify" as a sibling to verify-this-review: for every claim
LoopOver makes, the artifact that proves it, the endpoint or CLI that checks it,
who can run it, and the trust assumption behind it.

States the boundaries as plainly as the guarantees: the ledger is
tamper-evident rather than tamper-proof until external anchoring ships, live
gate execution is not attested by standing design, ground-truth honesty is
closed by no artifact including attestation, digests commit to inputs and never
to non-deterministic model outputs, and the hosted-tenant column is weaker than
the self-host one.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
loopover-ui b6d8e59 Commit Preview URL

Branch Preview URL
Jul 27 2026, 10:48 AM

@JSONbored JSONbored self-assigned this Jul 27, 2026
@codecov

codecov Bot commented Jul 27, 2026

Copy link
Copy Markdown

Bundle Report

Changes will increase total bundle size by 25.61kB (0.34%) ⬆️. This is within the configured threshold ✅

Detailed changes
Bundle name Size Change
loopover-ui 7.47MB 25.61kB (0.34%) ⬆️

Affected Assets, Files, and Routes:

view changes for bundle: loopover-ui

Assets Changed:

Asset Name Size Change Total Size Change (%)
assets/add-scalar-classes-DtYbu7Yi.js (New) 2.16MB 2.16MB 100.0% 🚀
assets/tanstack-vendor-D8SCSNQB.js (New) 816.24kB 816.24kB 100.0% 🚀
assets/docs.fumadocs-spike-api-reference-C-Uox3SB.js (New) 443.45kB 443.45kB 100.0% 🚀
assets/AgentScalarChatInterface.vue-B0cNKYbc.js (New) 201.7kB 201.7kB 100.0% 🚀
assets/modal-BNZ9LAz-.js (New) 184.5kB 184.5kB 100.0% 🚀
assets/client-BikVD0kZ.js (New) 151.47kB 151.47kB 100.0% 🚀
assets/maintainer-panel-BvELfceR.js (New) 78.99kB 78.99kB 100.0% 🚀
assets/routes-DqytIm1j.js (New) 35.96kB 35.96kB 100.0% 🚀
assets/owner-panel-Bqc3S9hh.js (New) 27.92kB 27.92kB 100.0% 🚀
assets/app-BTXFLuN8.js (New) 25.78kB 25.78kB 100.0% 🚀
assets/what-you-can-verify-GK7R7n_z.js (New) 24.96kB 24.96kB 100.0% 🚀
assets/ui-vendor-ClI8Aabw.js (New) 24.57kB 24.57kB 100.0% 🚀
assets/verify-this-review-BcbMSR3Z.js (New) 22.97kB 22.97kB 100.0% 🚀
assets/miner-panel-D4jRxBKo.js (New) 20.24kB 20.24kB 100.0% 🚀
assets/app.runs-4WLYfmIk.js (New) 20.22kB 20.22kB 100.0% 🚀
assets/api._op-CwUrhEgF.js (New) 17.57kB 17.57kB 100.0% 🚀
assets/self-hosting-docs-audit-Con_gRFD.js (New) 16.6kB 16.6kB 100.0% 🚀
assets/docs._slug-0JShm4cq.js (New) 15.52kB 15.52kB 100.0% 🚀
assets/playground-panel-BYAoX-6_.js (New) 14.42kB 14.42kB 100.0% 🚀
assets/fairness-DlaC4nWK.js (New) 10.73kB 10.73kB 100.0% 🚀
assets/app.audit-BCXjt6hd.js (New) 10.08kB 10.08kB 100.0% 🚀
assets/app.config-generator-CUX0T0Wl.js (New) 10.06kB 10.06kB 100.0% 🚀
assets/maintainers-cxSS6xdm.js (New) 8.06kB 8.06kB 100.0% 🚀
assets/miners-Csa6gc3h.js (New) 7.91kB 7.91kB 100.0% 🚀
assets/agents-DM9J5KGF.js (New) 7.74kB 7.74kB 100.0% 🚀
assets/commands-panel-FCqjVmgD.js (New) 6.65kB 6.65kB 100.0% 🚀
assets/maintainer-workflow-BEasQeUR.js (New) 6.52kB 6.52kB 100.0% 🚀
assets/digest-panel-ZDyCbnob.js (New) 6.15kB 6.15kB 100.0% 🚀
assets/repos._owner._repo.quality-iGmI6sH0.js (New) 6.14kB 6.14kB 100.0% 🚀
assets/docs-nav-BkE7FQy2.js (New) 6.01kB 6.01kB 100.0% 🚀
assets/docs.index-DFBnCWOI.js (New) 5.95kB 5.95kB 100.0% 🚀
assets/api.index-CtG9tJxA.js (New) 4.7kB 4.7kB 100.0% 🚀
assets/docs-BkbMllRc.js (New) 2.7kB 2.7kB 100.0% 🚀
assets/api-BFHuIF_-.js (New) 2.69kB 2.69kB 100.0% 🚀
assets/docs-page-Bg6E30PJ.js (New) 2.1kB 2.1kB 100.0% 🚀
assets/table-BAgmIO-H.js (New) 1.75kB 1.75kB 100.0% 🚀
assets/app.workbench-DSLnkRkr.js (New) 1.58kB 1.58kB 100.0% 🚀
assets/tabs-BivewvKD.js (New) 1.39kB 1.39kB 100.0% 🚀
assets/app.repos-BRaLy_7I.js (New) 1.07kB 1.07kB 100.0% 🚀
assets/input-DxWPwa7S.js (New) 796 bytes 796 bytes 100.0% 🚀
assets/file-cog-CZ63yIq5.js (New) 758 bytes 758 bytes 100.0% 🚀
assets/app.maintainer-xCyIBtum.js (New) 502 bytes 502 bytes 100.0% 🚀
assets/app.owner-CTHdLZpm.js (New) 474 bytes 474 bytes 100.0% 🚀
assets/app.commands-BpUdmIMn.js (New) 455 bytes 455 bytes 100.0% 🚀
assets/app.playground-BSwUykr_.js (New) 442 bytes 442 bytes 100.0% 🚀
assets/index-BKrfhlzU.js (New) 438 bytes 438 bytes 100.0% 🚀
assets/app.digest-CVu5GQg3.js (New) 430 bytes 430 bytes 100.0% 🚀
assets/eye-off-DpGzrJBD.js (New) 430 bytes 430 bytes 100.0% 🚀
assets/app.miner-fGLXvp_8.js (New) 422 bytes 422 bytes 100.0% 🚀
assets/key-round-C9l470RU.js (New) 355 bytes 355 bytes 100.0% 🚀
assets/bot-DkcbceqR.js (New) 328 bytes 328 bytes 100.0% 🚀
assets/trash-2-D4_NBVRx.js (New) 328 bytes 328 bytes 100.0% 🚀
assets/save-BPi1EteY.js (New) 327 bytes 327 bytes 100.0% 🚀
assets/git-pull-request-arrow-D87reRQH.js (New) 321 bytes 321 bytes 100.0% 🚀
assets/list-checks-BxTCz5dr.js (New) 279 bytes 279 bytes 100.0% 🚀
assets/compass-BuYYf1uq.js (New) 251 bytes 251 bytes 100.0% 🚀
assets/history-CAHxpGer.js (New) 237 bytes 237 bytes 100.0% 🚀
assets/message-square-CykX5RdR.js (New) 233 bytes 233 bytes 100.0% 🚀
assets/lock-CepXq3oI.js (New) 206 bytes 206 bytes 100.0% 🚀
assets/rotate-cw-DSeVNyWY.js (New) 201 bytes 201 bytes 100.0% 🚀
assets/play-CX2JuQZO.js (New) 190 bytes 190 bytes 100.0% 🚀
assets/circle-check-CibH0brc.js (New) 178 bytes 178 bytes 100.0% 🚀
assets/search-DczX1c_r.js (New) 174 bytes 174 bytes 100.0% 🚀
assets/add-scalar-classes-KjzP9mWn.js (Deleted) -2.16MB 0 bytes -100.0% 🗑️
assets/tanstack-vendor-DkvKc8eG.js (Deleted) -816.24kB 0 bytes -100.0% 🗑️
assets/docs.fumadocs-spike-api-reference-DlrBeBYL.js (Deleted) -443.45kB 0 bytes -100.0% 🗑️
assets/AgentScalarChatInterface.vue-D1wOoueS.js (Deleted) -201.7kB 0 bytes -100.0% 🗑️
assets/modal-tNZvNmgl.js (Deleted) -184.5kB 0 bytes -100.0% 🗑️
assets/client-Cl9RDoXi.js (Deleted) -151.47kB 0 bytes -100.0% 🗑️
assets/maintainer-panel-BnuGFLFs.js (Deleted) -78.99kB 0 bytes -100.0% 🗑️
assets/routes-D-rG_PYd.js (Deleted) -35.96kB 0 bytes -100.0% 🗑️
assets/owner-panel-D_okfM18.js (Deleted) -27.92kB 0 bytes -100.0% 🗑️
assets/app-Duu_XZV3.js (Deleted) -25.78kB 0 bytes -100.0% 🗑️
assets/ui-vendor-CWZJXKjt.js (Deleted) -24.57kB 0 bytes -100.0% 🗑️
assets/verify-this-review-BnZqoUqW.js (Deleted) -22.54kB 0 bytes -100.0% 🗑️
assets/miner-panel-B6Tojk4k.js (Deleted) -20.24kB 0 bytes -100.0% 🗑️
assets/app.runs-j0wpnRWU.js (Deleted) -20.22kB 0 bytes -100.0% 🗑️
assets/api._op-DD6tzuuR.js (Deleted) -17.57kB 0 bytes -100.0% 🗑️
assets/self-hosting-docs-audit-BjrkaR5l.js (Deleted) -16.6kB 0 bytes -100.0% 🗑️
assets/docs._slug-Csll7Hx8.js (Deleted) -15.37kB 0 bytes -100.0% 🗑️
assets/playground-panel-BMELUXBf.js (Deleted) -14.42kB 0 bytes -100.0% 🗑️
assets/fairness-z8pwc337.js (Deleted) -10.73kB 0 bytes -100.0% 🗑️
assets/app.audit-DIr7eX2g.js (Deleted) -10.08kB 0 bytes -100.0% 🗑️
assets/app.config-generator-CrY2Jiz2.js (Deleted) -10.06kB 0 bytes -100.0% 🗑️
assets/maintainers-DkVab-Im.js (Deleted) -8.06kB 0 bytes -100.0% 🗑️
assets/miners-HaD8xYe-.js (Deleted) -7.91kB 0 bytes -100.0% 🗑️
assets/agents-BkHB8Wxe.js (Deleted) -7.74kB 0 bytes -100.0% 🗑️
assets/commands-panel-DQPQeMDW.js (Deleted) -6.65kB 0 bytes -100.0% 🗑️
assets/maintainer-workflow-SKt4ouIK.js (Deleted) -6.52kB 0 bytes -100.0% 🗑️
assets/digest-panel-DDwTA_aC.js (Deleted) -6.15kB 0 bytes -100.0% 🗑️
assets/repos._owner._repo.quality-Cjbf5Ki4.js (Deleted) -6.14kB 0 bytes -100.0% 🗑️
assets/docs-nav-C_250m-R.js (Deleted) -5.95kB 0 bytes -100.0% 🗑️
assets/docs.index-BFfns2kg.js (Deleted) -5.95kB 0 bytes -100.0% 🗑️
assets/api.index-BAgAJlYd.js (Deleted) -4.7kB 0 bytes -100.0% 🗑️
assets/docs-B3jsL9aH.js (Deleted) -2.7kB 0 bytes -100.0% 🗑️
assets/api--eOp3xs2.js (Deleted) -2.69kB 0 bytes -100.0% 🗑️
assets/docs-page-zwz80XSR.js (Deleted) -2.1kB 0 bytes -100.0% 🗑️
assets/table-oq5PAVwo.js (Deleted) -1.75kB 0 bytes -100.0% 🗑️
assets/app.workbench-1ufs7b4B.js (Deleted) -1.58kB 0 bytes -100.0% 🗑️
assets/tabs-BDglh5ye.js (Deleted) -1.39kB 0 bytes -100.0% 🗑️
assets/app.repos-CEfqZSeh.js (Deleted) -1.07kB 0 bytes -100.0% 🗑️
assets/input-CJX2tbcM.js (Deleted) -796 bytes 0 bytes -100.0% 🗑️
assets/file-cog-BjXSzDaH.js (Deleted) -758 bytes 0 bytes -100.0% 🗑️
assets/app.maintainer-Ohvnl2zJ.js (Deleted) -502 bytes 0 bytes -100.0% 🗑️
assets/app.owner-BG9u2KTZ.js (Deleted) -474 bytes 0 bytes -100.0% 🗑️
assets/app.commands-BwTxtDCL.js (Deleted) -455 bytes 0 bytes -100.0% 🗑️
assets/app.playground-Ce4tIE18.js (Deleted) -442 bytes 0 bytes -100.0% 🗑️
assets/index-C_WgSe_W.js (Deleted) -438 bytes 0 bytes -100.0% 🗑️
assets/app.digest-CXAOfJdr.js (Deleted) -430 bytes 0 bytes -100.0% 🗑️
assets/eye-off-B1KLwrux.js (Deleted) -430 bytes 0 bytes -100.0% 🗑️
assets/app.miner-Caa-2pOI.js (Deleted) -422 bytes 0 bytes -100.0% 🗑️
assets/key-round-CC20bArn.js (Deleted) -355 bytes 0 bytes -100.0% 🗑️
assets/bot-CjcRm-wu.js (Deleted) -328 bytes 0 bytes -100.0% 🗑️
assets/trash-2-CXFkW5OH.js (Deleted) -328 bytes 0 bytes -100.0% 🗑️
assets/save-B-scgHdk.js (Deleted) -327 bytes 0 bytes -100.0% 🗑️
assets/git-pull-request-arrow-D2rWnG7Q.js (Deleted) -321 bytes 0 bytes -100.0% 🗑️
assets/list-checks-D_q_DENP.js (Deleted) -279 bytes 0 bytes -100.0% 🗑️
assets/compass-Cv2wpPDA.js (Deleted) -251 bytes 0 bytes -100.0% 🗑️
assets/history-CzM9Fm6-.js (Deleted) -237 bytes 0 bytes -100.0% 🗑️
assets/message-square-BhEHtcUt.js (Deleted) -233 bytes 0 bytes -100.0% 🗑️
assets/lock-BFS0cagl.js (Deleted) -206 bytes 0 bytes -100.0% 🗑️
assets/rotate-cw-wGbUwhhR.js (Deleted) -201 bytes 0 bytes -100.0% 🗑️
assets/play-DSrsC74z.js (Deleted) -190 bytes 0 bytes -100.0% 🗑️
assets/circle-check-CFrcX_Kf.js (Deleted) -178 bytes 0 bytes -100.0% 🗑️
assets/search-BO5jtACK.js (Deleted) -174 bytes 0 bytes -100.0% 🗑️

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 27, 2026
@loopover-orb

loopover-orb Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Tip

✅ LoopOver review result - approve/merge recommended

Review updated: 2026-07-27 10:51:25 UTC

3 files · 1 AI reviewer · no blockers · readiness 100/100 · CI green · clean

✅ Suggested Action - Approve/Merge

  • safe to merge

Review summary
This is a pure docs addition: a new MDX page laying out a claim/artifact/trust-assumption matrix, a one-line nav entry wiring it into docs-nav.tsx, and a cross-link added from verify-this-review.mdx. Content is internally consistent with the linked verify-this-review.mdx (endpoint shapes, exit codes, issue references all line up), and the PR closes #9186 per the description. No code paths, schema, or logic are touched, so there's little to break; the nav-drift test cited in the test plan covers the one behavioral change (the new nav entry).

Nits — 7 non-blocking
  • docs-nav.tsx:110 has zero test-path evidence per the classifier, but the cited `docs-nav.test.tsx` (bidirectional nav drift guard) is exactly the test that exercises this new entry — worth confirming that test file was actually re-run against this diff rather than just existing in the repo.
  • The new page states `GET /v1/public/decision-ledger/verify` and `/v1/public/decision-records/OWNER/REPO/123` return specific shapes but the diff includes no corresponding source file to cross-check the response contract against — take the author's live-verification claim in the test plan at face value since it isn't independently checkable from this diff.
  • Nit: the 'What you cannot verify' table and the matrix both repeat the ledger tamper-evident-not-tamper-proof point (rows 1 and the table) — intentional per the doc's own framing (last-column emphasis), so not asking for a change, just noting the duplication is deliberate.
  • If `buildLedgerAnchorPayload` really is unreferenced dead code as the description states, consider filing/linking a follow-up issue for external anchoring so this claim doesn't rot silently as the only place documenting that gap.
  • Consider adding a short automated check (or extending docs:drift-check) that flags claims naming specific exit codes or response shapes so future API changes are caught by CI rather than relying on manual doc updates.
  • Diff looks like trivial or whitespace-only churn — Reduce whitespace-only or formatting-only churn and keep the diff focused on substantive changes.
  • Code changes lack test evidence — Add focused regression tests or explain why existing coverage is sufficient.

Decision drivers

  • ✅ Code review — No blockers (1 reviewer)
  • ✅ Gate result — Passing (No configured blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ Linked #9186
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (1 linked issue).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 13 registered-repo PR(s), 13 merged, 331 issue(s).
Contributor context ✅ Confirmed Gittensor contributor JSONbored; Gittensor profile; 13 PR(s), 331 issue(s).
Improvement ℹ️ None detected risk: elevated · value: none · LLM: moderate
Linked issue satisfaction

Addressed
The PR publishes the tenant-facing verification matrix docs page covering all four numbered requirements (matrix rows with claim→artifact→endpoint→who→trust assumption, an explicit not-verifiable section citing #9141, and a self-host-vs-hosted distinction), plus links it as a sibling to verify-this-review.mdx as requested, with a decision record noted as resolving the requirements on the issue its

Review context
  • Author: JSONbored
  • Role context: owner (maintainer lane)
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: Python, TypeScript, Ruby, Go, MDX, Shell, Solidity, JavaScript
  • Official Gittensor activity: 13 PR(s), 331 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Start here: Treat this as maintainer-lane context rather than normal contributor-lane activity.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask <question> answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat <question> answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

Visual preview
Route Viewport Before (production) After (this PR's preview) Diff
/ desktop before /
before /
after /
after /
/ mobile before / (mobile)
before / (mobile)
after / (mobile)
after / (mobile)

Click any thumbnail to open the full-size screenshot. Before = production · After = this PR's preview deploy.

Scroll preview
Route Before (production) After (this PR's preview)
/ before / (scroll)
before / (scroll)
after / (scroll)
after / (scroll)

A short scroll-through clip (desktop) — click either thumbnail to open the full animation. Evidence for scroll-linked behavior a single screenshot can't show.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb loopover-orb Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LoopOver approves — the gate is satisfied and CI is green.

@loopover-orb
loopover-orb Bot merged commit a2c8ab8 into main Jul 27, 2026
9 checks passed
@loopover-orb
loopover-orb Bot deleted the docs/verification-contract-eval-interface branch July 27, 2026 10:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cloud: unified tenant verification contract — claim → artifact → endpoint → trust assumption

1 participant