styxx 7.49.0 is live. pip install -U styxx
we attacked our own proof format, found the hole, shipped the fix, and filed the advisory against ourselves.
→ the hole
OATH capsules are single-file documents that carry their own receipts plus a certificate, and styxx.capsule verify re-derives that certificate from the bytes. we went after the verifier ourselves. on every release since capsules shipped (7.47.0, 7.48.0, 7.48.1) it printed VERIFIED on capsules whose certificate had been edited: an unchecked number hidden, a ledger row deleted, a receipt repointed, an epistemics flag flipped, a page that shows one document while the verifier reads another. five forgeries. 7.48.0 and 7.48.1 passed every one.
→ the fix
7.49.0 compares the whole certificate and the page around it. all five forgeries fail now. a newly minted page shows a verdict only after its hashes match.
advisory, filed and published by us: GHSA-3g8h-qcfm-25xw
→ the part we left open, on purpose and in writing
capsules minted on the old page format still verify, because honest ones carry it. a forged one dressed up as "older" still passes on that page, but 7.49.0 prints six NOT CHECKED lines and three warnings next to it. on a new page the same forgery fails.
→ the diff gate holds back where it could be wrong
PATH-2a: where three known reader bugs could flip a verdict, the gate withholds the verdict.
→ the Action reports by default and blocks only if you opt in
reason: no kind of accusation it still makes has cleared our own 0.95 precision floor. path accusations measured 0.23 precision on 100 accusations sampled from 71,016 external agent PRs. that number is in the README.
→ "LIE" is gone. a contradicted claim prints CONTRADICTED, with its reason.
→ receipts
PyPI 7.49.0 · GitHub release with sha256 for both files · Zenodo DOI 10.5281/zenodo.23221755
a verifier that hides its own failure modes isn't worth running. so we published ours.