Assurance and verification · exact alpha.3
Evidence for the exact package—without turning evidence into praise or truth authority.
This page records artifact identity, rights posture, independent exact-package review, deterministic reconstruction, executed tests, explicit limitations, and the later human release decision.
- Independent review PASS
- 10 / 10 review gates
- 96 source tests
- Two exact clean builds
- 94 / 94 rights rows
- Candidate unchanged
Controlling status
Public release is authorized for three exact trust roots only.
Authority effect
PUBLIC_RELEASE_OF_EXACT_HASHED_COMMUNITY_EDITION_ARTIFACTS_ONLY
The release decision does not authorize scientific confirmation, truth certification, diagnosis, identity assignment, compliance certification, production security certification, deployment, training, memory write, publication of the separate theory-freeze archive, or disclosure of the private repository.
Exact trust roots
Recalculate these hashes after every download.
Source ZIP
The complete public source tree reviewed and released without byte changes.
Choose this when: you need the controlling source and documentation trust root.
SHA-256008b7ee0ae77360592c6073844f1b0401ffbbb34d520f02aac3c05a5b4ef2b9a
Python wheel
The exact commissioned pure-Python install artifact.
Choose this when: you want the reviewed offline package for Python 3.11+ environments.
SHA-256eea6dd5603360e0e0daf384dbe0417c5f4ff1777d2b13561684d3cb15a1e3a81
Python sdist
The exact commissioned Python source distribution.
Choose this when: you need the reviewed packaging-source trust root.
SHA-256d11157eb506be04d9785aa7e2902048595f941906f5a9eb4074c2632de1f1c86
Independent exact-package review
The reviewer passed all ten commissioned gates.
The review authenticated and replayed the exact source ZIP, wheel, sdist, frozen parent, and rights ledger. It made the candidate eligible for Thomas Prislac’s later exact-hash release decision; it did not itself publish or certify the product.
| Gate | Independent evidence |
|---|---|
| Identity, archive safety, nonmutation | 58 / 58 authentication and closure checks; final nonmutation confirmed. |
| Frozen-parent continuity | 94 paths: 74 identical, 20 changed, 0 added, 0 removed; one substantive runtime repair. |
| Rights and license | 94 / 94 rights reconciliation; MPL-2.0, SPDX, PEP 639, SBOM, and notices passed within a nonlegal ceiling. |
| Process contract | 201 / 201 checks across source and exact wheel; stable exit 0 / 1 / 2 behavior. |
| Schema, grounding, archive attacks | 139 / 139 source and 139 / 139 wheel adversarial cases. |
| Functional and benchmark replay | 96 passed, 0 failed, 0 skipped; 128 / 128 benchmark cases. |
| Offline installability | Exact wheel and exact-sdist-derived replay installation matched bounded runtime behavior. |
| Exact reconstruction | Two isolated roots reproduced source ZIP, wheel, and sdist byte for byte. |
| GUFT functions and claim ceiling | Projector, waveform, AHA, telemetry, and vertical slice executed; scientific claims remained unestablished. |
| Local-first and nonauthority | No account, activation, payment, provider, model, network, hidden telemetry, memory, training, publication, deployment, or authority effect was required or executed. |
71822aca369eb2181e1b10887463e4f361df8ce4d9d1eb78cc571f9c24420745
Fresh release-steward validation
The later release wrapper preserved the reviewed candidate and added only authority records.
Candidate mutation
None. The source ZIP, wheel, and sdist remained the exact independently reviewed bytes.
Fresh source execution
96 passed, 0 failed, 0 skipped. Demo, verify, and exact replay passed.
Exact builds
Two clean roots reconstructed the source ZIP, wheel, and sdist with the commissioned hashes.
Offline package replay
The exact wheel and exact sdist install, demonstration, verification, and replay routes passed.
Rights activation
Thomas Prislac’s August 23, 2026 decision activated MPL-2.0 public release for the exact hashes.
Public hosting
The release kit did not expose the private repository or separate theory-freeze package. External hosting was a later publication operation.
Rights and open-source posture
Every source member has one exact rights-ledger row.
File-level reconciliation
The rights ledger contains 94 unique rows for 94 source members and is bound to the exact source ZIP.
Ledger SHA-256faee9df1af490a842cacc974022998b92e20ab8b7cb6018a623fc8988ce266da
License and package metadata
The full MPL-2.0 text is included; all 29 Python files carry SPDX headers; package metadata uses the PEP 639 MPL-2.0 expression; the SPDX 2.3 SBOM declares and concludes MPL-2.0.
This is authentication and consistency review of supplied rights records, not external legal-title adjudication or a legal opinion.
Complete release evidence
Public-release kit, checksum, and machine-readable validation
UVLM_CoherenceLattice_Operational_Cognition_Engine_Community_Edition_v0.1.0-alpha.3_Public_Release_Kit_v1.0.0.zip
Contains release facts, Thomas’s authorization record, machine-readable decision receipt, rights activation, release validation, public notes, historical-state explanation, theory/plugin boundary, install guide, hosting handoff, exact artifacts, review evidence, rights records, manifests, and a public verifier.
SHA-25680a9ab074c3a78818d74deb38ae7b93efeb5999b9b25be8cf6597d7eaed7fc1e
Independent verification
Verify the bytes yourself.
# Source ZIP example — macOS / Linux sha256sum UVLM_CoherenceLattice_Operational_Cognition_Engine_Community_Edition_v0.1.0-alpha.3.zip # Source ZIP example — Windows PowerShell Get-FileHash -Algorithm SHA256 .\UVLM_CoherenceLattice_Operational_Cognition_Engine_Community_Edition_v0.1.0-alpha.3.zip
Expected source digest: 008b7ee0ae77360592c6073844f1b0401ffbbb34d520f02aac3c05a5b4ef2b9a
After extracting the complete release kit, run:
python verify_public_release.py
Hosted-copy boundary
The approved hash identifies the release, not the website link. After publication, a steward should download each file while logged out, recalculate its SHA-256, and record the public URL and verification time. This page does not claim that Squarespace itself independently certified the bytes.
Accurate limitations and nonclaims
What the evidence does not establish
Scientific validity
GUFT scientific truth, Pattern Donation semantic non-vacuity, external cross-domain utility, and improved deployed AI cognition remain unestablished.
Cross-platform reproducibility
Two same-toolchain clean roots reproduced exact artifacts. Exact cross-platform byte equality was not tested.
Security assurance
No full external penetration test, formal cryptographic audit, or production security certification was performed.
Accessibility assurance
Documentation follows an accessible posture, but qualified screen-reader, keyboard, low-vision, high-zoom, and cognitive-load review remains outside this release validation.
Human classification
No receipt or axis value may diagnose, classify, rank, or determine the worth, credibility, morality, identity, or spiritual state of a person.
Authority
A test, review, hash, receipt, or plugin cannot create truth, deployment, training, memory, publication, compliance, or final-decision authority by itself.
Support, correction, and security
One monitored inbox, routed by subject line
Do not email passwords, credentials, private keys, sensitive source material, protected health information, or customer records. Use email first to request an approved transfer route.
Voluntary nonprofit support
Help keep public-interest research open and usable.
Voluntary gifts help fund accessibility, independent review, documentation, maintenance, educational resources, and grant-sponsored access to UVLM tools and research.
Giving is always optional. Donations never affect access to public materials, product behavior, verification results, ordinary support, or governance decisions.