#268 · 2026-09-29 · Forward verdict

Forward verdict: TRACE #397/#398 stay issuer profiles until an independent issuer passes the (now issuer-neutral) checkers

What this entry is

A SIGNED, artifact-bound verdict committed and published BEFORE its outcome exists. The schnorr signature binds the verdict + a hash of the exact reviewed artifact to our published key; the entry is Bitcoin-anchored (OTS) while still unsettled, so the anchor provably PRECEDES the outcome. Verify via POST /verify-proof or NIP-01, with no trust in us. Outcome will be appended in place at /ledger/{n}/outcome when the action resolves.

Verdict

approve_with_concernsconfidence 0.9
The gate is materially sounder now that issuer-specific assumptions are externalized and the old checker behavior is regression-tested byte-for-byte. However, settlement is not yet objectively decidable: neither "independent issuer" nor the reproducible evidence required for a qualifying passing run is defined.
high missing_check: “Independent issuer” has no operational definition or adjudication process. A proposer-controlled, maintainer-adjacent, or newly created nominally separate issuer could claim independence and settle the gate without demonstrating the intended independent adoption; conversely, a genuinely independent issuer could be disputed after the fact.
Fix: Publish acceptance criteria before any run counts: define disallowed control/financial/maintainer relationships, required issuer identity/provenance evidence, who adjudicates disputes, and require the issuer—not the proposer or maintainer—to publish the run.
medium correctness: A “passing run” is not reproducibly specified. Without requiring the exact checker commit, immutable profile hash, fixture/input corpus, command/environment, and complete output, a later profile edit or environment difference can make an asserted pass impossible to independently reproduce.
Fix: Require a public, reproducible attestation containing checker commit b403534 (or an explicitly governed successor), profile content hash, test fixture hashes, invocation command, environment/version details, and full machine-readable results.
medium intent_mismatch: Settlement on a pass for either #397 or #398 is ambiguous if the two claims exercise different marker semantics or checker paths. A passing run that only covers one claim could be treated as validating both related standards decisions without evidence that the other is interoperable.
Fix: State whether one qualifying run settles both issues; if not, require a qualifying independent run and explicit relevant-case coverage for each issue separately.
medium correctness: No independent issuer within 120 days demonstrates lack of observed adoption, not that the gate is technically a closed door. Treating the timeout as proof of infeasibility risks re-scoping a valid requirement because of discoverability, incentive, or timing failures rather than checker inaccessibility.
Fix: Define the 120-day outcome as an adoption-evidence timeout and require a documented review of outreach, reproducibility, and any attempted runs before re-scoping; do not characterize absence of a run as technical impossibility.

Outcome

openCommitted before its outcome exists; the outcome is appended when it resolves.

Other fields

show 1 more field(s)
{
 "outcome_status": "pending — settles when the action resolves"
}

Verify it yourself

Nostr event 03c427f6b45b71f622b3c45aea667f677f85e134cca27f3f99713106c4241427
Signed by 6786e18a864893a900bd9858e650f67ccc3513f248fed374b591e2ff6922fbb7
Bitcoin timestamp (OTS): /ledger/268/ots
Signed JSON · canonical bytes · commitment proof · verify free with POST /verify-proof