{
  "schema": "trinityaccord.evidence-evolution-plan.v1",
  "version": "1.0.0",
  "status": "active_handoff",
  "decision_recorded_at_utc": "2026-08-09T00:00:00Z",
  "purpose": "Machine-readable handoff for future agents to audit and improve the evidence system without overwriting immutable historical checkpoints or repeating completed work.",
  "current_checkpoint": {
    "checkpoint_kind": "immutable_published_checkpoint_not_live_main",
    "scope_label": "2026 current evidence checkpoint v4",
    "core_concept_doi": "10.5281/zenodo.21739343",
    "core_version_doi": "10.5281/zenodo.21859437",
    "frozen_source_baseline_commit_sha": "ba34564c579d645a5a1595f0538223e0e957155e",
    "package_identity_sha256": "fda45c9766a060f1d9634ff7912647728c44999ec79f41af724c4c8fe8bc8b36",
    "public_metadata_and_byte_verification": "passed",
    "public_doi_only_cold_restore": "passed",
    "evidence_scope": {
      "bitcoin_inscriptions": 8,
      "bitcoin_canonical_originals": 3,
      "bitcoin_non_amending_ancillary": 5,
      "ethereum_non_nft_anchors": 12,
      "ethereum_chronicle_nfts": 175,
      "nft_contracts": 4,
      "proof_status_required": "PASS",
      "ordinary_verification_network_required": false
    },
    "intended_as_permanent_final": false,
    "future_material_versions_allowed": true
  },
  "live_repository_checkpoint": {
    "checkpoint_kind": "incorporated_into_immutable_checkpoint_v4",
    "repository_base_commit_before_delta": "f57ffd3763e4165c0030040683c4d51e4be83a79",
    "merge_commit": "determine_from_git_history_after_merge",
    "evidence_scope": {
      "bitcoin_inscriptions": 8,
      "bitcoin_canonical_originals": 3,
      "bitcoin_non_amending_ancillary": 5,
      "ethereum_non_nft_anchors": 12,
      "ethereum_chronicle_nfts": 175,
      "nft_contracts": 4,
      "ordinary_proof_verification_network_required": false
    },
    "ethereum_post_freeze_additions": [
      {
        "role": "Authority Manifest SHA-256 notarization",
        "tx_hash": "0x06b1d82b7828054f249cdcc2e820321f634bd8bef44318751113098d2ee37acd",
        "binding": "signed calldata equals SHA-256(authority.jcs.json)"
      },
      {
        "role": "Authority Manifest EIP-712 signature record",
        "tx_hash": "0x04314e8f9b47fac54dcf2db3a65f40aad60c226e65614f0ad22588bd39c416d2",
        "binding": "signed calldata records and the verifier cryptographically checks the EIP-712 Authority Manifest binding plus declared Ethereum/Arweave references"
      }
    ],
    "address_scope_audit": "api/ethereum-address-evidence-scope.v1.json",
    "current_offline_report": "evidence/ethereum-evidence-annex-v1/reports/OFFLINE-VERIFICATION.json",
    "published_final_doi_v3_includes_this_delta": false,
    "new_doi_publication_status": "published_verified_and_consumed",
    "new_arweave_upload_status": "intentionally_deferred_not_attempted",
    "recovery_boundary": "Version DOI 10.5281/zenodo.21859437 restores the complete 12-anchor state without GitHub.",
    "published_checkpoint_v4_includes_this_delta": true
  },
  "versioning_semantics": {
    "current_version_doi_is_immutable": true,
    "current_version_must_never_be_overwritten": true,
    "final_means_final_for_this_evidence_epoch": true,
    "final_does_not_mean_project_evolution_is_closed": true,
    "future_material_improvements_use_a_new_version": true,
    "concept_doi_may_resolve_a_later_verified_version": true,
    "github_main_may_continue_to_evolve": true,
    "current_checkpoint_is_permanent_final": false
  },
  "owner_decision": {
    "final_core_arweave_mirror": {
      "status": "intentionally_deferred",
      "authorized_for_upload": false,
      "reason": "The current exact baseline is already DOI-preserved and publicly cold-restored. A later materially improved evidence epoch may be a better single target for an additional permanent Arweave repository-capsule mirror.",
      "not_a_failure": true,
      "not_a_missing_cryptographic_proof": true,
      "existing_repository_capsule_arweave_mirror_is_historical": true,
      "do_not_claim_current_final_baseline_is_on_arweave": true,
      "non_binding_cost_observation": {
        "observed_at_utc": "2026-08-09T00:00:00Z",
        "payload_bytes": 50052055,
        "minimum_reward_ar": "0.507071251653",
        "suggested_one_time_cap_ar": "0.60",
        "price_endpoint": "https://arweave.net/price/50052055",
        "warning": "This is a historical planning observation only. Requote at signing time and obtain fresh owner authorization before any paid irreversible write."
      }
    }
  },
  "review_policy": {
    "quarterly_read_only_recovery_checks_continue": true,
    "next_read_only_architecture_review_not_before": "2027-02-08",
    "next_publication_decision_target": "2027-08-08",
    "calendar_dates_are_review_points_not_automatic_publication_triggers": true,
    "early_review_triggers": [
      "two consecutive public DOI recovery failures",
      "checksum or public metadata mismatch",
      "material Zenodo, GitHub, IPFS or Arweave availability-policy change",
      "new Bitcoin or Ethereum evidence objects entering the declared closed set",
      "material fail-closed verifier improvement",
      "completion of reproducible long-term verifier dependency artifacts",
      "planned transition to long-term unattended maintenance"
    ]
  },
  "maintenance_checkpoint_2026_08_08": {
    "status": "implemented_and_locally_verified",
    "scope": "Post-freeze repository hardening and future-agent handoff; this does not alter the bytes or identity of the immutable DOI version.",
    "reviewed_merged_pull_requests": [
      954,
      957,
      958,
      959
    ],
    "completed_work": [
      "NFT commitments and verification now reject omitted operator or batch_index keys and enforce event-specific null, required-operator and TransferBatch-index semantics.",
      "A synthetic ERC-1155 TransferBatch receipt exercises the previously untested verifier branch and its negative mutations.",
      "Bitcoin block time is decoded from and bound to the proof-carrying header; checkpoint votes require distinct matching providers.",
      "Bitcoin scoped mirror verification, stable success output, structured adapter failures, manifest-derived inventory totals and recovery dependencies are repaired.",
      "Ethereum and NFT checkpoint provenance counts also require distinct matching providers, matching the Bitcoin fail-closed rule.",
      "The unified final inventory freshly executes and compares the Bitcoin, Ethereum and NFT reports before consuming checked-in summaries.",
      "Final-publication observation identities, frozen input coverage and Zenodo Concept-DOI lineage preflight are fail-closed.",
      "Historical external-annex DOI roles and rich repository-version metadata survive future writer reruns.",
      "Human and machine discovery surfaces now expose this evolution handoff."
    ],
    "verification_record": {
      "bitcoin_offline_annex": "PASS; checked-in report unchanged",
      "ethereum_offline_annex": "PASS; checked-in report unchanged",
      "nft_offline_annex": "PASS; checked-in report unchanged",
      "nft_collection_merkle_root_unchanged": "097bb48d98ab7fc036aed97f5b5fcb1a65962d64d327081277255d1829212267",
      "targeted_review_regressions": "PASS",
      "complete_current_system_tests": "PASS",
      "gateway_unit_tests": "383 passed, 1 skipped",
      "live_site_read_only_checks": "Homepage and Verify navigation rendered without broken images or horizontal overflow; five critical public JSON endpoints returned HTTP 200 and parsed; healthz, readyz and readiness returned HTTP 200 with active protection and ready preflight/submit."
    },
    "external_write_record": {
      "new_zenodo_version_published": false,
      "arweave_upload_performed": false,
      "proof_or_commitment_bytes_changed": false,
      "owner_cost_authorization_consumed": false
    },
    "continuation_note": "Determine merge and deployment identity from Git history and GitHub before relying on this post-freeze maintenance checkpoint. The immutable DOI version remains the earlier named baseline."
  },
  "maintenance_checkpoint_2026_08_09": {
    "status": "completed_and_locally_verified",
    "scope": "Complete the observation-bounded Ethereum evidence set, close signed-transaction semantics, repair recovery discovery and resolve actionable recent PR review comments without publishing a DOI or writing Arweave.",
    "completed_work": [
      "Classified all 232 provider-observed normal transactions for the guardian address through outgoing nonce 219: 12 non-NFT self-data evidence transactions, 175 Chronicle NFT mint transactions, 33 other outgoing account operations and 12 incoming transactions.",
      "Added the two omitted self-data evidence transactions: the Authority Manifest SHA-256 notarization and the on-chain EIP-712 signature/release record.",
      "Generated and SHA-256-bound offline execution-trie and checkpoint-relative Beacon witnesses for both additions; existing proof bytes remain unchanged.",
      "Hardened the Ethereum verifier to recover and verify the signed transaction sender and enforce chain ID, destination, zero value, calldata length/hash, successful receipt status and anchor-specific payload semantics.",
      "Made the EIP-712 Authority Manifest signature machine-verifiable offline and bound its on-chain record to the declared Ethereum and Arweave references.",
      "Bound the BTC BIP-340 witness transaction calldata field-by-field to the preserved signature object and its Arweave TxID; BIP-340 validity remains checked by the authority-signature verifier.",
      "Fixed the Bitcoin report adapter so a verifier invocation error can never produce PASS.",
      "Moved external-annex core DOI-role validation before the first potentially irreversible Zenodo publication call.",
      "Added regressions for invocation failure, DOI preflight ordering, normalized provider identity, signed Ethereum semantics, receipt status, Authority digest and EIP-712 signature mutation.",
      "Expanded the recovery index and validator to enumerate and hash-check the current Ethereum and NFT witness file sets and exposed the live-versus-frozen split through public machine discovery.",
      "Made the preservation dispatcher inherit an explicitly selected Python interpreter so nested recovery validation cannot silently escape its pinned dependency environment."
    ],
    "verification_record": {
      "ethereum_offline_annex": "PASS; 12/12 L1/L2/L3 plus signed-transaction and payload semantics",
      "address_scope_partition": "PASS; 220 = 12 + 175 + 33 and 12 incoming are separate",
      "targeted_evidence_and_review_tests": "PASS; 40 passed",
      "recovery_index_and_frozen_inventory": "PASS",
      "complete_current_system_tests": "PASS; includes 504 top-level pytest tests",
      "sitemap_and_machine_source_contracts": "PASS"
    },
    "external_write_record": {
      "new_zenodo_version_published": true,
      "arweave_upload_performed": false,
      "existing_frozen_proof_bytes_changed": false,
      "new_post_freeze_proof_bytes_added": true,
      "owner_cost_authorization_consumed": false,
      "zenodo_checkpoint_sequence": 4,
      "zenodo_version_doi": "10.5281/zenodo.21859437",
      "owner_zenodo_authorization_consumed": true
    },
    "continuation_note": "Checkpoint v4 at 10.5281/zenodo.21859437 freezes 8 + 12 + 175. Future material improvements require a new owner-authorized version; no new Arweave upload was performed."
  },
  "future_agent_start_sequence": [
    "Read api/final-evidence-inventory.v1.json as the immutable DOI v4 checkpoint inventory, then read api/evidence-manifest.json for any explicitly separated later GitHub delta.",
    "Read api/evidence-relationship-map.v1.json and distinguish every frozen-DOI edge from moving-GitHub edges.",
    "Read FINAL-EVIDENCE-FREEZE.md, EVIDENCE-EVOLUTION.md and this plan.",
    "Run every checked-in Bitcoin, Ethereum and NFT offline verifier before proposing changes.",
    "Perform DOI-only cold restoration of the core repository and both external annex DOI records.",
    "Compare current GitHub main against checkpoint v4 source baseline ba34564c579d645a5a1595f0538223e0e957155e and produce an explicit delta report.",
    "Separate cryptographic proof defects from preservation, discovery, dependency and presentation improvements.",
    "Change proof or commitment bytes only when a reproduced defect or material new evidence requires it.",
    "Publish a new immutable DOI version only after all material changes pass fail-closed tests and public cold restore.",
    "Consider one exact Arweave mirror of the newly selected stable DOI capsule only after fresh owner cost authorization and public readback verification."
  ],
  "material_refresh_criteria": [
    "proof coverage or verifier rejection semantics materially improve",
    "new evidence objects are explicitly authorized and cryptographically bound",
    "offline verification becomes more independently reproducible",
    "long-term dependency artifacts and hashes are added",
    "a recovery drill identifies a reproducible gap",
    "machine discovery or relationship topology is materially corrected"
  ],
  "not_material_by_itself": [
    "a newer AI model exists",
    "cosmetic wording changes",
    "GitHub main has a later commit SHA",
    "a mirror URL changes without a payload-identity change"
  ],
  "deferred_improvements": [
    {
      "id": "long_term_verifier_dependencies",
      "status": "optional_future_hardening",
      "work": "Preserve the minimum Python wheel/sdist dependency set with SHA-256 values and a documented blank-machine bootstrap path."
    },
    {
      "id": "future_full_evidence_reaudit",
      "status": "scheduled_review",
      "work": "Use later verification capability to re-audit Bitcoin, Ethereum and NFT fail-closed semantics against real witnesses and adversarial mutations."
    },
    {
      "id": "final_core_arweave_mirror",
      "status": "intentionally_deferred",
      "work": "If later authorized, upload one deterministic archive of the selected stable DOI capsule, record its exact byte length and SHA-256, and verify public readback before registering the txid."
    }
  ],
  "authorization_boundary": {
    "read_only_audit_and_local_test_improvements_do_not_authorize_external_writes": true,
    "new_zenodo_publication_requires_fresh_owner_authorization": true,
    "paid_arweave_upload_requires_fresh_owner_authorization_and_cost_cap": true,
    "canonical_authority_or_governance_changes_require_explicit_owner_direction": true,
    "future_agents_must_not_use_repository_credentials_outside_existing_guarded_workflows": true,
    "latest_zenodo_authorization": "sequence_4_checkpoint_published_verified_and_consumed"
  },
  "canonical_authority": "Bitcoin Originals only",
  "non_amending_boundary": true,
  "not_instruction_override": true,
  "source_digest_algorithm": "sha256(canonical_json_without_source_digest)",
  "source_digest": "34fb339d1e16b536",
  "limitations": [
    "This plan records repository maintenance intent and does not amend the Bitcoin Originals.",
    "Dates and cost observations are planning checkpoints, not automatic authorization or guarantees of future service availability."
  ],
  "does_not_prove": [
    "future AI systems will necessarily be stronger",
    "all storage providers will remain available",
    "a future evidence refresh is required",
    "Arweave publication has been authorized or completed",
    "philosophical truth or independent institutional endorsement"
  ]
}
