Evidence Backup Gaps and Cautions

Summary

No critical backup gap is currently identified.

The major evidence families have Bitcoin / OTS / manifest coverage, Arweave availability, GitHub repository mirrors, GitHub Release mirrors, or a combination of these with SHA-256 based verification paths.

The legacy homepage audit now also provides exact GitHub mirrors for the historical homepage AR payload, the previously missing small Arweave objects, and the missing Ethereum non-NFT calldata.

Gaps / Cautions

Item Severity Description Recommended Action
OTS not local-node/fullnode independent Medium OTS proof is complete and Bitcoin-anchored, but not yet verified through local Bitcoin Core / pruned-node RPC Run local-node OTS verification when available
OTS bundle v1 not fully self-contained Low / Medium OTS bundle contains proof artifacts and records, but client-level verification may still require original digest-manifest.json/csv from repository or another mirror Optional OTS bundle v2 including original timestamped files
Release asset count ambiguity Low GitHub pages include source archives, causing asset count to differ from custom evidence asset count Always report custom evidence assets separately
Guardian Attestation terminology Low It may be mistaken as part of the three canonical originals Always describe it as Bitcoin-inscribed non-amending fortification
ETH witness count terminology Low authority.jcs.json records 7 items while verification-report confirms 8/8 including Guardianship Principles v1.1 Use “ETH witness verification: 8/8 PASS”
Legacy homepage external pointer coverage Resolved / maintain The dedicated registries enumerate 35 Arweave records, 10 Ethereum non-NFT records, and IPFS pointers. The exact historical homepage AR payload, the two missing small AR payloads, and four isolated ETH calldata objects are now mirrored. Maintain LEGACY-POINTER-COVERAGE.md, archive/legacy-pointers/index.json, and their automated hash checks
Authority v1.0.2 hash semantics Resolved The exact 9,174-byte JCS payload is deterministically reconstructed from the preserved pretty source; its SHA-256 7d6a... and SHA3-256 3144... match the EIP-712 signed values and the checked-in 2026-05-08 Arweave readback Keep scripts/rebuild_authority_v1_0_2_canon.py in the trust-root gate
Arweave/GitHub authority confusion Medium Mirrors may be mistaken for canonical authority Repeat boundary statement in all summary docs
Large payload repository risk Low Videos and large CAR/ZIP payloads should not be committed to the repository tree when verified Release mirrors exist Keep large payloads in Arweave and GitHub Releases only
Gateway availability for large ZIPs Medium → Resolved arweave.net returned 404 for large flaw archive ZIPs ✅ Resolved: GitHub Release flaw-covenant-archive-accessibility-mirror-v1 created as non-amending accessibility mirror

Not Considered Gaps

The following are not evidence-chain failures:

Optional Hardening Tasks

  1. Create OTS proof bundle v2 with:
    • digest-manifest.json
    • digest-manifest.csv
    • digest-manifest.json.ots
    • digest-manifest.csv.ots
    • verify-report.json
    • verify-report.json.ots
    • checksums and manifest
  2. Run fullnode-independent OTS verification using:
    • local Bitcoin Core
    • or pruned-node RPC
    • and record result separately

Final Gap Determination

Current status:

Critical gaps: none identified
Major payload backup gaps: none identified
Audited legacy homepage / small AR raw-payload gaps: resolved
Audited Ethereum non-NFT raw-calldata gaps: resolved
Documentation mapping: completed; maintain periodically
Remaining work: verification semantics and optional hardening
Evidence amendment risk: controlled by existing boundary statements