Six report runs from four physical machines re-ran this estate's kernels at pinned commits and compared output digests fixture by fixture. This page walks the attestation they produced and shows how to re-derive every number from the public repository.
data/determinism-attestation.json in the public repository, an in-toto Statement v1 emitted as a dated snapshot with generated_at 2026-09-29T11:59:19.482Z. Nothing on the page is fetched at run time.The first three steps set up the comparison before any result is read.
A kernel here is a small pure function with published fixtures, and every answer it emits carries a SHA-256 digest. The question this page answers: when the same kernel runs on a different physical machine, does the digest come out the same?
Same-machine checks run on every change to the estate. The class they cannot reach is the physical one. A different CPU, OS build, Node build, ICU or libm can in principle turn the same input bytes into a different answer, and only another machine can test for that.
The answer is organised as one attestation document that carries every machine's report beside every kernel's digest, so a reader can recompute the agreement count instead of trusting a summary. This page quotes the snapshot generated 2026-09-29T11:59:19.482Z, and the commands in step 6 re-derive its counts from the file itself.
The snapshot carries six attestor entries from four machines across four buses, and each entry is one report run that named itself. The msi bus had contributed no golden-hash report when the snapshot was generated.
| Bus | Machine | Node build | Report pin | Mode | Finished (UTC) | Signature |
|---|---|---|---|---|---|---|
| ainumbers-farm-aspire | aceraspire3 | v22.23.2 win32 x64 | 499af64ff53511cb76685473e99874c0108da0f9 | kernel | 2026-09-13 | unsigned |
| ainumbers-farm-nitro | LAPTOP-LGRIHR14 | v22.23.2 win32 x64 | 27a3ef5e2abe44345f28f455e99ff8330de42470 | kernel | 2026-09-12 | unsigned |
| ainumbers-farm-ps | DESKTOP-RT8F7U4 | v24.19.0 win32 x64 | 7ba5b0660fb86f6f8b8dcc80911bdd439541378d | vector | 2026-09-12 | unsigned |
| ainumbers-farm-ps | DESKTOP-RT8F7U4 | v24.19.0 win32 x64 | a6c14a89b8de1b81e3417b23cf2e776f998e00ff | kernel | 2026-09-11 | unsigned |
| ainumbers-farm | cmtus | v24.13.0 win32 x64 | 615bd9e8ca1cf5092b6700c6ee806aa1cecec359 | vector | 2026-09-12 | unsigned |
| ainumbers-farm | cmtus | v24.13.0 win32 x64 | 090958e52587229b36265157580623d4e5c92a47 | md-only | 2026-09-11 | unsigned |
The snapshot records what each run reported about itself: a machine name, a Node build, the commit pin the report was produced at and a signature status. The physical spread (CPU, OS build, Node build, ICU, libm) is exactly what the comparison exercises, and the fleet's three Node builds are what make an agreement informative.
Two runs are only comparable when the bytes going in match. Every report ran the repository at the commit it pinned, exercised the same published fixtures, and hashed each kernel's outputs with SHA-256. A kernel is marked agree when every report that exercised it recorded the same digest.
The digest compared is the newest vector-0 golden each report recorded for the kernel, and predicate.kernels[tool_id].golden_hashes keeps every pin's observation beside its vector index, so an older run stays auditable after a later pin moves the golden. The agreement counts published in the snapshot were recomputed from those per-report evidence records before the file shipped.
The next two steps read the result out of the snapshot, one exception class at a time.
Independent re-execution agreed across this snapshot. On every kernel marked agree, the runs that exercised it recorded no mismatch, and the DISAGREE list is empty. Of the 646 agree kernels, 525 were exercised by all six report runs.
| Run | Mode | Kernels exercised | Kernels agreed | Kernel mismatches | Vectors checked | Vectors matched | Threw |
|---|---|---|---|---|---|---|---|
| ainumbers-farm-aspire · 2026-09-13 | kernel | 647 | 647 | 0 | n/a | n/a | 0 |
| ainumbers-farm-nitro · 2026-09-12 | kernel | 663 | 650 | 13 | n/a | n/a | 3 |
| ainumbers-farm-ps · 2026-09-11 | kernel | 647 | 635 | 12 | n/a | n/a | 3 |
| ainumbers-farm-ps · 2026-09-12 | vector | 541 | 526 | 15 | 1,764 | 1,720 | 1 |
| ainumbers-farm · 2026-09-12 | vector | 541 | 536 | 5 | 1,764 | 1,757 | 0 |
| ainumbers-farm · 2026-09-11 | md-only | 641 | 641 | 0 | n/a | n/a | 0 |
The nitro bus's cross-machine run recorded 13 mismatched kernels and 3 throws, and the farm bus's all-vectors run matched 1,757 of 1,764 vectors. Every mismatched kernel in the table lands in a named class in the next step. A mismatch that no rule explained would have been classed DISAGREE, and that class is empty, as is same_pin_divergences.
One reconciliation is recorded beside the counts. The cmtus cross-machine report was aggregated from its markdown alone, and one of its declared skips could not be attributed to a named kernel, so it sits outside the machines-total for the kernels it touches. Agreement counts can only be understated by that choice.
17 of the 663 kernels sit outside the byte-agreement claim. Each one landed in a class decided by rule, and each rule names the reason the recorded difference is something other than one machine disagreeing with another.
| Class | Kernels | The rule | What the recorded difference is |
|---|---|---|---|
| witness-bound | 5 | the kernel's graph node declares ocg-private-input@1 at the report's own pin | the caller holds an input salt (OCG §25), so each machine hashed the witness it was handed |
| async-sentinel | 2 | the mismatch evidence is the async-dispatch sentinel shape | a serialized unawaited Promise on the recorded key path, an artifact of the call path |
| methodology | 10 | the report carries the recipe marker and reproduces the kernel same-machine through the canonical buildArtifact entry | the difference came from the tasking's literal recipe, and the same machine reproduces the canonical result |
| fixture-drift | 0 | a fixture whose stored bytes fail their own golden self-hash | none found in this snapshot |
| DISAGREE | 0 | same pin, same fixture, a different live hash, and no exclusion class | empty here. The aggregator refuses to publish a DISAGREE kernel silently, so one would have stopped this snapshot from shipping at all |
The class members in this snapshot: art-413, art-414, art-415, art-529 and art-548 are witness-bound. art-124 and art-424 are async-sentinel. The methodology class holds art-55, art-332, art-350, art-353, art-359, art-377, art-649, art-655, art-658 and art-659.
The last two steps are about trust: who signs, and where the claim ends.
The attestation is an in-toto Statement v1 with 663 subjects, one per kernel, each carrying its digest, and six attestor entries beside them. The pattern is reproducible builds applied to execution. Independent rebuilders compare digests on one artifact, and here the artifact is a run.
The signing lane gives every machine its own key. A report is signed with ssh-keygen -Y sign in the ainumbers-attest namespace, the public half is committed to its bus, and the aggregator verifies each signature against the committed keys before marking the report signed, unsigned or BAD-SIG. A BAD-SIG report is excluded from the counts and named in predicate.excluded_reports. In this snapshot every report is unsigned, the table in step 2 names that status on every row, and no report is excluded.
git clone https://github.com/PostOakLabs/ainumbers puts data/determinism-attestation.json and its integrity test on your machine.jq '.subject | length' data/determinism-attestation.json prints 663.jq '[.predicate.kernels[] | select(.class == "agree")] | length' data/determinism-attestation.json prints 646.node --test scripts/determinism-attestation.test.mjs recomputes every kernel's machines_agreeing and machines_total from the per-report evidence records, and it fails the moment a DISAGREE-class kernel appears.Fetch data/determinism-attestation.json from https://github.com/PostOakLabs/ainumbers and report: how many subjects it carries, how many kernels are marked agree, which kernels sit outside that class, and whether any DISAGREE kernel exists.
The snapshot supports one sentence: independent re-execution agreed at the pinned commits, on the machines named in step 2, for the kernels marked agree.
Reading the boundary is part of reading the result. The claim is about execution agreement. Deciding that the kernel logic itself is correct is the job formal verification already does elsewhere, and the formal-verification process explainer walks that evidence. The fleet covers the machines it names, and a machine class that none of the four represents is not covered by this snapshot. The reports behind it are unsigned today; step 2 names that status on every row, and the signing lane in step 6 is how a future snapshot closes it.