OpenChainGraph · Explainer 7 steps and one dated snapshot

The cross-machine determinism attestation

Six report runs from four physical machines re-ran this estate's kernels at pinned commits and compared output digests fixture by fixture. This page walks the attestation they produced and shows how to re-derive every number from the public repository.

Presenter mode shows one step per screen. Arrow keys move, A toggles autoplay, Esc exits.
Every number on this page is quoted from data/determinism-attestation.json in the public repository, an in-toto Statement v1 emitted as a dated snapshot with generated_at 2026-09-29T11:59:19.482Z. Nothing on the page is fetched at run time.
Part one · The question and the fleet

The question and the machines

The first three steps set up the comparison before any result is read.

1
Step 1 · The question

The question the attestation answers

A kernel here is a small pure function with published fixtures, and every answer it emits carries a SHA-256 digest. The question this page answers: when the same kernel runs on a different physical machine, does the digest come out the same?

Same-machine checks run on every change to the estate. The class they cannot reach is the physical one. A different CPU, OS build, Node build, ICU or libm can in principle turn the same input bytes into a different answer, and only another machine can test for that.

The answer is organised as one attestation document that carries every machine's report beside every kernel's digest, so a reader can recompute the agreement count instead of trusting a summary. This page quotes the snapshot generated 2026-09-29T11:59:19.482Z, and the commands in step 6 re-derive its counts from the file itself.

data/determinism-attestation.jsonpredicateType ainumbers.co/determinism-attestation/v1_type https://in-toto.io/Statement/v1
2
Step 2 · The fleet

Six report runs cover four machines

The snapshot carries six attestor entries from four machines across four buses, and each entry is one report run that named itself. The msi bus had contributed no golden-hash report when the snapshot was generated.

BusMachineNode buildReport pinModeFinished (UTC)Signature
ainumbers-farm-aspireaceraspire3v22.23.2 win32 x64499af64ff53511cb76685473e99874c0108da0f9kernel2026-09-13unsigned
ainumbers-farm-nitroLAPTOP-LGRIHR14v22.23.2 win32 x6427a3ef5e2abe44345f28f455e99ff8330de42470kernel2026-09-12unsigned
ainumbers-farm-psDESKTOP-RT8F7U4v24.19.0 win32 x647ba5b0660fb86f6f8b8dcc80911bdd439541378dvector2026-09-12unsigned
ainumbers-farm-psDESKTOP-RT8F7U4v24.19.0 win32 x64a6c14a89b8de1b81e3417b23cf2e776f998e00ffkernel2026-09-11unsigned
ainumbers-farmcmtusv24.13.0 win32 x64615bd9e8ca1cf5092b6700c6ee806aa1cecec359vector2026-09-12unsigned
ainumbers-farmcmtusv24.13.0 win32 x64090958e52587229b36265157580623d4e5c92a47md-only2026-09-11unsigned

The snapshot records what each run reported about itself: a machine name, a Node build, the commit pin the report was produced at and a signature status. The physical spread (CPU, OS build, Node build, ICU, libm) is exactly what the comparison exercises, and the fleet's three Node builds are what make an agreement informative.

predicate.attestors[]predicate.summary.machines = 4predicate.summary.attestor_runs = 6
3
Step 3 · The recipe

The same fixtures and a pinned commit

Two runs are only comparable when the bytes going in match. Every report ran the repository at the commit it pinned, exercised the same published fixtures, and hashed each kernel's outputs with SHA-256. A kernel is marked agree when every report that exercised it recorded the same digest.

one kernel same published fixtures pinned commit per report SHA-256 of every output aceraspire3v22.23.2 win32 x64 LAPTOP-LGRIHR14v22.23.2 win32 x64 DESKTOP-RT8F7U4v24.19.0 win32 x64 cmtusv24.13.0 win32 x64 d8e4bba9… d8e4bba9… d8e4bba9… d8e4bba9… d8e4bba9… identical

The digest compared is the newest vector-0 golden each report recorded for the kernel, and predicate.kernels[tool_id].golden_hashes keeps every pin's observation beside its vector index, so an older run stays auditable after a later pin moves the golden. The agreement counts published in the snapshot were recomputed from those per-report evidence records before the file shipped.

predicate.kernels[].golden_hashes[]predicate.verifier
Part two · What came back

The result and the exceptions

The next two steps read the result out of the snapshot, one exception class at a time.

4
Step 4 · The result

The agree class holds 646 kernels

Independent re-execution agreed across this snapshot. On every kernel marked agree, the runs that exercised it recorded no mismatch, and the DISAGREE list is empty. Of the 646 agree kernels, 525 were exercised by all six report runs.

RunModeKernels exercisedKernels agreedKernel mismatchesVectors checkedVectors matchedThrew
ainumbers-farm-aspire · 2026-09-13kernel6476470n/an/a0
ainumbers-farm-nitro · 2026-09-12kernel66365013n/an/a3
ainumbers-farm-ps · 2026-09-11kernel64763512n/an/a3
ainumbers-farm-ps · 2026-09-12vector541526151,7641,7201
ainumbers-farm · 2026-09-12vector54153651,7641,7570
ainumbers-farm · 2026-09-11md-only6416410n/an/a0

The nitro bus's cross-machine run recorded 13 mismatched kernels and 3 throws, and the farm bus's all-vectors run matched 1,757 of 1,764 vectors. Every mismatched kernel in the table lands in a named class in the next step. A mismatch that no rule explained would have been classed DISAGREE, and that class is empty, as is same_pin_divergences.

One reconciliation is recorded beside the counts. The cmtus cross-machine report was aggregated from its markdown alone, and one of its declared skips could not be attributed to a named kernel, so it sits outside the machines-total for the kernels it touches. Agreement counts can only be understated by that choice.

predicate.summary.agree = 646predicate.summary.DISAGREE = 0predicate.summary.same_pin_divergences = 0predicate.reconciliation_notes[]
5
Step 5 · The exceptions

Every recorded mismatch has a named cause

17 of the 663 kernels sit outside the byte-agreement claim. Each one landed in a class decided by rule, and each rule names the reason the recorded difference is something other than one machine disagreeing with another.

mismatched kernels 17 records witness-boundcaller-held salt (OCG §25)5 async-sentinelserialized unawaited Promise2 methodologythe tasking's literal recipe10 fixture-driftnone found0 DISAGREEa determinism finding would land here0 empty in this snapshot
ClassKernelsThe ruleWhat the recorded difference is
witness-bound5the kernel's graph node declares ocg-private-input@1 at the report's own pinthe caller holds an input salt (OCG §25), so each machine hashed the witness it was handed
async-sentinel2the mismatch evidence is the async-dispatch sentinel shapea serialized unawaited Promise on the recorded key path, an artifact of the call path
methodology10the report carries the recipe marker and reproduces the kernel same-machine through the canonical buildArtifact entrythe difference came from the tasking's literal recipe, and the same machine reproduces the canonical result
fixture-drift0a fixture whose stored bytes fail their own golden self-hashnone found in this snapshot
DISAGREE0same pin, same fixture, a different live hash, and no exclusion classempty here. The aggregator refuses to publish a DISAGREE kernel silently, so one would have stopped this snapshot from shipping at all

The class members in this snapshot: art-413, art-414, art-415, art-529 and art-548 are witness-bound. art-124 and art-424 are async-sentinel. The methodology class holds art-55, art-332, art-350, art-353, art-359, art-377, art-649, art-655, art-658 and art-659.

predicate.exclusion_rulespredicate.meta_sourcepredicate.kernels[].class
Part three · Reading it honestly

The claim and its boundary

The last two steps are about trust: who signs, and where the claim ends.

6
Step 6 · Signatures and the check

Signatures and the check you can run

The attestation is an in-toto Statement v1 with 663 subjects, one per kernel, each carrying its digest, and six attestor entries beside them. The pattern is reproducible builds applied to execution. Independent rebuilders compare digests on one artifact, and here the artifact is a run.

The signing lane gives every machine its own key. A report is signed with ssh-keygen -Y sign in the ainumbers-attest namespace, the public half is committed to its bus, and the aggregator verifies each signature against the committed keys before marking the report signed, unsigned or BAD-SIG. A BAD-SIG report is excluded from the counts and named in predicate.excluded_reports. In this snapshot every report is unsigned, the table in step 2 names that status on every row, and no report is excluded.

statement v1 _type in-toto Statement subject 663 kernels attestors 6 entries per kernel machines_agreeing machines_total aspire nitro ps (all vectors) ps (cross-machine) farm (all vectors) farm (md-only) the k-of-n check, per kernel count the reports that exercised it compare every recorded digest recomputed from the evidence records 646 kernels in the agree class independent re-execution agreed every report in this snapshot is unsigned (step 2 names each row)

Re-derive the counts yourself

  1. Clone the public repository. git clone https://github.com/PostOakLabs/ainumbers puts data/determinism-attestation.json and its integrity test on your machine.
  2. Count the subjects. jq '.subject | length' data/determinism-attestation.json prints 663.
  3. Count the agree class. jq '[.predicate.kernels[] | select(.class == "agree")] | length' data/determinism-attestation.json prints 646.
  4. Run the integrity gate. node --test scripts/determinism-attestation.test.mjs recomputes every kernel's machines_agreeing and machines_total from the per-report evidence records, and it fails the moment a DISAGREE-class kernel appears.
Prompt at this stepverify the statement
Fetch data/determinism-attestation.json from https://github.com/PostOakLabs/ainumbers and report: how many subjects it carries, how many kernels are marked agree, which kernels sit outside that class, and whether any DISAGREE kernel exists.
scripts/determinism-attestation.test.mjspredicate.excluded_reports = []
7
Step 7 · The boundary

What the claim covers

The snapshot supports one sentence: independent re-execution agreed at the pinned commits, on the machines named in step 2, for the kernels marked agree.

Reading the boundary is part of reading the result. The claim is about execution agreement. Deciding that the kernel logic itself is correct is the job formal verification already does elsewhere, and the formal-verification process explainer walks that evidence. The fleet covers the machines it names, and a machine class that none of the four represents is not covered by this snapshot. The reports behind it are unsigned today; step 2 names that status on every row, and the signing lane in step 6 is how a future snapshot closes it.

🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.