From 453981d30bcbe358dc70c93da9ad2b744e79b815 Mon Sep 17 00:00:00 2001 From: Midia Kiasat Date: Tue, 14 Apr 2026 00:37:23 +0200 Subject: [PATCH 1/2] Normalize VALIDEXOR boundary README and Apache license --- .github/workflows/identity.yml | 2 +- README.md | 224 ++++++++++++++------------------- package.json | 4 +- 3 files changed, 98 insertions(+), 132 deletions(-) diff --git a/.github/workflows/identity.yml b/.github/workflows/identity.yml index 3d49ee6..4388d00 100644 --- a/.github/workflows/identity.yml +++ b/.github/workflows/identity.yml @@ -33,4 +33,4 @@ jobs: grep -q "^Primitive ID: PRIM-005" README.md grep -q "^Package: @verifrax/validexor" README.md grep -q "^Binary: validexor" README.md - python3 -c 'import json, pathlib; d=json.loads(pathlib.Path("package.json").read_text()); assert d["name"]=="@verifrax/validexor"; assert d["version"]=="0.1.0"; assert d["license"]=="MIT"; assert d["bin"]["validexor"]=="validexor.sh"; assert d["repository"]["url"].endswith("Verifrax/validexor.git"); assert d["homepage"]=="https://github.com/Verifrax/validexor#readme"; assert d["bugs"]["url"]=="https://github.com/Verifrax/validexor/issues"; assert d["publishConfig"]["access"]=="public"' + python3 -c 'import json, pathlib; d=json.loads(pathlib.Path("package.json").read_text()); assert d["name"]=="@verifrax/validexor"; assert d["version"]=="0.1.0"; assert d["license"]== "Apache-2.0"; assert d["bin"]["validexor"]=="validexor.sh"; assert d["repository"]["url"].endswith("Verifrax/validexor.git"); assert d["homepage"]=="https://github.com/Verifrax/validexor#readme"; assert d["bugs"]["url"]=="https://github.com/Verifrax/validexor/issues"; assert d["publishConfig"]["access"]=="public"' diff --git a/README.md b/README.md index 8a838cc..ed38e78 100644 --- a/README.md +++ b/README.md @@ -1,12 +1,10 @@ # VALIDEXOR -Primitive ID: PRIM-005 -Package: @verifrax/validexor +Primitive ID: PRIM-005 +Package: @verifrax/validexor Binary: validexor -Verifrax primitive — verification primitive for deterministic irreversible systems. - ---- +VALIDEXOR is the Verifrax validation primitive: the bounded primitive surface for validation and admissibility checking without becoming authored protocol source, authority issuance, governed execution, public verification, proof publication, archive/reference, or intake. ## Proof artifacts @@ -30,146 +28,114 @@ This repository is part of the VERIFRAX proof perimeter. ## Status -Current release status: pre-stable primitive release line. - -Canonical release target: - -package version: 0.1.0 -tag: v0.1.0 - -VALIDEXOR is part of the Verifrax primitive layer and follows the canonical primitive governance, naming, version, and packaging rules. - ---- - -## Purpose - -VALIDEXOR verifies deterministic correctness after origin, custody, time, and boundary conditions have already been fixed. - -Once an artifact has a stable origin, preserved custody, explicit time boundary, and enforced operating boundary, the system still needs deterministic verification of whether the artifact satisfies the relevant contract. VALIDEXOR exists to make that verification explicit, repeatable, and non-ambiguous. - -It does not establish origin. It does not preserve custody. It does not fix temporal order. It does not enforce boundary conditions. It does not witness, judge, or terminate. Its role is narrower: verify contract-level correctness under already-fixed prior conditions. - ---- - -## What This Primitive Does - -- verifies an artifact or state against deterministic validation rules -- distinguishes valid from invalid outcomes under a fixed contract -- emits verification output suitable for downstream attestation and judgment - ---- - -## What This Primitive Does Not Do - -- does not establish first origin -- does not preserve custody continuity -- does not fix temporal ordering -- does not enforce operational boundaries -- does not witness or attest -- does not judge validity -- does not terminate lifecycle - ---- - -## Behavioral Contract - -Invocation model: - -executable: validexor -package: @verifrax/validexor -runtime: CLI-first - -The primitive operates on an artifact whose origin, custody, time, and boundary surfaces are already fixed. - -If the verification contract is absent, ambiguous, or non-deterministic, VALIDEXOR must not fabricate a valid result. +* Surface class: validation primitive +* Repository class: primitive package surface +* Public host ownership: none +* Package: `@verifrax/validexor` +* Binary: `validexor` +* Current repository posture: live primitive boundary +* License: Apache License Version 2.0 + +## Boundary + +This repository owns the validation primitive only. + +It defines bounded validation behavior as a primitive. +It does not author normative source material. +It does not issue authority. +It does not execute governed actions. +It does not verify published material. +It does not publish proof. +It does not serve as archive/reference. +It does not operate intake. +It does not replace adjacent sovereign boundaries. + +## What it does + +- defines the validation primitive for bounded Verifrax use +- keeps primitive behavior inspectable and deterministic +- supports adjacent repositories without claiming system-wide authority +- anchors validation meaning as a primitive boundary + +## What it does not do + +- not authored protocol source; that belongs to VERIFRAX +- not authority issuance; that belongs to AUCTORISEAL +- not governed execution; that belongs to CORPIFORM +- not public verification; that belongs to VERIFRAX-verify +- not proof publication; that belongs to proof +- not archive/reference; that belongs to SIGILLARIUM +- not intake; that belongs to apply +- not constitutional doctrine; that belongs to SYNTAGMARIUM +- not canonical world-state; that belongs to ORBISTIUM +- not reconciliation or repair; that belongs to CONSONORIUM +- not sovereign cognition; that belongs to TACHYRIUM -Exit codes: - -0 — verification completed successfully -non-zero — invocation failed or contract violated - ---- - -## Usage - -Install: - -npm install -g @verifrax/validexor - -Execute: - -validexor artifact.json - -stdin example: - -cat artifact.json | validexor - ---- - -## Determinism Guarantees - -For identical canonical input, VALIDEXOR must produce identical verification output. - -No hidden environmental state may influence the result. - -VALIDEXOR assumes an already-bounded origin, custody, time, and enforcement surface and does not substitute for those earlier primitives or for downstream attestation and judgment. - ---- +## Adjacent sovereign surfaces -## Security Model +- `VERIFRAX` — authored protocol and evidence-root boundary +- `AUCTORISEAL` — authority issuance +- `CORPIFORM` — governed execution +- `VERIFRAX-verify` — public verification +- `proof` — proof publication +- `SIGILLARIUM` — archive/reference +- `apply` — intake -VALIDEXOR protects against ambiguity in contract verification. +VALIDEXOR is a primitive. +It does not become the repositories that consume it. -Its security value is to prevent silent drift between what is claimed to satisfy a contract and what deterministically does satisfy it. It does not itself attest, judge, or terminate lifecycle state. +## Public surface ---- +The public surface of this repository is its repository identity, README boundary, package surface, binary surface, and primitive materials carried by this repository. -## Relationship to Other Primitives +Publication here is not authored source. +Publication here is not authority. +Publication here is not execution. +Publication here is not verification. +Publication here is not proof publication. +Publication here is not archive/reference. +Publication here is not intake. -Canonical primitive order: +## Package / host / repo truth -1 originseal -2 archicustos -3 kairoclasp -4 limenward -5 validexor -6 attestorium -7 irrevocull -8 guillotine +Repository truth for VALIDEXOR lives in this repository. -Repositories: +Package truth for this primitive is `@verifrax/validexor`. +Binary truth for this primitive is `validexor`. +Package, binary, and repository truth are related but not interchangeable. -https://github.com/Verifrax/originseal -https://github.com/Verifrax/archicustos -https://github.com/Verifrax/kairoclasp -https://github.com/Verifrax/limenward -https://github.com/Verifrax/validexor -https://github.com/Verifrax/attestorium -https://github.com/Verifrax/irrevocull -https://github.com/Verifrax/guillotine +## Validation meaning in-system ---- +Validation in-system means the stack can point to VALIDEXOR and say that a bounded validation primitive belongs to this boundary. -## Installation +Validation here validates. +Validation here does not author. +Validation here does not issue authority. +Validation here does not execute. +Validation here does not verify. +Validation here does not publish proof. -npm install -g @verifrax/validexor +That does not by itself mean: -command -v validexor +- the primitive became authored protocol source +- the primitive issued authority +- the primitive executed a governed action +- the primitive verified truth +- the primitive published proof +- the primitive replaced archive/reference +- the primitive replaced intake +- the primitive replaced the evidence-root repository -Repository: -- GitHub: https://github.com/Verifrax/validexor -- Package: @verifrax/validexor -- Binary: validexor +## Not this ---- +VALIDEXOR is not authored protocol source. +VALIDEXOR is not authority issuance. +VALIDEXOR is not governed execution. +VALIDEXOR is not public verification. +VALIDEXOR is not proof publication. +VALIDEXOR is not archive/reference. +VALIDEXOR is not intake. ## License -MIT - -## Adjacent sovereign surfaces - -This repository is part of the Verifrax sovereign stack and remains bounded relative to: - -- **[ANAGNORIUM](https://github.com/Verifrax/ANAGNORIUM)** for terminal recognition -- **[REGRESSORIUM](https://github.com/Verifrax/REGRESSORIUM)** for terminal recourse +Apache License Version 2.0 diff --git a/package.json b/package.json index 2dffc26..6438da7 100644 --- a/package.json +++ b/package.json @@ -1,8 +1,8 @@ { "name": "@verifrax/validexor", "version": "0.1.0", - "description": "Verifrax primitive — verification primitive for deterministic irreversible systems.", - "license": "MIT", + "description": "Verifrax primitive \u2014 verification primitive for deterministic irreversible systems.", + "license": "Apache-2.0", "repository": { "type": "git", "url": "git+https://github.com/Verifrax/validexor.git" From 13deb52e36d7e13d5de7debe31412188a75628d9 Mon Sep 17 00:00:00 2001 From: Midia Kiasat Date: Tue, 14 Apr 2026 09:18:42 +0200 Subject: [PATCH 2/2] Fix validexor Apache license truth --- LICENSE | 82 ++++++++++++++++++++++++++++++++++++++++++--------------- 1 file changed, 61 insertions(+), 21 deletions(-) diff --git a/LICENSE b/LICENSE index c04745e..52b1c27 100644 --- a/LICENSE +++ b/LICENSE @@ -1,21 +1,61 @@ -MIT License - -Copyright (c) 2026 Verifrax - -Permission is hereby granted, free of charge, to any person obtaining a copy -of this software and associated documentation files (the "Software"), to deal -in the Software without restriction, including without limitation the rights -to use, copy, modify, merge, publish, distribute, sublicense, and/or sell -copies of the Software, and to permit persons to whom the Software is -furnished to do so, subject to the following conditions: - -The above copyright notice and this permission notice shall be included in all -copies or substantial portions of the Software. - -THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, -OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE -SOFTWARE. +Apache License +Version 2.0, January 2004 +https://www.apache.org/licenses/ + +TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + +1. Definitions. + +"License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document. + +"Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License. + +"Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. + +"You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License. + +"Source" form shall mean the preferred form for making modifications. + +"Object" form shall mean any form resulting from mechanical transformation of a Source form. + +"Work" shall mean the work of authorship made available under the License. + +"Derivative Works" shall mean any work based on the Work. + +"Contribution" shall mean any work of authorship intentionally submitted for inclusion in the Work. + +"Contributor" shall mean Licensor and any individual or Legal Entity on behalf of whom a Contribution has been received. + +2. Grant of Copyright License. +Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form. + +3. Grant of Patent License. +Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work. + +4. Redistribution. +You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions: + +(a) You must give any other recipients of the Work or Derivative Works a copy of this License; and + +(b) You must cause any modified files to carry prominent notices stating that You changed the files; and + +(c) You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work; and + +(d) If the Work includes a "NOTICE" text file as part of its distribution, then any Derivative Works that You distribute must include a readable copy of the attribution notices contained within such NOTICE file. + +5. Submission of Contributions. +Unless You explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work by You to the Licensor shall be under the terms and conditions of this License. + +6. Trademarks. +This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor. + +7. Disclaimer of Warranty. +Unless required by applicable law or agreed to in writing, Licensor provides the Work on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + +8. Limitation of Liability. +In no event and under no legal theory shall any Contributor be liable to You for damages arising in any way out of the use of the Work. + +9. Accepting Warranty or Additional Liability. +While redistributing the Work or Derivative Works thereof, You may choose to offer support, warranty, indemnity, or other liability obligations consistent with this License. + +END OF TERMS AND CONDITIONS