Ghost-Ark, a verifier for the provenance limits of receipts
Ghost-Ark is a verifier and measurement harness for the provenance limits of AI-governance receipts — a research artifact of the S2 Lab, Penn State — whose stated thesis is that receipt soundness is a ternary relation Sound(C, Σ, P): a receipt identifies an execution only up to the kernel of its whole parse → canonicalize → digest pipeline, so soundness does not persist by default as the pathology alphabet grows or the consumer set widens.
01Falsifier — what changes this claim
A source-level review of the bound thesis shows that it does not state soundness as a ternary relation over the whole parse → canonicalize → digest pipeline, or does not identify Ghost-Ark as the stated S2 Lab research artifact.
Consequence NARROW
This is the condition and consequence recorded in the registry. The vocabulary this is published in defines what each consequence commits the author to.
02Scope
The repository README and thesis document at the bound commit.
03Forbidden rescues
Repairs declared unavailable in advance; using one after a failure would breach the recorded commitment.
do not replace a whole-pipeline claim with a canonicalizer-only claim after the condition fires
do not treat verifier acceptance or a pathology-free sample as evidence of semantic safety, authorization, or correctness
04Non-claims — what this does not license
a verifying receipt does not establish that the governed action was safe, authorized, or semantically correct
kernel collisions in real canonicalizers are demonstrated as possible, not as prevalent — the repository's E12 sample found 0 of 64 real payloads carrying any pathology class
not hardened for deployment; not post-quantum secure
05Binding and freshness
Binding
00_THESIS.md @ 98c90d82 Re-worded 2026-08-23 to track the bound thesis precisely: soundness as a ternary relation, and the kernel as a property of the whole pipeline rather than of the canonicalizer alone.
Reviewed
2026-08-24 · window 120 days
Expires
2026-12-22 — after this date the recorded review is overdue; this does not make the claim false
Triggers
executable fires when the thesis document on the default branch changes
Dimensions
visibilityPublicprovenanceLab repository, publicsupport roleDocumentmaturityIn development