Pranav Bhave

Film · 34 seconds · silent

What the Seal Proves

Two byte-different receipts can canonicalize to one digest-bound representation after parse → canonicalize → digest, so a verifying seal identifies an execution only up to that pipeline's kernel; and even a verified seal establishes nothing about whether the governed action was safe, authorized, or correct.

Read the argumentDownload MP4First published here 2026-09-02

The argument in text

The film's toy pipeline maps the byte strings {"amount": 1.0, "to": "acct-7"} and {"to": "acct-7", "amount": 1} — whose raw SHA-256 digests differ — to one canonical string {"amount":1,"to":"acct-7"} with SHA-256 2cdfe08c…; and, per the registered non-claim of GA-001, a verifying receipt does not establish that the governed action was safe, authorized, or semantically correct.

The digests are real SHA-256 values over exactly the bytes shown, computed by scripts/films/bind_facts.py with the film's own toy canonicalizer (sort keys, whole-valued floats become ints). They illustrate the kernel idea and are not Ghost-Ark's canonicalizer, corpus, or measurements. The boundary sentence is quoted verbatim from claims.yaml (GA-001 non_claims). Ghost-Ark is cited at its bound commit and nothing is built on it (its licence is unstated; commercial_reuse unknown is terminal).

What this does not establish

  • not a statement about any deployed receipt system, and not a measurement of Ghost-Ark's canonicalizer or corpus
  • the toy canonicalizer is the film's; nothing here is built on the lab repository, whose licence is unstated
  • kernel collisions in real canonicalizers are shown as possible, not prevalent
  • verifier acceptance is never treated here as evidence of semantic safety, authorization, or correctness

What would require a correction

sha256 of the shown raw bytes A and B are equal, or sha256 of the canonical bytes differs from the value on screen (recomputable with any SHA-256 tool); or the bound thesis no longer states soundness as a ternary relation over the whole parse → canonicalize → digest pipeline (GA-001, NARROW); or the registry's GA-001 non-claim no longer reads as quoted, in which case bind_facts.py --check fails before a re-render.

Read the supporting record: GA-001.

Sources and render record

Film manifest · Render receipt · First site deployment record

Current render: 2026-09-15. The receipt records the rendered inputs and output hash. It checks provenance, not scientific validity.