Skip to content

Current as of 2026-08-23

Bulla 0.49.2 is the released product.

The published package creates and verifies ActionReceipt 0.2 files, applies a supplied receiver policy, and reconciles receipts against a supplied action record. Repository-source profiles are listed separately below.

Inspect supporting evidence →

Status files and deployment limits

reproducible snapshot: status.json · sources.json (input digests) · Bulla release lineage · deployed-output binding is NOT_COMPUTED · public withdrawal record · historical receipt registry

Deployment-receipt generation, public release, and attestation remain BLOCKED_UNIMPLEMENTED.

Package

Bulla 0.49.2, recorded from current PyPI evidence.

Format

ActionReceipt 0.2, the normative receipt format.

Receiver decisions

Verification and a supplied RELY, REFUSE, or ESCALATE policy remain separate operations.

Coverage

A separately supplied receiver record provides the action list used for reconciliation.

Source profiles

15 experimental profiles remain outside the installed package contract.

SurfacePublic state
BullaPublished Python package 0.49.2
ActionReceipt v0.2Normative stable format
ActionReceipt v0.3Non-normative released draft
ActionReceipt v0.4Opt-in experimental draft
Answerability profilesRepository-source research profiles

Evidence still needed

I and r below belong to the Answerability Network profile. W is the independent-witness ledger; D belongs to the stable receiver-reliance path. Both intakes are open at zero. None is a total assembled across unrelated profiles.

Independent implementation

I0

Answerability Network profile; supplied-checker replays do not increment I.

Independent implementation → I

Independent witness

W0

Intake open; organizations under separate control count once, and the project-controlled exercise remains NOT_COUNTED.

Operate an independent witness

External replay

r0

Answerability Network profile; counted under the external-replay rule below.

Replay candidate → r

External reliance decision

D0

Intake open; candidate packets are not counted until signed qualification and head records merge.

External reliance candidate → possible D
Technical capability ledger
CapabilityMaturityAvailabilityEstablishedNot establishedExternal A/J/I/W/D
ActionReceiptreleasedPYPI RELEASEDPortable ActionReceipt v0.2 records, canonical hashing, cryptographic verification, and reference vectors.

released implementation and reproducible fixtures

The worldly truth of the recorded claim or occurrence of the underlying event.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE

0/0/0/0/0 · r0
Authority and scopereleased-draftPYPI RELEASEDOpt-in v0.3 implementation binds issuer authorization, delegation, and structured scope checks.

released draft with local conformance fixtures

The legality, legitimacy, or institutional sufficiency of the authored authority policy.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE

0/0/0/0/ · r0
Strict receipt ingestionreleased-draftPYPI RELEASEDA single byte-oriented parser rejects duplicate members, non-finite values, off-schema closed objects, and declared size, depth, node, and string limits before cryptographic verification.

published in Bulla 0.44.4 with internal adversarial fixtures

Independent hostile-input review or immunity to every parser implementation defect.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE

0/0/0/0/ · r0
ActionReceipt v0.4 occurrence bindingreleased-draftPYPI RELEASEDThe draft separately authenticates content, one claimed occurrence, and its authority envelope under a portable integer-only canonical data model; Python and Node reference checkers agree on the fixed vector.

opt-in draft published in Bulla 0.44.4 with internal cross-language reference checks

Worldly occurrence, witnessed time, cross-platform independent parity, or promotion over the normative v0.2 default.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE

0/0/0/0/ · r0
Semantic inventionexperimentalPYPI RELEASEDFinite FRSL-1 packages and negative certificates are independently replayable on the captive Golden corpus.

internal captive benchmark

Foreign generality, open-world completeness, or a stable semantic API.

TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · FINITE EXACT

0/0/0/0/ · r0
Partial envelopesexperimentalPYPI RELEASEDChecked RELY and REFUSE regions preserve residual escalation under a declared finite closure warrant.

internal formal and executable evidence

Completeness outside the declared model class or safety under an unmodeled closure expansion.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT

0/0/0/0/ · r0
Semantic FinalityexperimentalPYPI RELEASEDReplayable provisional, reserve, conflict, refinement, finalization, and stale-epoch transitions in a finite shadow model.

internal state-machine and Golden evidence

Production settlement, real custody, collectibility, actuarial value, or institutional efficacy.

TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT

0/0/0/0/ · r0
Claim Flow v0.4experimentalPYPI RELEASEDTyped appraisal, forum, precedent, applicability, and settlement transitions with explicit authority provenance.

internal formal and captive benchmark evidence

External legal validity, foreign applicability judgments, or automatic institutional authority.

TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT

0/0/0/0/ · r0
Generalization Constitution v0.5experimentalSOURCE ONLYCandidate, adoption, and applicability remain separate, with checked finite safe-scope frontiers and effect-laundering controls.

internal formal and captive-control evidence

Foreign transfer, external applicability judgments, or a stable precedent API.

TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT

0/0/0/0/ · r0
Golden Gate qualificationexperimentalPYPI RELEASEDThe finite checker core supports typed abstention and reproducible qualification; benchmark packets add captive mutation, portability, custody, and control evidence.

implemented methods with internal captive evidence

Reviewer-originated results, independent validation, production safety, or open-world completeness.

TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT

0/0/0/0/ · r0
Receipt-coupled dispatchexperimentalSOURCE ONLYThe reference boundary durably commits an authorized intent before external I/O, preserves uncertain outcomes, enforces committed adapter capabilities, and prevents duplicate effects under its captive verified-idempotency contract.

internal exhaustive model, crash fixtures, and captive adapters

Distributed atomicity, production payment safety, external adapter conformance, or nonlocal integration value.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · BOUNDED EXACT

0/0/0/0/ · r0
Agent Incident Packet v0.1experimentalSOURCE ONLYThe source profile requires an exact decision/effect anchor pair for each represented protocol and binds each reported denominator snapshot to a signed checkpoint whose issuer is accepted through external role context. Live timeline and publish receipts use ActionReceipt v0.4 with conventions: []; convention-bearing historical receipts remain opaque evidence artifacts only. Team-operated fixtures also bind non-circular redaction records and accepted reviewer statements, party statements, corrections, and witness evidence without collapsing their verification dimensions.

team-operated deterministic fixtures and isolated localhost HTTP/MCP pilots

A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved. Cross-runtime convention evaluation, denominator completeness, organizational independence, production containment, disclosure safety, external implementation parity, independent witnessing, and incident truth also remain unestablished. The empty-convention rule narrows this experimental profile and does not change ActionReceipt v0.4. An accepted observer can self-shorten rows.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE

0/0/0/0/ · r0
Acceptance Contract alphaexperimentalSOURCE ONLYThree synthetic deployment-handoff bundles retain one staging claim under one precommitted receiver policy. Missing rollback evidence produces HOLD_FOR_EVIDENCE and a conditional request; an accepted PASS produces PROCEED and ELIGIBLE; an accepted FAIL produces REFUSE. Authorization remains NOT_ISSUED and execution remains NOT_ATTEMPTED in every canonical result.

three deterministic bundles, project-authored strict evaluator, hostile mutations, distribution-boundary tests, and a finite abstract model

Deployment occurrence, worldly truth, receiver-record completeness, legal enforceability, production use, organizational independence, or external implementation parity.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT

0/0/0/0/ · r0
Recheckable Inference alphaexperimentalSOURCE ONLYTwo synthetic providers return byte-identical BACKUP artifacts. After both provider processes terminate, the retained, term-bound integer model reproduces one input-to-output relation while the opaque record supplies no model to rerun. Under the separately supplied buyer policy, the first relation is payment-eligible but not authorized or settled; the opaque response is refused. Adding one unmatched receiver effect leaves receipt integrity verified, changes coverage from 1/1 to 1/2, and makes payment ineligible. Project-authored Python, standalone Node, and browser verifiers reproduce these bounded reports.

three deterministic bundles, team-operated localhost roles, project-authored Python, standalone Node, and browser parity, transient hostile mutations, and a finite abstract model

Historical provider execution, answer truth, model quality, complete receiver denominators, payment execution, external implementation parity, organizational independence, custody, collectibility, production clearing, or worldly truth. All roles and evidence remain synthetic and team-controlled.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT

0/0/0/0/ · r0
Bonded witness covenantexperimentalSOURCE ONLYThe source profile verifies an objective same-size log-equivocation predicate, challenge chronology, a dedicated fixture-reported allocation, bounded remedy eligibility, exact authorization, and Test-ledger attempt reporting. Adding the reported bond changes capital and recourse only.

project-authored deterministic fixtures, Python and standalone Node parity, hostile mutations, and finite abstract-model checks

Witness independence, missing-event detection, provider truth, real custody, collectibility, deterrence, actual recovery, production operation, or a witness market.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT

0/0/0/0/ · r0
Answerability NetworkexperimentalSOURCE ONLYThe source profile composes one synthetic inference procurement, a selected ActionReceipt, leaf-bound witnessed history, objective fork handling, bounded recourse, and exact tri-state recall over 10,000 declared decisions. Python, standalone Node, and browser reports agree on six frozen stages.

project-authored deterministic corpus, Python/standalone-Node/browser parity, hostile mutations, generated presentation projection, and finite abstract-model checks

Provider-result truth, complete dependency capture, independent witnessing, real custody, collectibility, dollars moved, production operation, customer activity, or adoption.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT

0/0/0/0/ · r0
Assurance Linker alphaexperimentalSOURCE ONLYAssurance Linker 0.1 deterministically compiles a closed structured promise into explicit evidence, authority, coverage, capital, recourse, and consequence requirements. The additive source-only 0.2 accountability-circuit profile computes five synthetic USD-cent dossiers: signed receipt and receiver bindings, externally supplied witness roots, leaf-bound inclusion, RFC 6962 history consistency, authenticated causal order and adjacent mismatch checkpoints, exact byte equality or mismatch, a pinned challenge state, declared capital allocations, bounded consequence eligibility, exact authorization, and a signed team-operated fixture-attempt report. Python, standalone Node, and the browser kernel deep-equal on canonical reports and protected hostile outcomes. The formal refinement proves mismatch/conformance exclusion plus witnessed ordering, deadline, and recourse guards. The candidate route commits to the presentation and verification source closure. Existing Bitcoin Core 31.1 regtest evidence remains separate and sat-denominated.

team-authored deterministic fixtures, Python/standalone-Node/browser parity, finite abstract-model checks, one prior local Bitcoin Core regtest execution, and team-operated source-only trial and candidate materials

The accountability-circuit candidate has no bound anonymous deployment or reader attempts; comprehension remains NOT_COMPUTED. Trial 0.2-r5 also has no cold-reader calibration, candidate round, or foreign checker attempt. Foreign authorability, independent checker reproduction, external institutional handling, operational separation, marginal decision value, economic adoptability, representative demand, worldly truth, complete observation, external collateral encumbrance, custody, collectibility, legal enforceability, organizational independence, production safety, actual settlement, actuarial calibration, or mainnet readiness remain unestablished. The witness and fixture settlement roles are team-operated. The Bitcoin adapter is optional and does not evaluate predicates or replace the named settlement authority.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT

0/0/0/0/ · r0
Executable recourseexperimentalSOURCE ONLYA local receipt trace can open, acknowledge, evidence, decide, authorize, complete, route, expire, and close a challenge while keeping forum and remedy authority distinct.

internal replay and authority-separation fixtures; reachability captive

A separately controlled forum, operational reachability, institutional efficacy, or automatic enforcement of a semantic finding.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · BOUNDED EXACT

0/0/0/0/ · r0
Precedent compoundingresearchRESEARCH ONLYCompounding was observed in a team-authored, machine-planted, bounded-exact lineage benchmark and survives the declared captive controls.

internal captive observation

Generalized compounding on foreign meanings, independent adjudication, or economic value.

TEAM AUTHORED · MACHINE PLANTED · INTERNAL · BOUNDED EXACT

0/0/0/0/ · r0
Public control-plane alpha candidateexperimentalSOURCE ONLYDeterministic fixtures, source checkers, and local Cloudflare-runtime tests exercise one closed synthetic MCP authorization, receiver, denominator, witness, coverage, and packet-publication loop.

team-authored deterministic fixtures and local Cloudflare-runtime tests

The generated control-plane evidence ledger reports whether a public endpoint has tracked deployment evidence. Customer authority, denominator completeness, organizational independence, production safety, and incident truth remain unestablished.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · BOUNDED EXACT

0/0/0/0/ · r0
Witness pluralityblockedBLOCKEDA local checkpoint and inclusion-proof primitive is specified and tested.

local fixture only

Independent witness operators, plurality, stake, or a production witness network.

TEAM AUTHORED · MACHINE CHECKED · INTERNAL · NOT APPLICABLE

0/0/0/0/ · r0
Risk and insuranceresearchRESEARCH ONLYThe program contains mathematical ambiguity-reserve and worst-case exposure mechanisms under declared finite models.

internal research architecture

Underwriter validation, actuarial calibration, product pricing, or real collateral custody.

TEAM AUTHORED · NOT ADJUDICATED · INTERNAL · BOUNDED EXACT

0/0/0/0/ · r0

A/J/I/W means external authors, adjudicators, independent implementations, and witnesses. D counts qualified outside receiver decisions. r counts external replays of supplied checkers; a replay increments neither I nor D. Internal agents, supplied checkers, and GitHub runners do not increment those counts.

Rules for external-evidence counts

Each counter has one definition, and a counter changes only together with evidence that satisfies it. Canonical source: glyph/data/evidence-contract.json.

Outsider runs supplied checker on supplied artifacts

external replays

Dedicated intake authority qualifies a receiver-signed reliance and boundary package under a signed ledger head

external reliance decisions

Outsider writes a second checker from the specification

implementations

Outsider authors previously unseen cases

authors

Outsider decides contested semantic cases

adjudicators

Separately controlled service retains receipts

witnesses

An external person reproduced the team's supplied procedure on the team's supplied artifacts. It does not establish an independent implementation.

A named intake reviewer accepted one receiver-signed, locally reproducible policy decision and boundary record under the published external-control review rule. Organizational identity as a worldly fact, that the named policy was sound or appropriate, that the provider claim was true, that the receiver acted on the decision, or that any worldly effect occurred.

Run the released path

Install Bulla and create, verify, and reconcile one ActionReceipt locally.

Inspect source profiles

Review experimental protocols, their operating boundaries, and current evidence.