Real route authority
The current proof branch exercises the real /v1/exec consequence boundary with bounded capability leases and Biscuit authority. Invalid authority, wrong executor, mutated intent and inactive mounts are rejected.
Veklom's proof surface separates live reachability, authority enforcement, lifecycle behavior and consequence establishment. The current evidence supports a real governed execution path across persistent and ephemeral capability contexts. It does not yet support calling every runtime or every consequence independently proven.
Sealed bundles from the P2-HOST and VDB-MOBILITY-P1 programs. Hashes are computed over the served bytes at request time; compare them against your own download to verify bit-for-bit.
| Bundle | Program | File | Status | Bytes | SHA-256 |
|---|---|---|---|---|---|
| Bound evidence A | P2-HOST | bound_evidence_5982badd-7c48-4ea4-bbd8-79ccce295a2c.json | Present | 16216 | 4e660bdf1ac96154197db3305db0ce908d74272bcd21ed19ecb89668be984c6d |
| Bound evidence B | P2-HOST | bound_evidence_5737342f-1504-44aa-93f4-3fcd38383c5a.json | Present | 15251 | bd1e1faf4e004daf25a48ff0543d9689eaad85dee416909beed62ccab1f9da82 |
| Mobility P1 evidence | VDB-MOBILITY-P1 | mobility_p1_evidence_19579c43.json | Present | 8326 | 9b1c2afc54430b9d4ac9f579dddb0a423db0473580a76d7f7e8569efb4ab8424 |
Bundle parsed: 4 top-level fields
Bundle parsed: 4 top-level fields
Bundle parsed: 14 top-level fields
This distinction matters. The proof supports bounded authority across the actual execution route and a shared persistent/ephemeral contract. It does not yet prove real multi-hypervisor materialization or universal consequence truth.
The current proof branch exercises the real /v1/exec consequence boundary with bounded capability leases and Biscuit authority. Invalid authority, wrong executor, mutated intent and inactive mounts are rejected.
Persistent-service and ephemeral execution token types are both represented in the capability-mount contract and can traverse the same governed execution route. Lifecycle policy differs; bounded authority remains explicit.
Execution context is workspace-bound. A capability mounted to one workspace is not valid in another authenticated workspace. This is an authority boundary, not a UI convention.
The Activation path can re-observe durable target state directly. Executor-stage uncertainty is now recorded as OUTCOME_UNCERTAIN rather than relabeled as success or denial, but generic provider execution still needs independent consequence establishment before it is called proven.
A real HTTP execution path is dominated by capability lease checks, scoped authority and a common governed execution handler.
Persistent and ephemeral execution modes can share the same capability/authority contract shape while carrying different lifecycle semantics.
Workspace scope mismatch, invalid/incorrect authority, mutated action intent and inactive capability context can fail closed.
Revocation state on the execution route is sourced from persisted CapabilityLease and ExecutionIdentity records: a revoked, expired or suspended lease, a revoked execution identity, or a stale revocation epoch fails closed.
Authority minted for one execution cannot be presented for another: the Biscuit execution identity is bound to the lease execution identity, and a caller cannot choose the persisted run identity.
Executor-stage provider failure is reported as OUTCOME_UNCERTAIN with durable evidence and no automatic re-execution; pre-execution denials keep their own distinct codes.
Two simultaneous identical requests yield exactly one admitted consequence: the mount nonce is consumed by an atomic conditional update before any allow evidence exists; the loser is denied as token_replay.
Wasmtime and Firecracker are not yet established as real interchangeable execution substrates under the same Veklom contract.
Generic executor success is not yet equivalent to independently established business consequence.
Cross-provider production-scale governed compute, host-compromise resistance and hardware isolation remain outside the current proof.
People should be able to enter the current Capability OS, inspect available capabilities, use the surfaces that are already wired, and connect existing systems through VLink as those routes are brought online. Early access should expose what exists rather than hiding it behind a future-state promise.