Algorithm R8 is the public name of the R8 Verification System, a fail-closed scientific verification and provenance system for reproducible cloud-quantum experiments. “R8 Truth Machine” is a plain-language metaphor for the system’s purpose: it tests whether an experimental claim is supported by the exact frozen contract, execution record, raw evidence, and analysis that the claim requires. It is not a human lie detector and it does not make scientific truth automatic.
R8 is designed around four commitments:
- Verification — reject incomplete, inconsistent, or unbound evidence.
- Reconstruction — retain enough machine-readable material to repeat the offline computation and inspect every transformation.
- Frozen experimental contracts — preregister circuits, stages, statistics, gates, claim boundaries, and hashes before a relevant run.
- Fair comparison — preserve controls, independent-job structure, postselection accounting, error gates, and prespecified statistical rules.
The primary contribution of this release is the verification system itself. The defensible summary is “we built and exercised an auditable verification system”, not “we proved that a physical model is true.”
The R8 research program studies postselected-teleportation and noisy P-CTC-inspired protocols, including a fixed binary one-use strategy connected to the Ji–Lloyd–Wilde framework. The code also contains historical and exploratory work used to develop, stress, and audit that program.
This release does not, by itself, establish any of the following:
- physical P-CTCs;
- retrocausality or future-to-past signaling;
- optimal or asymptotic channel capacity;
- recovery of a private key before its required input exists;
- a break of RSA, PKCS #8, or any other cryptosystem;
- correctness of a physical theory merely because software tests pass; or
- endorsement, validation, or certification by IBM.
The narrow R8 model claim is defined by the frozen machine-readable contracts and research protocols. Per-file and per-stage evidence remains authoritative over narrative summaries. Exploratory R9 material and historical v6 material must not be relabeled as confirmatory R8 evidence.
The frozen R8 confirmatory plan contains 12 independent MAIN jobs and four
calibration checkpoints, totaling 16 provider stages and 622,592 planned
shots. The preserved live guard records six completed stages:
CAL_MAIN_BEFORE, MAIN_BLOCK_1 through MAIN_BLOCK_4, and
CAL_MAIN_MID_1, totaling 245,760 shots.
The first four MAIN blocks have a positive exploratory Bell-versus-collider
direction, but four jobs are below the frozen 12-job inferential unit. The
one-sided 4/4 sign direction gives p=0.0625, above the frozen 0.025 alpha.
CAL_MAIN_MID_1 then failed its frozen hardware/calibration gates. No later
MAIN blocks and no final A+B certificate are present. The confirmatory result
is therefore incomplete and INDETERMINATE, not a positive or negative
physical verdict.
The 20-qubit Kingston spatial panel is a separate R9 exploratory diagnostic:
four five-qubit spatial replicas and a matched solo baseline were evaluated
inside one provider job. Its baseline-region noninferiority estimate was
approximately −0.22 percentage points, with a 95% interval from −1.44 to
+0.93 percentage points against a −3 point margin. All spatial regions and
the solo arm nevertheless failed the absolute truth-table gate, and
confirmatory_main_authorized=false. It cannot support a claim of general
20-qubit coherence immunity or absence of crosstalk.
See docs/STATUS.md for the release status statement and
docs/CODE_AUDIT.md for the code-audit record.
- Scientific name: R8 Verification System
- Public name: Algorithm R8
- Descriptive name: R8 Truth Machine
- Release: 1.0.2
- Release date: 2026-07-30
- Author and project creator: Netanel Siboni
- Repository: https://github.com/netanelsibonis/algorithm-r8-quantum-truth-machine
- Python distribution:
algorithm-r8 - Compatibility import package:
pctc_ibm_pilot - Software license:
AGPL-3.0-only - Data/artifact license:
CC BY-NC 4.0
The public, secret-free IBM-pilot pytest baseline is:
1262 passed, 10 deselected, 4 warnings
The ten deselected cases are real-disk Job-1 HMAC-authentication tests. They
require three historical symmetric HMAC authentication keys that are
deliberately not published, because releasing them would permit new HMACs to
be forged. The trusted-custodian full baseline, run with those three keys
available outside the release, is 1272 passed, 4 warnings.
Both results validate tested software behavior; neither is a physical-science
result or a substitute for evidence verification.
Public CI also runs seven permission-normalizer regression tests, 181
independent simulation tests, static checks, and the release verifier.
The following paths are canonical for this release:
| Path | Role |
|---|---|
software/ibm-pilot/ |
Active Python implementation, tests, scripts, deployment templates, and retained development artifacts |
software/ibm-pilot/src/pctc_ibm_pilot/ |
Importable implementation |
software/ibm-pilot/tests/ |
Main automated test suite |
software/ibm-pilot/artifacts/r8-fixed-local/ |
Canonical fixed local R8 bundle and source contract |
research/design/ |
Research protocols, amendments, gates, and audits |
research/notes/ |
Literature and mathematical-physics audits |
research/sources/ |
Source inventory and original research brief |
research/simulations/ |
Independent offline simulation package and validation artifacts |
evidence/live-r8-frozen/ |
Curated target-specific freeze and compatibility evidence |
evidence/live-r8-campaign/ |
Curated live-campaign receipts, attestations, and evidence records |
provenance/deployed-runtime-without-venv/ |
Preserved deployed runtime source, templates, and release hashes, without its virtual environment |
provenance/historical-staging/ |
Inactive historical staging and compatibility material |
provenance/original-docs/ |
Unmodified or preserved earlier documentation |
manifests/ |
Release-level inventories and integrity manifests |
docs/ |
Current architecture and reproducibility guidance |
Historical directories are retained to support audit and provenance. Their
presence does not make them active execution candidates. Files whose names
contain VOID, historical, staging, exploratory, or an earlier version
label must be interpreted according to that status.
The deployed-runtime RELEASE.SHA256SUMS is the original 3,993-entry
installed manifest; 3,902 venv/ entries are deliberately absent from the
public snapshot. Its local README records the exact retained/missing counts.
Ten other historical manifests likewise name 11 deliberately redacted
authorization/key files. These manifests are preserved, not rewritten; see
manifests/HISTORICAL_MANIFEST_REDACTIONS.json. The release-level manifests
are the authoritative verification surface for the sanitized publication.
The supported reference platform is 64-bit Linux with Python 3.13.
python3 tools/prepare_public_test_tree.py
cd software/ibm-pilot
python3.13 -m venv .venv
.venv/bin/python -m pip install --upgrade pip
.venv/bin/python -m pip install -r requirements.lock
.venv/bin/python -m pip install -e . --no-deps
.venv/bin/python -m pytest -q -m "not private_evidence_keys"
.venv/bin/python -m compileall -q src tests scripts
.venv/bin/python -m pip checkThe preparation command changes permissions only. Git cannot represent the
0700 directory and 0600 file modes required by the fail-closed artifact
loaders, so the command normalizes the complete local artifact tree to those
strict modes after checkout without changing bytes.
Installation and testing are offline with respect to IBM Quantum. Dependency installation may contact the configured Python package index unless packages have already been mirrored or cached.
For the independent simulation package:
cd research/simulations
python3.13 -m venv .venv
.venv/bin/python -m pip install --upgrade pip
.venv/bin/python -m pip install -r requirements.lock
.venv/bin/python -m pip install -e . --no-deps
.venv/bin/python -m pytest -qSee docs/REPRODUCIBILITY.md for the complete
procedure and the distinction between byte verification, software
reproduction, analysis reproduction, and physical replication.
From the release root, run the canonical verifier:
python tools/verify_release.pyIt checks the release records at:
manifests/SHA256SUMSmanifests/RAW_NPZ_SHA256SUMSmanifests/FILE_INVENTORY.jsonmanifests/EXCLUSIONS.jsonmanifests/LICENSES.json
It also verifies the canonical AGPL-3.0-only and CC BY-NC 4.0 legal-code digests, package license metadata, and Netanel Siboni attribution.
The exact .git directory, or a .git worktree control file, is treated as
version-control metadata rather than release content. It is ignored by the
builder, verifier, and archive tool so an ordinary Git clone verifies against
the same manifests as the published archives.
The two primary self-contained R8 hash sets can also be checked directly without an IBM account:
(cd software/ibm-pilot/artifacts/r8-fixed-local \
&& sha256sum -c SHA256SUMS)
(cd evidence/live-r8-frozen/live-freeze \
&& sha256sum -c SHA256SUMS)A successful hash check establishes byte identity only. It does not independently authenticate the original provider, prove the interpretation of the data, or strengthen the frozen claim boundary.
R8 separates:
- research design and preregistration;
- deterministic local construction;
- read-only target inspection and target-specific freezing;
- explicit authorization;
- one-stage-at-a-time submission;
- retrieval-only collection;
- strict evidence loading and analysis; and
- immutable publication and provenance.
Submission is intentionally not part of the normal offline workflow. Credentials, account identifiers, approval secrets, HMAC keys, target private material, and live authorization capsules are not public research inputs and must never be inferred from source code or environment-variable presence.
See docs/ARCHITECTURE.md and
SECURITY.md.
| Component | Supported reference | Status |
|---|---|---|
| Operating system | 64-bit Linux | Supported and tested reference |
| Python | CPython 3.13 | Required by package metadata |
| Qiskit | 2.5.1 | Locked reference |
| Qiskit Aer | 0.17.2 | Locked test/offline reference |
| Qiskit IBM Runtime | 0.48.0 | Locked compatibility reference; no IBM affiliation implied |
| NumPy | 2.5.1 | Locked reference |
| SciPy | 1.18.0 | Locked reference |
| pytest | 9.0.3 | Locked test reference |
GNU sha256sum |
GNU/Linux-compatible | Used by documented integrity checks |
| OpenSSL CLI | Linux deployment path | Required by selected private-key challenge paths |
systemd, Unix sockets, memfd_create |
Linux only | Required by operational isolation paths |
| macOS | Not validated | Offline portions may work; no support claim |
| Windows | Not validated | Operational paths are not portable |
| IBM QPU execution | Not enabled by this release | Requires separate credentials, authority, budget, and fresh target checks |
The author and project creator is Netanel Siboni. IBM, IBM Quantum, Qiskit, and related names may appear because IBM infrastructure and software interfaces were used or targeted. IBM did not author this release, and no IBM endorsement, certification, partnership, or validation is claimed.
Use CITATION.cff or codemeta.json when
citing the software.
Author background and related technical work: NetanelAI.
Copyright © 2026 Netanel Siboni / נתנאל סיבוני.
This release uses two explicit licenses:
- Software: GNU Affero General Public License, version 3 only
(
AGPL-3.0-only). SeeLICENSE. - Data and artifacts: Creative Commons
Attribution-NonCommercial 4.0 International (
CC BY-NC 4.0). This covers first-party NPZ/NPY data, QPY circuits, receipts, evidence, provenance, integrity manifests, and research documentation. SeeLICENSE-DATA.
LICENSE-SCOPE.md is the authoritative map for mixed and
historical directories. AGPL-covered code may be used commercially subject to
the AGPL, including its network-source requirement. CC BY-NC-covered data and
artifacts require attribution to Netanel Siboni, identification of changes,
and noncommercial use. Third-party material remains under its own terms. A
machine-readable map is available at
manifests/LICENSES.json.
See also NOTICE and CONTRIBUTING.md.