Skip to content

About

Fail-closed scientific verification and provenance system for reproducible cloud-quantum experiments

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Algorithm R8

עברית / Hebrew

R8 Verification System — the “R8 Truth Machine”

Algorithm R8 is the public name of the R8 Verification System, a fail-closed scientific verification and provenance system for reproducible cloud-quantum experiments. “R8 Truth Machine” is a plain-language metaphor for the system’s purpose: it tests whether an experimental claim is supported by the exact frozen contract, execution record, raw evidence, and analysis that the claim requires. It is not a human lie detector and it does not make scientific truth automatic.

R8 is designed around four commitments:

  1. Verification — reject incomplete, inconsistent, or unbound evidence.
  2. Reconstruction — retain enough machine-readable material to repeat the offline computation and inspect every transformation.
  3. Frozen experimental contracts — preregister circuits, stages, statistics, gates, claim boundaries, and hashes before a relevant run.
  4. Fair comparison — preserve controls, independent-job structure, postselection accounting, error gates, and prespecified statistical rules.

The primary contribution of this release is the verification system itself. The defensible summary is “we built and exercised an auditable verification system”, not “we proved that a physical model is true.”

Scientific scope and claim boundary

The R8 research program studies postselected-teleportation and noisy P-CTC-inspired protocols, including a fixed binary one-use strategy connected to the Ji–Lloyd–Wilde framework. The code also contains historical and exploratory work used to develop, stress, and audit that program.

This release does not, by itself, establish any of the following:

  • physical P-CTCs;
  • retrocausality or future-to-past signaling;
  • optimal or asymptotic channel capacity;
  • recovery of a private key before its required input exists;
  • a break of RSA, PKCS #8, or any other cryptosystem;
  • correctness of a physical theory merely because software tests pass; or
  • endorsement, validation, or certification by IBM.

The narrow R8 model claim is defined by the frozen machine-readable contracts and research protocols. Per-file and per-stage evidence remains authoritative over narrative summaries. Exploratory R9 material and historical v6 material must not be relabeled as confirmatory R8 evidence.

Recorded experiment status at the release cut-off

The frozen R8 confirmatory plan contains 12 independent MAIN jobs and four calibration checkpoints, totaling 16 provider stages and 622,592 planned shots. The preserved live guard records six completed stages: CAL_MAIN_BEFORE, MAIN_BLOCK_1 through MAIN_BLOCK_4, and CAL_MAIN_MID_1, totaling 245,760 shots.

The first four MAIN blocks have a positive exploratory Bell-versus-collider direction, but four jobs are below the frozen 12-job inferential unit. The one-sided 4/4 sign direction gives p=0.0625, above the frozen 0.025 alpha. CAL_MAIN_MID_1 then failed its frozen hardware/calibration gates. No later MAIN blocks and no final A+B certificate are present. The confirmatory result is therefore incomplete and INDETERMINATE, not a positive or negative physical verdict.

The 20-qubit Kingston spatial panel is a separate R9 exploratory diagnostic: four five-qubit spatial replicas and a matched solo baseline were evaluated inside one provider job. Its baseline-region noninferiority estimate was approximately −0.22 percentage points, with a 95% interval from −1.44 to +0.93 percentage points against a −3 point margin. All spatial regions and the solo arm nevertheless failed the absolute truth-table gate, and confirmatory_main_authorized=false. It cannot support a claim of general 20-qubit coherence immunity or absence of crosstalk.

See docs/STATUS.md for the release status statement and docs/CODE_AUDIT.md for the code-audit record.

Release identity

  • Scientific name: R8 Verification System
  • Public name: Algorithm R8
  • Descriptive name: R8 Truth Machine
  • Release: 1.0.2
  • Release date: 2026-07-30
  • Author and project creator: Netanel Siboni
  • Repository: https://github.com/netanelsibonis/algorithm-r8-quantum-truth-machine
  • Python distribution: algorithm-r8
  • Compatibility import package: pctc_ibm_pilot
  • Software license: AGPL-3.0-only
  • Data/artifact license: CC BY-NC 4.0

The public, secret-free IBM-pilot pytest baseline is:

1262 passed, 10 deselected, 4 warnings

The ten deselected cases are real-disk Job-1 HMAC-authentication tests. They require three historical symmetric HMAC authentication keys that are deliberately not published, because releasing them would permit new HMACs to be forged. The trusted-custodian full baseline, run with those three keys available outside the release, is 1272 passed, 4 warnings. Both results validate tested software behavior; neither is a physical-science result or a substitute for evidence verification. Public CI also runs seven permission-normalizer regression tests, 181 independent simulation tests, static checks, and the release verifier.

Canonical repository map

The following paths are canonical for this release:

Path Role
software/ibm-pilot/ Active Python implementation, tests, scripts, deployment templates, and retained development artifacts
software/ibm-pilot/src/pctc_ibm_pilot/ Importable implementation
software/ibm-pilot/tests/ Main automated test suite
software/ibm-pilot/artifacts/r8-fixed-local/ Canonical fixed local R8 bundle and source contract
research/design/ Research protocols, amendments, gates, and audits
research/notes/ Literature and mathematical-physics audits
research/sources/ Source inventory and original research brief
research/simulations/ Independent offline simulation package and validation artifacts
evidence/live-r8-frozen/ Curated target-specific freeze and compatibility evidence
evidence/live-r8-campaign/ Curated live-campaign receipts, attestations, and evidence records
provenance/deployed-runtime-without-venv/ Preserved deployed runtime source, templates, and release hashes, without its virtual environment
provenance/historical-staging/ Inactive historical staging and compatibility material
provenance/original-docs/ Unmodified or preserved earlier documentation
manifests/ Release-level inventories and integrity manifests
docs/ Current architecture and reproducibility guidance

Historical directories are retained to support audit and provenance. Their presence does not make them active execution candidates. Files whose names contain VOID, historical, staging, exploratory, or an earlier version label must be interpreted according to that status.

The deployed-runtime RELEASE.SHA256SUMS is the original 3,993-entry installed manifest; 3,902 venv/ entries are deliberately absent from the public snapshot. Its local README records the exact retained/missing counts. Ten other historical manifests likewise name 11 deliberately redacted authorization/key files. These manifests are preserved, not rewritten; see manifests/HISTORICAL_MANIFEST_REDACTIONS.json. The release-level manifests are the authoritative verification surface for the sanitized publication.

Quick start: offline software validation

The supported reference platform is 64-bit Linux with Python 3.13.

python3 tools/prepare_public_test_tree.py
cd software/ibm-pilot
python3.13 -m venv .venv
.venv/bin/python -m pip install --upgrade pip
.venv/bin/python -m pip install -r requirements.lock
.venv/bin/python -m pip install -e . --no-deps
.venv/bin/python -m pytest -q -m "not private_evidence_keys"
.venv/bin/python -m compileall -q src tests scripts
.venv/bin/python -m pip check

The preparation command changes permissions only. Git cannot represent the 0700 directory and 0600 file modes required by the fail-closed artifact loaders, so the command normalizes the complete local artifact tree to those strict modes after checkout without changing bytes.

Installation and testing are offline with respect to IBM Quantum. Dependency installation may contact the configured Python package index unless packages have already been mirrored or cached.

For the independent simulation package:

cd research/simulations
python3.13 -m venv .venv
.venv/bin/python -m pip install --upgrade pip
.venv/bin/python -m pip install -r requirements.lock
.venv/bin/python -m pip install -e . --no-deps
.venv/bin/python -m pytest -q

See docs/REPRODUCIBILITY.md for the complete procedure and the distinction between byte verification, software reproduction, analysis reproduction, and physical replication.

Offline integrity verification

From the release root, run the canonical verifier:

python tools/verify_release.py

It checks the release records at:

  • manifests/SHA256SUMS
  • manifests/RAW_NPZ_SHA256SUMS
  • manifests/FILE_INVENTORY.json
  • manifests/EXCLUSIONS.json
  • manifests/LICENSES.json

It also verifies the canonical AGPL-3.0-only and CC BY-NC 4.0 legal-code digests, package license metadata, and Netanel Siboni attribution.

The exact .git directory, or a .git worktree control file, is treated as version-control metadata rather than release content. It is ignored by the builder, verifier, and archive tool so an ordinary Git clone verifies against the same manifests as the published archives.

The two primary self-contained R8 hash sets can also be checked directly without an IBM account:

(cd software/ibm-pilot/artifacts/r8-fixed-local \
  && sha256sum -c SHA256SUMS)
(cd evidence/live-r8-frozen/live-freeze \
  && sha256sum -c SHA256SUMS)

A successful hash check establishes byte identity only. It does not independently authenticate the original provider, prove the interpretation of the data, or strengthen the frozen claim boundary.

Architecture and safety model

R8 separates:

  1. research design and preregistration;
  2. deterministic local construction;
  3. read-only target inspection and target-specific freezing;
  4. explicit authorization;
  5. one-stage-at-a-time submission;
  6. retrieval-only collection;
  7. strict evidence loading and analysis; and
  8. immutable publication and provenance.

Submission is intentionally not part of the normal offline workflow. Credentials, account identifiers, approval secrets, HMAC keys, target private material, and live authorization capsules are not public research inputs and must never be inferred from source code or environment-variable presence.

See docs/ARCHITECTURE.md and SECURITY.md.

Support matrix

Component Supported reference Status
Operating system 64-bit Linux Supported and tested reference
Python CPython 3.13 Required by package metadata
Qiskit 2.5.1 Locked reference
Qiskit Aer 0.17.2 Locked test/offline reference
Qiskit IBM Runtime 0.48.0 Locked compatibility reference; no IBM affiliation implied
NumPy 2.5.1 Locked reference
SciPy 1.18.0 Locked reference
pytest 9.0.3 Locked test reference
GNU sha256sum GNU/Linux-compatible Used by documented integrity checks
OpenSSL CLI Linux deployment path Required by selected private-key challenge paths
systemd, Unix sockets, memfd_create Linux only Required by operational isolation paths
macOS Not validated Offline portions may work; no support claim
Windows Not validated Operational paths are not portable
IBM QPU execution Not enabled by this release Requires separate credentials, authority, budget, and fresh target checks

Authorship, IBM notice, and citation

The author and project creator is Netanel Siboni. IBM, IBM Quantum, Qiskit, and related names may appear because IBM infrastructure and software interfaces were used or targeted. IBM did not author this release, and no IBM endorsement, certification, partnership, or validation is claimed.

Use CITATION.cff or codemeta.json when citing the software.

Author background and related technical work: NetanelAI.

Licensing

Copyright © 2026 Netanel Siboni / נתנאל סיבוני.

This release uses two explicit licenses:

  • Software: GNU Affero General Public License, version 3 only (AGPL-3.0-only). See LICENSE.
  • Data and artifacts: Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0). This covers first-party NPZ/NPY data, QPY circuits, receipts, evidence, provenance, integrity manifests, and research documentation. See LICENSE-DATA.

LICENSE-SCOPE.md is the authoritative map for mixed and historical directories. AGPL-covered code may be used commercially subject to the AGPL, including its network-source requirement. CC BY-NC-covered data and artifacts require attribution to Netanel Siboni, identification of changes, and noncommercial use. Third-party material remains under its own terms. A machine-readable map is available at manifests/LICENSES.json.

See also NOTICE and CONTRIBUTING.md.

About

Fail-closed scientific verification and provenance system for reproducible cloud-quantum experiments

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages