SIGNED TELEMETRY ROOT ENVELOPE · 0.2-RE1 + 0.2-REB1

A digest of what?
Now it is exact.

Every witnessed root can resolve to one canonical envelope, and the batch verifier now reconstructs the exact cross-deployment collection used by independent witnesses and certification. Raw signed telemetry and key manifests stay local.

1VERIFIED EVENT PREFIX
1PRIOR ROOT LINK
24HMAX SERIES CADENCE
0EVENT UPLOADS
01 / TRANSITIVE COMMITMENT

Tail binds prefix.
Root binds tail.

Each signed event hashes its predecessor. RE1 re-verifies that chain, hashes the canonical prefix and key manifest, then hashes the complete envelope without its own digest field. Changing any included event, identity, key, count, boundary, tail, or prior root changes the commitment.

01Verify prefix

Every event shape, sequence, hash link, Ed25519 signature, and key-lifecycle boundary must pass 0.2-T1.

verifyTelemetry(prefix, keyManifest)
02Bind boundary

The root records the exact due time and latest accepted event at or before that boundary, including zero-event windows.

tail.occurred_at ≤ covers_through_at
03Reproduce collection

REB1 verifies every deployment, classifies failures, and emits the same canonical root projection and digest consumed by RC1.

SHA-256(RC1 root collection)
02 / CANONICAL ENVELOPE

Small document.
Complete binding.

The root includes only aggregate identifiers and cryptographic commitments. Raw event evidence remains local. The environment identity is hashed; the complete prefix and frozen key manifest receive separate canonical digests for independent reproduction.

ROOT DIGEST SCOPERFC 8785
root_commitment_sha256 = SHA-256(JCS({
  deployment + hashed environment,
  root ordinal + coverage boundary,
  cumulative + interval event counts,
  genesis + signed chain tail,
  canonical prefix digest,
  frozen key-manifest digest,
  previous root commitment
}))
NO SELF-REFERENCESHA-256
03 / CREATE + VERIFY BATCH

One module.
Every due root.

Create or verify one envelope, reconstruct one complete cadence series, or verify all deployments as one certification batch. Missing roots, invalid envelopes, changed keys or prefixes, broken chains, shifted cadence, duplicate environments, and root-collection drift fail deterministically.

CI / NODE 22+LOCAL ONLY
node wanted-root-envelope.mjs \
  --create events.jsonl key-manifest.json 0 \
  2026-08-29T18:00:00.000Z

node wanted-root-envelope.mjs \
  --verify-series roots.json events.jsonl key-manifest.json \
  ACTIVATION_AT OBSERVATION_END_AT 24

node wanted-root-envelope.mjs --verify-batch batch.json

node wanted-root-envelope.mjs --conformance-batch \
  root-envelope-conformance-vectors.json
CREATE · VERIFY · SERIES · BATCH · CONFORMANCEEXIT 0 / 1 / 2