Manifest receipt

Locked & verifiable.

An evaluation claim anchored to a SHA-256 hash at the recorded time. Anyone can re-derive it from the canonical bytes below.

SHA-256f38e1825ae4f7ba7e6469026f054503bb6dfe0f0f3bdcb70d8af0053261de8b7
Registered2026-09-22T14:57:40.168Z
Independent timestampRFC 3161 · 2026-09-22T14:57:40Z · timestamp.sigstore.dev · token
Transparency logRekor v2 · log2025-1.rekor.sigstore.dev · index 120937972 · inclusion proof
KindPRML manifest — conformed to the published v0.1 schema at commit time
Manifest
# Revision after the phase 4.1 pilot: one translated query was corrected, so the
# dataset bytes (and hash) changed. Metric, comparator, threshold and seed are
# unchanged. The reason and approval are recorded in deviation-2026-09-22.md;
# v1 stays on record — a revision never edits a locked manifest, it adds one.
version: prml/0.1
claim_id: 01a0c98f-d00d-79b2-8fdd-90a8b40d574d
created_at: '2026-09-22T14:40:40Z'
metric: instruction_set_accuracy
comparator: '>='
threshold: 0.85
dataset:
  id: cphos-en-sample-v2
  hash: e4c01b52f9853a32142a484d1c4b7fe12cf740fec094353d839e05a0b7547bb0
seed: 7
producer:
  id: falsify.dev/examples/prep-eval
raw bytes →
Amendment chain1 manifest — not amended · full chain →
README badge
PRML locked[![PRML locked](https://registry.falsify.dev/badge/f38e1825ae4f7ba7e6469026f054503bb6dfe0f0f3bdcb70d8af0053261de8b7.svg)](https://registry.falsify.dev/f38e1825ae4f7ba7e6469026f054503bb6dfe0f0f3bdcb70d8af0053261de8b7)
Verify in CI
- uses: studio-11-co/prml-verify-action@v2 with: mode: verdict expected-hash: f38e1825ae4f7ba7e6469026f054503bb6dfe0f0f3bdcb70d8af0053261de8b7github.com/studio-11-co/prml-verify-action →

share on x →

Verify this hash yourself

Paste your manifest YAML. The canonical hash must match f38e1825ae4f…. This runs the registry's own canonicalization module (canonical.js) in your browser; for verification that does not trust this registry at all, use any of the four reference implementations offline.

Verify the independent timestamp (RFC 3161, offline)

The token countersigns this manifest hash with the timestamp authority's key, so the time claim no longer rests on this registry. Verify with OpenSSL 3 (LibreSSL, the macOS default, cannot check the ESS extension):

curl -sO https://registry.falsify.dev/f38e1825ae4f7ba7e6469026f054503bb6dfe0f0f3bdcb70d8af0053261de8b7.tsr
curl -s https://timestamp.sigstore.dev/api/v1/timestamp/certchain -o chain.pem
awk 'split_after==1{n++;split_after=0} /END CERTIFICATE/{split_after=1} {print > ("tsa-" n ".pem")}' n=0 chain.pem
openssl ts -verify -digest f38e1825ae4f7ba7e6469026f054503bb6dfe0f0f3bdcb70d8af0053261de8b7 \
  -in f38e1825ae4f7ba7e6469026f054503bb6dfe0f0f3bdcb70d8af0053261de8b7.tsr -CAfile tsa-1.pem -untrusted tsa-0.pem

Expected output: Verification: OK.

What this receipt proves — and what it does not

PRML v0.2 is a frozen RFC (comment window closed 2026-05-22) — spec.falsify.dev/v0.2-rfc. Editor: spec.falsify.dev/editor.