RAB-1 · frozen reproducible result

Runtime authority after uncertain consequences.

EvidenceBound Runtime Authority Benchmark on NVIDIA OpenShell tests whether recovery authority and trusted operation-lineage constraints remain enforceable at an independent pre-effect HTTP boundary immediately before a consequential side effect.

FULL_PASSProtocol v1.0.0Stock OpenShell v0.1.2Exact-tag regenerated
System under test

Independent runtime enforcement substrate

RAB-1 composes EvidenceBound authority semantics with stock NVIDIA OpenShell as an independent runtime enforcement substrate. The target is synthetic and non-idempotent: every accepted target contact creates a new consequence.

agent / sandbox request ↓ NVIDIA OpenShell Supervisor Middleware HTTP_REQUEST / PRE_CREDENTIALS ↓ EvidenceBound authority middleware ↓ ALLOW / DENY ↓ synthetic non-idempotent consequential target
Controlled comparison

Same runtime. Same target. One authority layer changed.

Negative control: the same OpenShell runtime, network policy and target without EvidenceBound authority middleware. After an uncertain original consequence and retry, the control produced two target contacts and two consequences.

Controlled condition: the same OpenShell runtime and target with EvidenceBound authority middleware attached fail-closed.

12/12 hard gates

All precommitted hard gates passed in the frozen empirical result.

8/8 frozen scenarios

All frozen negative/control scenarios satisfied the precommitted verifier.

0 DENY → target contacts

No middleware-denied request ID appeared in target-contact evidence.

Authority conditions

Recovery authority is not inferred from retry intent.

Uncertain outcome

Replay and replacement attempts after uncertain consequences are distinguished from fresh authority.

Revocation and lineage

Revoked, already-claimed, or wrong-lineage authority cannot create a replacement consequence.

Authorized recovery

After externally adjudicated NOT_COMMITTED and a fresh recovery grant, one replacement consequence is allowed.

Concurrent replay

Two concurrent attempts using the same operation authority produce one ALLOW and one target consequence.

Selective preservation

Blocking or revoking one lineage does not invalidate an unrelated valid authority.

Independent verifier

The verdict is computed from retained raw evidence by a verifier that does not import the runtime authority implementation.

Reproducibility

Frozen identities and exact-tag regeneration.

AnchorFrozen value
OpenShell releasev0.1.2
OpenShell source commit6648bd0c290efbc41ba131ee9831ee45cd431f94
Execution tagrab1-v1-full-pass-20260930
Execution SHA5f4948894e0af6cb4a39f3823a400313c76d366b
Exact-tag regenerationGitHub Actions run 36759924096
Retained regeneration artifact73 retained files
Evidence manifest0 evidence hash failures
Core scenario recordsByte-identical to frozen primary
Methodology integrity. A prior controlled attempt failed two hard gates and was retained. The frozen oracle, protocol, scenario expectations and verifier were not changed after that failure; the runtime harness was corrected and rerun, then independently regenerated from the exact execution tag.
Permitted external claim

Evidence-scoped claim boundary.

EvidenceBound demonstrated outcome-aware recovery authority and trusted operation-lineage enforcement at the OpenShell pre-effect HTTP boundary under the tested benchmark conditions.
Not claimed. RAB-1 does not establish universal agent safety, exactly-once execution, production correctness, distributed recovery correctness, EU regulatory-reasoning accuracy, superiority over OpenShell, or NVIDIA validation or endorsement. Independent blinded practitioner review is in progress and is separate from the frozen benchmark verdict.
NVIDIA logo
Tested on / enforced through NVIDIA OpenShellIndependent EvidenceBound research. NVIDIA and OpenShell identifiers are used only to identify the tested runtime technology; this is not NVIDIA validation or endorsement.