# Verifying the current release before valuable funds **Aurion 0.2.1 remains blocked for real-funds readiness.** The active desktop and seed validators accept plot proofs recomputed from public inputs without storing the claimed plot, and a producer's proof choice influences the next challenge. Custom finite-capacity WOTS/Merkle signatures, legacy recovery limitations, missing independent audits and unqualified independent operation remain open. Improved wallet, backup and deployment code does not resolve these protocol risks. ## Run the offline verifier From the full source checkout, using existing Python and Node installations: ```sh python3 scripts/check_readiness.py --output /tmp/aurion-readiness-new.json python3 scripts/check_readiness.py --run-local-tests --output /tmp/aurion-local-checks-new.json ``` Choose a **new** output filename each time. The verifier refuses existing files, symlinks and symlink ancestors and writes a mode-0600 report. It does not overwrite wallets or backups. Exit **1** is the expected blocked-readiness result, including when every local test passes. There is no readiness override or activation mode. The default command runs the actual protocol probes; the second also runs both complete local test suites. Neither command commissions services, contacts auditors, recruits operators, deploys code or starts a mainnet node. Use a quiet checkout with no concurrent edits. Before/after fingerprints cannot detect every transient rewrite. Place reports outside public source directories. The report binds the observations to hashes of listed public source, tests and scope documents. It checks unchanged coin/seed/genesis pins, computes the actual published genesis from both validators, and rejects source drift during the run. Those pins identify the known experimental protocol; they are **not** independent approval of its security. The published genesis remains `4f3347fd386cf267163dc329bd9781ef61b2915927507646d31c2584b977000d`. The attack reproduction uses disposable publicly derived keys and two in-memory regtest validators. Each accepts a declared 4,294,967,295-entry plot without a plot file, then accepts two proof choices producing different next challenges. The report records accepted checkpoint IDs, balances and challenge values. These are reproduced failures, not passing security tests. No production keys, funded wallet, live database, deployed endpoint or mainnet state is accessed. Separate deterministic internal review also found arrival-order-dependent fork choice beyond the 100-checkpoint reorganization boundary: offering the same signed checkpoint set in two orders left one node at height 101/weight 641 and the other at height 1/weight 218,003. The late heavier branch was rejected as beyond the reorg limit. This is a further unresolved convergence risk, not proof of finality. The default verifier reproduces the two storage/challenge attacks above; it does not claim to rerun that separate arrival-order experiment. ## Read local results accurately Fresh test results are separate from readiness. The complete-suite option records actual Node/Python counts, exit status, failures, errors and skips. JavaScript files with registered tests run directly with TAP case summaries, avoiding a wrapper result that hides nested skips. Three reviewed assertion-only scripts (`cloud-http`, `market-http` and `swaps`) instead report process completion with `counts: null`. Their completion does not independently prove that every intended assertion ran; no observed skip markers does not prove complete coverage. Generated ZIP/checksum downloads can be rebuilt by tests; their final hashes are inventoried separately from executable source/test inputs. The generated public `site/verification.json` is also excluded to avoid making a report depend on its own bytes; it cannot override any readiness gate. Missing dependencies, sandbox-blocked checks, timeouts and skipped native checks remain visible. A skipped proof-of-space test does not verify its native dependency. Controller fixtures do not establish real browser crash durability; local Python execution does not verify native Windows, Cloudflare Workers or a deployed node. Tests use the repository's current environment; the verifier does not install dependencies or establish their independent provenance. Historical counts in `site/readiness.json` and previous qualification JSON files are untrusted earlier-run claims, not fresh test observations. Changing their booleans, gate labels or reviewer names cannot override an active-protocol flaw. A source hash, signature or successful checklist can authenticate limited bytes or metadata; it cannot establish the truth, competence or independence behind an audit or operator claim. This script does not authenticate external evidence. ## Evidence still required All six conditions apply to the **same** candidate specification, source, dependencies, deployed protocol and preserved chain history: | Condition | Evidence required before a readiness statement | | --- | --- | | Storage-enforcing consensus | Complete challenge/timing/weight/fork-choice specification and independent analysis; measured recomputation, compression, grinding, withholding and hostile-bootstrap attacks; cross-runtime rejection vectors. | | Standard signatures | Reviewed production integration and library/backend provenance, cross-runtime vectors, bounded verification and a versioned migration. The isolated ML-DSA-65 and chiapos candidates do not satisfy this. | | Signing, rotation and recovery | Crash/restore/copy/concurrency/expiry/exhaustion tests and reviewed migration/recovery rules. Previously reused keys and unknown signing history cannot be repaired by a local index reset. | | Independent audits | Externally authenticated reviewers with relevant cryptography/consensus expertise, disclosed relationships, exact reviewed scope/hashes, findings and independent remediation retests. No unresolved critical/high findings; exclusions and residual risks remain public or in an authorized verifiable summary. | | Adversarial recovery | Reproducible hostile-network, partition, reorganization, resource-exhaustion and clean-room restore campaigns with seeds/raw measurements, supported runtime/resource bounds, and independently reproduced results. | | Independent operation | Consenting separately administered operators, exact releases/genesis and independently observed sustained chain progress; dated founder-seed/provider outage, partition/rejoin, upgrade and backup-restore exercises. Separate cloud accounts or matching endpoints alone do not establish independence or economic security. | See [SECURITY.md](SECURITY.md), [PROTOCOL_UPGRADE.md](PROTOCOL_UPGRADE.md), [AUDIT_SCOPE.md](AUDIT_SCOPE.md) and [NODE_OPERATIONS.md](NODE_OPERATIONS.md). A deterministic local multi-node harness remains internal engineering evidence: several objects or processes under one administrator are not an independent network, and simulated elapsed time is not observed public uptime. ## Preserve existing funds and history This verifier neither changes genesis nor rewrites balances, plots, signing journals or production Durable Object namespaces. It does not inspect or certify the recovery of actual funded user data. Follow [UPDATE_AND_RECOVERY.md](UPDATE_AND_RECOVERY.md), preserve originals, and verify a candidate replay in isolation before any separately authorized migration. A code rollback does not rewind ledger data or make an already consumed signing slot safe. Unknown legacy signing history remains a reason to stop fresh signing. ## No new personal spending These local checks request no paid services. Existing hardware, electricity, dependency downloads and AI-platform use are not promised free. No sponsor, grant, donated audit, independent operator or production funding is secured by this work. External review and independent operations can require personal spending only if separately authorized; the current instruction authorizes none. A zero-new-personal-spend completion is possible only if qualified third parties actually supply or fund the missing work. It does not lower the evidence gates and cannot promise immediate certification or an audit award.