P363 · Tool use

Evidence Bound to the Same Stable Bytes

Ensure measurements, sizes and digests in an evidence bundle describe the same stable source content.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

A video receipt records digest, byte count and duration. The teaching source is replaced from A to B during collection. Hashing A and probing B creates a complete-looking receipt that describes no single consistent content version.

Mechanism

Acquire a stable snapshot in a controlled environment, recording source identity and checking regular-file/path requirements. Compute size, SHA-256 and media measurements on that same snapshot. If source correspondence during collection is required, check mutation during copying and probing and recollect on conflict. Associate measurements by digest and require repeated references to agree on duration. Validate manifests against actual artifacts; retain failure reasons rather than deleting evidence to force acceptance.

Bad example

Hash source A for the video receipt. After replacement, probe B's duration and publish both as verified evidence.

Good example

Collect digest, size and duration from one controlled snapshot and record source identity. Reject and recollect if the source changes or verification disagrees. Reject conflicting durations for the same digest too. Report verification scope without turning byte agreement into a claim of correct video content.

Why the change matters

A digest binds content identity; duration and size must belong to that identity as well. Individually successful measurements remain invalid when combined across versions. A stable snapshot gives collection a common object.

Observable expectation

Teaching check: snapshot A records digest-A, size 1000 and 10 seconds; another reference to that digest must also say 10 seconds. A12-second reference conflicts. Simulated source replacement during collection yields no valid receipt. Recheck output size and digest against the manifest. Numbers and digest labels are illustrative.

Limits

Hash agreement does not establish meaning, trustworthy origin, safe execution or permission. Before/after hashes cannot exclude all adversarial intermediate mutations; snapshots and identity protection depend on platform capabilities. The frozen implementation’s open flags are not cross-platform guarantees; verify equivalent mechanisms when porting.

Sources and evidence

Read the editorial criteria