fall-federate · proof of play

Two nodes, one signed exchange, one payout — checked in your browser.

Not a claim, a re-run. Below, two genuinely independent sovereign identities federate: one asks, the other answers from its own expertise, and the value is settled with a bounded provenance royalty upstream. Every signature is verified here, on your machine, against nothing but the public keys. Then a live version runs over a real WebRTC datachannel. And separately, the estate's mutation gate is run against a real external repo we don't own.

Recorded exchange · re-verify

1 · The signed federation, re-checked from the evidence alone

This exchange was produced cold with real Ed25519 (Node). The bundle below carries the two identities, the contributor's signed lineage, the signed query, the signed answer bound to that query, and the settlement. Press the button — your browser re-verifies every signature with WebCrypto. No secrets, no trust in our machine.

    the raw evidence bundle (open the file)
    loading…

    ../evidence.json — the exact bytes, independently checkable.

    Live · real transport

    2 · Run a fresh federation over a real WebRTC datachannel

    This spins up two independent identities and connects them peer-to-peer over a real WebRTC datachannel (STUN for the public reflexive address — the sovereign way, no relay). One signs a query, sends it over the wire; the other verifies it, answers, signs; the first verifies and settles the payout. All in your browser, live. Same machine here, real transport — a second physical machine/human is the follow-on step (below).

      Proof rail · run against others

      3 · The estate's mutation gate, run against a real repo we don't own

      The same witness gate that proves the estate's own code was run against left-pad — the public package that famously broke npm in 2016 — using its own passing test suite (35 tests). A mutation gate alters one operator at a time and requires the suite to catch it; a survivor means a line the green suite does not actually pin. This is a real, reproducible verdict on code we don't control.

      Reproduce it: git clone https://github.com/left-pad/left-pad && cd left-pad && npm i, then run the estate's witness Action: witness mutate index.js --test node test.js. Result file: ../witness-external.json.

      What this proves — and what still needs a second human

      • ✓Proven cold: two genuinely-independent Ed25519 identities exchange a signed query/answer bound together, settle a bounded provenance payout, and a third party re-verifies it all from the bundle alone. Tamper one byte and it fails (tested).
      • ✓Proven live: the same exchange over a real WebRTC datachannel with a STUN reflexive address — real transport, not a loopback of one key.
      • ✓Proven external: the mutation gate produced a real verdict on a real repo we don't own.
      • ◻Still needs a second human: the live run here is two identities in one browser. The true test is a second person on a different machine. Do it now → /join/: one of you starts a connection and sends an invite blob over Signal, the other pastes it and sends an answer back, and you federate peer-to-peer for real. The mechanism is proven; the remaining step is a willing second operator.
      • ◻Still open (proof rail): merging witness into a real external team's CI (a FAIL on a push to a repo we don't own) needs a willing external maintainer — a warm intro, not a stranger's repo spammed with a PR.