Not normative · Verdict
GB1 verdict — alignment and range access
This page records why blob extension §28 marks GB1 closed. It is a record of evidence, not part of the specification: it adds no requirement, and the gate’s text on the security page is what it answers to.
1. The gate
Section titled “1. The gate”GB1 alignment and range access: an SOP-BLOB-1 object imported into the transfer layer; a plaintext range served via one verified range request from a non-decrypting holder; decrypt of only the fetched chunks; tamper anywhere in a served range and any chunk tag detected.
2. Where the evidence was read
Section titled “2. Where the evidence was read”- Commit.
af7e168e6e2b574e42549cca1fd6a8195d0254de, ondevelop. Every test named below exists at that commit, and onmain. - Run. CI run 60665, job
Rust Test (sovm workspace), 2026-10-03T01:24Z, stepcargo test (sovm workspace on loopback), which checked out exactly that commit. Every test named below passed in it. None of them is ignored by default, so the same tests run in that job on every merge.
3. The clauses, and the tests that carry each
Section titled “3. The clauses, and the tests that carry each”Every test below except the last row’s lives in the GB1 prototype’s gb1
tests. The prototype is a member of the sovm workspace. It runs against the
transfer layer’s pinned version, so a dependency bump that changes any measured
behavior fails the build.
| Clause | Tests |
|---|---|
| an SOP-BLOB-1 object imported into the transfer layer | an_sop_blob_1_object_imports_under_the_storage_id_the_spec_derives: the identifier the transfer layer assigns on import equals the storage identity the specification derives over the encrypted object |
| a plaintext range served via one verified range request from a non-decrypting holder | one_range_request_moves_exactly_the_chunk_and_nothing_around_it: a holder with no key serves one chunk’s ciphertext span through one verified request, and the bytes moved are exactly that span |
| decrypt of only the fetched chunks | the_reader_decrypts_the_fetched_chunk_and_holds_nothing_else: the reader recovers the requested plaintext from the fetched chunk and holds no other chunk |
| tamper anywhere in a served range detected | a_single_flipped_bit_anywhere_in_a_served_range_fails_verified_streaming: every single-bit flip across a served range is refused by verified streaming |
| any chunk tag detected | a_flipped_byte_in_the_fetched_ciphertext_fails_the_chunk_tag: ciphertext that passes the transfer layer but has been altered fails at the chunk’s authentication tag |
| the group size the gate’s prose says to prototype against | the_verification_group_is_the_sixteen_kib_format_section_7_assumes and verified_ranges_are_served_in_one_kib_units_not_in_verification_groups: the verification group matches the reference assumption, and the serving unit is one 1 KiB chunk |
| negative control on alignment | a_span_shifted_off_the_grid_over_fetches_one_serving_unit_per_edge: a span shifted off the chunk grid pays one extra serving unit per edge, so the exact-span result in the second row cannot pass vacuously |
| the serving unit holds at the binding’s transfer path | gi2_a_ranged_get_moves_only_the_requested_range_not_the_whole_object in sovm-iroh’s gates tests: a one-byte request moves exactly one serving unit, asserted by equality rather than by a ceiling |
4. The rulings that interpreted the gate
Section titled “4. The rulings that interpreted the gate”The chunk constant is confirmed, not re-derived. Section 28 asks for a re-derivation if the group size or the hashing behavior differs from the reference assumptions. The group size matched. The hashing behavior differed, but in the finer direction: verified ranges are served in 1 KiB units, not in 16 KiB groups, and 1 KiB divides the 1 MiB chunk exactly. So the reason the constant was chosen still holds. The ruling recorded that the trigger fired and the answer did not change, rather than recording that the trigger did not fire. The same measurement corrected two passages. One is format §7’s statement of the serving granularity. The other is this gate’s fourth clause, which previously said “tamper in any 16 KiB group”. Section 7’s number was accepted only on the condition that something fails when it stops being true. The exact-equality assertion in the table’s last row is that condition.
The transported length is unauthenticated, and GB1 holds anyway. The
prototype found that the object length the transfer layer carries is outside
range authentication: the_bao_length_prefix_is_outside_the_range_verification
accepts a share of single-bit flips in it. That does not fail any clause of
GB1, because an SOP-BLOB-1 reader takes the object’s length from the signed
manifest and derives every span from the chunk grid. Format §7 now states this
as a requirement on the reader instead of leaving it as an unstated dependency.
The gate closes on its own text. GB1 closed by itself, while GB2 and GB3 stay open. This follows the rule SOVM/1’s other gated pages already apply: a gate closes when its own text is satisfied, not when all of its siblings are.
5. What the evidence does not show
Section titled “5. What the evidence does not show”The evidence covers the reference transfer layer only, at its pinned version. It says nothing about seek-and-play performance or decode-path overhead (GB2). It does not cover padding or storage overhead (GB3). It does not show a range read through the binding’s own fetch interface end to end: the prototype drives the transfer layer directly, and the binding’s ranged fetch is measured separately by its own gate tests.
6. Reproducibility
Section titled “6. Reproducibility”The workspace these tests live in is not released, so an outsider cannot
re-run them today. Reproducibility is a target, owed under decision D-0002
by project P-0058, which releases the node code the tests exercise; until
then this page is a record an outsider can read and not yet one they can check.