Not normative · Verdict
GI2 verdict — object identity
This page records why SOVM-IROH §10 marks GI2 closed. It is a record of evidence, not part of the specification: it adds no requirement, and the gate’s text on the binding page is what it answers to.
1. The gate
Section titled “1. The gate”GI2 object identity: the storage_id returned by iroh-blobs equals the spec-derived BLAKE3 over the exact encrypted bytes, on import and on fetch.
2. Where the evidence was read
Section titled “2. Where the evidence was read”- Commit.
d6f6a00e0e5ba94a78318401a87d0bd76ded7d6e, onmainsince the promotion of 2026-09-11. Every test named below exists at that commit. - Run. CI run 19083, job
Rust Test (sovm workspace), 2026-09-08T22:47Z, stepcargo test (sovm workspace on loopback), which checked out exactly that commit. Every test named below passed in it. None of them is ignored by default, so the same tests run in that job on every merge.
3. The clauses, and the tests that carry each
Section titled “3. The clauses, and the tests that carry each”| Clause | Tests |
|---|---|
| storage_id equals the spec-derived BLAKE3 on import | gi2_storage_id_is_blake3_of_the_exact_bytes_on_import_and_fetch in sovm-iroh’s gates tests: the id iroh-blobs returns for an imported object equals BLAKE3 computed directly over the exact encrypted bytes, trailer included, with no iroh-blobs in that call |
| … and on fetch, on the node that did not import | an_object_imported_on_one_machine_is_fetched_by_the_other in sovm-run’s two_machines tests: the fetch happens in a second process with its own store, over a real endpoint, and the fetched bytes re-derive to the same id |
| the identity holds under ranged transfer | gi2_a_ranged_get_moves_only_the_requested_range_not_the_whole_object, gi2_the_binding_returns_exactly_the_requested_range_and_reports_its_cost, gi2_a_relayed_range_is_accepted_when_the_sender_is_honest, gi2_a_tampered_relayed_range_is_rejected_against_the_storage_id and gi2_export_ranges_reads_without_validation_and_export_bao_refuses, all in gates |
| negative control | a_fetch_of_an_object_no_one_holds_fails in two_machines: a fetch cannot succeed vacuously |
The assumption under “spec-derived BLAKE3” — that iroh-blobs’ verification groups align with the specification’s chunk constant — was measured separately by a time-boxed spike, which found the store hash equal to BLAKE3 over the exact encrypted bytes and no over-fetch on an aligned chunk.
4. The rulings that interpreted the gate
Section titled “4. The rulings that interpreted the gate”The gate is read on its own text. GI2 carries no independence clause. Its closure rests on an equality whose two halves have different provenance — one derived by iroh-blobs inside the transfer plane, the other by hashing the encrypted bytes directly — asserted on the fetching node as well as on the importing one. An equality that asked iroh-blobs for both halves would be a store agreeing with itself and would close nothing.
The one open question was shared with GI1, and was ruled on 2026-09-08. The cross-process fetch runs on one kernel, as GI1’s two-process evidence does. The independence ruling recorded on the GI1 verdict settled it; nothing specific to GI2 was open. The binding page marked the gate closed on 2026-09-11.
5. What the evidence does not show
Section titled “5. What the evidence does not show”It does not show object identity between two hosts, and it does not bear on the container roster’s reliability, on which GI2’s evidence does not depend.
6. Reproducibility
Section titled “6. Reproducibility”The workspace these tests live in is not released, so an outsider cannot
re-run them today. Reproducibility is a target, owed under decision D-0002
by project P-0058, which releases the node code the tests exercise; until
then this page is a record an outsider can read and not yet one they can check.