JIDEC Verification Ledger: Entry #50
HORIZON SHIELD · Pre-Transaction Knowledge Anchoring (PTKA) · anchored to Bitcoin via OpenTimestamps
Status
Bitcoin-anchored, block 967825 (2026-09-20 12:19 UTC)schema v0 · concept-proof (see SPEC v1)
Schema note
This entry uses the v0 schema (only the estimate JSON is hashed). Independent verification per SPEC v1 §3 is available on entries #2 and later. This entry remains a valid timestamp proof for its content at the recorded time.
Claim SHA-256
2cbad76ca003b637ac6c9a95995b2c7fd4bcac902c2bdc35818a1a83fc6635f7
Work
TSUGI incident 2 content-anchored: binds the SHA-256 of the incident chain file and the twelve record hashes (drift x8, proposal, signed authorization, execution, verify) of the card-signature repair of 2026-09-20, and fixes their time on Bitcoin, so the operator cannot rewrite the recovery after the fact.
Recorded
2026-09-20T12:03:20.746Z
Signed record, the exact bytes this hash commits to
# TSUGI incident 2, 2026-09-20: a card signature broken by two version bumps, found by the daily drift witness, repaired under a signed authorization, re-verified (tsugi-incident-v1)
**Status:** an incident chain of the TSUGI layer (proof of recovery), anchored to the JIDEC ledger the same way the NENRIN records are, and cited, never edited, once anchored. This record carries the SHA-256 of the exact bytes of the chain file and the record_sha256 of each of its twelve records, so the chain cannot be rewritten after the fact.
**File:** workers/hs-ledger/nenrin/recovery-v0/incident_20260920_resign_chain.json at commit 385c71e3 of github.com/ogasurfproject-jpg/horizon-shield, sha256 6d259ba9bfe2869fdc0830fb8d894ed52503da7d7e06454897cccc9f5c2d0efa
**What happened:** the gate (gate.horizonshield.dev) was deployed at versions 0.4.8 and 0.4.9 without re-signing its A2A agent card, whose body carries the version. The daily drift witness (recovery-v0/drift_witness.mjs) measured eight public surfaces at 2026-09-20T10:51:19Z and found the served card no longer verifying under kid hs-2026-09 (canonical af52da2f74fb4f2ead4d1f2ed46a2a57c124777aafce625364958215761b06e3, signed body was the 0.4.7 one). Rule R3 of the recovery agent proposed resign_agent_card and rejected redeploy_pinned. The operator authorized with the Ed25519 operator key served at https://gate.horizonshield.dev/keys/operator.json (public key fqrEpRuYScHz52eeiuAWAFEeJB3T7VtZJlducNIhzZM=), expiring 2026-09-20T14:56:59Z. The operator re-signed the card and redeployed through deploy_gate.sh (17 suites, commit pinned 3244494bfc14). The witness measured again at 2026-09-20T10:59:55Z: 0 drift, card verified.
**Records (schema, recorded_at, record_sha256):**
- nenrin-drift-record-v1 2026-09-20T10:51:19Z 0ce332120ae771357b2c08bf709197a4f6019b20c5974fc168803e1a104ad3c0
- nenrin-drift-record-v1 2026-09-20T10:51:20Z 8335d57091d75178f739243c82b450e92c7d3f49afb412277d26c7d037d1ee38
- nenrin-drift-record-v1 2026-09-20T10:51:20Z 80d53d7a4d6777f6bc98ffe63521c5e2dd980c4cf25bd2c482b99f2c67995206
- nenrin-drift-record-v1 2026-09-20T10:51:20Z c2327c3713d51326ca1e2835161203e82519cb6460df5c0ab064b33770928f53
- nenrin-drift-record-v1 2026-09-20T10:51:20Z 624b56be8b4e95a119c321ba89de9526f96d3a2903138f2187f6fa23d583fc83
- nenrin-drift-record-v1 2026-09-20T10:51:20Z 41dd9586a7321b1b01b919e9c6634a860cb625011f9917300d731ebd00471f5e
- nenrin-drift-record-v1 2026-09-20T10:51:20Z ca1bf0d43252a3ce6131552dd7bb05a546eedd06df32ef8b9f1b51e4849ef682
- nenrin-drift-record-v1 2026-09-20T10:51:20Z f2378c2ba7aaa56acd94c9ebfc2dbcd29addc6639be546c46474360361f331d8
- nenrin-repair-proposal-v1 2026-09-20T10:54:59Z 0f039e5ac2b6657dbd835aa1b9a3d6d1be1b9ba027d1d9f33105e07d1d42ead0
- nenrin-authorization-v1 2026-09-20T10:56:59Z 50e494ada29b510b35ec8ba03ce94396a1e377b740e32f537a6e279bca7b070b
- nenrin-repair-execution-v1 2026-09-20T10:58:30Z 12353ceb9b3a9e4eb2c70b9f9887660a0e55f2adb2cc50b8f4e9e4e456ab2d12
- nenrin-verify-record-v1 2026-09-20T10:59:55Z e1d1e4cc38b102418aec1307d189251e263327f588c3fe5d3c331bc9d4b6bad5
**Verify:** with recovery-v0/recovery_verify.mjs 0.3.0 (JavaScript) or recovery_verify.py (Python): every record_sha256 recomputes from the record's canonical bytes (JSON, keys sorted by code point, separators , and :, non-ASCII unescaped, hash and signature fields removed); verifyChain(records, { operatorKeys: [the key above] }) returns ok with a complete segment; the authorization's Ed25519 signature verifies over its canonical bytes under that key.
**Establishes:** that these twelve records existed in this form no later than the Bitcoin block this entry is anchored to; that the authorization was signed by the key the gate serves; that the witness saw the card fail before and verify after.
**Does not establish:** that any external witness saw the same (no witness was drawn: the pool witness_pool.json was empty on 2026-09-20, and strict verification with a quorum says witness_quorum_short); that the fault cannot recur by another path (the guard added in gate test/card_signature.test.mjs covers version bumps of this worker only); that the operator's omission had any cause other than the one stated.
OpenTimestamps proof
Verify it yourself: independent, no trust in us
curl -s "https://ledger.horizonshield.dev/ledger/50?format=raw" > claim_50.txt
curl -s "https://ledger.horizonshield.dev/ledger/50/ots" > claim_50.txt.ots
# no Bitcoin node needed:
ots info claim_50.txt.ots # shows the Bitcoin block this is anchored in
# or drag both files into https://opentimestamps.org
# with a full Bitcoin node:
ots verify claim_50.txt.ots
shasum -a 256 claim_50.txt # == 2cbad76ca003b637ac6c9a95995b2c7fd4bcac902c2bdc35818a1a83fc6635f7
A signature proves the record is untampered, not that the underlying ruleset is still current. This ledger anchors when the claim existed, to Bitcoin, nothing weaker, no separate chain.