Erratum — R-Series Reproduced Test Evidence, Reports 1–5
Issued 30 August 2026
An internal reconciliation completed on 30 August 2026 identified defects in the text of all five R-Series Reproduced Test Evidence reports. The reports remain published, unchanged, and reachable from this notice. They should be read only together with this erratum.
Every original PDF is preserved byte for byte. Nothing has been edited, re-rendered, replaced or removed. The SHA-256 digest of each file is printed below so any reader can confirm that the document they hold is the document that was originally published.
Defect 1 — the post-quantum sentence (affects all five reports)
Each report contains the sentence: “The Post-Quantum (PQ) leg currently utilizes size-conformant ground stand-ins.” That wording describes the signature algorithm as a stand-in. It should have described key custody.
The post-quantum leg uses real ML-DSA-65 signatures. What is a stand-in is the key custody: a software signer, not a FIPS-certified hardware security module, and not FIPS 204/205 validated. The reports therefore understate their own cryptography while appearing to overstate their assurance — and they disagree with this site’s own machine-readable records, which are correct.
One limit is unchanged and still applies: the deployed production signing path has not been bound to real ML-DSA-65 by any evidence published here.
Defect 2 — the adversarial-case figure (affects Report 1 only)
Report 1 prints the closing tiles “404,000 FUZZ CASES” and “0 ATTACKS SUCCEEDED” — both withdrawn by this erratum and quoted here only to identify them — and instructs the reader to reproduce them at frozen tag audit-tob-v1.1.0 · 697f339.
The test oracle used in that run could not report a failure for the downgrade attack it enumerated. Its success condition required a receipt to be unflagged, while the verifier under test flagged exactly that receipt and accepted it. The condition was therefore unsatisfiable, and that family of attacks could only ever report zero. The oracle encoded “we flagged it” as success where the specification requires “we refused it.” Flagging is not refusing.
A corrected oracle, run against the same frozen code and the same deterministic seed, reports a non-zero number of slips. That corrected count is stated in the H-1 erratum on the Evidence page. It is deliberately not restated here, and it does not repair the report. Reprinting it inside a certificate-shaped document would not make it reproducible: the oracle, the corpus manifest and the run logs needed to check it are not yet public, and a figure a reader cannot verify is what produced this erratum in the first place. Report 1’s own instruction — reproduce these tiles at the frozen tag — cannot be satisfied by any reader today. Treat the printed tiles as withdrawn, not as replaced by a new number.
Two further limits of that run, not stated in the report: the fuzz seed is hard-coded and not overridable, so every re-run explores an identical fixed trajectory and adds no coverage; and the downgrade family is a small minority of the total case count, not a proportional share of it. The figure was also characterised as “malformed and malicious inputs” where this site’s web and JSON records use the narrower and more accurate “adversarial cases.”
Why no corrected PDF has been issued
A corrected report set has not been published, and will not be published until it can be produced reproducibly. Two reasons, both deliberate:
- The five reports must be corrected together or not at all. Defect 1 affects all five. A certificate family that disagrees with itself about its own cryptography is worse than no certificate, so a partial re-issue is not an acceptable intermediate state.
- The source that produced these documents is not currently available. The reports were rendered on 28 July 2026 from HTML source in a transient environment that was not retained. Neither the source nor the render script exists in any repository. Re-issuing therefore means rebuilding the documents from their underlying records — not re-running a build — and doing that correctly takes longer than publishing this notice.
Until then the honest position is the one on this page: the original documents stay published and unmodified, and this erratum stays in front of them.
The five reports, as published
Each link below opens the original, unmodified document. Both defects above apply to every report; Defect 2 applies additionally to Report 1.
Report 1 of 5 — Reference Core
DCS_RSeries_ReferenceCore_Evidence.pdfAffected by Defect 1 and Defect 2. The closing tiles and the reproduction instruction on this report should not be relied on as published.
sha256 be7ff49cbfded460ee91534095aed3a44df0b200b6df3aba7ea23b1f4d4558b0
Open archived original →Report 2 of 5 — Dual Anchor
DCS_RSeries_DualAnchor_Evidence.pdfAffected by Defect 1.
sha256 0c755ef57e1dbbf54247b7790856803b478af91111fc921f013b0ebfd1702083
Open archived original →Report 3 of 5 — Wycheproof Ed25519
DCS_RSeries_Wycheproof_Ed25519_Evidence.pdfAffected by Defect 1.
sha256 d7fd49255532760b673ec411227206b610e40af362ad816cd9579c68e859ff91
Open archived original →Report 4 of 5 — NIST ACVP ML-DSA-65
DCS_RSeries_NIST_ACVP_MLDSA65_Evidence.pdfAffected by Defect 1.
sha256 455d5dd3cdff4621bc895d8b8a9a1bdc557b0ef68f81173164febde5bced2784
Open archived original →Report 5 of 5 — R+12 Fabric
DCS_RSeries_R12_Fabric_Evidence.pdfAffected by Defect 1.
sha256 a57d5d91b6a343b8e4cc99b3456d6f3e83b055ff91f8e2ba6e80e85ace2a4d75
Open archived original →What is not affected
This erratum concerns the wording and the one figure identified above. It is not a finding of fabrication. The underlying test records behind these reports were reviewed and every disputed number traced to observed data. The conformance and interoperability results reported elsewhere on this site, and the machine-readable evidence records that accompany them, are unchanged by this notice.