{
  "report": "Dual-anchor permanence",
  "id": "dual-anchor",
  "component": "Base L2 + Bitcoin stand-in, single-chain-outage resilient",
  "suite_file": "test/dual_anchor.test.mjs",
  "suite_file_sha256": "43e014ea624d8df92279fc0f5a46cea80d4f10dacccac359433e17dc39f0f4cf",
  "result": {
    "passed": 15,
    "failed": 0,
    "skipped": 0,
    "unit": "tests",
    "suites": 1,
    "status": "PASS"
  },
  "detail": "15 tests incl. negative cases",
  "note": "Includes negatives: forged aggregate rejected, tampered inclusion path rejected, empty week rejected, hostile input never throws. DARK by default (a live rail is refused unless *_LIVE=1).",
  "what_it_proves": "A root anchored to both rails verifies on each independently; when one chain is down the other still proves the root; both down -> honest UNANCHORED.",
  "what_it_does_not_prove": "Live on-chain permanence today. Bitcoin rail is a deterministic stand-in; the Base anchor is a local stub for the acceptance path. Real chain writes require live network keys.",
  "raw_excerpt": "$ node --test test/dual_anchor.test.mjs\n# tests 15 · pass 15 · fail 0",
  "frozen_tag": "audit-tob-v1.1.0",
  "commit": "697f339",
  "reproduced_utc": "2026-07-27",
  "node": "v22.22.3",
  "repo": "github.com/DCS-LabsAI/dcs-rseries-core",
  "prod_dependencies": 0,
  "reproduced_by": "DCS Labs — live reproduction from clean checkout",
  "posture": "ground-demonstrated; not externally audited",
  "non_claim": "Post-quantum signature: the current R-Series hybrid profile signs the post-quantum leg with real ML-DSA-65. Key custody: a software signer — hardware-backed HSM/KMS custody is a separate deployment control, is not deployed here, and no FIPS-validated module is claimed. Not independently audited by external third parties. Anchoring: the Base rail is live; the Bitcoin/OpenTimestamps rail is a deterministic stand-in and runs DARK by default — an anchoring rail, not the post-quantum signature leg."
}