# Evidence and path policy

This directory separates **raw historical evidence** from the normalized, reviewer-facing public projection used by the showcase.

## Historical runtime paths

Raw evidence files are preserved byte-for-byte from the original Kaggle TPU runs. Absolute paths such as `/kaggle/working/...` therefore describe the runtime filesystem that existed when a recorded job executed. They are intentionally not rewritten, because changing them would alter the original evidence bytes and invalidate the recorded `raw_sha256` integrity value.

A historical runtime path does not imply that the historical path is a live public URL, nor that a reviewer is expected to have the original Kaggle filesystem mounted.

## Normalized reviewer-facing set evidence

Every curated set has a descriptor under `evidence/normalized/sets/`. These 51 descriptor files use **one stable schema** regardless of the historical raw JSON format. Each descriptor exposes the same top-level sections for prompt provenance, timing evidence, execution evidence, selected-output mapping, and raw-evidence references. Missing historical material is represented explicitly with `null`, empty arrays, or fail-closed status values rather than by changing the schema.

These normalized descriptors are the recommended reviewer interface. Raw JSON remains available as secondary source material and is never rewritten to imitate the normalized schema.

## Portable reviewer-facing paths

The public showcase uses portable reviewer-facing paths such as `assets/images/sets/...` for deployable images and `evidence/timing/...` for preserved evidence files. The normalized catalogs (`data/showcase.json` and `evidence/index.json`) avoid machine-specific absolute paths except where a historical path is explicitly exposed as provenance inside a verified mapping.

## Output identity mapping

`evidence/index.json` is fail-closed. A raw historical output is mapped to a selected public image only when all of the following are available and agree:

1. the selected image seed;
2. the raw `pngs` historical path for that seed;
3. the raw VAE output `png_sha256`; and
4. the selected public image SHA256.

When all four selected outputs in a run match byte-for-byte, the run receives `selected_output_mapping.status = "exact-sha256-match"` and each output records `seed`, `historical_path`, `public_path`, and `sha256`.

If that identity cannot be proven, the run remains `selected_output_mapping.status = "not-established"`. This does **not** invalidate the run-level TPU execution evidence; it only means the currently selected public images are not claimed to be byte-identical to that preserved run.

## Execution evidence scope

A verified run in `evidence/index.json` proves the recorded execution properties supported by its preserved `generation_summary.json`, including TPU backend/device information when present. Association to a selected set is accepted only through an exact recovered-prompt match or exact selected-output SHA256 identity for all four selected seed/output pairs. The label `4-image-batch-on-8-device-mesh` means four seeded images were generated in one recorded batch on an eight-device TPU mesh. It does not assert four independent model instances.

For integrity checking, compare each run's `raw_sha256` in `evidence/index.json` with the SHA256 of the referenced raw evidence file.
