Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Cortex Logo

Cortex Platform

Spatiotemporal Authority & Semantic Verification Framework

PyPI Version Python Version License: Apache 2.0 Type Checked: Pyright Certification: 136/136 PASS


Cortex is a spatiotemporal authority and semantic verification framework designed to enforce execution integrity, capability-negotiated sandboxing, and post-facto deterministic verification across autonomous software runtimes and AI agent architectures.


📖 System Architecture & Design Overview

Traditional security architectures rely on static user identity roles (POSIX permissions, IAM roles, cgroups) which fail under non-deterministic AI agent workloads and dynamic plugin executions:

  • Ambient Authority Leakage: Agents executing inside shell environments inherit full ambient process permissions, allowing unmediated filesystem or network access.
  • Subshell Script Bypasses: Malicious or miscalibrated plugins invoke shell scripts (.sh), subprocesses, or eval blocks to bypass application-level checks.
  • Trace Non-Repudiation: Without cryptographic trace verification, auditing why an autonomous agent performed a destructive side-effect is impossible.

Cortex replaces ambient authority with a Hardware/Kernel-Enforced 4-Layer Security Boundary:

 ┌─────────────────────────────────────────────────────────────────────────────────────────────┐
 │ 1. STATIC CAPABILITY NEGOTIATION & STCR MAPPING (Gate K / ADR-008)                          │
 │ Manifests declare required permissions before plugins access the kernel bus.                │
 └──────────────────────────────────────────────┬──────────────────────────────────────────────┘
                                                │ SignedIntent Payload (CBE Format)
                                                ▼
 ┌─────────────────────────────────────────────────────────────────────────────────────────────┐
 │ 2. EXECUTION TOKEN INTENT PARITY & ACTUATION GATE (Gate H / P2)                             │
 │ Single-use ExecutionTokens bind tokens strictly to intent hashes: D3 == D2                  │
 └──────────────────────────────────────────────┬──────────────────────────────────────────────┘
                                                │ Governed Side-Effect Execution
                                                ▼
 ┌─────────────────────────────────────────────────────────────────────────────────────────────┐
 │ 3. ROLLING CAUSAL WITNESS JOURNALING (Gate I / P3)                                          │
 │ Emits tamper-evident rolling hash commitments: W_{t+1} = SHA256(W_t || D_E || D_I)          │
 └──────────────────────────────────────────────┬──────────────────────────────────────────────┘
                                                │ Raw Evidence Traces (R, E)
                                                ▼
 ┌───────────────────────────────────────────────────────────────────────────────────────────────┐
 │ 4. ZERO-DEPENDENCY INDEPENDENT UNTRUSTED VERIFIER (Gate J / P4)                               │
 │ Standalone CLI tools/cortex-verifier evaluates traces ➔ VALID (0), INVALID (1), INDETERMINATE │
 └───────────────────────────────────────────────────────────────────────────────────────────────┘

🗺️ Repository Map & Documentation Architecture

For open-source contributors and systems architects, the codebase is structured logically across normative specifications, architecture records, polyglot engines, and verification suites:

Cortex Platform Architecture Map
├── docs/                                    # Master Technical & Specification Portal
│   ├── architecture/                        # Architectural Audits & Verification Matrices
│   │   ├── verification_closure_matrix.md   # Master Phase 13 Assurance Status Matrix
│   │   ├── gate_g_complete_mediation_inventory.md # Complete Mediation Path Analysis
│   │   └── threat_model.md                  # Threat Vectors & Mitigation Catalog
│   ├── spec/                                # Normative Protocol & Security Specifications
│   │   ├── gate_g_remediation_specification.md # Worker Sandbox & Narrow IPC Architecture
│   │   ├── gate_h_execution_token_specification.md # ExecutionToken & Intent Parity Spec (P2)
│   │   ├── gate_i_causal_witness_specification.md  # Rolling Witness Chain Specification (P3)
│   │   ├── gate_j_independent_verifier_specification.md # Untrusted Verifier Engine Spec (P4)
│   │   └── v03_layer2_streaming_spec.md     # Layer 2 Streaming Protocol Framing
│   └── adrs/                                # Architectural Decision Records
│       └── ADR-008-identity-specification-supersession.md # Identity Supersession (UUIDv5/v7)
│
├── tools/                                   # Standalone Tooling & Verification Engines
│   └── cortex_verifier.py                   # Zero-dependency Independent Verifier CLI (Gate J)
│
├── tests/conformance/                       # Conformance & Adversarial Certification Suite
│   ├── run_certification.py                 # Master 74-Check Conformance Test Runner
│   ├── test_gate_h_adversarial.py           # Gate H Parity & Replay Protection Tests (21/21)
│   ├── test_gate_i_causal_witness.py        # Gate I Tamper-Evident Witness Chain Tests (7/7)
│   └── test_gate_j_independent_verifier.py # Gate J Verifier Engine Adversarial Tests (12/12)
│
├── cortex/                                  # Python Control Plane & Reference Runtime
├── cortex-emulator/                         # Rust STCR Hardware State Machine Emulator
├── cortex-go/                               # Go Layer 2 High-Concurrency Transport Adapter
└── rtl/                                     # SystemVerilog STCR Hardware Pipeline

🛡️ The Safety Invariants Matrix ($P1$–$P4$)

Security Invariant Mathematical / Normative Definition Status Empirical Verification & Test Harness
$P1$: Authority Attenuation $\Lambda_{t+1} \subseteq \Lambda_t \land w_1 \sqsubseteq w_2$ PARTIAL Python PluginContext & Rust cortex-emulator STCR.
$P2$: Execution Parity $D_3 \equiv D_2 \equiv \text{SHA256}(\text{CBE}(\text{SignedIntent}))$ CERTIFIED 21/21 Gate H Scenarios PASS (test_gate_h_adversarial.py).
$P3$: Causal Witness $W_{t+1} = \text{SHA256}(W_t \parallel \text{CBE}(E_{t+1}) \parallel \text{CBE}(I_{t+1}))$ CERTIFIED 7/7 Gate I Scenarios PASS (test_gate_i_causal_witness.py).
$P4$: Independent Verifier $\text{Verify}(R, E) \to {\text{VALID, INVALID, INDETERMINATE}}$ CERTIFIED 12/12 Gate J Scenarios PASS (tools/cortex-verifier.py).
Complete Mediation (Gate G) $\forall \text{eff} \in \text{Effects}, \text{eff} \text{ passes through } \text{ExecutionToken}$ SPECIFIED Sandbox & Narrow IPC Architecture (gate_g_remediation_specification.md).

⚡ Contributor Quickstart & Test Commands

1. Prerequisites & Environment Setup

Clone the repository and install dependencies via uv or standard Python 3.10+:

git clone https://github.com/Iradukunda-Fils/Cortex.git
cd Cortex
uv venv && source .venv/bin/activate
uv pip install -e .

2. Run Static Analysis & Type Checking

Ensure 0 type errors across the codebase:

pyright

3. Run Master Certification Pipeline

Execute the full 74-check conformance suite covering golden corpus vectors, Coq/Rust/RTL cycle assertions, Gate H parity, Gate I witness, and Gate J verification:

python3 tests/conformance/run_certification.py

4. Run Independent Verifier Engine CLI

Verify raw untrusted evidence bundles out-of-band without importing runtime modules:

python3 tools/cortex_verifier.py tests/conformance/fixtures/evidence_bundle_valid.json
# Output: VERDICT: VALID (0) - EVIDENCE_VERIFIED_VALID

💻 Developer Code Example: End-to-End Governed Execution

Here is how an application mints an intent, acquires an ExecutionToken, and enforces $D_3 \equiv D_2$ parity:

import hashlib
from cortex.cbe import encode_cbe

# 1. Define SignedIntent
intent_payload = {
    "body": {
        "intent_type": "STORAGE_WRITE",
        "target_resource": "/data/export.csv",
        "payload": {"bytes": 1024},
        "timestamp_ns": 1776274200000000000
    },
    "authority_pubkey": "PUBKEY_NODE_01",
    "signature": "a3f890b..."
}

# 2. Mint ExecutionToken (D2 = SHA256(CBE(SignedIntent)))
signed_intent_cbe = encode_cbe(intent_payload)
intent_hash_d2 = hashlib.sha256(signed_intent_cbe).hexdigest()
token = {"intent_hash": intent_hash_d2, "epoch": 1, "nonce": "abc123nonce"}

# 3. Actuation Boundary Assertion (D3 == D2)
d3_hash = hashlib.sha256(encode_cbe(intent_payload)).hexdigest()
if d3_hash != token["intent_hash"]:
    raise PermissionError(f"TRAP_INTENT_PARITY_MISMATCH: {d3_hash} != {token['intent_hash']}")

print("✅ Governed Side-Effect Actuated Successfully!")

📄 License & Governance

Licensed under the Apache License, Version 2.0. See LICENSE for details.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cortex_runtime-0.3.0rc1.tar.gz (61.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cortex_runtime-0.3.0rc1-py3-none-any.whl (96.8 kB view details)

Uploaded Python 3

File details

Details for the file cortex_runtime-0.3.0rc1.tar.gz.

File metadata

  • Download URL: cortex_runtime-0.3.0rc1.tar.gz
  • Upload date:
  • Size: 61.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for cortex_runtime-0.3.0rc1.tar.gz
Algorithm Hash digest
SHA256 01a89fec6335d52fa5d9145e3ec6699d487c967a517f11c3390ad5dd0da3701f
MD5 546b536852fa249db2961ca245fe57f3
BLAKE2b-256 8c99ecd3e66b3ced1fe1ebd7dcbeb439ad9c226e8c1fb7ea1e9821ddf3d92046

See more details on using hashes here.

Provenance

The following attestation bundles were made for cortex_runtime-0.3.0rc1.tar.gz:

Publisher: pypi.yml on Iradukunda-Fils/Cortex

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cortex_runtime-0.3.0rc1-py3-none-any.whl.

File metadata

File hashes

Hashes for cortex_runtime-0.3.0rc1-py3-none-any.whl
Algorithm Hash digest
SHA256 0defb8e1dd30ea82faebc11a0af0761e8f6b5915003916473cbc791bc053fb4b
MD5 d5824939bffae331f66960544f1ba5db
BLAKE2b-256 eac3e33a9b726a81a7737f4b7d9286316de1691e8d190a2865378ba3c93f23fb

See more details on using hashes here.

Provenance

The following attestation bundles were made for cortex_runtime-0.3.0rc1-py3-none-any.whl:

Publisher: pypi.yml on Iradukunda-Fils/Cortex

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.6.0

2 files

0.5.0

2 files

0.4.0

2 files

0.3.0

2 files

This release

0.3.0rc1 This release

2 files

0.2.1

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page