{"service":"probe402","what_this_is":"The published heads of probe402's daily manifest hash chain. One row per archive day: every object written that day is hashed, the hashes are sealed into a manifest, and the manifest's own hash is the row below. Each day's manifest names the previous day's hash, so a day cannot be removed or rewritten without breaking every day after it.","source_of_record":{"file":"docs/evergreen/ARCHIVE-CHAIN.md","says":"A row is written only for a day the verifier has re-derived from an OFF-VENDOR replica — never from the archive itself, and never from a manifest it did not rebuild from the objects. Rows are append-only. A row that turns out to be wrong is corrected by appending, never by editing.","this_route_is_a_copy_of_it":"The record of account is a file in git, off the vendor that holds the archive; this route serves a copy of that file's table so that it is reachable at all. A test parses the record of account and fails the build if the two disagree."},"what_this_route_is_not":"🔴 Trustless. These bytes come from a Cloudflare Worker, and the archive they describe sits in the same account. Anyone who can rewrite the archive could serve you a matching row from here. Publication does not fix that and this page does not pretend it does.","what_publication_buys":"Keep a copy of this table. Any head you have recorded that later reads differently here is a discrepancy you hold and we cannot reconcile after the fact — from us, from Cloudflare, or from anyone with access to either. That is the whole of what publishing a digest buys, it does not depend on trusting the channel it arrived on, and it is why serving these came before anchoring them in a public timestamp (ADR-060): anchoring an unpublished head only proves some digest existed on a date, with nothing retrievable behind it.","heads":[{"date":"2026-08-21","chain_index":0,"manifest_sha256":"f0bca18bc38e9a7d202bedc12def262cd4a17ec61136ee07f911afc775bafc65","objects":450,"blobs":384,"bytes":2649415,"verified_from":"scratch/replica-b6","verified_at":"2026-08-23","verifier":"0.1.0"},{"date":"2026-08-22","chain_index":1,"manifest_sha256":"6c7307b90cd4526281918351d2db867a16649334670c2b6d8a181b7bee95fb5b","objects":668,"blobs":571,"bytes":4003155,"verified_from":"scratch/replica-s3","verified_at":"2026-08-23","verifier":"0.1.0"},{"date":"2026-08-23","chain_index":2,"manifest_sha256":"a02a3bb34b13ead82ab0c2e340005b7f50e342d939f6aff11c4cdc015b56fef0","objects":668,"blobs":571,"bytes":3998871,"verified_from":"scratch/offvendor-w34","verified_at":"2026-08-24","verifier":"0.1.0"},{"date":"2026-08-24","chain_index":3,"manifest_sha256":"4489acd993301d55ef9cfdbea259e8103caab82e388193029da9280b63e8a163","objects":663,"blobs":483,"bytes":3729622,"verified_from":"scratch/offvendor-0825","verified_at":"2026-08-25","verifier":"0.1.0"},{"date":"2026-08-25","chain_index":4,"manifest_sha256":"f1a092c896cc7fed856b277b9966271c97c6561448f068a97b406b3cf21fb7fe","objects":671,"blobs":428,"bytes":5074926,"verified_from":"scratch/build35-before","verified_at":"2026-08-27","verifier":"0.1.0"},{"date":"2026-08-26","chain_index":5,"manifest_sha256":"6bb70b7cd09e8c4bf7fe11ba1f77088a8af1ad4be48ade32a9ba2eedadad44af","objects":1144,"blobs":860,"bytes":8835947,"verified_from":"scratch/build35-before","verified_at":"2026-08-27","verifier":"0.1.0"}],"head_count":6,"continuity":{"head_count":6,"indices_contiguous_from_zero":true,"dates_strictly_increasing":true,"first_date":"2026-08-21","last_date":"2026-08-26","checks_run":17,"problems":[]},"how_an_outsider_checks_us":[{"step":1,"says":"Take any manifest_sha256 from the published heads.","status":"executable","today":"The heads are on this route, as JSON or as a page, free and unauthenticated. Until 2026-08-25 they existed only in a private git repository that answers 404 to a stranger, so this step could not be performed by the reader it was addressed to.","blocked_by":null},{"step":2,"says":"Get that day's objects — the day's pack object, or the individual keys the manifest names.","status":"blocked","today":"Nothing. We do not serve the archive objects and we are not planning to. Every capture is a verbatim record of a payment-quote handshake with somebody else's endpoint, and some of those responses carry credentials the endpoint handed us. Publishing the archive would publish those.","blocked_by":"Our own refusal (ADR-057). This is the step that makes the recipe's closing sentence — 'no trust in Cloudflare, and none in us, is required at any step' — overstated as written, and we would rather say so here than leave a reader to discover it after two steps of work."},{"step":3,"says":"Re-hash each object, rebuild the manifest, hash the manifest.","status":"blocked","today":"Nothing, because step 2 is blocked. There is nothing to re-hash.","blocked_by":"Step 2."},{"step":4,"says":"It must equal the row here, and equal the prev_manifest_sha256 recorded in the next day's manifest.","status":"blocked","today":"Half of the inputs. The row is now fetchable, so the comparison target exists; the day manifests are not served, so the linkage half cannot be checked at all. The indices and dates published beside each head are internally consistent and you can confirm that from the table alone — but that is a property of the table, not evidence about the archive.","blocked_by":"The day manifests are not served. That is the next step in the ranking (ADR-060 step 3): the hash LISTS, not the captures, which makes the linkage and each capture_sha256 checkable from outside without republishing anything a capture carries."}],"recipe_steps_executable_today":1,"recipe_steps_blocked_today":3,"verdict":"https://probe402.com/verdict","method":"https://probe402.com/method"}