CRUSETRA
Appendix A · Dossier Method and reproducibility ← Back to the findings

How the Dossier checks the four reports.

A matte aluminium balance with two pans at exactly the same height; the right pan is the tool's polished onyx.

This page shows what the Dossier is made of: the reports it reads, the five controls run on each, and where it does not guess. It also shows what its own public test set holds, a frozen file of measurements that carries its content hash. The Dossier is the audit piece of the suite. It proves the chain, or it names what is missing.

The Dossier runs five controls in order and names each refusal

Each report the Dossier reads passes the same five controls. Present means a readable report from a named tool. Sealed means the content hash written in the report matches a hash recomputed from its content. Signed means the public test set the report cites carries the tool's signature. Fresh means the report was measured within the declared validity period. Past that, it is marked due, and past two validity periods it is marked stale. Consistent means the report names one dataset and one content hash. If the tool version is unknown, the Dossier writes unknown. It does not guess a version.

The Dossier builds its list of controls from the code that declares them, so a missing control is computed. No hand-written list is recited.

Each answer carries its reason in words. A report that cannot state its measurement day is not called stale. The Dossier marks it unjudgeable and prints that, which is a different and worse fact.

Verify the controls

The test suite checks each control on a report it should accept and on one it should refuse.

run it yourself
npm testthe five controls and their refusals, with the rest of the suite

Where it livessrc/controles/index.ts:15 · src/controles/index.ts:24 · src/controles/fresh.ts:5

Its own public test set is the suite judged by the Dossier

To build its own public test set, the Dossier runs on the other tools' public test sets. It prints coverage, content hashes, signatures and freshness as it finds them on the day of the measure. A Dossier that flattered its own suite would be of no use to a reviewer. On day one that meant three questions of four covered, with the fourth named missing, and two content hashes recomputed. It also meant zero verifiable signatures, printed in the file and recorded as a failed control.

Verify the public test set

The public test set carries its content hash. Recompute it with the repository's own tool.

run it yourself
npm run sceller -- releve-public.json --checkprints "already sealed, and the seal matches"

Where it livessrc/measure.ts:93 · src/sceller.ts:60

You declare the validity period, and the Dossier counts age against it

Freshness only means something against a validity period, and you declare it. It is ninety days by default, written in the public test set as a declaration. You change it with a flag, and an auditor can see that flag because the file stores the settings it was measured under. So two Dossiers can be compared knowing whether the rule moved between them.

Verify the settings

The public test set carries its settings block, validity period included.

run it yourself
python3 -c "import json; r=json.load(open('releve-public.json'))['reglages']; print(r['rythmeJours'], 'days, stale beyond', r['staleApres'], 'validity periods')"prints the declared validity period the freshness answers were judged against

Where it livessrc/controles/fresh.ts:22 · src/measure.ts:98