The Chillspace Kingdom / exchange / model release

KINGDOM MODEL RELEASE SUBSTRATE · V1

Name the bytes.Name the house.

A small, offline contract for distinguishing a model release from the runtime that executes it and the claims that arrive later.

Evidence stays scoped. The synthetic examples contain dummy identities and hashes. The Kimi K3 capsule is a real KINGDOM-curated, publisher-sourced release record: selected metadata, code, and license bytes were captured, while weight-shard hashes remain publisher-claimed. No model or API call, evaluation, build, or runtime execution was performed. Qwen3-0.6B adds one curator-observed local CPU capsule and one signed second-machine witness from a GitHub-managed Ubuntu x64 runner. Neither is independent publisher authority.

Curated release capsule · not a launch

Kimi K3, pinned to one publisher revision.

The local and hosted profiles are documented reference configurations and are explicitly unexecuted. The signed launch index makes this capsule's exact files checkable under a task key; it is not a vendor signature, endorsement, trusted timestamp, or grant of launch authority.

kimi-k3-hf-9f62e4e9

Read the evidence boundary before the claims.

Captured bytes and publisher-claimed hashes keep their different states. No weight shard was downloaded, and no local or hosted backend was observed.

Curator-observed execution · bounded witness

Qwen3-0.6B, pinned and executed locally.

This separate capsule binds one immutable publisher snapshot to three CPU runs. Its signed launch index makes the finite public record checkable under a task key; it does not transform one private synthetic case into a benchmark or launch claim.

qwen3-0.6b-hf-c1899de2

Qwen3-0.6B · one executed CPU witness.

All ten publisher files were streamed locally through SHA-256. The weights and 11.4 MB tokenizer JSON are not bundled; the retained record publishes no raw prompt, output, or deliberation.

Signed execution referrer · same curator

Qwen3-0.6B, witnessed on GitHub-managed Ubuntu x64.

This third capsule does not rewrite the release. Its signed witness index anchors the local capsule's exact release and launch digests to a workflow-produced evidence tar. The immutable ten-file snapshot descriptor set and byte total match; the public fixture differs from the earlier private fixture, so cross-platform output equality is not claimed. A second machine is not a second human, vendor, or publisher authority.

qwen3-0.6b-gh-ubuntu-abad124

One public fixture · provenance and misses retained.

The first attempt failed before inference on a namespace observation bug and remains visible. The successful thinking run stayed open at 96 tokens with no final answer; two non-thinking runs were token-identical, correct under last-numeric scoring, and strict-format failures.

Offline provenance verification assumes the locally resolved gh executable is trusted. The registry validator constrains its version and verification result, but does not authenticate or digest-pin that executable.

Synthetic mechanics · three separate lifetimes

One launch need not become one mutable scroll.

These three dummy records exercise the contract without making real-world claims. A release identity remains stable when a new runtime, evaluation, signature, correction, or deprecation is attached. Every edge names the digest it means.

01 · addressed by digest

Model release

Artifacts, interface, reasoning contract, disclosures, license states, and exact descriptors where bytes are available.

synthetic release JSON
02 · addressed by digest

Execution profile

Engine, precision, kernels, hardware, backend declarations, and an exact binding back to one release digest.

synthetic profile JSON
03 · separately addressed

Attestation

Build provenance, evaluation, signature evidence, correction, or deprecation bound to a release or profile.

synthetic evaluation JSON

Reviewed machine contract

The public schema is the reviewed bytes.

Canonical schema SHA-256 36b428ac4a890a6960ca06683ec9b758aa709ac4a0da3428bbd4344969318f87
open schema.v1.json

Launch path

Capture what can change independently.

InventoryList every runtime-critical artifact, interface, license, and disclosure state.
Hash bytesRecord media type, size, SHA-256, and whether the bytes were actually compared.
ReceiptValidate strict JSON and bind content, source bytes, schema, and validator implementation.
Resolve runtimePin local execution details or honestly name provider-managed and unknown API internals.
Attach claimsBind evaluations, builds, signatures, and corrections to exact subjects and evidence.

Fingerprint vocabulary

Four identities, four scopes.

NameScopeHonest boundary
Artifact descriptorExact file bytes, media type, and sizeA declaration until supplied bytes are streamed and compared.
Release digestCanonical release manifestShows the declaration is unchanged; says nothing by itself about safety or origin.
Profile digestCanonical execution houseNames declared runtime configuration, not universal reproducibility.
Backend observationTime-scoped provider claim and evidenceOpaque, provider-defined, and not a cryptographic weight fingerprint.

Reasoning interface, not private thought

Disclosure and continuation are separate axes.

What a caller may see

full · summary · none · unknown

This describes the public reasoning interface. It does not request or preserve hidden chain-of-thought.

How a turn may continue

plaintext · encrypted · server-held · none · unknown

Opaque continuation state can coexist with a visible summary. Compatibility is recorded without collecting a session trace.

The line

Validation is not a launch blessing.

It makes claims inspectable. It does not turn them into truth or authority.

  • The Kimi K3 capsule made no model or API call, downloaded no weight shards, and ran no inference, evaluation, or build.
  • Captured metadata, code, and license bytes are not the same evidence state as publisher-claimed weight-shard hashes.
  • The Qwen witness streamed all ten files locally; its 1.5 GB weights and 11.4 MB tokenizer JSON are not mirrored here.
  • Qwen's thinking attempt truncated at 128 tokens without a close or final segment. Its two non-thinking controls had identical continuation-token and decoded-output SHA-256 values and matched the private integer last, but failed strict formatting.
  • No raw prompt, expected value, decoded output, or generated deliberation from the local Qwen capsule is public. Its one private synthetic case is not a benchmark, safety test, quality assessment, or broad reasoning claim.
  • The GitHub-hosted witness anchors the same release and exact snapshot descriptor set, but uses a different public fixture. It makes no cross-platform output-equality claim and remains curator-observed.
  • The first GitHub run failed before inference on a namespace observation bug and remains visible. The successful thinking run was open at 96 tokens with no answer; its two non-thinking runs were token-identical, last-numeric matches, and strict-format failures.
  • Raw hosted output and deliberation are omitted; their fingerprints are public, and low-entropy result semantics are inferable from the scoring flags. The omitted bytes are not thereby reproduced, and hashes are not encryption.
  • Offline registry verification validates the signed file graph and retained GitHub/Sigstore bundle while forcing HTTP proxy routes to unreachable loopback. The bundle authenticates the workflow-produced tar, not its evaluation semantics or the loader's model-file inode.
  • A curator signature proves control of its task key, not publisher identity, vendor endorsement, safety, quality, behavior, or claim truth.
  • No promotion of aliases, seeds, tensor inventories, or behavioral probes into weight digests.
  • No user or KINGDOM session content in curated JSON records; captured publisher documents retain their public illustrative examples.
  • No launch, deployment, permission, or readiness authority is granted by a valid record, receipt, registry, or signature.