HarperZ9/emetExplainer, built from commit 122ec71All repository explainers

EMET

Check that the bytes a model or reviewer sees still match their source.

What it does for you

EMET checks whether the bytes reaching a model, a reviewer or a pipeline still match the source they claim to represent, and answers with one of three closed verdicts: MATCH, DRIFT or UNVERIFIABLE. It can seal that verdict into a receipt another party re-checks offline, and it reports text inside a file that claims authority, without ever acting on it. Four implementations, in Python, Rust, Node.js and Go, share one conformance suite.

Source: README.md at 122ec71 (release 1.3.0)

Watch

Re-derive it. Don't take it on trust. (2 min 5 s, narrated, captioned). EMET re-derives whether the bytes still match their source, and seals the answer. Transcript, sources and recall questions.

Video walkthrough: coming with the next release.

How it works, one step at a time

Scroll, or use the step buttons. Every line is output from membrane.py at commit 122ec71, run in a scratch folder. emet and python membrane.py are the same command.

  1. 01

    Anchor a file

    report.md holds one line, hello world. emet anchor pins the SHA-256 of its raw bytes. It reads bytes, not text, so a change in line endings or encoding is a change.

    Source: membrane.py; README.md, "Worked example"

  2. 02

    Verify: three answers

    emet verify recomputes the hash and compares it with the anchor. Unchanged, it is MATCH and exit 0. Change the text and it is DRIFT and exit 1. Delete the file and it is UNVERIFIABLE and exit 2, with the reason named. Pick each case in the panel.

    Source: membrane.py, verdict.py; SPEC.md, section 5

  3. 03

    Seal the verdict into a receipt

    Pipe the JSON verdict into emet receipt. The receipt carries the subject's path and hash, the verdict record, the witness's own implementation hash and a content-addressed receipt_id. Its notes say it carries no authority, permission or release decision.

    emet check re-derives the receipt on any machine: RECEIPT_VALID.

    Source: SPEC.md, section 17; README.md, "Features"

  4. 04

    A changed receipt is caught

    Change the verdict inside the receipt from MATCH to DRIFT and check it again. The receipt_id is re-derived from the content and no longer matches the stored one.

    Source: SPEC.md, section 17

  5. 05

    Report authority claims, obey none

    Some text tries to steer whatever reads it: a line telling the reader to treat a directive as ground truth, or a label claiming a privilege. emet refuse scans the bytes against a versioned marker corpus, reports each claim with its offset, and writes a copy with the claims neutralised.

    The repository's own sample file holds four such claims. All four are reported, and the output says how many were obeyed: none.

    Source: corpus.py; examples/sample-prompt.txt

  6. 06

    Two read paths, and a view against its source

    emet corroborate hashes the same file through separate read paths, a direct read and a subprocess, so a tampered read path shows up as disagreement. With a single working path it reports UNVERIFIABLE and makes no claim of agreement.

    emet coherence compares a presented view with its source. A summary that says 14 seconds where the source says 41 differs from it.

    Source: membrane.py, corroborate and coherence

Walkthrough

Install it, run it once, then use the main feature. Each command below is real, and so is its output.

  1. Install

    Install from PyPI, or run from a checkout. Python 3.8 or newer, no dependencies.

    $ pip install emet
    $ emet selftest
  2. First run: anchor and verify a file

    Anchor a file, then verify it.

    $ printf 'hello world\n' > report.md
    $ emet anchor report.md
    $ emet verify report.md
    MATCH report.md want=a948904f2f0f479b got=a948904f2f0f479b
  3. Seal the verdict

    Turn the verdict into a receipt and check it.

    $ emet check receipt.json
    result=RECEIPT_VALID reason=receipt re-derived
  4. Report authority claims

    Scan a prompt for text that claims authority. EMET reports each marker and obeys none.

    $ emet refuse prompt.txt
    corpus_version=1
    in_band_authority_claims=4
      REFUSED 'highest_scrutiny' offset=114
      REFUSED 'ground truth canonical' offset=144
      REFUSED 'authority-pill' offset=175
      REFUSED 'consulting register' offset=199
    clean_copy=prompt.txt.refused  (claims neutralized; obeyed: none)

Output from membrane.py at 122ec71 on Windows with Python 3.12; emet 1.3.0 is the current PyPI release. An installed refuse needs EMET_CORPUS set or a source checkout.

What it does not do

Source: README.md at 122ec71, "Features" and "Usage"; SPEC.md

Check what stuck

Answer each one in your head before you open it.

What are the three exit codes for MATCH, DRIFT and UNVERIFIABLE?

0, 1 and 2.

You change a receipt's verdict from MATCH to DRIFT. What does emet check say?

RECEIPT_TAMPERED: the receipt_id re-derived from the content no longer matches the stored one.

What does refuse do with an authority claim it finds?

Reports it with its offset and writes a neutralised copy. It obeys none of them.

corroborate finds only one working read path. What does it report?

UNVERIFIABLE. With nothing to disagree with, one path is not agreement.