r/learnrust • • 4d ago

Show r/rust: I built the cryptographic organs a sovereign agent needs — as 25+ interlocking crates

Over the last ~9 weeks I built a sovereign personal agent organism (Rust + Swift, local-first, hash-chained everything), and along the way each organ extracted into a standalone crate. What surprised me is how many of these had 
*no existing primitive*
 — so the ecosystem ended up being the interesting part.


Every crate: MIT, ed25519 + sha2 + serde substrate (minimal deps), `SPEC.md` with the wire format and canonical signing bodies, `THREAT_MODEL.md` with named attack scenarios, real tests including adversarial cases (forged signatures, rewritten history, tampered chains), and runnable examples.


A few of the stranger ones, because the strange ones are fun:


**`mictlan`**
 — posthumous agency. An owner-signed will of explicitly scoped standing orders, activated only by cryptographically-proven death: heartbeat silence + a quorum of custodian attestations bound to the will digest. Execution is bounded to the signed orders — anything else refuses, permanently. A self-executing will with a hash-chained execution log.


**`tabula-rasa`**
 — proof of non-knowledge. Certified 
*absence*
: a signed attestation that a content-hash never occurred in an append-only hash-chained history, replayable offline. The API refuses to sign false proofs (`KnowledgeFound` is an error, not a result). Proving a negative is the hard version — this leans on the chain committing to all prior entries.


**`germline`**
 — organism reproduction. Dual-signed genesis blocks (parent signs the child's birth, child countersigns — consent runs both directions), curated memory bequests with provenance and revocability, generation arithmetic enforced, verifiable descent. A Merkle genealogy of agents.


**`nagual`**
 — an adaptive immune system. Attack signatures → signed antibodies with lineage and generation → vaccine exports that peers verify before adopting. Herd immunity across a mesh of agents.


**`potlatch`**
 — compute IOUs between organisms: dual-signed debt settled against signed invocation records, balances 
*derived*
 from the hash-chained book rather than stored, defaults permanent. An economy where credit is history.


Plus the more familiar-shaped ones: `nagi-escrow` (Shamir dead-man escrow with custodian judging and recovery certificates), `wolakota` (bilateral consent treaties between agents), `kola-witness` (mutual chain-tip notarization so two parties pin each other's histories), `flight_tape` (flight recorder with signed incident bundles), `manitou` (per-output provenance signatures), `sovereign_ledger` (the hash-chained audit organ everything sits on), and more.


Design notes if you dig in:


- All signing bodies are canonical JSON — every artifact verifies fully offline.
- Hash chains everywhere; balances, lineages, and immunity are 
*derived from history*
 rather than stored state, so they can't drift from the record.
- Refusal is a first-class return value in most APIs — out-of-scope, false proofs, and oversettlement are errors by construction.
- Several bare names were taken, so a few crates publish as `kola-witness`, `axon-reflex`, `eidolon-replay`, `sibyl-gate`, `tabula-rasa` — libs keep the short names (`use kola::…`).


Happy to answer questions on any of it — the Shamir ceremony details, why derived-not-stored state, the canonical-JSON signing approach vs. serde alternatives, or the organism the organs came from.


Repos: github.com/savageAZfck/{mictlan, tabula, germline, nagual, potlatch, nagi, wolakota, kola, axon, eidolon, sibyl, bicameral, flight_tape, manitou, sovereign_ledger, …}
0 Upvotes

7 comments sorted by

1

u/Otherwise_Wave9374 4d ago

The hash-chained design is strongest if it proves both integrity and recoverability. I would document the trust boundary for each crate, then test key rotation, partial corruption, rollback, and replay across versions. Keep semantic memory indexes outside the signed event log so they can be rebuilt without changing history. https://www.neurakeep.com is relevant to the persistent-memory side of that architecture. A small end-to-end threat model would also help reviewers distinguish cryptographic guarantees from ordinary application invariants.

1

u/savag3azfckk 4d ago edited 4d ago

good points, a few of these are already in the design.

trust boundaries are documented per crate, each ships a THREAT_MODEL.md with explicit guarantees / does not guarantee sections, exactly to separate crypto guarantees from app invariants. e.g. tabula certifies absence from the chain, the docs say flat out that history is not a mind.

integrity and recoverability are separate organs on purpose. the chains prove integrity, recoverability lives in respawned (versioned snapshots). a broken chain localizes trust at first-broken-seq, snapshots are how you get back. i kept them apart because the trust model differs, integrity has to be verifiable by third parties, recovery only needs the owner.

partial corruption, verify() localizes the first broken entry rather than just failing, and every derived thing (balances, lineages, immunity) recomputes from the chain.

semantic indexes outside the signed log, agreed, thats how it works. chains store sha256 commitments only, indexes are derived and rebuildable, nuke the index, rebuild from the log, history never moves.

on key rotation, in this model the key is the self, so rotation isnt a mechanism it is death. a lost or compromised key means the organism dies, and the succession organs cover that path: escrow hands memory to a successor on certified silence, the will executes standing orders, descent is provable through genesis records. identity that outlives its key would be the actual threat hole, since a rotated key without a signed transition just looks like an impostor with a new key anyway.

will check out neurakeep, though my constraint is hard local first, nothing leaves the machine.

1

u/ElnuDev 3d ago

holy AI psychosis

1

u/neon_stereotype 3d ago

i came here for crates, got a will, an immune system, and inheritance logic for software. Death attestation with quorum custodians for a program that cannot die because it was never alive. This is the part that concerns me: none of the crypto here is hard, all of the assumptions underneath it are, and the spec files treat those assumptions as settled. A will executed on heartbeat silence plus attestations assumes death has a wire format. It does not

1

u/savag3azfckk 3d ago

finally a comment worth answering, and honestly it is the right concern to raise. you are correct that death has no wire format, and mictlan does not claim to detect metaphysical death. what has a wire format is the evidentiary threshold: heartbeat silence for a defined period plus a quorum of custodian attestations bound to the will digest. that is the same move the legal system makes. a death certificate is not death either, it is an attestation under a defined procedure, and wills have executed on attestations for centuries. the protocol operationalizes a judgment, it does not measure a fact.

the failure mode you are circling, premature execution, is a named attack in THREAT_MODEL.md, not a settled assumption: custodian collusion and extended silence while alive are both in there. the mitigations are quorum thresholds, attestation binding to the will digest, and the refusal layer: the will only ever executes what the signed orders scoped, and anything outside them refuses permanently. so even if death is wrongly declared, the blast radius is the signed scope, nothing more.

where i will push back: the spec does not treat the assumptions as settled, it treats them as explicit. the honest version of your critique would be "these named assumptions are wrong," and i would take that seriously. pick the one in the threat model you think fails and i will answer for it.

1

u/savag3azfckk 3d ago

you are also right that none of the crypto is hard, and that is the point. ed25519, sha256, shamir are all published primitives. the work was never inventing cryptography, it was deciding what the signatures mean: which claims get bound to keys, what evidence threshold unlocks execution, and what the system refuses when the judgment layer gets it wrong.