{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:IRSWZVTFJRH77D7V7OD7EO7D5J","short_pith_number":"pith:IRSWZVTF","canonical_record":{"source":{"id":"1705.07354","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.PL","submitted_at":"2017-05-20T20:08:30Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"b7703343a39019b063afd851eaab839c4da281873681d7ca93de7fca86c6c353","abstract_canon_sha256":"3b00e55786194c61659270a1d0961f75404cb12128b3c37799d79b2a5ed2b0c2"},"schema_version":"1.0"},"canonical_sha256":"44656cd6654c4fff8ff5fb87f23be3ea7f9118266c432efbc451a01d5ed6f7ff","source":{"kind":"arxiv","id":"1705.07354","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.07354","created_at":"2026-05-18T00:19:04Z"},{"alias_kind":"arxiv_version","alias_value":"1705.07354v3","created_at":"2026-05-18T00:19:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.07354","created_at":"2026-05-18T00:19:04Z"},{"alias_kind":"pith_short_12","alias_value":"IRSWZVTFJRH7","created_at":"2026-05-18T12:31:21Z"},{"alias_kind":"pith_short_16","alias_value":"IRSWZVTFJRH77D7V","created_at":"2026-05-18T12:31:21Z"},{"alias_kind":"pith_short_8","alias_value":"IRSWZVTF","created_at":"2026-05-18T12:31:21Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:IRSWZVTFJRH77D7V7OD7EO7D5J","target":"record","payload":{"canonical_record":{"source":{"id":"1705.07354","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.PL","submitted_at":"2017-05-20T20:08:30Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"b7703343a39019b063afd851eaab839c4da281873681d7ca93de7fca86c6c353","abstract_canon_sha256":"3b00e55786194c61659270a1d0961f75404cb12128b3c37799d79b2a5ed2b0c2"},"schema_version":"1.0"},"canonical_sha256":"44656cd6654c4fff8ff5fb87f23be3ea7f9118266c432efbc451a01d5ed6f7ff","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:19:04.080969Z","signature_b64":"ZLLpb3T0Xz9Y7OFm1EuMqcZXk6qfxO00623Vcqzltb48dVrYxliJsYBlmvmkjbdCZbweCq/nJM76xCZWd4aNBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"44656cd6654c4fff8ff5fb87f23be3ea7f9118266c432efbc451a01d5ed6f7ff","last_reissued_at":"2026-05-18T00:19:04.080414Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:19:04.080414Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1705.07354","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:19:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"V+S8D+BmMDKhwCl4THCr81EUG3Eu0liJjF63MXTN4WLKDjFG6pQSJZsLixxWdnYYokB/IqpnZlgbNYPwUfkMBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T08:20:42.070983Z"},"content_sha256":"ebae15362bb4e9ff3f42e768151eda32544e428e7c766d7a7ac768287ea3bbb3","schema_version":"1.0","event_id":"sha256:ebae15362bb4e9ff3f42e768151eda32544e428e7c766d7a7ac768287ea3bbb3"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:IRSWZVTFJRH77D7V7OD7EO7D5J","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"The Meaning of Memory Safety","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.PL","authors_text":"Arthur Azevedo de Amorim, Benjamin C. Pierce, Catalin Hritcu","submitted_at":"2017-05-20T20:08:30Z","abstract_excerpt":"We give a rigorous characterization of what it means for a programming language to be memory safe, capturing the intuition that memory safety supports local reasoning about state. We formalize this principle in two ways. First, we show how a small memory-safe language validates a noninterference property: a program can neither affect nor be affected by unreachable parts of the state. Second, we extend separation logic, a proof system for heap-manipulating programs, with a memory-safe variant of its frame rule. The new rule is stronger because it applies even when parts of the program are buggy"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.07354","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:19:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ORS0vpqc7AvGXhf0wIGuimKBaqSZ4IQ0yTXNScTIboEGDckeVhwsBmgwPsPmyhtNAox/ReBPZo018LehyPKXDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T08:20:42.071687Z"},"content_sha256":"e3bb7d9dd27d5e51081366806a5dc6af8c9c97f92424453321e44fd3467e3e16","schema_version":"1.0","event_id":"sha256:e3bb7d9dd27d5e51081366806a5dc6af8c9c97f92424453321e44fd3467e3e16"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/IRSWZVTFJRH77D7V7OD7EO7D5J/bundle.json","state_url":"https://pith.science/pith/IRSWZVTFJRH77D7V7OD7EO7D5J/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/IRSWZVTFJRH77D7V7OD7EO7D5J/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T08:20:42Z","links":{"resolver":"https://pith.science/pith/IRSWZVTFJRH77D7V7OD7EO7D5J","bundle":"https://pith.science/pith/IRSWZVTFJRH77D7V7OD7EO7D5J/bundle.json","state":"https://pith.science/pith/IRSWZVTFJRH77D7V7OD7EO7D5J/state.json","well_known_bundle":"https://pith.science/.well-known/pith/IRSWZVTFJRH77D7V7OD7EO7D5J/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:IRSWZVTFJRH77D7V7OD7EO7D5J","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"3b00e55786194c61659270a1d0961f75404cb12128b3c37799d79b2a5ed2b0c2","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.PL","submitted_at":"2017-05-20T20:08:30Z","title_canon_sha256":"b7703343a39019b063afd851eaab839c4da281873681d7ca93de7fca86c6c353"},"schema_version":"1.0","source":{"id":"1705.07354","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.07354","created_at":"2026-05-18T00:19:04Z"},{"alias_kind":"arxiv_version","alias_value":"1705.07354v3","created_at":"2026-05-18T00:19:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.07354","created_at":"2026-05-18T00:19:04Z"},{"alias_kind":"pith_short_12","alias_value":"IRSWZVTFJRH7","created_at":"2026-05-18T12:31:21Z"},{"alias_kind":"pith_short_16","alias_value":"IRSWZVTFJRH77D7V","created_at":"2026-05-18T12:31:21Z"},{"alias_kind":"pith_short_8","alias_value":"IRSWZVTF","created_at":"2026-05-18T12:31:21Z"}],"graph_snapshots":[{"event_id":"sha256:e3bb7d9dd27d5e51081366806a5dc6af8c9c97f92424453321e44fd3467e3e16","target":"graph","created_at":"2026-05-18T00:19:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We give a rigorous characterization of what it means for a programming language to be memory safe, capturing the intuition that memory safety supports local reasoning about state. We formalize this principle in two ways. First, we show how a small memory-safe language validates a noninterference property: a program can neither affect nor be affected by unreachable parts of the state. Second, we extend separation logic, a proof system for heap-manipulating programs, with a memory-safe variant of its frame rule. The new rule is stronger because it applies even when parts of the program are buggy","authors_text":"Arthur Azevedo de Amorim, Benjamin C. Pierce, Catalin Hritcu","cross_cats":["cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.PL","submitted_at":"2017-05-20T20:08:30Z","title":"The Meaning of Memory Safety"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.07354","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ebae15362bb4e9ff3f42e768151eda32544e428e7c766d7a7ac768287ea3bbb3","target":"record","created_at":"2026-05-18T00:19:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"3b00e55786194c61659270a1d0961f75404cb12128b3c37799d79b2a5ed2b0c2","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.PL","submitted_at":"2017-05-20T20:08:30Z","title_canon_sha256":"b7703343a39019b063afd851eaab839c4da281873681d7ca93de7fca86c6c353"},"schema_version":"1.0","source":{"id":"1705.07354","kind":"arxiv","version":3}},"canonical_sha256":"44656cd6654c4fff8ff5fb87f23be3ea7f9118266c432efbc451a01d5ed6f7ff","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"44656cd6654c4fff8ff5fb87f23be3ea7f9118266c432efbc451a01d5ed6f7ff","first_computed_at":"2026-05-18T00:19:04.080414Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:19:04.080414Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ZLLpb3T0Xz9Y7OFm1EuMqcZXk6qfxO00623Vcqzltb48dVrYxliJsYBlmvmkjbdCZbweCq/nJM76xCZWd4aNBQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:19:04.080969Z","signed_message":"canonical_sha256_bytes"},"source_id":"1705.07354","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ebae15362bb4e9ff3f42e768151eda32544e428e7c766d7a7ac768287ea3bbb3","sha256:e3bb7d9dd27d5e51081366806a5dc6af8c9c97f92424453321e44fd3467e3e16"],"state_sha256":"c8e03eb5a7a006d6c319b104b984c259ba107333aa53d35d7f66ef89c175e2f1"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"e1mdTdMS+eOHSdsm+6vhZgqyizIxoO8b+imujShD3F8z9tm4XZXjNT4lK4mS9G6+XK939iZImDFqcYYHvxEiCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T08:20:42.075596Z","bundle_sha256":"12680457341fbb5eec3f98284c7958ebe8fecd5e2ce8730a5354f347d9d67814"}}