Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

All Projects
productioncore

ONLY Lang

A DSL where equilibrium is the only truth


A domain-specific language for arithmetic constraints, self-healing fields, ghost memory, policy gates, and Trust Derivation Objects. Scripts declare harmony, evolve lost variables, assert bounds, track lineage, and optionally emit Groth16 ZK proofs so an auditor can verify under-budget without seeing proprietary numbers. Compiled IR runs sub-microsecond equilibrium checks; WASM target runs in the browser.

Overview

ONLY Lang is the policy and arithmetic language of the ONLY Engine. Traditional languages are Boolean: a flipped bit is an error. ONLY Lang is equilibrium: a flipped value is a solvable unknown. The interpreter (and its compiled IR) treat require_equilibrium(τ) as a first-class constraint — the residual ( r = \sum s_i v_i ) must satisfy ( |r| \le τ ), or the script heals, denies, or escalates.

The language is not general-purpose. It is deliberately small: arithmetic constraints, bounded branching, ghost encoding, and evidence export. That restriction is the product.

The Arithmetic Substrate

Four crates form the runtime:

  • only-core (no_std) — Prouhet–Thue–Morse sign generation, residual ( \sum s_i v_i ), first-order equilibrium check
  • only-evolution (no_std) — the healer. Single-missing solve: ( v_{target} = -\mathrm{sum} / s_{target} ). Multi-missing strategies (equal mids, ratio ends, affine ends) when extra constraints are present
  • only-memory (no_std) — Ghost Memory. First-order equilibrium looks empty to the provider (( \sum s_i v_i = 0 )); the second-order moment ( \sum s_i v_i^2 ) encodes the payload for the holder
  • only-lang — parser (nom), evaluator, TDO export, evidence packs, WASM bindings

If a field is corrupted, evolve(i) reconstructs index ( i ) from the remaining values. Tests cover a full corruption matrix: every index zeroed, healed, and the ghost payload still revealed.

Language Surface

Scripts are sequences of commands, not general programs:

require_equilibrium(1e-9)
alias(0, "salary")
alias(1, "bonus")
bind_all()
assert_bounds(0.0, 200000.0, "salary")
budget_limit(250000.0)
track_lineage(true)
generate_zk_proof(true)
report_json()
CommandMeaning
harmony(τ) / require_equilibrium(τ)Set residual tolerance; fail if (
evolve(i)Heal missing/corrupted index ( i )
data(d) / corrupt(i)Encode a ghost payload; zero an index
assert_bounds(min, max, i|name)Range-check a field or named alias
budget_limit / max_exposure / volatility_limit / time_windowPolicy ceilings
if_broken { ... }Run inner commands only when equilibrium fails
if_greater_than("name", v) { ... }Named-alias predicate (no general if/else)
escalate("reason")Human-in-the-loop override — gate state becomes ESCALATE
track_lineage(true)Mint a Trust Derivation Object on exit
generate_zk_proof(true)Compile the invariant to a Groth16 circuit (--features zk)
import("policy.only")Compose policies from files
report() / report_json() / report_to("path")Human or TDO JSON export

Fuel bounding (fuel_consumed vs a gas limit) makes runaway scripts fail closed.

Trust Derivation Object (TDO)

When track_lineage(true) is set, the evaluator mints a TDO on exit:

  • executed command trace
  • fuel used
  • linked identity (DID / wallet)
  • final residual
  • gate state: ALLOW / DENY / ESCALATE
  • replay hash and signature placeholder

report_json() emits the full TDO. This is the audit artifact: an auditor can replay the script against the same signs and confirm the gate decision.

Zero-Knowledge Proofs

Plaintext TDOs reveal the actual field values. Enterprises often cannot: salary, transaction amount, exposure. generate_zk_proof(true) (feature zk, arkworks Groth16 over BN254) compiles the invariant into an arithmetic circuit:

Public: signs, tolerance ( τ ), gate state, fuel limit Private: field values, fuel consumed

Constraints: residual equality, ( |r| \le τ ), optional per-index bounds, fuel ≤ limit.

The TDO then carries a Groth16 proof instead of the raw numbers. The auditor verifies under-budget / in-bounds / in-equilibrium without seeing proprietary values. (Trusted setup is circuit-specific; production deployments should use an MPC ceremony.)

Compiled IR and WASM

  • only-lang-ir — bytecode (1–9 bytes/op) for sub-microsecond equilibrium checks on embedded targets. Harmony, evolve, corrupt, residual, policy limits, IF_BROKEN jumps, halt
  • only-lang-wasm — wasm-pack --target web build with target-specific tokio/getrandom so the same evaluator runs in the browser

Evidence, Identity, Documents

Beyond the arithmetic core, only-lang ships the enterprise envelope:

  • Evidence packs — HTML/SVG/JSON artifacts with gate badges, reason codes, tool-gating tables
  • Evidence store — queryable run history; ZKP compliance proof placeholder
  • LifeStack identity — codon-DAG delegation lineage, RLWE enclave binding
  • Document governance — C2PA read, PDF sign, PIR watermark
  • SDK — OnlyOSClient propose → decide → execute gated tools with ALLOW/DENY/ESCALATE
  • Small claims — qualification, letter draft, court-filing stub (England & Wales pilot)

Use Cases

  • Policy gates that must fail closed (budget, exposure, volatility)
  • Self-healing numeric fields in telemetry and finance
  • Ghost-encoded payloads that look empty to an untrusted provider
  • Audit-grade TDOs for DGV / EU AI Act evidence
  • Privacy-preserving proofs: "this salary was under cap" without revealing the salary
  • Browser-side equilibrium checks via WASM
  • Embedded / FPGA residual checks via the IR

Status

Parser, evaluator, healer, ghost memory, TDO export, IR, and WASM target are implemented. Groth16 integration is wired behind --features zk (arkworks 0.5, BN254).

Key Highlights

  • Equilibrium-first DSL — residual Σ s_i v_i, heal via evolve(i), ghost payload in the 2nd moment
  • Trust Derivation Objects — command trace, fuel, identity, gate state, replay hash
  • generate_zk_proof(true) — Groth16 over BN254 so auditors verify without seeing values
  • Compiled IR for <1µs embedded checks; wasm-pack target for the browser
  • if_broken / escalate / fuel limits — no unbounded general branching
  • Evidence packs, LifeStack identity, C2PA/PDF/PIR watermark, gated SDK

Links