Software provenance on GenLayer

Trace where software really came from.

ForkReason compares two repositories, reconstructs their development lineage from code, history, bugs and tests, weighs the innocent explanations alongside the obvious one, and records the finding as an immutable decision through GenLayer consensus.

Public GitHub repository — owner/name or a full URL.

Public GitHub repository — owner/name or a full URL.

Enter two repositories to begin.

No wallet needed to analyze. You only sign when you want a finding recorded on chain or a challenge submitted.

Live lineage reconstructionorigin → target
origin2021-04-02signalmarker appearsbugdefect presentfix2021-07-01target2021-11-19
  • 6evidence layers
  • 0repository code executed
  • ∞challengeable revisions

A worked example

A finding, with its counter-evidence attached

This is a fixture bundled with ForkReason for demonstration. Real cases in Explore come from actual repository analyses.

Fixture · not live data

acme/ledger-core→contrib/ledger-engine
Likely derivedHIGH

The target carries an off-by-one defect the origin fixed five months earlier, shares uncommon constants, and reuses distinctive test names under renamed modules. The commit timeline puts the origin first.

  • 5strong signals
  • 1conflicting signal
  • 6explanations weighed
  • 1revision recorded

Counter-evidence kept: the target's author renamed every module and rewrote the public API. ForkReason reports that divergence rather than suppressing it.

The reasoning

Similarity is not lineage

A code-matching tool answers “how similar are these?” and stops. A lineage tool has to answer “what actually happened here?” — and be honest when the answer is nothing.

  1. Similarity

    Two files match. That alone explains nothing — every framework produces matches.

  2. Chronology

    Did the signal appear in the origin before the target? Without order, similarity is coincidence.

  3. Historical evidence

    Shared defects, fix timing, and implementation order narrow what actually happened.

  4. Alternative explanations

    Shared upstream, same specification, coincidence, insufficient history — each scored on its own evidence.

  5. Consensus

    Independent validators re-derive the decision from the same evidence. Agreement is recorded on chain.

The evidence model

Six layers, weighted against coincidence

ForkReason measures a repository across six independent dimensions. A match on framework boilerplate is discounted to nothing before it can become evidence of anything.

Each layer can be strong on its own and still lead to INSUFFICIENT_EVIDENCE. That outcome is a result, not a failure.

How a direction is proven

Chronology is the part similarity cannot fake

Matching code proves two things share text. It says nothing about which came first. ForkReason reads both histories and looks for a defect that existed in one repository before the other appeared — because a bug nobody else writes identically is a timestamp you cannot forge.

Illustrative fixtureDemonstrates the rule the engine enforces on real repositories. Not live analysis data.
origin/repotarget/repo3f9c1ab8d40e77b17c9e0c2a55f15e70b31
  1. originorigin existsFirst commit. Establishes that derivation could happen from here.3f9c1ab
  2. originoff-by-one introducedchunked_transfer() drops the final byte. A distinctive mistake, not a common one.8d40e77
  3. originrare constant addedCHECKPOINT_MAGIC 0x5F3759DF, undocumented, never explained.b17c9e0
  4. originbug fixedOff-by-one corrected. The buggy behaviour now exists only in history.c2a55f1
  5. targettarget appearsIts first commit already contains the unfixed off-by-one.5e70b31

What the engine concludes

The target's earliest commit already contains the origin's unfixed defect, so the defect was carried across — not independently reinvented. Direction is origin → target, and this survives even if every other signal were removed.

Why GenLayer

One model does not decide the case

A lineage finding is a judgement about the past. Judgements that rest on one model reading two READMEs are not verifiable, and not worth recording.

GenLayer runs the decision through independent validators. A validator that merely confirms the leader has parsed valid JSON is not verification — so ForkReason's validators recompute the decision from the evidence and compare the substantive fields.

The result is a record anyone can check: the evidence manifest, its hash, the revision, and the transaction that committed it.

  1. 01

    Evidence

    The pipeline produces a bounded manifest: strongest signals, contradictions, and every competing explanation.

  2. 02

    Independent evaluation

    Validators do not vote on the leader's answer. Each derives its own conclusion from the same evidence.

  3. 03

    Stable fields compared

    Verdict, direction, shared upstream, confidence bucket. Prose is never compared for equality.

  4. 04

    Consensus

    Agreement produces a decision. Disagreement produces nothing — the case does not resolve as accepted.

  5. 05

    Immutable revision

    The finding is recorded with its manifest hash. It is appended to, never edited.

Contestable by design

A conclusion you disagree with should not be the end of it

Every resolved case can be challenged with new evidence. Revision N is never overwritten — a challenge produces revision N+1, and both stay readable forever.

The first pass

Strong code and bug signals, a compatible timeline, and no counter-evidence. ForkReason records a derivation and stops there.

Verifiable by construction

Open source, because the evidence has to be checkable

A forensic claim you cannot audit is a rumour with a nice font. ForkReason's pipeline, evidence model, contract and verdicts are all public.

Find out where it came from.

Two repositories. A real forensic pipeline. A decision you can check, challenge, and trace back to the evidence.

ForkReason — Trace where software really came from