The source-integrity gap is the part I keep staring at. Proving a predicate over a committed value feels clean enough, but once you have to attest to the binary that touched the data, it starts sounding like you are proving the whole stack by side quest.