smart-byte: the pack is placeholders, and the spec mandates a suite that does not exist #99
Open
dcharlot
wants to merge 3 commits from
ci/smart-byte-pack into main
pull from: ci/smart-byte-pack
merge into: Transaction-Science:main
Transaction-Science:main
Transaction-Science:ci/macos-energy-widen
Transaction-Science:ci/neural-e2e-guard
Transaction-Science:ci/tier2-packs
Transaction-Science:wai-webcodecs-negotiation
Transaction-Science:ci/macos-energy-backend
Transaction-Science:feat/wai-video-workflow
Transaction-Science:ci/joule-code-pack
Transaction-Science:ci/jcp-pack
Transaction-Science:joulecontract/run-negative-vectors
Transaction-Science:ci/jouleclaw-arm64-debuginfo
Transaction-Science:ci/run-conformance-verifiers
Transaction-Science:mesh/cost-calibration
Transaction-Science:diagnose/grounding-backing
Transaction-Science:wai/energy-operating-point
Transaction-Science:wai/2030-transport-landscape
Transaction-Science:wai/constraints-and-unidirectional
Transaction-Science:wai/determinism-tier-covers-emitted-medium
Transaction-Science:wai/moq-streaming-format
Transaction-Science:wai/mpeg-ai-part6-mapping
Transaction-Science:wai/prior-carriage-and-derivations
Transaction-Science:wai/receipt-classes-and-key-discovery
Transaction-Science:wai/task-fidelity
Transaction-Science:wai/transparency-emission
Transaction-Science:wai/c2pa-emitter
Transaction-Science:compliance/eu-scale-pack
Transaction-Science:compliance/composite-grade-v2
Transaction-Science:jcp/erasure-tombstone-v2
Transaction-Science:jcp/avoided-energy
Transaction-Science:jcp/erasure-tombstone
Transaction-Science:jcp/environment-binding
Transaction-Science:proof/stub-on-the-wire
Transaction-Science:compliance/composite-grade
Transaction-Science:mesh/context-cost-profile
Transaction-Science:ar-1-on-main
Transaction-Science:jcp/mcp-meta-receipt
Transaction-Science:wai/energy-binding
Transaction-Science:jcp/energy-coverage-relanded
Transaction-Science:jcp/energy-coverage
Transaction-Science:wai/video-byte-equality
Transaction-Science:eoc/multi-tenant-allocation
Transaction-Science:compliance/banding-function
Transaction-Science:ci-standards-workspaces
Transaction-Science:sandbox/honest-tier
Transaction-Science:proof/joule-ceiling
Transaction-Science:chore/rust-1.98-and-deps
Transaction-Science:wai-jpegai-full-wasm
Transaction-Science:wai-3d-landscape
Transaction-Science:wai-binding-real-decode
Transaction-Science:wai-determinism-tiers
Transaction-Science:wai-jpegai-wasm-demo
Transaction-Science:wai-jpegai-integrate
Transaction-Science:fix-byte-exact-includes
Transaction-Science:ci-windows-shell
Transaction-Science:jpegai-dequant-derive
Transaction-Science:ci-rust-setup
Transaction-Science:fl2-land
Transaction-Science:ci/cross-workspace-check
Transaction-Science:ci-enable
Transaction-Science:jcp-training-receipt
Transaction-Science:joule-code/repair-grant-literals
Transaction-Science:jcp-gateway-flow-relay
Transaction-Science:jcp-receipt-flow-seal
Transaction-Science:jcp-runtime-flow-gate
Transaction-Science:jcp-flow-witness
Transaction-Science:jcp-flow-lattice
Transaction-Science:rust-toolchain-1.97.1
Transaction-Science:score-binary-on-320fa1e
Transaction-Science:sandbox/cred-injection-2
Transaction-Science:sandbox/credential-injection
Transaction-Science:corpus-embedder-s5
Transaction-Science:jcp/cite
Transaction-Science:receipts-corpus-connector
Transaction-Science:jcp/grant-caveats
Transaction-Science:feat/jpegai-derive-inputs
Transaction-Science:feat/jpegai-weight-tools
Transaction-Science:feat/jpegai-icci-validation
Transaction-Science:jcp/x402-example-settlement
Transaction-Science:jcp/x402-bridge
Transaction-Science:jcp/receipt-payload-hash
Transaction-Science:fix/jpegai-pih-flags
Transaction-Science:feat/jpegai-e2e-chain
Transaction-Science:feat/jpegai-e2e-z
Transaction-Science:feat/jpegai-ton
Transaction-Science:jcp/dual-ceilings
Transaction-Science:feat/jpegai-pih
Transaction-Science:feat/jpegai-bitstream
Transaction-Science:feat/jpegai-icci-net2
Transaction-Science:feat/jpegai-icci-net
Transaction-Science:feat/jpegai-dwt
Transaction-Science:feat/jpegai-color
Transaction-Science:score-binary-rerank
Transaction-Science:feat/jpegai-efl
Transaction-Science:feat/jpegai-lef
Transaction-Science:feat/jpegai-efn
Transaction-Science:feat/jpegai-lsbs
Transaction-Science:feat/jpegai-reconstruct
Transaction-Science:jcp/orchestrate-profile-mapping
Transaction-Science:jpegai-sigma-index
Transaction-Science:hyperscale-floorfix
Transaction-Science:feat/jpegai-pipeline-dequant
Transaction-Science:feat/jpegai-e2e-synthesis
Transaction-Science:recovery/jpegai-decoders
Transaction-Science:wai/jpegai-synthesis-executor
Transaction-Science:jouletag-standard
Transaction-Science:wai/jpegai-gate-fixes
Transaction-Science:wai/int-transformer-executors
Transaction-Science:wai/int-transformer-kernels
Transaction-Science:energy/rapl-nvml-hardware-fixes
Transaction-Science:fix/omni-build-and-gguf-tokenizer
Transaction-Science:jouletable-standard
Transaction-Science:jouleclaw/gguf-decoders
Transaction-Science:wai/confidentiality-freshness
Transaction-Science:joulehook-standard
Transaction-Science:honest-counter-provenance
Transaction-Science:amd-kds-adapter
Transaction-Science:evidence-derived-grounding
Transaction-Science:mapping-physically-rooted-clarify
Transaction-Science:attested-efficiency-demo
Transaction-Science:efficiency-energy-attestation
Transaction-Science:mapping-attested-kernel
Transaction-Science:energy-counter-attestation
Transaction-Science:efficiency-surface
Transaction-Science:efficiency-spec
Transaction-Science:harness-econ
Transaction-Science:federation-quic-on-main
No reviewers
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
Transaction-Science/open-standards!99
Loading…
Reference in a new issue
No description provided.
Delete branch "ci/smart-byte-pack"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
smart-byte/conformance/v1is published for third parties to certify against.Its gate —
.github/workflows/conformance.yml, named "smart-byte conformancegate" — runs
jqover it: valid JSON, top-level array,nameanddescriptionpresent, names unique within a file.Those are well-formedness checks. No value in the pack has ever been compared
against the implementation, and
smart-byte-rshas no conformance crate thatreads it.
This is documented, not hidden
conformance/v1/regeneration.mdis candid that theexpected_*fields areplaceholders "not yet cryptographically computed". Nobody concealed anything.
What changed is its precondition. The doc says to regenerate "when
smart-byte-rslands", describing it as a "private repo, to be open-sourcedalongside spec v1.0 freeze".
smart-byte-rshas landed — 22 crates, in thestandards-buildmatrix. The mechanical pass it describes is now possible, andoverdue. Its named entry point,
cargo run --bin gen-conformance-vectors, doesnot exist.
What the pack actually contains
Established by running it, not reading it.
✅ REAL — and now asserted properly. Every positive vector's
signing_key_seedderives exactly theverifying_keyit publishes. GenuineEd25519.
sig-004-wrong-key's deliberate mismatch is asserted too, so thenegative case cannot quietly become a positive one.
⚠️ NOT REAL — now pinned so it is visible.
sig-001b""sig-002/003<PLACEHOLDER_SAID>;expected_saidis one repeated character;canonical_cbor_hexis the same 7-byte truncated prefixcanon-002,canon-003expected_cbor_hexof odd length (109 and 37 chars) — undecodablesaid-004vssaid-005Second commit: the spec is in worse shape than the pack
From asking why the vectors could not simply be regenerated.
spec/identity_and_key_rotation.mdsays implementers "MUST pass everyvector" in a pack whose every
expected_saidis a placeholder. Therequirement is unsatisfiable as written — a conforming implementation
cannot be conforming.
empty-map case, the one-field case, the worked example, several
envelope-shaped objects, and "one adversarial case where a non-canonical CBOR
encoding produces a different digest (to verify that implementations reject
non-canonical input rather than silently re-encoding)". The file holds five
vectors, all envelope-shaped. That adversarial case is the only negative
test named, it is the security-relevant one, and it is absent — an
implementation that silently re-encodes non-canonical input passes this pack
completely.
../conformance/said_vectors.json, which does not exist; the file is at../conformance/v1/said_vectors.json. Line 266 states "all paths are relativeto this file", so both the breakage and the intent were unambiguous. This is
the one thing here that is corrected rather than pinned — it is a pointer
fix, not a normative change.
Falsified
Every pinning test was falsified by simulating the fix, which is the only
way to prove a pin will fire when the thing it pins is repaired:
said-005a distinctexpected_saidcanon-002's hex even-lengthverifying_keysig-001's signaturePack and spec restored afterwards and verified byte-identical to main. Workspace
622 passed, 0 failures;
clippy -D warningsclean onsmart-byte-core;check-no-vanity-metrics.shpasses.What this does not do
No vector is touched. Regenerating a published pack — and deciding whether it
should gain the missing cases — is a normative change to a public artifact and a
maintainer's call. This moves the state out of a doc nobody opens and into test
output, and gives a signal the moment someone regenerates, correctly or not.
The follow-up, if you want it: write the missing
gen-conformance-vectorsagainst the now-landed
smart-byte-rs, add the adversarial non-canonical case,and do the mechanical pass. That is a separate, normative PR.
🤖 Generated with Claude Code
`smart-byte/conformance/v1` is published for third parties to certify against. Its gate — `.github/workflows/conformance.yml`, named "smart-byte conformance gate" — runs `jq` over it: valid JSON, top-level array, `name` and `description` present, names unique. Those are well-formedness checks. No value in the pack has ever been compared against the implementation, and `smart-byte-rs` has no conformance crate that reads it. `conformance/v1/regeneration.md` is candid that the `expected_*` fields are placeholders "not yet cryptographically computed". So this is a known state, openly documented, and not a defect anyone hid. What has changed is its stated precondition: the doc says regenerate "when `smart-byte-rs` lands", describing it as a "private repo, to be open-sourced alongside spec v1.0 freeze". `smart-byte-rs` HAS landed — 22 crates, in the `standards-build` matrix — so the one mechanical pass that doc describes is now possible, and overdue. Its named entry point, `cargo run --bin gen-conformance-vectors`, does not exist. What the pack actually contains, established by running it rather than reading it: REAL — every positive vector's `signing_key_seed` derives exactly the `verifying_key` it publishes. That is asserted properly here, along with `sig-004-wrong-key`'s deliberate mismatch, so the negative case cannot quietly become a positive one. NOT REAL — the `expected_*` values: - `sig-001` says it signs "a known envelope SAID". It does not. The value is RFC 8032's signature over the EMPTY message, proven by verifying it against `b""`. `sig-002`/`sig-003` carry another RFC 8032 signature, over neither their SAID nor the empty message. - Every SAID envelope carries the literal `<PLACEHOLDER_SAID>`; every `expected_said` is one repeated character rather than a digest; every `canonical_cbor_hex` is the same 7-byte truncated prefix. - `canon-002` and `canon-003` publish `expected_cbor_hex` of ODD length (109 and 37 characters), which cannot be decoded to bytes at all. A third party fails before reaching any comparison. - The doc's own consistency claim does not hold in the direction that matters: `said-004` and `said-005` are different envelopes published with the SAME expected SAID, so even as filler the pack asserts a collision. The pinning tests are written to FAIL once the pack is regenerated, which is the intended signal to replace each with a real assertion — the same pattern `map-conformance` uses for its JSON round-trip defect. Each was falsified by simulating the fix: substituting a real-looking SAID, giving `said-005` a distinct value, making `canon-002`'s hex even-length, corrupting a verifying key, and replacing `sig-001`'s signature. All five fail as intended, and the pack was restored and verified byte-identical to main. Regenerating a published pack is a normative change to a public artifact and a maintainer's call, so no vector is touched here. This only makes the state visible in test output instead of in a doc nobody opens. Co-Authored-By: Claude Opus 5 <[email protected]>d92626d08623ceabf08esmart-byte: verify what the pack really contains, and pin what it does notto smart-byte: the pack is placeholders, and the spec mandates a suite that does not exist23ceabf08e0acb0cc57f0acb0cc57f5391e895d5View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.