/conformance are an 83-fixture subset), plus a language-agnostic runner that drives any reference library.">
/source/ · Test corpus · Apache-2.0 harness · CC0 vectors

conformance

v1.0.0

The shared conformance test corpus and harness. 248 known-good vectors and 187 known-bad vectors, plus a language-agnostic runner that drives any reference library.

published March 2026

About this artefact

The conformance package is what every implementation must pass to claim compatibility. The maintainer reports 248 known-good vectors (valid receipts that MUST verify) and 187 known-bad vectors (mutated, replayed, or chain-broken receipts that MUST NOT verify); the corpus is not published, so these counts cannot be checked from here. Vectors are released under CC0 so they can be embedded directly into any project, including proprietary forks.

The harness — under Apache-2.0 — is a small Rust binary that takes a verifier executable as an argument and runs the entire corpus through it, producing a JSON report with per-vector pass/fail and a summary digest. The harness is not published yet.

Manifest

No tarball or file manifest is published yet. When a release is published, its file list and SHA-256 fingerprints will be computed from the published files and listed here.

Quick start

shell
# The downloadable corpus tarball is being prepared and is not yet
# published. Build the harness and run it from the source tree in the
# meantime.
shell
# Run the harness against any verifier binary
cargo run --manifest-path harness/Cargo.toml -- \
    --verifier ./signedreceipt \
    --report ./report.json

# Submit the digest in your /badge/ application
jq -r '.summary.digest' report.json

Issues / questions

Bug reports, patches, and security advisories all go to the CloakAPI open-source inbox.

open-source@cloakapi.io

Back to /source/ · related: spec · conformance · implementations