conformance
v1.0.0The shared conformance test corpus and harness. 248 known-good vectors and 187 known-bad vectors, plus a language-agnostic runner that drives any reference library.
About this artefact
The conformance package is what every implementation must pass to claim compatibility. The maintainer reports 248 known-good vectors (valid receipts that MUST verify) and 187 known-bad vectors (mutated, replayed, or chain-broken receipts that MUST NOT verify); the corpus is not published, so these counts cannot be checked from here. Vectors are released under CC0 so they can be embedded directly into any project, including proprietary forks.
The harness — under Apache-2.0 — is a small Rust binary that takes a verifier executable as an argument and runs the entire corpus through it, producing a JSON report with per-vector pass/fail and a summary digest. The harness is not published yet.
Manifest
Quick start
# The downloadable corpus tarball is being prepared and is not yet # published. Build the harness and run it from the source tree in the # meantime.
# Run the harness against any verifier binary
cargo run --manifest-path harness/Cargo.toml -- \
--verifier ./signedreceipt \
--report ./report.json
# Submit the digest in your /badge/ application
jq -r '.summary.digest' report.json
Issues / questions
Bug reports, patches, and security advisories all go to the CloakAPI open-source inbox.
Back to /source/ · related: spec · conformance · implementations