Skip to content

Run the Acta fixture checks as a receipt verifier and grade it against draft 03 - #469

Open
astrogilda wants to merge 2 commits into
agentrust-io:mainfrom
astrogilda-forks:feat/acta-receipt-verifier
Open

astrogilda wants to merge 2 commits into
agentrust-io:mainfrom
astrogilda-forks:feat/acta-receipt-verifier

Conversation

@astrogilda

Copy link
Copy Markdown
Contributor

This moves the Acta fixture tests' signature and chain checks into a receipt verifier, tools/acta_receipt_verifier.py, which those tests now call. It adds the draft-farley-acta-signed-receipts-03 rules for signature members in the payload (6.6), sha256-prefixed chain links (6.7) and key validity windows (9.2). The six fixtures keep their verdicts: none has a signature member, 6.7 allows their bare-hex links, and their key has no window.

Tests for the added rejections, each failing with its rule off: test_a_payload_carrying_a_signature_member_is_refused (6.6); test_issued_at_before_valid_from_is_refused and test_issued_at_at_valid_until_is_refused (9.2); test_a_link_naming_another_algorithm_is_refused and test_a_missing_link_after_a_known_predecessor_is_refused (6.7).

A separate workflow grades the verifier against the receipt-signature corpus of agent-evidence-vectors 0.17.4, which I maintain. requirements/acta-receipt-vectors.txt pins it by sha256, and the job sits outside the CI workflow that review waits on. With and without key windows it gets all 25 expected verdicts, as does @tomjwxf's @veritasacta/verify 0.10.21.

Move the signature and chain checks out of tests/test_acta_fixtures.py
into tools/acta_receipt_verifier.py, so the fixture tests and anyone
holding one receipt run the same code, and add the rules that revision
03 of draft-farley-acta-signed-receipts makes over revision 02:

- section 6.6: a payload carrying a signature member is refused, null
  and the empty string included;
- section 6.7: previousReceiptHash may carry the sha256: prefix, a
  prefix naming another algorithm is refused, and a receipt presented
  after a predecessor it does not link to is refused; the bare hex
  digest of revision 02 is still accepted;
- section 9.2: a key's valid_from and valid_until, when the key set
  gives them, bound issued_at.

The command line reads the issuer key from a JWK Set and answers with an
exit status and a JSON line. tests/test_acta_receipt_verifier.py has one
test per added rule, each failing when that rule is switched off.

Signed-off-by: Sankalp Gilda <23521054+astrogilda@users.noreply.github.com>
Run tools/acta_receipt_verifier.py through the vectors-receipt-signature
corpus of agent-evidence-vectors 0.17.4, which presents each receipt
twice, with the issuers' key set and without its validity windows, and
grades every answer against draft-farley-acta-signed-receipts-03. The
test asserts that every member ran, none failed, the section 9.2 window
check is applied, and no proposed rule outside the draft is.

The package needs Python 3.13 and requirements/dev.txt is compiled for
3.11, so it gets its own hash-pinned lock and workflow, as
runtime-evidence does. The CI matrix skips the file with a reason.

Signed-off-by: Sankalp Gilda <23521054+astrogilda@users.noreply.github.com>
@astrogilda
astrogilda requested review from a team, lywinged and rajnisht7 as code owners October 5, 2026 17:50
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

❔ Contributor Check: UNKNOWN

Check Result
Profile UNKNOWN
Credential LOW
Overall UNKNOWN

Automated check by AgenTrust Contributor Check.

@github-actions github-actions Bot added the needs-review:UNKNOWN Contributor check flagged UNKNOWN risk label Oct 5, 2026

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@astrogilda the verifier can come in. I checked the three rules against draft-03 and they match it: 6.6 on signature scope, 6.7 on the sha256: prefix and the bare-hex compatibility allowance, and 9.2 on key windows.

The corpus grading should not come in. Please drop .github/workflows/acta-receipt-vectors.yml, requirements/acta-receipt-vectors.in, requirements/acta-receipt-vectors.txt and tests/test_acta_receipt_vectors.py. This repo's CI does not install a contributor's own package to grade the spec's tooling. Run agent-evidence-vectors against tools/acta_receipt_verifier.py from your repo and publish the result there.

With those four files removed it merges once green.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review:UNKNOWN Contributor check flagged UNKNOWN risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants