Repository navigation
Run the Acta fixture checks as a receipt verifier and grade it against draft 03 - #469
astrogilda wants to merge 2 commits into
Conversation
Move the signature and chain checks out of tests/test_acta_fixtures.py into tools/acta_receipt_verifier.py, so the fixture tests and anyone holding one receipt run the same code, and add the rules that revision 03 of draft-farley-acta-signed-receipts makes over revision 02: - section 6.6: a payload carrying a signature member is refused, null and the empty string included; - section 6.7: previousReceiptHash may carry the sha256: prefix, a prefix naming another algorithm is refused, and a receipt presented after a predecessor it does not link to is refused; the bare hex digest of revision 02 is still accepted; - section 9.2: a key's valid_from and valid_until, when the key set gives them, bound issued_at. The command line reads the issuer key from a JWK Set and answers with an exit status and a JSON line. tests/test_acta_receipt_verifier.py has one test per added rule, each failing when that rule is switched off. Signed-off-by: Sankalp Gilda <23521054+astrogilda@users.noreply.github.com>
Run tools/acta_receipt_verifier.py through the vectors-receipt-signature corpus of agent-evidence-vectors 0.17.4, which presents each receipt twice, with the issuers' key set and without its validity windows, and grades every answer against draft-farley-acta-signed-receipts-03. The test asserts that every member ran, none failed, the section 9.2 window check is applied, and no proposed rule outside the draft is. The package needs Python 3.13 and requirements/dev.txt is compiled for 3.11, so it gets its own hash-pinned lock and workflow, as runtime-evidence does. The CI matrix skips the file with a reason. Signed-off-by: Sankalp Gilda <23521054+astrogilda@users.noreply.github.com>
|
❔ Contributor Check: UNKNOWN
Automated check by AgenTrust Contributor Check. |
imran-siddique
left a comment
There was a problem hiding this comment.
@astrogilda the verifier can come in. I checked the three rules against draft-03 and they match it: 6.6 on signature scope, 6.7 on the sha256: prefix and the bare-hex compatibility allowance, and 9.2 on key windows.
The corpus grading should not come in. Please drop .github/workflows/acta-receipt-vectors.yml, requirements/acta-receipt-vectors.in, requirements/acta-receipt-vectors.txt and tests/test_acta_receipt_vectors.py. This repo's CI does not install a contributor's own package to grade the spec's tooling. Run agent-evidence-vectors against tools/acta_receipt_verifier.py from your repo and publish the result there.
With those four files removed it merges once green.
This moves the Acta fixture tests' signature and chain checks into a receipt verifier,
tools/acta_receipt_verifier.py, which those tests now call. It adds the draft-farley-acta-signed-receipts-03 rules for signature members in the payload (6.6), sha256-prefixed chain links (6.7) and key validity windows (9.2). The six fixtures keep their verdicts: none has a signature member, 6.7 allows their bare-hex links, and their key has no window.Tests for the added rejections, each failing with its rule off: test_a_payload_carrying_a_signature_member_is_refused (6.6); test_issued_at_before_valid_from_is_refused and test_issued_at_at_valid_until_is_refused (9.2); test_a_link_naming_another_algorithm_is_refused and test_a_missing_link_after_a_known_predecessor_is_refused (6.7).
A separate workflow grades the verifier against the receipt-signature corpus of agent-evidence-vectors 0.17.4, which I maintain.
requirements/acta-receipt-vectors.txtpins it by sha256, and the job sits outside the CI workflow that review waits on. With and without key windows it gets all 25 expected verdicts, as does @tomjwxf's@veritasacta/verify0.10.21.