Skip to content

Add frozen CH06 conformance matrix - #49

Merged
404SecNotFound merged 1 commit into
mainfrom
codex/ch06-conformance-matrix
Sep 8, 2026
Merged

404SecNotFound merged 1 commit into
mainfrom
codex/ch06-conformance-matrix

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

Cohaera's CH06 evidence-integrity claim had unit and smoke coverage but no frozen comparison against a verifier that does not share its implementation. This PR adds a deterministic conformance lab built from one pristine signed, multiplexed stream and applies nine mutations only after signing.

The lab covers intact, deleted, modified, chain-metadata-stripped, reordered, truncated, replayed, missing-key, and unsupported-scheme inputs. A hand-written expectation file is compared with both Cohaera and a standard-library-only baseline that independently implements canonical hashing, sequence/chain checks, Ed25519 verification, and replay state.

Current result:

  • 9/9 predeclared cases pass.
  • 0 manipulated affected sessions report verified_complete.
  • 0 intact or reorder-only sessions report inadmissible.
  • Missing and unsupported evidence explicitly degrades or declines.
  • Cohaera provides additional per-session localization for a body modification and a truncated stream.

Validation:

  • python lab/local/run.py --check
  • python lab/ch06/run.py --check
  • pytest -q tests/test_ch06_lab.py tests/test_lab.py — 48 passed
  • python tools/verify.py — 16 passed, 0 failed, 0 not evaluated; 1,190 tests

@404SecNotFound
404SecNotFound merged commit 6c7b26c into main Sep 8, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant