Skip to content

fix(extensions): align verifiability test vectors with the reference implementation - #1400

Open
xibz wants to merge 1 commit into
cloudevents:mainfrom
xibz:fix/verifiability-test-vectors
Open

xibz wants to merge 1 commit into
cloudevents:mainfrom
xibz:fix/verifiability-test-vectors

Conversation

@xibz

@xibz xibz commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #1386. Some of the verifiability extension's published test vectors didn't match the reference implementation, and some couldn't be reproduced from the event JSON printed next to them, so implementations couldn't pass them as written.

Proposed Changes

  • Cases 1 and 2 carried an outdated payload: a bare digest instead of the JSON material body.
  • Cases 6a and 6b were corrupted, and their signatures didn't verify against the test key.
  • Cases 1–5 printed their events with different indentation from the events that were signed. Whitespace inside data is part of the signed bytes, so the digests didn't match the events shown.
  • Every vector is now the reference implementation's expected value, and Cases 1–5 print their events exactly as its test fixtures, so signing each printed event reproduces its vector.
  • The HTTP examples are consistent too: the structured-mode examples use the Case 1 event so the signed one carries Case 1's material, the binary-mode example is signed over its body as shown, and each Content-Length matches its body.

No normative text changes. Only the example values are updated.

Release Note

Verifiability extension: corrected the test vectors and HTTP examples so every published value reproduces from the event shown.

…implementation

Some published vectors didn't match the reference implementation, and
some couldn't be reproduced from the event JSON printed next to them:

- Cases 1 and 2 carried an outdated payload, a bare digest instead of the
  JSON material body.
- Cases 6a and 6b were corrupted and their signatures didn't verify
  against the test key.
- Cases 1-5 printed their events with different indentation from the
  events that were signed. Whitespace inside `data` is part of the signed
  bytes, so the digests didn't match the events shown.

Every vector is now the reference implementation's expected value, and
Cases 1-5 print their events exactly as its test fixtures, so signing
each printed event reproduces its vector.

The HTTP examples are made consistent too: the structured-mode examples
use the Case 1 event so the signed one carries Case 1's material, the
binary-mode example is signed over its body as shown, and each
Content-Length matches its body.

Signed-off-by: xibz <bjp@apple.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant