[SCITT] Re: A page for independent runs of the Vaara conformance vectors

Henri Sirkkavaara <hello@vaara.io> Fri, 21 August 2026 05:28 UTC

Return-Path: <hello@vaara.io>
X-Original-To: scitt@mail2.ietf.org
Delivered-To: scitt@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9CD9912D30722 for <scitt@mail2.ietf.org>; Thu, 20 Aug 2026 22:28:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787290080; bh=DCGYd/rE9XtWjPRONXMSrYBg+LxSU8LcTJIF13HVRtc=; h=Date:To:From:Cc:Subject:In-Reply-To:References; b=QLtiLHvjepBCtK/3STf3Lb5rmLZBaMLQz+dH6TA/z6zuEZx36SP2D7bn+5faEZ7Th wQoCRtfWA+bj43V4DpeGZdPbu+ba2odD6/vTQoc7lbmWr7TSB4oQO6+fH+di//QTmK Stx1Z59aLc2sdGXc/tc8/ggq0BX266pf6zMQhhYI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.796
X-Spam-Level:
X-Spam-Status: No, score=-2.796 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=vaara.io
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tCK-TeyhX17s for <scitt@mail2.ietf.org>; Thu, 20 Aug 2026 22:27:58 -0700 (PDT)
Received: from mail-4318.protonmail.ch (mail-4318.protonmail.ch [185.70.43.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F2B6812D3070D for <scitt@ietf.org>; Thu, 20 Aug 2026 22:27:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vaara.io; s=protonmail; t=1787290069; x=1787549269; bh=DCGYd/rE9XtWjPRONXMSrYBg+LxSU8LcTJIF13HVRtc=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=lL4vC09oA5CBNrFSanH7d2yiPoIn5WifxG8/qWXAWzG7iPMGcG5TaRYN+rPvo3WkN QBhpMi1kKEibzgqrz/E61jSjTO5i8Ie70Q5hbBuwTd2FMOoxyaiIr/8xKr3zR1BCND fbnernf1Okb4qS59C0xlV/pB5fnGdDIzvbDAWXY5LnDSqyuGqqNT5BRnLt1LgaGXER yXBtDvgHnkkBVAgnCqmtG2Bhi5DaJD99BSpU+3J4OP/EcP0r1w3F0uo57/l04uO1Kh 7jAfW3iXQge4qs2+7n6V0ooON3l/Bpgu/kAabxriBUXb4GVMV0HEdLLufBdGFTrqVk 6FJwMRUNbUypw==
Date: Fri, 21 Aug 2026 05:27:43 +0000
To: Joel Hillier <jhillier=40certisyn.com@dmarc.ietf.org>
From: Henri Sirkkavaara <hello@vaara.io>
Message-ID: <Oy1hoH0AG0EmM4SI5S3sqz_u01myZ_S9OTioBGsSUr7AUH6P5FKrt1381rlyQsen-lZ3BoeM_vyodZ-OSpOARE6PSQsBkb8m1oflcrjDOts=@vaara.io>
In-Reply-To: <BYAPR19MB28069B0FEA3E8F8BB3474D28ADA42@BYAPR19MB2806.namprd19.prod.outlook.com>
References: <TpUyxx5ABMjWSmfHKAapGrveJcPcen7ixrikIXT4TPILEwwp7bSORsZTKSCIack7ylQyz7tf_V4p4JiD6Ns0bnUoQ_pliWSJ_CsFLvStQEk=@vaara.io> <BYAPR19MB28069B0FEA3E8F8BB3474D28ADA42@BYAPR19MB2806.namprd19.prod.outlook.com>
Feedback-ID: 189084408:user:proton
X-Pm-Message-ID: 02a912bf11657d9158d4dcd0610738357e846cd3
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="b1=_amylktSTdH6zjnXgiUl3o9ZNEHpOUlgUyHl3qDsJdI"
Message-ID-Hash: TCVDVHHI7X4V46SDP7UF76B322ERJ4II
X-Message-ID-Hash: TCVDVHHI7X4V46SDP7UF76B322ERJ4II
X-MailFrom: hello@vaara.io
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "scitt@ietf.org" <scitt@ietf.org>, Henri Sirkkavaara <hello@vaara.io>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [SCITT] Re: A page for independent runs of the Vaara conformance vectors
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/bvSel2bifGT_rhVF60EDaTjmdOU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>

Joel,

Yes to both directions, and the reciprocal half is the part I want.

Send me the ARP vectors and the runner invocation and I will run them and report what I get, in the same terms: what passed, what did not, and the reason where it did not. If my run disagrees with yours, that disagreement is the result, not a problem to resolve privately first.

You are right that the terms belong on the page rather than only on the list. I have put them there: a run that disagrees is a row, with the reason stated, and the form publishes without me in the loop. Nobody has to take my word for either.
The point about an author's own negative controls is the one I would like to quote back at people, because it applies to me first. My eight negative cases are fault injection into an implementation written from my reading of my own text. They demonstrate that the implementation matches my reading. They cannot demonstrate anything about the text. Only your run can do that.

Henri Sirkkavaara
Vaara - Runtime execution layer for AI agents
Built to see over the noise.
vaara.ioHelsinki, Finland

On Friday, August 21st, 2026 at 00:08, Joel Hillier <jhillier=40certisyn.com@dmarc.ietf.org> wrote:

> Hi Henri,
>
> I'll run them and file a row, and if it disagrees with yours then that's the row I file.
>
> The sentence that makes this worth more than a page is "a run that disagrees with mine is a row too, with the reason stated." A conformance register that can only record agreement is a marketing surface, and every reader knows it, so it carries no information either way. The disagreement row is the whole load-bearing part. And the form publishing without you in the loop is what makes it credible rather than promised, because a curator who can decline a row is a curator whose agreements mean nothing. Both of those are worth stating on the page itself as its terms, not just on the list where they'll scroll away.
>
> Why I think this is the scarcest instrument in the area right now. An author's own negative controls are fault injection into an implementation written from that author's reading of that author's text. It's the one configuration that structurally can't surface a specification defect, because the specification and the implementation share a mind, so a passing suite proves the two agree, which was never in doubt. Only a second implementer working from the text alone produces evidence about the text. ARP carries this as a named open item rather than a satisfied one, and the reason it's still open is precisely that there was nowhere for such a run to be recorded and no norm that it should be.
>
> So the page isn't a Vaara artefact. It's the missing half of everybody's conformance claim, and I'd like to reciprocate rather than only consume it. ARP's vectors and runners are public, they take no arguments, and I'll stand up the same kind of register on the same terms: disagreements published, no gate, no blacklist. A run of yours by me and a run of mine by you are worth more than either suite growing by a hundred cases.
>
> One suggestion for the row format, straight out of the type-table thread. A row records that a checker agreed. What a checker pins varies, and your own example this morning was a suite that pins the decoded field mapping and never the scope digest, because ingestion happens on the decoded map while identity is over the encoded bytes. Those are different agreements, and a row that says only "passed" merges them.
>
> I'd have the row carry the suite names and the commit, so a reader can tell whether an independent run confirmed identity reproducibility or ingestion compatibility. Two implementations can agree on every field mapping and still compute different digests over the same input, and a register that can't show the difference will eventually get cited for the stronger claim.
>
> Nobody owes you a run, as you say. This one's owed in the other direction: the check I posted yesterday asks other people to audit their own constructions, and the first person to build somewhere for the answers to be recorded has done the harder half.
>
> Joel