[SCITT] Re: Last Call: <draft-ietf-scitt-receipts-ccf-profile-04.txt> (CCF Profile for COSE Receipts) to Proposed Standard

Henri Sirkkavaara <hello@vaara.io> Sun, 06 September 2026 12:42 UTC

Return-Path: <hello@vaara.io>
X-Original-To: scitt@mail2.ietf.org
Delivered-To: scitt@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6241F13646FF6; Sun, 6 Sep 2026 05:42:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788698529; bh=RzAtv4PNiXRDVe7ZxEbghSmBM5y6rnp2OGZUd5CBmHc=; h=Date:To:From:Cc:Subject:In-Reply-To:References; b=sfpSp4yVI0MLUjamfs3JznZC77L6UCka2MWD4TDyUNUTy9X+w5TT9p4j3ywB6/7ZP 7O+GtoT7577rnXzudOxfX0TVeYvi6Ll/W9QpC+UwuKBlOAo2X7lU780dEN/waywIa/ fyQdPStIn51NPewCaPIsaOPF+TBaeTjnFZLDq3M4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level:
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=vaara.io
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7x3VLkaEUJdk; Sun, 6 Sep 2026 05:42:08 -0700 (PDT)
Received: from mail-24420.protonmail.ch (mail-24420.protonmail.ch [109.224.244.20]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2BBC713646FF1; Sun, 6 Sep 2026 05:42:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vaara.io; s=protonmail; t=1788698520; x=1788957720; bh=RzAtv4PNiXRDVe7ZxEbghSmBM5y6rnp2OGZUd5CBmHc=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=feZYl5thx0JrZPTDNxWZRJWp1PgNTirYUFa+/ne6jXqqnd1anTq5YMw5W9nOMo/HU iTpMHPofP9Yn8Mnfuu3NE0kmksYJKa0Q1EbgmXaApDrBvU/QGfOigGRfmUpinmYBjJ JbORSJuj7IMDMroqXwYvd3uSXCehZUtCBDuSwa7n8WUD92qvdGSjUPXvQDK2aUOM/F sR88Hg61wBB/tmmpZhpSFlUULadCmWEmhEtOdAWD5ARIonOgPINDfRr7H3mnGqtFZI 9c5RfbW7oHgIFGVpSbWBTCEOzk7UwfuA1mNxa3b1KOBOy2I0Zf3UUfdO1vJJlv1VJX wjqkA7xCuOebQ==
Date: Sun, 06 Sep 2026 12:41:55 +0000
To: Emek Can Dogru <e.dogru@conarium.dev>
From: Henri Sirkkavaara <hello@vaara.io>
Message-ID: <1udIFKkCbk4eZyI53aLizoDWj-1cx38Sfw7mL7fMUrkHCsfypOhjCGOWVFhdqCvxHDNC1oT3CFwQgYgxZnGQbSkIqKGfRHcZa8ZI69revhQ=@vaara.io>
In-Reply-To: <1788694937221219054.1788694937@conarium.dev>
References: <Y6yqZIoHnmxUHakB-MQWgEM5hvK5JZMv4ycu04O1zh4I3hdI276Wm3Qi-XZrFAjz0bR_BvB2zDSKNEumECSFTRtA2UVcd-h8Lp5VKPuvVoU=@b7n0de.com> <e41f6328-fc26-4a5f-998a-d121d4e22db9@csoai.org> <2JUHvi5yKlM6eew-jlJdy5FjrjDV8igRuIm0OIPZkjl9rEgnMbyf6fLx0AOi_F_X2gRpVtTl9Yka_FPh11842XCXOMNQtruqMN5CwSEbNV0=@vaara.io> <1788694937221219054.1788694937@conarium.dev>
Feedback-ID: 189084408:user:proton
X-Pm-Message-ID: 01859f888dc080a8ae03dc88bd0a4f0124bc5193
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: ZCPUFSTQ4WCYTX5SKWRXP74FSMHB5TLB
X-Message-ID-Hash: ZCPUFSTQ4WCYTX5SKWRXP74FSMHB5TLB
X-MailFrom: hello@vaara.io
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-scitt.ietf.org-0; header-match-scitt.ietf.org-1; header-match-scitt.ietf.org-2; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: hello@vaara.io, nicholas@csoai.org, last-call@ietf.org, scitt@ietf.org, kontakt@b7n0de.com, vernon@sigilcore.com, pki@varwof.com
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [SCITT] Re: Last Call: <draft-ietf-scitt-receipts-ccf-profile-04.txt> (CCF Profile for COSE Receipts) to Proposed Standard
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/hIntJzXvOEgePdgXIovIYKQw3oA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>

Emek,

Thank you for running it, and for pinning the script.

Your n = 2, 3, 5, 9 numbers settle the remedy choice I left to the authors. The path "1" of length one lands on index 1, 2, 4 and 8 in trees of 2, 3, 5 and 9, each being the right child of the split at the largest power of two below n. So the pair addresses a leaf only once the verifier already holds n, and the proof carries neither n nor the index today.

That makes the two remedies unequal. The path-length rule needs the tree size shipped with the proof. The index needs nothing added. So I withdraw the first and recommend the second.

Still non-blocking, and my support for -04 as Proposed Standard stands.


On Sunday, September 6th, 2026 at 14:42, Emek Can Dogru <e.dogru@conarium.dev> wrote:

> Henri,
> 
> Finding 1 reproduces from the text of -04 alone: sizes 2 to 11 exactly
> as you corrected them, and over sizes 2 to 1024 only the ten powers of
> two decode every leaf.
> 
> One measurement bears on the remedy. The (bits, length) pair identifies
> a leaf only when the verifier knows n: the one-element path "1" is
> index 1 in a tree of 2, index 2 in a tree of 3, index 4 in a tree of 5
> and index 8 in a tree of 9. The proof carries neither n nor the index,
> and the payload is the root. So the path-length rule needs the tree
> size to travel with the proof; carrying the index needs nothing added.
> 
> Script, eleven lines, pinned at
> https://gist.github.com/dogrucanemek-alt/a48eb01ae668314fbad889ff69e1e84c
> 
> Nothing here blocks -04.
> 
> Emek Can Dogru
> 
> On Sun, Sep 6, 2026 at 2:14 PM Henri Sirkkavaara <hello@vaara.io> wrote:
> > All,
> >
> > A correction to my own review of 4 September first. In finding 1 I listed n = 3, 5, 6, 7 and 11 as the sizes where the path bits decode to the wrong index. That enumeration is incomplete: 9 and 10 fail as well. Rechecking 2 through 11 against the definitions as written, every non-power-of-two size has at least one leaf that decodes wrong, and 2, 4 and 8 decode exactly. So the condition is that index recovery holds when the number of transactions is a power of two, and not otherwise.
> >
> > Then one ask, and it sits where the thread already is rather than off to the side. This week has settled that the document's defect class is unnamed preimages: Nicholas on internal-evidence, Konrad's sentence binding the octets of the Signed Statement as registered, Anton's as-transmitted registering the same rule.
> >
> > Finding 4 in my review is that defect one layer further out, and it is the largest instance in the document. Section 2.1 defines MTH over "a list of serialized transactions (as byte strings)" and gives MTH({d[0]}) = HASH(d[0]). Section 3.2 computes the leaf as HASH(internal-transaction-hash || HASH(internal-evidence) || data-hash). Nothing in the document says that d[i] is that concatenation. A builder working from 2.1 and a verifier working from 3.2 can produce different roots, and 2.1 is the definition that looks authoritative, because it is the one labelled Merkle Tree Hash.
> >
> > If the group is naming preimages before this document leaves, that is the one to name.
> >
> > On finding 1, I left the choice of remedy to the authors and will now say which I would take. Make the path length part of the decoding rule, or carry the index in the proof. Attaching the power-of-two condition to the sentence documents the hazard and leaves it in place, and an application whose author does not read that sentence still gets a wrong index and no error.
> >
> > Still non-blocking, and my support for -04 as Proposed Standard stands.
> 
> --
> SCITT mailing list -- scitt@ietf.org
> To unsubscribe send an email to scitt-leave@ietf.org
> 

Henri Sirkkavaara
Vaara - Runtime execution layer for AI agents
Built to see over the noise.
vaara.io
Helsinki, Finland