Return-Path: <hello@vaara.io>
X-Original-To: scitt@mail2.ietf.org
Delivered-To: scitt@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id 6241F13646FF6;
	Sun,  6 Sep 2026 05:42:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1;
	t=1788698529; bh=RzAtv4PNiXRDVe7ZxEbghSmBM5y6rnp2OGZUd5CBmHc=;
	h=Date:To:From:Cc:Subject:In-Reply-To:References;
	b=sfpSp4yVI0MLUjamfs3JznZC77L6UCka2MWD4TDyUNUTy9X+w5TT9p4j3ywB6/7ZP
	 7O+GtoT7577rnXzudOxfX0TVeYvi6Ll/W9QpC+UwuKBlOAo2X7lU780dEN/waywIa/
	 fyQdPStIn51NPewCaPIsaOPF+TBaeTjnFZLDq3M4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level: 
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7,
	RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001,
	RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001,
	RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001]
	autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=vaara.io
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 7x3VLkaEUJdk; Sun,  6 Sep 2026 05:42:08 -0700 (PDT)
Received: from mail-24420.protonmail.ch (mail-24420.protonmail.ch
 [109.224.244.20])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id 2BBC713646FF1;
	Sun,  6 Sep 2026 05:42:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vaara.io;
	s=protonmail; t=1788698520; x=1788957720;
	bh=RzAtv4PNiXRDVe7ZxEbghSmBM5y6rnp2OGZUd5CBmHc=;
	h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References:
	 Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID:
	 Message-ID:BIMI-Selector;
	b=feZYl5thx0JrZPTDNxWZRJWp1PgNTirYUFa+/ne6jXqqnd1anTq5YMw5W9nOMo/HU
	 iTpMHPofP9Yn8Mnfuu3NE0kmksYJKa0Q1EbgmXaApDrBvU/QGfOigGRfmUpinmYBjJ
	 JbORSJuj7IMDMroqXwYvd3uSXCehZUtCBDuSwa7n8WUD92qvdGSjUPXvQDK2aUOM/F
	 sR88Hg61wBB/tmmpZhpSFlUULadCmWEmhEtOdAWD5ARIonOgPINDfRr7H3mnGqtFZI
	 9c5RfbW7oHgIFGVpSbWBTCEOzk7UwfuA1mNxa3b1KOBOy2I0Zf3UUfdO1vJJlv1VJX
	 wjqkA7xCuOebQ==
Date: Sun, 06 Sep 2026 12:41:55 +0000
To: Emek Can Dogru <e.dogru@conarium.dev>
From: Henri Sirkkavaara <hello@vaara.io>
Message-ID: 
 <1udIFKkCbk4eZyI53aLizoDWj-1cx38Sfw7mL7fMUrkHCsfypOhjCGOWVFhdqCvxHDNC1oT3CFwQgYgxZnGQbSkIqKGfRHcZa8ZI69revhQ=@vaara.io>
In-Reply-To: <1788694937221219054.1788694937@conarium.dev>
References: 
 <Y6yqZIoHnmxUHakB-MQWgEM5hvK5JZMv4ycu04O1zh4I3hdI276Wm3Qi-XZrFAjz0bR_BvB2zDSKNEumECSFTRtA2UVcd-h8Lp5VKPuvVoU=@b7n0de.com>
 <e41f6328-fc26-4a5f-998a-d121d4e22db9@csoai.org>
 <2JUHvi5yKlM6eew-jlJdy5FjrjDV8igRuIm0OIPZkjl9rEgnMbyf6fLx0AOi_F_X2gRpVtTl9Yka_FPh11842XCXOMNQtruqMN5CwSEbNV0=@vaara.io>
 <1788694937221219054.1788694937@conarium.dev>
Feedback-ID: 189084408:user:proton
X-Pm-Message-ID: 01859f888dc080a8ae03dc88bd0a4f0124bc5193
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: ZCPUFSTQ4WCYTX5SKWRXP74FSMHB5TLB
X-Message-ID-Hash: ZCPUFSTQ4WCYTX5SKWRXP74FSMHB5TLB
X-MailFrom: hello@vaara.io
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-scitt.ietf.org-0;
 header-match-scitt.ietf.org-1; header-match-scitt.ietf.org-2;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: hello@vaara.io, nicholas@csoai.org, last-call@ietf.org, scitt@ietf.org,
 kontakt@b7n0de.com, vernon@sigilcore.com, pki@varwof.com
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BSCITT=5D_Re=3A_Last_Call=3A_=3Cdraft-ietf-scitt-receipts-ccf-pr?=
	=?utf-8?q?ofile-04=2Etxt=3E_=28CCF_Profile_for_COSE_Receipts=29_to_Proposed?=
	=?utf-8?q?_Standard?=
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/scitt/hIntJzXvOEgePdgXIovIYKQw3oA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>

Emek,

Thank you for running it, and for pinning the script.

Your n =3D 2, 3, 5, 9 numbers settle the remedy choice I left to the author=
s. The path "1" of length one lands on index 1, 2, 4 and 8 in trees of 2, 3=
, 5 and 9, each being the right child of the split at the largest power of =
two below n. So the pair addresses a leaf only once the verifier already ho=
lds n, and the proof carries neither n nor the index today.

That makes the two remedies unequal. The path-length rule needs the tree si=
ze shipped with the proof. The index needs nothing added. So I withdraw the=
 first and recommend the second.

Still non-blocking, and my support for -04 as Proposed Standard stands.


On Sunday, September 6th, 2026 at 14:42, Emek Can Dogru <e.dogru@conarium.d=
ev> wrote:

> Henri,
>=20
> Finding 1 reproduces from the text of -04 alone: sizes 2 to 11 exactly
> as you corrected them, and over sizes 2 to 1024 only the ten powers of
> two decode every leaf.
>=20
> One measurement bears on the remedy. The (bits, length) pair identifies
> a leaf only when the verifier knows n: the one-element path "1" is
> index 1 in a tree of 2, index 2 in a tree of 3, index 4 in a tree of 5
> and index 8 in a tree of 9. The proof carries neither n nor the index,
> and the payload is the root. So the path-length rule needs the tree
> size to travel with the proof; carrying the index needs nothing added.
>=20
> Script, eleven lines, pinned at
> https://gist.github.com/dogrucanemek-alt/a48eb01ae668314fbad889ff69e1e84c
>=20
> Nothing here blocks -04.
>=20
> Emek Can Dogru
>=20
> On Sun, Sep 6, 2026 at 2:14 PM Henri Sirkkavaara <hello@vaara.io> wrote:
> > All,
> >
> > A correction to my own review of 4 September first. In finding 1 I list=
ed n =3D 3, 5, 6, 7 and 11 as the sizes where the path bits decode to the w=
rong index. That enumeration is incomplete: 9 and 10 fail as well. Rechecki=
ng 2 through 11 against the definitions as written, every non-power-of-two =
size has at least one leaf that decodes wrong, and 2, 4 and 8 decode exactl=
y. So the condition is that index recovery holds when the number of transac=
tions is a power of two, and not otherwise.
> >
> > Then one ask, and it sits where the thread already is rather than off t=
o the side. This week has settled that the document's defect class is unnam=
ed preimages: Nicholas on internal-evidence, Konrad's sentence binding the =
octets of the Signed Statement as registered, Anton's as-transmitted regist=
ering the same rule.
> >
> > Finding 4 in my review is that defect one layer further out, and it is =
the largest instance in the document. Section 2.1 defines MTH over "a list =
of serialized transactions (as byte strings)" and gives MTH({d[0]}) =3D HAS=
H(d[0]). Section 3.2 computes the leaf as HASH(internal-transaction-hash ||=
 HASH(internal-evidence) || data-hash). Nothing in the document says that d=
[i] is that concatenation. A builder working from 2.1 and a verifier workin=
g from 3.2 can produce different roots, and 2.1 is the definition that look=
s authoritative, because it is the one labelled Merkle Tree Hash.
> >
> > If the group is naming preimages before this document leaves, that is t=
he one to name.
> >
> > On finding 1, I left the choice of remedy to the authors and will now s=
ay which I would take. Make the path length part of the decoding rule, or c=
arry the index in the proof. Attaching the power-of-two condition to the se=
ntence documents the hazard and leaves it in place, and an application whos=
e author does not read that sentence still gets a wrong index and no error.
> >
> > Still non-blocking, and my support for -04 as Proposed Standard stands.
>=20
> --
> SCITT mailing list -- scitt@ietf.org
> To unsubscribe send an email to scitt-leave@ietf.org
>=20

Henri Sirkkavaara
Vaara -=C2=A0Runtime execution layer for AI agents
Built to see over the noise.
vaara.io
Helsinki, Finland

