The language-neutral half of AgentSpaces: what every implementation claims conformance to.
| File | What it is |
|---|---|
SPEC.md |
The normative specification (v0.1.13): identity, peering, discovery, the replicated space, capabilities, the programming model, security. |
TECH-SPEC.md |
What the reference implementation puts on the wire, byte by byte, and which algorithm runs behind each operation; §1.5 defines conformance and §10 is the checklist a new implementation follows. |
golden.json |
The golden vectors: 92 named byte strings and values a conforming implementation reproduces exactly (70 of them) or refuses (22 hostile adv_* inputs). |
sync-golden.sh |
Copies golden.json into every consumer's vendored location and checks the copies are identical. |
Each implementation keeps a vendored copy of golden.json at a fixed path, so every
repository builds and runs its conformance gate standalone and offline:
| Implementation | Vendored copy | Suite |
|---|---|---|
agentspaces/ (Java, the reference) |
tools/golden/golden.json |
GoldenVectorsConformanceTest, GoldenVectorsV0110ConformanceTest, AdversarialVectorsTest, SignedAgentVectorsClusterTest, VoteVectorsConformanceTest, IdsTest — run with -Dgolden.required=true |
agentspaces-python/ |
tests/golden.json |
tests/test_golden.py, tests/test_adversarial.py |
agentspaces-typescript/ |
test/golden.json |
test/golden.test.ts |
This file is the source; the copies are derived. sync-golden.sh refreshes them and
verify-all.sh at the workspace root refuses when any copy differs. A vector is never edited
by hand: the generator (agentspaces/tools/golden/GoldenVectors.java, which needs the Java
classes and so lives with them) reloads the fixed key material from the existing file, adds or
changes only the vectors whose inputs changed, and writes here; see
agentspaces/docs/BUILD-ENVIRONMENTS.md for the incantation.
Fixed key material and identifiers: private_key_pkcs8, public_key_raw, peer_id,
group_id, space_id, hlc_encoded, and the adversarial forger's and the subordinate agent's
keys (adv_forger_*, agent_*_key_*). Everything else is a canonical CBOR encoding
(*_cbor), a signature (*_signature), a delta (*_delta), or a derived identifier, named
for the structure it pins.
private_key_pkcs8public_key_rawpeer_idgroup_idhlc_encodedping_body_cborping_envelope_cborping_frame_cborping_envelope_signaturepeer_ad_cborsigned_peer_ad_cborintro_rumor_body_cbortask_payload_cborspace_idsign_view_cborrecord_signaturestate_sign_view_cborstate_signatureentry_state_dto_cbordelta_cbortake_claim_cbortake_claim_signatureclaim_delta_cbordigest_body_cbormax_frame_bytesfounding_fields_cborfounding_signaturefounding_document_cborfounding_group_idfounding_ad_idgroup_ad_cborsigned_group_ad_cborgroup_ad_want_envelope_cborgroup_ad_want_frame_cborgroup_ad_envelope_cborgroup_ad_frame_cboragent_card_cboragent_card_signaturesigned_agent_card_cborspace_ad_cborspace_ad_space_idspace_credential_record_cboraggregate_share_frame_cboraggregate_extremum_frame_cboraggregate_histogram_frame_cboraggregate_roster_frame_cboraggregate_roster_tokenlearn_model_encodinglearn_content_idlearn_exchange_offer_cborlearn_exchange_accept_cborlearn_exchange_busy_cborcertificate_verify_atagent_private_key_pkcs8agent_public_key_rawagent_certificate_unsigned_cboragent_certificate_signatureagent_certificate_cborrecord_signature_agent_keyentry_state_with_certificate_cbordelta_with_certificate_cboragent_card_with_key_cboragent_card_with_key_signaturetake_claim_agent_signatureclaim_delta_with_certificate_cborvote_three_names_one_peer_proposalvote_three_names_one_peer_delta_1vote_three_names_one_peer_delta_2vote_three_names_one_peer_delta_3wire_version
Added in v0.1.13 (TODO-9-10-11 Phase 3; every vector above keeps its bytes). The two
v0.1.11 vectors entry_state_with_certificate_cbor and delta_with_certificate_cbor now
carry a refused verdict: they put a peer-signed state on an agent-attested entry. They are
kept under their old names for continuity, and are also published as
adv_legacy_state_on_attested_entry_* below, the names the Java, Python, and TypeScript
suites check the refusal under.
state_sign_view_agent_cbor,state_signature_agent_key: an agent-signed state's view (appendssigner,signedAt) and the agent key's signature over itentry_state_agent_signed_cbor,delta_agent_signed_cbor: the agent-signed control, which every receiver acceptscontent_key_epoch_2,content_key_aad_epoch_2,key_epoch_sealed_payload,sign_view_key_epoch_cbor,entry_record_key_epoch_cbor: a record sealed under epoch 2 (appendskeyEpoch; the AAD appends|2)epoch_commitment_cbor,epoch_proof_signature: a rotator's signed commitment to an epoch keywrap_binding_v2_cbor: the key-wrap binding withepoch,rotator, andagentagent_encryption_private_key_pkcs8,agent_encryption_public_key_raw,agent_certificate_with_encryption_unsigned_cbor,agent_certificate_with_encryption_signature,agent_certificate_with_encryption_cbor: a certificate that also certifies the agent's X25519 keycredential_revocation_agent_cbor,signed_credential_revocation_agent_cbor,credential_revocation_agent_key_cbor,signed_credential_revocation_agent_key_cbor: revocations of an agent (retired, effective an hour before issue) and of its key (key-compromise), issued by the agent's own peeragent_card_with_actions_cbor,agent_card_with_actions_signature: a card with a declared action and its agent's certificate, issued atcertificate_verify_at
Every adv_* vector is a hostile input that decodes cleanly (or fails a bounds check) and
must be rejected — by failed verification, a lattice bound, or a reader filter — without
crashing the receiver. All three implementations reject the same set:
adv_claim_bad_signature_deltaadv_claim_transplanted_deltaadv_claim_nan_bid_deltaadv_claim_epoch_zero_deltaadv_claim_epoch_jump_deltaadv_claim_eternal_deltaadv_deep_nesting_cboradv_frame_bad_signatureadv_frame_wrong_destinationadv_frame_wrong_destination_toadv_group_ad_wrong_id_cboradv_group_ad_forged_signature_cboradv_forger_private_key_pkcs8adv_forger_public_key_rawadv_cert_wrong_peer_deltaadv_cert_wrong_agent_deltaadv_cert_expired_deltaadv_cert_uncertified_key_deltaadv_cert_peer_signed_record_deltaadv_claim_cert_peer_signed_deltaadv_claim_cert_expired_deltaadv_claim_cert_wrong_holder_deltaadv_legacy_state_on_attested_entry_dto_cbor,adv_legacy_state_on_attested_entry_delta_cbor(v0.1.13): a peer-signed state on an agent-attested entryadv_agent_state_peer_key_delta(v0.1.13): agent-signer fields, signed by the peer keyadv_agent_state_wrong_signer_delta(v0.1.13): a signer other than the record's issuer
The specification's revision history is SPEC.md §15. A change to any signed structure regenerates the vectors, and the three suites must be green before the change lands.