feat(vectors): add service_trust_v0 conformance set - #1
Conversation
5 vectors for the service_trust risk-check provider category (Supership, Crest Deployment Systems). Per invitation from @chopmob-cloud on x402-foundation/x402#2421. Covers: in-index scoring, null-score semantics, timestamp_ms canonicalization, batch composition. Known limitations documented. Category: service_trust (on-chain payment evidence, not compliance). Signing: EdDSA (Ed25519), canon_version: jcs-rfc8785-v1.
|
@chopmob-cloud -- noting a provenance gap in Both drafts use
Requesting acknowledgment in the -01 revision, consistent with the acknowledgment of other contributors whose work was incorporated. Not a legal claim -- an attribution correction. |
|
Happy to remove any particular information or participates.
Just advise and we will strip the information
…On Sun, 24 May 2026, 16:01 Andy Salvo, ***@***.***> wrote:
*andysalvo* left a comment
(chopmob-cloud/algovoi-jcs-conformance-vectors#1)
<#1 (comment)>
@chopmob-cloud <https://github.com/chopmob-cloud> -- noting a provenance
gap in draft-hopley-x402-compliance-receipt-00 and
draft-hopley-x402-refund-receipt-00.
Both drafts use screen_timestamp_ms / refund_timestamp_ms (epoch integer)
and urn:x402:canonicalisation:jcs-rfc8785-v1. The acknowledgments credit
FeedOracle and Vauban Pay but omit andysalvo/Crest, whose contributions to
these conventions are in the public record:
- #2326 2026-05-20T18:58Z
<x402-foundation/x402#2326 (comment)>:
identified the timestamp precision failure mode and proposed pinning the
lexical format
- #2326 2026-05-20T19:16Z
<x402-foundation/x402#2326 (comment)>:
your reply citing ***@***.*** <https://github.com/andysalvo> -- the
framing is exactly right" and calling the timestamp case "the natural sixth
pair invariant"
- #2357 2026-05-20T18:33Z
<x402-foundation/x402#2357 (comment)>:
three-implementation consensus post establishing timestamp_ms as
canonical
- PR #2398 <x402-foundation/x402#2398>: vector
0009 (field-name-load-bearing) proving the convention
- #2326 2026-05-21T02:38Z
<x402-foundation/x402#2326 (comment)>:
your attestation vectors citing ***@***.***
<https://github.com/andysalvo>'s PR #2398 vector 0009" as the
work-receipt-layer counterpart
Requesting acknowledgment in the -01 revision, consistent with the
acknowledgment of other contributors whose work was incorporated. Not a
legal claim -- an attribution correction.
—
Reply to this email directly, view it on GitHub
<#1 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/B3TVLQDSIKZNTG43Q7JIRE344MFEBAVCNFSM6AAAAACZKQ7QG2VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHM2DKMRZGA4DONBRGE>
.
Triage notifications on the go with GitHub Mobile for iOS
<https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675>
or Android
<https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub>.
You are receiving this because you were mentioned.Message ID:
***@***.***
com>
|
|
To clarify -- not requesting removal of anything from this repo. Requesting acknowledgment in the IETF drafts ( Suggested wording: "The |
|
Hi @andysalvo, Thanks for putting this together and for engaging with the substrate. After review I am going to close this PR rather than merge it. Going forward What I would suggest instead: publish the Supership If it is useful to Supership, AlgoVoi is happy to cross-link to such a downstream-adopter artefact from https://docs.algovoi.co.uk/substrate-authorship-provenance once it exists in your repo, as an example of the canonicalisation discipline being applied by an independent service-trust provider. For reference points:
Thanks again. -- AlgoVoi (chopmob-cloud) |
|
@andysalvo -- following up on your acknowledgment request.
The Appendix is intentionally placed in the canonicalisation I-D rather than the compliance-receipt or refund-receipt I-Ds, since Datatracker URL once approved: https://datatracker.ietf.org/doc/draft-hopley-x402-canonicalisation-jcs-v1/ Recommendation still stands that Thanks again. -- AlgoVoi (chopmob-cloud) |
|
@andysalvo -- retracting the earlier close. AlgoVoi is back open to participation from independent adopters and contributors; the prior close was applied under too strict an interpretation of "sole AlgoVoi authorship" and the call is now reversed. PR is reopened. Reviewing your Two things stand:
Will follow up with a review pass on the PR shortly. Apologies for the friction. -- AlgoVoi (chopmob-cloud) |
|
@andysalvo -- closing the loop:
Appendix C "Known Adopters" lists Supership Also confirmed: your Thanks for the patience through the close/reopen. -- AlgoVoi (chopmob-cloud) |
|
@andysalvo — to close the loop on your acknowledgment request from this thread (2026-05-24 16:40 UTC). Three I-D revisions staged with Crest Deployment Systems credited for the
|
|
Filed all three -02 revisions to IETF datatracker. Status:
Once confirmation links are clicked, all three POST publicly on the datatracker with the Acknowledgment wording from the previous comment intact. If you want any phrasing adjusted before the publication ages into the archive, flag it in the next few hours and a -03 lands with the change. -- AlgoVoi |
|
Reviewed the attribution wording across all three drafts — it's accurate and we're grateful for the care. No edits requested. Ship it to datatracker when you're ready. Yes to On collaboration — the domain split you named on #2299 is the real handshake. You're upstream of compliance posture; we're upstream of conformance evidence. Those compose cleanly. Concrete proposal: a joint cross-vector test harness where AlgoVoi compliance vectors and Crest conformance vectors run against the same fixture set, producing a single receipt that carries both a compliance disposition and a conformance proof. We'll host the fixture runner at verify.crestsystems.ai backed by our 47K+ service index; you'd own the compliance vector spec. Receipts cross-reference by JCS hash. We'll open a |
|
@andysalvo — thanks. Filing the -02 confirmations now. Yes to The joint-harness-v0 proposal — "AlgoVoi upstream of compliance posture / Crest upstream of conformance evidence" is the right structural framing. A joint receipt carrying both a compliance disposition (ALLOW / REFER / DENY) and a conformance proof (PASS / FAIL with byte-evidence) is the kind of cross-domain composition the canonicalisation pin was specified to support. Looking forward to the issue draft this week. One forward-compatibility note: keep the joint receipt under -- AlgoVoi |
|
Following up on the joint-harness-v0 discussion. We're ready to scope it. Concrete proposal: a verification endpoint that any framework integrating x402 facilitation can hit during onboarding. Developer runs We'll host and maintain the runner. You own the compliance vector spec. Receipts cross-reference by JCS hash. The separation is clean: facilitator processes the payment, verifier proves the implementation is correct. Happy to start with a shared fixture format this week. |
|
Andy -- sounds good. Happy to start looking into the joint-harness-v0 scoping over the next few days. The clean separation you described (facilitator processes the payment / verifier proves the implementation is correct) and the JCS-hash cross-reference primitive both compose with the substrate as it stands. Send the shared fixture format draft over when you have it and I will turn it round. -- AlgoVoi (chopmob-cloud) |
|
Sounds good. We'll draft the fixture format spec and send it over -- JCS-hash cross-reference primitive + verification receipt shape. Clean and minimal. |
|
Yep deffo - I need my bed and some painkillers - copying emails and code
has my eyes all over the place!!!!
…On Tue, 26 May 2026 at 21:57, Andy Salvo ***@***.***> wrote:
*andysalvo* left a comment
(chopmob-cloud/algovoi-jcs-conformance-vectors#1)
<#1 (comment)>
Sounds good. We'll draft the fixture format spec and send it over --
JCS-hash cross-reference primitive + verification receipt shape. Clean and
minimal.
—
Reply to this email directly, view it on GitHub
<#1?email_source=notifications&email_token=B3TVLQHJNNRDBOKBJ643FGL44YALDA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINJUHA3TONRZGM2KM4TFMFZW63VMON2GC5DFL5RWQYLOM5S2KZLWMVXHJLDGN5XXIZLSL5RWY2LDNM#issuecomment-4548776934>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/B3TVLQHM2QFA7VO2VO7XAA344YALDAVCNFSM6AAAAACZKQ7QG2VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHM2DKNBYG43TMOJTGQ>
.
Triage notifications on the go with GitHub Mobile for iOS
<https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675>
or Android
<https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub>.
You are receiving this because you modified the open/close state.Message
ID: <chopmob-cloud/algovoi-jcs-conformance-vectors/pull/1/c4548776934@
github.com>
|
|
@chopmob-cloud -- here's the shared fixture format draft for joint-harness-v0. Two primitives:
Key design decisions:
Full spec + JSON Schema: Let me know what needs adjustment. |
|
Andy -- moved this forward overnight rather than waiting. Spun up a private repo with the joint-harness-v0 scope, schema, six fixtures (full Crest-recommendation x AlgoVoi-verdict matrix), and a Python reference harness. 8-impl JCS cross-validation runs 48/48 byte-for-byte PASS. You should have a collaborator invitation in your inbox: https://github.com/chopmob-cloud/algovoi-crest-joint-harness Four open questions logged in FIXTURE_FORMAT.md for your input. No pressure on timing -- the draft is there when you want to look at it. -- AlgoVoi (chopmob-cloud) |
Summary
Per your invitation on x402-foundation/x402#2421, adding
service_trust_v0conformance vectors from the Supership risk-check provider.5 vectors covering:
score: null, recommendation: no_datasemanticstimestamp_mscanonicalization alignment with #2326 conventionIncludes
KNOWN_LIMITATIONS.mddocumenting what these vectors do and don't cover.Provider details
service_trustjcs-rfc8785-v1https://supership.crestsystems.ai/.well-known/risk-check.jsonHappy to adjust naming or layout to match corpus conventions.