Does the verifier still refuse when you are the one tampering?
Step 5 is a transcript of a verifier that ran on the build machine. You have
to take that on trust. This runs a structural verifier in your browser, right now,
over the bundle embedded in this page: results.json (500 B), vac.json (2638 B), from
vac-protocol/examples/outsider at commit 05b74450506d. The sha256
comparisons are real SHA-256 through crypto.subtle. The first button re-verifies the
bundle unaltered; each of the sixteen after it alters an in-memory copy and re-verifies
that. The served bytes are read once and never written.
The refusal names it prints are not typed into the JavaScript. They are
extracted from vac/verify.py at build time into one generated table that both
sides read, so a refusal the reference verifier renames cannot keep appearing here.
What this run checked, and what it did not
the reference verifier's own words for a structural run
proved offline: manifest schema, artifact presence + sha256, bundle closure,
stated limitations, stamp agreement, declared results recomputed from artifacts.
semantic replay: NOT run by this tool. A structural PASS means the bundle is
internally honest, not that the issuer's grader agrees. To re-earn the
verdicts, run the bundle's replay block at the pinned issuer_commit:
(replay block unreadable — see failures above)
That last line ends where the terminal above continues it: when the manifest
reads, the replay block echoed here is the bundle's own. When it does not read, there is no replay
block to echo and this panel shows none, while the command line prints a line naming that gap. The
break-json and no-manifest buttons are that case.
Vocabulary: derived at build time by parsing vac/verify.py (sha256 4c0cf48dce78, 2148 lines) for every site that appends a named refusal. verify.py emits
22 named refusals. This page's verifier references 20 of them
through the generated table, which is how it can emit them at all:
artifact-unparsable, check-artifact-not-listed, draft-incomplete, duplicate-artifact, empty-limitations, evidence-unchecked, invalid-json, issuer-commit-mismatch, missing-artifact, missing-issuer-commit, missing-manifest, raw-aggregate-mismatch, schema-violation, sha256-mismatch, stamp-mismatch, summary-mismatch, summary-outruns-checks, unknown-profile, unlisted-file, unscopable-check. It does not emit unsafe-archive, which verify.py reaches only through the archive path: this page embeds the bundle already unpacked, so that path does not exist here. It does not emit unsafe-bundle, which verify.py emits only for a symbolic link in a bundle directory: this page holds the bundle as paths and bytes, which cannot express a link, and the build refuses to embed a bundle that holds one.
bundle sha256: results.json 832bd15a039b8767; vac.json f49133a8cb7de857
· verify.py sha256 4c0cf48dce7817d5 · the panel is generated by
suite/browserverify.py and runs suite/vacbrowser.js