Architecture
Components
pytest hooks + fixture
│
▼
receipt payload ── source manifest ── Git metadata ── environment
│
▼
canonical JSON + SSH signature
│
▼
schema-3 receipt
│
├── verify: schema → signature → tree → outcomes → policy
└── merge: compatible shards → union → merger signature
| Module | Responsibility |
|---|---|
plugin.py |
pytest options, collection, phase outcomes, fixture checks |
config.py |
CLI/TOML precedence and runtime configuration |
gitutils.py |
strict Git queries and tracked-index entries |
fingerprint.py |
deterministic tracked/extra manifest |
compare.py |
reference/candidate execution and comparison |
receipt.py |
payload construction, canonicalization, atomic output |
signers/ed25519.py |
Ed25519/ECDSA/RSA signing and GitHub key lookup |
verify.py |
schema, signature, repository, test, shard, and policy checks |
merge.py |
compatible shard union and controlled carry-forward |
Recording sequence
- Session start records time and removes the old output.
- Collection records the exact selected node-ID sequence.
pytest_runtest_makereportobserves setup, call, and teardown.gpu_proof_checkstores named comparison outcomes on the test item.- Session finish fills any missing terminal reports as errors.
- Receipt construction requires a Git repository and nonempty source scope.
- Signer metadata is inserted into the payload before canonicalization.
- The JSON file is flushed, fsynced, and atomically replaced.
Receipt-generation failure changes pytest's exit status unless explicit best-effort mode was requested.
Schema 3
The top-level blocks are:
repo: remote, signed GitHub identity, commit, branch, and dirty state;fingerprint: manifest algorithm, tracked paths, extra paths, count, digest;session: start/end, pass/fail, exact node IDs, pytest arguments;tests: terminal outcome, phase, duration, and comparison checks;environment: Python, platform, pytest, plugin, and self-reported GPU data;shards: optional narrow manifests and carry metadata;signer: signed username, algorithm, backend, and key fingerprint;signature: base64 signature value only.
The signature covers canonical JSON for every field except signature:
payload = {key: value for key, value in receipt.items() if key != "signature"}
canonical = json.dumps(
payload, sort_keys=True, separators=(",", ":"), allow_nan=False
).encode()
Putting signer metadata inside this payload prevents identity or algorithm substitution after signing.
Fingerprint manifest
sha256-manifest-v2 enumerates stage-0 Git index entries. Regular files bind
bytes and mode, symbolic links bind their target string, and submodules bind
the checked-out commit or index gitlink. Explicit extra paths add ignored or
generated files without sweeping unrelated build output into the claim. The
committed receipt path is an explicit exclusion because its final signed bytes
cannot recursively be an input to its own digest.
The digest is over canonical JSON for the file map, not a concatenation with ambiguous boundaries.
Verification order
The verifier fails at the first invalid trust boundary:
- repository and JSON readability;
- supported schema and strict structure;
- signature and signed identity;
- repository policy and fingerprint;
- Git ancestry and dirty-tree policy;
- shard and carry-forward consistency;
- session, test, comparison, and skip outcomes;
- required test manifest and GPU metadata;
- timestamp validity and freshness.
Legacy schema-1/2 receipts remain readable, but schema 3 uses stricter clean tree and signed-identity defaults.