Skip to content
VERASPEC
Repository
Errata ledgerstable

§7 Audit findings — specification and schema

7.1 breaking-major (2)

IDTitleSourceClassificationDispositionStatus
CPNP-04§4 step 6's "clamp to [0,255]" destroys every >8-bit-per-channel sourceaudit/corebreaking-majorfixed-in-1.0.1 E3Closed
WIRE-15The wire profile has no versioning or negotiation mechanism at allaudit/wirebreaking-majordrafted-in-1.1 §14.1 (VER-F major)Draft — ratification required

7.2 patch-correction (82)

IDTitleSourceClassificationDispositionStatus
SCHEMA-05space_id pattern rejects hyphenated authority labels its own prose permitsaudit/embedpatch-correctiondrafted-in-1.1 §11.6 — deferred from 1.0.1 by ADR-0002Draft — ratification required
SPEC-09-embreference is optional, so a descriptor can make no testable conformance claimaudit/embedpatch-correctionfixed-in-1.0.1 E13; validator-rule VER404Closed
MOD-02Implementation docstring restates the false pixel_hash survival claimaudit/corepatch-correctionfixed-in-1.0.1 E1; README/CLAUDE.md corrected in this branch; models.py Hashes docstring corrected in this branch — it now states E1's survival profile instead of "pixel does not [change]"Closed
REC-03raw[].sha256 covers re-framed bytes, not the segment as stored in the containeraudit/corepatch-correctionfixed-in-1.0.1 E11; validator-rule VER1302Closed
REC-08Emitted descriptor omits preprocessing content, reference, and architectureaudit/corepatch-correctionfixed-in-1.0.1 E13; validator-rule VER404/VER405Closed
CPNP-07§4 step 3 defines only the success path of colour managementaudit/corepatch-correctionfixed-in-1.0.1 E8Closed
CPNP-02hdr_present decided by a raw substring scan of the whole fileaudit/corepatch-correctionfixed-in-1.0.1 E5 (spec half); implementation documented — not patchedClosed
REC-10Chain has neither chronology nor fidelity — every event shares one timestampaudit/corepatch-correctionfixed-in-1.0.1 E16; validator-rule VER1201–VER1204Closed
REC-09record_id is uuid5 over pixel_hash alone, colliding across distinct Recordsaudit/corepatch-correctionfixed-in-1.0.1 E16; fixed in this branch (D7.0 #4)Closed
REC-05One identifier serves both the iptc availability key and the iptc-iim segmentaudit/corepatch-correctionfixed-in-1.0.1 E21Closed
REC-06stripped_suspected, redacted, and availability_basis are never producedaudit/corepatch-correctiondocumented — not patched; validator-rule VER901Deferred
MOD-04weights_sha256 optional in the internal type despite mandatory weight pinningaudit/corepatch-correctiondocumented — not patched; ADR-0007 defines the preimageDeferred
SPEC-01-coreimage.width/height never defined as pre- or post-orientationaudit/corepatch-correctionfixed-in-1.0.1 E2Closed
SPEC-03-coreraw[].segment permits other, but availability has no slot for itaudit/corepatch-correctionfixed-in-1.0.1 E21; drafted-in-1.1 §10.3Closed
HASH-02Perceptual digest encoding, bit order, and parameters are unpinnedaudit/corepatch-correctionfixed-in-1.0.1 E22; drafted-in-1.1 §2.4 registryClosed
CPNP-08Out-of-range and malformed Orientation values are undefined by the specaudit/corepatch-correctionfixed-in-1.0.1 E6Closed
WIRE-01hashes_only privacy mode withholds the thumbnail but not the embeddingaudit/wirepatch-correctiondrafted-in-1.1 §14.5Draft — ratification required
WIRE-04No update path: createRecord collisions are treated as successaudit/wirepatch-correctiondrafted-in-1.1 §14.6Draft — ratification required
WIRE-05rkey truncates pixel_hash to 52 bits and any taken-rkey error counts as successaudit/wirepatch-correctiondocumented — not patched; drafted-in-1.1 §14.6Deferred
WIRE-07No hash-bearing lexicon field carries a pattern or length constraintaudit/wirepatch-correctiondrafted-in-1.1 §14.3Draft — ratification required
WIRE-10Mapper supports one of three vector carriages and silently degrades for the othersaudit/wirepatch-correctiondrafted-in-1.1 §14.3; annex E24Draft — ratification required
WIRE-11decode_vector hardcodes little-endian fp16 regardless of declared dtypeaudit/wirepatch-correctiondocumented — not patched; annex E24Deferred
WIRE-12Lexicon const on dtype/normalization is enforced by neither producer nor consumeraudit/wirepatch-correctiondrafted-in-1.1 §14.3Draft — ratification required
WIRE-13verVersion/cpnpVersion are defaulted, not propagated from the Recordaudit/wirepatch-correctiondrafted-in-1.1 §14.2; annex N6Draft — ratification required
WIRE-16knownValues is an open set in Lexicon but is modelled as a closed enumaudit/wirepatch-correctiondrafted-in-1.1 §14.3Draft — ratification required
WIRE-18Wire image.format is unconstrained while the Record schema closes itaudit/wirepatch-correctiondrafted-in-1.1 §14.3Draft — ratification required
WIRE-19No size bound on the wire beyond the thumbnail blobaudit/wirepatch-correctiondrafted-in-1.1 §7 limits + §14.3Draft — ratification required
WIRE-24Consumer discards the producer's createdAt for the relay's observation timeaudit/wirepatch-correctiondocumented — not patched; annex E16Deferred
WIRE-25A wire record claims VER 1.0 conformance while carrying no Layer 2 contentaudit/wirepatch-correctiondrafted-in-1.1 §14.8Draft — ratification required
WIRE-29Three fields are both required and defaulted, which is contradictory in Lexiconaudit/wirepatch-correctiondrafted-in-1.1 §14.3Draft — ratification required
WIRE-32Duplicate space_id resolves last-wins in the wire mapperaudit/wirepatch-correctionfixed-in-1.0.1 E18; validator-rule VER401; drafted-in-1.1 §11.4Closed
SPEC-01The identity gradient claims pixel_hash survives metadata stripping — it does notaudit/specpatch-correctionfixed-in-1.0.1 E1Closed
SPEC-02§7.1's byte-exact preservation MUST defeats §7.5's redaction-with-proofaudit/specpatch-correctionfixed-in-1.0.1 E15; validator-rule VER1005; ADR-0006Closed
SPEC-03The conformance table marks contextual embeddings mandatory at L3; §8 calls them optionalaudit/specpatch-correctionfixed-in-1.0.1 E13Closed
SPEC-04image.width/height undefined for Orientation 5–8 transposesaudit/specpatch-correctionfixed-in-1.0.1 E2Closed
SPEC-05Alpha compositing assumes an 8-bit domain but is ordered before the quantize stepaudit/specpatch-correctionfixed-in-1.0.1 E4Closed
SPEC-06The HDR/gain-map step is ordered after decode and colour managementaudit/specpatch-correctionfixed-in-1.0.1 E5Closed
SPEC-07§4 disclaims cross-CMM bit-exactness while §3/§12 present pixel_hash as stable identityaudit/specpatch-correctionfixed-in-1.0.1 E1Closed
SPEC-08CPNP-1 ignores gAMA/cHRM/sRGB chunks and EXIF ColorSpace without saying soaudit/specpatch-correctionfixed-in-1.0.1 E9Closed
SPEC-09No ruling on XMP tiff:Orientation versus EXIF tag 274audit/specpatch-correctionfixed-in-1.0.1 E6Closed
SPEC-10The animated-source rule lives in Scope and never reaches normative CPNP textaudit/specpatch-correctionfixed-in-1.0.1 E7Closed
SPEC-11The quantize step leaves operation order, value domain, and tie behaviour undefinedaudit/specpatch-correctionfixed-in-1.0.1 E3Closed
SPEC-12The pixel_hash preimage does not specify integer serializationaudit/specpatch-correctionfixed-in-1.0.1 E10Closed
SPEC-13The preimage domain tag is VER1: and does not carry cpnp_versionaudit/specpatch-correctionfixed-in-1.0.1 E10 (limitation acknowledged); CPNP-2 must version the tagClosed
SPEC-14The signing payload is undefined and the signature sits inside what it signsaudit/specpatch-correctionfixed-in-1.0.1 E17; validator-rule VER1401–VER1403Closed
SPEC-15record_id and created_at have no normative definition anywhereaudit/specpatch-correctionfixed-in-1.0.1 E16Closed
SPEC-16The chain is called append-only with no mechanism making that checkableaudit/specpatch-correctionfixed-in-1.0.1 E16; validator-rule VER1201–VER1204Closed
SPEC-17Reconciliation precedence omits platform, which the conflict-source enum admitsaudit/specpatch-correctionfixed-in-1.0.1 E14Closed
SPEC-18Four prose object literals list members the schema makes optionalaudit/specpatch-correctionfixed-in-1.0.1 E15/E16/E17 (per-object rulings); remainder documentedClosed
SPEC-21"Full space descriptor" is mandatory at every level and defined nowhereaudit/specpatch-correctionfixed-in-1.0.1 E13; validator-rule VER404Closed
SPEC-23§8 puts a MUST on consumers to filter by a grade that no field carriesaudit/specpatch-correctionfixed-in-1.0.1 E19Closed
SPEC-26No behaviour defined for a present-but-unusable ICC profileaudit/specpatch-correctionfixed-in-1.0.1 E8Closed
SPEC-27No field is designated the ecosystem dedup key, and asset identity is undefinedaudit/specpatch-correctionfixed-in-1.0.1 E27; App. D #7Closed
SCH-01format is a non-assertive annotation in 2020-12, so date-time/uuid/uri go uncheckedaudit/specpatch-correctionfixed-in-1.0.1 E23; validator-rule VER202Closed
SCH-02contentEncoding is likewise non-assertive, so base64 payloads go uncheckedaudit/specpatch-correctionfixed-in-1.0.1 E23; validator-rule VER202/VER1301Closed
SCH-03pixel_hash's inert properties entries prove a forgotten additionalProperties: falseaudit/specpatch-correctionfixed-in-1.0.1 (schema delta 2)Closed
SCH-04Closure is applied inconsistently across sibling objects with no stated policyaudit/specpatch-correctionfixed-in-1.0.1 (schema delta 3, content_hash); the other seven objects deferred past 1.0.xClosed
SCH-06embedding.space_id is unconstrained while the descriptor's carries a patternaudit/specpatch-correctionvalidator-rule VER403; drafted-in-1.1 §11.6Closed
SCH-07No length constraint on perceptual digests despite §5's exact bit widthsaudit/specpatch-correctionfixed-in-1.0.1 (schema delta 1); validator-rule VER801/VER802Closed
SCH-08Base64 and by-reference vectors are undecodable as specifiedaudit/specpatch-correctionfixed-in-1.0.1 E24; validator-rule VER601–VER606Closed
SCH-09The oneOf forbids carrying an inline vector and a vector_ref togetheraudit/specpatch-correctionfixed-in-1.0.1 E24 (exclusivity is intentional)Closed
SCH-10The space_id pattern contradicts the word "semver" it implementsaudit/specpatch-correctiondrafted-in-1.1 §11.6 — deferred from 1.0.1 by ADR-0002Draft — ratification required
SCH-11preprocessing is a free-form object, so {} conformsaudit/specpatch-correctionvalidator-rule VER405; drafted-in-1.1Closed
SCH-12Availability is closed over five families; the raw-segment enum has sixaudit/specpatch-correctionfixed-in-1.0.1 E21; drafted-in-1.1 §10.3Closed
SCH-14The §7.5 redaction literal is outright rejected by the redactions[] schemaaudit/specpatch-correctionfixed-in-1.0.1 E15; ADR-0006 decided (§10 REV-18); the 1.1 schema encodes the in-view shape (draft §5.2); validator-rule VER1001/VER1002Closed
SCH-15Trust tiers live in a parallel array keyed by an opaque field stringaudit/specpatch-correctionfixed-in-1.0.1 E13/E15 reading; validator-rule VER305/VER1004Closed
SCH-17availability.c2pa and provenance.c2pa.status can contradict undetectedaudit/specpatch-correctionfixed-in-1.0.1 E28; validator-rule VER1103Closed
SCH-18Nothing requires source_bytes_ref.sha256 to equal identity.content_hashaudit/specpatch-correctionfixed-in-1.0.1 E25; validator-rule VER1305Closed
SCH-20tolerance_cosine admits 0.0001 — a conformance bar everything clearsaudit/specpatch-correctiondocumented — annex editorial note N5; drafted-in-1.1 §8.2Closed
SCH-21conformance_level is optional, so a profile validator has nothing to validate againstaudit/specpatch-correctionvalidator-rule VER301 (absent ⇒ effective L0)Closed
EX-01The example's preserved ICC segment decodes to 30 bytes declaring a 3144-byte profileaudit/specpatch-correctionfixed-in-1.0.1 example edit (b) — digest made self-consistent; truncation documented in E26Closed
EX-02The example's @context does not define the dc: prefix it usesaudit/specpatch-correctionfixed-in-1.0.1 example edit (c)Closed
EX-03The example asserts a description with no in-asset sourceaudit/specpatch-correctiondocumented — annex E26 (illustrative artifact)Closed
EX-04The example's chain records one embed event for two embeddingsaudit/specpatch-correctionfixed-in-1.0.1 example edit (d)Closed
THESIS-01The repo's headline claim is falsified by its own passing testaudit/testspatch-correctionfixed-in-1.0.1 E1; README/CLAUDE.md corrected in this branchClosed
SPEC-PIXHASH-TOLpixel_hash is claimed as stable identity while ICC bit-exactness is disclaimedaudit/testspatch-correctionfixed-in-1.0.1 E1/E12 (exact per profile, robust across profiles)Closed
SPEC-ORIENT-OOROut-of-range and malformed Orientation values are undefinedaudit/testspatch-correctionfixed-in-1.0.1 E6Closed
SCHEMA-EMB-SPACEID-UNPATTERNEDembedding.space_id is unpatterned while the descriptor's is constrainedaudit/testspatch-correctionvalidator-rule VER403; drafted-in-1.1 §11.6Closed
SCHEMA-PREPROC-EMPTYpreprocessing: {} conforms, voiding §6.1 and §6.2audit/testspatch-correctionvalidator-rule VER405; drafted-in-1.1Closed
IMPL-RECORD-ID-COLLIDESrecord_id collides across distinct Records describing the same assetaudit/testspatch-correctionfixed-in-1.0.1 E16; fixed in this branch (D7.0 #4)Closed
SCRIPT-FUSED-RECIPE-INPUTSrecipe.inputs has no defined referentaudit/testspatch-correctionfixed-in-1.0.1 E20; validator-rule VER704Closed
SCRIPT-DTYPE-ASSUMEDThe migration reader hardcodes fp16 and the base64 carriageaudit/testspatch-correctiondocumented — not patched; annex E24Deferred

7.3 additive-1.1 (26)

IDTitleSourceClassificationDispositionStatus
SPEC-05-embspace_id requires no controlled authority, no resolvability, no registryaudit/embedadditive-1.1drafted-in-1.1 (§2.2 registry, §11.3 descriptor binding); validator-rule VER404Draft — ratification required
SCHEMA-06preprocessing has no required keys, so {} satisfies §6.1's enumerationaudit/embedadditive-1.1drafted-in-1.1 §11.x; validator-rule VER405Draft — ratification required
SCHEMA-07model is required for fused spaces that run no forward passaudit/embedadditive-1.1drafted-in-1.1 §11.5Draft — ratification required
SPEC-06-emb§8's grade MUST is placed on a token that exists only in a prose tableaudit/embedadditive-1.1fixed-in-1.0.1 E19 (derived mapping); drafted-in-1.1Closed
SPEC-07-embkind cannot express a joint image-text space (CLIP/SigLIP)audit/embedadditive-1.1drafted-in-1.1 §11.1Draft — ratification required
SPEC-08-embFused recipe is unconstrained and is not part of fused-space identityaudit/embedadditive-1.1fixed-in-1.0.1 E20; drafted-in-1.1 §11.5; validator-rule VER704Closed
CPNP-06icc_error is set internally and can never be serialized into a closed recordaudit/coreadditive-1.1fixed-in-1.0.1 E8 (fail closed, no undeclared field); App. D #3Closed
SPEC-02-coreNothing marks which preserved raw segments were consumed by CPNP-1audit/coreadditive-1.1drafted-in-1.1 §10.2Draft — ratification required
REC-11The closed action enum cannot express the actions the pipeline actually performsaudit/coreadditive-1.1ADR-0004; drafted-in-1.1 §2.3Draft — ratification required
WIRE-02privacy is declarative with no consumer obligation anywhereaudit/wireadditive-1.1drafted-in-1.1 §14.5Draft — ratification required
WIRE-03No retraction, deletion, or tombstone semantics; delete commits are ignoredaudit/wireadditive-1.1drafted-in-1.1 §14.6Draft — ratification required
WIRE-08Wire comparability rests on string equality of an opaque spaceIdaudit/wireadditive-1.1drafted-in-1.1 §14.3/§11.3Draft — ratification required
WIRE-09Wire record carries no role, source.class, or grade, so §8's consumer MUST is unsatisfiableaudit/wireadditive-1.1drafted-in-1.1 §14.3; annex E19Draft — ratification required
WIRE-14No consumer reads verVersion/cpnpVersion; foreign-universe hashes are trustedaudit/wireadditive-1.1drafted-in-1.1 §14.2Draft — ratification required
WIRE-21No trust tier and no record signature on the wire; every record is unsignedaudit/wireadditive-1.1drafted-in-1.1 §14.7Draft — ratification required
WIRE-26Tags are a wire-only extension with no taxonomy version and no grounding in VER 1.0audit/wireadditive-1.1drafted-in-1.1 §14.8; §13 extensionsDraft — ratification required
WIRE-30No provenance federates, so 1.1 provenance additions have no wire carriageaudit/wireadditive-1.1drafted-in-1.1 §14.8Draft — ratification required
WIRE-31Two perceptual algorithms are hardcoded as fixed lexicon slotsaudit/wireadditive-1.1drafted-in-1.1 §14.4Draft — ratification required
SPEC-19binary dtype has no usable metric in the three-value metric enumaudit/specadditive-1.1drafted-in-1.1 §11.2 (hamming)Draft — ratification required
SPEC-22Inline descriptors have no binding to the published immutable descriptoraudit/specadditive-1.1drafted-in-1.1 §11.3 (descriptor_sha256); validator-rule VER402Draft — ratification required
SCH-05The record root is closed and no extension syntax exists anywhereaudit/specadditive-1.1drafted-in-1.1 §13 (extensions)Draft — ratification required
SCH-13availability_basis is one record-level string for potentially many familiesaudit/specadditive-1.1fixed-in-1.0.1 E21 (scope pinned); drafted-in-1.1 §10.3Closed
SCH-16Raw segments have no ordering index and no by-reference carriageaudit/specadditive-1.1fixed-in-1.0.1 E11 (concatenation order); drafted-in-1.1 §10.1Closed
TEST-GRADE-TOKENThe grade vocabulary exists only as prose with non-ASCII tokensaudit/testsadditive-1.1fixed-in-1.0.1 E19Closed
DOC-DEMO-RKEY-TRUNCATIONThe wire profile keys records on a 52-bit truncation of pixel_hashaudit/testsadditive-1.1drafted-in-1.1 §14.6Draft — ratification required
SPEC-AVAIL-BASIS-SCOPE§7.2 wants a basis per family; the schema carries one record-scoped valueaudit/testsadditive-1.1fixed-in-1.0.1 E21 (scope pinned); drafted-in-1.1 §10.3Closed

7.4 editorial (9)

IDTitleSourceClassificationDispositionStatus
SCHEMA-08§6.1 lists architecture; the schema does not require itaudit/embededitorialdocumented — annex editorial note N4Closed
CPNP-10alpha_present is set for a fully opaque alpha channel where compositing is a no-opaudit/coreeditorialdocumented — reading pinned by annex E4/N3Closed
WIRE-28Lexicon prose is stale and self-contradicting against the code it describesaudit/wireeditorialdocumented — annex editorial note N6Closed
WIRE-33One width/height pair on the wire with no statement of which dimensions they areaudit/wireeditorialfixed-in-1.0.1 E2; annex editorial note N6Closed
SPEC-20The acquisition-method ellipsis implies an open set the schema closesaudit/speceditorialdocumented — annex editorial note N1Closed
SPEC-24§4 items 7–8 are definitions, not executable stepsaudit/speceditorialdocumented — annex editorial note N2Closed
SPEC-25"Alpha semantics" is listed as metadata although alpha is pixel dataaudit/speceditorialdocumented — annex editorial note N3Closed
SCRIPT-STRIPCOPYA helper states pixel_hash invariance unconditionallyaudit/testseditorialfixed-in-1.0.1 E1; script documented — not patchedClosed
DOC-DEMO-VERIFY-PREDICATEThe demo states the wire-integrity check as sha256 over base64 textaudit/testseditorialdocumented — not patchedDeferred