Developer guide · Zikaron

Checksums

Every figure for the release files, the signature, the law’s digests and the registry contract can be recomputed yourself.

Release files

Version 0.1.0 has three release files, with their checksums in the release list SHA256SUMS.txt:

.dmg033cccae949d3d37d6c2c8674ae32419a01790c523ab34b84ea54211cc78d1dd
.pkg6f49a4cb35b7e7aeaa2fc724382ff650bd9a6e6a6a5347d598533e8ee5f5464a
Source383b08847004b3409275c388dd6e1b8bb76c63fab1e73d0d2734e6c6720b81f5

Compute one file and compare it with the table:

shasum -a 256 ZIKARON-0.1.0-macos-arm64.dmg

Or put the release list and the downloaded files in one folder and check them all at once:

shasum -a 256 -c --ignore-missing SHA256SUMS.txt

The drop zone on the download page does the same: it computes the SHA-256 in the browser and compares it with the list.

Signature

The app and the dmg are signed with Kaptonia’s self-signed certificate; the pkg is checked by its SHA-256. Once installed, look at the app’s signature: Authority in the output should be Kaptonia, and Identifier should be com.kaptonia.zikaron.app:

codesign -dvv /Applications/ZIKARON.app

Then look at the signing requirement; the string after certificate leaf is the certificate’s SHA-1:

codesign -d -r- /Applications/ZIKARON.app

To compute the certificate’s SHA-256, extract the certificate first:

codesign -d --extract-certificates /Applications/ZIKARON.app shasum -a 256 codesign0
SignerCN=Kaptonia (self-signed)
Certificate SHA-256a6ddc371e855197c5021ef44ab0802749cda318bc12d0138ccac9f46a4d46905
Certificate SHA-1570690b34fc35243ae8b45be0aeb800e1074225e
Valid2026-09-26 to 2036-09-23

The dmg’s own signature can be checked the same way: codesign -dvv ZIKARON-0.1.0-macos-arm64.dmg.

Zikaron record

The code of each release is one commit. Before 0.1.0 was published, the project recorded that commit and each release file’s fingerprint in its Zikaron ledger and anchored them on Ethereum mainnet: written once and final, with a block time. The “Zikaron record” column of the download table links to this transaction.

Transaction0x028fdb5591635442bb0ca30dced70305438dac34434b7a02c9daa7f9054fd329
Block26094186 · 2026-10-01 01:29:59 UTC
Recorder address0x3be672658efa08b9820bbebaf7c4f0e77433f878
Registry contract0x36Ea8A857a5FE813429d4D9947000C644A88809A

The content fingerprints recorded in the ledger:

.dmg033cccae949d3d37d6c2c8674ae32419a01790c523ab34b84ea54211cc78d1dd
.pkg6f49a4cb35b7e7aeaa2fc724382ff650bd9a6e6a6a5347d598533e8ee5f5464a
Source383b08847004b3409275c388dd6e1b8bb76c63fab1e73d0d2734e6c6720b81f5
SHA256SUMS.txtc054be85a20952f986ea46ad9f6201c2c9bdcbecef01ef62e650525a54e52cef
Source commit 54fe7dbb0a679c69cac91c68b99fe704f30abd2bdc9107053650dec2373f2507ed1b434

The source commit’s fingerprint is the SHA-256 of the commit object. In a clone of the repository at tag v0.1.0, run:

git cat-file commit HEAD | shasum -a 256

What is anchored on chain is the IDs of the ledger entries, and the entries record the fingerprints above.

The law’s digests

Both laws are frozen, and their digests are written in the law texts. Unpack the source and compute them yourself; the results should match the table:

cd zikaron-0.1.0/base/zikaron-conformance ./criterion-digest.sh ./criterion-digest-kit.sh
zikaron/1 · §12.50xbecfb6f0d0f8b71c314f1b2efef414abfb6df74b711ca8f81efdef685d0132fc
zikaron.kit/1 · §13.50x3f8368ebc8b5b7c97e4b5c4240f57f6fc06421b4effbd5a7446d128434a20535

Each script reads a few Python source files and computes one digest; change any byte of them and the digest changes. See The law and the conformance suite.

The registry contract

The registry contract does one thing: it receives a fingerprint and emits an event. The app comes with two deployments; read the code on chain and compute its keccak256, and the result should equal the code hash below:

cast keccak $(cast code <contract address> --rpc-url <node>)
Code hash0xfa97a1d9b22fab2b52f4e27c9a965b32734c40001b565ab365d05c887118f57d
Ethereum mainnet0x36Ea8A857a5FE813429d4D9947000C644A88809A
Sepolia0xC29410B882c4C3b77e33659d2f06ac563e7B08a3

How to recompute the hash from source is under The registry contract and anchoring.