Checksums
Every figure for the release files, the signature, the law’s digests and the registry contract can be recomputed yourself.
Release files
Version 0.1.0 has three release files, with their checksums in the release list SHA256SUMS.txt:
.dmg033cccae949d3d37d6c2c8674ae32419a01790c523ab34b84ea54211cc78d1dd.pkg6f49a4cb35b7e7aeaa2fc724382ff650bd9a6e6a6a5347d598533e8ee5f5464aCompute one file and compare it with the table:
shasum -a 256 ZIKARON-0.1.0-macos-arm64.dmgOr put the release list and the downloaded files in one folder and check them all at once:
shasum -a 256 -c --ignore-missing SHA256SUMS.txtThe drop zone on the download page does the same: it computes the SHA-256 in the browser and compares it with the list.
Signature
The app and the dmg are signed with Kaptonia’s self-signed certificate; the pkg is checked by its SHA-256. Once installed, look at the app’s signature: Authority in the output should be Kaptonia, and Identifier should be com.kaptonia.zikaron.app:
codesign -dvv /Applications/ZIKARON.appThen look at the signing requirement; the string after certificate leaf is the certificate’s SHA-1:
codesign -d -r- /Applications/ZIKARON.appTo compute the certificate’s SHA-256, extract the certificate first:
codesign -d --extract-certificates /Applications/ZIKARON.app
shasum -a 256 codesign0The dmg’s own signature can be checked the same way: codesign -dvv ZIKARON-0.1.0-macos-arm64.dmg.
Zikaron record
The code of each release is one commit. Before 0.1.0 was published, the project recorded that commit and each release file’s fingerprint in its Zikaron ledger and anchored them on Ethereum mainnet: written once and final, with a block time. The “Zikaron record” column of the download table links to this transaction.
The content fingerprints recorded in the ledger:
.dmg033cccae949d3d37d6c2c8674ae32419a01790c523ab34b84ea54211cc78d1dd.pkg6f49a4cb35b7e7aeaa2fc724382ff650bd9a6e6a6a5347d598533e8ee5f5464aSHA256SUMS.txtc054be85a20952f986ea46ad9f6201c2c9bdcbecef01ef62e650525a54e52cef54fe7dbb0a679c69cac91c68b99fe704f30abd2bdc9107053650dec2373f2507ed1b434The source commit’s fingerprint is the SHA-256 of the commit object. In a clone of the repository at tag v0.1.0, run:
git cat-file commit HEAD | shasum -a 256What is anchored on chain is the IDs of the ledger entries, and the entries record the fingerprints above.
The law’s digests
Both laws are frozen, and their digests are written in the law texts. Unpack the source and compute them yourself; the results should match the table:
cd zikaron-0.1.0/base/zikaron-conformance
./criterion-digest.sh
./criterion-digest-kit.shEach script reads a few Python source files and computes one digest; change any byte of them and the digest changes. See The law and the conformance suite.
The registry contract
The registry contract does one thing: it receives a fingerprint and emits an event. The app comes with two deployments; read the code on chain and compute its keccak256, and the result should equal the code hash below:
cast keccak $(cast code <contract address> --rpc-url <node>)How to recompute the hash from source is under The registry contract and anchoring.