Test vectors

The golden vectors that prove the binary claims in this specification. They are the genuine output of the reference, generated by vectors/gen_vectors.py and stored in vectors/vectors.json.

Regenerate and verify (from the repository root):

PYTHONPATH=reference/Reticulum \
    python3 docs/src/appendix/reticulum/vectors/gen_vectors.py

Pinned to RNS 1.3.5 @ d5e62d4. Fixed inputs: source identity private = 0001…3f, destination identity private = 4041…7f, time = 1700000000.0.

Vector kinds

  • frozen — deterministic; the hex is the proof.
  • frozen-injection — ephemeral-key path made reproducible by pinning os.urandom/time/X25519 generation, with a decrypt/verify/derive roundtrip.
  • computed — reconstructed per source layout where a live link/transport is needed; byte-exact and cited.

Primitives

  • VEC-HASH (frozen, Identity.py:409-426): full_hash("reticulum-spec") = 659fe249468c635cdfe90a12624abec49f0bd36ba66d467b4f7155c79e8addf2; truncated 659fe249468c635cdfe90a12624abec4.
  • VEC-HKDF (frozen, HKDF.py:35): hkdf(32, 00..1f, salt=00..0f) = 2bc3faec9f360e81e77086b6e17a9ce8722a4cb3bc0ed90b4d78d37036e43a0f.
  • VEC-HMAC (frozen): HMAC-SHA256 over the fixed key/message.
  • VEC-AES (frozen): AES-256-CBC one block → e23fc0b91c7bd64425c559736e9b0c58, decrypts back.

Identity

  • VEC-ID-HASH (frozen): 64-byte public key from 0001…3f; identity hash aca31af0441d81dbec71e82da0b4b5f5.
  • VEC-ID-SIGN (frozen): Ed25519 signature bbfdcde5aa05197f…, validate true.
  • VEC-ID-TOKEN (frozen-injection, encrypt, Identity.py:827-928): 112-byte token efd9ec3449e46df2… = ephemeral_pub(32) || IV(16) || ciphertext || HMAC(32); decrypt(token) == plaintext.

Destination

  • VEC-DEST-HASH (frozen): app test, aspect vec → name hash 9da53eec82a28ce2f2e9 (10), destination hash 07d4541d4fdc0abfacc9364fdf979ee1 (16).

Packet

  • VEC-PKT-PLAIN (frozen): 0800fc0910664040482cd653166c8f225520006869 — flags 08 (PLAIN/DATA), hops 00, dest(16), context 00, data "hi".
  • VEC-PKT-ENC (frozen-injection): SINGLE encrypted HEADER_1 packet, flags 00.
  • VEC-PKT-HEADER2 (computed, Packet.py:256-260): 4000 a0..af b0..bf 00 64617461 — flags 40 (HEADER_2), transport id(16), dest(16), context, data.

Announce

  • VEC-ANN-NORATCHET (frozen-injection): flags 01 (context flag 0); 150 data bytes 79a631eede1bf9c9… = pubkey(64) || name(10) || random(10) || sig(64) || app_data(2); validate_announce true.
  • VEC-ANN-RATCHET (frozen-injection): context flag 1; 182 data bytes including the 32-byte ratchet; validate_announce true.
  • VEC-LINK (frozen-injection, Link.py:308-366): request data a4e09292… = eph_x25519(32) || eph_ed25519(32) || signalling(3); link id 4725ac1375601d182afec3610f019b25; ECDH agreement true; 64-byte session key 569ac51a07fb242f… = hkdf(64, ecdh, salt=link_id).

Resource

  • VEC-RES-ADV (computed, Resource.py:1275-1352): advertisement dict with flags 03 (compressed+encrypted), packs to 146 bytes.
  • VEC-RES-PROOF (frozen, Resource.py:752-753): proof_data = resource_hash || full_hash(data || resource_hash) = d257b38bc5d6aa22… (64 bytes).

Channel and Buffer

  • VEC-CHAN-ENVELOPE (frozen): abcd0007000b6368616e6e656c64617461 — type abcd, sequence 0007, length 000b, payload "channeldata".
  • VEC-STREAM-HDR (frozen): 810273747265616d64617461 — header 8102 (eof set over stream id 0x0102), data "streamdata".

Transport

  • VEC-PATH-REQUEST (frozen-injection, Transport.py:2780-2787): payload 000102…0f (target 16) || tag(16), in a PLAIN packet (flags 08).

Framing and IFAC

  • VEC-HDLC (frozen, TCPInterface.py:44-52): 01 7E 02 7D 03 frames to 7e017d5e027d5d037e.
  • VEC-IFAC (frozen, Transport.py:1112-1148): tag 2cf485c1dfcea002, masked output 9f4a2cf485c1dfcea0…, IFAC header flag set, mask/unmask roundtrip recovers the original packet and tag.