Native audit format vectors
These are audit journal, not session recording, vectors.
Version 1 includes a complete sealed clear .baudit and a complete sealed
age-encrypted .beaudit, each with a separate signed head.cbor checkpoint.
The signing and age-recipient seeds are public test data; never use them
to protect production data. The recipient key differs from the signing key.
For the byte layout and field keys, see the audit format and
shared container rules. Operational CLI verification requires
a configured journal root with a signed head, not a bare downloaded
segment; see the audit log reference.
Downloads
The manifest is the strict version 1 inventory: public test seeds, producer and recipient identity, sizes, raw file SHA-256 values, reproducibility, and audit domain hashes.
| Clear vector | Purpose |
|---|---|
baudit-v1.baudit |
Complete deterministic signed clear segment: magic, header, two records, seal. |
baudit-v1-head.cbor |
Raw signed head checkpoint for the clear segment. |
baudit-header.unit |
Exact framed header excerpt from the clear segment. |
baudit-records.unit |
Exact two consecutive framed record excerpts from the clear segment. |
baudit-seal.unit |
Exact framed seal excerpt from the clear segment. |
baudit-v1-redacted.jsonl |
Clear journal export without private event fields. |
baudit-v1-with-sensitive.jsonl |
Clear journal export with private event fields. |
| Encrypted vector | Purpose |
|---|---|
beaudit-v1.beaudit |
Complete frozen signed age-encrypted segment. |
beaudit-v1-head.cbor |
Raw signed head checkpoint for the encrypted segment. |
beaudit-header.unit |
Exact framed signed mode-1 header excerpt; independently reproducible with the public signing seed. |
beaudit-records.unit |
Exact two frozen framed record excerpts, including randomized age ciphertext. |
beaudit-seal.unit |
Exact frozen framed seal excerpt from the encrypted segment. |
beaudit-v1-redacted.jsonl |
Encrypted journal outer-only export, no decryption key. |
beaudit-v1-with-sensitive.jsonl |
Full verified export after decryption with the public test recipient identity. |
Every .unit file is an actual signed CBOR unit, an exact framed excerpt
from its complete segment, not a synthetic body. Each records file contains
two adjacent units. The encrypted header declares mode 1 and recipient
SHA256:ZsrOVCtcb1bouzun0GIHz5vL5oCjVhVIQ3jfIBIgZ8g; its framed bytes
are independently deterministic. The encrypted record and seal excerpts
depend on frozen ciphertext.
Both segment types begin with the eight bytes \x89BAUDIT\n. Each following
unit is type:u8 | length:u32be | commit-state:u8 | deterministic-CBOR |
crc32c:u32be | BFCOMMIT. CRC32C excludes the commit-state byte. Types
1, 2, 3 mean header, record, and seal. The separate head is raw CBOR,
not a framed unit.
Fixture events
The two fixed UUIDv4 record IDs are
34e34ab8-7457-4d88-a5e4-c57791775c3a and
6d05798f-b877-4191-8aa0-4576a30411ad. They were recorded on
2026-09-13T12:34:56.123456789Z and 2026-09-13T12:35:01.987654321Z.
Their public event fields (name / domain / outcome) are
custom.authentication / authentication / success and
custom.session / session / denied. Record IDs, timestamps, and hashes
belong to the separate export envelope.
With sensitive output, the first event also has flow fixture-flow, a
connection ID, public-key authentication method, and verified phase. The
second has the same flow, a session ID, exec task, and
authorized-key-policy reason. Redacted JSONL excludes all these private
fields, even for the clear segment. Public envelope metadata can still be
sensitive.
Known values
| Public test value | Value |
|---|---|
| Signing seed | 000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f |
| Distinct age-recipient seed | 4242424242424242424242424242424242424242424242424242424242424242 |
| Trusted producer ID | 95b9aca00d322047048950d19cc5aece6fa757edd9104a5521446a168792b298 |
| Expected encrypted recipient fingerprint | SHA256:ZsrOVCtcb1bouzun0GIHz5vL5oCjVhVIQ3jfIBIgZ8g |
The clear header has no recipient.
| Domain-separated audit hash | Clear | Encrypted (frozen) |
|---|---|---|
| First record | 4abff565227d1caa4dd8024573ccb9e913d9c4bd9c5c436ea365e10f2e2b0e0c |
948219b4682315c7c2630691cd0d37da1f68f4610e821d55f6b7ddc1635b11b1 |
| Second record / signed head tip | 0411421b5a07a742ea3bcea32f41fc2d962eb061b8cbbda88d94484d42a67d2f |
597d1df3c659c5de7a183d2e1c8b5f7829d27b52fd5bdb6f1659b17560e88749 |
| Content (magic through final record) | 5fb0c20d9d91de7b9a4835e4ecc878978931d87a73a5f7b6730a28967866463a |
1ad8504fc41e89811d0236e6b17cc2fc34920d3ab58dd8e9ffb3c213b7ce8f8f |
| Segment (entire sealed file) | fe793ee92c2547663fbd50dec41971378d3d837bb2e6237fe06d6009d0ce9bc5 |
917fba80141b65171aa763ee878d45e67c9852aaa227fad87d89eb9451c3ff57 |
These hashes use the audit-specific domain prefixes,
not raw SHA-256 file digests. For example, baudit-v1.baudit is 1021 bytes
with raw SHA-256
9e996c9f05ba029cd9c9767d5227ce85d5638d464ced4b6d9854c82f6e6e7111;
beaudit-v1.beaudit is 1500 bytes with raw SHA-256
6e2405618accc2392ef8740e543416e2ee51174ea9eaf7e30857d91bf5f6d2ed.
The manifest lists the exact lengths and raw SHA-256 for every download.
The head is an independent signed checkpoint bound to the second record hash;
it is not included in either segment hash.
Verification and reproduction
mise exec -- go test ./pkg/audit -count=1 checks the exact asset list,
manifest schema, metadata, lengths, and hashes against the actual bytes. It
regenerates the clear header, records, seal, and head with production
encoders and compares every byte; decodes and compares framed .unit excerpts;
and independently regenerates the signed mode-1 header without encrypting.
The tests use VerifyJournalIntegrity, VerifyJournals, and
ExportJSONLines on a temporary
<journal>/<producer-id>/segment-<sequence>-<hash> plus head.cbor tree.
They check both redacted and full exports. For encrypted bytes they verify
signatures and hashes without a key, verify and export private fields using
the published test key, and reject missing or wrong keys in full mode. Normal
tests never rewrite fixtures.
Age encryption consumes fresh randomness. The encrypted .beaudit, its head
(which signs its ciphertext-dependent chain tip), both JSONL exports, and the
encrypted record and seal units have reproducible: false: they are frozen
decoder vectors, not bytewise regeneration targets. Only
beaudit-header.unit is independently reproducible (reproducible: true).
To update clear vectors and re-extract encrypted units without changing the four frozen Age files, run:
1 | |
This first checks the existing .beaudit, its head, and both JSONL exports
against the old manifest's actual SHA-256 and size; then it verifies the
frozen journal and writes excerpts and an updated manifest. Only deliberate
replacement of the age ciphertext uses both flags:
1 | |
The age flag alone is rejected. Review every resulting binary and manifest change before publishing. Never compare a freshly encrypted segment byte for byte with the frozen one. A valid self-signature does not establish trust: pin the expected producer ID and, for encrypted journals, the expected recipient fingerprint from a trusted source.
The opt-in generator writes multiple files and is not transactional. If it fails, resolve the cause, regenerate, and pass the complete vector test suite before publishing anything.