Privacy-sanitized source narrative
Pinned HashSigsRS legacy WOTS vectors
This page publishes the producing narrative as escaped plaintext. It preserves repository provenance while withholding machine-local paths and private build-host labels.
Sanitization disclosure
This is a public projection, not a byte-identical copy when substitutions are listed. The pre-sanitization digest identifies the narrative bytes read from the documentation checkout; the cryptographic subject commit is recorded separately.
No local-path or private-host substitutions were required for this source file.Provenance
The digest identifies the narrative bytes read by this documentation build before substitutions. It does not assert that those narrative bytes existed at the cryptographic subject/source commit.
Producing narrative
# Pinned HashSigsRS vectors
`wotsplus_keccak256.json` is an unmodified copy of
`tests/test_vectors/wotsplus_keccak256.json` from QuipNetwork/hashsigs-rs commit
`2d315dd4168804b7cbc51c51a1bf7ca27bf74140` (2026-03-25).
- Upstream license: `AGPL-3.0-or-later`
- File SHA-256:
`5e960bc3b4e6153cf42ad7c70424d9361a55f19f694eef7cb2cb7f16f7d2b041`
- Profiles covered: `LEGACY_KECCAK` only
- Cases: `vector0` through `vector4`
These vectors use legacy Keccak-256 padding. They must not be accepted as
`HASHSIGS_SHA256_GENERIC_V1` vectors. The JSON includes all 67 upstream
randomization elements (and a `publicKeySegments` field that duplicates that
array). Tests pin the complete file checksum, compare each observable public key
and signature byte-for-byte, and independently confirm that only elements zero
through 15 can affect those outputs.