On this page· 3
Verify
- file format 6
- Rust SDK 1.0 preview
Verify is the fixed list of ten checks a reader runs on a pack. Opening a pack with the Rust SDK runs the first eight.
The order is fixed. A reader that stops at the first failure reports the kind of that failure, so every conforming reader reports the same kind for the same file.
Figure 1 The ten verify steps
- 1Size
invalid_header - 2Header
invalid_header unsupported_version - 3Footer
invalid_footer unsupported_version - 4Header against footer
header_footer_ mismatch - 5Layout
invalid_footer appendix_alignment limit_exceeded - 6Digest
checksum_mismatch - 7Body
invalid_utf8 invalid_record json - 8Count
record_count_ mismatch - 9Appendix
appendix_invalid appendix_crc_ mismatch - 10Bindingscounted, not raised: a caller that binds a dangling target gets
dangling_embref
| # | Step | Check | Error kinds |
|---|---|---|---|
| 1 | Size | the file is at least 353 bytes | invalid_header |
| 2 | Header | ASCII, byte 256 is LF, the grammar matches; the version is 6 | invalid_header unsupported_version |
| 3 | Footer | magic is PLXF; the version is 6; bytes 44 to 63 are zero | invalid_footer unsupported_version |
| 4 | Header against footer | a final header line equals the footer on four values; a placeholder defers to the footer; anything else fails | header_footer_mismatch |
| 5 | Layout | 257 ≤ T ≤ L − 96; without an appendix A = 0 and T = L − 96; with one, A is a multiple of 64, A is T rounded up, A + csdt_size = L − 96, and the padding is zero | invalid_footer appendix_alignment limit_exceeded |
| 6 | Digest | SHA-256 of bytes 257 up to L − 96 equals footer bytes 64 to 95 | checksum_mismatch |
| 7 | Body | valid UTF-8; the marker line is last when there is an appendix and absent otherwise; every line parses | invalid_utf8 invalid_record json |
| 8 | Count | the number of record lines equals record_count | record_count_mismatch |
| 9 | Appendix | the container's own checks, the CRC32C of every section, and the footer's copy of the container's checksum | appendix_invalid appendix_crc_mismatch |
| 10 | Bindings | every local target is in range; every ext target has its csdt_ref record | counted, not raised: a caller that binds a dangling target gets dangling_embref |
limit_exceeded at step 5 means the layout is valid in 64-bit arithmetic but an offset or size does not fit the platform's address width. It is never truncated.
Pack::openandPack::from_bytesrefuse a pack that fails steps 1 to 8, and return the first failing step's kind.OpenOptions::no_verify()skips steps 4, 6, 7 and 8: header against footer, digest, body and count. Size, header, footer and layout still run.Pack::verifythen returns a report with one member per check.
Note
Pack::verify reports what it can read. Damage that leaves a record line unparseable is returned as an error, json or invalid_record, not as a report.
An implementation claims one or more conformance levels. Each level is a set of requirements and a set of test cases in the conformance corpus.
| Level | Requires | Cases in corpus 1 |
|---|---|---|
| Reader-Core | layout, header line, records, identity, digest, verify steps 1 to 8, footer and JSON spelling | 42 |
| Reader-Appendix | Reader-Core, the appendix, verify steps 9 and 10 | 27 |
| Writer | writes files that pass both reader levels, in sort order and spelling | 27 |
| Merger | merge | 11 |
| Differ | diff | 4 |
The Rust SDK passes all 111 cases of corpus version 1, recorded 2026-10-02. Conformance