On this page· 3

Verify

  • file format 6
  • Rust SDK 1.0 preview

Verify is the fixed list of ten checks a reader runs on a pack. Opening a pack with the Rust SDK runs the first eight.

The ten steps

The order is fixed. A reader that stops at the first failure reports the kind of that failure, so every conforming reader reports the same kind for the same file.

Figure 1 The ten verify steps

  1. 1Sizeinvalid_header
  2. 2Headerinvalid_headerunsupported_version
  3. 3Footerinvalid_footerunsupported_version
  4. 4Header against footerheader_footer_mismatch
  5. 5Layoutinvalid_footerappendix_alignmentlimit_exceeded
  6. 6Digestchecksum_mismatch
  7. 7Bodyinvalid_utf8invalid_recordjson
  8. 8Countrecord_count_mismatch
  9. 9Appendixappendix_invalidappendix_crc_mismatch
  10. 10Bindingscounted, not raised: a caller that binds a dangling target gets dangling_embref
Step 9 is dashed: it runs only when the pack has an appendix. Step 10 checks bindings, local or in another file. A reader that stops at the first failure reports that step's kind.
Table 1. Verify steps: 10
#StepCheckError kinds
1Sizethe file is at least 353 bytesinvalid_header
2HeaderASCII, byte 256 is LF, the grammar matches; the version is 6invalid_header unsupported_version
3Footermagic is PLXF; the version is 6; bytes 44 to 63 are zeroinvalid_footer unsupported_version
4Header against footera final header line equals the footer on four values; a placeholder defers to the footer; anything else failsheader_footer_mismatch
5Layout257 ≤ T ≤ L − 96; without an appendix A = 0 and T = L − 96; with one, A is a multiple of 64, A is T rounded up, A + csdt_size = L − 96, and the padding is zeroinvalid_footer appendix_alignment limit_exceeded
6DigestSHA-256 of bytes 257 up to L − 96 equals footer bytes 64 to 95checksum_mismatch
7Bodyvalid UTF-8; the marker line is last when there is an appendix and absent otherwise; every line parsesinvalid_utf8 invalid_record json
8Countthe number of record lines equals record_countrecord_count_mismatch
9Appendixthe container's own checks, the CRC32C of every section, and the footer's copy of the container's checksumappendix_invalid appendix_crc_mismatch
10Bindingsevery local target is in range; every ext target has its csdt_ref recordcounted, not raised: a caller that binds a dangling target gets dangling_embref

limit_exceeded at step 5 means the layout is valid in 64-bit arithmetic but an offset or size does not fit the platform's address width. It is never truncated.

Open, or ask for a report

  • Pack::open and Pack::from_bytes refuse a pack that fails steps 1 to 8, and return the first failing step's kind.
  • OpenOptions::no_verify() skips steps 4, 6, 7 and 8: header against footer, digest, body and count. Size, header, footer and layout still run. Pack::verify then returns a report with one member per check.

Note

Pack::verify reports what it can read. Damage that leaves a record line unparseable is returned as an error, json or invalid_record, not as a report.

Open and verify a pack, with code

Conformance levels

An implementation claims one or more conformance levels. Each level is a set of requirements and a set of test cases in the conformance corpus.

Table 2. Conformance levels with cases in corpus 1: 5
LevelRequiresCases in corpus 1
Reader-Corelayout, header line, records, identity, digest, verify steps 1 to 8, footer and JSON spelling42
Reader-AppendixReader-Core, the appendix, verify steps 9 and 1027
Writerwrites files that pass both reader levels, in sort order and spelling27
Mergermerge11
Differdiff4

The Rust SDK passes all 111 cases of corpus version 1, recorded 2026-10-02. Conformance

Sections