docs: explain synthetic verification fixtures - #7
Draft
salismidtrans wants to merge 1 commit into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
testdata/README.mdwith the fixture inventory, test-only BI-SNAP key warning, contributor safety rules, and proof-level boundary.Why
The public repository already tracks deterministic payloads, generated cryptographic test vectors, and complete/broken merchant-repository shapes. Merchants evaluating the public preview need to know what these fixtures validate and, equally importantly, what they cannot prove.
Safety boundary
The fixtures contain synthetic identifiers, deterministic signatures, empty credential placeholders, and a deliberately public test-only RSA key pair. They must never be reused in a merchant environment. Passing fixture-backed tests is local deterministic CLI proof only; real Sandbox and provider proof still require merchant-owned credentials, activation, callbacks, and provider interaction.
Validation
go test ./... -count=1./tools/check_release.shAll checks passed on commit
20f79217b238168750e8322af0621c269c3d0f23.