HashSigs RHDL privacy-sanitized source narrative Evidence record: legacy-wots-upstream-vectors Repository-relative source: tests/vectors/hashsigs/README.md Cryptographic subject/source commit: 2165652a5a1a853252bf5fe5e4b2084c65bc94de Cryptographic source dirty: no Pre-sanitization narrative SHA-256: b370a6950234741fd65d31f9284f562c35484e40744bf4e292eb1587ef695407 Narrative checkout commit: 3810cf837ea79ca005f4ab227b0b5c2134fe6ad1 Narrative checkout dirty: no Sanitization substitutions: none required This public projection is not byte-identical when substitutions are listed. The digest identifies the pre-sanitization narrative bytes read by this documentation build. It does not assert that those bytes existed at the cryptographic subject commit. --- sanitized narrative --- # Pinned HashSigsRS vectors `wotsplus_keccak256.json` is an unmodified copy of `tests/test_vectors/wotsplus_keccak256.json` from QuipNetwork/hashsigs-rs commit `2d315dd4168804b7cbc51c51a1bf7ca27bf74140` (2026-03-25). - Upstream license: `AGPL-3.0-or-later` - File SHA-256: `5e960bc3b4e6153cf42ad7c70424d9361a55f19f694eef7cb2cb7f16f7d2b041` - Profiles covered: `LEGACY_KECCAK` only - Cases: `vector0` through `vector4` These vectors use legacy Keccak-256 padding. They must not be accepted as `HASHSIGS_SHA256_GENERIC_V1` vectors. The JSON includes all 67 upstream randomization elements (and a `publicKeySegments` field that duplicates that array). Tests pin the complete file checksum, compare each observable public key and signature byte-for-byte, and independently confirm that only elements zero through 15 can affect those outputs.