gateway v0.1.0
First binary release of the attested-input gateway, built from the tagged source (7b3afab).
What this is
One Go binary, standard library only: gateway canon | verify | conform | serve | keygen. Receipt format version 2 — Ed25519 signatures with a prevSignature chain, keyId on every receipt, signed seals, and /publickey — with SPEC.md normative for the format and the frozen conformance corpus (30 canon + 19 store vectors) as its teeth. The gateway binds localhost and invokes subprocesses by design, which is why it is deliberately a separate artifact from the judgment-pack runtime and is never folded into it.
Why a published artifact
Downstream consumers stage binaries through a verified lock — name, version, digest, checked before anything executes. Until now the only way to pin this gateway was an untagged source build. This release gives the pin a published, immutable target, per the replay discipline documented in judgment-pack-runtime#94: record the artifact digest next to what it produced.
Verification
sha256sum -c checksums.txt --ignore-missingagainst your downloaded archive.- The published
linux_amd64binary was run against the corpus at this tag before publication:gateway conform→ 30 canon vectors, 19 store vectors, 0 disagreements. The other platforms are cross-compiled from the same source and were not corpus-verified on their native platforms. - Build:
go1.26.5,CGO_ENABLED=0 go build -trimpath -buildvcs=false -ldflags "-s -w -buildid=", archives normalized (sorted entries, zeroed ownership, fixed mtime).
Contents
Each archive carries the binary plus LICENSE, README.md, and SPEC.md.
Two standing bounds from SPEC.md worth repeating with any distribution: the gateway's public key must reach verifiers out of band (fetching it from the audited gateway proves consistency, not authenticity), and the corpus is frozen — a vector change is a spec change.