VC/DID development plan — canivc.com + EECC test environments#

Date: 2026-07-11. Grounded against the tree at 898159c (docs/test-results/latest.json, 2026-07-11) and the canivc landing 12cd438. Extends the existing coverage program (2026-07-10-vc-did-coverage-program.md, epic #288) with the two new interop test environments the owner named: canivc.com (Digital Bazaar community-compatibility aggregator) and the EECC (European EPC Competence Center) VC/DID interop stack. Every number is labelled pass/fail/total (anti-pattern #25); no bare ratios.

Update 2026-07-14 (obsolescence sweep): Tracks A1 and A4 named below both landed and their target suites are now fully green: vc_di_eddsa 31 pass, 0 fail (out of 31 — proof sets/chains + previousProof chaining landed, closing the "multi-proof / proof.previousProof chaining unsupported" gap called out below) and vc20_api 59 pass, 0 fail (out of 59 — relatedResource digest/id checks and the VP JSON-LD named-graph @container: @graph expansion gap both closed). The root-cause narrative in §1 below is preserved as the 2026-07-11 baseline diagnosis that motivated this plan; treat its score numbers as historical, not current.

1. Current state (verified, as of 2026-07-11 — see update above for current scores)#

Scores (latest.json): vc_stage1 117 pass, 0 fail (of 117, structural, VC.Credential.fst direct); vc_di_eddsa 26 pass, 5 fail (of 31, official eddsa suite via bin/vc-api-shim); vc20_api 22 pass, 37 fail (of 59, official vc-data-model-2.0 HTTP tests via the shim); did_key 8 pass, 0 fail (of 8, internal vectors only).

F* modules: VC.Credential.fst (VCDM 2.0 structural checker, 117/0), VC.DataIntegrity.fst (eddsa-rdfc-2022, 4 crypto assume vals at :34-51), VC.Multibase.fst (pure codecs, all targets), VC.Context.fst (offline term resolver), DID.Key.fst (Ed25519-only, returns bare RDF, not a DID Resolution Result envelope).

Crypto (per crypto-policy + node-crypto-haclstar-vc-wasm-build): native = vendored HACL* C (Ed25519 + SHA-256 only; P-256/BBS/RSA explicitly excluded from the curated closure). Off-native = HACL*'s official hacl-wasm@1.4.0 vendored and wired (Node + browser), gated by npm/factoidal/test/vc-crypto.test.js. Flag: issue #286's checklist still shows the wasm-wiring item unchecked though the artifacts are in the tree — likely stale (obsolescence-sweep item), confirm before closing.

Why the fails fail (the actionable part):

2. The two new environments#

canivc.com = static aggregator over 10 published interop index.json reports (vc2.0, vc-di-ecdsa, ed25519signature2020, vc-di-eddsa, vc-di-bbs, did-key, vc-api-issuer, vc-api-verifier, vc-bitstring-status-list, vc-jose-cose). We measurably run 3 of 10. Demands we don't yet meet: structural validation over HTTP; proof-set / previousProof chains; a DID Resolution Result envelope; BitstringStatus­ List; ECDSA/ES256. Out of realistic near-term reach without new crypto/ serialization decisions: BBS (no HACL* BBS), JOSE/COSE, Ed25519Signature­ 2020, full VC-API exchanges.

EECC (github.com/european-epc-competence-center) = GS1 product-passport VC/DID stack. Not vendored yet (grep-confirmed zero real hits). Licence-gated per crypto-policy:

3. Prioritized tracks (one commit-sized deliverable each)#

Order: A2 → A1 → A3 → B1 → B2 → B3 → C. Ranked by score-per-effort.

Track A — canivc burndown (no new vendoring):

Track B — EECC-motivated new coverage:

Track C — cross-check + honesty:

4. Dependencies / fixtures#

5. /goal line (VC track)#

Advance VC/DID conformance against canivc.com and the EECC interop stack: wire VC.Credential's structural checker into the vc-api-shim's HTTP verify/issue path (official vc-data-model-2.0-test-suite currently 22 pass, 37 fail of 59, the shim doing zero structural validation of its own); close the vc-di-eddsa gaps (26 pass, 5 fail of 31 — proof-set/previousProof chaining + DATA_LOSS_DETECTION_ERROR); add a DID Resolution Result envelope to unlock the canivc did:key conformance suite (internal vectors 8 pass, 0 fail of 8, community suite unrun); then vendor EECC's Apache-2.0 vc-verifier-rules/webuild-attestations fixtures and implement BitstringStatusList status processing, with ECDSA/P-256 (via an extended HACL* closure, subject to the wasm gate) as a stretch track — all under no-hand-rolled-crypto and shim-stays-zero-semantic-logic (rule #11), tracked under epic #288.