Specification
- Revision 6.0
- file format 6
- Whole specification on one page
verify checks a pack and returns a report with the keys sha256_ok, header_footer_agree, record_count{declared, actual}, appendix{present, file_checksum_ok, sections[{index, type, crc_ok}]}, embrefs{total, resolved, dangling, type_mismatch}. Opening a pack runs steps 1 to 8 by default; the caller may opt out explicitly.
Input: the bytes of a .plxi file. If they start with 1F 8B (gzip ID1, ID2 [RFC1952]), a reader MAY decompress them and continue with the result; .plxi.gz is a transport encoding only (§11).
- Size.
L >= 353, elseinvalid_header. - Header. Bytes 0..257 are ASCII, byte 256 is LF, and bytes 0..256 match
header-content padding(§3.1): elseinvalid_header. A version other than 6:unsupported_version. - Footer. Bytes
L-96 .. Lper the §10.0 table: magicPLXF, elseinvalid_footer; version 6, elseunsupported_version; reserved bytes 44..64 all zero, elseinvalid_footer. - Header against footer. Classify the header (§3.3). Final:
records,csdt_offset,csdt_size, digest equal the footer's, elseheader_footer_mismatch. Placeholder: continue with the footer's values. Neither:header_footer_mismatch. - Layout. With
T = text_section_size,A = csdt_offset,C = csdt_size, all integers from the footer, compared without overflow:257 <= T <= L - 96, elseinvalid_footer;C = 0:A = 0andT = L - 96, elseinvalid_footer;C > 0:A mod 64 = 0, elseappendix_alignment;A = Trounded up to a multiple of 64 andA + C = L - 96, elseinvalid_footer; the padding bytesT .. Aare all0x00, elseinvalid_footer.- The checks above are made in 64-bit arithmetic, before any conversion to an in-memory index, so a layout that fails them is
invalid_footeron every platform. Only a layout that passes them and still holds an offset or size that cannot be represented as an in-memory index on the platform (for example at or above 2^32 on a 32-bit target) fails, withlimit_exceeded; it MUST NOT be truncated.
- Digest. SHA-256 of bytes
257 .. L-96equals footer bytes 64..96, elsechecksum_mismatch. - Body. Bytes
257 .. Tare valid UTF-8, elseinvalid_utf8. WhenC > 0, the last line is the marker line, elseinvalid_record. Every other non-empty line parses as a record (§4), elsejsonorinvalid_record. A marker line elsewhere:invalid_record. - Count. The number of record lines equals the footer's
record_count, elserecord_count_mismatch. - Appendix (Reader-Appendix, only when
C > 0): open the container at bytesA .. A+Cwith the checks of §7.3; check every section's CRC32C; compare the footer'scsdt_file_checksumwith the container'sfile_checksum. - Bindings (Reader-Appendix): for each
localtarget (§5.4),section_indexis below the section count andrecord_indexis below that section'srecord_count; for eachexttarget, acsdt_refrecord with thatref_idexists in the pack. Each failure counts as dangling. Verify reports counts; a consumer that binds a dangling target fails withdangling_embref.- Type check under the Compact embedding profile (the entity-embedding binding that importers use): a
localtarget of anembrefis expected to name a section of typeCompact(0x0020) whoserecord_strideequals the Compact record size (320 bytes), with dtypeRECORD. Verify counts mismatches intype_mismatch; a consumer that binds one fails withsection_type_mismatch. The profile belongs to the consumer, not to the file format: other kinds of section are legalembreftargets.
- Type check under the Compact embedding profile (the entity-embedding binding that importers use): a
- 1Sizeinvalid_header
- 2Headerinvalid_headerunsupported_version
- 3Footerinvalid_footerunsupported_version
- 4Header against footerheader_footer_mismatch
- 5Layoutinvalid_footerappendix_alignmentlimit_exceeded
- 6Digestchecksum_mismatch
- 7Bodyinvalid_utf8invalid_recordjson
- 8Countrecord_count_mismatch
- 9Appendixappendix_invalidappendix_crc_mismatchonly when the pack has an appendix
- 10Bindingsdangling_embrefsection_type_mismatchcounts only; a consumer that binds a failing target reports
dangling_embreforsection_type_mismatch
Steps run in this order. A verifier that stops at the first failure MUST report the kind of that first failure, so every conforming implementation reports the same kind for the same file. Reports for steps it did not reach are absent.
© 2020-2026 Cintile Inc. All Rights Reserved.
Anyone may implement this format. Copying or republishing the text of this specification requires permission from Cintile Inc.