urna validate
Reference for urna validate, which checks a .urna file's header, section checksums, manifest, footer hash, contract, embedding values and inlined blobs.
urna validate checks the integrity of a .urna file and prints its file_hash and content_hash. It stops at the first failure with a typed error. It needs no Python and no embedder.
Usage
urna validate <FILE>Arguments
| Argument | Description |
|---|---|
<FILE> | Path to the .urna file |
Options
| Option | Description |
|---|---|
-h, --help | Print help |
Behavior
validate reads the whole file into memory and runs, in order:
- The reader's parse and integrity check: file length, magic (
URNA, or the legacyNEST), version1.0, header checksum, file size, and for every section a legal encoding, 64-byte alignment, bounds and payload checksum; then the manifest parse and validation, the footer hash, header and manifest agreement, the six required sections, the embeddings size for the declareddtype, the size of every named space band, and thesearch_contractagainst the manifest. The full list is in what the reader checks on open. - A walk over the
embeddingssection for NaN and Inf. - A decode of the
search_contractsection. - When the file has inlined media (
blob_data,0x17): a SHA-256 of every inlined blob, compared with the hash recorded for it inblob_refs(0x14).
The checks it does not run:
- It does not decode the
hnsw_index,bm25_indexorgraph_adjacencypayloads, or the blob span overlay. Their checksums are verified, their contents are not. - It does not check named space bands for NaN or Inf.
A file with a well-formed checksum over a malformed index payload therefore passes validate and fails when a search opens it. To run the full open as well, follow validate with a command that opens the file for search, such as urna inspect --json.
The checksums are unkeyed. A passing validate proves the file is consistent with itself, not who built it. See Security.
Output
On success, to stdout:
OK: <file> is a valid .urna v1 file
Header checksum: valid
Section checksums: <n> sections OK
Footer hash: valid
Manifest: valid (contract enforced)
Required sections: all present
Embedding values: no NaN/Inf
Inlined blobs: <n> verified against blob_refs
File hash: sha256:<64 hex>
Content hash: sha256:<64 hex>The Inlined blobs line appears only when the file has a blob_data section. File hash is the SHA-256 of the whole file, the same value sha256sum prints. Content hash is the first half of every citation into the file (see Citations and hashes).
On failure, the first error goes to stderr as Error: <message>. For every check except the inlined-blob proof, nothing reaches stdout. The blob proof runs after the OK: line and the lines up to Embedding values are printed, so a blob failure leaves those lines on stdout: in scripts, test the exit code, not the OK: line. Section ids in these messages are decimal: section 2 is chunks_canonical (0x02).
| Error | Cause |
|---|---|
magic mismatch | Not a .urna file |
unsupported version | A format version this reader does not know |
invalid header checksum | The header was modified or damaged |
file size mismatch, file truncated | The file is shorter or longer than its header says |
section <id> checksum mismatch | A section payload was modified or damaged |
footer hash mismatch | Bytes changed that no section checksum covers, such as the manifest |
missing required section | One of the six canonical sections is absent |
NaN or Inf detected in embeddings | An embedding value is not finite |
inlined blob <i> (<uri>) fails its content_hash | Inlined media bytes do not match blob_refs |
blob_data has <n> entries but blob_refs has <m> records | The two media tables disagree |
The complete list is in Typed errors.
Exit codes
| Code | Meaning |
|---|---|
0 | Every check passed |
1 | A check failed, or the file is missing or unreadable |
2 | Usage error: a missing argument |
Examples
Validate the quickstart corpus:
urna validate examples/quickstart/out/quickstart.urnaOK: examples/quickstart/out/quickstart.urna is a valid .urna v1 file
Header checksum: valid
Section checksums: 9 sections OK
Footer hash: valid
Manifest: valid (contract enforced)
Required sections: all present
Embedding values: no NaN/Inf
File hash: sha256:e4d5f8907faad38c192dc6929e36dbf16db558410b2dae5abb4d65f10f508832
Content hash: sha256:1147b2560863331b21bd9d60fe6bdd99507dc34e17108444dc38194f8e6f09dfA copy with one bit flipped inside chunks_canonical:
Error: section 2 checksum mismatchA copy with one bit flipped inside the manifest, which only the footer hash covers:
Error: footer hash mismatchUse it in a script:
urna validate corpus.urna > /dev/null && echo "corpus ok"urna cite
Reference for urna cite, which resolves a urna://content_hash/chunk_id citation into the chunk's stored text and source span after checking the content_hash.
urna inspect
Reference for urna inspect, which prints a .urna file's header, section table with checksums, manifest and hashes, as text or as JSON with blobs and spaces.