Verify Downloads#

Check the release checksum and signature before installing an Altifigence artifact.

Overview#

Download Digital Design Studio and Altifigence CLI from the official downloads page, without website sign-in. Verify the exact file before installing it or running any extracted program. Account services, AI, Cloud compute, and paid features still require their own authentication and permissions.

As of 24 September 2026, the public Linux downloads are Digital Design Studio 1.0.30 and CLI 0.1.9. The desktop filename retains systemverilog-ide for package compatibility; the product is Digital Design Studio. ISA is part of that application and has no separate current installer.

Current Release Sources#

Product

Installer

Verification

Digital Design Studio · Debian / Ubuntu · x86_64

Linux download

SHA-256 · Ed25519 manifest · signed Debian package

Altifigence CLI · Linux · x86_64

Linux download

SHA-256 · Ed25519 archive and catalog

Digital Design Studio · Windows 11

Public signed installer not yet available

Use the official download page to check availability

Download links follow the approved release channel. A GitHub tag alone does not publish a file: release verification must pass before it is promoted to Cloudflare. Use a fresh directory per product and keep the artifact and matching trust files together. If a release changes between requests, retry the full set; never skip a failed check.

Verify a Desktop Release Manifest#

Run these commands in the directory containing the downloaded .deb, using Bash, OpenSSL 3, curl, xxd, GNU coreutils, and dpkg. The pinned Ed25519 key is ide-download-2026-08-v1; its raw public bytes are 0Km02/+3ttNrM7J6RZ7dTFIPa4TLTMrbrJ0OUOvgjsE=.

Bash
(
set -euo pipefail
DDS_TRUST=https://www.altifigence.com/downloads/digital-design-studio/trust
curl --fail --silent --show-error "$DDS_TRUST/SHA256SUMS" -o SHA256SUMS
curl --fail --silent --show-error "$DDS_TRUST/SHA256SUMS.sig" -o SHA256SUMS.sig

{ printf '302a300506032b6570032100' | xxd -r -p
  printf '0Km02/+3ttNrM7J6RZ7dTFIPa4TLTMrbrJ0OUOvgjsE=' | base64 -d
} | { echo "-----BEGIN PUBLIC KEY-----"; base64 -w64; echo "-----END PUBLIC KEY-----"; } > dds-download.pem
openssl pkeyutl -verify -pubin -inkey dds-download.pem \
  -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig

grep -E '^[0-9a-f]{64}  altifigence-systemverilog-ide_[0-9]+(\.[0-9]+)+_amd64\.deb$' \
  SHA256SUMS > PACKAGE.SHA256
test "$(wc -l < PACKAGE.SHA256)" -eq 1
PACKAGE=$(cut -d' ' -f3 PACKAGE.SHA256)
VERSION=${PACKAGE#altifigence-systemverilog-ide_}
VERSION=${VERSION%_amd64.deb}
dpkg --compare-versions "$VERSION" ge 1.0.30
sha256sum -c PACKAGE.SHA256
)

The signature must succeed, exactly one package must be selected, its version must be 1.0.30 or newer, and its checksum must report OK. A checksum alone does not authenticate a publisher. The legacy filename is expected; do not rename the signed package.

Verify the Embedded Desktop Package Signature#

After the manifest check succeeds, use debsig-verify and GnuPG to check the package signature against the published policy and keyring. Install missing verification tools through your distribution. The command below uses a separate policy directory instead of changing the system trust directories. Package-signing fingerprint: 1AD14D70B6EB0DDE1119E705F44BC2496665A843.

Bash
(
set -euo pipefail
DDS_TRUST=https://www.altifigence.com/downloads/digital-design-studio/trust
for FILE in altifigence-desktop.pol altifigence-desktop.gpg altifigence-desktop-packages.asc; do
  curl --fail --silent --show-error "$DDS_TRUST/$FILE" -o "$FILE"
done
grep -E '^[0-9a-f]{64}  altifigence-desktop\.(pol|gpg)$' SHA256SUMS > TRUST.SHA256
test "$(wc -l < TRUST.SHA256)" -eq 2
sha256sum -c TRUST.SHA256

FPR=1AD14D70B6EB0DDE1119E705F44BC2496665A843
for KEY in altifigence-desktop.gpg altifigence-desktop-packages.asc; do
  ACTUAL_FPR=$(gpg --batch --show-keys --with-colons "$KEY" \
    | awk -F: '$1 == "fpr" { print $10; exit }')
  test "$ACTUAL_FPR" = "$FPR"
done

VERIFY_DIR=$(mktemp -d)
mkdir -p "$VERIFY_DIR/keyrings/$FPR" "$VERIFY_DIR/policies/$FPR"
cp altifigence-desktop.gpg "$VERIFY_DIR/keyrings/$FPR/"
cp altifigence-desktop.pol "$VERIFY_DIR/policies/$FPR/"
PACKAGE=$(cut -d' ' -f3 PACKAGE.SHA256)
debsig-verify --policies-dir "$VERIFY_DIR/policies" \
  --keyrings-dir "$VERIFY_DIR/keyrings" "$PACKAGE"
)

Only exit status 0 is success. Missing signatures, missing policies, a different fingerprint, or a rejected signature mean stop. Do not disable signature checks or add an unknown certificate. Some distributions integrate debsig-verify into package installation; check your distribution policy before enabling system-wide enforcement.

Verify the CLI Archive#

CLI 0.1.9 uses Ed25519 signatures and a version 2 DDS release catalog. It does not use the older RSA key or the altifigence-cli-v... filename. Check the pinned public-key DER SHA-256 before trusting any downloaded material, including the installer.

Bash
(
set -euo pipefail
CLI_VERSION=0.1.9
CLI_ARCHIVE="altifigence-cli-$CLI_VERSION-x86_64-unknown-linux-gnu.tar.gz"
CLI_TRUST=https://www.altifigence.com/downloads/cli/trust
EXPECTED_KEY=db9e725f448279fd97d3c6ed7a717b91b87cc66455ae03586d1756a16dee0844
test -f "$CLI_ARCHIVE"
for FILE in CLI-RELEASE-PUBLIC-KEY.pem SHA256SUMS SHA256SUMS.sig \
  RELEASE-CATALOG.json RELEASE-CATALOG.json.sig "$CLI_ARCHIVE.sig"; do
  curl --fail --silent --show-error --proto '=https' "$CLI_TRUST/$FILE" -o "$FILE"
done
ACTUAL_KEY=$(openssl pkey -pubin -in CLI-RELEASE-PUBLIC-KEY.pem \
  -outform DER | sha256sum | cut -d' ' -f1)
test "$ACTUAL_KEY" = "$EXPECTED_KEY"
openssl pkeyutl -verify -pubin -inkey CLI-RELEASE-PUBLIC-KEY.pem \
  -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
awk -v name="$CLI_ARCHIVE" \
  'NF == 2 && $2 == name && length($1) == 64 && $1 !~ /[^0-9a-f]/ {print; n++}
   END {if (n != 1) exit 1}' SHA256SUMS > CLI-ARCHIVE.SHA256
sha256sum -c CLI-ARCHIVE.SHA256
openssl pkeyutl -verify -pubin -inkey CLI-RELEASE-PUBLIC-KEY.pem \
  -rawin -in "$CLI_ARCHIVE" -sigfile "$CLI_ARCHIVE.sig"
openssl pkeyutl -verify -pubin -inkey CLI-RELEASE-PUBLIC-KEY.pem \
  -rawin -in RELEASE-CATALOG.json -sigfile RELEASE-CATALOG.json.sig
jq -e --arg version "$CLI_VERSION" \
  '.schemaVersion == 2 and .releaseOwner == "altifigence-internal/digital-design-studio"
   and .package.version == $version and .package.target == "x86_64-unknown-linux-gnu"
   and .signature.algorithm == "Ed25519"' RELEASE-CATALOG.json
)

The key digest, archive checksum, all three signatures, and catalog identity checks must succeed before extraction or execution. Keep the verified catalog, signature, and public key beside the archive; Install on Linux uses them to verify every payload file before installation.

When Verification Fails#

Do not install or run the file. Download a fresh artifact and matching trust files from the official HTTPS links, in a new directory. If the failure repeats, send the filename, version, calculated SHA-256, and exact failing command to contact@altifigence.com. Never attach credentials, cookies, access tokens, private keys, or project source.

An unavailable Windows channel is not an invitation to use a development .LOCAL package or bypass Windows security. Wait for a publicly signed release. Verified downloads do not grant account services or paid entitlements.