# Suggested upstream change (NOT applied — shipped engine is verbatim) The attestation covers file digests, so verification should be OS-agnostic. Today `verify_attestation.py` exits 2 ("not a Surgeon package") on archives re-zipped by Windows Explorer / PowerShell Compress-Archive (backslash entry names) and by macOS Finder (`__MACOSX/` twins + `.DS_Store` break single-root detection). This Space repairs the container in its wrapper before invoking the engine, but local `python verify_attestation.py package.zip` still fails on such archives. Minimal engine-side fix (route through Michael): 1. normalize names once: `names = [n.replace("\\", "/") for n in z.namelist()]` and read via a map from normalized -> original name; 2. ignore archiver junk when detecting the wrapper root and when reading: any path whose first segment is `__MACOSX`, or whose leaf is `.DS_Store`, `Thumbs.db`, `desktop.ini`, or starts with `._`. Digest comparison logic unchanged; junk entries are never subjects.