Skip to content

Normative · Part

Status and decision gates

SSP/1’s maturity is stated on the specification’s status page: complete enough to implement, with its open gaps enumerated. This page states what closing those gaps requires, as gates a conformance case can cite.

The gates below are SSP/1’s own. They are not a subset of the SOP/1 gates, and neither series substitutes for the other: SOP/1’s gate G9 governs SOP/1’s promotion, so evidence filed against it is evidence about the object plane. SSP/1 depends on SOP/1 for nothing, and routing SSP/1’s evidence through a SOP/1 gate would invert that dependency in the one artifact a third party can execute — the published corpus.

Each gate is independently demonstrable and independently closeable. A gate that fails is information rather than a setback; what it must not be is unfalsifiable, which is why G2’s lesson — that a gate stated as the absence of a behaviour has no achievable evidence standard — is applied here too. GS8’s revocation-window conjunct is stated as a measurement for exactly that reason: section 40.3 defines no on-wire revocation record, and a window that exists is bounded rather than wished away.

The following gates MUST pass before SSP/1 becomes a normative production protocol. All eight are open. A conformance case cites the gate its evidence bears on; these identifiers are that traceability, and they are stable once published.

Which series a case cites follows what would be wrong if the case failed, not which corpus the case files under. Almost every case citing these gates is in ssp1-conformance-v1, but corpus membership is not the rule: a case elsewhere that demonstrates something SSP/1 states and SOP/1 does not have — the change event’s own canonical key ordering, event_id’s lowercase-hex derivation — cites these gates too. The converse is the more common direction. A case that reads at an SSP/1 anchor while demonstrating something both layers share, such as the one deterministic encoding or the one hash, is evidence about the substrate and cites SOP/1’s series instead; so does a case pinning a registry literal, whatever the literal is for, since the registry is one namespace both layers draw from.

GS1 conformance corpus, independently generated
(a) a published ssp1-conformance-v1 corpus covering canonical CBOR
encodings, COSE change-event signatures over synthetic keys, HLC
sequences and materializer scenarios, produced by a generator that
imports no sovm crate
(b) two independent implementations agree over it
Section 39 names the empty corpus as the gap that blocks production.
(a) is the artifact; (b) is what the artifact is for.
GS2 change-event wire form and authentication
canonical deterministic CBOR -- key order independent of input order,
NaN and infinity refused rather than serialised, timestamp as ISO 8601
UTC text, decimal as text, binary as a native byte string, a tombstone
payload carrying null rather than an empty map; the SSP/1 COSE
profile's protected-header bytes and empty unprotected bucket; mesh_id
bound as external_aad; event_id equal to BLAKE3 over the exact
COSE_Sign1 bytes, with a tick yielding a distinct identifier
GS3 hybrid logical clock
a total order across nodes with no coordinator over a corpus of
concurrent and causally related events; monotonicity preserved across
process death and restart; a timestamp beyond the 300 000 ms skew
bound rejected and never clamped; the applied watermark never advanced
past a skew-rejected event
GS4 deterministic convergence
replicas fed the same event set in different orders and across
partitions materialise identical state; per-column last-writer-wins
resolves a row whose columns were last written by different events;
concurrent delete and re-insert converge identically on every replica;
a delete that loses existence still advances the tombstone clock;
resurrection rebuild consults only upserts beating that clock
GS5 backfill covering sets and rehydration
a widening backfill restores every clocked column of a row whose
columns were last written at different HLCs, not only the columns of
its latest event and not only the columns holding a non-null value --
a column an upsert explicitly nulled arrives with its clock, so a
late write below it loses on the receiver as it does on the sender;
the losing delete is delivered, so sender and
receiver tombstone clocks agree afterwards; a backfilled event is
byte-identical to the original and applies as a no-op on a receiver
that already holds it; resume_after_row_key never advances past a
partially pushed row; a node rehydrating after eviction regains the
same state
GS6 scope enforcement
the floor enforced on both sides -- a producer treats a local
violation as an error, a receiver drops and logs; a receiver cannot
widen its own feed, policy being sender-side; no matching policy row
denies; two incomparable maximal rows deny and log; a schema-level
wildcard is unrepresentable rather than merely refused; a forked
role-assignment chain resolves the subject's role layer as absent
GS7 the fail-closed inventory, executed
every row of section 35 demonstrated as a case that fails in the
stated way, including the one deliberate exception -- eviction, which
fails open and keeps the row -- and including the reject / hold / drop
distinction of section 38, since conflating them is the stated common
implementation error
GS8 identity, admission and the revocation window
site_id derived from the 33-byte compressed encoding only, any other
encoding rejected rather than converted; vouch quorum, validity and
future-dating bounds enforced; an identity conflict on an existing
site_id hard-failing rather than overwriting; a pairing signature
failure aborting with no downgrade; and the window of section 40.3 --
during which a peer may still accept events from a removed node --
measured on a representative deployment rather than asserted absent
Gate State Verdict
GS1 conformance corpus, independently generated open target
GS2 change-event wire form and authentication open target
GS3 hybrid logical clock open target
GS4 deterministic convergence open target
GS5 backfill covering sets and rehydration open target
GS6 scope enforcement open target
GS7 the fail-closed inventory, executed open target
GS8 identity, admission and the revocation window open target

GS1 is load-bearing for the rest: GS2 through GS8 are stated as things a corpus demonstrates, so the corpus is the instrument the other seven are read with. Its second half — agreement between two independent implementations — is the half no amount of corpus authoring can supply.