Normative · Part
Status and decision gates
SSP/1’s maturity is stated on the specification’s status page: complete enough to implement, with its open gaps enumerated. This page states what closing those gaps requires, as gates a conformance case can cite.
The gates below are SSP/1’s own. They are not a subset of the SOP/1 gates, and neither series substitutes for the other: SOP/1’s gate G9 governs SOP/1’s promotion, so evidence filed against it is evidence about the object plane. SSP/1 depends on SOP/1 for nothing, and routing SSP/1’s evidence through a SOP/1 gate would invert that dependency in the one artifact a third party can execute — the published corpus.
Each gate is independently demonstrable and independently closeable. A gate that fails is information rather than a setback; what it must not be is unfalsifiable, which is why G2’s lesson — that a gate stated as the absence of a behaviour has no achievable evidence standard — is applied here too. GS8’s revocation-window conjunct is stated as a measurement for exactly that reason: section 40.3 defines no on-wire revocation record, and a window that exists is bounded rather than wished away.
56. Decision gates
Section titled “56. Decision gates”The following gates MUST pass before SSP/1 becomes a normative production protocol. All eight are open. A conformance case cites the gate its evidence bears on; these identifiers are that traceability, and they are stable once published.
Which series a case cites follows what would be wrong if the case failed, not
which corpus the case files under. Almost every case citing these gates is in
ssp1-conformance-v1, but corpus membership is not the rule: a case elsewhere
that demonstrates something SSP/1 states and SOP/1 does not have — the change
event’s own canonical key ordering, event_id’s lowercase-hex derivation —
cites these gates too. The converse is the more common direction. A case that
reads at an SSP/1 anchor while demonstrating something both layers share, such
as the one deterministic encoding or the one
hash, is evidence about the substrate and cites SOP/1’s
series instead; so does
a case pinning a registry literal, whatever the literal is for,
since the registry is one namespace both layers draw from.
GS1 conformance corpus, independently generated (a) a published ssp1-conformance-v1 corpus covering canonical CBOR encodings, COSE change-event signatures over synthetic keys, HLC sequences and materializer scenarios, produced by a generator that imports no sovm crate (b) two independent implementations agree over it Section 39 names the empty corpus as the gap that blocks production. (a) is the artifact; (b) is what the artifact is for.
GS2 change-event wire form and authentication canonical deterministic CBOR -- key order independent of input order, NaN and infinity refused rather than serialised, timestamp as ISO 8601 UTC text, decimal as text, binary as a native byte string, a tombstone payload carrying null rather than an empty map; the SSP/1 COSE profile's protected-header bytes and empty unprotected bucket; mesh_id bound as external_aad; event_id equal to BLAKE3 over the exact COSE_Sign1 bytes, with a tick yielding a distinct identifier
GS3 hybrid logical clock a total order across nodes with no coordinator over a corpus of concurrent and causally related events; monotonicity preserved across process death and restart; a timestamp beyond the 300 000 ms skew bound rejected and never clamped; the applied watermark never advanced past a skew-rejected event
GS4 deterministic convergence replicas fed the same event set in different orders and across partitions materialise identical state; per-column last-writer-wins resolves a row whose columns were last written by different events; concurrent delete and re-insert converge identically on every replica; a delete that loses existence still advances the tombstone clock; resurrection rebuild consults only upserts beating that clock
GS5 backfill covering sets and rehydration a widening backfill restores every clocked column of a row whose columns were last written at different HLCs, not only the columns of its latest event and not only the columns holding a non-null value -- a column an upsert explicitly nulled arrives with its clock, so a late write below it loses on the receiver as it does on the sender; the losing delete is delivered, so sender and receiver tombstone clocks agree afterwards; a backfilled event is byte-identical to the original and applies as a no-op on a receiver that already holds it; resume_after_row_key never advances past a partially pushed row; a node rehydrating after eviction regains the same state
GS6 scope enforcement the floor enforced on both sides -- a producer treats a local violation as an error, a receiver drops and logs; a receiver cannot widen its own feed, policy being sender-side; no matching policy row denies; two incomparable maximal rows deny and log; a schema-level wildcard is unrepresentable rather than merely refused; a forked role-assignment chain resolves the subject's role layer as absent
GS7 the fail-closed inventory, executed every row of section 35 demonstrated as a case that fails in the stated way, including the one deliberate exception -- eviction, which fails open and keeps the row -- and including the reject / hold / drop distinction of section 38, since conflating them is the stated common implementation error
GS8 identity, admission and the revocation window site_id derived from the 33-byte compressed encoding only, any other encoding rejected rather than converted; vouch quorum, validity and future-dating bounds enforced; an identity conflict on an existing site_id hard-failing rather than overwriting; a pairing signature failure aborting with no downgrade; and the window of section 40.3 -- during which a peer may still accept events from a removed node -- measured on a representative deployment rather than asserted absent| Gate | State | Verdict |
|---|---|---|
| GS1 conformance corpus, independently generated | open | target |
| GS2 change-event wire form and authentication | open | target |
| GS3 hybrid logical clock | open | target |
| GS4 deterministic convergence | open | target |
| GS5 backfill covering sets and rehydration | open | target |
| GS6 scope enforcement | open | target |
| GS7 the fail-closed inventory, executed | open | target |
| GS8 identity, admission and the revocation window | open | target |
GS1 is load-bearing for the rest: GS2 through GS8 are stated as things a corpus demonstrates, so the corpus is the instrument the other seven are read with. Its second half — agreement between two independent implementations — is the half no amount of corpus authoring can supply.