Skip to content

Normative · Part

The shared substrate

Both layers of SOVM/1 are built from the same five mechanisms, and this part is their one normative home: a mechanism stated once cannot drift into two, where a share of it restated per layer can.

What is defined here is defined once: a layer page that needs one of these mechanisms references this part and states only its own instantiation choices — which records it signs, what context it binds, where padding applies. A layer page MUST NOT restate a rule defined here, and where a layer page appears to state a substrate rule, this part governs.

The requirement keywords and the encoding rules are the specification’s conventions. Vocabulary shared with the layers is terminology. This part restates neither.

Mechanism Where
The signature container and its one suite Signature profile
The hash convention Section 1 below
The context principle Section 2 below
The chained-record schema Chained records
The padding function Padding

SOVM/1’s single hash is BLAKE3, applied to the exact bytes of a signed or stored structure — never to a re-encoding, a parsed value, or a normalised form.

Every content-derived identifier in SOVM/1 is this construction: event_id over exact COSE_Sign1 bytes as received, object_manifest_hash, the links of the authorization chain, previous_receipt_hash in the sequencing-receipt chain, and storage_id, which is additionally pinned to the iroh-blobs BLAKE3 hash of the exact encrypted object bytes.

Neither layer maintains a second hash namespace, and an implementation MUST NOT introduce one. Where two byte strings differ, their identifiers differ; whether two differing byte strings may denote the same logical value is a question the signature profile’s canonicity clauses exist to close.

external_aad carries what the verifier must supply rather than trust.

A record is signed over context the receiving side provides from its own state — at minimum the verifier’s own 16-byte mesh_id, and in the object plane richer per-record context: storage identity, domain, key generation. The context is never transmitted with the record. A record replayed outside its context therefore fails signature verification, not a policy check layered above it.

Each layer states, per record type, exactly what its external_aad contains. What no layer may do is bind nothing, or bind a value the sender supplied.

This part defines mechanisms, not meaning. Which records exist, what they authorise, when they are emitted and how they converge is the business of the layer parts. An implementation cannot conform to the substrate alone; the substrate is the floor under every conformance module: none of it may become optional.