Normative
Terminology
This page is an index, not a definition. Every term below is defined in the section that owns it, and this page points there. A glossary that restated the definitions would be a second copy of each, free to drift from the first — exactly what the substrate’s define-once rule exists to prevent.
What this page does own is disambiguation: five words appear in both layers with different meanings, and no single part can settle that, because each part is right within itself.
Shared vocabulary
Section titled “Shared vocabulary”Defined once in SSP/1 terminology and used unchanged by every part.
| Term | In one clause | Defined in |
|---|---|---|
| mesh | The set of nodes under one trust authority that replicate to each other | SSP/1 terminology |
| node | One member of a mesh | SSP/1 terminology |
| trust authority | Whoever holds the mesh’s root of trust and decides admission | SSP/1 terminology |
site_id |
A node’s stable identifier, the first 16 bytes of BLAKE3(IK_pub) |
SSP/1 terminology |
mesh_id |
The mesh identifier, derived from the founding node’s root key | SSP/1 terminology |
| HLC | A hybrid logical clock timestamp: the pair (physical_ms, logical) |
SSP/1 data model |
| change event | The unit of replication | SSP/1 data model |
| mailbox | An asynchronous store-and-forward channel that moves opaque payloads without being able to read them | SSP/1 transport |
| blind replica | A node holding complete ciphertext it is cryptographically unable to decrypt | SOP/1 §16.3 |
Words that mean two things
Section titled “Words that mean two things”Each row is a word both layers use in good faith for different constructs. The specification does not rename either; it states which is which, and each part qualifies the word where the other’s sense is reachable.
tombstone
Section titled “tombstone”| Sense | What it is | Defined in |
|---|---|---|
| row tombstone | The sync layer’s deletion marker. A later, higher-HLC upsert legitimately resurrects the row |
SSP/1 semantics |
| permanent identity tombstone | The object plane’s deletion record. No later write may resurrect what it names | SOP/1 §14.2 |
The two share a word and nothing else. Unqualified, SSP/1 means the row tombstone and SOP/1 means the permanent identity tombstone; a cross-layer sentence qualifies it.
| Sense | What it is | Defined in |
|---|---|---|
| reserved token | An SSP/1 operation token with no specified message format, which an implementation MUST fail closed on | SSP/1 §18.2 |
| physical purge | A real, specified storage operation on the object plane | SOP/1 §19.5 |
Reserving the token in the sync layer is what keeps the two from being confused
on the wire: an implementation that meets purge there refuses rather than
guessing that the object plane’s operation was meant.
| Sense | What it is | Defined in |
|---|---|---|
| syncable scope | The bound on which tables may replicate to a node | SSP/1 scope |
| decryption scope | Which cryptographic domains a node holds keys for | SOP/1 §6.3 |
A node may hold a table in its syncable scope and be unable to read it, which is the blind-replica case and is deliberate. Scope is not placement, and neither is permission.
domain
Section titled “domain”| Sense | What it is | Defined in |
|---|---|---|
| cryptographic domain | An MLS group whose membership is the set of nodes authorized to decrypt it | SOP/1 §6.3 |
| domain-separation label | A string mixed into a hash or KDF so two derivations cannot collide | Registry |
generation
Section titled “generation”| Sense | What it is | Defined in |
|---|---|---|
| key generation | The monotonic counter on a domain KEK, advanced by a membership-security transition | SOP/1 §7 |
| record generation | The monotonic counter in a chained record, which orders an authority’s own statements | Chained records |
Both are monotonic counters and neither is a timestamp. A verifier compares generations for ordering and MUST NOT infer elapsed time from the difference.