{
  "$schema": "./manifest.schema.json",
  "schema_version": 1,
  "corpora": {
    "sop1-conformance-v1": {
      "layer": "sop",
      "spec_baseline": "SOP/1 initial specification",
      "spec_commit": "484f24792be396a211ae1f38a0d6c48626f8ce13",
      "generator": "generate.py",
      "vectors": [
        {
          "file": "sop/registry.json",
          "description": "Wire-visible family-registry literals pinned as exact UTF-8 bytes.",
          "cases": [
            {
              "id": "content_type.sovm_ssp_event_v1",
              "anchor": "/ssp/data-model/#7-the-change-event",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-event-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_vouch_v1",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-vouch-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_role_v1",
              "anchor": "/ssp/scope/#153-role-assignment-records",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-role-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_custodian_v1",
              "anchor": "/ssp/scope/#154-custodian-designation-records",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-custodian-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_capability_v1",
              "anchor": "/ssp/scope/#155-capability-requirement-records",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-capability-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_modules_v1",
              "anchor": "/ssp/scope/#156-per-node-module-set-records",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-modules-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_binding_v1",
              "anchor": "/ssp/transport/#28-default-binding-profile",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-binding-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_eventkey_v1",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-eventkey-v1"
              ]
            },
            {
              "id": "content_type.sovm_ssp_succession_v1",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/ssp-succession-v1"
              ]
            },
            {
              "id": "content_type.sovm_sop_access_v1",
              "anchor": "/sop/domains/#75-cose-accessrecord-and-wrapped-dek",
              "module": "SOVM-OBJ",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/sop-access-v1"
              ]
            },
            {
              "id": "content_type.sovm_sop_recovery_root_v1",
              "anchor": "/sop/objects/#127-catalog-checkpoints-and-recoveryroot",
              "module": "SOVM-OBJ",
              "gates": [
                "G9",
                "G10"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/sop-recovery-root-v1"
              ]
            },
            {
              "id": "content_type.sovm_sop_authorization_v1",
              "anchor": "/sop/identity/#57-membership-authorization-artifacts",
              "module": "SOVM-OBJ",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/sop-authorization-v1"
              ]
            },
            {
              "id": "label.sovm_mesh_id_v1",
              "anchor": "/ssp/#terminology",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm-mesh-id-v1"
              ]
            },
            {
              "id": "label.sovm_mesh_pair_v1",
              "anchor": "/ssp/identity/#201-key-agreement",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm-mesh-pair-v1"
              ]
            },
            {
              "id": "label.sovm_mls_credential_binding_v1",
              "anchor": "/sop/identity/#53-mls-credential-binding",
              "module": "SOVM-OBJ",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm-mls-credential-binding-v1"
              ]
            },
            {
              "id": "hkdf_info.pair_session",
              "anchor": "/ssp/identity/#201-key-agreement",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "pair-session"
              ]
            },
            {
              "id": "hkdf_info.pair_sas",
              "anchor": "/ssp/identity/#202-out-of-band-authentication",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "pair-sas"
              ]
            },
            {
              "id": "object_format.sop_pme_1",
              "anchor": "/sop/parquet/#112-initial-profile-sop-pme-1",
              "module": "SOVM-OBJ",
              "gates": [
                "G5"
              ],
              "tier": "conformance",
              "registry_literals": [
                "SOP-PME-1"
              ]
            },
            {
              "id": "metadata_key.sovm_sop_pad_v1",
              "anchor": "/sop/parquet/#118-padmé-object-size-padding",
              "module": "SOVM-OBJ",
              "gates": [
                "G5"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm:sop-pad-v1"
              ]
            },
            {
              "id": "object_format.sop_blob_1",
              "anchor": "/sop-blob/format/#6-construction",
              "module": "SOVM-BLOB",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "SOP-BLOB-1"
              ]
            },
            {
              "id": "object_kind.blob",
              "anchor": "/sop-blob/manifest/#10-the-blob-field-set",
              "module": "SOVM-BLOB",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "blob"
              ]
            },
            {
              "id": "alpn.sovm_0",
              "anchor": "/bindings/iroh/#2-alpn",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "sovm/0"
              ]
            },
            {
              "id": "error_code.protocol_violation",
              "anchor": "/bindings/iroh/#9-error-codes",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "PROTOCOL_VIOLATION"
              ]
            },
            {
              "id": "error_code.trust_failed",
              "anchor": "/bindings/iroh/#9-error-codes",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "TRUST_FAILED"
              ]
            },
            {
              "id": "error_code.frame_too_large",
              "anchor": "/bindings/iroh/#9-error-codes",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "FRAME_TOO_LARGE"
              ]
            },
            {
              "id": "error_code.unsupported_binding_version",
              "anchor": "/bindings/iroh/#9-error-codes",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "registry_literals": [
                "UNSUPPORTED_BINDING_VERSION"
              ]
            }
          ]
        },
        {
          "file": "sop/deterministic-cbor.json",
          "description": "RFC 8949 section 4.2.1 core deterministic CBOR: shortest integers, integer/float type distinction, preferred floats, native byte strings, bytewise map-key ordering, and fail-closed rejection of NaN/infinity.",
          "cases": [
            {
              "id": "cbor.integer.shortest_form",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "shortest-form integers"
            },
            {
              "id": "cbor.integer_float_distinct",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "so `70` and `70.0` remain different canonical bytes."
            },
            {
              "id": "cbor.float.preferred_shortest",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "preferred float serialization"
            },
            {
              "id": "cbor.bytes.native_string",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "Binary values are native byte strings — no base64 layer"
            },
            {
              "id": "cbor.map.bytewise_key_order",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "bytewise lexicographic map-key ordering"
            },
            {
              "id": "cbor.map.change_event_key_order",
              "anchor": "/ssp/data-model/#7-the-change-event",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "bytewise lexicographic map-key ordering"
            },
            {
              "id": "cbor.reject.nan_and_infinity",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "NaN and the infinities MUST NOT appear"
            }
          ]
        },
        {
          "file": "sop/blake3-identifier.json",
          "description": "BLAKE3-over-exact-bytes identifier derivation: known-answer tests plus the lowercase-hex event_id / identifier derivation shape.",
          "cases": [
            {
              "id": "blake3.kat.empty",
              "anchor": "/ssp/data-model/#9-event-identity",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance"
            },
            {
              "id": "blake3.kat.range_0_31",
              "anchor": "/ssp/data-model/#9-event-identity",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance"
            },
            {
              "id": "event_id.lowercase_hex_of_exact_bytes",
              "anchor": "/ssp/data-model/#9-event-identity",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "property",
              "normative_quote": "event_id = lowercase hex BLAKE3 (32-byte output) of the"
            },
            {
              "id": "identifier.blake3_over_exact_signed_bytes",
              "anchor": "/registry/#shared-conventions",
              "module": "SOVM-BASE",
              "gates": [
                "G9"
              ],
              "tier": "property",
              "normative_quote": "An identifier is BLAKE3 over the exact bytes of a signed or"
            }
          ]
        },
        {
          "file": "sovm/frame.json",
          "description": "SOVM-IROH frame discipline: 4-byte big-endian length prefix over deterministic CBOR, Padme bucket padding with the prefix stating the padded length, trailing bytes after the CBOR item ignored, and fail-closed rejection of a prefix beyond the declared bound.",
          "cases": [
            {
              "id": "iroh_frame.unpadded.prefix_is_exact_body_length",
              "anchor": "/bindings/iroh/#4-streams-and-framing",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "4-byte big-endian unsigned length prefix"
            },
            {
              "id": "iroh_frame.padme.padded_to_next_bucket",
              "anchor": "/bindings/iroh/#4-streams-and-framing",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "padded to a Padmé bucket"
            },
            {
              "id": "iroh_frame.padme.multibyte_pad_prefix_states_padded_length",
              "anchor": "/bindings/iroh/#4-streams-and-framing",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "the length prefix states the"
            },
            {
              "id": "iroh_frame.trailing_bytes_after_item_ignored",
              "anchor": "/bindings/iroh/#4-streams-and-framing",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "MUST ignore bytes after the CBOR item"
            },
            {
              "id": "iroh_frame.reject.prefix_exceeds_bound",
              "anchor": "/bindings/iroh/#4-streams-and-framing",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "a transport error, not a malformed body"
            }
          ]
        },
        {
          "file": "sovm/transport-binding.json",
          "description": "The sovm/ssp-binding-v1 transport binding record: a deterministic ES256 COSE_Sign1 over {channel_pub, generation} with kid = site_id and external_aad = mesh_id, plus the rejections the signature profile mandates (high-S, DER, uncompressed key, tampered payload) and generation supersession.",
          "cases": [
            {
              "id": "iroh_binding.valid_record_resolves_site_id",
              "anchor": "/bindings/iroh/#3-connection-and-identity",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "first frame on the first stream it opens"
            },
            {
              "id": "iroh_binding.reject.high_s_signature",
              "anchor": "/bindings/iroh/#3-connection-and-identity",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "absent or invalid binding record"
            },
            {
              "id": "iroh_binding.reject.der_signature",
              "anchor": "/bindings/iroh/#3-connection-and-identity",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "absent or invalid binding record"
            },
            {
              "id": "iroh_binding.reject.uncompressed_root_key",
              "anchor": "/bindings/iroh/#3-connection-and-identity",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "absent or invalid binding record"
            },
            {
              "id": "iroh_binding.reject.tampered_payload",
              "anchor": "/bindings/iroh/#3-connection-and-identity",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "absent or invalid binding record"
            },
            {
              "id": "iroh_binding.superseded.lower_generation",
              "anchor": "/bindings/iroh/#3-connection-and-identity",
              "module": "SOVM-IROH",
              "gates": [
                "G9"
              ],
              "tier": "negative"
            }
          ]
        },
        {
          "file": "sovm/ssp-vouch.json",
          "description": "The sovm/ssp-vouch-v1 vouch certificate of SSP/1 section 21: a deterministic ES256 COSE_Sign1 over {subject_ik_pub, subject_site_id, issued_at_s} with kid = the voucher's site_id and external_aad = mesh_id, and the refusals that make section 21.2's five-step order observable -- records bad in two steps at once, pinned to the step that speaks first, plus the subject_site_id mismatch a conforming encoder cannot mint because it derives the field.",
          "cases": [
            {
              "id": "ssp_vouch.valid_record_verifies_under_the_voucher_key",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "The voucher's identity travels in the protected `kid`"
            },
            {
              "id": "ssp_vouch.valid_at_the_last_second_of_the_window",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "Validity is 86 400 s from `issued_at_s`, with 300 s future-dating tolerance."
            },
            {
              "id": "ssp_vouch.valid_at_the_future_dating_tolerance",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "Validity is 86 400 s from `issued_at_s`, with 300 s future-dating tolerance."
            },
            {
              "id": "ssp_vouch.reject.subject_site_id_mismatch",
              "anchor": "/ssp/identity/#212-verification-order",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "`subject_site_id` binds to `subject_ik_pub`"
            },
            {
              "id": "ssp_vouch.reject.mismatch_outranks_untrusted_voucher",
              "anchor": "/ssp/identity/#212-verification-order",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "The order is normative because each step narrows what the next one has to consider"
            },
            {
              "id": "ssp_vouch.reject.uncompressed_subject_key_prefix",
              "anchor": "/ssp/identity/#191-suite-and-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "reject an uncompressed or hybrid encoding of a node root public key"
            },
            {
              "id": "ssp_vouch.reject.uncompressed_subject_key_full_point",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "payload fields present and correctly sized"
            },
            {
              "id": "ssp_vouch.reject.untrusted_voucher_outranks_signature",
              "anchor": "/ssp/identity/#212-verification-order",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "trusted **for exactly the key the keyring holds**"
            },
            {
              "id": "ssp_vouch.reject.expiry_outranks_signature",
              "anchor": "/ssp/identity/#212-verification-order",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "the validity window, including future-dating tolerance"
            },
            {
              "id": "ssp_vouch.reject.expired_at_the_window_boundary",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "Validity is 86 400 s from `issued_at_s`, with 300 s future-dating tolerance."
            },
            {
              "id": "ssp_vouch.reject.beyond_the_future_dating_tolerance",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "Validity is 86 400 s from `issued_at_s`, with 300 s future-dating tolerance."
            },
            {
              "id": "ssp_vouch.reject.high_s_signature",
              "anchor": "/ssp/identity/#212-verification-order",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "the COSE signature, with `external_aad` set to the local `mesh_id`"
            },
            {
              "id": "ssp_vouch.reject.der_signature",
              "anchor": "/ssp/identity/#211-vouch-certificate",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "the record decodes under the COSE profile"
            },
            {
              "id": "ssp_vouch.reject.wrong_mesh_id",
              "anchor": "/ssp/identity/#212-verification-order",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "a vouch from another mesh fails step 5"
            }
          ]
        }
      ]
    },
    "ssp1-conformance-v1": {
      "layer": "ssp",
      "spec_baseline": "SSP/1 initial specification (unrevisioned)",
      "spec_commit": "484f24792be396a211ae1f38a0d6c48626f8ce13",
      "generator": "generate.py",
      "vectors": [
        {
          "file": "ssp/change-event.json",
          "description": "The SSP/1 change event as exact bytes: the seven-field payload map, the value conventions CBOR has no native type for, the COSE_Sign1 parts including the empty unprotected bucket and the mesh_id external_aad, and the NaN/infinity refusals.",
          "cases": [
            {
              "id": "ssp_event.payload.canonical_bytes",
              "anchor": "/ssp/data-model/#7-the-change-event",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "The payload is a deterministic CBOR map with exactly these fields:"
            },
            {
              "id": "ssp_event.payload.key_order_is_independent_of_input_order",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "bytewise lexicographic map-key ordering"
            },
            {
              "id": "ssp_event.payload.tombstone_carries_null_not_empty_map",
              "anchor": "/ssp/data-model/#7-the-change-event",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "Column values. Null for tombstones."
            },
            {
              "id": "ssp_value.timestamp_is_iso8601_utc_text",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "ISO-8601 text string, UTC"
            },
            {
              "id": "ssp_value.decimal_is_text_not_binary64",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "Text string, to avoid binary64 rounding"
            },
            {
              "id": "ssp_value.binary_is_a_native_byte_string",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "Binary values are native byte strings"
            },
            {
              "id": "ssp_event.reject.nan_in_a_column_value",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "serializer MUST fail closed rather than emit them."
            },
            {
              "id": "ssp_event.reject.infinity_in_a_column_value",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "NaN and the infinities MUST NOT appear"
            },
            {
              "id": "ssp_event.protected_header.canonical_bytes",
              "anchor": "/ssp/data-model/#7-the-change-event",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "kid` cannot be altered in flight"
            },
            {
              "id": "ssp_event.unprotected_bucket_is_the_empty_map",
              "anchor": "/ssp/data-model/#7-the-change-event",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "The unprotected bucket MUST be empty"
            },
            {
              "id": "ssp_event.sig_structure.binds_mesh_id_as_external_aad",
              "anchor": "/ssp/data-model/#10-event-authentication",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "`external_aad` set to the receiver's own 16-byte `mesh_id`"
            },
            {
              "id": "ssp_event.cose_sign1.exact_bytes",
              "anchor": "/ssp/data-model/#10-event-authentication",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "Verification is COSE_Sign1 verification with:"
            }
          ]
        },
        {
          "file": "ssp/event-identity.json",
          "description": "event_id as lowercase-hex BLAKE3 over the exact COSE_Sign1 bytes of a signed change event, and the distinct identifier a producer gets by ticking the HLC instead of re-signing.",
          "cases": [
            {
              "id": "ssp_event_id.blake3_of_exact_cose_bytes",
              "anchor": "/ssp/data-model/#9-event-identity",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "exact COSE_Sign1 bytes as received"
            },
            {
              "id": "ssp_event_id.a_tick_yields_a_distinct_identifier",
              "anchor": "/ssp/data-model/#9-event-identity",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "it MUST tick the HLC and sign a **new** event rather than re-sign the"
            }
          ]
        },
        {
          "file": "ssp/event-signing-subkey.json",
          "description": "The SSP/1 event-signing subkey: the section 10.1 record recomputed from its parts with the step that refuses each invalid one, the section 10.2 scope boundary a record signed under an event_pub violates, and section 10.3 selection over subkey chains -- consecutive, gapped and overlapping -- including the fail-closed cases where no generation covers the event's HLC and where more than one does.",
          "cases": [
            {
              "id": "ssp_eventkey.genesis_record_verifies_under_the_node_identity_key",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "a verifier MUST reject an `sovm/ssp-eventkey-v1` record whose signature"
            },
            {
              "id": "ssp_eventkey.successor_generation_carries_a_revocation_cutoff",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "`null` at `generation` 0."
            },
            {
              "id": "ssp_eventkey.generation_may_skip_ahead_of_its_predecessor",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "a successor need only exceed its predecessor rather than carry exactly one more"
            },
            {
              "id": "ssp_eventkey.reject.uncompressed_event_pub_is_not_converted",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "An uncompressed or hybrid encoding MUST be rejected rather than converted"
            },
            {
              "id": "ssp_eventkey.reject.der_signature_is_not_accepted",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "exactly one signature suite and it is ES256"
            },
            {
              "id": "ssp_eventkey.reject.event_pub_is_not_a_compressed_point",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "An uncompressed or hybrid encoding MUST be rejected rather than converted"
            },
            {
              "id": "ssp_eventkey.reject.not_after_equal_to_issuance",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "A verifier MUST reject a record whose `not_after` is not strictly greater than"
            },
            {
              "id": "ssp_eventkey.reject.prior_revoked_at_present_at_generation_zero",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "`null` at `generation` 0."
            },
            {
              "id": "ssp_eventkey.reject.prior_revoked_at_absent_above_generation_zero",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "`null` at `generation` 0."
            },
            {
              "id": "ssp_eventkey.reject.prior_revoked_at_past_the_predecessor_not_after",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "It MUST NOT be greater than the N−1 record's `not_after`."
            },
            {
              "id": "ssp_eventkey.reject.signed_by_an_identity_key_the_keyring_does_not_hold",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "a verifier MUST reject an `sovm/ssp-eventkey-v1` record whose signature"
            },
            {
              "id": "ssp_eventkey.reject.record_minted_for_another_mesh",
              "anchor": "/ssp/data-model/#101-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "a verifier MUST reject an `sovm/ssp-eventkey-v1` record whose signature"
            },
            {
              "id": "ssp_eventkey.reject.successor_subkey_signed_by_the_subkey",
              "anchor": "/ssp/data-model/#102-scope-boundary-of-the-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "an `sovm/ssp-eventkey-v1` record (no successor subkeys, no delegation chains)"
            },
            {
              "id": "ssp_eventkey.reject.scope_speaks_before_the_field_rules",
              "anchor": "/ssp/data-model/#102-scope-boundary-of-the-event-signing-subkey",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "A verifier MUST reject any record in that list whose signature verifies under an"
            },
            {
              "id": "ssp_eventkey.select.inside_the_genesis_window",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "A verifier MUST select exactly one candidate generation and MUST NOT iterate over"
            },
            {
              "id": "ssp_eventkey.select.at_the_revocation_cutoff_the_predecessor_still_covers",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "`issued_at(G) ≤ hlc ≤ min( not_after(G), prior_revoked_at(G+1) if a generation-G+1"
            },
            {
              "id": "ssp_eventkey.select.one_millisecond_past_the_cutoff_is_the_successor",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "`issued_at(G) ≤ hlc ≤ min( not_after(G), prior_revoked_at(G+1) if a generation-G+1"
            },
            {
              "id": "ssp_eventkey.select.inside_the_successor_window",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "A verifier MUST select exactly one candidate generation and MUST NOT iterate over"
            },
            {
              "id": "ssp_eventkey.select.a_gap_in_the_chain_does_not_shorten_the_predecessor",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "`issued_at(G) ≤ hlc ≤ min( not_after(G), prior_revoked_at(G+1) if a generation-G+1"
            },
            {
              "id": "ssp_eventkey.select.a_later_generation_covers_its_own_window",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "A verifier MUST select exactly one candidate generation and MUST NOT iterate over"
            },
            {
              "id": "ssp_eventkey.select.outside_an_overlap_the_chain_still_resolves",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "A verifier MUST select exactly one candidate generation and MUST NOT iterate over"
            },
            {
              "id": "ssp_eventkey.select.reject.before_the_chain_begins",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "Fail closed if no generation's window covers the HLC, if more than one does, or if"
            },
            {
              "id": "ssp_eventkey.select.reject.after_the_chain_ends",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "Fail closed if no generation's window covers the HLC, if more than one does, or if"
            },
            {
              "id": "ssp_eventkey.select.reject.inside_the_gap_between_generations",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "Fail closed if no generation's window covers the HLC, if more than one does, or if"
            },
            {
              "id": "ssp_eventkey.select.reject.two_generations_cover_the_hlc",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "Fail closed if no generation's window covers the HLC, if more than one does, or if"
            },
            {
              "id": "ssp_eventkey.select.reject.event_signed_under_a_generation_that_is_not_selected",
              "anchor": "/ssp/data-model/#103-subkey-validity-and-verification",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "negative",
              "normative_quote": "A verifier MUST select exactly one candidate generation and MUST NOT iterate over"
            }
          ]
        },
        {
          "file": "ssp/succession.json",
          "description": "The sovm/ssp-succession-v1 record of SSP/1 identity section 22.1: a deterministic ES256 COSE_Sign1 over {successor_ik_pub, successor_site_id, retired_at_hlc, issued_at_s} with kid = the predecessor's site_id and external_aad = mesh_id, and the refusals that make its five-step order observable -- records bad in two steps at once, the successor_site_id mismatch a conforming encoder cannot mint, and the three step-3 outcomes the fork rule needs: an untrusted predecessor, a re-delivery of the accepted record, and a fork.",
          "cases": [
            {
              "id": "ssp_succession.valid_record_verifies_under_the_predecessor_key",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "`kid` | The predecessor, because the predecessor signs"
            },
            {
              "id": "ssp_succession.valid_at_the_cutoff_skew_bound",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "`retired_at_hlc` does not exceed the verifier's own wall clock by more than"
            },
            {
              "id": "ssp_succession.valid_long_after_issue_because_the_record_has_no_expiry",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "conformance",
              "normative_quote": "the record has no expiry"
            },
            {
              "id": "ssp_succession.reject.successor_site_id_mismatch",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "`successor_site_id` re-derives from `successor_ik_pub`"
            },
            {
              "id": "ssp_succession.reject.mismatch_outranks_untrusted_predecessor",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "A verifier MUST check, in this order"
            },
            {
              "id": "ssp_succession.reject.uncompressed_successor_key_prefix",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "`successor_site_id` re-derives from `successor_ik_pub`"
            },
            {
              "id": "ssp_succession.reject.uncompressed_successor_key_full_point",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "payload fields present and correctly sized"
            },
            {
              "id": "ssp_succession.reject.untrusted_predecessor_outranks_signature",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "the protected `kid` resolves as a currently trusted peer"
            },
            {
              "id": "ssp_succession.reject.second_record_after_acceptance_is_a_fork",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "Two distinct succession records under one predecessor `kid` are a fork"
            },
            {
              "id": "ssp_succession.reject.fork_outranks_signature",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "A verifier MUST check, in this order"
            },
            {
              "id": "ssp_succession.reject.redelivery_of_the_accepted_record_is_not_a_fork",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "Two distinct succession records under one predecessor `kid` are a fork"
            },
            {
              "id": "ssp_succession.reject.cutoff_beyond_the_skew_bound",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "retiring node cannot pin its cutoff far ahead and grant itself a window"
            },
            {
              "id": "ssp_succession.reject.cutoff_bound_outranks_signature",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "A verifier MUST check, in this order"
            },
            {
              "id": "ssp_succession.reject.high_s_signature",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "the COSE signature, with `external_aad` set to the local `mesh_id`"
            },
            {
              "id": "ssp_succession.reject.der_signature",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "content type known, unprotected bucket empty"
            },
            {
              "id": "ssp_succession.reject.wrong_mesh_id",
              "anchor": "/ssp/identity/#221-retirement-by-succession",
              "module": "SOVM-SYNC",
              "gates": [
                "G9"
              ],
              "tier": "negative",
              "normative_quote": "the COSE signature, with `external_aad` set to the local `mesh_id`"
            }
          ]
        },
        {
          "file": "ssp/hybrid-logical-clock.json",
          "description": "Hybrid logical clock tick and observe sequences: counter behaviour when the wall clock advances, stands still and moves backward, the merge rule for each way the maximum can be held, the skew ceiling as a rejection that never clamps, and the canonical bytes of the resulting timestamp pair.",
          "cases": [
            {
              "id": "ssp_hlc.tick.wall_clock_ahead_resets_the_counter",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "if `now > last.physical_ms`, the new HLC is `(now, 0)`"
            },
            {
              "id": "ssp_hlc.tick.wall_clock_unchanged_increments_the_counter",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "otherwise it is `(last.physical_ms, last.logical + 1)`"
            },
            {
              "id": "ssp_hlc.tick.wall_clock_moves_backward_never_lowers_physical",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "never lowers `physical_ms`"
            },
            {
              "id": "ssp_hlc.tick.repeated_ticks_within_one_millisecond_stay_ordered",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "otherwise it is `(last.physical_ms, last.logical + 1)`"
            },
            {
              "id": "ssp_hlc.observe.remote_alone_holds_the_maximum",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "| `remote` only | `remote.logical + 1` |"
            },
            {
              "id": "ssp_hlc.observe.local_and_remote_share_the_maximum",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "| Both `last` and `remote` | `max(last.logical, remote.logical) + 1` |"
            },
            {
              "id": "ssp_hlc.observe.local_alone_holds_the_maximum",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "| `last` only | `last.logical + 1` |"
            },
            {
              "id": "ssp_hlc.observe.wall_clock_alone_holds_the_maximum",
              "anchor": "/ssp/data-model/#11-hybrid-logical-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "| `now` alone | `0` |"
            },
            {
              "id": "ssp_hlc.observe.at_the_skew_bound_is_accepted",
              "anchor": "/ssp/data-model/#111-clock-skew-bound",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "by more than **300 000 ms** (5 minutes)"
            },
            {
              "id": "ssp_hlc.observe.reject.beyond_the_skew_bound_is_not_clamped",
              "anchor": "/ssp/data-model/#111-clock-skew-bound",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "negative",
              "normative_quote": "Rejection is fail-closed and MUST be surfaced."
            },
            {
              "id": "ssp_hlc.observe.a_skew_rejection_is_not_terminal",
              "anchor": "/ssp/data-model/#111-clock-skew-bound",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "rejection is also not terminal: a receiver MUST NOT retain the event and MUST NOT"
            },
            {
              "id": "ssp_hlc.wire.timestamp_pair_canonical_bytes",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "bytewise lexicographic map-key ordering"
            },
            {
              "id": "ssp_hlc.wire.counter_at_the_shortest_form_boundary",
              "anchor": "/ssp/data-model/#8-canonical-encoding",
              "module": "SOVM-SYNC",
              "gates": [
                "GS2"
              ],
              "tier": "conformance",
              "normative_quote": "shortest-form integers"
            }
          ]
        },
        {
          "file": "ssp/limits.json",
          "description": "Every row of the /ssp/limits/ section 35 fail-closed inventory as an executable negative: the offending bytes are pinned, and the harness asserts the condition genuinely obtains, that the recomputed refusal matches the pinned reason, and that the pinned behaviour is still what the section says. The corpus and the section are checked for the same set of conditions, so a row added with no case reddens.",
          "cases": [
            {
              "id": "ssp.limits.fail_closed.invalid_event_signature",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Invalid event signature | Drop and surface — never hold, so a forger cannot stall the impersonated node's stream"
            },
            {
              "id": "ssp.limits.fail_closed.unknown_sender_kid",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Unknown sender `kid` | Drop and surface"
            },
            {
              "id": "ssp.limits.fail_closed.unknown_critical_cose_header_or_content_type",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Unknown critical COSE header or content type | Reject"
            },
            {
              "id": "ssp.limits.fail_closed.clock_skew_beyond_bound",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Clock skew beyond bound | Reject, never clamp"
            },
            {
              "id": "ssp.limits.fail_closed.watermark_advance_past_skew_rejected_event",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Watermark advance past a skew-rejected event | Never advance — the rejected HLC is above every honest one, so advancing would acknowledge the site's whole unapplied backlog"
            },
            {
              "id": "ssp.limits.fail_closed.hlc_high_water_mark_missing_or_unverified",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "No HLC high-water mark covering every event the node has released, or a mark that fails its integrity check | Refuse to stamp further events under that `site_id` — never resume from the wall clock. Surface the two as distinct conditions"
            },
            {
              "id": "ssp.limits.fail_closed.out_of_scope_event",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Out-of-scope event | Drop and log, never raise"
            },
            {
              "id": "ssp.limits.fail_closed.row_key_null_empty_or_unresolvable",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "`row_key` null, empty, or naming any column the destination lacks | Drop — never partially resolve a key, which would address every row sharing the surviving prefix"
            },
            {
              "id": "ssp.limits.fail_closed.no_matching_policy_row",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "No matching policy row | Deny"
            },
            {
              "id": "ssp.limits.fail_closed.incomparable_maximal_policy_rows",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Incomparable maximal policy rows | Deny and log, never guess open"
            },
            {
              "id": "ssp.limits.fail_closed.purge_requested",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Purge requested | Error, never downgrade to soft delete"
            },
            {
              "id": "ssp.limits.fail_closed.identity_conflict_on_existing_site_id",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Identity conflict on existing `site_id` | Hard fail, never overwrite"
            },
            {
              "id": "ssp.limits.fail_closed.pairing_signature_failure",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Pairing signature failure | Abort, no downgrade"
            },
            {
              "id": "ssp.limits.fail_closed.pairing_ceremony_deadline_exceeded",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Pairing ceremony deadline exceeded | Abort — never extend the deadline, and never resume the ceremony that ran past it"
            },
            {
              "id": "ssp.limits.fail_closed.node_below_required_key_protection",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Node below a policy-required `key_protection` level | Refuse, never admit at a lower level"
            },
            {
              "id": "ssp.limits.fail_closed.hardware_attested_without_evidence",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "`hardware_attested` claimed with absent, malformed, expired, revoked or mismatched evidence | Treat as `software` — never as `hardware_unattested`"
            },
            {
              "id": "ssp.limits.fail_closed.attestation_revocation_stale",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Attestation revocation data unobtainable or stale beyond the configured bound | Treat the attestation as unverified"
            },
            {
              "id": "ssp.limits.fail_closed.non_compressed_root_public_key",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Non-compressed encoding of a node root public key | Reject — never convert"
            },
            {
              "id": "ssp.limits.fail_closed.non_low_s_signature",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Non-low-S signature | Reject — never normalise"
            },
            {
              "id": "ssp.limits.fail_closed.der_or_non_64_byte_signature",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "DER-encoded or non-64-byte signature | Reject"
            },
            {
              "id": "ssp.limits.fail_closed.public_key_point_validation_failure",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Public key failing point validation | Reject before use"
            },
            {
              "id": "ssp.limits.fail_closed.verify_after_sign_check_fails",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Hardware signer's verify-after-sign check fails | Abort — never release the signature"
            },
            {
              "id": "ssp.limits.fail_closed.unregistered_conformance_module",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Conformance claim naming a module identifier the [registry](/registry/#conformance-module-identifiers) does not register | Reject the claim — never ignore the identifier and evaluate the rest"
            },
            {
              "id": "ssp.limits.fail_closed.realtime_advertised_without_capability",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "`supports_realtime: true` about to be advertised by an implementation that does not claim `SOVM-SYNC-RT`, or on a binding that cannot carry unsolicited one-way bodies | Advertise `false` — never advertise a capability not held"
            },
            {
              "id": "ssp.limits.fail_closed.unknown_ssp_version",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Unknown `ssp_version` | Refuse the exchange"
            },
            {
              "id": "ssp.limits.fail_closed.malformed_sync_body",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Malformed sync body | Reject"
            },
            {
              "id": "ssp.limits.fail_closed.unsolicited_push_without_mutual_realtime",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "Unsolicited push without mutual `supports_realtime` | Reject"
            },
            {
              "id": "ssp.limits.fail_closed.nan_or_infinity_in_canonical_cbor",
              "anchor": "/ssp/limits/#35-fail-closed-inventory",
              "module": "SOVM-SYNC",
              "gates": [
                "GS7"
              ],
              "tier": "negative",
              "normative_quote": "NaN or infinity in canonical CBOR | Refuse to serialize"
            }
          ]
        },
        {
          "file": "ssp/resolved-ambiguities.json",
          "description": "Receiver-side SSP/1 behaviour, one case per resolution from the pre-implementation spec review: the per-column covering set, the inclusive cursor bound, partial apply of unknown payload columns, the watermark a skew rejection pins, the restart tick from the persisted HLC mark, and the partial rebuild an eviction horizon truncates.",
          "cases": [
            {
              "id": "ssp_backfill.covering_set_is_per_column_not_the_latest_event",
              "anchor": "/ssp/scope/#16-widening-backfill",
              "module": "SOVM-SYNC",
              "gates": [
                "GS5"
              ],
              "tier": "conformance",
              "normative_quote": "Re-sending only the HLC 9 event backfills `b` and silently drops `a`."
            },
            {
              "id": "ssp_sync.selection_is_cursor_driven_and_inclusive",
              "anchor": "/ssp/messages/#32-sync-exchange",
              "module": "SOVM-SYNC",
              "gates": [
                "GS5"
              ],
              "tier": "conformance",
              "normative_quote": "`have_max_hlc` is advisory and MUST NOT be used as a selection lower bound."
            },
            {
              "id": "ssp_apply.unknown_payload_columns_are_applied_in_part",
              "anchor": "/ssp/semantics/#136-held-and-dropped-groups",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "The columns it does have are **applied**; the rest are **ignored** and their column clocks left untouched"
            },
            {
              "id": "ssp_apply.a_skew_rejection_pins_the_watermark_below_itself",
              "anchor": "/ssp/data-model/#111-clock-skew-bound",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "MUST NOT advance to or past the rejected event's HLC"
            },
            {
              "id": "ssp_hlc.restart_ticks_from_the_persisted_mark",
              "anchor": "/ssp/data-model/#112-clock-durability-across-restart",
              "module": "SOVM-SYNC",
              "gates": [
                "GS3"
              ],
              "tier": "conformance",
              "normative_quote": "from the wall clock alone is not permitted, and the case that breaks it is"
            },
            {
              "id": "ssp_eviction.a_rebuild_below_the_horizon_comes_back_partial",
              "anchor": "/ssp/semantics/#134-resurrection-rebuild",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "A receiver MUST NOT present a partial rebuild as a complete one."
            }
          ]
        },
        {
          "file": "ssp/apply-conditions.json",
          "description": "The /ssp/semantics/ section 13.6 apply conditions whose effect is a column clock or a key refusal: an upsert sharing no column with the destination still creates the row, an unmaterialized column is not a cleared one, a null or empty row_key is dropped without stalling the watermark, and a composite key that only partly resolves is dropped rather than matched on its surviving prefix.",
          "cases": [
            {
              "id": "ssp_apply.an_empty_payload_intersection_still_creates_the_row",
              "anchor": "/ssp/semantics/#136-held-and-dropped-groups",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "the row exists and its key columns are"
            },
            {
              "id": "ssp_apply.an_unmaterialized_column_is_not_a_cleared_one",
              "anchor": "/ssp/semantics/#136-held-and-dropped-groups",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "unmaterialized column to the application as a default, a zero, or a cleared value."
            },
            {
              "id": "ssp_apply.a_null_or_empty_row_key_is_dropped_and_surfaced",
              "anchor": "/ssp/semantics/#136-held-and-dropped-groups",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "no column clock, no existence bit and no tombstone clock can be located for"
            },
            {
              "id": "ssp_apply.a_partially_resolvable_composite_row_key_is_dropped",
              "anchor": "/ssp/semantics/#136-held-and-dropped-groups",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "turning one event into a mass update. Either the whole key resolves or the event"
            }
          ]
        },
        {
          "file": "ssp/materialization.json",
          "description": "The /ssp/semantics/ section 13 merge: an ordered sequence materialized column by column, a contested cell resolved on the HLC rather than on arrival order, an equal HLC broken by the site_id, a delete that a lower-HLC write arriving after it neither resurrects nor overwrites, and the whole event set converging to one row from every delivery order rather than only the written one.",
          "cases": [
            {
              "id": "ssp_materialize.an_ordered_sequence_builds_the_row_column_by_column",
              "anchor": "/ssp/semantics/#131-per-column-last-writer-wins-bounded-by-the-tombstone-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "Resolution is **per column**, not per row. Two nodes editing different columns of"
            },
            {
              "id": "ssp_materialize.the_higher_hlc_wins_a_contested_cell",
              "anchor": "/ssp/semantics/#131-per-column-last-writer-wins-bounded-by-the-tombstone-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "is written only if its event's HLC — including the `site_id` tiebreak — beats"
            },
            {
              "id": "ssp_materialize.an_equal_hlc_is_broken_by_the_site_id",
              "anchor": "/ssp/semantics/#131-per-column-last-writer-wins-bounded-by-the-tombstone-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "is written only if its event's HLC — including the `site_id` tiebreak — beats"
            },
            {
              "id": "ssp_materialize.a_late_earlier_update_neither_resurrects_the_row_nor_restores_the_column",
              "anchor": "/ssp/semantics/#133-the-tombstone-clock",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "A column write below the tombstone is rejected whether it arrives before the delete"
            },
            {
              "id": "ssp_materialize.every_delivery_order_converges_on_one_row",
              "anchor": "/ssp/semantics/#135-convergence",
              "module": "SOVM-SYNC",
              "gates": [
                "GS4"
              ],
              "tier": "conformance",
              "normative_quote": "arbitrary cross-peer interleaving, at-least-once duplication — converges to the same",
              "notes": "Checks every delivery order of the event set, not the two named ones -- the named orders carry the watermark traces, which are the part that legitimately differs. Section 13.5 asks implementations for property-based testing over randomized orders, which a frozen vector cannot be; exhaustive enumeration over a small set is what this corpus can offer, and it is a floor under that testing, not a substitute for it."
            }
          ]
        }
      ]
    }
  }
}
