Skip to content

docs(specs): make the profile version fix the protocol parameters - #65

Merged
xgreenx merged 1 commit into
mainfrom
specs/fixed-protocol-parameters
Oct 1, 2026
Merged

xgreenx merged 1 commit into
mainfrom
specs/fixed-protocol-parameters

Conversation

@xgreenx

@xgreenx xgreenx commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

The Canonical Runtime derives a proof's expiry from the profile version it ran, so one version must mean one value on every chain and through every verifier upgrade. Spec side of libid-org/libID-contracts#65; the contracts implementation lands in a separate libID-contracts PR.

Changes

  • Protocol parameters (libid.md): per-profile table; ("x", 1) and ("github", 1) fix proofLifetime 3600 and maxFutureAttestationSkew 300, ("google", 1) names neither.
  • REQ-PARAM-01: the profile fixes each value, the verifier exposes no setter, governance cannot change it, and a new value takes a new Platform Ceremony Version.
  • REQ-PARAM-02, TEST-PARAM-01: the verifier uses its profile's value; the test covers chains, Verifier Versions and upgrades.
  • Ceremony boundary: the Platform Ceremony Version and Platform Profile terms, common §5 and platform §2 include the values, so REQ-COMMON-01B bumps the version on a change.
  • Governance scope: trust model, principal table, Verifier Governance Process term and common §5.1 list no parameters.
  • Per-profile skew: ASM-NOTARY-01, REQ-COMMON-26, platform §2.2, REQ-PLAT-09, §7 and TEST-PLAT-07 read the profile's value.
  • Security considerations: the window is the profile's; governance can end acceptance early by retiring a trust root or Verifier Version.

Verified

  • lint_spec.py: the same findings on main and on this branch; 0 errors and 7 warnings over the three specs, 80 and 93 over all five.

Not verified / known issues

  • The contracts subtract a per-profile future observation allowance from evidence time; the spec does not define it (pre-existing gap).
  • docs(specs): establish protocol terminology #19 (draft) rewrites this section with governance-owned values and will conflict.

The Canonical Runtime derives a proof's expiry from the profile it ran, so
a lifetime governance can change lets that expiry disagree with a Consumer
Chain, or shift under a verifier upgrade. Each Platform Profile now fixes
proofLifetime and maxFutureAttestationSkew per (platform, version); a new
value takes a new Platform Ceremony Version. Governance keeps the Supported
Version Set and the trust roots. Spec side of
libid-org/libID-contracts#65.

Assisted-by: Claude Opus 5.5
Signed-off-by: Green Baneling <XgreenX9999@gmail.com>
@cloudflare-workers-and-pages

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
d438d08 2026-09-30T13:55:18.415Z View logs ↗

@xgreenx
xgreenx requested a review from Wondertan September 30, 2026 23:20
@xgreenx xgreenx self-assigned this Sep 30, 2026
@xgreenx
xgreenx marked this pull request as ready for review September 30, 2026 23:20
@xgreenx
xgreenx merged commit 3c6a04d into main Oct 1, 2026
5 of 6 checks passed
@xgreenx
xgreenx deleted the specs/fixed-protocol-parameters branch October 1, 2026 00:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants