Skip to content

CC 5.3.1 / 5.3.4 (rc6): lineage-head cosign route under ciris.lineage_head_cosign.v1, and the witnessed head served beside the bundle #693

Description

@emooreatx

Ruling (rc6, CIRISConstitution#118 / #119 → CC 3.2 T4a + T6, CC 5.3.1, CC 5.3.4, on branch rc6, lands on main at the rc6 cut). Trust-root lineages are witnessed, and attaching requires a witnessed head inside the root's attach_window. Server owns the witness-plane route and the served head.

Server's half.

  1. POST /v1/transparency/lineage-head/cosign (beside the STH cosign route, same witness directory). Body: lineage_key_id, head_digest_sha256_hex (SHA-256 of the JCS-canonical signed roster record), head_asserted_at, prior_head_digest_sha256_hex (the head this witness last cosigned for this lineage; absent on first), signed_at, witness_key_id, hybrid signatures. Canonical bytes under the domain label ciris.lineage_head_cosign.v1 — distinct from ciris.sth_cosign.v1 so a head cosign can never be replayed as a tree-head cosign. Verify against the witness directory; refuse a witness that is a founder of the lineage (an independent set is the rule).
  2. Consistency, and equivocation as evidence: the new head MUST descend from the prior head the witness cosigned (walk supersedes); otherwise 422 LINEAGE_HEAD_INCONSISTENT (CC 5.3.6.1). A head carrying a valid founder-quorum signature that does not descend from the lineage's witnessed head is recorded and never cosigned — that record is the hard_case:lineage_equivocation evidence, and dropping it would lose the proof.
  3. The head beside the bundle: GET /v1/trust-root/bundle gains lineage_head outside bundle (unsigned convenience like everything outside bundle): the latest roster record of ciris-canonical (and humanity-accord), its digest, asserted_at, and its cosignatures. Also served alone at GET /v1/trust-root/lineage-head for a consumer refreshing before attach. The consumer verifies the record's quorum signature, each cosignature against its own witness directory, descent from the bundle's genesis record, and CC 3.2 T4a's window.
  4. Cadence: the canonical node re-commits both lineages at least once per witness_cadence (default 24 h) whether or not the head moved.
  5. Evidence rows at CC 5.3.1 (CLM-lineage-head-cosign) and CC 3.2 (CLM-attach-freshness, CLM-witnessed-lineage, shared with the persist tickets).

Depends on #537 (the bundle route itself) and the persist tickets filed with this one. Refs: CIRISConstitution#118, #119, CIRISPersist#926.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions