Ruling (rc6, CIRISConstitution#118 / #119 → CC 3.2 T4a + T6, CC 5.3.1, CC 5.3.4, on branch rc6, lands on main at the rc6 cut). Trust-root lineages are witnessed, and attaching requires a witnessed head inside the root's attach_window. Server owns the witness-plane route and the served head.
Server's half.
POST /v1/transparency/lineage-head/cosign (beside the STH cosign route, same witness directory). Body: lineage_key_id, head_digest_sha256_hex (SHA-256 of the JCS-canonical signed roster record), head_asserted_at, prior_head_digest_sha256_hex (the head this witness last cosigned for this lineage; absent on first), signed_at, witness_key_id, hybrid signatures. Canonical bytes under the domain label ciris.lineage_head_cosign.v1 — distinct from ciris.sth_cosign.v1 so a head cosign can never be replayed as a tree-head cosign. Verify against the witness directory; refuse a witness that is a founder of the lineage (an independent set is the rule).
- Consistency, and equivocation as evidence: the new head MUST descend from the prior head the witness cosigned (walk
supersedes); otherwise 422 LINEAGE_HEAD_INCONSISTENT (CC 5.3.6.1). A head carrying a valid founder-quorum signature that does not descend from the lineage's witnessed head is recorded and never cosigned — that record is the hard_case:lineage_equivocation evidence, and dropping it would lose the proof.
- The head beside the bundle:
GET /v1/trust-root/bundle gains lineage_head outside bundle (unsigned convenience like everything outside bundle): the latest roster record of ciris-canonical (and humanity-accord), its digest, asserted_at, and its cosignatures. Also served alone at GET /v1/trust-root/lineage-head for a consumer refreshing before attach. The consumer verifies the record's quorum signature, each cosignature against its own witness directory, descent from the bundle's genesis record, and CC 3.2 T4a's window.
- Cadence: the canonical node re-commits both lineages at least once per
witness_cadence (default 24 h) whether or not the head moved.
- Evidence rows at CC 5.3.1 (
CLM-lineage-head-cosign) and CC 3.2 (CLM-attach-freshness, CLM-witnessed-lineage, shared with the persist tickets).
Depends on #537 (the bundle route itself) and the persist tickets filed with this one. Refs: CIRISConstitution#118, #119, CIRISPersist#926.
Ruling (rc6, CIRISConstitution#118 / #119 → CC 3.2 T4a + T6, CC 5.3.1, CC 5.3.4, on branch
rc6, lands onmainat the rc6 cut). Trust-root lineages are witnessed, and attaching requires a witnessed head inside the root'sattach_window. Server owns the witness-plane route and the served head.Server's half.
POST /v1/transparency/lineage-head/cosign(beside the STH cosign route, same witness directory). Body:lineage_key_id,head_digest_sha256_hex(SHA-256 of the JCS-canonical signed roster record),head_asserted_at,prior_head_digest_sha256_hex(the head this witness last cosigned for this lineage; absent on first),signed_at,witness_key_id, hybrid signatures. Canonical bytes under the domain labelciris.lineage_head_cosign.v1— distinct fromciris.sth_cosign.v1so a head cosign can never be replayed as a tree-head cosign. Verify against the witness directory; refuse a witness that is a founder of the lineage (an independent set is the rule).supersedes); otherwise422 LINEAGE_HEAD_INCONSISTENT(CC 5.3.6.1). A head carrying a valid founder-quorum signature that does not descend from the lineage's witnessed head is recorded and never cosigned — that record is thehard_case:lineage_equivocationevidence, and dropping it would lose the proof.GET /v1/trust-root/bundlegainslineage_headoutsidebundle(unsigned convenience like everything outsidebundle): the latest roster record ofciris-canonical(andhumanity-accord), its digest,asserted_at, and its cosignatures. Also served alone atGET /v1/trust-root/lineage-headfor a consumer refreshing before attach. The consumer verifies the record's quorum signature, each cosignature against its own witness directory, descent from the bundle's genesis record, and CC 3.2 T4a's window.witness_cadence(default 24 h) whether or not the head moved.CLM-lineage-head-cosign) and CC 3.2 (CLM-attach-freshness,CLM-witnessed-lineage, shared with the persist tickets).Depends on #537 (the bundle route itself) and the persist tickets filed with this one. Refs: CIRISConstitution#118, #119, CIRISPersist#926.