§15.4 is written as a threat model and has accumulated normative language that the references do not implement. Two cases so far.
Profile enforcement at dispatch. "Coordinators MUST reject a method call whose namespace's owning profile is not in the workspace's advertised set." Not implemented in either reference. Tracked in #136. Also not implementable as phrased, because namespaces span profiles: participant covers core/1.0 and security-signed/1.0, audit covers core/1.0 and audit-scitt/1.0, task and review and escalate each straddle their home profile and routing/1.0, and workspace covers core, modes and control. The rule has to be per method.
Envelope id replay. "envelope id is a ULID ... which conformant Coordinators MUST reject on second observation (error code -32701 id_reused)". Not implemented. -32701 appears in SPECIFICATION.md §15.4 and in GLOSSARY.md and in no coordinator; neither reference keeps a seen-id set, and no error constant is allocated for it. The task.create idempotency map is a different mechanism serving a different purpose: it dedupes one method by an explicit caller-supplied key, rather than rejecting any envelope whose id has been seen before.
What to do
Two options per claim, and they can differ:
- Implement it, and add the error code and conformance vectors.
- Move it out of the normative voice into the operational threat model in
SECURITY.md, which §15.4 already points at for the full model.
Either is fine. Leaving MUSTs in the specification that the reference implementations do not meet is the problem, because the references are what conformance is measured against and both are shipped as the definition of correct behaviour.
Suggest a sweep of the whole of §15 for the same pattern once #136 is settled, and a CI check that every error code named in the specification is allocated in both references.
§15.4 is written as a threat model and has accumulated normative language that the references do not implement. Two cases so far.
Profile enforcement at dispatch. "Coordinators MUST reject a method call whose namespace's owning profile is not in the workspace's advertised set." Not implemented in either reference. Tracked in #136. Also not implementable as phrased, because namespaces span profiles:
participantcoverscore/1.0andsecurity-signed/1.0,auditcoverscore/1.0andaudit-scitt/1.0,taskandreviewandescalateeach straddle their home profile androuting/1.0, andworkspacecovers core, modes and control. The rule has to be per method.Envelope id replay. "envelope
idis a ULID ... which conformant Coordinators MUST reject on second observation (error code-32701 id_reused)". Not implemented.-32701appears inSPECIFICATION.md§15.4 and inGLOSSARY.mdand in no coordinator; neither reference keeps a seen-id set, and no error constant is allocated for it. Thetask.createidempotency map is a different mechanism serving a different purpose: it dedupes one method by an explicit caller-supplied key, rather than rejecting any envelope whose id has been seen before.What to do
Two options per claim, and they can differ:
SECURITY.md, which §15.4 already points at for the full model.Either is fine. Leaving MUSTs in the specification that the reference implementations do not meet is the problem, because the references are what conformance is measured against and both are shipped as the definition of correct behaviour.
Suggest a sweep of the whole of §15 for the same pattern once #136 is settled, and a CI check that every error code named in the specification is allocated in both references.