跳转到内容

ak.profile.circle_conformance.v1

← Profiles

ak.profile.circle_conformance.v1

role

"interop"

description

"Conformance profile pinning the machine-contract surface for Circle (intra-Realm scoped event/message boundary; see zh/models/circle.md). Splits actor content payload (`scope_circle_id` where that object schema defines it), the signed Event `scope_ref`, and the materialized object's `effective_scope`; it also pins the Circle event-kind family, member-state transition table, encryption-profile compatibility, and scope-rebind reducer-reject semantics. Required by implementations that emit or consume Circle events or that materialize Circle-scoped Strand / Message / Morph / Relation / Space objects."

enforcement_phases

[
  "conformance",
  "peer_eligibility"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.self.events.command.submit.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.committed_event.read.scan.v1",
    "binding_kind": "http_json"
  }
]

inherits

[]

required_event_kinds

[
  "ak.circle.create",
  "ak.circle.update",
  "ak.circle.archive",
  "ak.circle.restore",
  "ak.circle.tombstone",
  "ak.circle.member.state"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.circle.v1",
  "ak.schema.event.v1",
  "ak.schema.event_payload.v1"
]

required_capability_actions

[
  "ak.circle.create",
  "ak.circle.manage",
  "ak.circle.member.add",
  "ak.circle.member.manage",
  "ak.circle.member.add.others",
  "ak.circle.audit"
]

required_fixtures

[
  "circle-scope-fixture.json",
  "privacy-security-fixture.json"
]

optional_extensions

[
  "scope_rebind_audit_paired"
]

feature_discovery

{
  "required": [
    "circle_submit_payload_shape",
    "circle_signed_scope_ref_shape",
    "circle_mls_genesis_activation_check",
    "circle_scope_rebind_default_reject",
    "circle_member_state_transition_table"
  ],
  "unsupported_optional": "implementations that cannot verify the signed Event scope_ref and its equivalence to reducer-derived scope MUST NOT claim ak.profile.circle_conformance.v1; receivers MUST treat any unknown Circle event-kind as schema_violation"
}

additional_requirements

{
  "submit_payload_must": "Object payload schemas that own scope_circle_id (including Strand, Morph, Relation, and scoped Space create/update shapes) MAY carry only that field as their actor-authored scope selector and MUST reject effective_scope (reason=effective_scope_reducer_managed). The rejection is decidable from the artifact schemas alone on both surfaces: every create shape reuses its object schema, and Relation - the one object schema that declares effective_scope on a patch surface - additionally forbids the effective_scope / effective_scope.* patch paths, registered per object kind in registry/reducer-managed-path-registry.json. Message and structural-operation payloads derive scope from accepted target references and MUST NOT invent a duplicate scope_circle_id; every Event still carries the producer-signed scope_ref.",
  "canonical_reducer_output_must": "The producer MUST sign the tagged Event scope_ref. The receiver MUST derive the effective scope from the frozen pre-state and payload, require exact equality with scope_ref, and materialize the same value as the object's read-only effective_scope. A later scope_circle_id rebind MUST NOT re-interpret historical Events or objects.",
  "scope_rebind_default_reject_must": "Default reducer MUST reject scope_circle_id rebind (None<->Some, Some(A)->Some(B)) with failed_precondition reason=scope_rebind_forbidden. Profile-declared audit-paired rebind MAY be permitted, but MUST emit ak.audit.accessed pairing.",
  "circle_membership_subset_must": "Circle.members MUST be a strict subset of parent Realm.members; reducer MUST reject ak.circle.member.state -> join when the target actor is not a `join` member of the parent Realm (reason=circle_member_must_be_realm_member).",
  "scope_invariant_must": "The Station sync surface MUST NOT deliver Events with scope_ref.kind=circle to actors who are not members at that Event's committed Circle-stream position (see zh/models/circle.md §9.3 scope-delivery invariant).",
  "circle_mls_genesis_activation_must": "A Circle scope is plaintext until its own ak.mls.genesis is accepted. That accepted RealmCommit irreversibly activates standard RFC 9420 for the Circle scope; a later plaintext content write into the activated scope MUST be rejected and the activation MUST NOT be reversed. See zh/models/circle.md section 7."
}

Source