ak.profile.circle_conformance.v1
ak.profile.circle_conformance.v1
role
"interop" description
"Conformance profile pinning the machine-contract surface for Circle (intra-Realm scoped event/message boundary; see zh/models/circle.md). Splits actor content payload (`scope_circle_id` where that object schema defines it), the signed Event `scope_ref`, and the materialized object's `effective_scope`; it also pins the Circle event-kind family, member-state transition table, encryption-profile compatibility, and scope-rebind reducer-reject semantics. Required by implementations that emit or consume Circle events or that materialize Circle-scoped Strand / Message / Morph / Relation / Space objects." enforcement_phases
[
"conformance",
"peer_eligibility"
] operation_requirements
[
{
"direction": "provide",
"operation_id": "ak.self.events.command.submit.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.committed_event.read.scan.v1",
"binding_kind": "http_json"
}
] inherits
[] required_event_kinds
[
"ak.circle.create",
"ak.circle.update",
"ak.circle.archive",
"ak.circle.restore",
"ak.circle.tombstone",
"ak.circle.member.state"
] rejected_event_kinds
[] required_schemas
[
"ak.schema.circle.v1",
"ak.schema.event.v1",
"ak.schema.event_payload.v1"
] required_capability_actions
[
"ak.circle.create",
"ak.circle.manage",
"ak.circle.member.add",
"ak.circle.member.manage",
"ak.circle.member.add.others",
"ak.circle.audit"
] required_fixtures
[
"circle-scope-fixture.json",
"privacy-security-fixture.json"
] optional_extensions
[
"scope_rebind_audit_paired"
] feature_discovery
{
"required": [
"circle_submit_payload_shape",
"circle_signed_scope_ref_shape",
"circle_mls_genesis_activation_check",
"circle_scope_rebind_default_reject",
"circle_member_state_transition_table"
],
"unsupported_optional": "implementations that cannot verify the signed Event scope_ref and its equivalence to reducer-derived scope MUST NOT claim ak.profile.circle_conformance.v1; receivers MUST treat any unknown Circle event-kind as schema_violation"
} additional_requirements
{
"submit_payload_must": "Object payload schemas that own scope_circle_id (including Strand, Morph, Relation, and scoped Space create/update shapes) MAY carry only that field as their actor-authored scope selector and MUST reject effective_scope (reason=effective_scope_reducer_managed). The rejection is decidable from the artifact schemas alone on both surfaces: every create shape reuses its object schema, and Relation - the one object schema that declares effective_scope on a patch surface - additionally forbids the effective_scope / effective_scope.* patch paths, registered per object kind in registry/reducer-managed-path-registry.json. Message and structural-operation payloads derive scope from accepted target references and MUST NOT invent a duplicate scope_circle_id; every Event still carries the producer-signed scope_ref.",
"canonical_reducer_output_must": "The producer MUST sign the tagged Event scope_ref. The receiver MUST derive the effective scope from the frozen pre-state and payload, require exact equality with scope_ref, and materialize the same value as the object's read-only effective_scope. A later scope_circle_id rebind MUST NOT re-interpret historical Events or objects.",
"scope_rebind_default_reject_must": "Default reducer MUST reject scope_circle_id rebind (None<->Some, Some(A)->Some(B)) with failed_precondition reason=scope_rebind_forbidden. Profile-declared audit-paired rebind MAY be permitted, but MUST emit ak.audit.accessed pairing.",
"circle_membership_subset_must": "Circle.members MUST be a strict subset of parent Realm.members; reducer MUST reject ak.circle.member.state -> join when the target actor is not a `join` member of the parent Realm (reason=circle_member_must_be_realm_member).",
"scope_invariant_must": "The Station sync surface MUST NOT deliver Events with scope_ref.kind=circle to actors who are not members at that Event's committed Circle-stream position (see zh/models/circle.md §9.3 scope-delivery invariant).",
"circle_mls_genesis_activation_must": "A Circle scope is plaintext until its own ak.mls.genesis is accepted. That accepted RealmCommit irreversibly activates standard RFC 9420 for the Circle scope; a later plaintext content write into the activated scope MUST be rejected and the activation MUST NOT be reversed. See zh/models/circle.md section 7."
}