V0.1

Conformance boundary

This page is a proposal for public review, not a certification or evidence of implementation compliance.

IP-CONF-01 — Bounded claim. A semantic conformance statement identifies the exact candidate clauses and profiles tested; it must not imply independent certification or wire interoperability. See OPEN-08.

Semantic candidate

A semantic implementation claim should identify the clauses tested and demonstrate at least:

  1. Exact-target Use authorization and denial for expired, restricted, out-of-scope, non-member, and incomplete-path cases (IP-AUTH-01, IP-AUTH-03, IP-RES-01).
  2. No path pooling, scope promotion, or authority from identity references or security class (IP-AUTH-02–IP-AUTH-05, IP-ID-06).
  3. Opaque one-target output and privacy-preserving failures, including telemetry constraints (IP-RES-03, IP-RES-09, IP-LC-03–IP-LC-04).
  4. A coherent resolution point under concurrent association, grant, restriction, membership, lifecycle, and generation changes (IP-RES-04–IP-RES-06).
  5. No success after failed or uncertain validation commit; bounded retry and generic exhaustion (IP-RES-06).
  6. No stale local mapping/session generation across the Passport resolution point (IP-RES-07).
  7. No lease semantics: later protected operations reauthorize (IP-AUTH-06).
  8. Single-use binding acceptance, same-operation receipt recovery, different-operation replay rejection, and distinct local CAS installation (IP-BIND-04–IP-BIND-06).
  9. Uncertain local commit recovery through local idempotency state without duplicate installation (IP-BIND-08).
  10. Bounded admission/execution/cancellation behavior for any implementation claiming the resolver resource-bound profile (IP-SEC-04).

These are candidate semantic obligations. Their exact test harness, mandatory subset, error transport, and timing tolerances remain subject to OPEN-05, OPEN-07, and OPEN-08.

Named profiles

IP-CONF-02 — Named profile claim. A profile names specific assertion encoding, issuer trust, transport, key lifecycle, error behavior, and test vectors. ipa1 is a candidate optional profile only. A profile-level claim must identify its version and pass its own published vectors. See OPEN-02 and OPEN-08, plus the profile page.

Implementation evidence

IP-CONF-03 — Evidence provenance. PostgreSQL lock tests, Rust test counts, Aardwolf session behavior, operational runbooks, and deployment settings support claims about a pinned implementation revision. They do not establish universal interoperability or production readiness. [ADR 8H; canonical validation plan and resolver contract.] No implementation evidence is independently reproduced or approved for publication with this site. See evidence status.

No conformance mark or interoperability statement is justified by this draft alone.