V0.1
Conformance boundary
This page is a proposal for public review, not a certification or evidence of implementation compliance.
IP-CONF-01 — Bounded claim. A semantic conformance statement identifies the exact candidate clauses and profiles tested; it must not imply independent certification or wire interoperability. See OPEN-08.
Semantic candidate
A semantic implementation claim should identify the clauses tested and demonstrate at least:
- Exact-target
Useauthorization and denial for expired, restricted, out-of-scope, non-member, and incomplete-path cases (IP-AUTH-01,IP-AUTH-03,IP-RES-01). - No path pooling, scope promotion, or authority from identity references or security class (
IP-AUTH-02–IP-AUTH-05,IP-ID-06). - Opaque one-target output and privacy-preserving failures, including telemetry constraints (
IP-RES-03,IP-RES-09,IP-LC-03–IP-LC-04). - A coherent resolution point under concurrent association, grant, restriction, membership, lifecycle, and generation changes (
IP-RES-04–IP-RES-06). - No success after failed or uncertain validation commit; bounded retry and generic exhaustion (
IP-RES-06). - No stale local mapping/session generation across the Passport resolution point (
IP-RES-07). - No lease semantics: later protected operations reauthorize (
IP-AUTH-06). - Single-use binding acceptance, same-operation receipt recovery, different-operation replay rejection, and distinct local CAS installation (
IP-BIND-04–IP-BIND-06). - Uncertain local commit recovery through local idempotency state without duplicate installation (
IP-BIND-08). - Bounded admission/execution/cancellation behavior for any implementation claiming the resolver resource-bound profile (
IP-SEC-04).
These are candidate semantic obligations. Their exact test harness, mandatory subset, error transport, and timing tolerances remain subject to OPEN-05, OPEN-07, and OPEN-08.
Named profiles
IP-CONF-02 — Named profile claim. A profile names specific assertion encoding, issuer trust, transport, key lifecycle, error behavior, and test vectors. ipa1 is a candidate optional profile only. A profile-level claim must identify its version and pass its own published vectors. See OPEN-02 and OPEN-08, plus the profile page.
Implementation evidence
IP-CONF-03 — Evidence provenance. PostgreSQL lock tests, Rust test counts, Aardwolf session behavior, operational runbooks, and deployment settings support claims about a pinned implementation revision. They do not establish universal interoperability or production readiness. [ADR 8H; canonical validation plan and resolver contract.] No implementation evidence is independently reproduced or approved for publication with this site. See evidence status.
No conformance mark or interoperability statement is justified by this draft alone.