Skip to content

Specify the join-key rule and collect the shipped anomalies - #149

Merged
germ-mark merged 6 commits into
mainfrom
llm/book-join-key-rule
Sep 23, 2026
Merged

germ-mark merged 6 commits into
mainfrom
llm/book-join-key-rule

Conversation

@germ-mark

@germ-mark germ-mark commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

A follow-up to #148: this commit landed after that PR merged.

Spec (Group Rules rule 4, and the A.3 step): until a leaf moves, its owner signs in that group with the key the leaf presents. A group joined from the A.3 KP′ is signed with KP′'s key, even if the owner rotated after minting it. Moving one group's leaf never retires a key that another group's leaf still presents.

Shipped anomalies: they're now collected in one "Shipped anomalies" section at the end of Session Lifecycle, linked from the catch-up text, the A.3 host paragraph and Protocol Flows. There are six numbered deviations, each with its resolution nested beneath it:

  1. Wrong trigger: healed by spec behavior, since a conforming peer's reciprocal A.5 completes it.
  2. Born-dedicated acceptor's PQ leaf: healed once the acceptor runs a conforming engine.
  3. Born-dedicated catch-up Upds: healed by the peer's host, which approves offers the engine marks as catch-ups.
  4. History window: healed wherever a conforming engine validates; not healable by a deployed validator.
  5. Unchecked join: needs an accommodation. A conforming peer defers a reciprocal A.5 until the peer's own A.5 has landed, and a conforming engine that takes the party over re-proposes under the carried key.
  6. The deployed card host never sends side-band frames, though it receives them: healed once the acceptor's host carries them. An upgraded acceptor's Welcome' completes A.3 because the deployed initiator binds and its bind rides an ordinary frame. Later A.4 and A.5 rounds stay open until the deployed party upgrades; re-send cadence is host policy, and a host never drops the parked leg. No protocol change.

Book-only, with an empty changeset. mdbook build passes. No mermaid fences changed.

🤖 Generated with Claude Code

The deployed A.3 join signs with the current key, which a later
responder commit can orphan; a conforming peer defers the reciprocal
A.5 until the peer's own A.5 has landed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 23, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 46903a2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

germ-mark and others added 2 commits September 23, 2026 12:25
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@germ-mark germ-mark changed the title Specify signing a joined group with its KeyPackage key Specify the join-key rule and collect the shipped anomalies Sep 23, 2026
germ-mark and others added 3 commits September 23, 2026 12:38
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@germ-mark
germ-mark merged commit 69a9f0e into main Sep 23, 2026
11 checks passed
@germ-mark
germ-mark deleted the llm/book-join-key-rule branch September 23, 2026 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant