Documentation · Foundation
  1. Documentation overview
  2. Core concepts
  3. Protocol Line
  4. Foundation
  5. Identity
  6. Pairwise protection
  7. Messaging & reliability
  8. HTTPS transport
  9. Groups & federation
  10. Verification
  11. Governance & license

Foundation: closed representations and registries

Foundation defines deterministic representations, field authority, lifecycle, bounds, source closure, and fail-closed parsing shared by all capabilities.

Two disjoint representations

Governance and distribution inputs use restricted canonical JSON. Endpoint runtime records use bounded deterministic CBOR. They are separate contracts rather than alternate encodings of one object.

SurfaceRepresentationCore rule
GovernanceRestricted JCS-style JSONClosed schemas, canonical member order, valid Unicode, no duplicate names or trailing content.
Endpoint runtimeDeterministic CBORUnsigned labels, shortest definite forms, bounded values, no tags, floats, aliases, duplicates, or trailing bytes.

Canonical field authority

The Canonical Field Registry owns every admitted logical field and exclusion. Versioned schemas and registries may project that authority but cannot silently add, rename, relocate, or reinterpret fields.

Source closure

Explicit sorted source manifests bind the tracked graph. Unsafe or undeclared paths, missing regular files, and symlinks reject. Deterministic generation reads those declared sources without machine, time, account, process, or runtime-state input.

Fail closed

Unknown core fields, duplicate labels, aliases, ambiguous encodings, incomplete identities, substituted input, and out-of-bound values reject without state advance. Capability-specific sources retain their own semantic authority.