Skip to content

Interop node: in-toto predicate conformance lifecycle and freshness #148

Description

@hippoley

Why this node matters

in-toto/attestation#597 proposes a repository-owned conformance layer for every predicate. If that shape is accepted, later predicate families can inherit its verifier-interoperability contract.

This is a higher-leverage node than proposing another CounterProof-specific packet: the question is how independent verifiers prove they agree on a shared attestation specification.

CounterProof's narrow contribution

CounterProof has already hit the stale-evidence class in production-facing public claims:

historically valid evidence
!=
currently applicable evidence

The analogous conformance failure is:

passed corpus revision A
!=
conforms to current corpus revision B

A portable conformance receipt should bind:

  • predicate type;
  • specification revision or digest;
  • conformance manifest digest;
  • vector-set identity;
  • comparison surface;
  • verifier identity/version;
  • per-vector observed verdict;
  • evaluation timestamp.

When the corpus moves, the historical receipt remains valid for its pinned bytes but becomes stale as evidence for the new corpus until rerun.

Current upstream state observed 2026-10-07

Artifact

CounterProof PR #147 carries the first implementation of external-claim freshness plus:

docs/interop/in-toto-conformance-lifecycle.md

Next external handoff

When write access to the upstream thread is available, contribute the lifecycle boundary to #597 without proposing a new normative layer:

Passing repository-owned vectors demonstrates interoperability on the pinned corpus revision; it does not by itself establish conformance to later corpus revisions.

Success is upstream discussion/adoption of the boundary, not ownership of the predicate or conformance design.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions