Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions evidence/compatibility-environment-v1.10.17.json
Original file line number Diff line number Diff line change
Expand Up @@ -50,12 +50,12 @@
{
"id": "connected-http-json",
"reference": "spec/v1.9/iicp-core.md",
"sha256": "9731eb9556af07d8c775dd14bba0cc24aa705934801570fdbeaa5d426648bc97"
"sha256": "9a782a382d3c434b6c99163e1f6d3838105a1739cd31cc6878e474ac8dee98c2"
},
{
"id": "native-framing-draft",
"reference": "spec/v1.9/iicp-framing.md",
"sha256": "75a11f6d5c75f2ee77827989d2180ff98add5c4b44ae979f8503a567e8fc1bf4"
"sha256": "6c1a9f395f974adb63c1875a44684779b8f52755d8233e510fbd3d365351e77e"
}
],
"identity_and_security_profiles": [
Expand Down
13 changes: 13 additions & 0 deletions registry/source-classification.json
Original file line number Diff line number Diff line change
Expand Up @@ -1636,6 +1636,19 @@
}
]
},
{
"urn": "urn:iicp:intent:pre1:discovery-scale:v1",
"classification": "candidate-unregistered",
"disposition": "observed outside the canonical registry; requires separate review and evidence",
"sources": [
{
"repository": "iicp-directory-rust",
"paths": [
"src/db.rs"
]
}
]
},
{
"urn": "urn:iicp:intent:research:summarize:v1",
"classification": "canonical",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
{
"path": "native-framing-v1.json",
"fixture_version": "1.0.0-draft",
"sha256": "945c5086f0f7173beb7708478a36be74c0a4256ca4a4efd1a855e0e0057c3376"
"sha256": "02cc7bfbd3c238191ca3961aa03d09f143a51a43397e056d496977e5a9bf0471"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"fixture_version": "1.0.0-draft",
"status": "implementation-backed-pre-ratification",
"purpose": "Cross-implementation native framing vectors for the current ordered-stream binding. They cover bounded frame decoding and the fail-closed stable task-session type boundary. Dispatch direction, TLS, lifecycle, dedicated experimental relay sessions, logical fragmentation and unsupported QUIC behavior remain outside this fixture.",
"purpose": "Cross-implementation native framing vectors for the current experimental ordered-stream binding. They cover bounded frame decoding and the fail-closed task-session type boundary. Passing these vectors does not admit native TCP to the coordinated stable or production baseline. Dispatch direction, TLS, lifecycle, dedicated experimental relay sessions, logical fragmentation and unsupported QUIC behavior remain outside this fixture.",
"frame": {
"framing_version": 1,
"header_bytes": 12,
Expand Down Expand Up @@ -71,7 +71,7 @@
"conflict": "0x0B/0x0C are CONTROL/ADVERTISE in the draft registry but RELAY_BIND/RELAY_ACK in maintained relay experiments; stable task sessions reject both bytes before proportional allocation.",
"relay_boundary": "Experimental relay sessions remain isolated on their dedicated transport and do not count as stable task-profile conformance.",
"extension_boundary": "0xF0-0xFE require negotiated extension state; the current stable task profile negotiates none and rejects them before proportional allocation.",
"production_security_disposition": "open_qualify_or_exclude",
"production_security_disposition": "excluded_from_stable_baseline",
"plaintext_scope": "development_only",
"stable_claim": "not_admitted"
},
Expand Down
46 changes: 26 additions & 20 deletions spec/v1.9/iicp-core.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# IICP Core — Wire Format and Mandatory Requirements

**Version**: 1.3.3
**Date**: 2026-07-09
**Version**: 1.3.4
**Date**: 2026-08-28
**Status**: draft
**Issue**: #17 (S.5 — spec split)
**Authority**: Protocol Steward
Expand Down Expand Up @@ -128,7 +128,7 @@ Content-Type: `application/json`

| Field | Type | Constraint |
|-------|------|-----------|
| `endpoint` | string (URL) | Routable URL for the node's control plane (health probe, heartbeat, HTTP fallback transport). HTTPS MUST be used for Phase 1 deployments; http:// is accepted for Phase 3+ native-transport nodes advertising the control plane directly on port 9484 (IPv6-direct tier, where iicp-native framing provides its own integrity). MUST be validated by directory liveness check [→ DIR-REG-04]. See iicp-dir.md §3.1 for full transport/scheme matrix. |
| `endpoint` | string (URL) | Routable URL for the node's control plane (health probe, heartbeat, supported HTTP task transport). HTTPS MUST be used for production and coordinated stable deployments. Explicit development profiles MAY use `http://` when the directory's liveness and routability policy permits it, but plaintext native framing does not provide transport integrity. MUST be validated by directory liveness check [→ DIR-REG-04]. See iicp-dir.md §3.1 for the full transport/scheme matrix. |
| `region` | string | IANA-style tag (e.g., `us-west`, `eu-central`); max 64 chars |
| `capabilities` | array | MUST contain at least one capability object |
| `capabilities[].intent` | string | Standard: `urn:iicp:intent:<domain>:<action>:v<N>`; Custom: `urn:iicp:intent:x.<vendor>:<action>:v<N>` — see `iicp-semantics.md §1.1` |
Expand Down Expand Up @@ -401,10 +401,10 @@ the HTTPS endpoint configured by the operator and is not required to use 9484.

| Aspect | Phase 1 (deployed) | Phase 2 (deployed) | Phase 3 (target) | Phase 4+ (roadmap) |
|--------|-------------------|--------------------|-------------------|---------------------|
| Port | Advertised HTTPS port | Advertised HTTPS port | Advertised task/native port | TCP profile implemented; QUIC/UDP remains a draft |
| Port | Advertised HTTPS port | Advertised HTTPS port | Advertised task port | Experimental TCP profile implemented; QUIC/UDP remains a draft |
| Encoding | JSON | JSON + CBOR optional | CBOR preferred (`application/cbor`) | CBOR (default) |
| Transport | HTTPS/1.1 or HTTPS/2 | HTTPS/2 | HTTP or negotiated native TCP | QUIC mapping is future work |
| Framing | REST (no custom framing) | REST + HMAC-SHA256 envelope | REST (IICP binary framing optional) | Native IICP binary framing |
| Transport | HTTPS/1.1 or HTTPS/2 | HTTPS/2 | HTTP; explicitly enabled native TCP remains experimental | QUIC mapping is future work |
| Framing | REST (no custom framing) | REST + HMAC-SHA256 envelope | REST; experimental IICP binary framing optional | Native framing and QUIC remain post-baseline research |
| TLS version | TLS 1.3 MUST [→ SEC-TLS-01] | TLS 1.3 MUST | TLS 1.3 MUST | TLS 1.3 + PQ option |
| Auth | Bearer node_token | JWT HS256 | W3C DID (Phase 3+) | PQ — Dilithium3 |
| Peer discovery | Directory REST | Gossip (PEER_EXCHANGE) | DID-resolved mesh | — |
Expand All @@ -414,10 +414,13 @@ tooling compatibility and minimise implementation risk at PoC scale. CBOR and QU
deferred; the current transport boundary and evidence are recorded in
`docs/architecture/environmental-independence-and-extension-architecture.md`.

**Current transport evidence**: Maintained implementations support HTTP task
endpoints and a native framed TCP profile. Deployment metadata can negotiate or
advertise ports other than 9484. The QUIC mapping remains an active draft and is
not a mandatory conformance requirement.
**Current transport evidence and release boundary**: Maintained implementations
support HTTP task endpoints. They also contain an explicitly enabled plaintext
native framed TCP development profile with cross-SDK byte-vector coverage. That
profile has no maintained native TLS terminator and is excluded from the
coordinated stable and production baseline. Deployment metadata can advertise
ports other than 9484. The QUIC mapping remains an active draft and is not a
mandatory conformance requirement.

**Standards intent**: IICP is being prepared for external review. This project
intent is not IETF endorsement, IANA assignment or external ratification.
Expand All @@ -429,12 +432,13 @@ All components MUST validate TLS certificates on outbound connections.
| Surface | Scheme rule |
|---------|-------------|
| Directory control plane (`/v1/register`, `/v1/discover`, `/v1/heartbeat`, etc.) | HTTPS/TLS 1.3 MUST. |
| Node task/control endpoint advertised as `endpoint` | HTTPS is preferred. Routable `http://` MAY be accepted for native/node consumers only when the directory's liveness and routability checks pass and the deployment profile permits it (see iicp-dir.md §3.1). |
| Node task/control endpoint advertised as `endpoint` | HTTPS is required for production and coordinated stable deployments. Routable `http://` MAY be accepted only by an explicit development profile when the directory's liveness and routability checks pass (see iicp-dir.md §3.1). |
| Browser consumers from `https://iicp.network` | HTTPS, browser-safe relay, or WebRTC path only; a public `http://` node endpoint is not browser-usable from the HTTPS site because browsers block mixed active content. |
| Native data plane | `iicp://` or `iicpsec://` per `transport_endpoint`; `iicpsec://` SHOULD be preferred where available. |
| Native data plane | Experimental and outside the coordinated stable/production baseline. `iicp://` is plaintext development use. `iicpsec://` may be advertised only when a real native TLS path exists; an HTTPS proxy or tunnel is not such evidence. |

Plaintext HTTP to the directory MUST be rejected. Plaintext HTTP node endpoints
are route evidence, not browser usability or confidentiality evidence.
are development route evidence, not browser usability, confidentiality or
stable-production evidence.

---

Expand Down Expand Up @@ -495,7 +499,7 @@ in active use:

## 8. Security Requirements (Phase 1 minimum)

- TLS 1.3 MUST be enforced on all endpoints [→ SEC-TLS-01]. Exception: Phase 3+ nodes registering an http:// `endpoint` on port 9484 (IPv6-direct, native IICP transport tier) — such nodes SHOULD use `iicpsec://` for their `transport_endpoint` and are exempt from the HTTPS requirement only for the control-plane port-9484 listener where iicp-native framing provides its own integrity.
- TLS 1.3 MUST be enforced on every production and coordinated stable endpoint [→ SEC-TLS-01]. Explicit development profiles MAY use plaintext `http://` and `iicp://` with visible warnings, but they are outside stable/production claims. Native framing, magic bytes and task authentication do not provide transport confidentiality or integrity.
- `POST /v1/register` rate limit: 10/min per IP MUST be enforced [→ DIR-RL-01]
- `node_token`: 32+ bytes cryptographically random, stored bcrypt-hashed, returned once [→ DIR-REG-05, DIR-REG-07]
- Adapter MUST validate `node_token` on every `POST /v1/task` [→ TASK-1]
Expand All @@ -504,7 +508,7 @@ in active use:
- **Privacy (PA-1..PA-4)**: Implementers and operators MUST inform clients that the inference-executing node receives the full task payload in plaintext, including any user-provided content. IICP provides confidentiality for transit (TLS 1.3) and isolation of the directory from payload content; it does not provide confidentiality against the inference-executing node. [→ SEC-PRIV-01]
- Relay nodes and directory operators MUST NOT log task payload content beyond the TTL required for rate-limiting. [→ SEC-PRIV-03]
- Registration `node_id` MUST default to an anonymized UUID not tied to hardware or operator identity. [→ SEC-PRIV-08]
- All IICP connections MUST use TLS 1.3 or higher with ephemeral key exchange (forward secrecy). [→ SEC-TLS-01, SEC-PRIV-09]. Same Phase 3+ port-9484 exception applies as above.
- All production and coordinated stable IICP connections MUST use TLS 1.3 or higher with ephemeral key exchange (forward secrecy). [→ SEC-TLS-01, SEC-PRIV-09].
- **Privacy adversary model** (PA-1..PA-4) and its trust boundaries are defined in `docs/security/privacy-adversary-and-trust-model.md` and SHALL be considered when implementing any component that handles task routing or node metadata.

---
Expand Down Expand Up @@ -600,18 +604,20 @@ status or health command (e.g., `iicp-proxy status`).

### 11.3 Default Port

Port **9484/TCP** is the provisional default for the native peer profile. It is
IANA-unassigned and is not reserved for IICP. Implementations MAY use it while
it remains available, but MUST advertise the actual selected port. Directory
HTTPS endpoints and HTTP task endpoints use their advertised ports. No IICP
UDP service port is specified by this release.
Port **9484/TCP** is the provisional convention for the explicitly enabled
experimental native peer profile. It is IANA-unassigned and is not reserved for
IICP. Development implementations MAY use it while it remains available, but
MUST advertise the actual selected port. Directory HTTPS endpoints and HTTP task
endpoints use their advertised ports. No IICP UDP service port is specified by
this release.

---

## Changelog

| Version | Date | Change |
|---------|------|--------|
| 1.3.4 | 2026-08-28 | Corrects the transport security and release boundary: supported HTTP is the coordinated stable qualification target; plaintext native TCP is explicit development-only and excluded from stable/production claims; native framing is not transport integrity and HTTPS routing does not prove `iicpsec://`. |
| 1.3.3 | 2026-07-30 | Corrected transport and registry status: 9484 is an unassigned provisional TCP convention, not an IANA reservation; directory HTTPS and advertised endpoint ports are separate; QUIC/UDP remains draft. |
| 1.3.2 | 2026-07-09 | #614 adds optional `generated_by_ai` response metadata and the compatibility-proxy header rule; it is a transparency notice, not authenticity proof. |
| 1.3.1 | 2026-06-28 | §8 replaces the stale blanket "plaintext HTTP rejected" wording with an endpoint scheme matrix: directory control plane is HTTPS/TLS-only; node task endpoints may be routable `http://` for native consumers where IICP-DIR permits and probes them; browser consumers require HTTPS/relay/WebRTC-safe paths; native data plane uses `iicp://`/`iicpsec://`. |
Expand Down
17 changes: 9 additions & 8 deletions spec/v1.9/iicp-dir.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# IICP-DIR — Directory Sub-Protocol Specification

**Version**: 1.1.25
**Date**: 2026-08-20
**Version**: 1.1.26
**Date**: 2026-08-28
**Status**: draft
**Issue**: #14
**Authority**: Protocol Steward
Expand Down Expand Up @@ -154,22 +154,22 @@ the verified `operator_pubkey` + trust tier (`did_key` self-asserted in Phase A;
domain-verified in Phase B). An invalid delegation leaves the node operator-unverified but does NOT
reject the registration (no false binding is possible without the operator's signature). [→ DIR-OPID-01]

**Dual-endpoint model (v1.5.0, optional — default to HTTP-only)**:
**Dual-endpoint model (v1.5.0, experimental — default to HTTP-only)**:

A node MAY advertise two endpoints with distinct roles:

| Field | Scheme | Role | Used by |
|-------|--------|------|---------|
| `endpoint` | `http://` / `https://` | Control plane: health probe, registration heartbeat, HTTP fallback transport | Directory `assertLive`; legacy clients |
| `transport_endpoint` | `iicp://` / `iicpsec://` | Data plane: native binary framing per ADR-040 (default port 9484) | Clients preferring native transport |
| `transport_endpoint` | `iicp://` / `iicpsec://` | Experimental data plane: native binary framing per ADR-040 (provisional port 9484 convention) | Explicitly configured experimental peers |

Rules:
- `endpoint` is REQUIRED (no change from prior versions).
- `transport_endpoint` is OPTIONAL. When present its URI scheme MUST be `iicp` (plaintext binary framing) or `iicpsec` (TLS-wrapped framing). Default port for both is 9484 (ADR-040 §3).
- `transport_endpoint` is OPTIONAL and outside the coordinated stable/production baseline. When present its URI scheme MUST be `iicp` (plaintext binary framing) or `iicpsec` (TLS-wrapped framing). Port 9484 is a provisional, unassigned convention; the advertised port is authoritative (ADR-040 §3).
- The directory MUST NOT perform an HTTP probe against `transport_endpoint` — its liveness is implied by `endpoint`'s `/iicp/health` response (Phase 5.x scope; native-protocol dial-back is Phase 6).
- Clients SHOULD prefer `transport_endpoint` when issuing task CALLs. When absent or unreachable, clients fall back to `endpoint` (HTTP transport per spec §3.3).
- Stable clients MUST NOT infer production support from the field or prefer it by default. A client MAY use `transport_endpoint` only when its experimental native binding is explicitly enabled and the advertised scheme is supported. Otherwise it uses `endpoint` (HTTP transport per spec §3.3).
- Both endpoints MUST resolve to the same node (operator MUST NOT advertise a `transport_endpoint` belonging to a different host).
- `endpoint` and `transport_endpoint` MAY share the same host:port: a node MAY multiplex the HTTP control plane and the native binary transport on one listener via first-byte protocol detection (the IICP frame magic `IICP` distinguishes a native connection from an HTTP request line). Single-port operation lets a CGNAT node serve both planes through one pinhole, so the native transport is reachable exactly when `endpoint` is (#457; the reference SDKs default to this).
- `endpoint` and `transport_endpoint` MAY share the same host:port when the operator explicitly enables the experimental listener: a node MAY multiplex the HTTP control plane and the native binary transport on one listener via first-byte protocol detection (the IICP frame magic `IICP` distinguishes a native connection from an HTTP request line). Maintained provider defaults do not mount or advertise native TCP. Same-port advertisement does not prove native TLS or production readiness.

Example with both endpoints:

Expand Down Expand Up @@ -552,7 +552,7 @@ set as safe presentation metadata only.

| Field | Type | Notes |
|-------|------|-------|
| `transport_endpoint` | string\|null | Native IICP binary endpoint (ADR-040). Scheme `iicp://` (plaintext) or `iicpsec://` (TLS). Clients SHOULD prefer this over `endpoint`. `null` = node only serves HTTP transport via `endpoint`. |
| `transport_endpoint` | string\|null | Experimental native IICP binary endpoint (ADR-040), outside the coordinated stable/production baseline. Scheme `iicp://` (plaintext development use) or `iicpsec://` (TLS only when a real native TLS terminator exists). Clients use it only after explicit binding enablement; `null` means the node only advertises HTTP transport via `endpoint`. |
| `reputation_score` | float [0.0, 1.0] | Delta-based EMA per spec §11.2 (ADR-023). Default 0.5 for nodes with no heartbeat history. |
| `probation` | boolean | `true` when `completed_tasks_count < 100`. Nodes in probation are excluded from `?qos=interactive` and `?qos=realtime` queries. |
| `completed_tasks_count` | integer | Cumulative count of successfully completed tasks (heartbeat-reported). Used for probation tier gating (spec §11.3). |
Expand Down Expand Up @@ -1876,6 +1876,7 @@ Tracking: #508

| Version | Date | Change |
|---------|------|--------|
| 1.1.26 | 2026-08-28 | Corrects the native transport support boundary: `transport_endpoint` remains experimental and optional, maintained stable defaults use HTTP, clients do not prefer it without explicit enablement, and HTTPS route evidence must not be treated as native TLS evidence. |
| 1.1.25 | 2026-08-20 | HEARTBEAT adds `reputation_model`, opaque epoch and retry-safe metrics batch acknowledgement. AUDIT_REPORT integrity evidence is separated from `outcome-v2` execution-outcome reputation. |
| 1.1.23 | 2026-07-18 | #534 clarifies adoption-gated strict E050: every re-registration of an existing secured node requires the current token, including unchanged routes, so a tokenless refresh cannot mint a credential and then authorize a second-step route takeover. Transitional old-endpoint-absence behavior remains unchanged until an explicit cutover. |
| 1.1.22 | 2026-07-11 | #618 accountless operator-key lifecycle: dual-key signed normal rotation preserves linked-node, credit/reputation and recognition continuity atomically while policy manifests remain independently re-signed; signed revocation fails closed for node operator bindings. Old keys become ineligible for new claims, and public receipts remain redacted/no-store. |
Expand Down
Loading