diff --git a/CONTINUATION.md b/CONTINUATION.md
index b999440..b072582 100644
--- a/CONTINUATION.md
+++ b/CONTINUATION.md
@@ -18,9 +18,10 @@ private development methods or production systems.
5. Use [`standards/REVIEWING.md`](standards/REVIEWING.md) for an independent
standards review or Internet-Draft candidate review.
6. Use [`standards/IICP_PROTOCOL_POSITIONING.md`](standards/IICP_PROTOCOL_POSITIONING.md)
- and the dated [protocol comparison](standards/PROTOCOL_COMPARISON_2026-08-15.md)
+ as the current entry point to the dated
+ [September comparison](standards/PROTOCOL_COMPARISON_2026-09-25.md)
before changing IICP's boundary with IAIP, AIDIP, MCP, A2A or discovery
- protocols. The machine-readable facts live in
+ protocols. The machine-readable assessment lives in
`standards/protocol-comparison-v1.json`.
## What an independent implementation needs
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 7b74b25..334c508 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -4,13 +4,23 @@ Start with a public issue that identifies an interoperability problem rather
than a preferred implementation. Specification changes should include schemas,
compatibility behavior and conformance vectors where applicable.
-Run the repository checks before proposing a change:
+From the repository root, use an isolated Python environment with the
+requirements in `tools/requirements.txt` and the local conformance runner
+(`python3 -m pip install './conformance-runner[signing]'`). Run the checks
+relevant to the files changed before proposing a pull request:
```bash
python3 tools/generate_implementations.py --check
+tools/run_profile_fixture_contract.sh
python3 tools/check_public_prose.py --strict README.md GOVERNANCE.md CONTRIBUTING.md
+python3 tools/check_public_artifact_closure.py --all-public
```
+`ecosystem.yml` contains the required pull-request `validate` job.
+`profile-fixtures.yml` is a manual diagnostic workflow, not an additional
+qualification pass. Do not interpret a skipped, unrun or dependency-failed
+check as passing evidence. Run locally first to conserve hosted CI minutes.
+
The prose check blocks objective citation artifacts and reports stylistic or
substance heuristics for human review. It checks writing quality, not whether a
person or a model wrote the text. Do not replace flagged words mechanically;
@@ -27,6 +37,11 @@ Implementation bugs belong in the owning repository listed in
`IMPLEMENTATIONS.md`. Never include production credentials, private topology or
real task data.
+An implementation result may expose a discrepancy in the specification, but
+it cannot silently change released semantics. Record the applicable release,
+Profile and binding; propose any interoperable correction with compatibility
+behavior and fixtures. Preserve immutable tags and release assets.
+
## Where to open an issue
- Use this repository for normative protocol semantics, registries,
diff --git a/README.md b/README.md
index df2a167..f119417 100644
--- a/README.md
+++ b/README.md
@@ -5,12 +5,12 @@
[](LICENSE)
[](https://agenticsorg.github.io/community-projects/oia-matrix.html#oia-roble3-iicp)
-*Building the HTTP for the Age of Generative AI*
+Provider-neutral discovery, eligibility and execution handoff for intelligence workloads.
-**Protocol-suite release**: v1.10.17
+**Published Protocol Suite**: see the generated [current-version projection](ecosystem/CURRENT_VERSIONS.md)
**Wire compatibility baseline**: v1.9.0
-**Reference implementation**: [iicp.network](https://iicp.network)
-**Status**: Project-normative beta suite; individual profiles retain their own status
+**Project status**: project-normative beta; each optional Profile has its own status
+**Working `main`**: may contain unreleased changes; cite an immutable tag for a released contract
---
@@ -43,7 +43,12 @@ inspect.
## What Is IICP?
-IICP is an open protocol that lets AI agents discover each other, negotiate capabilities, and route tasks across a distributed network — without any central broker owning the compute or controlling the data.
+IICP specifies how a consumer expresses an intent, discovers currently eligible
+execution resources, applies non-overridable policy constraints and receives a
+route for direct execution. The directory is a control plane, not a task-payload
+broker. A selected execution binding may be HTTP, MCP, A2A or another supported
+path when that binding is implemented by the parties; native IICP execution is
+not a prerequisite for provider selection.
```
Agent A ──CALL──▶ IICP Node B ──▶ LLM Backend
@@ -54,12 +59,15 @@ Agent A ──CALL──▶ IICP Node B ──▶ LLM Backend
no payload passes through)
```
-The directory (`iicp.network`) is **bootstrap and discovery only** and does not receive task
-payloads. Tasks route to the selected execution node, whose operator can read the work it executes.
-Current IICP-CX clients encrypt requests across the network and relays when a provider advertises
-`cx_public_key`; this is transport confidentiality, not executor-blind inference or anonymity.
+The directory handles registration, health, discovery and route authorization;
+it does not receive task payloads. Tasks route to the selected execution node,
+whose operator can read the work it executes.
+IICP-CX can encrypt a request across the network and relays when the chosen
+client and provider support the Profile and the provider advertises a usable
+`cx_public_key`. This is route confidentiality, not executor-blind inference
+or anonymity; key advertisement alone is not a verified encrypted round trip.
-### The core idea
+### The core idea (conceptual, not a wire-format example)
```json
{
@@ -70,7 +78,12 @@ Current IICP-CX clients encrypt requests across the network and relays when a pr
}
```
-An **intent URN** expresses what you want, not which model or endpoint to call. The network finds the best available node that can serve that intent, routes the task, and returns a structured response.
+An intent identifier describes the requested operation, not a particular model
+or endpoint. Discovery returns candidates under the applicable capability,
+policy and availability rules. A client still needs the appropriate dispatch
+authority and an eligible route before execution. For executable examples,
+start with the [role-based agent guide](docs/agent-bootstrap.md) and the
+applicable released Profile or binding.
### Factual runtime self-description
@@ -106,10 +119,11 @@ deployment and governance. It does not calculate a winner score. The chronology
also separates the age of a protocol from the first public appearance of an
overlapping mechanism.
-This boundary has real overlap with current IAIP and AIDIP Internet-Drafts.
-Review the [`selection and eligibility problem statement`](standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md), the concise [`IICP protocol positioning`](standards/IICP_PROTOCOL_POSITIONING.md)
-and the dated, source-backed
-[`mechanism comparison`](standards/PROTOCOL_COMPARISON_2026-08-15.md) before
+This boundary has real overlap with individual Internet-Drafts such as IAIP and
+AIDIP; mandatory filtering before ranking is not unique to IICP.
+Review the [selection and eligibility problem statement](standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md),
+the [current positioning entry point](standards/IICP_PROTOCOL_POSITIONING.md)
+and its dated, source-backed assessment before
making differentiation or standards claims. Internet-Drafts are work in
progress and are not IETF endorsement.
@@ -121,9 +135,9 @@ progress and are not IETF endorsement.
| Document | What it covers | Normative level |
|----------|---------------|-----------------|
-| [iicp-core.md](spec/v1.9/iicp-core.md) | Wire format, 14 message types, required fields, error codes, security minimums | **MUST** |
-| [iicp-semantics.md](spec/v1.9/iicp-semantics.md) | Intent routing, QoS tiers, node scoring, retry policy, circuit breaker | SHOULD / MAY |
-| [iicp-extensions.md](spec/v1.9/iicp-extensions.md) | Billing, reputation, MCP binding, Cooperative Inference, post-quantum | MAY / future |
+| [iicp-core.md](spec/v1.9/iicp-core.md) | Core task and directory contracts, errors and security boundaries | Apply requirements within the named release and binding |
+| [iicp-semantics.md](spec/v1.9/iicp-semantics.md) | Intent routing, eligibility, selection and retry semantics | Apply requirements within the named release and Profile |
+| [iicp-extensions.md](spec/v1.9/iicp-extensions.md) | Extension and optional Profile overview | Check each Profile's own status |
### Sub-protocols
@@ -139,8 +153,8 @@ progress and are not IETF endorsement.
| Document | What it covers |
|----------|---------------|
-| [IICP-core-phase1-profile.md](spec/v1.9/IICP-core-phase1-profile.md) | Phase 1 field subset — the minimum viable implementation |
-| [conformance-test-suite.md](spec/v1.9/conformance-test-suite.md) | 200+ machine-verifiable test IDs (DIR-*, PROXY-*, SEC-*, CIP-*, DIR-FED-*) mapped to REACH probes |
+| [IICP-core-phase1-profile.md](spec/v1.9/IICP-core-phase1-profile.md) | Historical Phase 1 compatibility subset; not the general current quickstart |
+| [conformance-test-suite.md](spec/v1.9/conformance-test-suite.md) | Canonical test identifiers and their applicable contracts; identifiers are not passing results |
| [validation-methodology.md](spec/v1.9/validation-methodology.md) | How to validate implementations; performance claim disclosure |
| [iicp-v1.5-overview.md](spec/v1.9/iicp-v1.5-overview.md) | What changed in v1.5; migration guide from v1.4.2 |
| [Pre-1.0 feature boundary](pre1/README.md) | Bounded client, Directory and Management capability crosswalk; not a stable-release authorization |
@@ -149,7 +163,7 @@ progress and are not IETF endorsement.
| Path | Contents |
|------|---------|
-| [schemas/task.json](schemas/task.json) | JSON Schema 2020-12 for `IicpTask` |
+| [schemas/task.json](schemas/task.json) | Historical Phase 1 JSON task schema, not a universal current task contract |
| [schemas/nodelist.json](schemas/nodelist.json) | JSON Schema 2020-12 for `NodeListResponse` |
| [registry/intents.json](registry/intents.json) | Official intent URN registry |
| [spec/intent-risk-taxonomy.json](spec/intent-risk-taxonomy.json) | Shared prohibited/high-risk/transparency/minimal intent classification fixture |
@@ -163,24 +177,17 @@ progress and are not IETF endorsement.
---
-## Quick Start: Implement IICP
+## Start with the applicable contract
-Read [IICP-core-phase1-profile.md](spec/v1.9/IICP-core-phase1-profile.md) for the minimum field subset. A Phase 1 node must:
+- **Application or agent developer:** use the [role-based agent guide](docs/agent-bootstrap.md) for consumer discovery and direct execution; use the chosen SDK repository for its current API.
+- **Provider operator:** use the same guide for registration and the [operator onboarding path](docs/operator-onboarding-recovery.md) for persistent service behavior.
+- **Directory implementer:** read the [specification index](spec/v1.9/README.md), directory contract and applicable HTTP/OpenAPI projection. PHP and Rust implementation details belong in their own repositories.
+- **Independent implementer or reviewer:** pin a Protocol Suite release, declare supported Profiles and bindings, then use the [conformance suite](spec/v1.9/conformance-test-suite.md) and [runner](conformance-runner/README.md). The [Phase 1 profile](spec/v1.9/IICP-core-phase1-profile.md) remains a historical compatibility path, not a claim of current full support.
-1. **Register** — `POST /v1/register` with `{endpoint, region, capabilities[], limits}`
-2. **Heartbeat** — `POST /v1/heartbeat` every 30 s with `{load, active_jobs}`
-3. **Accept tasks** — `POST /v1/task` — validate UUID-v4 `task_id`, intent URN, `timeout_ms` bounds
-4. **Discover peers** — `GET /v1/discover?intent=urn:iicp:intent:llm:chat:v1`
-5. **Return structured errors** — never raw exceptions; always `{"error": {"code": "IICP-Exxx", ...}}`
-
-### Conformance levels
-
-| Level | Documents to satisfy | Typical implementer |
-|-------|---------------------|---------------------|
-| **Core** | iicp-core.md MUSTs only | Minimal node, embedded device |
-| **Phase 1** | Core + IICP-core-phase1-profile.md | Reference implementation |
-| **Phase 2** | Phase 1 + iicp-dir.md §3.6 (peers) | Mesh node |
-| **Phase 3+** | Phase 2 + billing/reputation extensions | Full CIP node |
+A Profile is optional to select unless the named release requires it. Once an
+implementation declares support for a Profile, that Profile's requirements
+are mandatory within its scope. Publication, test execution, qualification
+and live deployment remain separate evidence states.
---
@@ -199,12 +206,14 @@ and published:
| TypeScript | `npm install @iicp/client` | [npm: @iicp/client](https://www.npmjs.com/package/@iicp/client) | [github.com/RobLe3/iicp-client-typescript](https://github.com/RobLe3/iicp-client-typescript) |
| Rust | `cargo add iicp-client` | [crates.io: iicp-client](https://crates.io/crates/iicp-client) | [github.com/RobLe3/iicp-client-rust](https://github.com/RobLe3/iicp-client-rust) |
-**No install at all?** [iicp.network/browser-node](https://iicp.network/browser-node)
-runs a real model in your browser (WebGPU) and queries the live mesh as an IICP
-consumer — with a connection console that shows every discover/dispatch wire step.
+**Experimental browser path:** [iicp.network/browser-node](https://iicp.network/browser-node)
+can run a supported model with WebGPU and query the public mesh as a consumer
+on compatible browsers. It is not a general installation or availability guarantee.
-The SDKs are conformant reference clients — a good starting point for understanding the
-wire format in practice. Bug reports and PRs are welcome on each repository.
+These maintained reference SDKs are useful implementation examples. A package
+release or same-project parity test does not by itself establish independent
+interoperability or certification; consult the named fixtures and retained
+results for a bounded conformance claim.
### Community integrations — independently maintained
@@ -224,12 +233,11 @@ carry the task after IICP selects a route.
### Reachability: the automatic NAT ladder
-A provider node should become reachable without router surgery. The SDKs escalate
-automatically: **direct** endpoint → **UPnP** pinhole → **IPv6** GUA → **relay**
-auto-election from the directory (outbound bind; `transport_method=turn_relay`) →
-**Quick Tunnel** (zero-account `cloudflared`; `transport_method=external_tunnel`) —
-each rung tried only when the previous fails, each surfaced honestly in the node's
-`exposure_mode` so discovery and scoring can see how a node is reached.
+Maintained providers can attempt direct, UPnP, IPv6, relay and tunnel routes
+according to their runtime and configuration. Reachability depends on the
+environment and must be observed, not inferred from a running process or an
+advertised URL. Relay remains experimental. See the owning SDK's current
+operator guide and the [directory state semantics](docs/architecture/directory-state-semantics.md).
---
@@ -279,9 +287,16 @@ To propose a new intent, open an issue with the URN, domain justification, and e
## Node Discovery and Scoring
-The directory scores nodes server-side at query time. Clients receive a pre-sorted list and may only filter (remove `available=false` nodes or those with open circuit breakers).
+The directory returns an ordered, eligibility-filtered list. Hard policy,
+security, availability and required capability constraints cannot be bypassed
+by a ranker or fallback. Default clients preserve directory recommendation
+order. A declared supported selection Profile may reorder only the eligible
+set and must keep any local ranking value distinct from the canonical
+directory score. A ticket for one directory-selected route does not authorize
+provider substitution. See [selection semantics](spec/v1.9/iicp-semantics.md)
+for the scoped rules.
-**Phase 3 scoring formula** (currently deployed):
+**Historical Phase 3 scoring example** (not a current deployment claim):
```
score = 0.35 × availability_factor
@@ -297,16 +312,23 @@ See [iicp-semantics.md](spec/v1.9/iicp-semantics.md) for full term definitions.
## Security Baseline
-All IICP implementations MUST:
-
-- Use **TLS 1.3 minimum** for all inter-node communication
-- Validate `task_id` as **UUID v4**
-- Validate `intent` against `urn:iicp:intent:[a-z0-9:]+:v[1-9][0-9]*`
-- Validate `timeout_ms` in range **[100, 300 000]**
-- Never log or expose `payload` content
-- Return **structured errors only** — no stack traces, no filesystem paths
-
-See [conformance-test-suite.md](spec/v1.9/conformance-test-suite.md) SEC-* test IDs for machine-verifiable checks.
+Apply the security, identifier, size and error requirements of the named
+release, Profile and binding rather than treating this overview as a
+validation grammar. Directory control endpoints require production HTTPS;
+HTTP task endpoints require HTTPS in the coordinated stable/production scope,
+with only explicit development exceptions. Plaintext native TCP is
+development-only and outside that stable scope; QUIC remains future work.
+See [Core transport and security](spec/v1.9/iicp-core.md), the
+[directory scheme rules](spec/v1.9/iicp-dir.md) and the
+[conformance identifiers](spec/v1.9/conformance-test-suite.md).
+
+Registration credentials identify a provider to its directory. Discovery
+does not give an arbitrary consumer permission to execute: provider task
+authorization uses the applicable consumer credential or dispatch mechanism.
+The historical Phase 1 body `auth.node_token` and later header-based consumer
+authorization have different scopes. HTTP error envelopes, native errors and
+optional binding errors must be interpreted under their respective contracts;
+there is no universal README-only `IICP-Exxx` JSON rule.
---
@@ -319,7 +341,7 @@ the authority for published component versions. The additive
how public evidence can report deployment and adoption without treating either
as a synonym for publication.
-**Cooperative Inference and routing hardening (active)**
+**Implementation and qualification evidence**
The [iicp.network](https://iicp.network) directory is live and the client SDK
release line is recorded in the generated
@@ -330,31 +352,20 @@ encryption evidence change over time; consult the
[live stats page](https://iicp.network/stats) before treating any network
condition as current.
-The mesh is usable for its current capabilities, while relay hardening, broader privacy evidence and public federation remain separate maturity gates. Remote execution still means the selected provider can read the task it executes.
-
-| Feature area | Status | Notes |
-|---|---|---|
-| Core protocol — register / discover / route | ✅ Live | Current evidence is published on the live stats page |
-| CIP coordinator (multi-node dispatch) | ✅ Implemented | Credit receipts, response integrity verification |
-| Reputation scoring | ✅ Ratified | Tier structure (§5.1.1) + bootstrap floor (§5.1.2) ratified 2026-05-24 — normative |
-| Published SDKs (Python / TypeScript / Rust) | ✅ Published | The generated [current-version projection](ecosystem/CURRENT_VERSIONS.md) is authoritative for package versions |
-| Node runtime (`iicp-node`) | ✅ Published | Ships inside every SDK (`pip install iicp-client` → `iicp-node serve`) |
-| Relay transport for unreachable workers | ✅ Shipped (v0.7.56) | HTTP long-poll worker transport — browsers and CGNAT operators bind outbound to a relay-capable node; consumers route through path-scoped relay endpoints with zero client changes |
-| **Browser node** (WebGPU, zero install) | ✅ Live | [iicp.network/browser-node](https://iicp.network/browser-node) — runs a real model in the browser via WebLLM, queries the live mesh as an IICP consumer (with a wire-level connection console), and can serve into the mesh via a relay. First **directory-listed browser node** verified end-to-end on 2026-06-12 |
-| Browser-consumable nodes (CORS) | ✅ Shipped (v0.7.56) | Every node endpoint answers CORS preflights — any https-exposed node can serve web-page consumers directly |
-| Automatic NAT escalation incl. Quick Tunnel | ✅ Shipped (all 3 flavours) | Ladder: direct → UPnP → IPv6 → relay auto-election → zero-account Cloudflare Quick Tunnel fallback. Direct paths stay preferred; Quick Tunnel remains a low-friction bootstrap/fallback rather than a production availability promise |
-| Signed event log + compliance attestation | ✅ Live | Every registration/heartbeat/eviction in a cryptographically signed log (federation bootstrap source); signed compliance attestation endpoint |
-| Federation (Phase 6 groundwork) | 🟢 FED-READY-1 proven | Rust replica directory bootstraps from the PHP seed via snapshot + signed event tail |
-| Operator identity (Ed25519 delegation) | 🟢 Phase A live | ADR-045 — operators sign a delegation binding their Ed25519 key to each node; the directory verifies + resolves a public `operator_display_name` in discovery. `operator_pubkey` is directory-private, never served. |
-| Founder recognition | 🟢 Live | Time-gated founder ordinals (iicp-recognition §5.4) — #1 reserved for the maintainer, #2..N earned by genuine served nodes; dedicated non-federated signed chain |
-
-**IICP is currently in Beta. You can join and test it if its current scope fits your use case.**
-
-The mesh works end-to-end, the SDKs are publicly installable with full three-language parity, and a browser tab can both consume the mesh and (via relay) serve into it. Current maturation work includes:
-- A standing public relay (the transport is built and verified; one reachable host activates browser/CGNAT serving for everyone)
-- A portable operator identity wallet (so node identities survive machine changes)
-- Security and authentication hardening to production standard
-- Complete live SDK/key adoption and verified privacy receipts before strict fail-closed privacy wording
+The [implementation index](IMPLEMENTATIONS.md) distinguishes published SDKs,
+the deployed PHP Genesis line, the Rust directory operator preview, the
+experimental browser node and the optional Management developer preview.
+The [pre-1.0 feature boundary](pre1/README.md) describes the proposed stable
+qualification scope; it does not grant a stable designation. The
+[SDK evidence contract](SDK_QUALITY_EVIDENCE.md) and
+[release-candidate rules](RELEASE_CANDIDATES.md) define how results must be
+attributed. Same-project parity is not independent interoperability.
+
+The public mesh can be used within its observed capabilities, but relay
+hardening, privacy evidence and federation operation remain separate gates.
+The selected remote executor can read the task it performs. Check dated
+[live evidence](https://iicp.network/stats) rather than assuming a published
+feature is deployed or currently reachable.
Follow this repo or [iicp.network](https://iicp.network) for announcements.
@@ -382,7 +393,10 @@ but publishing it does not move production traffic or deprecate PHP. The three
SDK repositories provide consumer and provider runtimes; the browser-node
repository provides the experimental browser implementation.
-The protocol specification in this repository is the authoritative source for building interoperable implementations. Third-party implementations that conform to the spec (see conformance test suite) are fully compatible with the live network.
+This repository is authoritative for released interoperability semantics.
+Conformance must name a release, supported Profiles and bindings, environment,
+fixtures and retained results. It does not by itself prove compatibility with
+every current live-directory feature or deployment policy.
Directory implementations also share an implementation-neutral
[context and signed service-event ownership](docs/architecture/context-and-service-event-ownership.md)
@@ -443,14 +457,21 @@ or successor effort can preserve compatibility and release history.
---
-## Tools
+## Verification tools
+
+Start with the current [contribution checks](CONTRIBUTING.md), the
+[profile fixture contract](tools/run_profile_fixture_contract.sh) and the
+[public artifact closure check](tools/check_public_artifact_closure.py).
+The conformance runner and its supported Profiles are documented in their
+own [runner guide](conformance-runner/README.md).
| File | Purpose |
|------|---------|
| [tools/protocol_integrity_analysis.py](tools/protocol_integrity_analysis.py) | Analyses a spec file for internal consistency |
| [tools/quick_validation.py](tools/quick_validation.py) | Quick syntax + field validation against v1.4.2 |
-The simulation-oriented tools use optional scientific dependencies. Install
+The tools in the table above are historical analysis aids, not the current
+validation entry point. Their optional scientific dependencies can be installed
them in an isolated environment with
`python3 -m pip install -r tools/research-requirements.txt`. They are historical
research aids, not normative conformance or release gates.
diff --git a/SPEC_RELEASE_PROCESS.md b/SPEC_RELEASE_PROCESS.md
index dc2bae5..516b567 100644
--- a/SPEC_RELEASE_PROCESS.md
+++ b/SPEC_RELEASE_PROCESS.md
@@ -48,9 +48,9 @@ implementation worktree.
## Boundaries
-- Current executable behavior takes precedence over contradictory historical
- prose; record the discrepancy and correction rather than retroactively
- reinterpreting wire behavior.
+- Current executable behavior can expose a contradiction in historical prose;
+ record it and propose the correction. It cannot override a released
+ normative contract or retroactively reinterpret wire behavior.
- Registry entries require implementation evidence and payload/schema review.
- Base-frame changes require an independent compatibility, malformed-input,
and cross-implementation evidence package. Semantic profiles are preferred.
diff --git a/TERMINOLOGY_AND_DISCOVERABILITY.md b/TERMINOLOGY_AND_DISCOVERABILITY.md
index 4f6c53c..25b8bf3 100644
--- a/TERMINOLOGY_AND_DISCOVERABILITY.md
+++ b/TERMINOLOGY_AND_DISCOVERABILITY.md
@@ -14,8 +14,8 @@ The subtitle describes the control-plane role. It does not mean that IICP
defines every agent task format, identity system, transport, or runtime.
The current mechanism-level boundary is recorded in
[`standards/IICP_PROTOCOL_POSITIONING.md`](standards/IICP_PROTOCOL_POSITIONING.md)
-and the dated
-[`standards/PROTOCOL_COMPARISON_2026-08-15.md`](standards/PROTOCOL_COMPARISON_2026-08-15.md).
+with its dated
+[`September assessment`](standards/PROTOCOL_COMPARISON_2026-09-25.md).
## Term map
diff --git a/VERSIONING.md b/VERSIONING.md
index afee806..fa04bf5 100644
--- a/VERSIONING.md
+++ b/VERSIONING.md
@@ -8,7 +8,9 @@
**Format**: `MAJOR.MINOR.PATCH` (semver)
**Source of truth**: `spec/v1.9/VERSION` in the [`RobLe3/IICP`](https://github.com/RobLe3/IICP) spec repo
-**Displayed as**: `IICP v1.9.0` or `IICP Protocol v1.9.0`
+**Displayed as**: `IICP Protocol Suite v`; read the generated
+[`ecosystem/CURRENT_VERSIONS.md`](ecosystem/CURRENT_VERSIONS.md) before citing
+the latest published release.
**Changelog**: `CHANGELOG.md` in the IICP spec repo
This is the version that external implementers, operators, and IETF reviewers see. It covers
@@ -24,7 +26,7 @@ the entire IICP specification suite (core, CIP, framing, identity, telemetry, et
| v1.9.0 | 2026-05-30 | RT-01/RT-05 reputation caps and directory drift closeout |
| v1.9.1 | 2026-07-30 | Status/version governance and transport/IANA errata; superseded because its bundled implementation index was stale |
| v1.9.2 | 2026-07-30 | Corrective immutable release with synchronized implementation/package references and a version-truth gate |
-| **v1.10.17** | **2026-08-25** | **Current candidate** — binds existing pre-normative compatibility and security evidence without ratifying a Profile or changing the base wire |
+| v1.10.17 | 2026-08-25 | Published suite release; binds existing pre-normative compatibility and security evidence without ratifying every Profile or changing the base wire |
| v1.10.16 | 2026-08-20 | Outcome-v2 reputation semantics and retry-safe metrics acknowledgement; no base-wire change |
| v1.10.15 | 2026-08-20 | Restricted trust-domain semantic vectors and security-profile evidence; no base-wire change |
| v1.10.14 | 2026-08-15 | Compatible chat helpers default to the bounded runtime-identity context; raw submit and non-chat operations remain unchanged; no base-wire change |
@@ -69,7 +71,9 @@ which version of a sub-document contains which normative text.
**Rules:**
- Sub-spec versions are for editors. End users see the Protocol Suite version.
-- When displaying both: `IICP v1.10.17 · S.12 CIP v0.6.13` (suite first, sub-spec second)
+- When displaying both: name the published suite release and the applicable
+ sub-spec revision separately; do not present a working-main revision as a
+ published release.
- Never use a sub-spec version alone as "the" IICP version on public-facing surfaces
---
@@ -87,7 +91,8 @@ releases MAY implement the same OpenAPI version.
**Format**: `vMAJOR.MINOR.PATCH`
**Scope**: Each software component has its own version
-**Source**: `directory/config/app.php iicp_version` (directory service)
+**Source**: the owning component repository and its immutable package or
+release metadata; runtime self-reporting is separate deployment evidence.
The reference implementation version tracks software releases, not protocol releases.
A software version can be ahead of or behind the spec version (e.g., directory v1.10.x
@@ -97,9 +102,8 @@ implements Protocol Suite v1.9.0).
|-----------|----------------|----------|
| Directory (PHP Genesis) | Check `IMPLEMENTATIONS.md` and the release registry | Current Genesis implementation |
| Directory (Rust preview) | Check `IMPLEMENTATIONS.md` and the release registry | Official second flavour; operator preview |
-| Adapter (Python) | v1.x — check adapter/VERSION or pyproject.toml | |
-| Proxy (Python) | v1.x | |
-| Rust node | v0.x | `iicp-node/Cargo.toml` |
+| Consumer/provider SDKs | Check `IMPLEMENTATIONS.md` and each owning repository | Independently versioned Python, TypeScript and Rust releases |
+| Browser node and Management | Check `IMPLEMENTATIONS.md` | Experimental and developer-preview lines, respectively |
**Rules:**
- Never use the directory software version as "the" IICP version on public surfaces
@@ -128,10 +132,10 @@ be displayed as the Protocol Suite, OpenAPI or package version.
| Surface | What to display | Example |
|---------|----------------|---------|
-| Research page badge | Protocol Suite version | Use `spec/v1.9/VERSION` and label the axis |
-| Spec references in page body | Suite + sub-spec | `IICP v1.10.17 · S.12 v0.6.13` |
-| Implementation evidence | Software version | `directory v1.9.19` |
-| PR commit messages | Component + software version | `[directory] v1.9.19` |
+| Research page badge | Published Protocol Suite version | Use the generated release projection and label the axis |
+| Spec references in page body | Suite + sub-spec | Name each applicable release or revision separately |
+| Implementation evidence | Software version | Name the component, immutable release or commit and evidence date |
+| PR commit messages | Component + software version | Name the component and intended release only if one is actually being prepared |
| IICP repo CHANGELOG | Protocol Suite version | `## v1.7.0 — 2026-05-24` |
| Spec file headers | Sub-spec version | `**Version**: 0.6.13` |
@@ -145,29 +149,17 @@ be displayed as the Protocol Suite, OpenAPI or package version.
## 8. Version Update Procedure
-When making spec changes that warrant a version bump:
-
-```bash
-# 1. Update the IICP spec repo (via GitHub API or clone)
-# - Update spec/v1.9/VERSION
-# - Add entry to CHANGELOG.md
-
-# 2. Update the sub-spec document version header
-# - File: spec/iicp-cooperative-inference.md (or other sub-spec)
-# - Field: **Version**: x.x.x
-# - Add changelog entry in the document's own changelog table
-
-# 3. Update website badge
-# - File: website/app/research/page.tsx
-# - Badge: "IICP vX.Y.Z · Updated YYYY-MM-DD"
-# - Footer: "Spec: S.12 vA.B.C"
-
-# 4. Update directory software version (only when shipping directory changes)
-# - File: directory/config/app.php
-# - Field: iicp_version
-
-# 5. Update website asset version (only when doing a full website deploy)
-# - File: website/public/assets/json/version-info.json
-```
-
-The IICP spec repo version and the directory software version update on independent schedules.
+For a reviewed Protocol Suite release, update this specification repository's
+`spec/v1.9/VERSION`, `CHANGELOG.md`, applicable specification documents and
+release metadata through [`SPEC_RELEASE_PROCESS.md`](SPEC_RELEASE_PROCESS.md).
+Change a sub-spec revision only in the document that owns it; the `spec/v1.9/`
+directory name is the wire-compatibility lineage, not the suite version.
+
+Implementation, SDK package, browser-node, Management, directory and website
+versions are updated in their **owning repositories**, on their own release
+schedules. Use [`IMPLEMENTATIONS.md`](IMPLEMENTATIONS.md), the
+[`ecosystem` registry](ecosystem/repositories.json) and the owning repository's
+release procedure to locate those sources. Update this repository's generated
+ecosystem projection from its authoritative catalogue; do not edit copied
+component paths or imply a package or deployment changed because the suite
+version changed.
diff --git a/docs/agent-bootstrap.md b/docs/agent-bootstrap.md
index 3da6339..cc76f2a 100644
--- a/docs/agent-bootstrap.md
+++ b/docs/agent-bootstrap.md
@@ -6,8 +6,7 @@ registration, health and discovery; the selected agents exchange the task
directly.
For the boundary with IAIP, AIDIP, MCP, A2A and DNS-based discovery, read the
-[protocol positioning](../standards/IICP_PROTOCOL_POSITIONING.md) and
-[source-backed comparison](../standards/PROTOCOL_COMPARISON_2026-08-15.md).
+[current positioning and comparison entry point](../standards/IICP_PROTOCOL_POSITIONING.md).
The short version is that IICP selects an eligible provider; the selected
execution protocol defines how that provider performs the task.
@@ -30,12 +29,15 @@ rather than treating this protocol overview as an installation runbook.
`https://iicp.network`.
3. Express the requested capability as an intent URN, for example
`urn:iicp:intent:llm:chat:v1`.
-4. Discover eligible providers and apply the SDK's health, policy and
- confidentiality checks.
+4. Discover candidates and apply the SDK's non-overridable capability,
+ security, policy, health and confidentiality eligibility checks. Default
+ selection preserves directory recommendation order unless a declared
+ supported selection Profile permits reordering within the eligible set.
5. Obtain dispatch authorization when the directory requires it.
6. Send the task to the selected provider endpoint, not to the directory.
7. Validate the response or receipt. If the provider fails, rediscover or try
- another eligible result within the task's retry policy.
+ another eligible result only within the task's retry and route-authority
+ rules. A single-route ticket does not permit provider substitution.
Installation:
@@ -57,8 +59,9 @@ the specification.
source control.
3. Declare only the intents, models, limits and policy that the runtime can
serve.
-4. Register a routable endpoint, then send heartbeats at the required
- interval.
+4. Register a routable endpoint, then send heartbeats at the applicable
+ interval. Registration credentials authorize provider-directory control
+ operations; they are not arbitrary consumer execution credentials.
5. Keep health output consistent with registered capabilities. Remove a model
from registration when the runtime no longer exposes it.
6. Authenticate incoming tasks, enforce local policy and return structured
diff --git a/docs/architecture/decision-documentation-map.md b/docs/architecture/decision-documentation-map.md
index 537b5a5..5ab013c 100644
--- a/docs/architecture/decision-documentation-map.md
+++ b/docs/architecture/decision-documentation-map.md
@@ -31,6 +31,14 @@ operations, credentials, raw logs, and agent tooling do not.
| Identifiers and registry governance | [Identifier and registry architecture](identifier-and-registry-architecture.md) | Treat released identifiers as opaque, stable project identifiers without implying IANA assignment |
| Portability and independent continuation | [Portability and non-capture](portability-and-non-capture.md) | Explain how users can choose implementations and operate without a mandatory commercial control plane |
| Node health and third-party operator tooling | [Node observability interfaces](node-observability-interfaces.md) | Distinguish authoritative health, directory-reported state, local observation, and inference |
+| Management, policy and restricted domains | [Pre-1.0 feature boundary](../../pre1/README.md) and the [Management implementation](https://github.com/RobLe3/iicp-management) | Distinguish desired, accepted, observed and effective state; policy constrains eligibility but does not grant execution or override domain-local authority |
+
+Closed User Groups apply domain-local policy and eligibility; optional
+Management contracts coordinate desired and observed state above the protocol
+execution boundary. Local enforcement evidence must not be described as a
+deployed remote-administration service. Future Software Defined Intelligence
+proposals are research, not an additional released Core contract. For exact
+Management APIs or installation, use its owning repository.
## Publication rule
@@ -56,4 +64,3 @@ For each accepted or superseded decision, reviewers should ask:
- Does the guide link to the authority instead of copying unstable details?
- Are published, deployed, adopted, and experimental states kept separate?
- If a later decision replaced this one, are stale examples removed or clearly historical?
-
diff --git a/docs/audits/specification-documentation-truth-2026-09-25.md b/docs/audits/specification-documentation-truth-2026-09-25.md
new file mode 100644
index 0000000..4c0063f
--- /dev/null
+++ b/docs/audits/specification-documentation-truth-2026-09-25.md
@@ -0,0 +1,79 @@
+# Specification documentation truth ledger, 25 September 2026
+
+**Scope:** documentation and comparison, not a new Protocol Suite release or
+qualification decision. The clean local checkout and GitHub `main` were
+`2d240649cf8d11a235132658a599e22ebcba6620` at baseline. Published
+Protocol Suite `v1.10.17` points to tag commit
+`156e0260660f382e236ecb12477d785e131ec2d5`; its wire compatibility
+baseline is `v1.9.0`. Working `main` has later changes and must not be
+retroactively described as the published tag.
+
+The August [documentation audit](specification-documentation-truth-2026-08-11.md)
+and its closed [issue #128](https://github.com/RobLe3/IICP/issues/128) are
+historical evidence, not an open authorization to rewrite a release. The
+generated implementation and version projections derive from
+`ecosystem/repositories.json`; their numbers are not copied into this ledger.
+
+| File / section | Existing claim or gap | Class and authority | Correction and acceptance |
+|---|---|---|---|
+| `README.md` / opening | Fixed suite number beside working-main prose, without clear release boundary. | Confirmed editorial defect; `VERSIONING.md`, generated projection and immutable tag. | Link generated current projection; distinguish tag from main. Projection and integrity checks pass. |
+| `VERSIONING.md` / history | Published v1.10.17 called a current candidate; obsolete monorepo source paths presented as current component metadata. | Confirmed editorial defect; release and owning component repositories. | Label published release and use generated/owning sources. No version bump or tag rewrite. |
+| `README.md` / quickstart | Historical Phase 1 endpoints and error shape presented as general implementation instructions. | Confirmed scope defect; current Core, DIR, agent bootstrap and binding rules. | Replace with role paths, preserve Phase 1 compatibility link. No current quickstart relies on historical Phase 1 alone. |
+| `README.md` / JSON example | Incomplete task sample could be mistaken for a valid wire submission. | Confirmed example-applicability defect; named contracts. | Label conceptual and link executable examples; schema validation applies only to examples named as executable. |
+| `README.md` / selection | “Clients may only filter” conflicts with scoped optional selection Profile. | Confirmed contradiction; `iicp-semantics.md` §3.2. | State hard eligibility, default directory order, optional eligible-set ranking and single-route ticket limit. No client widening implied. |
+| `README.md` / security | Universal TLS, identifier-regex and error-envelope bullets flatten distinct bindings and exceptions. | Confirmed contradiction; Core §§3, 7–8 and DIR scheme rules. | Refer to binding-specific contracts, provider versus consumer credentials and production/development split. No improvised universal grammar remains. |
+| `README.md` / maturity | Undated “Live”, “Ratified”, federation and relay assertions mix publication, deployment and qualification. | Missing current qualification; implementation index, pre-1 baseline and dated live evidence. | Replace status table with bounded evidence links. No stable or independent certification inferred. |
+| `README.md` / SDKs and compatibility | “Conformant” and “fully compatible with the live network” exceed cited evidence. | Missing independent qualification; conformance runner and retained results. | Describe maintained reference implementations and scoped claims only. |
+| `schemas/task.json` / scope | Schema itself states Phase 1, while README listed it as general `IicpTask`. | Explicit legacy scope; historical Phase 1 schema. | Relabel its index entry; do not widen or reinterpret its validation. Successor schema, if needed, requires separate review. |
+| `spec/v1.9/README.md` / index | Path name and Phase 1 reading order can be read as the current full contract. | Confirmed navigation defect; `SPEC_STATUS.md` and role guide. | Explain compatibility lineage, role paths, Profile applicability and historical subset. Preserve path and anchors. |
+| `CONTRIBUTING.md` / checks | Two checks alone obscure the required CI validation path and local prerequisites. | Confirmed guidance gap; current workflows and fixture script. | Document isolated dependencies, required `validate` job and manual diagnostic workflow. |
+| `SPEC_RELEASE_PROCESS.md` / boundary | “Executable behavior takes precedence” could be read as permitting code to supersede released normative text. | Confirmed wording ambiguity; `SPEC_STATUS.md`. | Clarify that implementation evidence reveals discrepancies but cannot redefine an immutable contract. |
+| `docs/agent-bootstrap.md` / dispatch | Fallback text lacked explicit single-route ticket and non-overridable eligibility limits. | Confirmed clarification; selection and trust contracts. | Clarify without changing SDK behavior. |
+| `docs/architecture/decision-documentation-map.md` / Management | Optional Management/CUG authority and proposed remote administration lacked a concise navigation boundary. | Informative clarification; pre-1 crosswalk and Management owner. | Link owner; separate local policy enforcement from remote service and future SDI ideas. |
+| `standards/PROTOCOL_COMPARISON_2026-08-15.md` / status | Dated rows do not cover later individual drafts, DAWN state or REQ-1–17. | Historical material, not wrong for its date. | Preserve file; create dated successor and mark old machine-readable ratings historical. |
+| `standards/protocol-comparison-v1.json` / evidence | No current source-revision inventory or individual requirements mapping. | Confirmed data gap; IETF Datatracker and current IICP contracts. | Add compatible metadata and 17 rows; offline validator rejects omissions and unsupported dispositions. |
+| `standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md` / principal | Cites principal-binding `-06`, now superseded by `-07`. | Historical material; current Datatracker revision. | Preserve snapshot; dated update records revision and unchanged IICP boundary. |
+
+## Contract discrepancies retained for owning review
+
+The Phase 1 `body.auth.node_token` schema does not represent every later
+header-authorized consumer request; this is a scoped legacy contract, not a
+reason to remove `auth` from it. Exact-match IICP identifiers do not implement
+the Intent Routing draft's aggregated prefix-routing requirements. Optional
+selection does not permit substitution under a single-route ticket. These
+facts are documented here rather than repaired through an unreviewed schema or
+wire change. Existing standards and registry issues (#40, #55, #56 and #58)
+remain the appropriate review paths if a genuine interoperability requirement
+is later established.
+
+| Topic | Verified disposition |
+|---|---|
+| Standard/custom intents and `+modifier` | `iicp-semantics.md` §§1.2, 1.5 permits project and `x.` forms, but deprecates `+modifier`; unknown modifiers are rejected before dispatch. `schemas/task.json` is too narrow to validate every current form, so it remains Phase 1-scoped. |
+| Unknown required extensions | Use the applicable Profile's fail-closed rule; no README alias or universal ignore rule is added. |
+| QoS, priority and consensus | Core §3.1 includes `realtime`, task priority and optional consensus that the historical schema omits. This confirms legacy scope rather than permission to widen its schema. |
+| Timeout and task identity | Core §3.1 and `task-time-semantics.md` separate provider-attempt `timeout_ms` from caller wait; retries retain `task_id` but use a new attempt `call_id` under the lifecycle rules. No new idempotency semantics are created here. |
+| Routing versus execution constraints | Eligibility and ticket route binding are applied before dispatch; provider admission and task constraints remain separate checks. |
+| Errors and HTTP resource bounds | Core §§3.2 and 7–8 define binding-specific errors; working-main Core §3.2 supports bounded identity-encoded HTTP task requests/responses. These later working-main rules are not attributed to the older immutable tag. |
+| Conditional capabilities | Effective-capability architecture describes the complete serving path. A legacy capability projection does not establish support for every conditional field; no schema widening is made. |
+
+## Verification disposition
+
+The pre-edit checks for generated projections, pre-1 baseline, comparison
+dataset, release integrity and public-artifact closure passed. The first full
+profile run stopped because the host Python lacked the local conformance
+runner. After installing the repository requirements and runner in an isolated
+environment, the next run found two new canonical-intent source paths in the
+standalone PHP and Rust directory package-execution scripts. Their source
+classification was added without changing the registry or the intent's
+meaning. The final full profile fixture contract passed, including the
+extended comparison and review-bundle tests. The Phase 1 task-schema example
+and conceptual README JSON parsed successfully; generated projection,
+release-integrity and all-public closure checks passed. Strict prose had one
+advisory about README boldface density and no error.
+
+The working-main integrity manifest now pins the reviewed documentation,
+comparison, source-classification and validator changes. It is labelled a
+working-main review candidate; the published v1.10.17 tag and release assets
+were not changed. The pre-1 strict freeze remains **OPEN** with six component
+reviews, and no issue closure, PR merge, preparation or same-project parity
+result is counted as independent qualification.
diff --git a/docs/oia-application-matrix.md b/docs/oia-application-matrix.md
index a6a37a8..34af5ae 100644
--- a/docs/oia-application-matrix.md
+++ b/docs/oia-application-matrix.md
@@ -23,7 +23,7 @@ IICP also has bounded supporting presence in:
| L2, Sovereign Infrastructure | Self-hosted public, private and local control-plane designs without a mandatory commercial service | [Portability and non-capture](architecture/portability-and-non-capture.md), [restricted trust-domain Profile](../research/pre-normative-profiles/restricted-trust-domain-v0.md) |
| L3, Agent Data Substrate | Provider, capability, health and routing-evidence records; task payloads remain outside the directory | [Directory state semantics](architecture/directory-state-semantics.md), [privacy threat model](security/privacy-adversary-and-trust-model.md) |
| L5, Inference & Retrieval | Selection among eligible inference or retrieval providers; IICP does not define model internals | [Effective service capabilities](architecture/effective-service-capability-semantics.md), [protocol positioning](../standards/IICP_PROTOCOL_POSITIONING.md) |
-| L7, Orchestration & Workflow | Intent resolution, policy-aware eligibility, provider selection, route authorization and binding handoff | [Core specification](../spec/v1.9/iicp-core.md), [mechanism comparison](../standards/PROTOCOL_COMPARISON_2026-08-15.md) |
+| L7, Orchestration & Workflow | Intent resolution, policy-aware eligibility, provider selection, route authorization and binding handoff | [Core specification](../spec/v1.9/iicp-core.md), [current protocol positioning](../standards/IICP_PROTOCOL_POSITIONING.md) |
| L8, Continuity Fabric | Signed events, receipts, provenance and conformance evidence with explicit claim boundaries | [Conformance suite](../spec/v1.9/conformance-test-suite.md), [public evidence access](public-evidence-access.md) |
This mapping does not claim that IICP owns each layer. Models, agent runtimes,
diff --git a/registry/source-classification.json b/registry/source-classification.json
index 3c1e285..4d91bbc 100644
--- a/registry/source-classification.json
+++ b/registry/source-classification.json
@@ -919,6 +919,7 @@
"parity/dispatch-route-ticket-v1.json",
"parity/effective-capability-v1/fixture.json",
"parity/policy-detail-disclosure-v0.json",
+ "scripts/pre1_package_execution.py",
"scripts/seed_operator_benchmark.py",
"spec/proposals/fixtures/profile-compatibility-v0.json",
"tests/Feature/AddressObserverTest.php",
@@ -967,6 +968,7 @@
"parity/effective-capability-v1/fixture.json",
"parity/policy-detail-disclosure-v0.json",
"parity/profile-compatibility-v0.json",
+ "scripts/pre1_package_execution.py",
"src/db.rs",
"src/federation.rs",
"src/main_tests.rs",
diff --git a/spec/v1.9/IICP-core-phase1-profile.md b/spec/v1.9/IICP-core-phase1-profile.md
index 473484f..0d6e8f6 100644
--- a/spec/v1.9/IICP-core-phase1-profile.md
+++ b/spec/v1.9/IICP-core-phase1-profile.md
@@ -6,6 +6,13 @@
**Authority**: Protocol Steward
**Relates to**: SPEC_ANALYSIS.md §1 and §7, GitHub issue #13
+> **Historical compatibility scope:** This accepted Profile remains
+> authoritative for the original Phase-1, IICP v1.4.2-compatible subset and
+> its implementation evidence. It is not the current general implementation
+> quickstart. Start with the repository [README](../../README.md), the
+> [role-based guide](../../docs/agent-bootstrap.md), and the applicable
+> released Profile or binding for new implementations.
+
---
## Purpose
diff --git a/spec/v1.9/README.md b/spec/v1.9/README.md
index 425ce1c..48a2934 100644
--- a/spec/v1.9/README.md
+++ b/spec/v1.9/README.md
@@ -4,11 +4,13 @@
[current-version projection](../../ecosystem/CURRENT_VERSIONS.md) and
[CHANGELOG](../../CHANGELOG.md) for the labeled release axes and history.
-This directory contains the normative and informational protocol documents for IICP.
+This directory contains normative and informational documents with different
+applicability. The `v1.9` path preserves the wire-compatibility lineage; it
+does not mean that every document here was released as suite v1.9.0. Pin an
+immutable suite tag, then check each document or optional Profile's status.
Before interpreting IICP as a replacement for another agent protocol, read the
-informative [protocol positioning](../../standards/IICP_PROTOCOL_POSITIONING.md)
-and dated [adjacent-protocol comparison](../../standards/PROTOCOL_COMPARISON_2026-08-15.md).
+informative [current positioning and comparison entry point](../../standards/IICP_PROTOCOL_POSITIONING.md).
They separate IICP's intent-resolution and provider-selection role from MCP,
A2A, discovery inputs and transports.
@@ -16,14 +18,19 @@ A2A, discovery inputs and transports.
## Recommended reading order
-Start here when you are new to the protocol. Each document builds on the previous ones.
+Application developers should first use the [role-based agent guide](../../docs/agent-bootstrap.md)
+and their SDK's current API. Independent implementers should read Core,
+Directory, Semantics, then only the Profiles and bindings they declare. Node
+and directory operators should also use the owning implementation's guide;
+standards and security reviewers should start at the [architecture map](../../docs/architecture/decision-documentation-map.md)
+and [review guide](../../standards/REVIEWING.md).
| # | File | What it covers |
|---|------|----------------|
| 1 | [`iicp-core.md`](./iicp-core.md) | **Start here.** Wire format, message types (CALL/RESPONSE/INIT), mandatory fields, error codes (IICP-E001–E033), retry/idempotency rules, QoS hints. |
| 2 | [`iicp-dir.md`](./iicp-dir.md) | Directory sub-protocol — register, heartbeat, discover, probe endpoints; node token auth; observed-IP recording. |
| 3 | [`iicp-semantics.md`](./iicp-semantics.md) | Routing semantics, QoS, node selection, intent URN grammar (including `x.` custom namespace). |
-| 4 | [`IICP-core-phase1-profile.md`](./IICP-core-phase1-profile.md) | Accepted Phase 1 conformance baseline — the minimal implementation contract. |
+| 4 | [`IICP-core-phase1-profile.md`](./IICP-core-phase1-profile.md) | Historical Phase 1 compatibility subset, not the general current implementation contract. |
| 5 | [`iicp-service-lifecycle-profile.md`](./iicp-service-lifecycle-profile.md) | Proposed optional lifecycle profile — streaming, cancellation, retry, and idempotency. |
| 6 | [`iicp-provider-admission-profile.md`](./iicp-provider-admission-profile.md) | Proposed optional provider-admission profile — readiness, bounded capacity, and deadlines. |
| 7 | [`iicp-confidentiality.md`](./iicp-confidentiality.md) | IICP-CX — key advertisement, payload encryption, keyless-node refusal, relay opacity, and Tier-2 confidentiality targets. |
diff --git a/spec/v1.9/release-integrity-manifest.json b/spec/v1.9/release-integrity-manifest.json
index ea29334..11833c8 100644
--- a/spec/v1.9/release-integrity-manifest.json
+++ b/spec/v1.9/release-integrity-manifest.json
@@ -2,17 +2,17 @@
"files": {
".github/workflows/profile-fixtures.yml": "8f1cfdc2776186d223d54bc0dd0340bb2b2541d3b1b9b72facfe6a6ddb0fe83b",
"CHANGELOG.md": "92df54226f25a66907475a57b5b1c963e7876f69c3198f4136fc9fc17518455a",
- "CONTINUATION.md": "2d019aba2d7d084987506c356be52efc7e15d2b5afc14b5747bd4f89d591209f",
- "CONTRIBUTING.md": "4b4f82a12e8422e1105591781dc69e222734315fcb6ff78b074a20c2e52df7cb",
+ "CONTINUATION.md": "6165accd83f54700ed295f0915fc422fe4fcf6c7e9b3b95332ee4e5d85c230f9",
+ "CONTRIBUTING.md": "0aaaef4b008332bae150fd14ead0401ecc5bd22b8f65452e390fd934d0ec04f2",
"GOVERNANCE.md": "aaf2eaf1f31347ffdd8e9b9ec060618b3cbcac6f35fc773352cf0a3fd7475dcd",
"IMPLEMENTATIONS.md": "249935e100dc925ff7fe913df51762619beb39c2d827e685896ab474c043983d",
"LICENSE": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30",
- "README.md": "b2c724e5984514580f00fef58798f49509ec2facdf5ecd24aad9d9b698d56361",
+ "README.md": "221bc6bfd82e933eb07ce762864a4afc4d6db755dc7617e06a2148a024857fc0",
"SECURITY.md": "80eee7c221d025a92cab8aca82777e3bd89bfc9b267ea0aa6c9fbafb639c3ef3",
- "SPEC_RELEASE_PROCESS.md": "b028249056253cc1a6327b7c03910eedbe0267f97d44027f8560ccfc955bce8f",
+ "SPEC_RELEASE_PROCESS.md": "09b994a03a2e8c83e016bf6ede3d1d2edbed5b0abbe9908d933017c8786e3650",
"SPEC_STATUS.md": "90935da47e9a249aceb01213011b8aa4f031613b6d14a532da693005992025b4",
- "TERMINOLOGY_AND_DISCOVERABILITY.md": "0da32511c32a544dfa3ff6779477786933ba7c4b66eb241215cbf0299d259123",
- "VERSIONING.md": "032149108e10df11f31725161b5c9cfb35d7fe8a7619b68e85f39de2c0bf8249",
+ "TERMINOLOGY_AND_DISCOVERABILITY.md": "ab79681cb2cb9ac6631fb786bc7167fd3fa7df57c3d8b62a351bc5b465477efe",
+ "VERSIONING.md": "41600f2cff6cc3d836303969d34e6898046d3ac09e5c7ac596637ffe2766b6c4",
"conformance-runner/CLEAN_ROOM_IMPLEMENTATION.md": "3c228cb5306e52c522fe091e2cd9cfa6e1a5d6b6e17288c8f19c30051f4b99b8",
"conformance-runner/EXTERNAL_RUN.md": "2433568e64aab598f130062c20ebe2e5f7e1ccebd923c72a53d6c7d3649042e8",
"conformance-runner/LICENSE": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30",
@@ -30,7 +30,8 @@
"conformance-runner/src/iicp_conformance/runner.py": "05527fb44e9714d25cd25cf0ed7340b34b2f3c6b111890830ded3accacdb436c",
"conformance-runner/tests/test_runner.py": "f42a0758494607a60594fd63bd0dbf648bc9df6c07319f923d2b6f22ed25caf2",
"docs/ECOSYSTEM_VERSION_TRUTH.md": "8db6c18d0aad1d7edfcb6c8ac547180dad41de19a1fd24ed103dca423b085688",
- "docs/agent-bootstrap.md": "84e234870fd8ae1e70bf413fbe150b612985e0b4fbdfd862924b297d6ac9529a",
+ "docs/agent-bootstrap.md": "e62e9152d8c71d263529ffcff6ba074b901040327b108147bd4eddb660a7b270",
+ "docs/architecture/decision-documentation-map.md": "10e2ee5a231e9f5a984d5c535064623b0e222aafd3b50e4000f17fde05eabb59",
"docs/architecture/directory-state-semantics-v1.json": "45c5328611249b5346924e8603803b08db26db0af1fafba15d0a1774454db030",
"docs/architecture/directory-state-semantics.md": "cd36bbd4cf0119d558247eaf3685c5971722506d37bdf820f972b94eef5f73dc",
"docs/architecture/effective-service-capability-semantics.md": "8afeb2a854d0e6b58a2a8f52945b0155a2175a83c8fa7742cb2e330d7f2e161d",
@@ -45,9 +46,10 @@
"docs/architecture/portability-and-non-capture.md": "98f56e514014514fccdd4a12f685722b158416ef3a1836384d2732aaad0a2823",
"docs/architecture/task-time-semantics-v1.json": "4220ac57b0c874b4324a9df5ede50273c3be009f22fdb10ccf138cf561a68f69",
"docs/architecture/task-time-semantics.md": "8662999ee16a7a777ac420a1909c0c9f89eb60b430ce3fca4eb0f3caf10d9f49",
+ "docs/audits/specification-documentation-truth-2026-09-25.md": "8c61e093ab75b1f0a363019c651af37bff999407d717b70f53a220e011e816ef",
"docs/external-evidence-participation.md": "65a91e144bda38e77d7e2b3bfb247f84619a7668e110ad89ad99e65faa1ba5ae",
"docs/governance/public-artifact-boundary.md": "776b00e46e5e6645d32d10761fe24dcb488aff2a62f647df0eb58bf0fee9bea0",
- "docs/oia-application-matrix.md": "4db9d733cf6f3890005a826bd2cd26d0aa1c7a2ba5929bf5341fd151e5843d67",
+ "docs/oia-application-matrix.md": "8f3ab3aaf6d660e6e8e1653aff1a700be6aceabc53f5e81a45586f58a0a4eea6",
"docs/operator-onboarding-recovery.md": "1dbf10a2a46ef110e545871ccce0a5a8e63838c1f85acc53cbcb4c0dfb2c34b1",
"docs/security/privacy-adversary-and-trust-model.md": "3e6a44b880e5b429e5be978f358d9145bab66c8024e2f1e0106c51f92482ca38",
"ecosystem/CURRENT_VERSIONS.md": "97a555dd3c710be3d25a529412f993791e83c58d97477f8b4430b188f629131f",
@@ -92,7 +94,7 @@
"registry/schemas/safety-moderate-v1-input.json": "0df26d42bd9b96597e69397952af84a08fd60fd36a1963a31e1ca95368b63656",
"registry/schemas/safety-moderate-v1-output.json": "2ad76c1f4fbcff037c68e2478c737da7ca879d60917c52369c5c965339bbe1d5",
"registry/schemas/translate-v1-input.json": "197067000ec2acfeba9ab463c61d733008a302a4a836bebc5ba02eec228823e4",
- "registry/source-classification.json": "ef251a93d20926890cf12cf08fa93280edd05c39d10fc5433f89cf9341e74b3a",
+ "registry/source-classification.json": "63706659a0fb14ff4b06040f8e4e384617327bb69a6d063133e4bf126db46f02",
"research/RESEARCH.md": "323dd757c9871aba21bf5933715ee746745fbecfc615d709f046deca7a6b58c5",
"research/native-ai-infrastructure/fixtures/native-framing-fixture-manifest-v1.json": "21ce99931b3e4b9a07bdadb70432c0c8a064497fe4b654c566b77f04378b3ccb",
"research/native-ai-infrastructure/fixtures/native-framing-v1.json": "02cc7bfbd3c238191ca3961aa03d09f143a51a43397e056d496977e5a9bf0471",
@@ -150,8 +152,8 @@
"schemas/samples/ecosystem-version-truth-stale.json": "a6758fc0a4d11f73878c47206ff869437ae219465cb3a15ad9a9749177d3c744",
"schemas/samples/ecosystem-version-truth-unavailable.json": "a2733b9f33ad68e9b36f555243ce87d4e47e4999a7fed23ef314bc84d6c0c94c",
"schemas/task.json": "adf60dd8670658904cd853239633cd1f36e9d1acbfa526dd62d31c4cbe31e61e",
- "spec/v1.9/IICP-core-phase1-profile.md": "59b8096b20358b5c5272c92726779d04896d49ed8ef7668b1dc0fd321fc947c3",
- "spec/v1.9/README.md": "cc772c76899fac209798fe78404ff1c05222a0a68d0f2d2cecd11c566951d217",
+ "spec/v1.9/IICP-core-phase1-profile.md": "6b06066c278fd2cb5509ab59c96cc7827264ef8f4b580eb1c755040a46d9b5a9",
+ "spec/v1.9/README.md": "e2cbe7ede14494392890354edb8a500d5de85e63f6099df297d62802d625e0fb",
"spec/v1.9/VERSION": "d2d98e986183e9995b2f59dcb713b69d886f478477ed8ec6fad703adbd7f3e26",
"spec/v1.9/conformance-badges.md": "1837103fa0f19f825413869a1d2415b3122afca09b0b58511ddef5dc5b1df05d",
"spec/v1.9/conformance-test-suite.md": "ddef908cdd00444967e2a6eacbb3d840c41c2cf6f359ff3923ed7fb73eacd766",
@@ -179,25 +181,27 @@
"spec/v1.9/replica-lifecycle-contract-v1.json": "9ae2e3536891c3488a2b4d04e543364359a2b9a2c389203ece0eaca1a341b541",
"spec/v1.9/validation-methodology.md": "78693a12a47ed74e72db6b27d23e956bca9a00544ab8637ebebeeb827e39f635",
"standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md": "b4627f036f266c86a8287d7414fd76badd3495158fd156cdc7fc55216e30e65a",
- "standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md": "15962ed454462f18e1991547cc4e1e57bc673e48191ca2bc246e3b8e4455cbfb",
- "standards/IICP_PROTOCOL_POSITIONING.md": "7f6eda683482750b53eeae074c959faef48008b69bf15d480747754f88a7dd21",
+ "standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md": "a9d38216adcbcd4d166652523a2e3beee051944d3d5dbf936e52543271d4748f",
+ "standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md": "b7f10cdf8bdcbd1b79375d0c31a4683c36f95b324f3401fb40f79b1d3bc192af",
+ "standards/IICP_PROTOCOL_POSITIONING.md": "b08fc139aaba9acd8d877c74bd00b5594f4f8442708789316f4c554f28e4ae93",
"standards/PROTOCOL_COMPARISON_2026-08-15.md": "9a6dca24f8001943e7e0a242dae736d582b42f440ecb6f3ef2c2c80da48e2445",
- "standards/REVIEWING.md": "9ea3a91be77a5ddc794fc5c77582d63751bab8ed8a3f6afe33e5627e6fd98971",
+ "standards/PROTOCOL_COMPARISON_2026-09-25.md": "6b679cf2e3c1a217fb65f0d4709e5de05f3c133a4c4fc53506e761cb1a14b94a",
+ "standards/REVIEWING.md": "5c9ac5196373c5f27d0b5f5ab33d47a2b489c8c791babf1ad706218250e95381",
"standards/SECURITY_PRIVACY_OPERATIONAL_CONSIDERATIONS_2026-08-13.md": "4b6f59bf2ba6d8049404cc97a0fe420b68a751d62589162fdd127e0db7e84962",
"standards/SELECTION_CANDIDATE_ADVERSARIAL_REVIEW_2026-08-21.md": "b3b9f5d6f342bbf616c5d2c8611184d21b325d3c88009bc75c8e71780965ab40",
- "standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md": "e4c0e85475d1d86201062af83f884f1b92d5f595cab45f6276316572a154901e",
- "standards/SELECTION_REVIEW_BUNDLE_README.md": "4fd5f1642f72aed05dde35dc5e88603124e06225ab0100ebff810172ec345260",
+ "standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md": "8a6ffd8731f4ece12971950f05b9593af8f65490f88ea1c833f4383f21d33afe",
+ "standards/SELECTION_REVIEW_BUNDLE_README.md": "037ae6ebd02305d729fd092ebf76f4d84428d44ed4b6ae6d6ea901c81d76a52e",
"standards/SELECTION_TRUST_AND_REVALIDATION.md": "a41396934bbb3588ea4c857e1c60af1d227ca6dfdda08b5416d4b5b615f6d657",
"standards/STANDARDS_READINESS.md": "6ac5166c32ce7b5b2df83110717c560817096a174061acad2ee1c0ac7f298c25",
"standards/SUBMISSION_GOVERNANCE_DECISION.md": "ded4b83c2c2ce76a3d2a973bfc36cf689f056c14c26b2ec74076526c349f3d79",
"standards/TRANSPORT_BINDING_AND_PORT_DECISION_2026-08-21.md": "db12730b8c0cf1eaf0cb695f47880201566dae0f5e2a652c06be7ac6d06d63fe",
- "standards/protocol-comparison-v1.json": "345eba31ded0728717524d747761c63e9ca612cad1075c99baea6960308a18c0",
+ "standards/protocol-comparison-v1.json": "60489fdd70b723927e76564464ebb7a7c371486191b779c7ea283e233f23cf61",
"standards/security-considerations-coverage-v1.json": "c917c578a146cc2feaf6c2e8a0c73259646065f480d00fff2c78e7a8282cbdce",
"standards/submission-governance-decision-v1.json": "310b377519cddebdf0e904bba895df32449a94ecb6950dbddbcd8656b6207409",
"tools/README.md": "4786a2353cfa698646c8fa1b16cdf08884c581139fe0ce85ad390962dad75b98",
"tools/audit_intent_sources.py": "ddd871d23fa2687d1c4bc575e0e3c6a22461474a5ecb9406300d4607c3a9bebe",
- "tools/build_selection_review_bundle.py": "c353a3b7ad5785612b6d570c2f6290ef020f374d56fbc4c136c45ad4d017f7e8",
- "tools/build_standards_review_bundle.py": "7ccd589fb4e22dce8e9ff27ffeadb3ac57f6fda97b9dae7243eaada7085599c7",
+ "tools/build_selection_review_bundle.py": "a9b987c95729ac12ecd91d877211f3fa51337e2b4e706905402a4c9c400d84c3",
+ "tools/build_standards_review_bundle.py": "a94e4d0888f918ee20d582e4c7efa48ae7dbb06ed7e4c533983da87b1cb59e7d",
"tools/check_clean_room_interoperability_record.py": "eed5d9a0d5eba295a3e7d5069cad2b526dad5983d3c82dc8a84cc1be1c3510f5",
"tools/check_compatibility_environment.py": "9248a9297ff23058199081d68d9f1a822a29c8bdb1f4c7548978ce6ede27a9de",
"tools/check_conformance_version_truth.py": "74feac0c41759115108cccea2498cc736dd2cf481239daada860a20009bbbc91",
@@ -211,7 +215,7 @@
"tools/check_newcomer_validation_record.py": "4cf42b3059a82066c7276f69be11b991994280d58e9799eebcddc0fc661cacd9",
"tools/check_operator_onboarding_recovery.py": "c7b8023b918a3ba936b4dbd7f41760b6d2f798daa399140b335ff0f63b0a5536",
"tools/check_profile_security_candidate.py": "505afe261598c302ebef4f743f0ba45eef6c7e401c5f80c1ce0c7f5239e3d9e9",
- "tools/check_protocol_comparison.py": "e82158f12f8ce9a25503102f7495c0013637f45783f12bbe8c872e206b48ce9e",
+ "tools/check_protocol_comparison.py": "d6dc24b91b2d7de2337d8f93ff51f36f359597661cc730788a0af1f1b29a15a0",
"tools/check_public_artifact_closure.py": "90ed34ea1cded5bc6f53252a76554319ca0c2e82f194f00652f9e11bab42b015",
"tools/check_public_evidence_access.py": "11dbe24705404e73ebe9fddb54f22bcd5facd977a06e374f8718bebd87fa60f5",
"tools/check_public_prose.py": "4b0fa3becd2c71af7a1a89d72f971988bc019acc3917d7d59b8ead2fafe94657",
@@ -219,10 +223,11 @@
"tools/check_runtime_health_fixture.py": "e8f89075b1803e697db457966f7384cb555bf10c020c5e10ffb47d39239d99e4",
"tools/check_security_considerations_coverage.py": "182d29f056e1e396d3331a1d1bac66d28d83bb4acf6beb4c785dc16c5acaccfe",
"tools/check_signed_message_envelope_boundary.py": "6ff4228e34408681bdcc4485d3470b9a86b7f7b4a4fd5bbf56e830e2fcc53c5b",
- "tools/check_spec_release_integrity.py": "a16ce4475c181aebdf00bac107a0bf02d616f4c1e9a67faf4f411843722da7c3",
+ "tools/check_spec_release_integrity.py": "b82117776fc3a16ae41e78b7571698ed4442d880b9cb9d5e65b36310b34eab8c",
"tools/check_submission_governance_decision.py": "a249100bf6c2836ea01ceee353fa5c139ecbe0f0b280fe250a86d11137dde9cd",
"tools/manage_release_closure.py": "758c6a3371d032224cc6cf023f280cf4e4380e615898ab3f007413ee433c6680",
"tools/requirements.txt": "c0134412c5344bebbcef0bbe0cd3ed6f94f984f3cf990bb5c9a0ce79123c9e02",
+ "tools/run_profile_fixture_contract.sh": "0832e7007a69529c610bd7102a1c8be94bf53203c09ed83debdec446a6f450bf",
"tools/test_audit_intent_sources.py": "8286e32879fcf48647f00facc8bca1fbf9a460393e9fc607e50440cd1fae063f",
"tools/test_clean_room_interoperability_record.py": "2f2cc274dfb5e9503b0d24d91bc5ee2e1878301c464ad3ff65d9afaa267a847b",
"tools/test_compatibility_environment.py": "c5cfb6c4bda7002b500f5b727c4ebd6bcf96052aef5ae8fefd902daf0ed324c8",
@@ -245,7 +250,7 @@
"tools/test_node_observability_contract.py": "f22c490c5ab3e0990b6175f509aad9a061eaf97e951493f5ad859904ead1d00b",
"tools/test_operator_onboarding_recovery.py": "ffd287d990e212ef476740f769159b2c12e8d91654542e21ca369fcd0f57e005",
"tools/test_profile_security_candidate.py": "cc9dcb233cd29c17c831a314748b83878948ffeeea044df47c8a6741124da12f",
- "tools/test_protocol_comparison.py": "691081f33110dd7b516c0da7794cad5a5436b9ec7ed4c88dd4389e070ae6a785",
+ "tools/test_protocol_comparison.py": "0f41b65d336c8d72b3fd30acb73ccc2cdfa1d1a47cc3e7beb2752e055d0c2fb5",
"tools/test_public_artifact_closure.py": "8670e18a3bc5336a1d2e3e012950946674a09e0589cbad2bfc133751b34785e3",
"tools/test_public_evidence_access.py": "44074627fe15a527f339e5d45c233b33b1393310469a59c9bfb92cc3514a4ee1",
"tools/test_public_prose.py": "39f8488525192780a4cabda0c3b5641208fb7b27c66044bd464693e740fc505f",
@@ -258,15 +263,15 @@
"tools/test_runtime_health_fixture.py": "fabb3f602238453ba476506734824a11e986391e140dfb5fd91968c6ab218207",
"tools/test_runtime_identity_context.py": "a738d6275a668609226ca563a8a6d8d73f0ce65703a62a7b6e3ad0b40f646584",
"tools/test_security_considerations_coverage.py": "aed836fde7c7f0dd517d0275090f7d4dd226451388690dd40038b4ecb23afd5f",
- "tools/test_selection_review_bundle.py": "56f5aaa11324229f8174ef243cac03bc68fec46c97392e4e19a68721345b5074",
+ "tools/test_selection_review_bundle.py": "d7e4b75923b209a7eca782cb8756589e87f1837caf893658a6fb0c706784f98e",
"tools/test_service_lifecycle_fixture.py": "95bac952af648bf78ba86e67bd2b70a309b156dedd411fc0d3ef9e1d760b070c",
"tools/test_signed_message_envelope_boundary.py": "8519856e2bfe5eb7850f1b598df27d06563a7389cb4052750bb77d82afc78f60",
- "tools/test_standards_review_bundle.py": "ae38c593d7b3b255353deb8048a31f68184e6b25fdcb8fe61c62387905153fee",
+ "tools/test_standards_review_bundle.py": "d5af4a2fe94e7569117e48a3a2305418a23337a13402f7fec233121b6c0b8d24",
"tools/test_submission_governance_decision.py": "d89a8a27a67e5c3daa0cfeed0fc61d1fbfe827787c8152dde9443713c05e8547",
"tools/test_task_time_semantics.py": "f7f9d9eb4e6798f7691831726c425483840ea543c4f14321db63087890ddf53e"
},
"manifest_version": "1.9.0",
"protocol_suite_version": "1.10.17",
"registry_version": "1.4.0",
- "status": "immutable canonical release candidate"
+ "status": "working-main review candidate; published v1.10.17 tag remains immutable"
}
diff --git a/standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md b/standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md
new file mode 100644
index 0000000..749f025
--- /dev/null
+++ b/standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md
@@ -0,0 +1,25 @@
+# Security, session and receipt crosswalk: September 2026 update
+
+**Verified:** 2026-09-25
+**Status:** informative; no protocol adoption or implementation decision.
+
+The [21 August crosswalk](EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md)
+remains a dated snapshot. The current Datatracker revision of the
+[Security Principal and Verifier Binding draft](https://datatracker.ietf.org/doc/draft-bu-agentproto-security-principal-binding/07/)
+is `-07` (2026-09-15), rather than `-06`. Its expanded verifier, dependency
+and negative-case treatment reinforces the same IICP review question: each
+identity, membership, route-authority and receipt claim needs an issuer,
+carrier, verifier, freshness condition and failure behavior. It does not
+merge those claims into one IICP credential or make the draft an IICP dependency.
+
+The checked [Agent Session Requirements](https://datatracker.ietf.org/doc/draft-feng-agentproto-session-requirements/02/)
+remain at `-02` (2026-08-20), and the checked
+[SCITT agent-action receipt profile](https://datatracker.ietf.org/doc/draft-noa-scitt-ai-agent-receipt/01/)
+remains at `-01` (2026-08-15). Discovery and policy-constrained selection
+precede any optional session; a receipt remains evidence of its issuer's
+bounded claim, not proof of task correctness. These are individual drafts,
+not an adopted session or receipt standard for IICP.
+
+No released IICP field, profile, ticket or receipt changes as a result of
+this source update. A future mapping needs a concrete cross-implementation
+use case, compatibility review and executable vectors.
diff --git a/standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md b/standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md
index 9ece65d..5cfb31e 100644
--- a/standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md
+++ b/standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md
@@ -4,10 +4,10 @@
submission, or a compatibility claim. Individual Internet-Drafts are work in
progress, not IETF endorsement.
-> This dated baseline is preserved for decision history. The current comparison
-> is [`PROTOCOL_COMPARISON_2026-08-15.md`](PROTOCOL_COMPARISON_2026-08-15.md),
-> with a short reviewer introduction in
-> [`IICP_PROTOCOL_POSITIONING.md`](IICP_PROTOCOL_POSITIONING.md).
+> This dated baseline is preserved for decision history. For current guidance,
+> use [`IICP_PROTOCOL_POSITIONING.md`](IICP_PROTOCOL_POSITIONING.md) and its
+> linked assessment. The [15 August comparison](PROTOCOL_COMPARISON_2026-08-15.md)
+> is another historical snapshot.
## Narrow problem statement
diff --git a/standards/IICP_PROTOCOL_POSITIONING.md b/standards/IICP_PROTOCOL_POSITIONING.md
index 01ea962..3bb0125 100644
--- a/standards/IICP_PROTOCOL_POSITIONING.md
+++ b/standards/IICP_PROTOCOL_POSITIONING.md
@@ -1,6 +1,6 @@
# IICP protocol positioning for reviewers
-**Evidence date:** 2026-08-15
+**Evidence date:** 2026-09-25
**Status:** informative project material; not an IETF submission or endorsement
## The narrow problem
@@ -44,13 +44,16 @@ semantics in its Core.
## Where the overlap is real
-Current individual Internet-Drafts such as IAIP and AIDIP also cover
-capability advertisement, intent-aware discovery, candidate matching and
-selection. This is direct overlap, not a naming difference. The question for
-review is whether IICP's combination of effective service capabilities,
-caller-visible policy eligibility, content-minimized directory operation and
-short-lived dispatch authorization forms a useful separable contract, or
-whether those parts should converge with adjacent work.
+Individual Internet-Drafts such as [IAIP](https://datatracker.ietf.org/doc/draft-sz-dmsc-iaip/02/)
+and [AIDIP](https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/02/)
+also cover capability advertisement, intent-aware matching and selection.
+IAIP also filters mandatory constraints before ranking; that sequence alone
+is not IICP's differentiator. [CIRP](https://datatracker.ietf.org/doc/draft-verma-cirp/02/)
+has scoped discovery and session authorization but leaves ranking outside its
+scope. The [DAWN proposed charter](https://datatracker.ietf.org/wg/dawn/about/)
+focuses on initial discovery and excludes semantic matchmaking and selection.
+These are distinct design boundaries, not proof of interoperable wire formats
+or of one project's superiority.
## The smallest interoperability claim
@@ -79,15 +82,20 @@ profile applies.
## Current evidence and limits
-IICP publishes a specification suite, two directory implementations, three
-SDK families, a browser implementation, fixtures and a conformance runner.
+IICP publishes a project-normative beta suite, two directory implementations,
+three SDK families, an experimental browser implementation, optional
+Management preview, fixtures and a conformance runner. The
+[generated version projection](../ecosystem/CURRENT_VERSIONS.md) names current
+component releases; the [pre-1.0 boundary](../pre1/README.md) is not a
+completed qualification result.
Most are maintained by the same project. Their agreement is parity evidence,
not independent interoperability or standards adoption. The native peer draft
is an unsubmitted individual-draft candidate. `urn:iicp:` identifiers and port
9484 have no IANA assignment.
-For the feature comparison, per-dimension evidence-maturity ratings, chronology
-and primary sources, read
-[`PROTOCOL_COMPARISON_2026-08-15.md`](PROTOCOL_COMPARISON_2026-08-15.md). The
-same dated facts are available as
-[`protocol-comparison-v1.json`](protocol-comparison-v1.json).
+For the current dated source inventory, bounded role comparison and individual
+REQ-1–17 analysis, read the
+[25 September assessment](PROTOCOL_COMPARISON_2026-09-25.md). The
+[15 August assessment](PROTOCOL_COMPARISON_2026-08-15.md) remains historical;
+its per-dimension maturity ratings have not been silently refreshed. The
+[machine-readable comparison](protocol-comparison-v1.json) marks that limit.
diff --git a/standards/PROTOCOL_COMPARISON_2026-09-25.md b/standards/PROTOCOL_COMPARISON_2026-09-25.md
new file mode 100644
index 0000000..3525702
--- /dev/null
+++ b/standards/PROTOCOL_COMPARISON_2026-09-25.md
@@ -0,0 +1,106 @@
+# IICP and adjacent IETF work: September 2026 assessment
+
+**Verified:** 2026-09-25
+**Status:** informative project analysis, not an IETF position, endorsement,
+interoperability certificate or change to the IICP Protocol Suite.
+
+This supersedes the *current-state* rows in the
+[15 August comparison](PROTOCOL_COMPARISON_2026-08-15.md), which remains an
+unaltered historical snapshot. Source revisions, dates and the requirement
+mapping also appear in [`protocol-comparison-v1.json`](protocol-comparison-v1.json).
+Individual Internet-Drafts are work in progress. The [DAWN group page](https://datatracker.ietf.org/wg/dawn/about/)
+described a **proposed** working group and draft charter at verification time,
+not an adopted WG specification. An intended Standards Track label is not
+IETF adoption.
+
+## Sources and roles
+
+| Work and primary source | Revision/date checked | Formal standing and relevant scope |
+|---|---|---|
+| [IAIP](https://datatracker.ietf.org/doc/draft-sz-dmsc-iaip/02/) | `draft-sz-dmsc-iaip-02`, 2026-05-25 | Individual I-D; agent-gateway registration, constraint filtering, ranking, selection and forwarding (§§6–8). |
+| [AIDIP](https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/02/) | `draft-cui-ai-agent-discovery-invocation-02`, 2026-07-06 | Individual I-D; agent discovery, optional intent-aware candidate selection and invocation. |
+| [CIRP](https://datatracker.ietf.org/doc/draft-verma-cirp/02/) | `draft-verma-cirp-02`, 2026-08-10 | Individual I-D; scoped capability discovery, authorization tickets, peer sessions and receipts; ranking is outside scope (§§1, 6–10). |
+| [Intent Routing Requirements](https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/) | `draft-feng-dmsc-intent-routing-requirements-00`, 2026-08-14 | Individual requirements I-D; REQ-1–17 in §3, not an implemented routing protocol. |
+| [DAWN](https://datatracker.ietf.org/wg/dawn/about/) | proposed charter `charter-ietf-dawn-00-07`, checked 2026-09-25 | Proposed WG; initial naming/discovery, excluding semantic matchmaking, ranking and selection in the proposed charter. |
+| [DNS-AID](https://datatracker.ietf.org/doc/draft-mozleywilliams-dnsop-dnsaid/02/) | `draft-mozleywilliams-dnsop-dnsaid-02`, 2026-05-27 | Individual I-D; DNS-based discovery of connectivity and capability-document references. |
+| [DMSC architecture](https://datatracker.ietf.org/doc/draft-li-dmsc-architecture/01/) | `draft-li-dmsc-architecture-01`, 2026-05-29 | Individual architecture I-D; compare domain boundaries and architecture, not an adopted DMSC standard. |
+| [DMSC information architecture](https://datatracker.ietf.org/doc/draft-li-dmsc-inf-architecture/07/) | `draft-li-dmsc-inf-architecture-07`, 2026-05-22 | Individual architecture I-D; an additional DMSC context source, not an implementation result. |
+| [AIPF](https://datatracker.ietf.org/doc/draft-zahed-agent-comm-framework/01/) | `draft-zahed-agent-comm-framework-01`, 2026-07-19 | Individual framework I-D; broader communication-layer architecture. |
+| [IACP](https://datatracker.ietf.org/doc/draft-gebauer-iacp/03/) | `draft-gebauer-iacp-03`, 2026-07-28 | Individual I-D; broader agent communication architecture. |
+| [Agent Routing Policy](https://datatracker.ietf.org/doc/draft-ahuja-agent-routing-policy/00/) | `draft-ahuja-agent-routing-policy-00`, 2026-09-17 | Individual I-D; policy grammar for inter-domain delegation, not evidence of a deployed policy engine (§§4–5). |
+| [Agent Session Requirements](https://datatracker.ietf.org/doc/draft-feng-agentproto-session-requirements/02/) | `draft-feng-agentproto-session-requirements-02`, 2026-08-20 | Individual requirements I-D; session establishment after discovery. |
+| [Security Principal Binding](https://datatracker.ietf.org/doc/draft-bu-agentproto-security-principal-binding/07/) | `draft-bu-agentproto-security-principal-binding-07`, 2026-09-15 | Individual guidance I-D; claim, carrier, verifier and freshness boundaries. |
+| [SCITT agent action receipts](https://datatracker.ietf.org/doc/draft-noa-scitt-ai-agent-receipt/01/) | `draft-noa-scitt-ai-agent-receipt-01`, 2026-08-15 | Individual profile I-D, not an adopted SCITT WG result; action-evidence export may be complementary. |
+
+[MCP](https://modelcontextprotocol.io/specification) and
+[A2A](https://a2a-protocol.org/latest/specification/) remain complementary
+execution and integration protocols in this comparison. They are not IETF
+initiatives by association. The source inventory records document metadata,
+not an exhaustive search for external implementations; absence of a link in a
+draft cannot establish that none exists.
+
+## Responsibility comparison
+
+| Dimension | IICP evidence and limit | Adjacent work and boundary |
+|---|---|---|
+| Intent and capability | Released project intent registry and effective-capability rules; identifiers are exact, opaque project values, not Internet-scale prefix routes. | IAIP/AIDIP overlap intent matching; CIRP has versioned capability identifiers; DNS-AID can supply discovery input. |
+| Required constraints, freshness and eligibility | Directory and client apply hard constraints before any optional ranking; current state and provenance must be revalidated. | IAIP also filters before ranking, so that ordering alone is not a differentiator. DAWN's proposed scope stops at initial discovery. |
+| Ranking and selection | Default directory order is preserved absent a declared selection Profile. A local ranker cannot widen eligibility or overwrite directory score. | IAIP ranks; AIDIP can rank candidates; CIRP deliberately returns unranked discovery. |
+| Route and endpoint authority | Discovery is not execution permission; single-route IICP dispatch tickets bind one eligible route, and endpoint authentication remains binding-specific. | CIRP ConnectTickets authorize a different session process. Shared terminology does not imply equivalent claims or wire compatibility. |
+| Payload path and lifecycle | The Directory is a control plane; the selected executor receives task content directly via the chosen binding. Native TCP is not in the coordinated stable baseline and QUIC is not implemented. | IAIP includes both direct-execution and gateway-forwarding descriptions; compare the path in the cited procedure. MCP/A2A own their execution lifecycles. |
+| Domains and policy | Optional restricted-domain/CUG and Management work constrain eligibility while retaining domain-local authority; remote administration is not a deployed Core feature. | Agent Routing Policy proposes a grammar; DMSC work explores domain architecture. Neither is proof of deployed enforcement or interoperable federation with IICP. |
+| Security, privacy and receipts | IICP publishes purpose-specific trust, ticket and receipt contracts and same-project fixtures. The chosen remote executor sees the task it performs. | Session, principal-binding and SCITT work offer possible crosswalks, not implicit IICP dependencies or proof of confidential execution. |
+| Implementation and compatibility | Published Python, TypeScript and Rust SDKs; PHP and Rust directory flavors; experimental browser node; optional Management preview. Evidence is mostly maintained by one project. | Architectural overlap is not demonstrated wire interoperability. Independent clean-room IICP implementation and cross-project conformance remain open evidence. |
+
+The IICP selection contract is most useful when a caller must choose among
+heterogeneous providers using current capability, policy, security and route
+evidence. It does not replace initial naming, session protocols or execution
+bindings. The exact-match `urn:iicp:` identifier design does **not** establish
+prefix aggregation or bounded Internet-wide routing state.
+
+## Intent Routing Requirements mapping
+
+The following labels are analytical, not qualification results. Source is
+[`draft-feng-dmsc-intent-routing-requirements-00` §3](https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/).
+`ALIGNED` means the cited IICP contract addresses the stated property in its
+declared scope; it does not mean that Internet-scale operation is measured.
+
+| REQ | IICP contract and evidence class | Disposition and missing evidence |
+|---|---|---|
+| 1 Open Participation | Core/DIR registration and published SDKs; project implementation evidence. | **PARTIAL** — public-mesh admission exists, but unrestricted Internet participation and independent implementations are not established. |
+| 2 Heterogeneous Handlers | Intent and effective-capability contracts plus SDK/provider adapters. | **ALIGNED** in the supported binding scope; arbitrary handler classes are not separately qualified. |
+| 3 Control/Data Separation | Core/DIR direct payload path and directory fixtures. | **ALIGNED** for supported paths; performance independence is not inferred from architecture alone. |
+| 4 Bounded State | Federation snapshot/event-tail design. | **NOT_ESTABLISHED** for any single node at Internet scale; directory state may grow with registrations. |
+| 5 Capability Aggregation | Effective-capability and directory discovery contracts. | **DIFFERENT_DESIGN** — no cross-domain aggregate advertisement equivalent to the draft requirement. |
+| 6 Local Forwarding Decisions | Client policy and direct handoff after directory selection. | **DIFFERENT_DESIGN** — IICP permits a directory selection step, not solely local datagram forwarding. |
+| 7 Holder-Decided Real-Time State | Provider-reported availability plus directory probes and admission. | **PARTIAL** — the provider retains execution admission, but directory-observed eligibility uses boundedly stale evidence. |
+| 8 Handler Delivery Policy | Advertised endpoint and route-authority rules. | **PARTIAL** — direct endpoint choice exists; the draft's alternative callback-delivery model is not a general IICP contract. |
+| 9 Session-Agnostic Delivery | Core intent/task identity separated from transport binding. | **PARTIAL** — binding independence is specified; the draft's datagram-delivery invariant is not. |
+| 10 Routable Identifier Matching | Stable opaque intent identifiers and directory matching. | **DIFFERENT_DESIGN** — exact matching does not make identifiers routable prefixes. |
+| 11 No Data-Path Inference | Control-plane selection and direct data path. | **ALIGNED** in the supported direct path; no Internet-wide deterministic-forwarding benchmark is claimed. |
+| 12 Hierarchical Prefix Namespace | Project `urn:iicp:` identifiers. | **DIFFERENT_DESIGN** — textual hierarchy is not prefix routing or aggregability. |
+| 13 Domain Isolation | Optional restricted-trust-domain fixtures and local policy authority. | **PARTIAL** — pre-normative profile; cross-domain deployment and independent enforcement not qualified. |
+| 14 Bounded Convergence | Signed federation snapshot/event-tail and freshness rules. | **NOT_ESTABLISHED** — no bounded cross-domain convergence result is published for the draft's scale. |
+| 15 Delivery Reachability | Directory reachability/availability gates and supported task paths. | **PARTIAL** — an eligible route can fail; IICP does not guarantee delivery to every registered handler. |
+| 16 Return Path | Direct CALL/RESPONSE bindings and task identity. | **ALIGNED** for supported request/response paths; adverse-network scale remains unmeasured. |
+| 17 Originator Decomposition | Application supplies the intent; directory does not infer it from task content. | **ALIGNED** in the declared Core scope; natural-language-to-intent conversion remains application-owned. |
+
+Each row's source section, IICP references, Profile/release scope, fixture
+references and evidence limitations are recorded in the companion dataset.
+The mapping leaves 4, 5, 6, 10, 12 and 14 unresolved or deliberately different;
+it is not a plan to change IICP merely to improve comparison coverage.
+
+## Chronology and evidence limits
+
+The first inspected IICP repository commit is dated 2025-10-27. This is a
+commit timestamp, not independent proof of when the repository became publicly
+accessible. AIDIP -00 (2025-10-15) predates it; AIDIP intent selection appeared
+in a later revision (2026-02-12), and IAIP -00 appeared on 2026-02-09. Compare
+individual mechanisms and dated public artifacts, not project age or alleged
+influence. The older comparison records the evidence behind those dates.
+
+No source reviewed here establishes IETF endorsement of IICP, common wire
+interoperability with these drafts, Internet-scale routing, a deployed remote
+Management authority, independent IICP certification or a winning protocol.
+Where source text or implementation evidence was not located, the dataset marks
+the limit instead of supplying an inferred result.
diff --git a/standards/REVIEWING.md b/standards/REVIEWING.md
index 57ee072..ffdc175 100644
--- a/standards/REVIEWING.md
+++ b/standards/REVIEWING.md
@@ -16,10 +16,13 @@ Start with:
for verifier, freshness, replay and consumer revalidation boundaries;
3. [`standards/IICP_PROTOCOL_POSITIONING.md`](IICP_PROTOCOL_POSITIONING.md)
for the narrow problem and protocol boundary;
-4. [`standards/PROTOCOL_COMPARISON_2026-08-15.md`](PROTOCOL_COMPARISON_2026-08-15.md)
- and [`standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md`](EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md)
- for current overlap, per-dimension evidence maturity and chronology across
- IAIP, AIDIP, MCP, A2A and related work;
+4. [`standards/PROTOCOL_COMPARISON_2026-09-25.md`](PROTOCOL_COMPARISON_2026-09-25.md)
+ and [`standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md`](EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md)
+ for the currently verified overlap, REQ-1–17 mapping and security revision
+ update. The [August comparison](PROTOCOL_COMPARISON_2026-08-15.md) and
+ [August security crosswalk](EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md)
+ remain dated historical snapshots; their maturity scores were not
+ automatically refreshed;
5. `standards/ietf/draft-roble-iicp-peer.md`;
6. `standards/SECURITY_PRIVACY_OPERATIONAL_CONSIDERATIONS_2026-08-13.md`;
7. [`standards/ietf/evidence-matrix.md`](ietf/evidence-matrix.md);
diff --git a/standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md b/standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md
index 49c9030..f2d86ab 100644
--- a/standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md
+++ b/standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md
@@ -145,5 +145,5 @@ question before broader IICP features are considered.
Core, Profile, Binding and Registry ownership.
- [Privacy adversary and trust model](../docs/security/privacy-adversary-and-trust-model.md):
directory and executor visibility boundaries.
-- [Protocol comparison](PROTOCOL_COMPARISON_2026-08-15.md): dated overlap and
- maturity evidence for adjacent work.
+- [Protocol positioning](IICP_PROTOCOL_POSITIONING.md): current entry point
+ to dated overlap and evidence assessments for adjacent work.
diff --git a/standards/SELECTION_REVIEW_BUNDLE_README.md b/standards/SELECTION_REVIEW_BUNDLE_README.md
index dd9d1a6..f930cbd 100644
--- a/standards/SELECTION_REVIEW_BUNDLE_README.md
+++ b/standards/SELECTION_REVIEW_BUNDLE_README.md
@@ -9,7 +9,8 @@ Read in this order:
2. `standards/SELECTION_TRUST_AND_REVALIDATION.md`
3. `standards/SELECTION_CANDIDATE_ADVERSARIAL_REVIEW_2026-08-21.md`
4. `standards/IICP_PROTOCOL_POSITIONING.md`
-5. `standards/PROTOCOL_COMPARISON_2026-08-15.md`
+5. `standards/PROTOCOL_COMPARISON_2026-09-25.md` for the current source and
+ requirements assessment; the 2026-08-15 comparison remains historical
6. `IMPLEMENTATIONS.md` and `SPEC_STATUS.md`
7. the capability, directory-state and observability decisions under `docs/`
8. the core, semantics, directory and conformance sources under `spec/v1.9/`
diff --git a/standards/protocol-comparison-v1.json b/standards/protocol-comparison-v1.json
index e340404..8c6dfc3 100644
--- a/standards/protocol-comparison-v1.json
+++ b/standards/protocol-comparison-v1.json
@@ -1,6 +1,6 @@
{
"schema": "iicp.protocol-comparison.v1",
- "as_of": "2026-08-15",
+ "as_of": "2026-09-25",
"status": "informative_research_not_endorsement",
"date_semantics": "Each entry updated value is the cited source revision date when published; otherwise it is the verification date.",
"comparison_values": [
@@ -111,12 +111,13 @@
},
"first_public_evidence": {
"date": "2025-10-27",
- "kind": "initial_public_spec_commit",
- "artifact": "IICP v1.4.2 initial public draft",
+ "kind": "earliest_inspected_spec_commit",
+ "artifact": "IICP v1.4.2 commit; public accessibility on that date not independently verified",
"source": "https://github.com/RobLe3/IICP/commit/686676ea24a620f6db4e62e8c1900ba75217d3e2",
- "confidence": "high"
+ "confidence": "commit_timestamp_only_public_access_not_independently_verified"
},
- "relative_to_iicp_first_public": "same_day"
+ "relative_to_iicp_first_public": "same_day",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "iaip",
@@ -185,7 +186,8 @@
"source": "https://datatracker.ietf.org/doc/draft-sz-dmsc-iaip/history/",
"confidence": "high"
},
- "relative_to_iicp_first_public": "postdates"
+ "relative_to_iicp_first_public": "postdates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "aidip",
@@ -254,7 +256,8 @@
"source": "https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/history/",
"confidence": "high"
},
- "relative_to_iicp_first_public": "predates"
+ "relative_to_iicp_first_public": "predates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "aipf",
@@ -323,7 +326,8 @@
"source": "https://datatracker.ietf.org/doc/draft-zahed-agent-comm-framework/history/",
"confidence": "high"
},
- "relative_to_iicp_first_public": "postdates"
+ "relative_to_iicp_first_public": "postdates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "iacp",
@@ -392,7 +396,8 @@
"source": "https://datatracker.ietf.org/doc/draft-gebauer-iacp/history/",
"confidence": "high"
},
- "relative_to_iicp_first_public": "postdates"
+ "relative_to_iicp_first_public": "postdates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "a2a",
@@ -461,7 +466,8 @@
"source": "https://api.github.com/repos/a2aproject/A2A",
"confidence": "high"
},
- "relative_to_iicp_first_public": "predates"
+ "relative_to_iicp_first_public": "predates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "mcp",
@@ -530,7 +536,8 @@
"source": "https://api.github.com/repos/modelcontextprotocol/modelcontextprotocol",
"confidence": "high"
},
- "relative_to_iicp_first_public": "predates"
+ "relative_to_iicp_first_public": "predates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "dns-aid",
@@ -599,7 +606,8 @@
"source": "https://datatracker.ietf.org/doc/draft-mozleywilliams-dnsop-dnsaid/history/",
"confidence": "high"
},
- "relative_to_iicp_first_public": "predates"
+ "relative_to_iicp_first_public": "predates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "agntcy",
@@ -668,7 +676,8 @@
"source": "https://api.github.com/repos/agntcy/acp-spec",
"confidence": "high"
},
- "relative_to_iicp_first_public": "predates"
+ "relative_to_iicp_first_public": "predates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
},
{
"id": "anp",
@@ -737,7 +746,8 @@
"source": "https://api.github.com/repos/agent-network-protocol/AgentNetworkProtocol",
"confidence": "high"
},
- "relative_to_iicp_first_public": "predates"
+ "relative_to_iicp_first_public": "predates",
+ "assessment_status": "historical_2026-08-15_not_refreshed"
}
],
"overlap_evidence": {
@@ -1085,5 +1095,435 @@
"source": "https://github.com/RobLe3/IICP/blob/main/standards/IICP_PROTOCOL_POSITIONING.md",
"confidence": "high"
}
+ ],
+ "legacy_assessment_as_of": "2026-08-15",
+ "current_assessment": "standards/PROTOCOL_COMPARISON_2026-09-25.md",
+ "first_public_evidence_note": "A Git commit date is not independent proof of when a repository became publicly accessible; chronology establishes neither influence nor priority.",
+ "source_inventory": [
+ {
+ "id": "iaip",
+ "document": "draft-sz-dmsc-iaip-02",
+ "revision_date": "2026-05-25",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "6-8",
+ "scope": "Gateway matching, selection and forwarding",
+ "source": "https://datatracker.ietf.org/doc/draft-sz-dmsc-iaip-02/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "aidip",
+ "document": "draft-cui-ai-agent-discovery-invocation-02",
+ "revision_date": "2026-07-06",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "architecture and protocol procedures",
+ "scope": "Discovery, selection and invocation",
+ "source": "https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation-02/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "cirp",
+ "document": "draft-verma-cirp-02",
+ "revision_date": "2026-08-10",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "1; 6-10",
+ "scope": "Scoped discovery, session authorization and receipts",
+ "source": "https://datatracker.ietf.org/doc/draft-verma-cirp-02/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "intent-routing-requirements",
+ "document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "revision_date": "2026-08-14",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "3.1-3.9",
+ "scope": "REQ-1 through REQ-17; requirements, not implementation",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements-00/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "dns-aid",
+ "document": "draft-mozleywilliams-dnsop-dnsaid-02",
+ "revision_date": "2026-05-27",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "architecture and discovery records",
+ "scope": "DNS discovery input",
+ "source": "https://datatracker.ietf.org/doc/draft-mozleywilliams-dnsop-dnsaid-02/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "dmsc-architecture",
+ "document": "draft-li-dmsc-architecture-01",
+ "revision_date": "2026-05-29",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "architecture",
+ "scope": "DMSC architecture context",
+ "source": "https://datatracker.ietf.org/doc/draft-li-dmsc-architecture-01/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "dmsc-information-architecture",
+ "document": "draft-li-dmsc-inf-architecture-07",
+ "revision_date": "2026-05-22",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "architecture",
+ "scope": "DMSC information architecture context",
+ "source": "https://datatracker.ietf.org/doc/draft-li-dmsc-inf-architecture-07/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "aipf",
+ "document": "draft-zahed-agent-comm-framework-01",
+ "revision_date": "2026-07-19",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "architecture",
+ "scope": "Agent communication framework",
+ "source": "https://datatracker.ietf.org/doc/draft-zahed-agent-comm-framework-01/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "iacp",
+ "document": "draft-gebauer-iacp-03",
+ "revision_date": "2026-07-28",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "architecture",
+ "scope": "Broader agent communication architecture",
+ "source": "https://datatracker.ietf.org/doc/draft-gebauer-iacp-03/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "agent-routing-policy",
+ "document": "draft-ahuja-agent-routing-policy-00",
+ "revision_date": "2026-09-17",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "4-5",
+ "scope": "Inter-domain policy grammar",
+ "source": "https://datatracker.ietf.org/doc/draft-ahuja-agent-routing-policy-00/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "agent-session-requirements",
+ "document": "draft-feng-agentproto-session-requirements-02",
+ "revision_date": "2026-08-20",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "requirements",
+ "scope": "Post-discovery session requirements",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-agentproto-session-requirements-02/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "security-principal-binding",
+ "document": "draft-bu-agentproto-security-principal-binding-07",
+ "revision_date": "2026-09-15",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "terminology and verifier questions",
+ "scope": "Claim and verifier boundary",
+ "source": "https://datatracker.ietf.org/doc/draft-bu-agentproto-security-principal-binding-07/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "scitt-agent-action-receipt",
+ "document": "draft-noa-scitt-ai-agent-receipt-01",
+ "revision_date": "2026-08-15",
+ "verified_at": "2026-09-25",
+ "formal_status": "individual_internet_draft",
+ "relevant_sections": "receipt profile",
+ "scope": "Action receipts; not an adopted SCITT WG result",
+ "source": "https://datatracker.ietf.org/doc/draft-noa-scitt-ai-agent-receipt-01/",
+ "evidence_class": "official_datatracker_document_text_and_metadata",
+ "retrieval_limitations": "Document text and formal status reviewed; external implementation and deployment searches are not exhaustive."
+ },
+ {
+ "id": "dawn",
+ "document": "charter-ietf-dawn-00-07",
+ "revision_date": "2026-09-11",
+ "verified_at": "2026-09-25",
+ "formal_status": "proposed_working_group_and_charter",
+ "relevant_sections": "proposed charter scope",
+ "scope": "Initial discovery; proposed charter excludes semantic matching, ranking and selection",
+ "source": "https://datatracker.ietf.org/wg/dawn/about/",
+ "evidence_class": "official_datatracker_group_status",
+ "retrieval_limitations": "Group page verified on date shown; charter revision date not separately established."
+ }
+ ],
+ "intent_routing_requirements": [
+ {
+ "id": "REQ-1",
+ "title": "Open Participation",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.1.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-dir.md",
+ "scope": "released_connected_directory",
+ "implementation_evidence": "Published SDK/provider and directory registration paths; same-project implementation only.",
+ "fixture_reference": "spec/v1.9/conformance-test-suite.md",
+ "positive_negative_cases": "Registration success and invalid credential/rejected registration are named; open global participation has no vector.",
+ "disposition": "PARTIAL",
+ "limitation": "Public registration and SDK support do not establish unrestricted global participation or independent implementation.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-2",
+ "title": "Heterogeneous Handlers",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.1.2",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "docs/architecture/effective-service-capability-semantics.md",
+ "scope": "released_and_implementation",
+ "implementation_evidence": "Published provider adapters and both directory flavors advertise typed capabilities; same-project implementation only.",
+ "fixture_reference": "research/pre-normative-profiles/fixtures/effective-capability-v1.json",
+ "positive_negative_cases": "Positive effective-capability advertisement and negative invalid limit; arbitrary handler types not enumerated.",
+ "disposition": "ALIGNED",
+ "limitation": "Supported adapters demonstrate heterogeneity; arbitrary handler classes are not qualified.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-3",
+ "title": "Control/Data Plane Separation",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.2.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-core.md",
+ "scope": "released_supported_bindings",
+ "implementation_evidence": "Maintained SDK consumers dispatch to providers after Directory discovery; same-project implementation only.",
+ "fixture_reference": "spec/v1.9/conformance-test-suite.md",
+ "positive_negative_cases": "Discovery and direct task path have named tests; no measured independence at Internet scale.",
+ "disposition": "ALIGNED",
+ "limitation": "Direct payload path is specified; throughput independence is not measured here.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-4",
+ "title": "Bounded State",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.3.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-federated-directory.md",
+ "scope": "released_design_not_scale_qualification",
+ "implementation_evidence": "Signed snapshot/event-tail design and directory flavors are published, but no sublinear-state implementation claim.",
+ "fixture_reference": null,
+ "positive_negative_cases": "No positive/negative Internet-scale bounded-state fixture located.",
+ "disposition": "NOT_ESTABLISHED",
+ "limitation": "No proof that any single directory has state sublinear in total registrations.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-5",
+ "title": "Capability Aggregation",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.3.2",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-dir.md",
+ "scope": "released_connected_directory",
+ "implementation_evidence": "Directory discovery is implemented; aggregate cross-domain advertisement is not specified.",
+ "fixture_reference": null,
+ "positive_negative_cases": "No aggregation or withdrawal fixture equivalent to the draft requirement.",
+ "disposition": "DIFFERENT_DESIGN",
+ "limitation": "No cross-domain aggregate advertisement contract equivalent to requirement.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-6",
+ "title": "Local Forwarding Decisions",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.4.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-semantics.md",
+ "scope": "released_connected_directory",
+ "implementation_evidence": "Directory recommendation and client policy run in maintained SDKs; no datagram-local forwarding implementation.",
+ "fixture_reference": null,
+ "positive_negative_cases": "No positive/negative local-only forwarding fixture; this is a different design.",
+ "disposition": "DIFFERENT_DESIGN",
+ "limitation": "Directory-assisted selection differs from local-only datagram forwarding.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-7",
+ "title": "Real-Time State Decided by Its Holder",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.4.2",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "docs/architecture/directory-state-semantics.md",
+ "scope": "working_main_architecture_and_implementation",
+ "implementation_evidence": "Provider availability reports and directory probes are implemented; both are same-project evidence.",
+ "fixture_reference": "docs/architecture/directory-state-semantics-v1.json",
+ "positive_negative_cases": "Available/reachable versus stale/unavailable cases; holder-only real-time selection not proven.",
+ "disposition": "PARTIAL",
+ "limitation": "Provider admission is local, while directory eligibility uses observations and reports with bounded freshness.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-8",
+ "title": "Delivery Endpoint Declared by Handler Policy",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.4.3",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-dir.md",
+ "scope": "released_connected_directory",
+ "implementation_evidence": "Provider route advertisement and bounded ticket validation exist in maintained implementations.",
+ "fixture_reference": "spec/v1.9/conformance-test-suite.md",
+ "positive_negative_cases": "Routable versus non-routable endpoint cases; callback-delivery alternative absent.",
+ "disposition": "PARTIAL",
+ "limitation": "Advertised routes exist; draft callback-delivery alternative is not a general IICP contract.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-9",
+ "title": "Session-Agnostic Delivery",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.4.4",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "docs/architecture/environmental-independence-and-extension-architecture.md",
+ "scope": "working_main_architecture",
+ "implementation_evidence": "HTTP task binding and draft native binding keep task identity separate from transport.",
+ "fixture_reference": "docs/architecture/environmental-independence-v1.json",
+ "positive_negative_cases": "Same logical intent over bindings is modeled; identical datagram-delivery behavior not tested.",
+ "disposition": "PARTIAL",
+ "limitation": "IICP task identity is binding-neutral but no identical datagram-delivery mechanism is specified.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-10",
+ "title": "Matching Based on Routable Identifiers",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.5.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "docs/architecture/identifier-and-registry-architecture.md",
+ "scope": "working_main_architecture",
+ "implementation_evidence": "Directory exact-match intent matching is implemented in both flavors.",
+ "fixture_reference": "registry/fixtures/intent-payloads-v1.json",
+ "positive_negative_cases": "Known exact intent versus unknown/mismatched intent; no prefix-routing vector.",
+ "disposition": "DIFFERENT_DESIGN",
+ "limitation": "IICP opaque exact-match identifiers are not routable prefixes.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-11",
+ "title": "Deterministic Forwarding, No Data-Path Inference",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.5.2",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-core.md",
+ "scope": "released_supported_bindings",
+ "implementation_evidence": "Maintained Directory is outside direct task-payload path; no data-path inference is required.",
+ "fixture_reference": "spec/v1.9/conformance-test-suite.md",
+ "positive_negative_cases": "Direct CALL/RESPONSE and refusal cases are named; Internet-scale forwarding cost unmeasured.",
+ "disposition": "ALIGNED",
+ "limitation": "Directory is not task-payload transit; no Internet-wide forwarding performance proof.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-12",
+ "title": "Routable Hierarchical Namespace",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.6.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "docs/architecture/identifier-and-registry-architecture.md",
+ "scope": "working_main_architecture",
+ "implementation_evidence": "Opaque project identifier architecture is documented; no prefix-aggregation implementation.",
+ "fixture_reference": null,
+ "positive_negative_cases": "No positive/negative prefix-matching or aggregate-state fixture.",
+ "disposition": "DIFFERENT_DESIGN",
+ "limitation": "Textual URN hierarchy does not imply aggregability or prefix matching.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-13",
+ "title": "Isolation and Cross-Domain Authorization",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.6.2",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "research/pre-normative-profiles/restricted-trust-domain-v0.md",
+ "scope": "optional_pre_normative_profile",
+ "implementation_evidence": "Restricted-domain membership and local policy are pre-normative same-project fixtures.",
+ "fixture_reference": "research/pre-normative-profiles/fixtures/restricted-trust-domain-v0.json",
+ "positive_negative_cases": "Allowed member and denied foreign/unverified member are covered in local fixtures; no external deployment proof.",
+ "disposition": "PARTIAL",
+ "limitation": "No qualified cross-domain deployment or independent enforcement evidence.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-14",
+ "title": "Bounded Convergence",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.7.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-federated-directory.md",
+ "scope": "released_design_not_scale_qualification",
+ "implementation_evidence": "Snapshot/event-tail federation exists as a design and preview implementation, not a bounded-convergence result.",
+ "fixture_reference": null,
+ "positive_negative_cases": "No latency-bound convergence fixture at cross-domain scale.",
+ "disposition": "NOT_ESTABLISHED",
+ "limitation": "No bounded cross-domain convergence result at draft scale.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-15",
+ "title": "Delivery Reachability",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.8.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "docs/architecture/directory-state-semantics.md",
+ "scope": "working_main_architecture_and_implementation",
+ "implementation_evidence": "Directory reachability and availability gates exist in maintained directories.",
+ "fixture_reference": "docs/architecture/directory-state-semantics-v1.json",
+ "positive_negative_cases": "Eligible/current versus stale/unreachable cases; delivery to every registered handler is not guaranteed.",
+ "disposition": "PARTIAL",
+ "limitation": "Registered is not necessarily available or reachable; eligible routes can fail.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-16",
+ "title": "Return-Path Reachability",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.8.2",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-core.md",
+ "scope": "released_supported_bindings",
+ "implementation_evidence": "Supported HTTP task handlers return responses directly to callers.",
+ "fixture_reference": "spec/v1.9/conformance-test-suite.md",
+ "positive_negative_cases": "Response and timeout/error paths are named; adverse-network return reachability unmeasured.",
+ "disposition": "ALIGNED",
+ "limitation": "Direct request/response path exists; adverse-network scale unmeasured.",
+ "verified_at": "2026-09-25"
+ },
+ {
+ "id": "REQ-17",
+ "title": "Intent Decomposed at the Originator",
+ "source_document": "draft-feng-dmsc-intent-routing-requirements-00",
+ "source_section": "3.9.1",
+ "source": "https://datatracker.ietf.org/doc/draft-feng-dmsc-intent-routing-requirements/00/",
+ "iicp_reference": "spec/v1.9/iicp-semantics.md",
+ "scope": "released_supported_bindings",
+ "implementation_evidence": "Maintained consumers submit explicit intent identifiers.",
+ "fixture_reference": "registry/fixtures/intent-payloads-v1.json",
+ "positive_negative_cases": "Known and unknown intent handling; natural-language decomposition is application-owned and untested by IICP.",
+ "disposition": "ALIGNED",
+ "limitation": "Application supplies intent; natural-language decomposition remains outside Core.",
+ "verified_at": "2026-09-25"
+ }
]
}
diff --git a/tools/build_selection_review_bundle.py b/tools/build_selection_review_bundle.py
index 42cedf4..de65f97 100644
--- a/tools/build_selection_review_bundle.py
+++ b/tools/build_selection_review_bundle.py
@@ -23,6 +23,9 @@
"CONTINUATION.md",
"TERMINOLOGY_AND_DISCOVERABILITY.md",
"ecosystem/public-repositories.json",
+ "ecosystem/CURRENT_VERSIONS.md",
+ "pre1/README.md",
+ "pre1/feature-baseline-v1.json",
"standards/REVIEWING.md",
"standards/SELECTION_REVIEW_BUNDLE_README.md",
"standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md",
@@ -30,24 +33,70 @@
"standards/SELECTION_CANDIDATE_ADVERSARIAL_REVIEW_2026-08-21.md",
"standards/IICP_PROTOCOL_POSITIONING.md",
"standards/PROTOCOL_COMPARISON_2026-08-15.md",
+ "standards/PROTOCOL_COMPARISON_2026-09-25.md",
"standards/protocol-comparison-v1.json",
"standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md",
+ "standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md",
"standards/TRANSPORT_BINDING_AND_PORT_DECISION_2026-08-21.md",
"docs/architecture/effective-service-capability-semantics.md",
"docs/architecture/effective-service-capability-v1.json",
"docs/architecture/directory-state-semantics.md",
+ "docs/architecture/directory-state-semantics-v1.json",
+ "docs/architecture/environmental-independence-v1.json",
+ "docs/architecture/identifier-and-registry-architecture.md",
+ "docs/architecture/identifier-registry-v1.json",
"docs/architecture/node-observability-interfaces.md",
"docs/architecture/node-observability-v1.json",
"docs/architecture/environmental-independence-and-extension-architecture.md",
"docs/security/privacy-adversary-and-trust-model.md",
"research/pre-normative-profiles/restricted-trust-domain-v0.md",
+ "research/pre-normative-profiles/fixtures/effective-capability-v1.json",
+ "research/pre-normative-profiles/fixtures/restricted-trust-domain-v0.json",
"research/pre-normative-profiles/selection-profile-v1.md",
"schemas/capability-requirements-v1.json",
"schemas/capability-refusal-v1.json",
+ "registry/fixtures/intent-payloads-v1.json",
"spec/v1.9/iicp-core.md",
"spec/v1.9/iicp-semantics.md",
"spec/v1.9/iicp-dir.md",
+ "spec/v1.9/iicp-federated-directory.md",
"spec/v1.9/conformance-test-suite.md",
+ # Local references needed to read the reviewed documents in isolation.
+ "CONTRIBUTING.md",
+ "GOVERNANCE.md",
+ "SPEC_RELEASE_PROCESS.md",
+ "docs/architecture/task-time-semantics-v1.json",
+ "docs/architecture/task-time-semantics.md",
+ "docs/governance/public-artifact-boundary.md",
+ "ecosystem/repositories.json",
+ "research/RESEARCH.md",
+ "research/native-ai-infrastructure/fixtures/native-framing-fixture-manifest-v1.json",
+ "research/native-ai-infrastructure/fixtures/native-framing-v1.json",
+ "research/pre-normative-profiles/dispatch-ticket-trust-profile-v2.md",
+ "research/pre-normative-profiles/endpoint-security-profile-v1.md",
+ "research/pre-normative-profiles/fixtures/reputation-outcome-v2.json",
+ "research/pre-normative-profiles/restricted-trust-domain-membership-v0.md",
+ "research/strategic/2026-07-11-layered-intent-capability-research.md",
+ "research/strategic/2026-08-12-execution-privacy-and-attested-confidential-execution.md",
+ "research/strategic/2026-08-12-heterogeneous-model-quality-and-learned-routing.md",
+ "research/strategic/2026-08-21-outcome-v2-implementation-experience.md",
+ "research/strategic/2026-08-21-weekly-intelligence-disposition.md",
+ "research/strategic/execution-privacy-feasibility/README.md",
+ "research/strategic/execution-privacy-feasibility/profile-v0.md",
+ "research/strategic/execution-privacy-feasibility/software_prototype.py",
+ "research/strategic/learned-routing-experiment/README.md",
+ "schemas/effective-capability-advertisement-v1.json",
+ "spec/v1.9/iicp-cbor-wire.md",
+ "spec/v1.9/iicp-confidentiality.md",
+ "spec/v1.9/iicp-framing.md",
+ "spec/v1.9/iicp-service-lifecycle-profile.md",
+ "spec/v1.9/replica-lifecycle-contract-v1.json",
+ "standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md",
+ "standards/SECURITY_PRIVACY_OPERATIONAL_CONSIDERATIONS_2026-08-13.md",
+ "standards/STANDARDS_READINESS.md",
+ "standards/ietf/evidence-matrix.md",
+ "tools/build_internet_draft.sh",
+ "tools/check_native_framing_fixtures.py",
)
diff --git a/tools/build_standards_review_bundle.py b/tools/build_standards_review_bundle.py
index 29bb7bc..13de61d 100644
--- a/tools/build_standards_review_bundle.py
+++ b/tools/build_standards_review_bundle.py
@@ -29,14 +29,77 @@
"docs/governance/public-artifact-boundary.md",
"docs/security/privacy-adversary-and-trust-model.md",
"ecosystem/public-repositories.json",
+ "ecosystem/CURRENT_VERSIONS.md",
+ "pre1/README.md",
+ "pre1/feature-baseline-v1.json",
"standards/REVIEWING.md",
"standards/IICP_PROTOCOL_POSITIONING.md",
"standards/PROTOCOL_COMPARISON_2026-08-15.md",
+ "standards/PROTOCOL_COMPARISON_2026-09-25.md",
+ "standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md",
+ "standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md",
"standards/protocol-comparison-v1.json",
+ "docs/architecture/directory-state-semantics-v1.json",
+ "docs/architecture/directory-state-semantics.md",
+ "docs/architecture/effective-service-capability-semantics.md",
+ "docs/architecture/effective-service-capability-v1.json",
+ "schemas/effective-capability-advertisement-v1.json",
+ "schemas/capability-requirements-v1.json",
+ "schemas/capability-refusal-v1.json",
+ "docs/architecture/environmental-independence-and-extension-architecture.md",
+ "docs/architecture/environmental-independence-v1.json",
+ "docs/architecture/identifier-and-registry-architecture.md",
+ "docs/architecture/identifier-registry-v1.json",
+ "registry/fixtures/intent-payloads-v1.json",
+ "research/pre-normative-profiles/fixtures/effective-capability-v1.json",
+ "research/pre-normative-profiles/fixtures/restricted-trust-domain-v0.json",
+ "research/pre-normative-profiles/restricted-trust-domain-v0.md",
+ "spec/v1.9/conformance-test-suite.md",
+ "spec/v1.9/iicp-core.md",
+ "spec/v1.9/iicp-dir.md",
+ "spec/v1.9/iicp-federated-directory.md",
+ "spec/v1.9/iicp-semantics.md",
"standards/STANDARDS_READINESS.md",
"standards/SECURITY_PRIVACY_OPERATIONAL_CONSIDERATIONS_2026-08-13.md",
"standards/ietf/README.md",
"standards/ietf/evidence-matrix.md",
+ # Local references needed to read the reviewed documents in isolation.
+ "GOVERNANCE.md",
+ "IMPLEMENTATIONS.md",
+ "SPEC_RELEASE_PROCESS.md",
+ "SPEC_STATUS.md",
+ "VERSIONING.md",
+ "docs/architecture/task-time-semantics-v1.json",
+ "docs/architecture/task-time-semantics.md",
+ "ecosystem/repositories.json",
+ "research/RESEARCH.md",
+ "research/native-ai-infrastructure/fixtures/native-framing-fixture-manifest-v1.json",
+ "research/native-ai-infrastructure/fixtures/native-framing-v1.json",
+ "research/pre-normative-profiles/dispatch-ticket-trust-profile-v2.md",
+ "research/pre-normative-profiles/endpoint-security-profile-v1.md",
+ "research/pre-normative-profiles/fixtures/reputation-outcome-v2.json",
+ "research/pre-normative-profiles/restricted-trust-domain-membership-v0.md",
+ "research/strategic/2026-07-11-layered-intent-capability-research.md",
+ "research/strategic/2026-08-12-execution-privacy-and-attested-confidential-execution.md",
+ "research/strategic/2026-08-12-heterogeneous-model-quality-and-learned-routing.md",
+ "research/strategic/2026-08-21-outcome-v2-implementation-experience.md",
+ "research/strategic/2026-08-21-weekly-intelligence-disposition.md",
+ "research/strategic/execution-privacy-feasibility/README.md",
+ "research/strategic/execution-privacy-feasibility/profile-v0.md",
+ "research/strategic/execution-privacy-feasibility/software_prototype.py",
+ "research/strategic/learned-routing-experiment/README.md",
+ "spec/v1.9/iicp-cbor-wire.md",
+ "spec/v1.9/iicp-confidentiality.md",
+ "spec/v1.9/iicp-framing.md",
+ "spec/v1.9/iicp-service-lifecycle-profile.md",
+ "spec/v1.9/replica-lifecycle-contract-v1.json",
+ "standards/IETF_AGENT_PROTOCOL_LANDSCAPE_2026-08-08.md",
+ "standards/SELECTION_CANDIDATE_ADVERSARIAL_REVIEW_2026-08-21.md",
+ "standards/SELECTION_ELIGIBILITY_PROBLEM_STATEMENT.md",
+ "standards/SELECTION_TRUST_AND_REVALIDATION.md",
+ "standards/TRANSPORT_BINDING_AND_PORT_DECISION_2026-08-21.md",
+ "tools/build_internet_draft.sh",
+ "tools/check_native_framing_fixtures.py",
)
diff --git a/tools/check_protocol_comparison.py b/tools/check_protocol_comparison.py
index 2c405f0..2df70cc 100644
--- a/tools/check_protocol_comparison.py
+++ b/tools/check_protocol_comparison.py
@@ -3,6 +3,7 @@
from __future__ import annotations
import json
+import re
from datetime import date
from pathlib import Path
from urllib.parse import urlparse
@@ -26,6 +27,8 @@ def validate(path: Path = DATA) -> list[str]:
allowed_scores = {0, 1, 2, 3, 4, None}
values = set(data.get("comparison_values", []))
entries = data.get("entries", [])
+ if data.get("legacy_assessment_as_of") != "2026-08-15":
+ errors.append("legacy maturity assessments must retain their historical evidence date")
if len(entries) < 6:
errors.append("comparison must include at least six subjects")
ids: set[str] = set()
@@ -34,6 +37,8 @@ def validate(path: Path = DATA) -> list[str]:
if ident in ids:
errors.append(f"duplicate id: {ident}")
ids.add(ident)
+ if entry.get("assessment_status") != "historical_2026-08-15_not_refreshed":
+ errors.append(f"{ident}: old maturity assessments must remain explicitly historical")
for field in (
"name", "category", "version", "formal_status", "updated",
"source", "role", "dimensions", "maturity",
@@ -93,6 +98,56 @@ def validate(path: Path = DATA) -> list[str]:
if chronology_dates != sorted(chronology_dates):
errors.append("mechanism chronology must be date sorted")
+ inventory = data.get("source_inventory", [])
+ source_ids: set[str] = set()
+ for index, source in enumerate(inventory):
+ label = f"source_inventory[{index}]"
+ ident = source.get("id")
+ if not ident or ident in source_ids:
+ errors.append(f"{label}: missing or duplicate id")
+ source_ids.add(ident)
+ for field in ("document", "formal_status", "relevant_sections", "scope",
+ "evidence_class", "retrieval_limitations"):
+ if not source.get(field):
+ errors.append(f"{label}: missing {field}")
+ revision = _validate_date(errors, source.get("revision_date"), f"{label}: revision date", as_of)
+ verified = _validate_date(errors, source.get("verified_at"), f"{label}: verification date", as_of)
+ if revision is not None and verified is not None and revision > verified:
+ errors.append(f"{label}: revision date cannot be later than verification date")
+ _validate_url(errors, source.get("source", ""), f"{label}: source")
+ if source.get("formal_status") == "individual_internet_draft" and not str(source.get("document", "")).startswith("draft-"):
+ errors.append(f"{label}: individual Internet-Draft must name its draft")
+ required_sources = {
+ "iaip", "aidip", "cirp", "intent-routing-requirements", "dawn",
+ "dns-aid", "dmsc-architecture", "dmsc-information-architecture",
+ "aipf", "iacp", "agent-routing-policy", "agent-session-requirements",
+ "security-principal-binding", "scitt-agent-action-receipt",
+ }
+ if source_ids != required_sources:
+ errors.append("current source inventory is incomplete or contains an unreviewed row")
+
+ requirements = data.get("intent_routing_requirements", [])
+ if [item.get("id") for item in requirements] != [f"REQ-{i}" for i in range(1, 18)]:
+ errors.append("intent routing mapping must contain ordered REQ-1 through REQ-17 exactly once")
+ dispositions = {"ALIGNED", "PARTIAL", "DIFFERENT_DESIGN", "OUT_OF_SCOPE", "NOT_ESTABLISHED"}
+ for index, requirement in enumerate(requirements):
+ label = f"intent_routing_requirements[{index}]"
+ for field in ("title", "source_document", "source_section", "iicp_reference",
+ "scope", "implementation_evidence", "positive_negative_cases",
+ "limitation"):
+ if not requirement.get(field):
+ errors.append(f"{label}: missing {field}")
+ if requirement.get("source_document") != "draft-feng-dmsc-intent-routing-requirements-00":
+ errors.append(f"{label}: wrong source revision")
+ if requirement.get("disposition") not in dispositions:
+ errors.append(f"{label}: invalid disposition")
+ _validate_date(errors, requirement.get("verified_at"), f"{label}: verification date", as_of)
+ _validate_url(errors, requirement.get("source", ""), f"{label}: source")
+ for field in ("iicp_reference", "fixture_reference"):
+ relative = requirement.get(field)
+ if relative and (Path(relative).is_absolute() or not (ROOT / relative).is_file()):
+ errors.append(f"{label}: invalid {field}")
+
forbidden = {"overall_score", "composite_score", "winner", "quality_rank", "rank"}
if _contains_forbidden_key(data, forbidden):
errors.append("composite ranking fields are forbidden")
@@ -119,8 +174,11 @@ def _validate_url(errors: list[str], value: str, label: str) -> None:
def _parse_date(errors: list[str], value: object, label: str) -> date | None:
+ if not isinstance(value, str) or re.fullmatch(r"\d{4}-\d{2}-\d{2}", value) is None:
+ errors.append(f"{label} must use YYYY-MM-DD")
+ return None
try:
- return date.fromisoformat(str(value))
+ return date.fromisoformat(value)
except ValueError:
errors.append(f"{label} must use YYYY-MM-DD")
return None
@@ -128,10 +186,11 @@ def _parse_date(errors: list[str], value: object, label: str) -> date | None:
def _validate_date(
errors: list[str], value: object, label: str, as_of: date | None
-) -> None:
+) -> date | None:
parsed = _parse_date(errors, value, label)
if parsed is not None and as_of is not None and parsed > as_of:
errors.append(f"{label} cannot be later than the evidence date")
+ return parsed
def _contains_forbidden_key(value: object, forbidden: set[str]) -> bool:
diff --git a/tools/check_spec_release_integrity.py b/tools/check_spec_release_integrity.py
index 9b754b7..3752d2b 100755
--- a/tools/check_spec_release_integrity.py
+++ b/tools/check_spec_release_integrity.py
@@ -76,6 +76,7 @@ def main() -> int:
"docs/governance/public-artifact-boundary.md",
"docs/security/privacy-adversary-and-trust-model.md",
"docs/architecture/environmental-independence-and-extension-architecture.md",
+ "docs/architecture/decision-documentation-map.md",
"docs/architecture/environmental-independence-v1.json",
"tools/test_environmental_independence_decision.py",
"docs/architecture/identifier-and-registry-architecture.md",
@@ -174,7 +175,9 @@ def main() -> int:
"standards/TRANSPORT_BINDING_AND_PORT_DECISION_2026-08-21.md",
"standards/REVIEWING.md",
"standards/PROTOCOL_COMPARISON_2026-08-15.md",
+ "standards/PROTOCOL_COMPARISON_2026-09-25.md",
"standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-08-21.md",
+ "standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md",
"standards/protocol-comparison-v1.json",
"tools/check_protocol_comparison.py",
"tools/test_protocol_comparison.py",
diff --git a/tools/run_profile_fixture_contract.sh b/tools/run_profile_fixture_contract.sh
index ad9a39e..11311e4 100755
--- a/tools/run_profile_fixture_contract.sh
+++ b/tools/run_profile_fixture_contract.sh
@@ -2,6 +2,10 @@
set -euo pipefail
python3 tools/manage_release_closure.py --check
+python3 tools/check_protocol_comparison.py
+python3 -m unittest discover -s tools -p 'test_protocol_comparison.py'
+python3 -m unittest discover -s tools -p 'test_selection_review_bundle.py'
+python3 -m unittest discover -s tools -p 'test_standards_review_bundle.py'
python3 -m unittest discover -s conformance-runner/tests
python3 -m unittest discover -s tools -p 'test_effective_capability_taxonomy.py'
python3 -m unittest discover -s tools -p 'test_runtime_identity_context.py'
diff --git a/tools/test_protocol_comparison.py b/tools/test_protocol_comparison.py
index d649d82..c37e394 100644
--- a/tools/test_protocol_comparison.py
+++ b/tools/test_protocol_comparison.py
@@ -56,7 +56,7 @@ def mutate(data: dict) -> None:
def test_future_evidence_date_fails(self) -> None:
errors = self._validate_mutation(
lambda data: data["entries"][0]["first_public_evidence"].__setitem__(
- "date", "2026-08-16"
+ "date", "2027-01-01"
)
)
self.assertTrue(any("later than the evidence date" in item for item in errors))
@@ -98,6 +98,80 @@ def test_key_chronology_is_explicit(self) -> None:
]
self.assertEqual(aidip_events, ["2025-10-15", "2026-02-12", "2026-07-06"])
+ def test_requirement_mapping_is_complete(self) -> None:
+ data = json.loads(DATA.read_text(encoding="utf-8"))
+ self.assertEqual(
+ [row["id"] for row in data["intent_routing_requirements"]],
+ [f"REQ-{number}" for number in range(1, 18)],
+ )
+
+ def test_missing_requirement_fails(self) -> None:
+ errors = self._validate_mutation(
+ lambda data: data["intent_routing_requirements"].pop()
+ )
+ self.assertTrue(any("REQ-1 through REQ-17" in item for item in errors))
+
+ def test_bad_requirement_disposition_fails(self) -> None:
+ errors = self._validate_mutation(
+ lambda data: data["intent_routing_requirements"][0].__setitem__(
+ "disposition", "CERTIFIED"
+ )
+ )
+ self.assertTrue(any("invalid disposition" in item for item in errors))
+
+ def test_source_revision_and_verification_dates_are_bounded(self) -> None:
+ errors = self._validate_mutation(
+ lambda data: data["source_inventory"][0].__setitem__(
+ "verified_at", "2027-01-01"
+ )
+ )
+ self.assertTrue(any("cannot be later than the evidence date" in item for item in errors))
+
+ def test_source_revision_before_verification_passes(self) -> None:
+ def mutate(data: dict) -> None:
+ data["source_inventory"][0]["revision_date"] = "2026-09-23"
+ data["source_inventory"][0]["verified_at"] = "2026-09-24"
+
+ self.assertEqual(self._validate_mutation(mutate), [])
+
+ def test_source_revision_equal_to_verification_passes(self) -> None:
+ def mutate(data: dict) -> None:
+ data["source_inventory"][0]["revision_date"] = "2026-09-24"
+ data["source_inventory"][0]["verified_at"] = "2026-09-24"
+
+ self.assertEqual(self._validate_mutation(mutate), [])
+
+ def test_source_revision_after_verification_fails(self) -> None:
+ def mutate(data: dict) -> None:
+ data["source_inventory"][0]["revision_date"] = "2026-09-24"
+ data["source_inventory"][0]["verified_at"] = "2026-09-23"
+
+ errors = self._validate_mutation(mutate)
+ self.assertTrue(any("revision date cannot be later than verification date" in item for item in errors))
+
+ def test_malformed_source_dates_fail_cleanly(self) -> None:
+ def mutate(data: dict) -> None:
+ data["source_inventory"][0]["revision_date"] = "not-a-date"
+ data["source_inventory"][0]["verified_at"] = "2026-99-99"
+
+ errors = self._validate_mutation(mutate)
+ self.assertTrue(any("revision date must use YYYY-MM-DD" in item for item in errors))
+ self.assertTrue(any("verification date must use YYYY-MM-DD" in item for item in errors))
+
+ def test_compact_source_date_is_not_accepted_as_yyyy_mm_dd(self) -> None:
+ errors = self._validate_mutation(
+ lambda data: data["source_inventory"][0].__setitem__(
+ "revision_date", "20260924"
+ )
+ )
+ self.assertTrue(any("revision date must use YYYY-MM-DD" in item for item in errors))
+
+ def test_missing_required_source_fails(self) -> None:
+ errors = self._validate_mutation(
+ lambda data: data["source_inventory"].pop()
+ )
+ self.assertTrue(any("source inventory is incomplete" in item for item in errors))
+
if __name__ == "__main__":
unittest.main()
diff --git a/tools/test_selection_review_bundle.py b/tools/test_selection_review_bundle.py
index 7c8396b..d094d5a 100644
--- a/tools/test_selection_review_bundle.py
+++ b/tools/test_selection_review_bundle.py
@@ -3,6 +3,8 @@
import hashlib
import json
+import posixpath
+import re
from pathlib import Path
import subprocess
import tempfile
@@ -39,12 +41,37 @@ def test_bundle_is_deterministic_and_claim_bounded(self):
"standards/SELECTION_TRUST_AND_REVALIDATION.md",
"docs/architecture/node-observability-interfaces.md",
"standards/PROTOCOL_COMPARISON_2026-08-15.md",
+ "standards/PROTOCOL_COMPARISON_2026-09-25.md",
+ "standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md",
"IMPLEMENTATIONS.md",
+ "ecosystem/CURRENT_VERSIONS.md",
+ "pre1/README.md",
+ "pre1/feature-baseline-v1.json",
+ "docs/architecture/identifier-registry-v1.json",
"spec/v1.9/conformance-test-suite.md",
"SHA256SUMS.json",
):
self.assertIn(PREFIX + required, names)
manifest = json.loads(archive.read(PREFIX + "SHA256SUMS.json"))
+ comparison = json.loads(archive.read(PREFIX + "standards/protocol-comparison-v1.json"))
+ references = {
+ row[field]
+ for row in comparison["intent_routing_requirements"]
+ for field in ("iicp_reference", "fixture_reference")
+ if row.get(field)
+ }
+ self.assertTrue(references.issubset(manifest["files"]))
+ for relative in manifest["files"]:
+ if not relative.endswith(".md"):
+ continue
+ markdown = archive.read(PREFIX + relative).decode("utf-8")
+ for target in re.findall(r"(? None:
"CONTINUATION.md",
"docs/governance/public-artifact-boundary.md",
"ecosystem/public-repositories.json",
+ "ecosystem/CURRENT_VERSIONS.md",
+ "pre1/README.md",
+ "pre1/feature-baseline-v1.json",
+ "docs/architecture/identifier-registry-v1.json",
+ "docs/architecture/effective-service-capability-v1.json",
+ "schemas/effective-capability-advertisement-v1.json",
+ "schemas/capability-requirements-v1.json",
+ "schemas/capability-refusal-v1.json",
"standards/REVIEWING.md",
"standards/IICP_PROTOCOL_POSITIONING.md",
"standards/PROTOCOL_COMPARISON_2026-08-15.md",
+ "standards/PROTOCOL_COMPARISON_2026-09-25.md",
+ "standards/EMERGING_SECURITY_SESSION_EVIDENCE_CROSSWALK_2026-09-25.md",
"standards/protocol-comparison-v1.json",
"standards/ietf/evidence-matrix.md",
f"standards/ietf/{SOURCE.name}",
@@ -71,6 +83,25 @@ def test_bundle_is_deterministic_and_self_describing(self) -> None:
):
self.assertIn(prefix + required, names)
manifest = json.loads(archive.read(prefix + "SHA256SUMS.json"))
+ comparison = json.loads(archive.read(prefix + "standards/protocol-comparison-v1.json"))
+ references = {
+ row[field]
+ for row in comparison["intent_routing_requirements"]
+ for field in ("iicp_reference", "fixture_reference")
+ if row.get(field)
+ }
+ self.assertTrue(references.issubset(manifest["files"]))
+ for relative in manifest["files"]:
+ if not relative.endswith(".md"):
+ continue
+ markdown = archive.read(prefix + relative).decode("utf-8")
+ for target in re.findall(r"(?