Files
buzz/docs
15d3fb2e0d docs(nip-fi): close the denominator contract in its own oracle
The denominator rewrite changed the body and left every summary of it
behind. Three sites still promised the deleted requirement-level contract:
the global-controls paragraph, the release gate, and -- worst -- the
FI-CONF-MUTATION row itself, which is one of the four CONF entries the
denominator counts. The gate contradicted the body it gates, so the
original ambiguity survived inside the oracle that claims to close it.
FI-CONF-INTEROP-EXIT likewise still demanded byte-identical requests the
section above had already stopped requiring. All four now say listed
oracle and compared object.

The exit test promised a request on the WebSocket upgrade and defined a
signing-input object only for NIP-98. Define the NIP-42 half alongside it,
compared against its own transport's NIP-01 serialization, and pin the
complete unsigned event fields for both transports in the fixture. The
assertion object compared a protected header the fixture never pinned;
pin the complete protected-header and claim-set JSON values.

Correct a false premise: signatures were said to differ because ES256 and
BIP-340 each draw fresh randomness. Deterministic ECDSA and fixed-aux
BIP-340 are conforming and need not differ. The conclusion is unchanged --
conforming implementations may disagree on octets, so an object requiring
equal octets fails conforming pairs -- but the reason now matches the
algorithms as specified rather than as commonly configured.

Give FI-TRACE-CAPABILITY-REVOCATION a lawful N/A. Core makes it
conditional on a configured revocation-bounded external projection, while
Applicability required every unlisted oracle, so a deployment with no such
projection had no disposition it could honestly claim. Same defect class
the offline-jwt fix closed for the current-status oracles, one oracle over.

All findings are Wren's, verified against the cited lines before editing.
A rewrite that changes a contract has to grep for every restatement of the
old one; the body moved and the summaries did not, which is exactly the
drift this document exists to make impossible.

Co-authored-by: Tyler Longwell <tlongwell@squareup.com>
Signed-off-by: Tyler Longwell <tlongwell@squareup.com>
2026-08-17 15:44:19 -04:00
..
…