dev.cocore.compute.receipt

cocore.dev

Schema Diff

+50 -0

From

CID
bafyreiauw7sdeyt...
Indexed At
2026-06-25 16:58 UTC
View this version

To

CID
bafyreihmilyggly...
Indexed At
2026-07-26 20:05 UTC
View this version

Compatibility Analysis

Breaking Changes Detected

4 breaking changes, 12 non-breaking changes.

Breaking Changes (4)
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.sig", kind: "prop", name: Some("sig") }
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.nonce", kind: "prop", name: Some("nonce") }
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.authority", kind: "prop", name: Some("authority") }
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.machineId", kind: "prop", name: Some("machineId") }
Non-Breaking Changes (12)
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.authority" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.machineId" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.nonce" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.sig" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.outputSchemaHash" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.toolSchemaHash" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.brokerageCountersignature" }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.outputSchemaHash", kind: "prop", name: Some("outputSchemaHash") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.toolSchemaHash", kind: "prop", name: Some("toolSchemaHash") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.brokerageCountersignature", kind: "prop", name: Some("brokerageCountersignature") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body.brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature", kind: "ref", name: None }

Migration Guidance

Added Elements

  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.authority" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.machineId" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.nonce" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.sig" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.outputSchemaHash" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.toolSchemaHash" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.brokerageCountersignature" }

Additional Notes

  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.sig", kind: "prop", name: Some("sig") }
  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.nonce", kind: "prop", name: Some("nonce") }
  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.authority", kind: "prop", name: Some("authority") }
  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.machineId", kind: "prop", name: Some("machineId") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.outputSchemaHash", kind: "prop", name: Some("outputSchemaHash") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.toolSchemaHash", kind: "prop", name: Some("toolSchemaHash") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.brokerageCountersignature", kind: "prop", name: Some("brokerageCountersignature") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body.brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature", kind: "ref", name: None }
1 1
{
2 2
  "id": "dev.cocore.compute.receipt",
3 3
  "defs": {
4 4
    "main": {
5 5
      "key": "tid",
6 6
      "type": "record",
7 7
      "record": {
8 8
        "type": "object",
9 9
        "required": [
10 10
          "job",
11 11
          "requester",
12 12
          "model",
13 13
          "inputCommitment",
14 14
          "outputCommitment",
15 15
          "tokens",
16 16
          "startedAt",
17 17
          "completedAt",
18 18
          "price",
19 19
          "attestation",
20 20
          "enclaveSignature"
21 21
        ],
22 22
        "properties": {
23 23
          "job": {
24 24
            "ref": "com.atproto.repo.strongRef",
25 25
            "type": "ref",
26 26
            "description": "Strong-ref to the requester's dev.cocore.compute.job record."
27 27
          },
28 28
          "tier": {
29 29
            "ref": "dev.cocore.compute.defs#tier",
30 30
            "type": "ref",
31 31
            "description": "The confidentiality tier this job actually ran under. Set by the provider to `attested-confidential` only when the input was sealed to a verified, enclave-bound ephemeral session key AND served by a measured native engine under a hardware-attested posture; otherwise `best-effort`. A requester recomputes this from the receipt's attestation + sessionKeyCommitment rather than trusting the field. Optional / additive; absent equivalent to `best-effort`."
32 32
          },
33 33
          "model": {
34 34
            "type": "string",
35 35
            "maxLength": 256
36 36
          },
37 37
          "price": {
38 38
            "ref": "dev.cocore.compute.defs#money",
39 39
            "type": "ref",
40 40
            "description": "MUST be <= job.priceCeiling. Currency MUST match job.priceCeiling.currency."
41 41
          },
42 42
          "params": {
43 43
            "ref": "#generationParams",
44 44
            "type": "ref",
45 45
            "description": "Optional record of the sampling parameters the provider committed to for this job. Integer-only (canonical JSON forbids floats): temperature/top_p are carried as integer milliunits. Covered by enclaveSignature, so a requester can prove the provider claimed these settings."
46 46
          },
47 47
          "tokens": {
48 48
            "ref": "dev.cocore.compute.defs#tokenCounts",
49 49
            "type": "ref"
50 50
          },
51 51
          "proBono": {
52 52
            "type": "boolean",
53 53
            "description": "True when the provider served this job pro bono under its `dev.cocore.compute.provider.proBono` election — free, unmetered, no exchange cut. A pro-bono receipt MUST carry `price.amount: 0` and `tokens: { in: 0, out: 0 }`: the work is explicitly not counted, so neither figure is a billing claim. An exchange settling a `proBono: true` receipt takes no fee and moves no balance (`amountCharged`, `providerPayout`, and `exchangeFee` are all 0). Covered by `enclaveSignature` like every other field, so the carve-out is part of the signed, self-verifying record rather than an off-record side channel. Absent/false ≡ a normal metered, billable receipt. Optional / additive; pre-2026-06 readers ignore it and still see a well-formed zero-price receipt."
54 54
          },
55 55
          "requester": {
56 56
            "type": "string",
57 57
            "format": "did",
58 58
            "description": "DID of the requester. Denormalized from the job record for indexer convenience; MUST equal the DID owning the job record."
59 59
          },
60 60
          "startedAt": {
61 61
            "type": "string",
62 62
            "format": "datetime"
63 63
          },
64 64
          "attestation": {
65 65
            "ref": "com.atproto.repo.strongRef",
66 66
            "type": "ref",
67 67
            "description": "Strong-ref to a dev.cocore.compute.attestation record published by this provider. completedAt MUST fall within [attestedAt, expiresAt] of that attestation."
68 68
          },
69 69
          "completedAt": {
70 70
            "type": "string",
71 71
            "format": "datetime"
72 72
          },
73 73
          "sessionNonce": {
74 74
            "type": "string",
75 75
            "maxLength": 64,
76 76
            "minLength": 32,
77 77
            "description": "Optional lowercase hex of the fresh requester nonce that the ephemeral session key was bound to (the freshness challenge for this job). Pairs with sessionKeyCommitment. Covered by enclaveSignature."
78 78
          },
79 79
          "inputCommitment": {
80 80
            "type": "string",
81 81
            "maxLength": 64,
82 82
            "minLength": 64,
83 83
            "description": "MUST equal job.inputCommitment."
84 84
          },
85 85
          "outputCipherURL": {
86 86
            "type": "string",
87 87
            "format": "uri",
88 88
            "description": "Optional URL where the encrypted output lives."
89 89
          },
90 90
          "enclaveSignature": {
91 91
            "type": "bytes",
92 92
            "maxLength": 256,
93 93
            "description": "Secure Enclave P-256 signature (DER) over a sorted-key canonical JSON of every other field in this record. Verified against the publicKey of the strong-reffed attestation. This binding survives PDS migration: the repo-commit signature changes when keys rotate, but the enclaveSignature does not."
94 94
          },
95 95
          "outputCommitment": {
96 96
            "type": "string",
97 97
            "maxLength": 64,
98 98
            "minLength": 64,
99 99
            "description": "SHA-256 hex over the plaintext output bytes — the decrypted result the requester receives. (The earlier 'encrypted output' wording was a doc error; the provider has always committed to the plaintext, which is what a requester can verify after decrypting. Use outputCipherCommitment to commit to the encrypted bytes on the wire.)"
100 100
          },
101 101
          "reasoningCommitment": {
102 102
            "type": "string",
103 103
            "maxLength": 64,
104 104
            "minLength": 64,
105 105
            "description": "Optional SHA-256 hex over the plaintext reasoning ('thinking') output bytes the provider produced for this job, separate from outputCommitment which covers only the answer the requester acts on. Present only when the model emitted reasoning on a distinct channel (a sibling reasoning_content field, or inline <think>...</think> tags the provider split out). Lets a requester independently verify the reasoning trace without it perturbing the answer's commitment. Covered by enclaveSignature."
106 106
          },
107 107
          "sessionKeyCommitment": {
108 108
            "type": "string",
109 109
            "maxLength": 64,
110 110
            "minLength": 64,
111 111
            "description": "Optional SHA-256 hex over (ephemeralPubKey || sessionNonce) — the per-job ephemeral X25519 key the requester sealed the input to, bound to the request nonce. Present when the job ran under the forward-secret confidential handshake (the enclave minted a fresh ephemeral key, enclave-signed it against the requester's nonce, and the requester sealed to that key after verifying it). Lets a requester prove after the fact that its prompt was sealed to a key the measured enclave controlled for this job, not the long-lived encryptionPubKey. Covered by enclaveSignature."
112 112
          },
113 113
          "outputCipherCommitment": {
114 114
            "type": "string",
115 115
            "maxLength": 64,
116 116
            "minLength": 64,
117 117
            "description": "Optional SHA-256 hex over the EXACT encrypted bytes delivered to the requester (the sealed reply). Lets a requester confirm the ciphertext they received is the one the provider's enclaveSignature commits to — defends against an intermediary swapping the delivered bytes. Covered by enclaveSignature like every other field."
118 +
          },
119 +
          "brokerageCountersignature": {
120 +
            "ref": "#brokerageCountersignature",
121 +
            "type": "ref",
122 +
            "description": "ADR-0004: the session-bound witness of the BROKERAGE (the matchmaking authority the requester routed through — e.g. the advisor). The brokerage live-challenges the machine it dispatches to, so its countersignature proves 'authority X dispatched THIS job to the machine it attested, and that machine served it'. This is what elevates a receipt to `attested-confidential` under the forkable-authority model: a self-published attestation record is NOT sufficient without a trusted brokerage's countersignature. UNLIKE every other field, this is NOT covered by `enclaveSignature` — it is signed by the brokerage, not the provider, and is added after the provider signs (verifiers strip it before checking enclaveSignature, exactly as they strip enclaveSignature and $type). A confidential requester REQUIRES this from an authority in its trust set (default: cocore's brokerage DID); best-effort receipts omit it. Optional / additive."
118 123
          }
119 124
        }
120 125
      }
121 126
    },
122 127
    "generationParams": {
123 128
      "type": "object",
124 129
      "properties": {
125 130
        "seed": {
126 131
          "type": "integer",
127 132
          "description": "RNG seed, when the provider ran with a fixed seed (enables reproducibility claims)."
128 133
        },
129 134
        "maxTokens": {
130 135
          "type": "integer",
131 136
          "minimum": 0,
132 137
          "description": "Max output tokens requested for this job."
133 138
        },
134 139
        "topPMilli": {
135 140
          "type": "integer",
136 141
          "maximum": 1000,
137 142
          "minimum": 0,
138 143
          "description": "Nucleus sampling top_p × 1000 (e.g. 0.95 -> 950). Omitted when the provider used the model default."
139 144
        },
145 +
        "toolSchemaHash": {
146 +
          "type": "string",
147 +
          "maxLength": 64,
148 +
          "minLength": 64,
149 +
          "description": "SHA-256 hex over the canonical JSON of the tools the provider used for this job. Present only when the job specified tools. Covered by enclaveSignature, so a requester can prove the provider honored the tool definitions they asked for."
150 +
        },
151 +
        "outputSchemaHash": {
152 +
          "type": "string",
153 +
          "maxLength": 64,
154 +
          "minLength": 64,
155 +
          "description": "SHA-256 hex over the canonical JSON of the outputSchema the provider used for this job. Present only when the job specified outputSchema. Covered by enclaveSignature, so a requester can prove the provider honored the schema they asked for."
156 +
        },
140 157
        "temperatureMilli": {
141 158
          "type": "integer",
142 159
          "minimum": 0,
143 160
          "description": "Sampling temperature × 1000 (e.g. 0.7 -> 700). Omitted when the provider used the model default."
144 161
        }
145 162
      },
146 163
      "description": "Sampling parameters committed to in a receipt. Integer-only because the canonical signing form forbids floats — temperature and top_p are carried as milliunits (value × 1000, e.g. temperature 0.7 -> 700)."
164 +
    },
165 +
    "brokerageCountersignature": {
166 +
      "type": "object",
167 +
      "required": [
168 +
        "authority",
169 +
        "machineId",
170 +
        "nonce",
171 +
        "sig"
172 +
      ],
173 +
      "properties": {
174 +
        "sig": {
175 +
          "type": "bytes",
176 +
          "maxLength": 256,
177 +
          "description": "P-256 signature (DER) by the brokerage authority key over the canonical message described above. Verified against the key in the `authority` DID document."
178 +
        },
179 +
        "nonce": {
180 +
          "type": "string",
181 +
          "maxLength": 64,
182 +
          "minLength": 16,
183 +
          "description": "Lowercase-hex nonce unique to this witness (the brokerage's per-job witness id). Bound into `sig`."
184 +
        },
185 +
        "authority": {
186 +
          "type": "string",
187 +
          "format": "did",
188 +
          "description": "The brokerage's DID (did:web or did:plc). The verifier resolves its DID document to get the signing key, and MUST require this DID to be in its configured trust set — validity is relative to a named authority the verifier chooses to trust (CA-style trust roots)."
189 +
        },
190 +
        "machineId": {
191 +
          "type": "string",
192 +
          "maxLength": 256,
193 +
          "description": "The stable per-machine id (the provider record's rkey / advisor machine_id) the brokerage dispatched to and live-challenged. Bound into `sig` so the witness names the specific machine that served."
194 +
        }
195 +
      },
196 +
      "description": "A brokerage's session-bound witness on a receipt (ADR-0004). Verified OFFLINE against the `authority` DID document's signing key (invariant #2 holds — the live challenge happened at seal time; the receipt stays verifiable after the fact). The signature covers the sorted-key canonical JSON of `{ authority, attestation, jobCid, jobUri, machineId, nonce, requester }`, where `attestation`/`jobUri` are the `uri` of the receipt's respective strong-refs, `jobCid` is the receipt's `job.cid`, and `requester` is the receipt's `requester` — so the witness is bound to this exact job, requester, serving machine, and attested identity, and cannot be lifted onto another receipt."
147 197
    }
148 198
  },
149 199
  "$type": "com.atproto.lexicon.schema",
150 200
  "lexicon": 1,
151 201
  "description": "A signed receipt of a single completed compute job. Published by the provider in its own repo. Strong-refs the requester's job and the active attestation. Carries an additional Secure-Enclave-bound signature so it remains verifiable across PDS migrations."
152 202
}

Compare Other Versions

Lexicon Garden

@