dev.cocore.compute.receipt

cocore.dev

Schema Diff

+77 -0

From

CID
bafyreifmosc6lhk...
Indexed At
2026-06-17 21:16 UTC
View this version

To

CID
bafyreihmilyggly...
Indexed At
2026-07-26 20:05 UTC
View this version

Compatibility Analysis

Breaking Changes Detected

4 breaking changes, 24 non-breaking changes.

Breaking Changes (4)
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.sig", kind: "prop", name: Some("sig") }
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.nonce", kind: "prop", name: Some("nonce") }
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.authority", kind: "prop", name: Some("authority") }
  • RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.machineId", kind: "prop", name: Some("machineId") }
Non-Breaking Changes (24)
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.defs#tier" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.authority" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.machineId" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.nonce" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.sig" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.outputSchemaHash" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.toolSchemaHash" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.brokerageCountersignature" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.proBono" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.reasoningCommitment" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.sessionKeyCommitment" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.sessionNonce" }
  • AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.tier" }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.outputSchemaHash", kind: "prop", name: Some("outputSchemaHash") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.toolSchemaHash", kind: "prop", name: Some("toolSchemaHash") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.brokerageCountersignature", kind: "prop", name: Some("brokerageCountersignature") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.proBono", kind: "prop", name: Some("proBono") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.reasoningCommitment", kind: "prop", name: Some("reasoningCommitment") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.sessionKeyCommitment", kind: "prop", name: Some("sessionKeyCommitment") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.sessionNonce", kind: "prop", name: Some("sessionNonce") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.tier", kind: "prop", name: Some("tier") }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body.brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature", kind: "ref", name: None }
  • AddedEdge AddedEdge { src: "dev.cocore.compute.receipt:body.tier", tgt: "dev.cocore.compute.defs#tier", kind: "ref", name: None }

Migration Guidance

Added Elements

  • AddedVertex { vertex_id: "dev.cocore.compute.defs#tier" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.authority" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.machineId" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.nonce" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature.sig" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.outputSchemaHash" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt#generationParams.toolSchemaHash" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.brokerageCountersignature" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.proBono" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.reasoningCommitment" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.sessionKeyCommitment" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.sessionNonce" }
  • AddedVertex { vertex_id: "dev.cocore.compute.receipt:body.tier" }

Additional Notes

  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.sig", kind: "prop", name: Some("sig") }
  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.nonce", kind: "prop", name: Some("nonce") }
  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.authority", kind: "prop", name: Some("authority") }
  • Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.receipt#brokerageCountersignature", src: "dev.cocore.compute.receipt#brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature.machineId", kind: "prop", name: Some("machineId") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.outputSchemaHash", kind: "prop", name: Some("outputSchemaHash") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt#generationParams", tgt: "dev.cocore.compute.receipt#generationParams.toolSchemaHash", kind: "prop", name: Some("toolSchemaHash") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.brokerageCountersignature", kind: "prop", name: Some("brokerageCountersignature") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.proBono", kind: "prop", name: Some("proBono") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.reasoningCommitment", kind: "prop", name: Some("reasoningCommitment") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.sessionKeyCommitment", kind: "prop", name: Some("sessionKeyCommitment") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.sessionNonce", kind: "prop", name: Some("sessionNonce") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body", tgt: "dev.cocore.compute.receipt:body.tier", kind: "prop", name: Some("tier") }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body.brokerageCountersignature", tgt: "dev.cocore.compute.receipt#brokerageCountersignature", kind: "ref", name: None }
  • Non-breaking: AddedEdge { src: "dev.cocore.compute.receipt:body.tier", tgt: "dev.cocore.compute.defs#tier", kind: "ref", name: None }
1 1
{
2 2
  "id": "dev.cocore.compute.receipt",
3 3
  "defs": {
4 4
    "main": {
5 5
      "key": "tid",
6 6
      "type": "record",
7 7
      "record": {
8 8
        "type": "object",
9 9
        "required": [
10 10
          "job",
11 11
          "requester",
12 12
          "model",
13 13
          "inputCommitment",
14 14
          "outputCommitment",
15 15
          "tokens",
16 16
          "startedAt",
17 17
          "completedAt",
18 18
          "price",
19 19
          "attestation",
20 20
          "enclaveSignature"
21 21
        ],
22 22
        "properties": {
23 23
          "job": {
24 24
            "ref": "com.atproto.repo.strongRef",
25 25
            "type": "ref",
26 26
            "description": "Strong-ref to the requester's dev.cocore.compute.job record."
27 27
          },
28 +
          "tier": {
29 +
            "ref": "dev.cocore.compute.defs#tier",
30 +
            "type": "ref",
31 +
            "description": "The confidentiality tier this job actually ran under. Set by the provider to `attested-confidential` only when the input was sealed to a verified, enclave-bound ephemeral session key AND served by a measured native engine under a hardware-attested posture; otherwise `best-effort`. A requester recomputes this from the receipt's attestation + sessionKeyCommitment rather than trusting the field. Optional / additive; absent equivalent to `best-effort`."
32 +
          },
28 33
          "model": {
29 34
            "type": "string",
30 35
            "maxLength": 256
31 36
          },
32 37
          "price": {
33 38
            "ref": "dev.cocore.compute.defs#money",
34 39
            "type": "ref",
35 40
            "description": "MUST be <= job.priceCeiling. Currency MUST match job.priceCeiling.currency."
36 41
          },
37 42
          "params": {
38 43
            "ref": "#generationParams",
39 44
            "type": "ref",
40 45
            "description": "Optional record of the sampling parameters the provider committed to for this job. Integer-only (canonical JSON forbids floats): temperature/top_p are carried as integer milliunits. Covered by enclaveSignature, so a requester can prove the provider claimed these settings."
41 46
          },
42 47
          "tokens": {
43 48
            "ref": "dev.cocore.compute.defs#tokenCounts",
44 49
            "type": "ref"
45 50
          },
51 +
          "proBono": {
52 +
            "type": "boolean",
53 +
            "description": "True when the provider served this job pro bono under its `dev.cocore.compute.provider.proBono` election — free, unmetered, no exchange cut. A pro-bono receipt MUST carry `price.amount: 0` and `tokens: { in: 0, out: 0 }`: the work is explicitly not counted, so neither figure is a billing claim. An exchange settling a `proBono: true` receipt takes no fee and moves no balance (`amountCharged`, `providerPayout`, and `exchangeFee` are all 0). Covered by `enclaveSignature` like every other field, so the carve-out is part of the signed, self-verifying record rather than an off-record side channel. Absent/false ≡ a normal metered, billable receipt. Optional / additive; pre-2026-06 readers ignore it and still see a well-formed zero-price receipt."
54 +
          },
46 55
          "requester": {
47 56
            "type": "string",
48 57
            "format": "did",
49 58
            "description": "DID of the requester. Denormalized from the job record for indexer convenience; MUST equal the DID owning the job record."
50 59
          },
51 60
          "startedAt": {
52 61
            "type": "string",
53 62
            "format": "datetime"
54 63
          },
55 64
          "attestation": {
56 65
            "ref": "com.atproto.repo.strongRef",
57 66
            "type": "ref",
58 67
            "description": "Strong-ref to a dev.cocore.compute.attestation record published by this provider. completedAt MUST fall within [attestedAt, expiresAt] of that attestation."
59 68
          },
60 69
          "completedAt": {
61 70
            "type": "string",
62 71
            "format": "datetime"
63 72
          },
73 +
          "sessionNonce": {
74 +
            "type": "string",
75 +
            "maxLength": 64,
76 +
            "minLength": 32,
77 +
            "description": "Optional lowercase hex of the fresh requester nonce that the ephemeral session key was bound to (the freshness challenge for this job). Pairs with sessionKeyCommitment. Covered by enclaveSignature."
78 +
          },
64 79
          "inputCommitment": {
65 80
            "type": "string",
66 81
            "maxLength": 64,
67 82
            "minLength": 64,
68 83
            "description": "MUST equal job.inputCommitment."
69 84
          },
70 85
          "outputCipherURL": {
71 86
            "type": "string",
72 87
            "format": "uri",
73 88
            "description": "Optional URL where the encrypted output lives."
74 89
          },
75 90
          "enclaveSignature": {
76 91
            "type": "bytes",
77 92
            "maxLength": 256,
78 93
            "description": "Secure Enclave P-256 signature (DER) over a sorted-key canonical JSON of every other field in this record. Verified against the publicKey of the strong-reffed attestation. This binding survives PDS migration: the repo-commit signature changes when keys rotate, but the enclaveSignature does not."
79 94
          },
80 95
          "outputCommitment": {
81 96
            "type": "string",
82 97
            "maxLength": 64,
83 98
            "minLength": 64,
84 99
            "description": "SHA-256 hex over the plaintext output bytes — the decrypted result the requester receives. (The earlier 'encrypted output' wording was a doc error; the provider has always committed to the plaintext, which is what a requester can verify after decrypting. Use outputCipherCommitment to commit to the encrypted bytes on the wire.)"
85 100
          },
101 +
          "reasoningCommitment": {
102 +
            "type": "string",
103 +
            "maxLength": 64,
104 +
            "minLength": 64,
105 +
            "description": "Optional SHA-256 hex over the plaintext reasoning ('thinking') output bytes the provider produced for this job, separate from outputCommitment which covers only the answer the requester acts on. Present only when the model emitted reasoning on a distinct channel (a sibling reasoning_content field, or inline <think>...</think> tags the provider split out). Lets a requester independently verify the reasoning trace without it perturbing the answer's commitment. Covered by enclaveSignature."
106 +
          },
107 +
          "sessionKeyCommitment": {
108 +
            "type": "string",
109 +
            "maxLength": 64,
110 +
            "minLength": 64,
111 +
            "description": "Optional SHA-256 hex over (ephemeralPubKey || sessionNonce) — the per-job ephemeral X25519 key the requester sealed the input to, bound to the request nonce. Present when the job ran under the forward-secret confidential handshake (the enclave minted a fresh ephemeral key, enclave-signed it against the requester's nonce, and the requester sealed to that key after verifying it). Lets a requester prove after the fact that its prompt was sealed to a key the measured enclave controlled for this job, not the long-lived encryptionPubKey. Covered by enclaveSignature."
112 +
          },
86 113
          "outputCipherCommitment": {
87 114
            "type": "string",
88 115
            "maxLength": 64,
89 116
            "minLength": 64,
90 117
            "description": "Optional SHA-256 hex over the EXACT encrypted bytes delivered to the requester (the sealed reply). Lets a requester confirm the ciphertext they received is the one the provider's enclaveSignature commits to — defends against an intermediary swapping the delivered bytes. Covered by enclaveSignature like every other field."
118 +
          },
119 +
          "brokerageCountersignature": {
120 +
            "ref": "#brokerageCountersignature",
121 +
            "type": "ref",
122 +
            "description": "ADR-0004: the session-bound witness of the BROKERAGE (the matchmaking authority the requester routed through — e.g. the advisor). The brokerage live-challenges the machine it dispatches to, so its countersignature proves 'authority X dispatched THIS job to the machine it attested, and that machine served it'. This is what elevates a receipt to `attested-confidential` under the forkable-authority model: a self-published attestation record is NOT sufficient without a trusted brokerage's countersignature. UNLIKE every other field, this is NOT covered by `enclaveSignature` — it is signed by the brokerage, not the provider, and is added after the provider signs (verifiers strip it before checking enclaveSignature, exactly as they strip enclaveSignature and $type). A confidential requester REQUIRES this from an authority in its trust set (default: cocore's brokerage DID); best-effort receipts omit it. Optional / additive."
91 123
          }
92 124
        }
93 125
      }
94 126
    },
95 127
    "generationParams": {
96 128
      "type": "object",
97 129
      "properties": {
98 130
        "seed": {
99 131
          "type": "integer",
100 132
          "description": "RNG seed, when the provider ran with a fixed seed (enables reproducibility claims)."
101 133
        },
102 134
        "maxTokens": {
103 135
          "type": "integer",
104 136
          "minimum": 0,
105 137
          "description": "Max output tokens requested for this job."
106 138
        },
107 139
        "topPMilli": {
108 140
          "type": "integer",
109 141
          "maximum": 1000,
110 142
          "minimum": 0,
111 143
          "description": "Nucleus sampling top_p × 1000 (e.g. 0.95 -> 950). Omitted when the provider used the model default."
112 144
        },
145 +
        "toolSchemaHash": {
146 +
          "type": "string",
147 +
          "maxLength": 64,
148 +
          "minLength": 64,
149 +
          "description": "SHA-256 hex over the canonical JSON of the tools the provider used for this job. Present only when the job specified tools. Covered by enclaveSignature, so a requester can prove the provider honored the tool definitions they asked for."
150 +
        },
151 +
        "outputSchemaHash": {
152 +
          "type": "string",
153 +
          "maxLength": 64,
154 +
          "minLength": 64,
155 +
          "description": "SHA-256 hex over the canonical JSON of the outputSchema the provider used for this job. Present only when the job specified outputSchema. Covered by enclaveSignature, so a requester can prove the provider honored the schema they asked for."
156 +
        },
113 157
        "temperatureMilli": {
114 158
          "type": "integer",
115 159
          "minimum": 0,
116 160
          "description": "Sampling temperature × 1000 (e.g. 0.7 -> 700). Omitted when the provider used the model default."
117 161
        }
118 162
      },
119 163
      "description": "Sampling parameters committed to in a receipt. Integer-only because the canonical signing form forbids floats — temperature and top_p are carried as milliunits (value × 1000, e.g. temperature 0.7 -> 700)."
164 +
    },
165 +
    "brokerageCountersignature": {
166 +
      "type": "object",
167 +
      "required": [
168 +
        "authority",
169 +
        "machineId",
170 +
        "nonce",
171 +
        "sig"
172 +
      ],
173 +
      "properties": {
174 +
        "sig": {
175 +
          "type": "bytes",
176 +
          "maxLength": 256,
177 +
          "description": "P-256 signature (DER) by the brokerage authority key over the canonical message described above. Verified against the key in the `authority` DID document."
178 +
        },
179 +
        "nonce": {
180 +
          "type": "string",
181 +
          "maxLength": 64,
182 +
          "minLength": 16,
183 +
          "description": "Lowercase-hex nonce unique to this witness (the brokerage's per-job witness id). Bound into `sig`."
184 +
        },
185 +
        "authority": {
186 +
          "type": "string",
187 +
          "format": "did",
188 +
          "description": "The brokerage's DID (did:web or did:plc). The verifier resolves its DID document to get the signing key, and MUST require this DID to be in its configured trust set — validity is relative to a named authority the verifier chooses to trust (CA-style trust roots)."
189 +
        },
190 +
        "machineId": {
191 +
          "type": "string",
192 +
          "maxLength": 256,
193 +
          "description": "The stable per-machine id (the provider record's rkey / advisor machine_id) the brokerage dispatched to and live-challenged. Bound into `sig` so the witness names the specific machine that served."
194 +
        }
195 +
      },
196 +
      "description": "A brokerage's session-bound witness on a receipt (ADR-0004). Verified OFFLINE against the `authority` DID document's signing key (invariant #2 holds — the live challenge happened at seal time; the receipt stays verifiable after the fact). The signature covers the sorted-key canonical JSON of `{ authority, attestation, jobCid, jobUri, machineId, nonce, requester }`, where `attestation`/`jobUri` are the `uri` of the receipt's respective strong-refs, `jobCid` is the receipt's `job.cid`, and `requester` is the receipt's `requester` — so the witness is bound to this exact job, requester, serving machine, and attested identity, and cannot be lifted onto another receipt."
120 197
    }
121 198
  },
122 199
  "$type": "com.atproto.lexicon.schema",
123 200
  "lexicon": 1,
124 201
  "description": "A signed receipt of a single completed compute job. Published by the provider in its own repo. Strong-refs the requester's job and the active attestation. Carries an additional Secure-Enclave-bound signature so it remains verifiable across PDS migrations."
125 202
}

Compare Other Versions

Lexicon Garden

@