From d9f35b5506514a2b88a4d4df4f47114e3acbbde0 Mon Sep 17 00:00:00 2001 From: Narasimha-sc <166327228+Narasimha-sc@users.noreply.github.com> Date: Mon, 6 Jul 2026 18:13:07 +0000 Subject: [PATCH] plans: verify domain-claim round-trip fidelity (elimination now airtight) The one field that changes when a name is added is the domain claim, so the elimination's last assumption was its store/read fidelity. Verified: ToField SimplexDomain = decodeLatin1 . strEncode, FromField = strDecode . encodeUtf8 (simplexmq SimplexName.hs:127-129); domains are ASCII and canonical (lowercased via strDecode, and the link arrives canonical via StrJSON), so the round-trip is identity, and the name case yields a non-empty access reconstructing to Just. So every Eq-field except publicGroupId provably converges. Noted the separate empty-access -> Nothing degeneracy (Shared.hs:726) as latent/out-of-scope. --- plans/2026-07-06-fix-directory-name-reapproval.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/plans/2026-07-06-fix-directory-name-reapproval.md b/plans/2026-07-06-fix-directory-name-reapproval.md index e54ac4cd3a..024ef741c0 100644 --- a/plans/2026-07-06-fix-directory-name-reapproval.md +++ b/plans/2026-07-06-fix-directory-name-reapproval.md @@ -74,6 +74,19 @@ is permanent → `groupUpdated` true every cycle → re-approval on repeat. is merely the *occasion* (the owner republishing the link) that surfaces the pre-existing `publicGroupId` staleness. +The claim's round-trip fidelity — the one field that *changes* when a name is +added, hence the last assumption behind the elimination — was verified: `ToField +SimplexDomain = decodeLatin1 . strEncode` and `FromField = strDecode . encodeUtf8` +(`simplexmq SimplexName.hs:127-129`); domains are ASCII, so the stored value is +`strDecode (strEncode d)`, which equals `d` for a canonical (lower-cased) domain, +and the link's domain is already canonical (it arrives via `StrJSON`/`strDecode`). +Because the name sets `group_domain`, `toPublicGroupAccess` returns `Just` (not the +degenerate empty-access→`Nothing` at `Shared.hs:726`), so the claim reconstructs +equal. So every field except `publicGroupId` provably converges — the elimination +is airtight, not "assuming fidelity". (The empty-access→`Nothing` degeneracy at +`Shared.hs:726` is a separate latent asymmetry, unreachable here since a claim makes +the access non-empty; out of scope.) + ## 4. The fix (core, minimal): compare *content*, ignoring immutable identity `publicGroupId` is immutable cryptographic identity (`sha256(genesis root key)`,