Proof
The definition of a proof, the grant a blob names as the source of its signer's authority, which guides authority-first fetching and offers but never replaces evaluation of the authority graph.

Part of Stem. This page defines proof and fixes its role: a hint, not an input to authorization.

A proof is the CID of a Grant that a blob's signer names as the grant through which it holds the authority the blob needs; it tells a receiving peer which blob to fetch first, and it is never what decides whether the blob is authorized.

Three blob types carry a proof field: a Node blob signed by someone other than the owner, a Grant signed by a delegate, and an Offer request. In each case the proof says: here is the grant that makes me allowed to do this. A peer that receives the blob and lacks the grant fetches the grant first, then the grants it chains back to, then evaluates. A peer that already holds the grant evaluates immediately.

Why a hint and not a rule

Authority in Stem is late-bound: a grant works while its issuer has enough authority, and that is decided by the whole graph, not by any one blob. If proof were the rule, a revoked grant could be cited forever. If proof were required to be the exact chain, a grant renewed under a new blob would invalidate every Node signed under the old one. So evaluation ignores proof entirely and asks the graph: does this signer hold the needed level over this subject now? The field exists to make "authority first" cheap and to make writes self-explaining to a human reading the blob.

What authority first means

The team's transport direction says blobs should arrive authority first and uploads should carry the context that proves the write is allowed. In Stem that is three rules. Fetch returns Groups, Grants and Revocations before Nodes, and Nodes before state. The handler, on a blob whose signer it cannot yet authorize, fetches the blob's proof and its chain before stashing. Offer carries a proof so the receiver can decide, before fetching anything, whether the sender could possibly be allowed to write into the claimed scope. Together they make the stash rare rather than routine.

Where it is used

    Node blob: proof on writes by non-owners.

    Grant: proof on delegated grants.

    Link kind: the proof link the handler emits, flagged as authority evidence and retained with the source.

    The sync protocol: authority-first ordering.

Today (HM24)

A Ref has a capability field that the daemon records as a ref/capability link and otherwise ignores; authorization is the two-lookup rule over all indexed Capabilities. Stem keeps exactly that stance, renames the field to say what it is for, and gives it work to do in fetch ordering.

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime