Since #116, scheduled envelopes are leafed over the final signed record R. Entries written before it leaf the producer envelope E, and per #102 they stay valid as evidence of E inclusion only.
An entry carries batch_id, canonicalization_id, leaf_count, merkle_root, mmr_checkpoint, producer and ts. None of them says which subject its leaves cover: canonicalization_id names the byte construction, not the subject. A verifier proving inclusion of R against an older entry fails with nothing in the entry to say why, and the same holds for E against a newer one. Today the only way to tell is the entry's timestamp against the #116 merge.
Proposal: add leaf_subject (envelope or record) to every entry written from now on. An entry without it predates the marker, and its subject is inferred from the staged file shape as it is today.
Open question for the format: does leaf_subject belong in the entry, or in the anchor profile that canonicalization_id names?
Since #116, scheduled envelopes are leafed over the final signed record R. Entries written before it leaf the producer envelope E, and per #102 they stay valid as evidence of E inclusion only.
An entry carries
batch_id,canonicalization_id,leaf_count,merkle_root,mmr_checkpoint,producerandts. None of them says which subject its leaves cover:canonicalization_idnames the byte construction, not the subject. A verifier proving inclusion of R against an older entry fails with nothing in the entry to say why, and the same holds for E against a newer one. Today the only way to tell is the entry's timestamp against the #116 merge.Proposal: add
leaf_subject(envelopeorrecord) to every entry written from now on. An entry without it predates the marker, and its subject is inferred from the staged file shape as it is today.Open question for the format: does
leaf_subjectbelong in the entry, or in the anchor profile thatcanonicalization_idnames?