Skip to content

Permit clock-skew leeway for Trust Manifest expiry - #126

Closed
jonathanhefner wants to merge 1 commit into
Agent-Card:mainfrom
jonathanhefner:agent/permit-clock-skew-leeway
Closed

jonathanhefner wants to merge 1 commit into
Agent-Card:mainfrom
jonathanhefner:agent/permit-clock-skew-leeway

Conversation

@jonathanhefner

Copy link
Copy Markdown
Collaborator

Consumers currently must treat a Trust Manifest as stale once expiresAt has passed and cannot rely on its claims as current or count its entry as Level 3. Clock differences can therefore cause premature rejection.

Permit clock-skew leeway chosen by the implementation or local policy, without prescribing an amount or requiring explicit caller configuration. Apply the allowance consistently to staleness, rejection, current reliance, and Level 3 qualification.

Validation: independent review of the final wording, git diff --check, and a successful specification build using uv run --offline --frozen python tools/build_spec.py specification/ai-catalog.md dist/index.html --config specification/respec-config.json.

Exact wall-clock agreement cannot be assumed between publishers and
consumers. Permit implementations or local policy to choose clock-skew
leeway without prescribing an amount or requiring explicit caller
configuration.

Apply that allowance consistently to `expiresAt` staleness, rejection,
current reliance, and Level 3 qualification.

Signed-off-by: Jonathan Hefner <jonathan@hefner.pro>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant