[SCITT] Re: CCS (-09): a verifier-side runtime evidence record for agent tool calls - boundary with SCITT work (individual submission)
Guigui Wang <wangguigui@correctover.com> Tue, 15 September 2026 16:00 UTC
Received: from mail-m15584.qiye.163.com (mail-m15584.qiye.163.com [101.71.155.84]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 546CB46 for <scitt@ietf.org>; Tue, 15 Sep 2026 16:00:30 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=correctover.com header.s=default header.b=fc+VrFgX; dmarc=pass (policy=quarantine) header.from=correctover.com; spf=pass (mx.ietf.org: domain of wangguigui@correctover.com designates 101.71.155.84 as permitted sender) smtp.mailfrom=wangguigui@correctover.com
Received: from [10.5.127.196] (unknown [115.190.127.223]) by smtp.qiye.163.com (Hmail) with ESMTP id 4ddbf1d0b; Tue, 15 Sep 2026 23:59:54 +0800 (GMT+08:00)
From: Guigui Wang <wangguigui@correctover.com>
To: kontakt@b7n0de.com
Date: Tue, 15 Sep 2026 23:59:53 +0800
Message-ID: <178948799378.10.2350348840232548838@correctover.com>
In-Reply-To: <T0NY85Sq4z5zDKLJ_M01K2UyzqlFXkC3DmYAN6KFs6EmUDO-jqgq4kDMVFuPlzzpt37Voryu3oLEaxbUU-b3cy9dVCufioIjwvfTy8xyhYY=@b7n0de.com>
References: <T0NY85Sq4z5zDKLJ_M01K2UyzqlFXkC3DmYAN6KFs6EmUDO-jqgq4kDMVFuPlzzpt37Voryu3oLEaxbUU-b3cy9dVCufioIjwvfTy8xyhYY=@b7n0de.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-HM-Tid: 0aa0a5cbd4da03cfkunm2f9079f1f7883c
X-HM-MType: 4
X-HM-Spam-Status: e1kfGhgUHx5ZQUpXWQgPGg8OCBgUHx5ZQUlOS1dZFg8aDwILHllBWSg2Ly tZV1koWUFDSUNOSEhLS043V1kYFggdWUFKV1ktWUFJV1kPCRoVCBIfWUFZQ0hIQlZJGENIGUoYSx hJHUhWHQkeHlUCFhMWGhIXJBQOD1lXWRgSC1lBWUpKTlVKQktVSklMVUlJSFlXWRYaDxIVHRRZQV lPS0hVSktISkhNSlVKS0tVSkJLS1kG
DKIM-Signature: a=rsa-sha256; b=fc+VrFgXUERwNVlBggKHbZFXWxgQIN99uWfuROwIW4hRY1OnhwwjQ46I/m4brOvJAIqXn2pt2UZ1OH6yC0sPuLcfSY9VN0+oNAO+24VXt5Z9S33maTpvnwikRV9u8OAjqOSLuyk7vD2o5T/n3WEU02BKXk/0Z8nNzzouMZ+05DVSbQ18UEZybuGZZRo4r0XvMXgengeMFNGBQdHB6sry9fcuLMCWXFpJgjLH7cavr3CiKgR1yHF2ynyqbScBVbTBc1GNCwtjQJP4Z8o54VX5iR31Zapq0EyGjEHWZETFCITKrHExyPdqJI59meKHAbyXSLSidwfhM2pv/p5bzd6jDw==; c=relaxed/relaxed; s=default; d=correctover.com; v=1; bh=dMXjRQz1icPwxitzP1a6+mEgsy4AYUJQ5DjxcZGlTeg=; h=date:mime-version:subject:message-id:from;
X-Spamd-Bar: -
Message-ID-Hash: 3QFEZABPDMBINXUX3RTW64JMNKLWQHMJ
X-Message-ID-Hash: 3QFEZABPDMBINXUX3RTW64JMNKLWQHMJ
X-MailFrom: wangguigui@correctover.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-scitt.ietf.org-0; header-match-scitt.ietf.org-1; header-match-scitt.ietf.org-2; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: scitt@ietf.org
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [SCITT] Re: CCS (-09): a verifier-side runtime evidence record for agent tool calls - boundary with SCITT work (individual submission)
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/-1azeMP3zUgiPnEX_-CjKoTRJCU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>
Konrad, Thanks for reading -09 so carefully, and for stating the boundary in your own words. Your reading matches the intent: CCS is a bounded, verifier-side admission record for a single tool call, and RFC 9943 keeps payload content outside the SCITT charter. When a CCS receipt is carried inside a registered signed statement it is composition, not a dependency, and the draft says exactly that and requests no IANA allocations. Two things in your proofbundle note are genuinely useful to us. First, your rule that a green run over accept-only cases is not conformance, and that every capability the corpus proves must also carry the rejection path, is the same anti-omission floor CCS tries to set for pre-execution verification; it is helpful to see it enforced in a shipping verifier rather than only asserted in text. Second, thank you for naming the open seam plainly - "provenance SHAPED, not provenance", with the gate verdict bound to the source tree and not yet to the shipped wheel. Collapsing that distinction is exactly the kind of grade inflation that makes evidence decay, and I would rather rely on partners who name the gap than partners who hide it. Happy to keep the two efforts interoperable at the payload layer without coupling them. Thanks, Guigui Wang Correctover - AI Reliability draft: https://datatracker.ietf.org/doc/draft-correctover-ccs/ (individual submission, not an RFC or IETF endorsement)
- [SCITT] CCS (-09): a verifier-side runtime eviden… Guigui Wang
- [SCITT] Re: CCS (-09): a verifier-side runtime ev… Konrad Gruszka
- [SCITT] Re: CCS (-09): a verifier-side runtime ev… Guigui Wang