WAI Extension: Unidirectional Delivery
Mirrored from the canonical text at commit 117bad22 ().
Status: Draft. Covers bearers with no return path — terrestrial broadcast, satellite, and multicast object carriage — where the sink receives and can never answer. Generalised from deployed national early-warning systems, which are the only place these seams are currently exercised at scale. WAI defines no bearer here and none of this requires one. Keywords MUST, MUST NOT, SHOULD, MAY are RFC 2119/8174.
1. What breaks without a return path
Three assumptions in the tree quietly presume the sink can talk back:
jwp-receiptsassumes relay-chain linkage throughout, and a chain implies hops that report.- Targeting presumes the source can learn something about the sink.
- Pre-emption — an object that must displace what is playing — has no signer class, because nothing in WAI has needed to assert authority over a sink before.
None of these is repaired by defining a bearer. Each is a seam that can be specified transport-independently, and each is specified below at the strength it actually holds — which in one case is considerably weaker than it looks.
2. Sink-evaluated predicates
A predicate capability carries, in the object, a condition the sink evaluates against locally-held state the source never learns. The canonical deployed instance is geographic: an object is relevant to a region, the receiver holds its own location, and the source is told nothing.
The determinism contract is predicate-equivalence, in the shape
state-feeds §3 uses: two conforming sinks holding the same
local state MUST reach the same verdict on the same predicate.
- A predicate MUST be a total function of the object and the sink’s declared state class. A predicate that can consult anything else is not evaluable twice.
- A predicate MUST NOT be able to cause a request. The moment evaluation emits a signal, the privacy property is gone and this is ordinary targeting.
The specifiable property is determinism and auditability, not enforcement. Every sink on the bearer receives every byte, and a sink can lie about its own state. Nothing here prevents that and nothing here should claim to. The real claim is narrow and worth having: the source learns nothing — which is the dual of source-side targeting, where the source learns everything and the sink is told nothing.
3. Authority and pre-emption
Pre-emption is the highest-authority instruction a media object can carry: it displaces what a person chose to watch. WAI has no signer class for it, so today an object either has no such field or has one anyone may set.
- An object asserting pre-emption MUST carry a priority field and be signed by a key the sink holds in a trust anchor for that assertion.
- The trust anchor MUST be sink-held and provisioned out of band. A trust anchor delivered over the bearer it authorises is not a trust anchor.
- A sink MUST NOT act on pre-emption from an unanchored key, and MUST NOT treat a valid signature alone as authority — signature validity establishes who signed, never that they were entitled to.
- Authority MUST NOT be inferred from position in the delivery chain. The entity that transmits is not thereby entitled to interrupt.
- A key-log anchor a sink fetched from an origin on first use
(
jwp-receipts§7.3) is not a trust anchor here. When a class is registered for pre-emption, its authority is confirmed only under a pinned anchor, and only for a key the pinned revision itself lists with it (jwp-receipts §7.4, §7.5).
4. Detached receipts
A unidirectional bearer cannot carry a receipt back, so jwp-receipts’
relay-chain model does not apply. The deliverable is an honest profile, not a
proof:
- A publisher MAY emit receipts for objects sent over a unidirectional bearer, and those receipts attest what was transmitted, not what was received and not what was rendered.
- Such a receipt MUST declare the bearer as unidirectional, so a relying party cannot mistake transmission for delivery.
- A sink MAY retain object commitments and reconcile them out of band later.
A reconciliation MUST be reported apart from the publisher’s chain — as a
claim(jwp-receipts§2.4.3), under a class registered for it in jwp-receipts §2.4.4, which none yet is — and never folded into the publisher’s chain as though it had been a hop. Like abinding-recoveryrecord (jwp-receipts §2.6.3), it attests less than a hop would, and says so.
No receipt can prove rendering over a bearer with no return path. This section does not attempt it. What it prevents is the quieter error: a receipt that says “delivered” because the transmitter transmitted, on a link that cannot tell it whether anyone was listening.
5. Framing
These seams are exercised today in national early-warning deployments, which is where a sink evaluating a condition the source never learns has had to be made to work at scale. The mechanisms are worth having for that reason and not only that one: a container that can only describe two-way delivery cannot describe broadcast, and broadcast is not a legacy case.