spec/ only; the rest of the Anyroute repository keeps its own license. This page is built from spec/CHANGELOG.md each time the site is built.All notable changes to the SEAL specification. The format follows Keep a Changelog, and versions follow Semantic Versioning. Before 1.0.0 any document may change incompatibly; implemented wire formats keep their own version strings.
[Unreleased]#
Added#
0001-attestation.mdSection 5.4: signed host admission policy schema, canonical bytes, immutable consecutive publication, Ed25519 signatures,host_policykey-log entries, fail-closed quote-bound comparisons and probation. Section 3.1.1 clarifies v1 compatibility and v2 field constraints.0002-transport.mdSection 3.3: the distinct encrypted-chat gateway adapter, client checks, metadata visibility and honest limits; ordinary chat and direct sidecar HPKE retain their existing formats.README.mdadds corresponding repository and hosted status rows.0001-attestation.mdSection 3.1.1: opt-in SHA-256 sidecar bindings v2 commits the pinned source archive hash, engine name/image digest and model ID/digest, with legacy v1 verification preserved and declaration limits stated.0002-transport.mdSection 5.6: laneunlinkableover the onion service is implemented, off by default (UNLINKABLE_VIA_ONION). Tor takes the place of the independent relay; onion requests are recognised only by the secret the onion proxy sets (compared in constant time), address headers are removed and never used on them, payment and endpoint rules are those of Section 5.5, streaming works, and the router refuses to start with the switch on unless the onion address, the proxy secret and blind tokens are configured. Sections 5.1, 5.4 and 5.5 name the second path, andGET /api/v1/statusreportslanes.unlinkable.via.README.md: theunlinkablelane row, G5, party R, an honest limit for the Tor path, and status rows.0001-attestation.mdSection 6.2: public-log anchoring (Rekor) is implemented, off by default, as an alternative to cosigning witnesses. Each new checkpoint, at most once per interval, becomes a Rekorhashedrekordentry over the checkpoint as the log signed it, signed with a dedicated ECDSA P-256 anchoring key and verified before it is served (GET /api/v1/tlog/rekor,/api/v1/tlog/rekor/{size},/api/v1/tlog/rekor/key); a client may accept a checkpoint on a verified anchor in place of the witness quorum; production starts the log with either. The section states the limits: after-the-fact detection, not prevention, and only when clients or monitors check Rekor.README.md: its status row.0001-attestation.mdSection 6.2: the witnessed log is implemented, off by default. Entry format and kinds (receipt keys, Oblivious HTTP key configurations, blind-token issuer keys, measurement bundles, sidecar key bindings), C2SP tlog-tiles serving, signed-note checkpoints, cosignature/v1 witnesses that check consistency before cosigning and hand cosignatures back withPOST /api/v1/tlog/cosignatures, and the client's split-view rule;README.mdstatus row updated.0004-receipts.mdSection 5.2: per-host anchoring of node receipts is implemented, off by default. The router takes each attested host's receipt key from the boot quote it verified, keeps only leaves signed by that key under that attestation, roots them per host and interval, posts each root withReceiptAnchor.anchorAttestedwhere a chain is configured (statuslocalotherwise), and servesGET /api/v1/host-anchors/proof/{leaf}andPOST /api/v1/host-anchors/proof;packages/clientchecks a receipt against the proof and the root on chain (verifyHostAnchor).0002-transport.mdSection 4.5: chunked Oblivious HTTP is implemented, off by default (OHTTP_CHUNKED_ENABLEDon the gateway,RELAY_CHUNKED_ENABLEDon a relay). Chunked requests, responses sent chunk by chunk as they are produced so"stream": trueworks through a relay, the final-chunk rule for truncation,Incremental: ?1,gateway.chunkedin the relay list, and an opt-in check of the key configuration against the witnessed log; a mandatory inclusion proof, relay diversity, fixed-tick padding and fingerprint normalisation stay planned.README.md: its status row.0005-policy.mdSection 3.4: privacy-safe stats as implemented. Four counter families with fixed labels and a per-request contribution bound of 1, hourly release with Laplace noise through Mironov's snapping mechanism and a CSPRNG, non-negative post-processing, the per-day epsilon ledger, theGET /v1/statsdocument, and the router's rule that attested and unlinkable traffic reaches public metrics only through these counters.0004-receipts.mdSection 4: router receipts v2 are implemented. A COSE_Sign1 (RFC 9052) signed EdDSA with the router's Ed25519 receipt key over a deterministic-CBOR (RFC 8949) claim set; bucketed token counts; the chunk hash chain over router streams; the v2 anchor leaf beside the v1 leaf in the same hourly tree;GET /api/v1/receipts/{id}/proof, withanchoredtrue only once the root is on chain; a byte-exact test vector.
Changed#
0002-transport.mdSection 5: lanes are first-class in the router. How a lane is chosen (request, key default, saved route, andunlinkableby default for a relayed blind-token request), enforcement with no fallback (503no_attested_endpoint), 403lane_requires_anonymous_authfor an API key or wallet onunlinkablewith an opt-in downgrade toattested, the lane-aware selection weightuptime * quality * attested_bonus / price^2, and lane availability in the model list and status. Replaces 409lane_unavailableand, for lanes, 503disclosure_provider_unavailable.0005-policy.mdSection 4.3: planned telemetry now covers only what Section 3.4 does not (per-category counts, attested privacy parameters).0004-receipts.mdSection 4.2: each chain valuec_itravels as an SSE comment line (: anyroute-chain <i> <hex>) after the i-th event instead of in the event'sidfield, so clients that treat every event block as starting withdata:keep working.README.md: status rows for privacy-safe stats and for receipts v2.
0.1.0 - 2026-09-29#
First public draft.
Added#
README.md: what SEAL is, the lanespublic,attestedandunlinkable, guarantees G1 to G8 as design targets, what each party learns, honest limits, and a status table of what exists in this repository and what is planned.0001-attestation.md: the sidecar's evidence document and version 1 bindings (report_data = SHA-256(canonical_json(bindings)) || nonce), the attestation reference and certificate, the model digest, boot order, measurement registry and Rekor bundles; planned version 2 binding, RTMR3 events, manifests, witnessed log and KMS.0002-transport.md: inner encryptionanyroute-hpke/v1(RFC 9180) with its request layout and framed response; the Oblivious HTTP gateway (RFC 9458, RFC 9292), epoch keys, signed key history and relays; the onion service; lane rules and refusals; planned chunked inner encryption and chunked Oblivious HTTP.0003-credits.md: Privacy Pass type0x0002blind RSA tokens (RFC 9474, RFC 9576 to RFC 9578) as implemented; planned blinded e-cash credits with BDHKE, DLEQ proofs, P2PK locks and change.0004-receipts.md: receipt claims across node receipts v1, router receipts v1 and planned COSE_Sign1 receipts v2; the chunk hash chain; hourly Merkle anchoring; the ten-step verification order and what can be checked today.0005-policy.md: the measured in-enclave classifier policy, refusal outcomes and receipts; plannedpolicy.json, streaming enforcement, noisy telemetry and disputes without logs.LICENSE: Apache License 2.0 for this folder.