{
"_doc": "The clock contract of the admission checks. Every shape check and every verify* takes an optional trailing `nowMs`: absent means the reader's wall clock (what these functions always did), a finite number means that instant, and an explicit `null` means NO CLOCK — the deterministic form. The rows below are built at test time by re-signing the fixture order with `ts` offset from the reader's own `Date.now()`, because a far-future timestamp cannot be pinned as a literal in a file: the whole point of the clocked form is that its verdict moves with the reader.",
"_why_clock_free_exists": "A replicated fold — a bank folding signed payment orders out of its log, on two replicas whose clocks differ — must reach byte-identical state from the same entries. With a wall clock inside the shape check, two replicas three minutes apart disagree about whether one entry is a valid order, and their balances diverge. That is a partition bug in a money ledger. `orderShape(e, null)` and `verifyOrder(e, null)` are what such a fold calls.",
"order_ts_rows": [
{ "name": "a ts on the reader's own clock", "ts_offset_ms": 0, "clocked": true, "clock_free": true },
{ "name": "a ts one minute into the reader's future, inside SKEW_MS", "ts_offset_ms": 60000, "clocked": true, "clock_free": true },
{ "name": "a ts exactly SKEW_MS ahead — the last admissible instant", "ts_offset_ms": 120000, "clocked": true, "clock_free": true },
{ "name": "a ts three minutes ahead: two replicas this far apart used to disagree", "ts_offset_ms": 180000, "clocked": false, "clock_free": true },
{ "name": "a ts a day into the reader's future", "ts_offset_ms": 86400000, "clocked": false, "clock_free": true },
{ "name": "a ts an hour into the reader's PAST is admissible either way", "ts_offset_ms": -3600000, "clocked": true, "clock_free": true }
],
"_clock_free_is_not_weaker": "The clock-free form drops exactly one bound on a wpo — `ts` no further ahead than SKEW_MS — and keeps every bound a timestamp carries relative to itself. These rows are rejected by BOTH forms, and each names the bound that does the rejecting.",
"order_ts_relative_rows": [
{ "name": "exp equal to ts", "patch": { "exp_is_ts": true }, "bound": "exp > ts" },
{ "name": "exp before ts", "patch": { "exp_minus_ts": -1 }, "bound": "exp > ts" },
{ "name": "exp one millisecond past ts + MAX_TTL_MS", "patch": { "exp_minus_ts": 7776000001 }, "bound": "exp <= ts + MAX_TTL_MS" },
{ "name": "a negative ts", "patch": { "ts": -1 }, "bound": "ts >= 0" },
{ "name": "a fractional ts", "patch": { "ts": 1735689600000.5 }, "bound": "ts is an integer" }
],
"_now_sweep": "A clock-free verdict must be the same verdict for every conceivable nowMs, since it consults none. The clocked verdict over the same values is the control: it changes, which is what makes the sweep non-vacuous.",
"now_sweep": [0, 1, 1000000000000, 1735689600000, 4102444800000, 8640000000000000],
"_bad_clock_arguments": "A garbled clock argument reads as ABSENT (the wall clock), never as `null`. An admission check must not have a most-permissive setting that a typo can select.",
"bad_clock_arguments_behave_as_wall_clock": ["a string", true, [], {}, "NaN", "Infinity"],
"_settlement": "A settlement is judged against ONE clock, its own and its embedded order's, and the clock-free form keeps `ts >= po.ts - SKEW_MS`: a settlement still cannot predate the order it settles.",
"settlement_ts_rows": [
{ "name": "a bank ts on the reader's clock", "ts_offset_ms": 0, "clocked": true, "clock_free": true },
{ "name": "a bank ts three minutes into the reader's future", "ts_offset_ms": 180000, "clocked": false, "clock_free": true }
],
"settlement_before_its_order_ms": -180001,
"_issuance": "A wri carries no `exp` and embeds no order, so its ONLY clock-relative bound is `ts` no further ahead than SKEW_MS. The clock-free form drops exactly that bound and nothing else — the deterministic verdict a replicated fold needs, and the one the ledger's storage read uses.",
"issuance_ts_rows": [
{ "name": "a bank ts on the reader's clock", "ts_offset_ms": 0, "clocked": true, "clock_free": true },
{ "name": "a bank ts exactly SKEW_MS ahead — the last admissible instant", "ts_offset_ms": 120000, "clocked": true, "clock_free": true },
{ "name": "a bank ts three minutes into the reader's future", "ts_offset_ms": 180000, "clocked": false, "clock_free": true },
{ "name": "a bank ts a day into the reader's future", "ts_offset_ms": 86400000, "clocked": false, "clock_free": true },
{ "name": "a bank ts an hour into the reader's past is admissible either way", "ts_offset_ms": -3600000, "clocked": true, "clock_free": true }
],
"_pay_request": "A wpr carries no `ts`, so its only clock-relative bound is `exp` no further out than now + MAX_TTL_MS + SKEW_MS. The clock-free form drops it and keeps `exp` a positive integer. A link is read by a person, now, so `parsePayFragment` always uses the wall clock.",
"pay_request_exp_rows": [
{ "name": "an exp an hour out", "exp_offset_ms": 3600000, "clocked": true, "clock_free": true },
{ "name": "an exp a century out", "exp_offset_ms": 3153600000000, "clocked": false, "clock_free": true }
]
}