{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://thehiveryiq.com/.well-known/schemas/delivery-schedule-commitment-v1.json",
  "title": "Delivery Schedule Commitment Receipt, v1",
  "description": "Canonical schema for the Hive delivery schedule commitment receipt, canonical type delivery.schedule. In the commitment phase a party, presented as a salted commitment, fixes before a period starts the expected deliveries for that period: an update interval or a list of expected items presented as salted commitments with due instants, a grace allowance, and the fingerprint of the instrument set. In the reconciliation phase the receipt links the commitment receipt by digest, carries observed deliveries as fingerprints, and carries findings that the verifier recomputes under the committed rule: missing, late, indeterminate, on time, and extra deliveries.",
  "type": "object",
  "required": [
    "receipt_id",
    "payload_sha256",
    "sig_b64u",
    "key_id",
    "algorithm",
    "ts",
    "signed_body"
  ],
  "additionalProperties": false,
  "properties": {
    "receipt_id": {
      "type": "string",
      "pattern": "^r_delivery[.]schedule_[0-9]{10,}_[0-9a-f]{12}$"
    },
    "payload_sha256": {
      "type": "string",
      "pattern": "^[0-9a-f]{64}$"
    },
    "sig_b64u": {
      "type": "string",
      "pattern": "^[A-Za-z0-9_-]{86}$"
    },
    "key_id": {
      "type": "string",
      "pattern": "^did:(hive|web|key):[A-Za-z0-9._:%-]+$"
    },
    "algorithm": {
      "type": "string",
      "const": "Ed25519"
    },
    "ts": {
      "type": "integer",
      "minimum": 1000000000
    },
    "signed_body": {
      "type": "object",
      "required": [
        "receipt_type",
        "schema",
        "phase",
        "schedule",
        "schedule_sha256",
        "salt_commitment",
        "committer_commitment",
        "issued_at",
        "boundary"
      ],
      "additionalProperties": false,
      "properties": {
        "receipt_type": {
          "type": "string",
          "const": "delivery.schedule"
        },
        "schema": {
          "type": "string",
          "const": "r1.0.0"
        },
        "phase": {
          "type": "string",
          "enum": [
            "commitment",
            "reconciliation"
          ]
        },
        "schedule": {
          "type": "object",
          "required": [
            "schedule_id",
            "schedule_version",
            "instrument_set_digest",
            "period",
            "rule"
          ],
          "additionalProperties": false,
          "properties": {
            "schedule_id": {
              "type": "string",
              "pattern": "^sch_[0-9a-z][0-9a-z._-]{0,47}$"
            },
            "schedule_version": {
              "type": "string",
              "pattern": "^[0-9a-zA-Z][0-9a-zA-Z._-]{0,31}$"
            },
            "instrument_set_digest": {
              "type": "string",
              "pattern": "^[0-9a-f]{64}$",
              "description": "Lowercase hex SHA-256 fingerprint of the instrument set the schedule covers. The set itself is never carried here."
            },
            "period": {
              "type": "object",
              "required": [
                "start",
                "end"
              ],
              "additionalProperties": false,
              "properties": {
                "start": {
                  "type": "object",
                  "required": [
                    "utc",
                    "drift_seconds"
                  ],
                  "additionalProperties": false,
                  "properties": {
                    "utc": {
                      "type": "string",
                      "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
                    },
                    "drift_seconds": {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 86400
                    }
                  }
                },
                "end": {
                  "type": "object",
                  "required": [
                    "utc",
                    "drift_seconds"
                  ],
                  "additionalProperties": false,
                  "properties": {
                    "utc": {
                      "type": "string",
                      "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
                    },
                    "drift_seconds": {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 86400
                    }
                  }
                }
              }
            },
            "rule": {
              "type": "object",
              "required": [
                "kind",
                "grace_seconds"
              ],
              "additionalProperties": false,
              "properties": {
                "kind": {
                  "type": "string",
                  "enum": [
                    "interval",
                    "list"
                  ]
                },
                "interval_seconds": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 86400,
                  "description": "For an interval rule, one expected delivery every this many seconds from period start. Zero is schema legal and refused by SCHEDULE_RULE_SHAPE."
                },
                "grace_seconds": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 86400
                },
                "items": {
                  "type": "array",
                  "maxItems": 20000,
                  "items": {
                    "type": "object",
                    "required": [
                      "item_commitment",
                      "due_utc"
                    ],
                    "additionalProperties": false,
                    "properties": {
                      "item_commitment": {
                        "type": "string",
                        "pattern": "^[0-9a-f]{64}$",
                        "description": "Salted commitment over the item descriptor, such as a file name."
                      },
                      "due_utc": {
                        "type": "string",
                        "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
                      }
                    }
                  }
                }
              }
            }
          }
        },
        "schedule_sha256": {
          "type": "string",
          "pattern": "^[0-9a-f]{64}$"
        },
        "salt_commitment": {
          "type": "string",
          "pattern": "^[0-9a-f]{64}$"
        },
        "committer_commitment": {
          "type": "string",
          "pattern": "^[0-9a-f]{64}$",
          "description": "Salted commitment over the descriptor of the party that recorded the schedule. No party is named here."
        },
        "issued_at": {
          "type": "object",
          "required": [
            "utc",
            "drift_seconds"
          ],
          "additionalProperties": false,
          "properties": {
            "utc": {
              "type": "string",
              "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
            },
            "drift_seconds": {
              "type": "integer",
              "minimum": 0,
              "maximum": 86400
            }
          },
          "description": "Written by the service from the envelope signing instant."
        },
        "schedule_receipt_sha256": {
          "type": "string",
          "pattern": "^[0-9a-f]{64}$",
          "description": "Reconciliation phase only. SHA-256 over the canonical commitment phase envelope this reconciliation is computed against."
        },
        "observation_drift_seconds": {
          "type": "integer",
          "minimum": 0,
          "maximum": 86400
        },
        "observations": {
          "type": "array",
          "maxItems": 40000,
          "items": {
            "type": "object",
            "required": [
              "slot_key",
              "delivered_at_utc",
              "content_sha256",
              "delivery_receipt_sha256"
            ],
            "additionalProperties": false,
            "properties": {
              "slot_key": {
                "type": "string",
                "pattern": "^(s[0-9]{1,6}|[0-9a-f]{64})$"
              },
              "delivered_at_utc": {
                "type": "string",
                "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
              },
              "content_sha256": {
                "type": "string",
                "pattern": "^[0-9a-f]{64}$",
                "description": "Fingerprint of the delivered content. The content is never carried here."
              },
              "delivery_receipt_sha256": {
                "type": "string",
                "pattern": "^[0-9a-f]{64}$",
                "description": "Fingerprint of the observed delivery receipt this observation was read from."
              }
            }
          }
        },
        "findings": {
          "type": "object",
          "required": [
            "expected_count",
            "observed_count",
            "on_time_count",
            "late_count",
            "indeterminate_count",
            "missing_count",
            "extra_count",
            "max_lateness_ms",
            "missing_slot_keys",
            "late_slot_keys",
            "indeterminate_slot_keys",
            "extra_observation_indexes"
          ],
          "additionalProperties": false,
          "properties": {
            "expected_count": {
              "type": "integer",
              "minimum": 0
            },
            "observed_count": {
              "type": "integer",
              "minimum": 0
            },
            "on_time_count": {
              "type": "integer",
              "minimum": 0
            },
            "late_count": {
              "type": "integer",
              "minimum": 0
            },
            "indeterminate_count": {
              "type": "integer",
              "minimum": 0
            },
            "missing_count": {
              "type": "integer",
              "minimum": 0
            },
            "extra_count": {
              "type": "integer",
              "minimum": 0
            },
            "max_lateness_ms": {
              "type": "integer",
              "minimum": 0
            },
            "missing_slot_keys": {
              "type": "array",
              "maxItems": 40000,
              "items": {
                "type": "string",
                "pattern": "^(s[0-9]{1,6}|[0-9a-f]{64})$"
              }
            },
            "late_slot_keys": {
              "type": "array",
              "maxItems": 40000,
              "items": {
                "type": "string",
                "pattern": "^(s[0-9]{1,6}|[0-9a-f]{64})$"
              }
            },
            "indeterminate_slot_keys": {
              "type": "array",
              "maxItems": 40000,
              "items": {
                "type": "string",
                "pattern": "^(s[0-9]{1,6}|[0-9a-f]{64})$"
              }
            },
            "extra_observation_indexes": {
              "type": "array",
              "maxItems": 40000,
              "items": {
                "type": "integer",
                "minimum": 0
              }
            }
          }
        },
        "boundary": {
          "type": "string",
          "minLength": 1,
          "const": "This receipt records a delivery schedule and, in its reconciliation phase, a count of observed deliveries against that schedule. Hive records and checks; it does not decide, block, enforce or sit in the access path of any delivery. In the commitment phase it shows that a party, presented as a salted commitment, recorded the named schedule, instrument set fingerprint, period, and update interval or expected item list at the recorded instant, and that this instant falls before the period start under the declared drift bounds. In the reconciliation phase it shows which expected slots the supplied observations left missing, late, indeterminate or on time, and which observations were extra, computed under the classification rule fixed by this instrument. A receipt shows what was recorded and when, not that it was correct: it does not establish that any observation is complete or accurate, that any delivered content was right, that the schedule was adequate or binding on anyone, or that any party met or breached an obligation. Observations, instants and fingerprints are presented as reported by the recording party."
        }
      }
    }
  }
}