{
 "@context": "https://schema.org",
 "@type": "Claim",
 "@id": "https://wulfkaal.github.io/positions/2026-08-26-016",
 "identifier": "kaal:position:2026-08-26-016",
 "additionalType": "https://wulfkaal.github.io/positions/schema.json#AffirmedPositionClaim",
 "name": "Revocation As Systemwide State Transition",
 "text": "Revocation is a state problem. Chen and his coauthors compare Intel MPK, ARM PAC, ARM MTE, and ARM Morello capabilities. They find that rights retained in registers on other cores prevent a revoking core from establishing that the right has disappeared, unless the system uses an interprocessor interrupt or a restricted single core model. Of the four mechanisms, only MTE implements the core coherent synchronization principle they identify.\n\nThe result supplies a concrete mechanism for failed propagation. Withdrawal can be correct at the source. An active component may still hold and exercise a derived instance of the grant. The issuer's record proves a local change. The prior right may remain live elsewhere. Local withdrawal is not cessation. Every live instance matters. A current validity check may instead stand between each instance and the protected action.\n\nThe evidence is narrower than the institutional claim. The paper studies access to memory across processor cores. It does not study legal grants, delegated purpose, revocation across machines, or sovereign local agent runtimes. It also does not establish that few systems can demonstrate propagation across the full universe of authorization systems. Its comparative result is limited to four modern hardware isolation mechanisms.\n\nA sovereign runtime should treat revocation as a systemwide transition with an observable completion condition. Each execution path must consult current authority state or operate through a revocable indirection. A completion receipt should bind the grant, the cutoff, the affected holders, synchronization evidence, and the first rejected use after the cutoff. The distinction controls the claim. Without that evidence, an issuer can demonstrate withdrawal. It cannot demonstrate cessation.",
 "author": {
  "@type": "Person",
  "name": "Wulf A. Kaal",
  "identifier": "https://orcid.org/0009-0008-7840-1847"
 },
 "datePublished": "2026-08-26",
 "dateModified": "2026-08-26",
 "creativeWorkStatus": "Affirmed",
 "responseType": "extension",
 "keywords": [
  "consensus-and-security",
  "governance-design",
  "ai-and-agents",
  "revocation",
  "authority",
  "capabilities",
  "isolation",
  "synchronization"
 ],
 "scope_conditions": [
  "The response is limited to the exact full-text propositions and the one mapped Kaal claim.",
  "External evidence level: peer-reviewed USENIX ATC conference paper with complete official proceedings full text.",
  "Mapping review tier: independent substantive scholarly-growth extension.",
  "The study concerns hardware memory-isolation rights rather than legal grants, delegated purpose, or institutional authority.",
  "Its propagation analysis is across processor cores and does not test revocation across machines or sovereign local agent runtimes.",
  "The comparative result covers Intel MPK, ARM PAC, ARM MTE, and ARM Morello capabilities rather than the full universe of authorization systems.",
  "The paper identifies MTE's synchronization property but does not define an institutional receipt proving that all operating holders ceased use.",
  "Software indirection, scanning, interrupts, or restricted execution may supply alternative revocation mechanisms at costs outside the paper's broad institutional claim."
 ],
 "currentDebate": {
  "name": "Limitations and Opportunities of Modern Hardware Isolation Mechanisms",
  "url": "https://www.usenix.org/conference/atc24/presentation/chen-xiangdong"
 },
 "extends": {
  "identifier": "kaal:claim:7314479-016",
  "url": "https://wulfkaal.github.io/claims/7314479-016",
  "citation": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479",
  "paper": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes",
  "authors": [
   "Wulf A. Kaal"
  ],
  "year": "2026",
  "ssrn": "https://ssrn.com/abstract=7314479",
  "source_pdf_sha256": "debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6"
 },
 "isBasedOn": [
  {
   "@id": "https://wulfkaal.github.io/claims/7314479-016"
  },
  {
   "@type": "CreativeWork",
   "name": "Limitations and Opportunities of Modern Hardware Isolation Mechanisms",
   "url": "https://www.usenix.org/conference/atc24/presentation/chen-xiangdong"
  }
 ],
 "batch_id": "kaal-review:2026-08-26:scholarly-growth-7314479-016-reviewed-v1",
 "review_provenance": "https://wulfkaal.github.io/positions/by-claim/7314479-016.html",
 "publicationStatus": "public",
 "recordTypeNote": "Dated commentary position extending a scholarly corpus claim. Not a verbatim claim extracted from the paper.",
 "isPartOf": {
  "@id": "https://wulfkaal.github.io/positions/index.json"
 },
 "version": "1.0",
 "canonical_url": "https://wulfkaal.github.io/positions/2026-08-26-016",
 "canonicalForm": "https://wulfkaal.github.io/positions/2026-08-26-016.md",
 "candidateId": "kaal:response-candidate:2026-08-26:scholarly-growth-7314479-016-revocation-as-systemwide-state-transition-01",
 "evidenceLevel": "peer-reviewed USENIX ATC conference paper with complete official proceedings full text",
 "reviewTier": "independent substantive scholarly-growth extension",
 "mappingConfidence": 0.98,
 "mappingAmbiguous": false,
 "mappingMethod": "independent substantive scholarly-growth one-to-one review",
 "mappingWhyRelevant": "The paper independently demonstrates the exact propagation mechanism required by Kaal's revocation claim. A revoking core can change its local state while active rights remain in registers on other cores, and only one of four evaluated mechanisms supplies the core-coherent synchronization principle. The mapping remains bounded because the evidence concerns hardware memory isolation rather than legal grants or sovereign runtime deployments.",
 "sourceProvenance": {
  "source": "USENIX ATC 2024 peer-reviewed conference paper with complete official proceedings full text",
  "sourceRecordId": "usenix:atc24:chen-xiangdong",
  "canonicalUrl": "https://www.usenix.org/conference/atc24/presentation/chen-xiangdong",
  "publicFullTextUrl": "https://www.usenix.org/system/files/atc24-chen-xiangdong.pdf",
  "retrievedAt": "2026-08-27T09:12:11.581Z",
  "fullTextPdfSha256": "90588b703374abc907473fc441864a36cef9e6ceb2a7d3b02271331258e83ebb",
  "extractedTextSha256": "405d33b4514cc377ce65ea30f1a709acc0b033cf11837e4bac1cf383d1586bcb",
  "officialProceedingsRecordSha256": "92956ffd16b684d567d80f66e64df04b2a6a47aeaabb95b0e9d6903afe871fb4",
  "primaryEvidenceReceiptSha256": "e3d42e33e6718133e1ba65fe81b2d67b05fea2c625b62f4d6852e31af5e34248",
  "sourceProposition": "Chen and his coauthors show that MPK, CHERI, and PAC can retain active rights in registers on other cores after a revocation decision, while MTE alone among four evaluated mechanisms provides the core-coherent synchronization they identify as necessary for global revocation.",
  "sourcePropositionSha256": "e904534eb93ce81bf90785a267dca1ce29680a76790ed6cf540e8172ac92ac77",
  "sourceEvidenceSetSha256": "f7e4002ad44c3ddf01491a589b1050cba2bdb38dd2a00a89802c2866be95a4ec",
  "sourceEvidencePassages": [
   {
    "text": "Hardware architectures that keep access rights in registers, e.g., Intel MPK, CHERI, and even PAC are facing another inherent limitation: it is impossible to perform revocation of rights across the cores (active capabilities can be retained in registers of other cores).",
    "locator": {
     "publication": "2024 USENIX Annual Technical Conference",
     "page": 2,
     "section": "1 Introduction"
    },
    "sha256": "eb45ea03c8b185ee5ff57425269e44bd7b30ac3c8bbb89971bbe1f1479162fbb"
   },
   {
    "text": "our analysis shows that ARM MTE is the only set of isolation extensions that implements this principle",
    "locator": {
     "publication": "2024 USENIX Annual Technical Conference",
     "page": 2,
     "section": "1 Introduction"
    },
    "sha256": "3098a66d8690ae40efa1bab9dfd82db439039c4d1eb025b324d1902070da6fe8"
   }
  ],
  "workId": "work:usenix:atc24:chen-xiangdong",
  "workAuthors": [
   "Xiangdong Chen",
   "Zhaofeng Li",
   "Tirth Jain",
   "Vikram Narayanan",
   "Anton Burtsev"
  ],
  "workPublishedAt": "2024-07",
  "identityKeys": [
   "usenix:atc24:chen-xiangdong",
   "pdf:90588b703374abc907473fc441864a36cef9e6ceb2a7d3b02271331258e83ebb",
   "proposition:e904534eb93ce81bf90785a267dca1ce29680a76790ed6cf540e8172ac92ac77"
  ],
  "claimMappings": [
   {
    "claimId": "kaal:claim:7314479-016",
    "claimUrl": "https://wulfkaal.github.io/claims/7314479-016",
    "rank": 1,
    "confidence": 0.98,
    "method": "independent substantive scholarly-growth one-to-one review",
    "whyRelevant": "The paper independently demonstrates the exact propagation mechanism required by Kaal's revocation claim. A revoking core can change its local state while active rights remain in registers on other cores, and only one of four evaluated mechanisms supplies the core-coherent synchronization principle. The mapping remains bounded because the evidence concerns hardware memory isolation rather than legal grants or sovereign runtime deployments.",
    "ambiguous": false
   }
  ],
  "substantiveReview": {
   "reviewedAt": "2026-08-27T09:12:11.581Z",
   "sourceIdentityVerified": true,
   "authorIndependenceVerified": true,
   "kaalReferenceFoundInSource": false,
   "temporalIndependence": "The USENIX paper was published in 2024, before Kaal's 2026 paper.",
   "canonicalPublicStatusVerified": true,
   "peerReviewedStatusVerified": true,
   "retractionOrSupersessionFound": false,
   "propositionFidelityVerified": true,
   "mechanismCorrespondence": "the revoking core changes local authority state while active rights can remain in registers on other cores, so cessation requires core-coherent synchronization or another mechanism that reaches every live instance",
   "compatibleScope": "revocation propagation among already operating hardware components, limited because the evidence concerns memory isolation rather than sovereign agent runtimes",
   "responseWordingDefensible": true,
   "oneToOneExtendsMapping": true,
   "exactSupportingQuotesVerified": true,
   "nonOverlap": {
    "candidateIdMatches": false,
    "canonicalUrlMatches": false,
    "propositionHashMatches": false,
    "priorPositionForClaim": false
   },
   "limitations": [
    "The study concerns hardware memory-isolation rights rather than legal grants, delegated purpose, or institutional authority.",
    "Its propagation analysis is across processor cores and does not test revocation across machines or sovereign local agent runtimes.",
    "The comparative result covers Intel MPK, ARM PAC, ARM MTE, and ARM Morello capabilities rather than the full universe of authorization systems.",
    "The paper identifies MTE's synchronization property but does not define an institutional receipt proving that all operating holders ceased use.",
    "Software indirection, scanning, interrupts, or restricted execution may supply alternative revocation mechanisms at costs outside the paper's broad institutional claim."
   ],
   "rejectionReasonsRecorded": true
  },
  "contentMap": {
   "proposition": "A correct issuer-side withdrawal does not prove that every active holder has ceased using the prior right.",
   "evidenceLayer": "peer-reviewed USENIX ATC conference paper with complete official proceedings full text",
   "strongestLimitation": "The comparative evidence covers four hardware isolation mechanisms and not authorization systems generally.",
   "consequence": "Revocation must be represented as a synchronized current-state transition with an observable completion condition.",
   "requestedAction": "Require each execution path to consult current authority or a revocable indirection and bind completion to holder-level synchronization evidence."
  },
  "stylePack": {
   "profile": "M1 early sole-author baseline v1.2.0",
   "verifiedProfileWorks": [
    "1428387",
    "1806252",
    "2150377",
    "2267560"
   ],
   "sameRegisterPassagePackAvailable": true,
   "limitation": "The short public position permits only bounded stylometric comparison."
  },
  "m1Validation": {
   "status": "M1-PASS-WITH-LIMITS",
   "deterministicGate": "pass",
   "hardFailures": 0,
   "warnings": 0,
   "words": 265,
   "reason": "The publication-bound position passed strict and public deterministic controls against a task-local multi-work style pack. Its short length limits stylometric comparison."
  }
 },
 "userAffirmation": "Authorized under public authority SHA-256 87aad20196a753015a36d970f742c885eb763efdbada4869949bfffe3298130c and event supersession SHA-256 7d47ef36085c4dce590f287c986e4106f3bf35a7da5a25322d6fc3d4abf456d4. Publication remains receipt-bound to successful workflows and exact live-byte verification.",
 "sha256": "b9e8582dfcb2438f698370af6cb11331495f465b4dff8838824a0d03ac7d0184"
}
