Family contract
PCOC is a construction pattern. An object is had by making one. It is bound to a key and to public time. It is checked without trusting the maker.
That pattern is not a product and it is not a parameter file. It is a list of debts. Any concrete construction that wants to belong still has to discharge them. The debts do not pick a work size, a memory size, or a clock. They say what kind of object may exist.
Why the scarce step sits on the object is How do you make a digital thing scarce? A cap and a list are the same office. That cut is Issued, listed, or made? The check, and why a refusal is not an acceptance, is Why can saying no be cheap when saying yes cannot?
Belonging to the family does not mean two instances share numbers. Membership does not establish that a particular lock is sound, unique, or measured against a determined adversary. Other instances are allowed.
A concrete contract claiming membership must do ten things.
- Define the object. A construction that produces something observable and checkable.
- Specify complete verification of the relations that object carries, without trusting the producer. A pass is not acceptance.
- Bind each object to a public key, so the object is not a bearer instrument.
- Make per-object cost first-class and observable. The cost relation is explicit and evaluable. Verification establishes the stated relations, not that a particular historical expenditure occurred.
- Order checks from cheap to dear, refusing malformed input before anything expensive runs. That ordering is a design duty, not a measured attacker and defender ratio.
- Bind the object to external public time, so the producer cannot freely relocate the work.
- Derive scarcity from cost, not from policy, permission, or an issuer.
- Be interoperable. Two independent implementations of the same instance must agree on construction, encodings, verification relations, and reported outcomes. That is interoperability of one contract, not sameness across instances.
- Bind the terminal state so a prefix of a run is not a cheap branch into another well-formed object. Well-formed is the construction, the anchors, the waypoints, the step counts, and the checkpoints, as the concrete contract states them. One execution yielding one well-formed member is construction completeness, not door admit. Door admit is policy on whether that paid cost is enough. Stage and exit counts belong to that contract, not a family definition of valid.
- Separate hash contexts by structural role. A version tag is not that separation.
Those ten are family obligations, not shared parameters. Each concrete contract owns its numbers, algorithms, encodings, evaluation rules, and the evidence that its construction meets its intended cost. Meeting the ten determines the relation a member must satisfy. It does not enlarge what membership attests.
A member satisfies only the relations defined by its concrete contract, in the view in which they were evaluated. Membership does not attest who any person is, that a holder is human, that a holder is unique, that a holder has only one object, qualification, reputation, standing, authorisation, that the key holder personally performed the work, or that a relying party accepts the object.
A concrete contract may not infer any of those from family membership. A separate system may impose additional rules. It must name them separately. Whether a population requires a distinct object for each claim is a relying-party condition, not a property membership supplies.
Within those limits the family still requires an external anchor. Without public time the work can be finished whenever the producer likes, stored, and presented later. The anchor must arrive at a time the producer does not control, carry content the producer cannot predict or select, be checkable by any verifier in the configured view, and supply an order the producer cannot rewrite. The family requires those four properties, not a system name. Bitcoin is one system a concrete contract may use. It is not family law. Any concrete contract must name its anchor and state how that anchor supplies the four.
The commitment surface used to place an object, and the position that defines earliest completion, belong to the instance. They are not extra family-level properties of the anchor.
The construction this repository runs discharges the ten as a hike: a room grown from a key and an opening header, legs taken while later headers close the stages, checked from the log without trusting the maker. The magnitudes, the step, and the exit belong to that construction. They do not live here. How you make one is that discharge, said once. A different construction may discharge the same ten with different magnitudes. What it may not do is drop one.