DOSFI Governance
The constitution, enforceable rules, and public action ledger that bind the DOSFI mesh. Foundation-governed, community-owned, irreversibly open-source.
Irreversible Open Source
DOSFI shall be irreversibly open-sourced under a permissive license. No acquisition, fork, or governance change may re-close the core runtime, settlement layer, or identity fabric.
Foundation Stewardship
Stewardship of DOSFI is distributed via a foundation, not a single company. No single entity may unilaterally amend the constitution, alter settlement, or revoke community ownership.
Community Ownership
The value of DOSFI is in its community. The constitution, rules, and action ledger are public. A 'buy and shelve' acquisition is structurally resisted by irreversibly open-sourcing the core and distributing stewardship.
Zero IP Leakage
All mesh-native execution must enforce strict privacy and zero IP leakage. Device IPs, hardware identifiers, routing paths, and node-level telemetry are redacted at the DOSFI boundary. Dispatch, scheduling, and routing decisions remain internal to DOSFI.
Hardware-Bound Identity
Node identity is hardware-bound. Every contributor must bind a hardware key and complete MFA before earning. Identity tiers (T1–T5) gate settlement, routing, and earning multipliers.
Verified Execution Settlement
Settlement is earned through verified execution, not claims. The strength of the verification mechanism is the keystone of settlement layer security. The core principle is to make Sybil attacks unprofitable rather than prevent them absolutely.
Reputation Ramp
New nodes enter through a reputation ramp. Earning multipliers scale with verified uptime, attestation, and work-attached heartbeat liveness. Fake benchmarks, fake GPUs, and fake heartbeats are slashed.
AI Model Containment
The inference runtime exposes no filesystem, outbound network access, persistent storage, or tool invocation APIs. The model's only externally observable effect is its inference output. These guarantees assume the integrity of the DOSFI runtime, underlying OS, and hardware isolation.
Internal Routing
All dispatch, scheduling, and routing decisions remain internal to DOSFI. Execution metadata is confidential and ephemeral. No user may observe device IPs, hardware identifiers, or specific node capability details.
Federation Sovereignty
Federated DOSFI instances retain sovereignty over their local identity, settlement, and routing. No federation may compel another to alter its constitution or revoke its community ownership.
| Rule | Type | Strictness | Violations | Status |
|---|---|---|---|---|
Hardware Key Binding Required Nodes without a bound hardware key cannot earn or route. | identity | strict | 0 | Active |
MFA Verification Gate MFA must be verified before any settlement is credited. | identity | strict | 0 | Active |
Sybil Unprofitability Enforcement Identity cost must exceed the value of any Sybil-derived earnings. Slashing applies to detected Sybil clusters. | settlement | strict | 0 | Active |
Reputation Ramp Enforcement New nodes earn at T1 multiplier until verified uptime, attestation, and liveness thresholds are met. | settlement | standard | 0 | Active |
Fake-GPU Slashing Nodes reporting inflated capability or fake GPUs are slashed and demoted. | anti_cheat | strict | 0 | Active |
Fake-Benchmark Detection Benchmark inflation is caught by the reputation ramp and penalized. | anti_cheat | standard | 0 | Active |
Work-Attached Heartbeat Liveness Liveness requires work-attached heartbeats. Fake-heartbeat schemes are dropped. | session | standard | 0 | Active |
Zero IP Leakage Boundary All telemetry is redacted at the DOSFI boundary. IP, hardware ID, and routing path leakage is blocked. | privacy | strict | 0 | Active |
Runtime Containment Enforcement The inference runtime must not expose filesystem, network, storage, or tool APIs. Violations block the node. | inference | strict | 0 | Active |
Internal Routing Opacity Routing decisions must not be observable by users. External routing queries are rejected. | routing | standard | 0 | Active |
Security gate blocked create on Node: Authentication required: no valid identity.; RBAC: role 'anonymous' cannot create Closed Core entity 'Node'.; Runtime isolation: 'Node' is Closed Core. Admin role required.
Security gate blocked create on Node: Authentication required: no valid identity.; RBAC: role 'anonymous' cannot create Closed Core entity 'Node'.; Runtime isolation: 'Node' is Closed Core. Admin role required.
Security gate blocked create on Node: Authentication required: no valid identity.; RBAC: role 'anonymous' cannot create Closed Core entity 'Node'.; Runtime isolation: 'Node' is Closed Core. Admin role required.
