diff --git a/tests/fixtures/ownership-tag-contract.txt b/tests/fixtures/ownership-tag-contract.txt index 471c413..fa1b3ef 100644 --- a/tests/fixtures/ownership-tag-contract.txt +++ b/tests/fixtures/ownership-tag-contract.txt @@ -20,9 +20,17 @@ # PipeWire registry `global` event and readable only via a node bind, so the # primary taint root must not rest on one observation mechanism alone. -# Carrier 1 — a node property. The consumer treats any value other than -# "false"/"0" as truthy, which is the fail-closed direction; the producer -# always emits exactly this value. +# Carrier 1 — a node property, matched EXACTLY: `prop_value` below is the +# ONLY spelling the consumer reads as owned. A producer emitting "true", "yes" +# or "" is NOT owned on this carrier, and only carrier 2 would still catch it. +# +# ⚠️ This wording is load-bearing and it CHANGED in round 10. The consumer +# used to accept any value other than "false"/"0", on the theory that leniency +# over-excludes and is therefore safe. It is not: leniency buys false-positive +# exclusion, and it let any process suppress a rival application's audio from +# the share with a property it did not even have to spell right. Fail-closed +# on this feature is about ANCESTRY — an unresolvable graph is not eligible — +# not about parsing. prop_key=peerspeak.owned prop_value=1