Summary

  • RFC 5262 can make a watcher’s full-and-delta sequence continuous and detect a missing update; it does not make that policy-shaped sequence a universal account of the presentity.
  • A defensible presence receipt binds the full baseline, every versioned diff, watcher and authorization context, reconstruction and expiry, then keeps contact attempt and human outcome separate.

Every update was present, and the answer was still incomplete

A monitoring console received full state followed by every numbered partial update. No version was skipped. Every XML operation applied successfully. The console therefore had strong evidence that it had reconstructed its assigned feed.

Another watcher saw a different contact method. Its authorization policy permitted a field that the first watcher was not allowed to receive. Both version histories were continuous. Neither history, by itself, was the complete presence of the person behind them.

This is the boundary RFC 5262 makes operationally important. Continuity is a property of a particular sequence. Presence is also a policy-shaped assertion, not a universal sensor reading.

One counter joins full state and partial state

The extension defines pidf-full and pidf-diff under application/pidf-diff+xml. A full document carries the local composition baseline. A diff carries add, replace and remove operations from the XML Patch framework.

When the optional version attribute is used, it increments by one between subsequent updates. Full and diff documents share the same counter. A recipient can therefore order messages and notice a gap rather than silently applying a later delta to an unknown predecessor.

That is useful evidence. It answers whether the receiver observed an uninterrupted sequence for this feed. It does not authenticate every source claim inside the baseline, prove that a suppressed field was false, or establish how old the real-world state had become before publication.

A good sequence can begin from the wrong baseline

Version 568 follows version 567 cleanly only if the recipient accepted the right version 567 for the same presentity, subscription and policy context. A perfect series that starts from a stale cached full document reconstructs stale state with great precision.

The receipt must therefore preserve the full baseline bytes and hash, not merely the starting number. It also needs the presentity URI, watcher, dialog or feed identity, content type, charset and authorization-policy revision. Otherwise “no version gap” can hide a baseline substitution.

This distinguishes RFC 5262 from a general truth ledger. Its counter helps maintain a local composition. The application still owns the identity and freshness preconditions around that composition.

Different watchers may correctly receive different worlds

Presence data can be sensitive. RFC 5262 carries forward the requirement that the surrounding protocol govern what information may be given to which watchers and when. That means absence has at least two possible meanings: the fact may be false, or the watcher may not be entitled to see it.

A sequence number cannot resolve that ambiguity. It orders what was disclosed under a policy; it does not reveal what the policy withheld. Comparing version 900 in two subscriptions is also unsafe unless the system has explicitly defined a shared sequence and equivalent policy scope.

For governance, the authorization decision belongs beside the content receipt. Store the policy identifier and decision, not an inference that every recipient saw the same source state.

Gap detection is not gap recovery

If a recipient expects 569 and receives 570, the counter exposes a missing update. That alarm is not itself a repair. The system must decide whether to pause display, request or await a new full document, discard local intermediates, or continue under an explicitly degraded policy.

Recovery needs its own evidence: the first unexpected version, the missing range, the last trusted reconstructed hash, the replacement full-state hash and the point at which the new state became visible. Without that record, a dashboard can move from “gap detected” to “green” without proving what repaired the gap.

Applying the diff is another separate boundary

RFC 5262 reuses RFC 5261 patch operations. Selectors must address the intended nodes in the accepted base, operations run in order and errors may be reported. A contiguous transport sequence can still fail during application, and a successful application can still remain only in memory.

Negotiating the MIME type proves capability agreement, not that this particular diff was parsed, committed or exposed. A complete receipt links receipt order to patch result, intermediate hashes, persistence and the exact reconstructed document observed downstream.

Well-formed presence is not lived presence

XML must be well formed and should be valid. Those are representation guarantees. They do not prove that a device remained reachable, a human remained willing to answer or a service accepted a later session.

Presence ages between publication and use. A tuple can be syntactically perfect, policy-authorized and sequentially current while reality changes a moment later. The subsequent invitation, negotiation and human or service response are separate events with separate owners.

The strongest operational language is therefore modest: “this watcher reconstructed the latest received state for this feed.” It should not become “the person was available.”

The partial-presence receipt

For consequential use, preserve:

  • presentity URI, watcher identity, subscription, dialog or feed identity;
  • authorization-policy identifier, revision, decision and permitted field scope;
  • accepted media type and charset;
  • full baseline bytes, hash, version, receipt time and expiry;
  • every diff’s bytes, hash, version, receipt order and receipt time;
  • expected versus received version and any detected gap;
  • each patch operation, selector context, matched preimage and apply result;
  • intermediate and reconstructed document hashes;
  • recovery request, replacement full state and discarded intermediates;
  • storage acknowledgement and downstream exposure; and
  • later contact attempt, negotiation, delivery and human or service outcome.

This receipt does not turn presence into certainty. It keeps a transport continuity claim from impersonating a complete institutional truth.

Sources