Publish the valid-but-unbound claim; the missing shape was confounded
The example set satisfied §11's both-shapes clause only by accident. Both
values of pdp_digest and pdp_path appeared, but they appeared in perfect
correlation with validity: claim.valid carried a digest with pdp_path true,
claim.revoked carried null with pdp_path false, and nothing else existed.
Two independent dimensions presented as one. A reader could reasonably conclude
that pdp_digest is null because the claim is revoked, or that pdp_path tracks
validity. Both are false, and the example set is what would have taught them --
the failure the both-shapes clause exists to catch, which this repo proposed and
then shipped a case of.
The missing shape is the consequential one: a claim that is entirely valid --
valid_now true, reason_code ok, not consumed -- and carries no PDP binding. It
is usable for a consumer comparing the native binding.digest and unusable on the
GH-DEC-2026-003 path, where a PEP MUST refuse it. valid_now true is not
permission to proceed on that lane. A consumer writing that refusal previously
had no published shape to test against and would have had to invent a fixture,
which is the drift §12 names.
examples/claim.valid.no-pdp.json publishes it. The tests now assert the
decorrelation rather than mere presence: one requires a valid claim with no PDP
binding to exist, the other requires valid claims to cover both pdp_path
declarations. Verified both fail when the new example is removed, so they hold
the property rather than restating today's file list. 121 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715850@bnt-lap001
Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
2026-09-07 13:48:00 +02:00
|
|
|
{
|
|
|
|
|
"schema_version": "0.1",
|
|
|
|
|
"kind": "approval-claim",
|
2026-09-10 19:26:12 +02:00
|
|
|
"yields_to": "net-kingdom taxonomy request-claim schema (statute \u00a717; unassigned)",
|
Publish the valid-but-unbound claim; the missing shape was confounded
The example set satisfied §11's both-shapes clause only by accident. Both
values of pdp_digest and pdp_path appeared, but they appeared in perfect
correlation with validity: claim.valid carried a digest with pdp_path true,
claim.revoked carried null with pdp_path false, and nothing else existed.
Two independent dimensions presented as one. A reader could reasonably conclude
that pdp_digest is null because the claim is revoked, or that pdp_path tracks
validity. Both are false, and the example set is what would have taught them --
the failure the both-shapes clause exists to catch, which this repo proposed and
then shipped a case of.
The missing shape is the consequential one: a claim that is entirely valid --
valid_now true, reason_code ok, not consumed -- and carries no PDP binding. It
is usable for a consumer comparing the native binding.digest and unusable on the
GH-DEC-2026-003 path, where a PEP MUST refuse it. valid_now true is not
permission to proceed on that lane. A consumer writing that refusal previously
had no published shape to test against and would have had to invent a fixture,
which is the drift §12 names.
examples/claim.valid.no-pdp.json publishes it. The tests now assert the
decorrelation rather than mere presence: one requires a valid claim with no PDP
binding to exist, the other requires valid claims to cover both pdp_path
declarations. Verified both fail when the new example is removed, so they hold
the property rather than restating today's file list. 121 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715850@bnt-lap001
Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
2026-09-07 13:48:00 +02:00
|
|
|
"issuer": "approval-engine",
|
|
|
|
|
"approval_id": "7c4e2b91-08da-4f63-b5c7-2a9e6d1f04b3",
|
|
|
|
|
"state": "valid",
|
|
|
|
|
"valid_now": true,
|
|
|
|
|
"consumed": false,
|
|
|
|
|
"binding": {
|
|
|
|
|
"action": "release.publish",
|
|
|
|
|
"target": {
|
|
|
|
|
"id": "svc-approval-engine",
|
|
|
|
|
"stage": "prod"
|
|
|
|
|
},
|
|
|
|
|
"actor": "agt-release-runner",
|
|
|
|
|
"principal": "bernd",
|
|
|
|
|
"purpose": "cut-0-1-0-release",
|
|
|
|
|
"digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
|
|
|
|
|
"pdp_digest": null,
|
2026-09-10 19:26:12 +02:00
|
|
|
"pdp_path": false,
|
|
|
|
|
"human_control": false
|
Publish the valid-but-unbound claim; the missing shape was confounded
The example set satisfied §11's both-shapes clause only by accident. Both
values of pdp_digest and pdp_path appeared, but they appeared in perfect
correlation with validity: claim.valid carried a digest with pdp_path true,
claim.revoked carried null with pdp_path false, and nothing else existed.
Two independent dimensions presented as one. A reader could reasonably conclude
that pdp_digest is null because the claim is revoked, or that pdp_path tracks
validity. Both are false, and the example set is what would have taught them --
the failure the both-shapes clause exists to catch, which this repo proposed and
then shipped a case of.
The missing shape is the consequential one: a claim that is entirely valid --
valid_now true, reason_code ok, not consumed -- and carries no PDP binding. It
is usable for a consumer comparing the native binding.digest and unusable on the
GH-DEC-2026-003 path, where a PEP MUST refuse it. valid_now true is not
permission to proceed on that lane. A consumer writing that refusal previously
had no published shape to test against and would have had to invent a fixture,
which is the drift §12 names.
examples/claim.valid.no-pdp.json publishes it. The tests now assert the
decorrelation rather than mere presence: one requires a valid claim with no PDP
binding to exist, the other requires valid claims to cover both pdp_path
declarations. Verified both fail when the new example is removed, so they hold
the property rather than restating today's file list. 121 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715850@bnt-lap001
Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
2026-09-07 13:48:00 +02:00
|
|
|
},
|
|
|
|
|
"freshness": {
|
|
|
|
|
"observed_at": "2026-08-29T12:00:00+00:00",
|
|
|
|
|
"ttl_seconds": 30,
|
|
|
|
|
"not_after": "2026-08-29T12:00:30+00:00"
|
|
|
|
|
},
|
|
|
|
|
"validity": {
|
|
|
|
|
"not_before": "2026-08-29T11:00:00+00:00",
|
|
|
|
|
"expires_at": "2026-08-29T15:00:00+00:00"
|
|
|
|
|
},
|
|
|
|
|
"reason_code": "ok"
|
|
|
|
|
}
|