Implement GH-DEC-2026-008: declared PDP-path intent, enforced at issue
Gate House ruled binding.pdp_digest is the binding correspondence on the GH-DEC-2026-003 path and is required there, having rejected a vocabulary mapping for the reasons we gave. It asked this engine to record the PDP digest at issue for approvals intended for that path, and to have the claim state which approvals those are rather than leaving it to the requester's memory. Schema v3 adds approvals.pdp_path. create() refuses pdp_path true without a pdp_digest, so an approval that would be unusable on the path fails at issue rather than at the protected side effect. The claim exposes binding.pdp_path, which makes it a guarantee rather than a hint: pdp_path true implies pdp_digest is non-null. Intent is declared and never inferred. A pdp_digest that happens to be present is not a declaration anybody made, so a recorded digest alone leaves pdp_path false, legacy rows migrate to false rather than being back-filled from their digests, and a successor inherits its predecessor's declaration. Approvals issued before the ruling stay usable by consumers in this engine's own vocabulary and are simply not usable on the PDP path -- the ruling's intended cost, stated as such. Schema, both published examples, a v2-to-v3 migration test asserting survivors keep their digest while declaring no path intent, and tests for refusal at issue, claim exposure, non-inference, and successor inheritance. 102 tests pass (8 new). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND Assistant: claude-code Assistant-Model: opus Assistant-Process: 411227@bnt-lap001 Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535
This commit is contained in:
parent
6d0dfc8010
commit
7e756773de
10 changed files with 166 additions and 11 deletions
|
|
@ -122,6 +122,24 @@ was not issued against a PDP decision — a stated fact rather than a missing
|
|||
key, so a consumer cannot read absence as an oversight. It is not required on
|
||||
every approval, because approvals legitimately exist that no decision preceded.
|
||||
|
||||
### Declared path intent — `binding.pdp_path`
|
||||
|
||||
`GH-DEC-2026-008` requires `pdp_digest` on the `GH-DEC-2026-003` path. This
|
||||
engine enforces that **at issue, not at consume**: an approval declared with
|
||||
`pdp_path: true` and no `pdp_digest` is refused at create. Discovering an
|
||||
unusable approval at the moment of the protected side effect is the worst place
|
||||
to find out.
|
||||
|
||||
So `binding.pdp_path` is a guarantee, not a hint: **`pdp_path: true` implies
|
||||
`pdp_digest` is non-null.** A consumer on that path MUST require `pdp_path`
|
||||
true, and MUST NOT infer path intent from a `pdp_digest` that merely happens to
|
||||
be present — a digest recorded for another reason is not a declaration that
|
||||
anybody made.
|
||||
|
||||
Intent is declared by the requester and never back-filled. Approvals issued
|
||||
before schema v3 carry `pdp_path: false` regardless of any digest they hold,
|
||||
and a successor created by supersession inherits its predecessor's declaration.
|
||||
|
||||
**A PEP on a privileged lane MUST refuse a claim whose `pdp_digest` is
|
||||
`null`.** Such a claim proves an approval exists; it does not prove the
|
||||
approval was issued against the request now being decided, and no vocabulary
|
||||
|
|
|
|||
|
|
@ -29,3 +29,16 @@ Restore is a stopped-single-writer operation:
|
|||
Approval mutation and outbox insertion share `BEGIN IMMEDIATE` and one commit;
|
||||
a failed outbox insert rolls the mutation back. Delivery occurs afterward and
|
||||
does not roll back a committed mutation.
|
||||
|
||||
## Schema v3 — declared PDP-path intent
|
||||
|
||||
`GH-DEC-2026-008` added `approvals.pdp_path` (INTEGER NOT NULL DEFAULT 0).
|
||||
Migration is the usual additive `ALTER TABLE`; run `approval-engine migrate`
|
||||
before a production start, which refuses an unmigrated store.
|
||||
|
||||
Legacy rows default to `0`. Intent is **not** back-filled from a recorded
|
||||
`pdp_digest`: an approval issued before the ruling was never declared for the
|
||||
PDP path, and inferring the declaration from an incidental digest would
|
||||
manufacture a statement nobody made. Such approvals stay usable by consumers in
|
||||
this engine's own vocabulary and are simply not usable on the PDP path — which
|
||||
is the ruling's intended cost, not a migration defect.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue