chore(registrar): assign State Hub identifiers
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4040362@bnt-lap001
Assistant-Session: 4fd0fd24-2ee8-4413-bd67-43bd79ca73f1
This commit is contained in:
repo-manager 2026-08-29 14:47:57 +02:00
parent 4392d51333
commit ebe3307e1c
2 changed files with 13 additions and 0 deletions

View file

@ -31,6 +31,7 @@ description: >
envelope needs a field this engine is not sending.
created: '2026-08-29'
updated: '2026-08-29'
state_hub_intake_id: "01a04d8f-b1c1-746a-8007-15221ebf0a48"
```
## AUDIT-IN-0001 — Proposed: audit-core takes the approval evidence half (security layer model v0.3 §9.4)
@ -85,4 +86,5 @@ resolution: 'Assent. The split is right: approval-engine owns the operative stat
Also raised: audit-core declared no layer, contrary to §11 — now declared Engine
layer, explicitly not a decision point.'
recorded_in: history/2026-08-28-approval-evidence-assent.md
state_hub_intake_id: "01a04d8f-be67-75ed-a221-d50f99dbb78e"
```

View file

@ -11,6 +11,7 @@ created: "2026-08-29"
updated: "2026-08-29"
depends_on:
- AUDIT-WP-0007
state_hub_workstream_id: "46a96b03-bc08-53b5-9c93-4071adabf734"
---
# AUDIT-WP-0009 — Evidence-role conformance under Security Layer Model v0.7
@ -58,6 +59,7 @@ Fixed by the statute; not deferred, not ours:
id: AUDIT-WP-0009-T01
status: todo
priority: high
state_hub_task_id: "f545b0e4-8c99-5186-affd-ce9a41209ed7"
```
Make `tamper_evidence` conditional on live attestation state. Derive the flag
rather than hard-coding it: the backend reports `True` only when a chain-head
@ -71,6 +73,7 @@ today are documented but unenforced.
id: AUDIT-WP-0009-T02
status: todo
priority: high
state_hub_task_id: "6de9945f-4dd1-57dd-898a-f59c35b1df6c"
```
Schedule chain-head attestation so the precondition T01 enforces is normally
met. `attest-chain` exists and is operator-run; `deploy/` has no job. Add one,
@ -83,6 +86,7 @@ and proves nothing. Record the cadence in `docs/integrity.md`.
id: AUDIT-WP-0009-T03
status: todo
priority: high
state_hub_task_id: "acae6085-ada7-51b2-8dc0-4abac7f7e7b3"
```
Represent the §9.6 evidence kind per source. Add `evidence_kind`
(`load-bearing` | `attributive`) to `SenderIdentity` and the sender registration
@ -96,6 +100,7 @@ for T04T06.
id: AUDIT-WP-0009-T04
status: todo
priority: high
state_hub_task_id: "f36470af-4019-54b2-96d7-e049d867c7db"
```
Heartbeat ingestion and missing-heartbeat findings. The required form for
low-volume load-bearing classes, and the only control covering adversarial
@ -109,6 +114,7 @@ itself go missing, which rate monitoring can never produce.
id: AUDIT-WP-0009-T05
status: wait
priority: medium
state_hub_task_id: "382575ca-1801-5a32-a93d-90a8b9c8adbf"
```
Accept and evaluate a declared emission cadence per source, and raise a finding
when the stream falls below it. **Waiting on** the §17 emission-cadence
@ -121,6 +127,7 @@ alternatives.
id: AUDIT-WP-0009-T06
status: todo
priority: medium
state_hub_task_id: "0a8d6eed-75dd-5aaa-bf86-60be9dadca03"
```
Reconciliation surface: per-source, per-class event counts over a bounded
window, readable by the source itself, so an emitter can compare audit-core's
@ -133,6 +140,7 @@ scoping, and no payloads in a counts response.
id: AUDIT-WP-0009-T07
status: todo
priority: medium
state_hub_task_id: "f572dfeb-0d1b-58d6-be83-405125189028"
```
Give stream-completeness findings a home. `/v1/dead-letters` and
`/v1/secret-findings` exist; a cadence miss (T05) and a missing heartbeat (T04)
@ -145,6 +153,7 @@ than adding a new shape.
id: AUDIT-WP-0009-T08
status: todo
priority: medium
state_hub_task_id: "f7b513ee-af48-5c5a-a34e-3e9922d29b76"
```
Assert the §9.4 approval-validity prohibition with a negative test. It is
currently honoured by absence, which is not the estate's idiom: §6.4 obligation
@ -156,6 +165,7 @@ is worth asserting in `tests/`.
id: AUDIT-WP-0009-T09
status: todo
priority: low
state_hub_task_id: "fd4a4ac3-e525-57c1-9179-e0fcd0226913"
```
Register `approval-engine` as a distinct source under §9.4 and `AUDIT-IN-0001`:
sender registration, the four event classes (issuance, use, supersession,
@ -168,6 +178,7 @@ events arriving. Not blocking: `approval-engine` is not yet emitting.
id: AUDIT-WP-0009-T10
status: todo
priority: low
state_hub_task_id: "ac3464fd-3df9-51a1-b1f4-3bf3c60e4265"
```
Make the §5 conformance check total. `layer.yaml` declares
`tooling_contacts: []`, true under §5 as written — audit-core is an Engine and