chore(registrar): assign State Hub identifiers
Assistant: claude-code Assistant-Model: opus Assistant-Process: 4040362@bnt-lap001 Assistant-Session: 4fd0fd24-2ee8-4413-bd67-43bd79ca73f1
This commit is contained in:
parent
4392d51333
commit
ebe3307e1c
2 changed files with 13 additions and 0 deletions
|
|
@ -31,6 +31,7 @@ description: >
|
|||
envelope needs a field this engine is not sending.
|
||||
created: '2026-08-29'
|
||||
updated: '2026-08-29'
|
||||
state_hub_intake_id: "01a04d8f-b1c1-746a-8007-15221ebf0a48"
|
||||
```
|
||||
|
||||
## AUDIT-IN-0001 — Proposed: audit-core takes the approval evidence half (security layer model v0.3 §9.4)
|
||||
|
|
@ -85,4 +86,5 @@ resolution: 'Assent. The split is right: approval-engine owns the operative stat
|
|||
Also raised: audit-core declared no layer, contrary to §11 — now declared Engine
|
||||
layer, explicitly not a decision point.'
|
||||
recorded_in: history/2026-08-28-approval-evidence-assent.md
|
||||
state_hub_intake_id: "01a04d8f-be67-75ed-a221-d50f99dbb78e"
|
||||
```
|
||||
|
|
|
|||
|
|
@ -11,6 +11,7 @@ created: "2026-08-29"
|
|||
updated: "2026-08-29"
|
||||
depends_on:
|
||||
- AUDIT-WP-0007
|
||||
state_hub_workstream_id: "46a96b03-bc08-53b5-9c93-4071adabf734"
|
||||
---
|
||||
|
||||
# AUDIT-WP-0009 — Evidence-role conformance under Security Layer Model v0.7
|
||||
|
|
@ -58,6 +59,7 @@ Fixed by the statute; not deferred, not ours:
|
|||
id: AUDIT-WP-0009-T01
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "f545b0e4-8c99-5186-affd-ce9a41209ed7"
|
||||
```
|
||||
Make `tamper_evidence` conditional on live attestation state. Derive the flag
|
||||
rather than hard-coding it: the backend reports `True` only when a chain-head
|
||||
|
|
@ -71,6 +73,7 @@ today are documented but unenforced.
|
|||
id: AUDIT-WP-0009-T02
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "6de9945f-4dd1-57dd-898a-f59c35b1df6c"
|
||||
```
|
||||
Schedule chain-head attestation so the precondition T01 enforces is normally
|
||||
met. `attest-chain` exists and is operator-run; `deploy/` has no job. Add one,
|
||||
|
|
@ -83,6 +86,7 @@ and proves nothing. Record the cadence in `docs/integrity.md`.
|
|||
id: AUDIT-WP-0009-T03
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "acae6085-ada7-51b2-8dc0-4abac7f7e7b3"
|
||||
```
|
||||
Represent the §9.6 evidence kind per source. Add `evidence_kind`
|
||||
(`load-bearing` | `attributive`) to `SenderIdentity` and the sender registration
|
||||
|
|
@ -96,6 +100,7 @@ for T04–T06.
|
|||
id: AUDIT-WP-0009-T04
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "f36470af-4019-54b2-96d7-e049d867c7db"
|
||||
```
|
||||
Heartbeat ingestion and missing-heartbeat findings. The required form for
|
||||
low-volume load-bearing classes, and the only control covering adversarial
|
||||
|
|
@ -109,6 +114,7 @@ itself go missing, which rate monitoring can never produce.
|
|||
id: AUDIT-WP-0009-T05
|
||||
status: wait
|
||||
priority: medium
|
||||
state_hub_task_id: "382575ca-1801-5a32-a93d-90a8b9c8adbf"
|
||||
```
|
||||
Accept and evaluate a declared emission cadence per source, and raise a finding
|
||||
when the stream falls below it. **Waiting on** the §17 emission-cadence
|
||||
|
|
@ -121,6 +127,7 @@ alternatives.
|
|||
id: AUDIT-WP-0009-T06
|
||||
status: todo
|
||||
priority: medium
|
||||
state_hub_task_id: "0a8d6eed-75dd-5aaa-bf86-60be9dadca03"
|
||||
```
|
||||
Reconciliation surface: per-source, per-class event counts over a bounded
|
||||
window, readable by the source itself, so an emitter can compare audit-core's
|
||||
|
|
@ -133,6 +140,7 @@ scoping, and no payloads in a counts response.
|
|||
id: AUDIT-WP-0009-T07
|
||||
status: todo
|
||||
priority: medium
|
||||
state_hub_task_id: "f572dfeb-0d1b-58d6-be83-405125189028"
|
||||
```
|
||||
Give stream-completeness findings a home. `/v1/dead-letters` and
|
||||
`/v1/secret-findings` exist; a cadence miss (T05) and a missing heartbeat (T04)
|
||||
|
|
@ -145,6 +153,7 @@ than adding a new shape.
|
|||
id: AUDIT-WP-0009-T08
|
||||
status: todo
|
||||
priority: medium
|
||||
state_hub_task_id: "f7b513ee-af48-5c5a-a34e-3e9922d29b76"
|
||||
```
|
||||
Assert the §9.4 approval-validity prohibition with a negative test. It is
|
||||
currently honoured by absence, which is not the estate's idiom: §6.4 obligation
|
||||
|
|
@ -156,6 +165,7 @@ is worth asserting in `tests/`.
|
|||
id: AUDIT-WP-0009-T09
|
||||
status: todo
|
||||
priority: low
|
||||
state_hub_task_id: "fd4a4ac3-e525-57c1-9179-e0fcd0226913"
|
||||
```
|
||||
Register `approval-engine` as a distinct source under §9.4 and `AUDIT-IN-0001`:
|
||||
sender registration, the four event classes (issuance, use, supersession,
|
||||
|
|
@ -168,6 +178,7 @@ events arriving. Not blocking: `approval-engine` is not yet emitting.
|
|||
id: AUDIT-WP-0009-T10
|
||||
status: todo
|
||||
priority: low
|
||||
state_hub_task_id: "ac3464fd-3df9-51a1-b1f4-3bf3c60e4265"
|
||||
```
|
||||
Make the §5 conformance check total. `layer.yaml` declares
|
||||
`tooling_contacts: []`, true under §5 as written — audit-core is an Engine and
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue