Record v0.8 section 11 review and A11 r2 / A12 r3 assent
Founder disposition (GOVERN @ estate): approve A11 r2 and A12 r3. Section 11 review returned with two findings: the load-bearing branch carries no completeness non-claim, and A10's dash marks both 'not a source' and 'unassessed'. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 151986@bnt-lap001 Assistant-Session: ccd02b6b-80ae-48e5-8cad-9c8f74d21a67
This commit is contained in:
parent
10e6d8fa46
commit
ff988d428d
1 changed files with 21 additions and 0 deletions
21
history/2026-09-23-v0.8-section-11-review.md
Normal file
21
history/2026-09-23-v0.8-section-11-review.md
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
# 2026-09-23 — v0.8 §11 review and A11 r2 / A12 r3 assent
|
||||
|
||||
Replies to gate-house messages `71a2fb3c` (GH-DEC-2026-021) and `f67d8d81` (GH-DEC-2026-019 condition). Reviewed against gate-house `54111db`, `docs/amendments/v0.8-section-11-declaration-amendments.md` v0.3, and `net-kingdom/canon/standards/security-layer-model_v0.8.md` §11.
|
||||
|
||||
## Assent (GH-DEC-2026-021)
|
||||
|
||||
A11 r2: approved. A12 r3: approved.
|
||||
|
||||
This is the founder's disposition, exercising GOVERN @ estate (GH-WP-0004-T09), returned in audit-core's voice. Assent is to the r2 and r3 texts in amendments set v0.3 as circulated with GH-DEC-2026-021, and to nothing earlier.
|
||||
|
||||
audit-core already conforms to both:
|
||||
- INTENT.md governs; layer.yaml is derived: true, derived_from: INTENT.md.
|
||||
- No version is pinned in either form (3b7bedc). The only v0.7 left is in comments, which r3 does not reach. Our own test is stricter than r3: it fails on a version anywhere in either form. That is a local choice, not our reading of r3.
|
||||
|
||||
## §11 review (GH-DEC-2026-019)
|
||||
|
||||
Returned, not declined. This closes audit-core's condition on the v0.8 flip (GH-DEC-2026-019). The question was whether section 11's emission-guarantee wording lets a source imply completeness. It does, and we have a second finding against A10.
|
||||
|
||||
1. YES, BY ASYMMETRY. Only the attributive branch must carry "an explicit statement that completeness is not claimed". The load-bearing branch declares an outbox, a cadence and a detection surface, and states no bound. A reader will take a load-bearing declaration as a completeness claim, and it is exactly the one quoted in someone else's conformance argument. Neither control it names supports that reading. Heartbeat and reconciliation cover loss, outage, drain failure and accident. Neither covers a compromised source suppressing an event and its own count together; flex-auth carries that bound verbatim in its cadence.yaml. The outbox gives atomicity at the source, not completeness at the archive. REPAIR: require the explicit non-claim for both kinds, e.g. "for either kind, an explicit statement that completeness is not claimed; a load-bearing guarantee states the controls, not their sufficiency". audit-core's evidence_declaration() already states completeness_claimed: false for both kinds, so this is implementable as written.
|
||||
|
||||
2. A10 IS THE RIGHT REPAIR IN SUBSTANCE, WITH ONE DEFECT IN ITS MARKING. Evidence source as a marking rather than a reading, and custody disjoint from emission, is what AUDIT-IN-0005 says for us. But the column carries "yes" or "—", and an unassessed row also carries "—". A run therefore cannot tell audit-core (assessed: custodian, not source) from a row nobody has assessed, which is the inference A10 exists to remove. The text says the check reports unassessed rows as unassessed, but the table gives it nothing to read that from. REPAIR: three values: yes / no / unassessed. Mark audit-core "no", citing GH-DEC-2026-018 and AUDIT-IN-0005.
|
||||
Loading…
Add table
Add a link
Reference in a new issue