Apply gate-house's section 11 rulings: four-token validator, emission guarantee, resource.system.
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s
Build and Publish Container Image / build-and-push (push) Successful in 1m11s

GH-DEC-2026-017: the validator admitted {Staff, Engine, Tooling}, built from
section 4's catalog rows, and rejected Taxonomy, which section 3.1 defines.
railiance-master was conforming; the validator was the divergent artifact.
Now four tokens, ASCII case folded, section 4's spelling canonical, INTENT.md
governing while form disagreements are still reported, and every run states
its scope (section 11 binds section 4; volunteers are not non-conformances).
Also fixes the survey silently dropping audit-core's layer.yaml by decoding
peers into flex-auth's own struct.

GH-DEC-2026-018: flex-auth is a section 4 source of evidence. G2 closes as a
question and reopens as a dated gap (review 2026-10-19). cadence.yaml
publishes the per-event-class inventory: deny, redact, not_applicable and
audit_only rare load-bearing (heartbeat and reconciliation, rate forbidden);
allow volume load-bearing (expected-rate and reconciliation). INTENT.md
declares source_of_evidence and names it; tests assert both. Delivery is
FLEX-WP-0031.

FLEX-DEC-2026-015: resource.system follows the runtime, not the repository,
answering ops-warden's WARDEN-IN-0003.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 06:35:30 +02:00
parent d6c9e3bad4
commit 80ffe729d4
14 changed files with 1502 additions and 78 deletions

View file

@ -39,7 +39,7 @@ reason the four cases below went unnoticed.
| `zone-engine` | zone **membership** compiles into the registry snapshot flex-auth consumes; per-zone **stance** is the consumer's | **held by flex-auth since 2026-08-19; not contested, not confirmed** |
| `user-engine` | PIP; supplies subject facts | **agreed** |
| `tenant-engine` | PIP and consumer. What `CheckRequest.tenant` denotes on the write API — caller, target, or guardrail scope — is **unanswered since 2026-09-15** | **unclear, and live**`FLEX-WP-0022`, re-asked 2026-09-20 |
| `audit-core` | records evidence; flex-auth produces the decision record | **unclear** — which of the two is the §4 *source of evidence* decides whether flex-auth owes an emission guarantee (B3 / G2) |
| `audit-core` | holds custody of evidence; flex-auth **emits** the decision record | **ruled 2026-09-21, against flex-auth** — flex-auth is the §4 source; custody is never source (`GH-DEC-2026-018`); `audit-core` confirmed independently and declined the role (`AUDIT-IN-0005`). G2 is now a dated gap |
| `maturity-engine` | PIP; supplies maturity claims. §9.5 forbids ranking blocked-clean below conforming | **agreed** |
| `kings-guard` | Staff; raised the authentication/assurance evidence gap that flex-auth **declined** (§13, `FLEX-DEC-2026-002`) | **agreed, by mutual declining** |
| `ops-mason` | catalogued PEP-shaped in §4 | **undeclared twice over** — no stance map (§13.1 marks it), no `layer:` key (B2) |
@ -48,13 +48,13 @@ reason the four cases below went unnoticed.
Full statements in `workplans/FLEX-WP-0030-boundary-declaration-cleanup.md` T04.
| # | Finding | Owner |
| --- | --- | --- |
| B1 | **Corrected 2026-09-21.** Nine of nine repositories carrying both §11 forms declare a different `layer:` value in each. §11 does not say which form governs | `gate-house` |
| B2 | `gate-house`, `key-cape`, `ops-mason`, `net-kingdom` carry no machine-readable layer declaration | each named repository |
| B3 | flex-auth declares no emission guarantee; whether it owes one turns on an unruled boundary with `audit-core` | `gate-house`, `audit-core` |
| B4 | a layer declaration should not pin a standard version; if §11 agrees it should say so generally | `gate-house` |
| B5 | canon names `access-engine`; the repository still answers to `flex-auth` and the rename has not landed | `gate-house` to note |
| # | Finding | Owner | Outcome |
| --- | --- | --- | --- |
| B1 | **Corrected 2026-09-21.** Nine of nine repositories carrying both §11 forms declare a different `layer:` value in each. §11 does not say which form governs | `gate-house` | **Ruled** `GH-DEC-2026-017` §1§2: `INTENT.md` governs, sidecar is derived and must agree, the disagreement is still reported; comparison folds ASCII case. flex-auth's validator changed |
| B2 | `gate-house`, `key-cape`, `ops-mason`, `net-kingdom` carry no machine-readable layer declaration | each named repository | `gate-house` declared `Staff` in the ruling commit; three remain |
| B3 | flex-auth declares no emission guarantee; whether it owes one turns on an unruled boundary with `audit-core` | `gate-house`, `audit-core` | **Ruled against flex-auth** `GH-DEC-2026-018`; per-class inventory published in `cadence.yaml`; delivery is dated gap G2 |
| B4 | a layer declaration should not pin a standard version; if §11 agrees it should say so generally | `gate-house` | **Ruled as asked** `GH-DEC-2026-017` §5, A12 |
| B5 | canon names `access-engine`; the repository still answers to `flex-auth` and the rename has not landed | `gate-house` to note | A13 notes it; ping when `FLEX-WP-0020` lands |
## What flex-auth is not claiming
@ -63,7 +63,7 @@ Full statements in `workplans/FLEX-WP-0030-boundary-declaration-cleanup.md` T04.
written the key; `gate-house` is the clearest case.
- **Not a request that any peer change casing.** B1 may equally be resolved by
ruling the vocabulary case-insensitive, which would make flex-auth's validator
the thing that changes.
the thing that changes. *(It was, and it did — see the second correction.)*
- **Not a grade.** §9.3's two-owner split is flex-auth's own finding and it cuts
here: the PDP does not get to score the repositories whose facts it consumes.
@ -110,3 +110,49 @@ tests and a receipt, and why this correction is recorded here rather than edited
away. A published review corrected silently is `FLEX-DEC-2026-008`'s defect, and
that rule does not have an exception for the reviewer.
## Correction — the validator, 2026-09-21
**This review treated flex-auth's validator as the §3 vocabulary. It was not,
and it was wrong.**
`internal/layer` admitted `{Staff, Engine, Tooling}`. §3 enumerates **four**
layers — Taxonomy, Tooling, Engines, Staff — and §3.1 defines Taxonomy, which
§4 catalogues twice (`info-tech-canon`, `net-kingdom`) and which the standard
itself is an instance of. The three-token set was built from §4's role-typed
catalog rows rather than from §3's layer table, so it took §4's spelling
(`Engine`) and lost §3's fourth row. Where this review and its survey said
"outside the §3 vocabulary as written", they meant "outside flex-auth's
validator", and the difference is the finding.
**`railiance-master`'s `Taxonomy` declaration was conforming all along; the
validator was the divergent artifact.** `railiance-master` said so with the
citations (§3.1, §4, §7, §17) against a record that had named it
non-conformant. `GH-DEC-2026-017` §3 ruled the same.
How it happened is §11's derived-artifact rule inverted: an artifact derived
from canon came to stand in for canon, because canon left the token set to be
inferred from two tables that disagree and the validator was the only
executable statement of one. flex-auth wrote that artifact.
**Fixed** in `internal/layer`, per `GH-DEC-2026-017` §2§4 and A9, A11:
- four tokens, closed: `Taxonomy`, `Tooling`, `Engine`, `Staff`;
- ASCII case folded before comparing; a lowercase declaration is conforming;
- §4's column spelling is canonical, so `engine` reports as `Engine` and
`Engines` (§3's plural heading) is not the token;
- `INTENT.md` governs; a disagreement between the two forms is still reported,
and a spelling-only disagreement is distinguished from a disagreement about a
layer (there are nine of the first and none of the second);
- **a run states its scope.** §11 binds §4. The survey now leads with its scope
(`estate-wide` or `§4 catalog`, `--catalog-only`), and reports a repository
outside §4 that declares as *declared voluntarily, outside catalog scope*
never as a non-conformance. This review's own survey was estate-wide over
fourteen counterparts and said nothing about which question it answered.
A second defect surfaced while fixing the first: the survey decoded peers'
files into flex-auth's own declaration struct, so a peer field sharing a name
with one of flex-auth's in a different shape (`audit-core`'s list-shaped
`emission_guarantee`) made that peer's `layer.yaml` silently disappear. Peers
are now read for `layer` and `role` only. A surveyor's schema is a house rule
too. Receipt: `docs/evidence/2026-09-21-layer-declaration-survey-after-ghdec017.json`.