Apply gate-house's section 11 rulings: four-token validator, emission guarantee, resource.system.
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s
Build and Publish Container Image / build-and-push (push) Successful in 1m11s

GH-DEC-2026-017: the validator admitted {Staff, Engine, Tooling}, built from
section 4's catalog rows, and rejected Taxonomy, which section 3.1 defines.
railiance-master was conforming; the validator was the divergent artifact.
Now four tokens, ASCII case folded, section 4's spelling canonical, INTENT.md
governing while form disagreements are still reported, and every run states
its scope (section 11 binds section 4; volunteers are not non-conformances).
Also fixes the survey silently dropping audit-core's layer.yaml by decoding
peers into flex-auth's own struct.

GH-DEC-2026-018: flex-auth is a section 4 source of evidence. G2 closes as a
question and reopens as a dated gap (review 2026-10-19). cadence.yaml
publishes the per-event-class inventory: deny, redact, not_applicable and
audit_only rare load-bearing (heartbeat and reconciliation, rate forbidden);
allow volume load-bearing (expected-rate and reconciliation). INTENT.md
declares source_of_evidence and names it; tests assert both. Delivery is
FLEX-WP-0031.

FLEX-DEC-2026-015: resource.system follows the runtime, not the repository,
answering ops-warden's WARDEN-IN-0003.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 06:35:30 +02:00
parent d6c9e3bad4
commit 80ffe729d4
14 changed files with 1502 additions and 78 deletions

View file

@ -38,21 +38,44 @@ Assent is to the boundary, recorded at the version where it was given.
## Conformance state at v0.8
**Conforming, with declared gaps below.** §11's four states: conforming,
blocked-clean, declared gap, undeclared violation. flex-auth claims no
blocked-clean capability and holds no undeclared violation it is aware of.
**Scope of this record:** one repository, `flex-auth`, which is the §4 row
`access-engine`. §11 binds §4 and flex-auth is in it, so this is an in-scope
record. Stated because a run MUST state its scope (A11, `GH-DEC-2026-017` §4).
**Not conforming on §11, held as a declared gap.** `GH-DEC-2026-018` ruled that
flex-auth is a §4 source of evidence for the decision record and owes an
emission guarantee it did not declare. Recorded in those words, as gate-house
wrote them: flex-auth asked for the unflattering reading, and softening it here
would make the register useless for whoever is next.
§11's four states: conforming, blocked-clean, declared gap, undeclared
violation. flex-auth claims no blocked-clean capability and holds no undeclared
violation it is aware of. Everything below is a declared gap: owner, blocker,
review date.
| # | Gap | Owner | Blocked on | Review |
| --- | --- | --- | --- | --- |
| G1 | Registry-snapshot digest absent from decision provenance. §9.7.2 promotes it to a conformance prerequisite: a decision that turned on registry content must be replayable from its own record. | `flex-auth` | implementation | `FLEX-WP-0019` |
| G2 | **Emission guarantee not declared.** §11 requires every §4 repository catalogued as a source of evidence to declare class, cadence and detection surface in its machine-readable declaration, and says a source declaring none is not conforming. flex-auth declares none. | `gate-house` to rule, then `flex-auth` | whether flex-auth is a §4 *source of evidence* or only the producer of an artifact `audit-core` sources — see `FLEX-WP-0030` B3 | `FLEX-WP-0030-T04` |
| G2 | **Emission guarantee declared, not delivered.** Ruled 2026-09-21 (`GH-DEC-2026-018`): flex-auth is the source; custody is never source; `audit-core` confirmed its half and declined the role (`AUDIT-IN-0005`). The per-event-class inventory and classification are **published** in [`cadence.yaml`](../../cadence.yaml) and named from `INTENT.md` (`source_of_evidence: true`, `emission_guarantee`). Five decision classes are load-bearing; `deny`, `redact`, `not_applicable`, `audit_only` are **rare** — heartbeat **and** reconciliation, rate monitoring forbidden; `allow` is **volume** — expected-rate **and** reconciliation. Nothing emits yet: no sender is registered with `audit-core`, no outbox, no heartbeat. | `flex-auth` | outbox + heartbeat implementation, and an `audit-core` sender registration (intake + token lane, per `AUDIT-IN-0002`/`0003`) — `FLEX-WP-0031` | **2026-10-19** |
| G3 | Published stance-register review is stale: written at two register rows, §13.1 now carries five, and its Finding 1 was ruled by v0.8 §6.4 obligation 3. | `flex-auth` | second edition | `FLEX-WP-0029` |
G2 is recorded as a gap rather than as conformance because the flattering reading
— that `audit-core` is the source and flex-auth merely produces — has not been
confirmed by anyone but flex-auth. §11 says a source that declares no emission
guarantee is not conforming; until the boundary is ruled, the conservative entry
is the honest one.
**G2 fails closed.** A stream with no delivered cadence produces no silence
finding, so the failure on its distinguishing case is a **missed detection**,
never a manufactured permission (A-17, §9.6's §8-asymmetry). That is why it can
be held as a gap rather than being a permission. It is still non-conformance,
tracked, and it is not closed by the classification being published: a
declaration of a guarantee nobody delivers is the §9.1 defect this standard
keeps correcting.
**What the classification is.** flex-auth's, published as §11 requires the
source to publish it. `GH-DEC-2026-018` §4 declined to classify on flex-auth's
behalf because §11 forbids inferring class from event name, payload or observed
rate, and that binds a ruling as hard as a runner. A conformance run is supplied
this inventory and must not derive it.
**Atomicity is pending, not waived.** Whether decision-record emission must be
atomic with the decision (§9.4) was expressly left open by `GH-DEC-2026-018`
pending this inventory. It now exists; the question goes to `FLEX-WP-0031`.
## Not gaps
@ -65,8 +88,11 @@ is the honest one.
## How this file is kept true
`internal/layer` asserts that `INTENT.md` carries no `standard_version` and names
a `conformance_record` that exists on disk. That is the same property flex-auth
`internal/layer` asserts that `INTENT.md` carries no `standard_version`, names
a `conformance_record` that exists on disk, states `source_of_evidence`, and —
because it is `true` — names an `emission_guarantee` that exists on disk and
classifies every event class, with every rare load-bearing class carrying
heartbeat and reconciliation and forbidding rate monitoring. That is the same property flex-auth
praised in `ops-warden`'s stance map: the published artifact is asserted equal to
the shipped one by test, rather than merely written down. It does **not** assert
the contents below the declaration — a reviewer still has to read this file.