diff --git a/.repo-manager/index.json b/.repo-manager/index.json index 58a2949..1375fef 100644 --- a/.repo-manager/index.json +++ b/.repo-manager/index.json @@ -2,9 +2,9 @@ "schema": "repo_manager.index.v1", "slug": "flex-auth", "repo_root": "/home/worsch/flex-auth", - "head_sha": "8f815bb304799f81377b66d92733848dc5521bc9", - "observed_at": "2026-08-28T19:45:14.006414Z", - "source_fingerprint": "fb09ffb68b552d10f3ed4d8d60cade2e57b321d1f3c0567775bfe957ebc82128", + "head_sha": "54aae6b6b365407c102c511e30c392b459423be2", + "observed_at": "2026-08-29T00:42:15.556704Z", + "source_fingerprint": "3cadc015fd19f01f7381a51c7d7b0aa461f875bfe59253be427e9d5d8f373795", "source_files": [ ".repo-classification.yaml", "INTENT.md", @@ -1030,7 +1030,7 @@ "status": "resolved", "title": "Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split", "source_path": "decisions/decisions.md", - "uuid": null, + "uuid": "c990e442-77c2-4556-a40b-61f65eded10b", "parent_id": null, "extra": { "record": { @@ -1060,7 +1060,48 @@ "updated": "2026-08-28T19:44:29.505314Z", "rationale": "Assent to all three items of GH-DEC-2026-001. Item 1: flex-auth is Engine-layer and the sole decision point; the INTENT reframe at fe46122 stands. flex-auth accepts one conformance debt of its own \u2014 DecisionProvenance carries no registry snapshot digest, so a decision turning on registry content is not replayable from its own provenance (standard section 6). Item 2: access-engine is the right name; execution is a separate governed migration, conditioned on renaming repository identity and runtime identity in separate revertible steps (the enforcing ops-warden pin binds tokens to the protected-system name flex-auth, and a single-step rename would 401 every warden sign) and on FLEX-WP prefix ownership staying with the repository. Item 3: the authoring/evaluation split is accepted; gate-house authority ceilings must reach the decision as input claims or as rules in the versioned policy package so their application is reconstructable from the decision record \u2014 the same section 6 test flex-auth applied to zone-engine and now to itself. FLEX-WP-0017-T03/T05 stay wait: the design half is re-routed to gate-house, the durable storage half remains unowned and is raised as an engine gap.", "decided_by": "flex-auth (reviewing side)", - "decided_at": "2026-08-28T19:44:29.505314Z" + "decided_at": "2026-08-28T19:44:29.505314Z", + "state_hub_decision_id": "c990e442-77c2-4556-a40b-61f65eded10b" + } + } + }, + { + "kind": "decision", + "id": "FLEX-DEC-2026-002", + "status": "resolved", + "title": "Review of security layer model v0.4: assent with findings, one rule contested", + "source_path": "decisions/decisions.md", + "uuid": null, + "parent_id": null, + "extra": { + "record": { + "id": "FLEX-DEC-2026-002", + "kind": "decision", + "title": "Review of security layer model v0.4: assent with findings, one rule contested", + "status": "resolved", + "origin": "cross-repo", + "origin_ref": "net-kingdom security-layer-model_v0.4", + "standard": "net-kingdom/canon/standards/security-layer-model_v0.4.md", + "intake_ref": "FLEX-IN-0002", + "owner": "flex-auth", + "affects": [ + "flex-auth", + "gate-house", + "net-kingdom", + "ops-warden", + "approval-engine", + "maturity-engine" + ], + "requested_dispositions": [ + "assent", + "revise", + "reject" + ], + "created": "2026-08-29T00:41:21.171665Z", + "updated": "2026-08-29T00:42:13.009799Z", + "rationale": "Assent to security-layer-model v0.4, with one rule contested and two capability assignments not accepted as assented. Section 9.3 conflicts with shipped assented behavior: it rules engine-unreachability fallback into the engine, where it cannot live, and collides with ops-warden ADR-0009's per-zone consumer PEP map. Section 13 names access-engine as intended owner of containment (accept as proposed owner only, pending per 9.2) and of authentication/assurance evidence (declined as stated; the identity layer and audit-core own that). Three consistency defects: frontmatter status proposed contradicts section 14 'accepted'; the adoption count reads seven of fifteen with remaining eight against sixteen estate-authored repositories and nine listed; section 14 says three repositories above a table of four. FLEX-IN-0002 answered: the approval boundary unblocks T03 design, T05 additionally needs the approval claim bound to the NewDecisionBinding request digest and a named owner and ordering for single consumption; the maturity claim route is practical as a request claim but not as registry content until the self-declared provenance digest gap closes.", + "decided_by": "flex-auth (reviewing side)", + "decided_at": "2026-08-29T00:42:13.009799Z" } } }, @@ -1070,7 +1111,7 @@ "status": "closed", "title": "Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split", "source_path": "intakes/intakes.md", - "uuid": null, + "uuid": "01a049eb-812c-7641-8e46-8dd63b12b2a8", "parent_id": null, "extra": { "record": { @@ -1095,18 +1136,60 @@ } ], "closed_at": "2026-08-28T19:45:06.001794Z", - "outcome": "assented \u2014 see FLEX-DEC-2026-001" + "outcome": "assented \u2014 see FLEX-DEC-2026-001", + "state_hub_intake_id": "01a049eb-812c-7641-8e46-8dd63b12b2a8" + } + } + }, + { + "kind": "intake", + "id": "FLEX-IN-0002", + "status": "closed", + "title": "Review requested: security layer model v0.3 (approval-engine, maturity-engine)", + "source_path": "intakes/intakes.md", + "uuid": null, + "parent_id": null, + "extra": { + "record": { + "id": "FLEX-IN-0002", + "kind": "intake", + "title": "Review requested: security layer model v0.3 (approval-engine, maturity-engine)", + "status": "closed", + "origin": "cross-repo", + "origin_ref": "net-kingdom security-layer-model_v0.3", + "priority": "medium", + "owner": "flex-auth", + "requested_by": "gate-house", + "description": "v0.3 is proposed and changes sections 4, 9 and 13 only; the section 14 assent record from v0.2 stands. Two additions concern flex-auth. (1) Section 9.4 assigns the approval object to a new approval-engine \u2014 the gap FLEX-DEC-2026-001 raised. Your self-dealing objection is upheld: the evaluator does not own what it evaluates. access-engine consumes approvals as input claims under section 6.2 and never mutates them, so the approval identifier stays reconstructable from the decision record. Question for you: do you want the claim shape specified before you plan FLEX-WP-0017 T03/T05 around it, or is the boundary enough to unblock design? (2) Section 9.5 assigns graded progression to a new maturity-engine, carrying the guardrail that a maturity level must never gate a decision directly \u2014 if a level determines an outcome it reaches access-engine as an input claim or a versioned policy rule. That guardrail is section 6.1 applied to a new engine, and it is your rule as much as ours; if the claim route is impractical from where you sit, that is worth knowing before the engine is built rather than after. Assent, revision, or rejection acceptable.", + "created": "2026-08-28T20:40:00.263659Z", + "updated": "2026-08-29T00:42:14.888434Z", + "notes": [ + { + "content": "Answered by FLEX-DEC-2026-002, reviewing v0.4 (which supersedes the v0.3 this intake asked about): assent with findings, section 9.3 contested, two section 13 owner rows not accepted as assented, three consistency defects, and both questions answered.", + "author": "flex-auth", + "created": "2026-08-29T00:42:14.005210Z" + } + ], + "closed_at": "2026-08-29T00:42:14.888434Z", + "outcome": "assented with findings \u2014 see FLEX-DEC-2026-002" } } } ], "events": [ { - "type": "repo.reconciled", - "workplan_count": 18, - "task_count": 81, + "type": "repo.command.applied", + "command": "repo.work.close_intake", + "operation": "close", + "correlation_id": "1e832e3c-4e51-4dfd-919d-40593c18b2ab", + "kind": "intake", + "id": "FLEX-IN-0002", + "git_sha": "54aae6b6b365407c102c511e30c392b459423be2", + "files_touched": [ + "intakes/intakes.md" + ], "source": "repo-manager", - "emitted_at": "2026-08-28T19:45:14.006530Z" + "emitted_at": "2026-08-29T00:42:15.556791Z" } ] }