flex-auth/docs/evidence/2026-09-21-layer-declaration-survey-after-ghdec017.json
tegwick e0c6c4389d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 1m11s
Widen A12 enforcement from the key name to the declaration's content (GH-DEC-2026-020).
internal/layer/conformance.go enforced A12 as "no key named standard_version",
and so could not see the same pin as a versioned standard: path or as
companion_version. It now detects a version of the standard or its companion
in any key or value of the declaration (INTENT.md frontmatter, layer.yaml),
including a version in a path, and excludes comments and schema_version. It
refuses to be applied to pep-stance.yaml, pip-claims.yaml or
evidence-classification.yaml, which A12 r2 does not reach (§3).

Every run of check_layer_conformance and of the estate survey now prints the
standard version it checks against (layer.ValidatedAgainst, kings-guard's
pattern) and its scope (§4). The survey applies the same detection to peers'
declarations; the receipt is refreshed because the survey's output changed
(no peer declaration currently carries a version).

Tests fail if a versioned standard: path or a companion_version comes back.
flex-auth's own INTENT.md needed no change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 09:39:46 +02:00

528 lines
12 KiB
JSON

{
"checks_only": "the closed four-token §3 vocabulary, ASCII case folded per GH-DEC-2026-017 §2; and A12 r2 (GH-DEC-2026-020): no standard or companion version in any key or value of INTENT.md frontmatter or layer.yaml; stance, claims and classification maps not read; no flex-auth house rules applied to peers",
"derived_at": "run time",
"off_vocab": null,
"root": "/home/worsch",
"rows": [
{
"Repo": "approval-engine",
"Intent": {
"Source": "approval-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "approval-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "audit-core",
"Intent": {
"Source": "audit-core/INTENT.md",
"Layer": "Engine",
"Role": "Evidence",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "audit-core/layer.yaml",
"Layer": "engine",
"Role": "evidence",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "flex-auth",
"Intent": {
"Source": "flex-auth/INTENT.md",
"Layer": "Engine",
"Role": "PDP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"InCatalog": true
},
{
"Repo": "gate-house",
"Intent": {
"Source": "gate-house/INTENT.md",
"Layer": "Staff",
"Role": "—",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"File": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"InCatalog": true
},
{
"Repo": "key-cape",
"Intent": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"File": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"InCatalog": true
},
{
"Repo": "kings-guard",
"Intent": {
"Source": "kings-guard/INTENT.md",
"Layer": "Staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"File": {
"Source": "kings-guard/layer.yaml",
"Layer": "staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"InCatalog": true
},
{
"Repo": "maturity-engine",
"Intent": {
"Source": "maturity-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "maturity-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "net-kingdom",
"Intent": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"File": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"InCatalog": true
},
{
"Repo": "ops-mason",
"Intent": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"File": {
"Source": "",
"Layer": "",
"Role": "",
"Found": false,
"InVocabulary": false,
"Canonical": ""
},
"InCatalog": true
},
{
"Repo": "ops-warden",
"Intent": {
"Source": "ops-warden/INTENT.md",
"Layer": "Staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"File": {
"Source": "ops-warden/layer.yaml",
"Layer": "staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"InCatalog": true
},
{
"Repo": "secrets-engine",
"Intent": {
"Source": "secrets-engine/INTENT.md",
"Layer": "Engine",
"Role": "Lifecycle",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "secrets-engine/layer.yaml",
"Layer": "engine",
"Role": "lifecycle",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "tenant-engine",
"Intent": {
"Source": "tenant-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "tenant-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "user-engine",
"Intent": {
"Source": "user-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "user-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "zone-engine",
"Intent": {
"Source": "zone-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "zone-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
}
],
"scope": {
"Name": "estate-wide",
"Statement": "every repository surveyed, catalogued or not. Repositories outside §4 are reported as declared voluntarily, outside catalog scope — never as §11 non-conformances.",
"Repos": [
"approval-engine",
"audit-core",
"flex-auth",
"gate-house",
"key-cape",
"kings-guard",
"maturity-engine",
"net-kingdom",
"ops-mason",
"ops-warden",
"secrets-engine",
"tenant-engine",
"user-engine",
"zone-engine"
]
},
"self_disagreeing": [
{
"Repo": "approval-engine",
"Intent": {
"Source": "approval-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "approval-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "audit-core",
"Intent": {
"Source": "audit-core/INTENT.md",
"Layer": "Engine",
"Role": "Evidence",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "audit-core/layer.yaml",
"Layer": "engine",
"Role": "evidence",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "kings-guard",
"Intent": {
"Source": "kings-guard/INTENT.md",
"Layer": "Staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"File": {
"Source": "kings-guard/layer.yaml",
"Layer": "staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"InCatalog": true
},
{
"Repo": "maturity-engine",
"Intent": {
"Source": "maturity-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "maturity-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "ops-warden",
"Intent": {
"Source": "ops-warden/INTENT.md",
"Layer": "Staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"File": {
"Source": "ops-warden/layer.yaml",
"Layer": "staff",
"Role": "",
"Found": true,
"InVocabulary": true,
"Canonical": "Staff"
},
"InCatalog": true
},
{
"Repo": "secrets-engine",
"Intent": {
"Source": "secrets-engine/INTENT.md",
"Layer": "Engine",
"Role": "Lifecycle",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "secrets-engine/layer.yaml",
"Layer": "engine",
"Role": "lifecycle",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "tenant-engine",
"Intent": {
"Source": "tenant-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "tenant-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "user-engine",
"Intent": {
"Source": "user-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "user-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
},
{
"Repo": "zone-engine",
"Intent": {
"Source": "zone-engine/INTENT.md",
"Layer": "Engine",
"Role": "PIP",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"File": {
"Source": "zone-engine/layer.yaml",
"Layer": "engine",
"Role": "pip",
"Found": true,
"InVocabulary": true,
"Canonical": "Engine"
},
"InCatalog": true
}
],
"spellings": {
"Engine": [
"approval-engine/INTENT.md",
"audit-core/INTENT.md",
"flex-auth/INTENT.md",
"maturity-engine/INTENT.md",
"secrets-engine/INTENT.md",
"tenant-engine/INTENT.md",
"user-engine/INTENT.md",
"zone-engine/INTENT.md"
],
"Staff": [
"gate-house/INTENT.md",
"kings-guard/INTENT.md",
"ops-warden/INTENT.md"
],
"engine": [
"approval-engine/layer.yaml",
"audit-core/layer.yaml",
"maturity-engine/layer.yaml",
"secrets-engine/layer.yaml",
"tenant-engine/layer.yaml",
"user-engine/layer.yaml",
"zone-engine/layer.yaml"
],
"staff": [
"kings-guard/layer.yaml",
"ops-warden/layer.yaml"
]
},
"undeclared": [
"key-cape",
"net-kingdom",
"ops-mason"
],
"validated_against": "net-kingdom security-layer-model v0.8 with amendments A9-A13 (A12 r2), gate-house@104f3fc (GH-DEC-2026-017, GH-DEC-2026-020)",
"version_pinned": null,
"volunteers": null
}