Rule what A12 leaves alone, which text a run names, and one detector for the estate
GH-DEC-2026-021 rules the five questions from the GH-DEC-2026-020 round, with counts re-measured on disk. 1. A12 reaches a pin, not a citation. A prose revision citation is provenance. No declaration changes, gate-house's own included. The narrow reading benefits gate-house, so it is drafted as A12 r3 for assent, not self-approved. 2. VALIDATED_AGAINST names accepted v0.7 plus the decisions enforced. tenant-engine and flex-auth re-point now. 3. ops-warden's playbook detector is the estate reference, with one addition. Copies converge by the post-flip re-point commit. 4. The re-point is a post-flip closing condition of GH-WP-0004 (T11), not a GH-DEC-2026-019 precondition. 5. whitehat-security's conformance_state moves out of the declaration. A single-repository run is admitted as A11 r2. INFD-IN-0007 and GH-WP-0004-T06 are left open, coupled. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
parent
d8c82a8bb4
commit
39d9287596
3 changed files with 302 additions and 9 deletions
|
|
@ -4,7 +4,8 @@
|
|||
**Publisher:** net-kingdom
|
||||
**Project family:** NetKingdom security layer
|
||||
**Status:** drafted — circulating for assent; the v0.8 acceptance flip is held on it (`GH-DEC-2026-019`)
|
||||
**Version:** 0.2 — A12 revised as A12 r2 (`GH-DEC-2026-020`); re-circulated for assent
|
||||
**Version:** 0.3 — A11 r2 and A12 r3 (`GH-DEC-2026-021`); both re-circulated for assent.
|
||||
0.2 revised A12 as A12 r2 (`GH-DEC-2026-020`)
|
||||
**Date:** 2026-09-21
|
||||
**Workplan:** `GH-WP-0004`
|
||||
**Base:** `net-kingdom/canon/standards/security-layer-model_v0.8.md` (proposed, not accepted)
|
||||
|
|
@ -28,8 +29,8 @@ its authority. This document moves them into the statute; it does not decide the
|
|||
| --- | --- | --- | --- |
|
||||
| A9 | §3 | `GH-DEC-2026-017` §2, §3 | T01 |
|
||||
| A10 | §4, §11 | `GH-DEC-2026-018` §5 | T02 |
|
||||
| A11 | §11 | `GH-DEC-2026-017` §1, §4 | T03 |
|
||||
| A12 r2 | §11 | `GH-DEC-2026-017` §5, `GH-DEC-2026-020` | T04 |
|
||||
| A11 r2 | §11 | `GH-DEC-2026-017` §1, §4, `GH-DEC-2026-021` §5 | T03 |
|
||||
| A12 r3 | §11 | `GH-DEC-2026-017` §5, `GH-DEC-2026-020`, `GH-DEC-2026-021` §1 | T04 |
|
||||
| A13 | §4 | `access-engine` B5, `FLEX-WP-0020` | T05 |
|
||||
|
||||
**A note on A2.** The clause A10 repairs is `gate-house`'s own, added as `A2` of the v0.8
|
||||
|
|
@ -134,7 +135,13 @@ reading that favoured it and held the gap open as `G2` rather than closing it fo
|
|||
|
||||
---
|
||||
|
||||
## A11 — §11, which form governs, and what a run's scope is (T03)
|
||||
## A11 r2 — §11, which form governs, and what a run's scope is (T03)
|
||||
|
||||
**Revision note (r2, 2026-09-21).** `kings-guard` (KG-DEC-2026-005) found that the scope
|
||||
paragraph names two estate scopes and is silent on the scope most copied checkers actually
|
||||
run: one repository grading itself. r2 adds one sentence admitting it (`GH-DEC-2026-021`
|
||||
§5). Nothing else changes. **Assent given to A11 as first circulated is to that text and
|
||||
is asked again for r2.**
|
||||
|
||||
**Why.** §11 accepts *"a `layer:` key in the `INTENT.md` frontmatter, or an equivalent
|
||||
declaration file"* and does not say which governs when a repository carries both. Nine do,
|
||||
|
|
@ -163,7 +170,9 @@ for nine repositories and both follow §11.
|
|||
> using this form, and a voluntary declaration is welcome; it is not a §4 obligation and a
|
||||
> run that grades it is over-scoped. A run over §4 and a run over every repository carrying
|
||||
> a declaration answer different questions, and a report that does not say which it did
|
||||
> cannot be acted on.
|
||||
> cannot be acted on. **A run over a single repository is a permitted third scope:** it
|
||||
> names the repository and states whether that repository is in §4, and a run over a
|
||||
> repository outside §4 reports a voluntary result, not §4 conformance.
|
||||
|
||||
**Authority.** `GH-DEC-2026-017` §1 and §4. Raised by `access-engine` (`B1` as corrected,
|
||||
2026-09-21), which mechanised a finding it had published unmechanically and thereby
|
||||
|
|
@ -172,7 +181,15 @@ outside §4.
|
|||
|
||||
---
|
||||
|
||||
## A12 r2 — §11, a declaration carries no standard version, and a run states the version it checks against (T04)
|
||||
## A12 r3 — §11, a declaration carries no standard version, and a run states the version it checks against (T04)
|
||||
|
||||
**Revision note (r3, 2026-09-21).** r2's *"no key or value … carries a version"* literally
|
||||
reached a revision cited in prose, such as *"Outside §5 by the v0.5 scope rule"*. Eight
|
||||
declarations carry such a citation, `gate-house`'s own among them. `approval-engine` and
|
||||
`kings-guard` raised it, and `kings-guard` proposed the wording adopted here.
|
||||
`GH-DEC-2026-021` §1 rules the narrow reading. r3 adds one sentence (marked below) and
|
||||
changes nothing else. The narrow reading benefits `gate-house`, which is disclosed in the
|
||||
ruling, and it is therefore not self-approved. **Assent to r2 is asked again for r3.**
|
||||
|
||||
**Revision note (r2, 2026-09-21).** A12 as first circulated said *"MUST NOT carry a
|
||||
standard version"*, and every checker in the estate implemented it as *"no key named
|
||||
|
|
@ -204,7 +221,11 @@ by key-name checkers that could not see the same pin under another name.
|
|||
> value of either carries a version of this standard **or of its companion** — including a
|
||||
> version carried in a path or file name, such as a `standard:` key naming
|
||||
> `…security-layer-model_v0.7.md`. Comments, and the version of a declaration file's own
|
||||
> schema, are not versions of this standard and are not reached.
|
||||
> schema, are not versions of this standard and are not reached. *(r3)* **A version is
|
||||
> reached when it is carried as a pin:** in a key naming a version of this standard or its
|
||||
> companion, in a path or file name, or in the value of a key that identifies this standard
|
||||
> or its companion. A citation of an earlier revision in a record's prose, stating where a
|
||||
> rule came from, is provenance and is not reached.
|
||||
>
|
||||
> **The rule reaches the declaration only.** A stance map, claims map, or evidence
|
||||
> classification states a position on clause text, which is version-scoped as a layer is
|
||||
|
|
@ -226,7 +247,7 @@ by key-name checkers that could not see the same pin under another name.
|
|||
|
||||
**Authority.** `GH-DEC-2026-017` §5 — cited by its body section; the decision's
|
||||
`rationale:` part numbering is a summary and is not cited (`GH-DEC-2026-020` §5) — and
|
||||
`GH-DEC-2026-020` §1–§4. Raised by `access-engine` against its own file, which is where this
|
||||
`GH-DEC-2026-020` §1–§4, and `GH-DEC-2026-021` §1 for r3. Raised by `access-engine` against its own file, which is where this
|
||||
whole review started; the reach questions raised by `approval-engine`, `ops-warden` and
|
||||
`informed-decision` in applying it, and collected with measured counts by `the-custodian`.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue