Rule what A12 leaves alone, which text a run names, and one detector for the estate

GH-DEC-2026-021 rules the five questions from the GH-DEC-2026-020 round, with
counts re-measured on disk.

1. A12 reaches a pin, not a citation. A prose revision citation is provenance.
   No declaration changes, gate-house's own included. The narrow reading
   benefits gate-house, so it is drafted as A12 r3 for assent, not
   self-approved.
2. VALIDATED_AGAINST names accepted v0.7 plus the decisions enforced.
   tenant-engine and flex-auth re-point now.
3. ops-warden's playbook detector is the estate reference, with one addition.
   Copies converge by the post-flip re-point commit.
4. The re-point is a post-flip closing condition of GH-WP-0004 (T11), not a
   GH-DEC-2026-019 precondition.
5. whitehat-security's conformance_state moves out of the declaration.
   A single-repository run is admitted as A11 r2.

INFD-IN-0007 and GH-WP-0004-T06 are left open, coupled.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 12:39:57 +02:00
parent d8c82a8bb4
commit 39d9287596
3 changed files with 302 additions and 9 deletions

View file

@ -4,7 +4,8 @@
**Publisher:** net-kingdom
**Project family:** NetKingdom security layer
**Status:** drafted — circulating for assent; the v0.8 acceptance flip is held on it (`GH-DEC-2026-019`)
**Version:** 0.2 — A12 revised as A12 r2 (`GH-DEC-2026-020`); re-circulated for assent
**Version:** 0.3 — A11 r2 and A12 r3 (`GH-DEC-2026-021`); both re-circulated for assent.
0.2 revised A12 as A12 r2 (`GH-DEC-2026-020`)
**Date:** 2026-09-21
**Workplan:** `GH-WP-0004`
**Base:** `net-kingdom/canon/standards/security-layer-model_v0.8.md` (proposed, not accepted)
@ -28,8 +29,8 @@ its authority. This document moves them into the statute; it does not decide the
| --- | --- | --- | --- |
| A9 | §3 | `GH-DEC-2026-017` §2, §3 | T01 |
| A10 | §4, §11 | `GH-DEC-2026-018` §5 | T02 |
| A11 | §11 | `GH-DEC-2026-017` §1, §4 | T03 |
| A12 r2 | §11 | `GH-DEC-2026-017` §5, `GH-DEC-2026-020` | T04 |
| A11 r2 | §11 | `GH-DEC-2026-017` §1, §4, `GH-DEC-2026-021` §5 | T03 |
| A12 r3 | §11 | `GH-DEC-2026-017` §5, `GH-DEC-2026-020`, `GH-DEC-2026-021` §1 | T04 |
| A13 | §4 | `access-engine` B5, `FLEX-WP-0020` | T05 |
**A note on A2.** The clause A10 repairs is `gate-house`'s own, added as `A2` of the v0.8
@ -134,7 +135,13 @@ reading that favoured it and held the gap open as `G2` rather than closing it fo
---
## A11 — §11, which form governs, and what a run's scope is (T03)
## A11 r2 — §11, which form governs, and what a run's scope is (T03)
**Revision note (r2, 2026-09-21).** `kings-guard` (KG-DEC-2026-005) found that the scope
paragraph names two estate scopes and is silent on the scope most copied checkers actually
run: one repository grading itself. r2 adds one sentence admitting it (`GH-DEC-2026-021`
§5). Nothing else changes. **Assent given to A11 as first circulated is to that text and
is asked again for r2.**
**Why.** §11 accepts *"a `layer:` key in the `INTENT.md` frontmatter, or an equivalent
declaration file"* and does not say which governs when a repository carries both. Nine do,
@ -163,7 +170,9 @@ for nine repositories and both follow §11.
> using this form, and a voluntary declaration is welcome; it is not a §4 obligation and a
> run that grades it is over-scoped. A run over §4 and a run over every repository carrying
> a declaration answer different questions, and a report that does not say which it did
> cannot be acted on.
> cannot be acted on. **A run over a single repository is a permitted third scope:** it
> names the repository and states whether that repository is in §4, and a run over a
> repository outside §4 reports a voluntary result, not §4 conformance.
**Authority.** `GH-DEC-2026-017` §1 and §4. Raised by `access-engine` (`B1` as corrected,
2026-09-21), which mechanised a finding it had published unmechanically and thereby
@ -172,7 +181,15 @@ outside §4.
---
## A12 r2 — §11, a declaration carries no standard version, and a run states the version it checks against (T04)
## A12 r3 — §11, a declaration carries no standard version, and a run states the version it checks against (T04)
**Revision note (r3, 2026-09-21).** r2's *"no key or value … carries a version"* literally
reached a revision cited in prose, such as *"Outside §5 by the v0.5 scope rule"*. Eight
declarations carry such a citation, `gate-house`'s own among them. `approval-engine` and
`kings-guard` raised it, and `kings-guard` proposed the wording adopted here.
`GH-DEC-2026-021` §1 rules the narrow reading. r3 adds one sentence (marked below) and
changes nothing else. The narrow reading benefits `gate-house`, which is disclosed in the
ruling, and it is therefore not self-approved. **Assent to r2 is asked again for r3.**
**Revision note (r2, 2026-09-21).** A12 as first circulated said *"MUST NOT carry a
standard version"*, and every checker in the estate implemented it as *"no key named
@ -204,7 +221,11 @@ by key-name checkers that could not see the same pin under another name.
> value of either carries a version of this standard **or of its companion** — including a
> version carried in a path or file name, such as a `standard:` key naming
> `…security-layer-model_v0.7.md`. Comments, and the version of a declaration file's own
> schema, are not versions of this standard and are not reached.
> schema, are not versions of this standard and are not reached. *(r3)* **A version is
> reached when it is carried as a pin:** in a key naming a version of this standard or its
> companion, in a path or file name, or in the value of a key that identifies this standard
> or its companion. A citation of an earlier revision in a record's prose, stating where a
> rule came from, is provenance and is not reached.
>
> **The rule reaches the declaration only.** A stance map, claims map, or evidence
> classification states a position on clause text, which is version-scoped as a layer is
@ -226,7 +247,7 @@ by key-name checkers that could not see the same pin under another name.
**Authority.** `GH-DEC-2026-017` §5 — cited by its body section; the decision's
`rationale:` part numbering is a summary and is not cited (`GH-DEC-2026-020` §5) — and
`GH-DEC-2026-020` §1§4. Raised by `access-engine` against its own file, which is where this
`GH-DEC-2026-020` §1§4, and `GH-DEC-2026-021` §1 for r3. Raised by `access-engine` against its own file, which is where this
whole review started; the reach questions raised by `approval-engine`, `ops-warden` and
`informed-decision` in applying it, and collected with measured counts by `the-custodian`.