Rule what A12 leaves alone, which text a run names, and one detector for the estate

GH-DEC-2026-021 rules the five questions from the GH-DEC-2026-020 round, with
counts re-measured on disk.

1. A12 reaches a pin, not a citation. A prose revision citation is provenance.
   No declaration changes, gate-house's own included. The narrow reading
   benefits gate-house, so it is drafted as A12 r3 for assent, not
   self-approved.
2. VALIDATED_AGAINST names accepted v0.7 plus the decisions enforced.
   tenant-engine and flex-auth re-point now.
3. ops-warden's playbook detector is the estate reference, with one addition.
   Copies converge by the post-flip re-point commit.
4. The re-point is a post-flip closing condition of GH-WP-0004 (T11), not a
   GH-DEC-2026-019 precondition.
5. whitehat-security's conformance_state moves out of the declaration.
   A single-repository run is admitted as A11 r2.

INFD-IN-0007 and GH-WP-0004-T06 are left open, coupled.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 12:39:57 +02:00
parent d8c82a8bb4
commit 39d9287596
3 changed files with 302 additions and 9 deletions

View file

@ -3683,3 +3683,248 @@ holding its own change on a bar it set for itself, and the question turned out t
in `GH-DEC-2026-017` §5. `kings-guard` answered it for itself before it was asked, and that in `GH-DEC-2026-017` §5. `kings-guard` answered it for itself before it was asked, and that
answer is the ruling. `informed-decision` removed `companion_version` and said so, which is answer is the ruling. `informed-decision` removed `companion_version` and said so, which is
the only reason question 2 had a split to report. the only reason question 2 had a split to report.
## GH-DEC-2026-021 — A12 reaches a pin, not a citation; the run names the text in force; one reference detector, converged by the flip commit
```yaml
id: GH-DEC-2026-021
kind: decision
title: A12 reaches a pin, not a citation; the run names the text in force; one reference
detector, converged by the flip commit
status: resolved
owner: Bernd Worsch
standard: net-kingdom/canon/standards/security-layer-model_v0.8.md
source_note: the-custodian 3d2775e2 and 45cd7bf9 (counts re-measured here); approval-engine
358143da; kings-guard 8f821b10 (KG-DEC-2026-005); tenant-engine 38efcca1; whitehat-security
986bac64; ops-warden acc25ebe (playbook 0f9ada0); the-custodian docs/assessments/2026-09-21-layer-declaration-boundaries.md
requested_dispositions:
- approved
- revised
- rejected
affects:
- gate-house
- net-kingdom
- kings-guard
- approval-engine
- maturity-engine
- zone-engine
- railiance-master
- railiance-platform
- informed-decision
- tenant-engine
- flex-auth
- secrets-engine
- user-engine
- ops-warden
- whitehat-security
- audit-core
created: '2026-09-21T10:38:31.327138Z'
updated: '2026-09-21T10:39:28.023577Z'
rationale: 'Five questions from the GH-DEC-2026-020 round, counts re-measured on disk.
(1) A12 reaches a pin, not a citation: a version in a key naming a standard or companion
version, in a path or file name, or in an identity-bearing standard:/companion:
value. A revision cited in prose is provenance and is not reached, because nothing
opens or branches on it. No declaration changes, including gate-house''s own INTENT.md.
The narrow reading benefits gate-house, so it goes to assent as A12 r3, and if that
is rejected gate-house rewords first. tenant-engine''s rewording is harmless and
stays. (2) VALIDATED_AGAINST names accepted v0.7 plus the gate-house decisions enforced
(017, 020, 021), with a gate-house commit recommended. tenant-engine and flex-auth
re-point now. (3) ops-warden''s playbook detector is the estate reference, with
one addition (a version token in a standard:/companion: value is a pin). Copies
converge when next edited and no later than the post-flip re-point commit. (4) The
re-point is not a 019 closing condition, because it is circular before acceptance.
It is a post-flip closing condition of GH-WP-0004 (T11). (5) whitehat-security''s
conformance_state moves to run/evidence records, concurring with its reading. kings-guard''s
single-repository scope is accepted as A11 r2. INFD-IN-0007 and GH-WP-0004-T06 are
left open and coupled. Nothing in net-kingdom canon is edited.'
decided_by: Bernd Worsch
decided_at: '2026-09-21T10:39:28.023577Z'
```
## Context
`GH-DEC-2026-020` is applied in all eleven repositories it named. The round returned five
questions, collected by `the-custodian` (`3d2775e2`, corrected by `45cd7bf9`) and raised
directly by `approval-engine`, `kings-guard`, `tenant-engine`, `whitehat-security` and
`ops-warden`. Every count below was re-measured here on disk on 2026-09-21, parsing the
`INTENT.md` frontmatter of each repository that declares `layer:` and every `layer.yaml`,
comments excluded.
- **Prose citations.** Eight declarations carry a revision citation in a prose value, in ten
values: `kings-guard` 3; `approval-engine`, `maturity-engine`, `zone-engine`,
`railiance-master`, `informed-decision`, `railiance-platform` and `gate-house`'s own
`INTENT.md` 1 each. The custodian's "2" for `railiance-platform` is two citations
(`v0.8`, `v0.7`) in one value. Seven are the same sentence, *"Outside §5 by the v0.5 scope
rule"*. `tenant-engine` carried an eighth copy citing **v0.7**, which was the wrong
revision, and has reworded it.
- **`VALIDATED_AGAINST`.** Eight checkers: six name v0.7 (`kings-guard`, `user-engine`,
`zone-engine`, `secrets-engine`, `maturity-engine`, `ops-warden`), two name the proposed
v0.8 (`tenant-engine`, `flex-auth`). Only `ops-warden` names both a net-kingdom and a
gate-house commit. `kings-guard`, `user-engine` and `zone-engine` name v0.7 and nothing
else. The custodian's corrected count stands.
- **Detectors.** They diverge as reported. One more measured case: `informed-decision`'s
declaring frontmatter carries `intent_version: 0.1.0`, the version of its own `INTENT.md`.
A detector that flags any key containing or ending in `version` flags it. The reference
detector does not.
## Decision
### 1. A12 reaches a pin, not a citation. No declaration changes
**Ruled narrow.** A version is *reached* when it is carried **as a pin**: in a key that names
a version of this standard or its companion, in a path or file name, or in the value of an
identity-bearing key that names this standard or its companion (`standard:`, `companion:`).
A revision cited in a record's prose, to say where a rule came from, is **provenance** and
is not reached.
**Reason.** A12's ground, stated in `GH-DEC-2026-017` §5 and kept in `GH-DEC-2026-020` §1,
is that a version in a declaration *reads as a validity condition* and will be branched on,
and that a path is what a tool opens. No tool opens or branches on *"the v0.5 scope rule"*.
Striking the citation deletes provenance and reduces the pin risk by nothing. The
distinction can also be checked mechanically: a pin sits in a key name, in a path-shaped
token, or in an identity-bearing key. A reference detector built on that structure (§3)
separates pins from citations without an allowlist. `approval-engine`'s worry was that a
content-reading checker cannot tell the two apart by pattern. That is true of a bare `vN.N`
regex, and it is the reason §3 names one detector.
**Conflict of interest, stated.** `gate-house`'s own `INTENT.md` carries one of these
citations, so the narrow reading benefits the ruler, as it benefits `kings-guard`, which
proposed it. The reason above does not depend on `gate-house`'s line. The wording goes to
assent as A12 r3 and is not self-approved. If A12 r3 is rejected in favour of the literal
reading, `gate-house` rewords its own frontmatter **in the commit that records the
rejection**, before anyone else is asked to.
**Who changes under each outcome:**
- **Narrow (ruled):** no declaration changes. `gate-house`'s `INTENT.md` stands.
`approval-engine`'s single-line allowlist and `kings-guard`'s NOTE both become
unnecessary, and both are conforming until §3's convergence.
- **Literal (if A12 r3 is rejected):** ten values in eight declarations are reworded:
`kings-guard` (3), `approval-engine`, `maturity-engine`, `zone-engine`,
`railiance-master`, `railiance-platform`, `informed-decision` and `gate-house` (1 each).
In addition, `approval-engine` drops its allowlist, `kings-guard` turns its NOTE into a
failure, and the reference detector is widened to any `vN.N` in any value.
**`tenant-engine`'s rewording is harmless.** Its note now reads *"the standard's scope
rule"*, and that conforms under both readings. It also removed a citation that named the
wrong revision (v0.7, where the rule is v0.5's), so the change was an improvement for a
reason unrelated to A12. Leave it and do not revert it. The repair that *is* owed is in its
detector. It fails a bare `vN.N` in any value, which over-reaches this ruling, and it
converges under §3.
### 2. `VALIDATED_AGAINST` names the text in force. ops-warden's playbook is confirmed, with one tightening
**Confirmed.** While the v0.8 flip is held under `GH-DEC-2026-019`, a checker's
`VALIDATED_AGAINST` names the **accepted** `security-layer-model_v0.7.md` and the
gate-house decision records whose rulings the checker enforces beyond v0.7 (today
`GH-DEC-2026-017`, `GH-DEC-2026-020`, `GH-DEC-2026-021`). A run that names the proposed v0.8
claims a check against text that does not govern. That is the same defect `GH-DEC-2026-020`
§4 moved the version out of the declaration to prevent.
**Tightening.** Naming v0.7 alone understates the check. A checker that enforces A12's
content reach is enforcing `GH-DEC-2026-020`, not v0.7, and its run must say so. A
gate-house commit is **recommended** and not required. The accepted v0.7 text is frozen,
so its file name identifies it, while the decision set grows, so a commit pins what "the
decisions" meant at the time of the run. `ops-warden`'s constant is the reference form.
**Who changes:**
- **Now:** `tenant-engine` and `flex-auth` each re-point one constant from v0.8 to the v0.7
form. They claim non-governing text today.
- **At convergence (§3), not in a separate commit:** `kings-guard`, `user-engine` and
`zone-engine` add the decision ids. `maturity-engine` and `secrets-engine` add `021`.
`ops-warden` adds `021` when it next touches the constant.
### 3. ops-warden's detector is the estate reference, with one addition, and copies converge by the flip commit
**Ruled.** The detector quoted in `ops-warden`'s playbook
(`wiki/playbooks/netkingdom-layer-declaration.md`, `0f9ada0`) is the **estate reference**
that copies converge on. Its structure already implements §1. It flags keys that name a
standard or companion version, flags versions in path or file-name tokens, skips
`schema_version`, never reads comments, and does not flag a space-preceded `vN.N` in prose.
**One addition,** from `kings-guard`'s identity-bearing clause: any version token (`v?N.N`)
in the value of a `standard:` or `companion:` key is a pin. Without it,
`standard: security-layer-model v0.7` passes, and that form is the pin A12 exists to stop.
`ops-warden` adds it to the reference. The playbook's "pending" note on prose citations
becomes "not reached (`GH-DEC-2026-021` §1)".
**The reference errs on one side, deliberately.** Its path pattern flags a versioned path of
*any* document in a declaration, which is wider than A12's "this standard or its
companion". No declaration carries such a path today (measured). A repository that needs one
raises it, and it is not waived by allowlist.
**Timetable.** A copy converges **when it is next edited, and no later than the commit that
re-points its `VALIDATED_AGAINST` after the flip** (§4). That commit touches every checker
anyway, and a flip that leaves eight detectors disagreeing would accept §11 while its check
still cannot make two runs agree, which is the defect `GH-DEC-2026-019` holds on. Each
repository implements its own copy. `gate-house` does not edit them.
**Where each copy stands against the reference on today's declarations:** none produces a
wrong verdict on its own declaration today. `tenant-engine` (any bare `vN.N`) and
`maturity-engine` (any key containing `version`) over-reach. `flex-auth`'s estate survey is
the only copy run over peers, so it is the one whose divergence is visible to others.
### 4. The re-point is a consequence of the flip, not a condition on it. It is added to GH-WP-0004's closure instead
**Not added to `GH-DEC-2026-019`'s closing conditions.** Those conditions must hold *before*
the flip. A checker cannot name v0.8 as in force before v0.8 is accepted without becoming the
defect §2 corrects, so making the re-point a precondition would be circular.
**What is ruled instead.** The re-point and §3's convergence are a **post-flip closing
condition of `GH-WP-0004`**, carried as `GH-WP-0004-T11`. The workplan does not finish until
all eight checkers name v0.8 and run the reference detector, or a repository records a dated
reason in writing. The flip notice from T10 names the eight repositories, so nothing depends
on each of them noticing on its own. This keeps the custodian's point, which is that seven
hand edits need something to ensure they happen, and does not hold the flip on them.
### 5. `conformance_state` moves out of the declaration. A11 admits a single-repository run
**`whitehat-security`'s `conformance_state`: its reading is concurred with.** The key
carries no version, so A12 does not reach it and it is not a non-conformance. But it is
state judged against a particular §5 text, and it changes when WHITEHAT-WP-0008 gets an
engagement window. Under `GH-DEC-2026-020` §4 that belongs to a run's output or to the
record that retains it, not to a standing declaration. `whitehat-security` moves it to
WHITEHAT-WP-0008 or its evidence records, at its own next touch and no later than the flip.
`declared_at` stays: it dates the act of declaring and is not state.
**`kings-guard`'s A11 point: accepted.** A11's scope sentence names the two estate scopes
and is silent on the scope almost every copied checker actually runs, which is one
repository grading itself. Drafted as **A11 r2**. A single-repository run is a permitted
scope. It names the repository and says whether that repository is in §4. A run over a
repository outside §4 reports a voluntary result, not §4 conformance. On that sentence,
`informed-decision`'s self-check is well-scoped rather than over-scoped.
## What this does not rule
- **`INFD-IN-0007`**, how §3.4's Staff definition fits a repository that is deterministic by
test and holds evidence `audit-core` depends on. It is **left open, explicitly.** It is a
question about §3's primary cut, not about §11. A real answer amends §3.4 or states a
carried tension in the standard's voice, and neither belongs in a set whose hold is
scoped to §11 (`GH-DEC-2026-019` §5).
- **`GH-WP-0004-T06`, the §4 row `informed-decision` asked for.** It is **left open**, and it
is coupled to `INFD-IN-0007`. A catalogued Staff row is measured against §3.4 directly, and
drafting the row before that fit is answered would put a row into §4 that §3.4 prohibits
on its face. The answer is recorded as received and it is not declined.
- **The sidecar schema's version policy**, which remains `ops-warden`'s.
## Reversal condition
§1 reverses if a tool is found reading or branching on a prose revision citation in a
declaration. The remedy is then the literal reading, and `gate-house`'s own line goes first.
§3's reference reverses if a declaration is found that the reference passes and a reader
would take as pinned to a version. The detector is widened, and the ruling does not change.
§4 reverses if T11 is still open six months after the flip. That would show a workplan
closing condition is not enough, and the re-point becomes a precondition of the *next* flip.
## Provenance
Raised independently by `approval-engine`, which allowlisted its one line and asked instead
of rewording, and by `kings-guard`, which proposed the narrow wording and said plainly that
it benefits from it. `tenant-engine` reworded ahead of the ruling, offered to revert, and
turned out to have removed a wrong citation. `the-custodian` measured the eight declarations
and the checker split, and corrected its own count within a minute. `ops-warden` wrote the
reference detector as steward's practice, left the open question visibly pending rather than
deciding it in code, and the detector is adopted largely as written.

View file

@ -4,7 +4,8 @@
**Publisher:** net-kingdom **Publisher:** net-kingdom
**Project family:** NetKingdom security layer **Project family:** NetKingdom security layer
**Status:** drafted — circulating for assent; the v0.8 acceptance flip is held on it (`GH-DEC-2026-019`) **Status:** drafted — circulating for assent; the v0.8 acceptance flip is held on it (`GH-DEC-2026-019`)
**Version:** 0.2 — A12 revised as A12 r2 (`GH-DEC-2026-020`); re-circulated for assent **Version:** 0.3 — A11 r2 and A12 r3 (`GH-DEC-2026-021`); both re-circulated for assent.
0.2 revised A12 as A12 r2 (`GH-DEC-2026-020`)
**Date:** 2026-09-21 **Date:** 2026-09-21
**Workplan:** `GH-WP-0004` **Workplan:** `GH-WP-0004`
**Base:** `net-kingdom/canon/standards/security-layer-model_v0.8.md` (proposed, not accepted) **Base:** `net-kingdom/canon/standards/security-layer-model_v0.8.md` (proposed, not accepted)
@ -28,8 +29,8 @@ its authority. This document moves them into the statute; it does not decide the
| --- | --- | --- | --- | | --- | --- | --- | --- |
| A9 | §3 | `GH-DEC-2026-017` §2, §3 | T01 | | A9 | §3 | `GH-DEC-2026-017` §2, §3 | T01 |
| A10 | §4, §11 | `GH-DEC-2026-018` §5 | T02 | | A10 | §4, §11 | `GH-DEC-2026-018` §5 | T02 |
| A11 | §11 | `GH-DEC-2026-017` §1, §4 | T03 | | A11 r2 | §11 | `GH-DEC-2026-017` §1, §4, `GH-DEC-2026-021` §5 | T03 |
| A12 r2 | §11 | `GH-DEC-2026-017` §5, `GH-DEC-2026-020` | T04 | | A12 r3 | §11 | `GH-DEC-2026-017` §5, `GH-DEC-2026-020`, `GH-DEC-2026-021` §1 | T04 |
| A13 | §4 | `access-engine` B5, `FLEX-WP-0020` | T05 | | A13 | §4 | `access-engine` B5, `FLEX-WP-0020` | T05 |
**A note on A2.** The clause A10 repairs is `gate-house`'s own, added as `A2` of the v0.8 **A note on A2.** The clause A10 repairs is `gate-house`'s own, added as `A2` of the v0.8
@ -134,7 +135,13 @@ reading that favoured it and held the gap open as `G2` rather than closing it fo
--- ---
## A11 — §11, which form governs, and what a run's scope is (T03) ## A11 r2 — §11, which form governs, and what a run's scope is (T03)
**Revision note (r2, 2026-09-21).** `kings-guard` (KG-DEC-2026-005) found that the scope
paragraph names two estate scopes and is silent on the scope most copied checkers actually
run: one repository grading itself. r2 adds one sentence admitting it (`GH-DEC-2026-021`
§5). Nothing else changes. **Assent given to A11 as first circulated is to that text and
is asked again for r2.**
**Why.** §11 accepts *"a `layer:` key in the `INTENT.md` frontmatter, or an equivalent **Why.** §11 accepts *"a `layer:` key in the `INTENT.md` frontmatter, or an equivalent
declaration file"* and does not say which governs when a repository carries both. Nine do, declaration file"* and does not say which governs when a repository carries both. Nine do,
@ -163,7 +170,9 @@ for nine repositories and both follow §11.
> using this form, and a voluntary declaration is welcome; it is not a §4 obligation and a > using this form, and a voluntary declaration is welcome; it is not a §4 obligation and a
> run that grades it is over-scoped. A run over §4 and a run over every repository carrying > run that grades it is over-scoped. A run over §4 and a run over every repository carrying
> a declaration answer different questions, and a report that does not say which it did > a declaration answer different questions, and a report that does not say which it did
> cannot be acted on. > cannot be acted on. **A run over a single repository is a permitted third scope:** it
> names the repository and states whether that repository is in §4, and a run over a
> repository outside §4 reports a voluntary result, not §4 conformance.
**Authority.** `GH-DEC-2026-017` §1 and §4. Raised by `access-engine` (`B1` as corrected, **Authority.** `GH-DEC-2026-017` §1 and §4. Raised by `access-engine` (`B1` as corrected,
2026-09-21), which mechanised a finding it had published unmechanically and thereby 2026-09-21), which mechanised a finding it had published unmechanically and thereby
@ -172,7 +181,15 @@ outside §4.
--- ---
## A12 r2 — §11, a declaration carries no standard version, and a run states the version it checks against (T04) ## A12 r3 — §11, a declaration carries no standard version, and a run states the version it checks against (T04)
**Revision note (r3, 2026-09-21).** r2's *"no key or value … carries a version"* literally
reached a revision cited in prose, such as *"Outside §5 by the v0.5 scope rule"*. Eight
declarations carry such a citation, `gate-house`'s own among them. `approval-engine` and
`kings-guard` raised it, and `kings-guard` proposed the wording adopted here.
`GH-DEC-2026-021` §1 rules the narrow reading. r3 adds one sentence (marked below) and
changes nothing else. The narrow reading benefits `gate-house`, which is disclosed in the
ruling, and it is therefore not self-approved. **Assent to r2 is asked again for r3.**
**Revision note (r2, 2026-09-21).** A12 as first circulated said *"MUST NOT carry a **Revision note (r2, 2026-09-21).** A12 as first circulated said *"MUST NOT carry a
standard version"*, and every checker in the estate implemented it as *"no key named standard version"*, and every checker in the estate implemented it as *"no key named
@ -204,7 +221,11 @@ by key-name checkers that could not see the same pin under another name.
> value of either carries a version of this standard **or of its companion** — including a > value of either carries a version of this standard **or of its companion** — including a
> version carried in a path or file name, such as a `standard:` key naming > version carried in a path or file name, such as a `standard:` key naming
> `…security-layer-model_v0.7.md`. Comments, and the version of a declaration file's own > `…security-layer-model_v0.7.md`. Comments, and the version of a declaration file's own
> schema, are not versions of this standard and are not reached. > schema, are not versions of this standard and are not reached. *(r3)* **A version is
> reached when it is carried as a pin:** in a key naming a version of this standard or its
> companion, in a path or file name, or in the value of a key that identifies this standard
> or its companion. A citation of an earlier revision in a record's prose, stating where a
> rule came from, is provenance and is not reached.
> >
> **The rule reaches the declaration only.** A stance map, claims map, or evidence > **The rule reaches the declaration only.** A stance map, claims map, or evidence
> classification states a position on clause text, which is version-scoped as a layer is > classification states a position on clause text, which is version-scoped as a layer is
@ -226,7 +247,7 @@ by key-name checkers that could not see the same pin under another name.
**Authority.** `GH-DEC-2026-017` §5 — cited by its body section; the decision's **Authority.** `GH-DEC-2026-017` §5 — cited by its body section; the decision's
`rationale:` part numbering is a summary and is not cited (`GH-DEC-2026-020` §5) — and `rationale:` part numbering is a summary and is not cited (`GH-DEC-2026-020` §5) — and
`GH-DEC-2026-020` §1§4. Raised by `access-engine` against its own file, which is where this `GH-DEC-2026-020` §1§4, and `GH-DEC-2026-021` §1 for r3. Raised by `access-engine` against its own file, which is where this
whole review started; the reach questions raised by `approval-engine`, `ops-warden` and whole review started; the reach questions raised by `approval-engine`, `ops-warden` and
`informed-decision` in applying it, and collected with measured counts by `the-custodian`. `informed-decision` in applying it, and collected with measured counts by `the-custodian`.

View file

@ -114,6 +114,10 @@ state_hub_task_id: "8dd32a14-35d9-55c3-adfa-d9c728b550b1"
Asked, not enrolled. Its correction from `surface` to `Staff`/`pep-shaped` is its own and Asked, not enrolled. Its correction from `surface` to `Staff`/`pep-shaped` is its own and
is not a condition of this task. is not a condition of this task.
Answered **yes** by `informed-decision` (`docs/section-4-catalog-row.md`). The row is not
drafted yet: it is coupled to `INFD-IN-0007` (how §3.4's Staff definition fits a
deterministic repository that holds evidence), which is left open by `GH-DEC-2026-021`.
```task ```task
id: GH-WP-0004-T06 id: GH-WP-0004-T06
status: todo status: todo
@ -155,6 +159,12 @@ Returns so far: `approval-engine` assents to A9A13 as first circulated (98d33
re-circulated 2026-09-21 to the round list with `GH-DEC-2026-020`; assent to r2 is asked re-circulated 2026-09-21 to the round list with `GH-DEC-2026-020`; assent to r2 is asked
afresh from every round member, including `approval-engine`. afresh from every round member, including `approval-engine`.
A12 r2 returns: `approval-engine` approved; `kings-guard` revised (KG-DEC-2026-005, prose
citations; A11 single-repository scope); `audit-core`, `access-engine` (`flex-auth`) and
`ops-warden` deferred assent to the operator, which is pending and not refused.
`GH-DEC-2026-021` rules both findings. The set is now v0.3, with **A11 r2 and A12 r3**
re-circulated 2026-09-21. Assent to the earlier texts does not carry over.
```task ```task
id: GH-WP-0004-T09 id: GH-WP-0004-T09
status: progress status: progress
@ -174,7 +184,24 @@ priority: medium
state_hub_task_id: "34d0582b-9b7e-5dcf-ac1e-0257312b8b7b" state_hub_task_id: "34d0582b-9b7e-5dcf-ac1e-0257312b8b7b"
``` ```
### T11 — Post-flip: all eight checkers name v0.8 and run the reference detector
A post-flip closing condition, not a condition on the flip (`GH-DEC-2026-021` §4). The
following re-point `VALIDATED_AGAINST` to the accepted v0.8 and converge their copies on the
reference detector in `ops-warden`'s playbook (`GH-DEC-2026-021` §3), or record a dated
reason in writing: `kings-guard`, `user-engine`, `zone-engine`, `secrets-engine`,
`maturity-engine`, `ops-warden`, `tenant-engine` and `flex-auth`. The T10 flip notice names
all eight. `whitehat-security`'s move of `conformance_state` out of its declaration is
tracked here with the same deadline.
```task
id: GH-WP-0004-T11
status: wait
priority: medium
```
## Done when ## Done when
All five amendments are in the v0.8 cut, the three `GH-DEC-2026-019` closing conditions All five amendments are in the v0.8 cut, the three `GH-DEC-2026-019` closing conditions
are met, and `net-kingdom` has flipped v0.8 to `accepted`. are met, `net-kingdom` has flipped v0.8 to `accepted`, and T11's post-flip re-point is
done.