repo.work.create_decision GH-DEC-2026-009

correlation_id: b5a1db81-fa81-4449-878f-206dce74ceaf
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
This commit is contained in:
repo-manager 2026-09-06 14:17:19 +02:00
parent 8a3eec5301
commit 45a65c0748

View file

@ -1072,3 +1072,43 @@ workflow, not the possibility of one. The expected resolution is that such a cas
needs a *class* binding with its own contract, not a relaxation of this one to an
optional field, because an optional correspondence is indistinguishable at the
consumer from no correspondence at all.
## GH-DEC-2026-009 — Unknown is not a zone and fails closed; stance maps declare their scoping axis
```yaml
id: GH-DEC-2026-009
kind: decision
title: Unknown is not a zone and fails closed; stance maps declare their scoping axis
status: resolved
owner: Bernd Worsch
repo: gate-house
standard: net-kingdom/canon/standards/security-layer-model_v0.7.md
source_note: flex-auth/docs/stance-register-review.md
requested_dispositions:
- approved
- revised
- rejected
affects:
- gate-house
- net-kingdom
- ops-warden
- secrets-engine
- user-engine
- tenant-engine
- ops-mason
- access-engine
- zone-engine
rationale: 'Raised by access-engine on the first occasion the §13.1 register held
enough rows to diverge. Two rulings. First: an unreachable engine and an unclassifiable
subject are different failure cases, and §9.3''s per-zone availability trade is
only available for the first. Trading openness for a zone requires knowing the zone;
where the scope is unknown the trade cannot have been made for it, and fail_open
on unknown hands the most permissive stance to exactly the request an attacker can
most easily make unclassifiable. unknown is therefore not a zone and MUST fail closed.
Second: the register cannot aggregate across incommensurable scoping axes, so each
map declares its axis and its relationship to zone, and the register states what
it cannot answer rather than implying it can.'
decided_by: Bernd Worsch
created: '2026-09-06T12:17:19.104531Z'
updated: '2026-09-06T12:17:19.104531Z'
```