From 45a65c07482cfbd19a19a8b653fe1a4251f42d91 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Sun, 6 Sep 2026 14:17:19 +0200 Subject: [PATCH] repo.work.create_decision GH-DEC-2026-009 correlation_id: b5a1db81-fa81-4449-878f-206dce74ceaf reason: rmgr CLI source: repo-manager Assistant: claude-code Assistant-Model: opus Assistant-Process: 425128@bnt-lap001 Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63 --- decisions/decisions.md | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/decisions/decisions.md b/decisions/decisions.md index 0b6bd85..64ca393 100644 --- a/decisions/decisions.md +++ b/decisions/decisions.md @@ -1072,3 +1072,43 @@ workflow, not the possibility of one. The expected resolution is that such a cas needs a *class* binding with its own contract, not a relaxation of this one to an optional field, because an optional correspondence is indistinguishable at the consumer from no correspondence at all. + +## GH-DEC-2026-009 — Unknown is not a zone and fails closed; stance maps declare their scoping axis + +```yaml +id: GH-DEC-2026-009 +kind: decision +title: Unknown is not a zone and fails closed; stance maps declare their scoping axis +status: resolved +owner: Bernd Worsch +repo: gate-house +standard: net-kingdom/canon/standards/security-layer-model_v0.7.md +source_note: flex-auth/docs/stance-register-review.md +requested_dispositions: +- approved +- revised +- rejected +affects: +- gate-house +- net-kingdom +- ops-warden +- secrets-engine +- user-engine +- tenant-engine +- ops-mason +- access-engine +- zone-engine +rationale: 'Raised by access-engine on the first occasion the §13.1 register held + enough rows to diverge. Two rulings. First: an unreachable engine and an unclassifiable + subject are different failure cases, and §9.3''s per-zone availability trade is + only available for the first. Trading openness for a zone requires knowing the zone; + where the scope is unknown the trade cannot have been made for it, and fail_open + on unknown hands the most permissive stance to exactly the request an attacker can + most easily make unclassifiable. unknown is therefore not a zone and MUST fail closed. + Second: the register cannot aggregate across incommensurable scoping axes, so each + map declares its axis and its relationship to zone, and the register states what + it cannot answer rather than implying it can.' +decided_by: Bernd Worsch +created: '2026-09-06T12:17:19.104531Z' +updated: '2026-09-06T12:17:19.104531Z' +```