State two properties once, and repair SCOPE.md's withdrawn framing
Two things this week's rulings left owed, both the failure mode those rulings were about. A-16 and A-17, and Core Rules 16 and 17. Two general properties had been stated three times each, always against the instance that produced them and nowhere in general — which is how a property gets found by accident or not at all. That is the defect gate-house corrected in three other repositories this month while carrying it here. A-16, distinguishable routes: where one observable state is reachable by two routes differing in security meaning, the record must say which. Four instances, and they only look like one rule once they are next to each other — an envelope identical whether access-engine issued it or a responder forged it (GH-DEC-2026-010), unknown versus absent in a stance map (-011), a tenant claim directory-asserted versus registration-supplied (-013), erased versus never held on an evidence path (-014). The rule is not that the routes must diverge; usually they must behave identically and safely. It is that a later reader can tell them apart, or a sound check gets read as carrying a property it does not have. A-17, fail-closed transitions: a transitional deviation is admissible only where it fails closed on the case distinguishing it from the conformant state. Written because two requests for transitional relief arrived in one week and were answered oppositely, and the answers would otherwise read as arbitrary rather than as one rule. Both are marked repository-level and explicitly not estate doctrine. Graduation waits on a repository that bears a cost under them having argued them, which is the bar security-layer-model met and these have not. SCOPE.md was still the withdrawn authority-plane framing. It opened by saying gate-house "decides whether a requested action is authorized" and listed deterministic authorization decisions as in scope — the design retired by GH-DEC-2026-001, surviving in a derived document a reader would take as current, with a dead pointer to Blueprint section 3 non-goals that the re-cut removed. Rewritten from current INTENT, including what is not owned here and what would put the repository out of scope. The irony is noted rather than hidden: a derived artifact contradicting its source, in the repository that generalised that failure into statute section 12 after finding six instances in one week elsewhere. rmgr conform clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm Assistant: claude-code Assistant-Model: opus Assistant-Process: 1754332@bnt-lap001 Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
parent
2117d28809
commit
a5a1bcf537
4 changed files with 167 additions and 34 deletions
|
|
@ -4,8 +4,8 @@
|
|||
**Project family:** NetKingdom
|
||||
**Artifact:** `ArchitectureBlueprint.md`
|
||||
**Status:** Current — doctrine architecture; no runtime role
|
||||
**Version:** 0.2
|
||||
**Date:** 2026-09-01
|
||||
**Version:** 0.3
|
||||
**Date:** 2026-09-10
|
||||
**Decision:** `decisions/decisions.md` GH-DEC-2026-001
|
||||
|
||||
---
|
||||
|
|
@ -545,6 +545,49 @@ Assistant sessions do not silently become Autonomous sessions.
|
|||
|
||||
Deterministic boundaries continue to hold when every agent behaves incorrectly.
|
||||
|
||||
### A-16 — Distinguishable routes
|
||||
|
||||
Where one observable state is reachable by two routes that differ in security
|
||||
meaning, the record distinguishes which route produced it.
|
||||
|
||||
The two routes usually behave identically, and must — `unknown` and `absent` both
|
||||
fail closed, and should. A-16 is not a requirement that they diverge; it is a
|
||||
requirement that a later reader can tell them apart. Where they cannot, a sound
|
||||
check gets read as establishing a property it does not carry, and the safer
|
||||
reading of the appearance becomes unavailable to everyone.
|
||||
|
||||
Instances: `GH-DEC-2026-010` (a decision envelope reads identically whether
|
||||
`access-engine` issued it or a responder forged it), `GH-DEC-2026-011` (`unknown`
|
||||
versus `absent` in a stance map), `GH-DEC-2026-013` (a `tenant` claim
|
||||
directory-asserted about the principal versus registration-supplied about the
|
||||
client), `GH-DEC-2026-014` (*erased* versus *never held* on an evidence path).
|
||||
|
||||
### A-17 — Fail-closed transitions
|
||||
|
||||
A transitional deviation from an invariant is admissible only where it fails
|
||||
closed on the case that distinguishes it from the conformant state.
|
||||
|
||||
This governs what may enter the declared-gap register rather than what a system
|
||||
does at runtime. The admitting question is not the quality of the design or the
|
||||
length of the transition, but the direction of failure at the distinguishing
|
||||
case. A promise that fails open is a permission; a promise that fails closed is a
|
||||
gap.
|
||||
|
||||
Instances: `GH-DEC-2026-011` (a dated transitional `unknown: fail_open` declined
|
||||
— its distinguishing case is exactly where it fails open, so the transition
|
||||
licenses the forbidden thing and dates it), `GH-DEC-2026-013` (a
|
||||
registration-bound tenant granted — registration and directory disagreeing
|
||||
refuses issuance rather than picking a winner), `GH-DEC-2026-014` (commitment-only
|
||||
evidence granted — a reviewer who cannot obtain the content gets no
|
||||
reconstruction rather than a wrong one).
|
||||
|
||||
**A-16 and A-17 are newer than A-01…A-15 and are not yet estate doctrine.** They
|
||||
are stated here because a property recorded only against the instance that
|
||||
produced it is found by accident or not at all. Graduation to
|
||||
`net-kingdom/canon/standards/` waits on a repository bearing a cost under them
|
||||
having argued them, which is the bar `security-layer-model` met and these have
|
||||
not.
|
||||
|
||||
## 16. Conformance architecture
|
||||
|
||||
Gate House doctrine is real only when the loop turns:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue