Close the binding-correspondence gap as GH-DEC-2026-008
access-engine raised, and declined to solve locally, a hole in the split GH-DEC-2026-005 ruled on. approval-claim verification item 4 is a disjunction and neither limb delivers "approved for THIS request" on the PDP path: limb one requires translating between two engines' vocabularies and no mapping is published, limb two (pdp_digest) is optional. Where the digest is absent a consumer can hold valid_now true, receive an ALLOW, consume and act with nothing establishing that approval and decision concern the same action and target. Ruled: the PDP digest is the correspondence and is required on that path; a claim without one fails closed; the native limb survives only for consumers already in approval-engine's vocabulary, including T-06. No mapping is published — a translation can be wrong while still producing a confident answer, it fails open, it would be owned by neither engine, and recomputing another layer's binding is the re-derivation GH-DEC-2026-005 already forbids. The cost is stated: an approval issued without a bound CheckRequest is unusable on this path, which is correct behaviour. Also: adopted hub row b606e8ce as canonical for GH-DEC-2026-005 rather than registering a duplicate; recorded approval-engine's narrowing of the approver-threshold consequence (distinctness is a UNIQUE storage invariant, so the PEP stopped checking that the engine applied its own invariant, not whether dual control could be forged); and drafted A7/T08, a §11 marking obligation and §12 consumer rule for derived summaries, after four instances in one week across four repositories. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ Assistant: claude-code Assistant-Model: opus Assistant-Process: 425128@bnt-lap001 Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
This commit is contained in:
parent
865bab3955
commit
f0f888ca7e
4 changed files with 196 additions and 4 deletions
|
|
@ -163,3 +163,22 @@ cite the decision; keep §17's drafter credit to `kings-guard`.
|
|||
Surfaced by `docs/conformance/2026-09-06-v06-findings-audit.md`, which also confirms
|
||||
that all fifteen v0.6 review findings are dispositioned in v0.7 — this is the one
|
||||
paragraph a later decision made stale, not a missed finding.
|
||||
|
||||
```task
|
||||
id: GH-WP-0003-T08
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
**Derived summaries must be marked (A7).** Four instances in one week, in four
|
||||
repositories, of a repository acting on a derived summary rather than the
|
||||
authoritative body — a stale revisit trigger here, a change log read for section text
|
||||
here, a dual-control rule written against an assumed schema in `access-engine`, a
|
||||
fixture read for contract prose in `secrets-engine`. Proposed by `approval-engine` on
|
||||
the observation that at four instances it is a property of how the estate publishes
|
||||
rather than four separate lapses: authoritative bodies with derived summaries beside
|
||||
them and no staleness marker on the derivatives.
|
||||
|
||||
Drafted as A7 — a §11 marking obligation on the publisher and a §12 paragraph on the
|
||||
consumer. The limit is stated in the draft: marking makes staleness visible, it does
|
||||
not detect a marked derivative that is still wrong.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue